Google Search

Showing posts with label botnet. Show all posts
Showing posts with label botnet. Show all posts

Tuesday, October 15, 2013

Botnet smackdown, Oracle on Java, Passwords you can eat - 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Watch our 60 Second Security videos for a fast, incisive and entertaining angle on what's been going on recently in computer security.

Here you go: the latest security news in just 60 seconds.

(If you enjoyed this video, you'll find plenty more on the SophosLabs YouTube channel.)

http://twitter.com/duckblog

Tags: 2FA, 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, botnet, citadel, FBI, java. patch, linkedin, Malware, Microsoft, Motorola, Oracle, pill, stomach, takedown, token, update, vulnerability


View the original article here

Saturday, August 24, 2013

Network gaming company uses its “cheat-prevention” client to build a Bitcoin botnet

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

In one episode of the nerdtastic TV sitcom Big Bang Theory, the socially-challenged Caltech physicist antihero, Dr Sheldon Cooper, has his World of Warcraft account hacked.

A giant shopping-list of Sheldon's virtual property gets plundered: his wand of untainted power, all his gold, and even Glenn, his beloved battle ostrich.

As Sheldon laments, "Three thousand hours. Three thousand hours clicking on that mouse, collecting weapons and gold. It's almost as if it was a huge waste of time."

And that's the problem with games that you play across the internet: how do you trust the other people in the contest?

Even when there's no money involved, it spoils the fun if the other guys aren't on the level.

That's where on-line communities like ESEA, or E-Sports Entertainment, come into play.

ESEA describes itself on Facebook as "the leading game play based community. With a sweet pick up game mod, a custom anti-cheat client that works, and cool statistics to log all of your activity, ESEA is the place to play!"

To join ESEA's network, you need to install and use the company's custom client software.

The client is designed, amongst other things, to maintain a level playing field by detecting cheats, such as players who programmatically automate tasks - rapid, accurate shooting, for instance - that are supposed to be a battle of dexterity between human opponents.

Imagine the stirrings of discontent when players on ESEA's network started wondering about symptoms such as their GPUs (graphics processing units, the special graphics cards that speed up the display) running at high utilisation.

Overcooking your GPU can be a costly exercise, since it increases electricity consumption and may shorten the life of your hardware.

What was causing the hot and heavy running?

Surreptitious Bitcoin mining, it seems!

One customer took the simple precaution of looking in the ESEA client log file and found this:

Another user got in telephonic contact with a sysadmin at ESEA to discuss what was going on, and received some surprising admissions during the call.

Here's a partial transcript of the sysadmin's comments:

It shouldn't be any surprise, but the [anti-cheat] client is capable of doing a lot of things that people don't know about. [...] They think the client does screenshots and that's about it. Truth be told...it probably does more than about 50 different things, because there are more than 50 ways to cheat.

[...] Funnily enough, there was a debate, a conversation, regarding the subject of using the client to mine Bitcoins. That was a joke, but at the same time it was half serious.

The high-performance GPUs that many gamers own are handy for Bitcoining, because the Bitcoin system relies on computing massive numbers of SHA checksums, a task that just happens to be ideally suited to today's graphics hardware.

The ESEA staffer continues, rather unconvincingly:

It turned out I actually did write code to do it, but it wasn't supposed to be code that was everywhere. [...] I restarted the server and the [configuration] setting got reset and [the mining code] actually got turned on, which was only, like, it wasn't for very long.

We calculated how much we would actually make, if we really wanted to do it. We would make hundreds of thousands of dollars if we actually did it with everybody. But that would be pretty intense.

[Voice of caller] Not to mention kind of illegal.

And that's the problem with software that you run across the internet: how do you trust the other people in the protocol?

Even if there's no money involved, it spoils the fun if the other guys aren't on the level.

ESEA head honcho Torbull has now tried to make a clean breast of it, admitting that the company had toyed with the idea of using its customers as a giant Bitcoin botnet, but decided not to go ahead.

Nevertheless, someone inside the company didn't listen, and ran a Bitcoin farm on ESEA customers' computers for the next two weeks.

The outcome fell far short of the hundreds of thousands of dollars predicted above, but was nevertheless a handy sum to accumulate for free: just under $4000's worth of Bitcurrency.

It's a funny sort of infringement, because the Bitcoins weren't actually stolen, and the client software was voluntarily installed by each user, no doubt under terms and conditions that permit fairly arbitrary remote updates and reconfiguration.

Indeed, the Bitcoins didn't even exist until before the unauthorised mining started.

ESEA has decided to donate the proceeds to charity, to chip in the same amount again itself, and to create a prize pool for customers that will return $3,713.55 back into its customer community.

Peace with honour?

Probably - but it does raise the age old question: who will guard the guards?

Follow @duckblog


View the original article here

Monday, January 28, 2013

Suspected gang behind the $850 million Butterfly botnet arrested

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Evil butterfly. Image from ShutterstockThe FBI has announced that 10 individuals have been arrested, suspected of involvement in infecting 11 million computers with spyware that led to an alleged $850 million in losses.

The FBI is said to have worked in co-ordination with law enforcement agencies around the world on the investigation.

The suspected gang were arrested in Bosnia and Herzegovina, Croatia, Macedonia, New Zealand, Peru, the United Kingdom, and the United States, as international computer crime cops linked the individuals with the Yahos malware.

According to the FBI, the Yahos malware threat compromised 11 million PCs worldwide, forming the Butterfly botnet, and stole computer users' credit card details, as well as bank account information, and other personal data that could lead to identity theft.

Typically, computers became infected through the oldest trick in the book - duping unsuspecting users into running an executable program that installed the malware. The malware managed to spread its impact by spreading via popular instant messaging services as well as social networks such as Facebook and MySpace.

The FBI has publicly thanked the security team at Facebook for providing assistance with the investigation, providing data that helped identify the perpetrators and - importantly - those who had been affected by the malware.

The authorities certainly should be applauded for investigating those alleged to be behind the Yahos malware and Butterfly botnet. Computer crime cases like this can often be complicated, and cover multiple jurisdictions and time zones.

Once again, it's a good reminder to all of us who use computers that we should not be dissuaded from reporting a malware attack simply because "the bad guys are probably based in a country far far away".

It would be a crying shame if the authorities were able to determine who they believed was responsible for malware or a botnet, but was unable to dig up any victims. Thankfully, with the help of Facebook, that hasn't happened on this occasion.

(By the way, don't confuse the Yahos/Butterfly botnet with the Mariposa botnet. It's an easy mistake to make as "Mariposa" is Spanish for "butterfly").

Follow @gcluley

Evil butterfly image from Shutterstock.


View the original article here

Saturday, October 20, 2012

Over 9 million PCs infected - ZeroAccess botnet uncovered

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Zero. Image from ShutterstockZeroAccess is a hugely widespread malware threat that has plagued individuals and enterprises for years. It has evolved over time to cater for new architectures and new versions of Windows.

Here at SophosLabs we have looked at previous incarnations of the ZeroAccess rootkit in depth, describing how it enslaves victim PCs, adding them to a peer-to-peer botnet which can receive commands to download further malware.

Most recently, Sophos's researchers explored how ZeroAccess took a major shift in strategy, operating entirely in user-mode memory.

Due to the continued high profile of this malware family we felt it was necessary to examine the threat in greater detail, not only the latest version of ZeroAccess, but also the ZeroAccess botnet as a whole.

SophosLabs researchers can reveal that the current version of ZeroAccess has been installed on computers over nine million times with the current number of active infected PCs numbering around one million.

Total installs of ZeroAccess

ZeroAccess uses a peer-to-peer network to download plugin files which carry out various tasks designed to generate revenue for the botnet owners. Our researchers monitored this network for a period of two months to discover where in the world the peers were located and what kind of files the botnet was being instructed to download.

We found the IP addresses of infected machines from a total of 198 countries ranging from the tiny island nation of Kiribati to the Himalayan Kingdom of Bhutan, as can be seen when the infected machines are plotted on a world map:

Infected computers plotted on a world map

The largest numbers of infected computers were found in the USA, Canada and Western Europe:

Infected machines around the world

Our research has discovered that the ZeroAccess botnet is currently being used for two main purposes: Click fraud and Bitcoin mining.

If running at maximum capacity the ZeroAccess botnet is capable of making a staggering amount of money: in excess of $100,000 a day.

We have also reverse-engineered the mechanisms by which the ZeroAccess owners keep tabs on the botnet, and discovered an array of techniques used that are designed to bury the call-home network communications in legitimate-seeming traffic.

You can find out much more about ZeroAccess in our new technical paper - "The ZeroAccess Botnet - Mining and fraud for massive financial gain".

Follow @SophosLabs

Snake in the shape of a zero image from Shutterstock.


View the original article here

Wednesday, July 25, 2012

Android botnet wants to sell you Viagra, penny stocks and e-cards

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Malware, Mobile, Spam

Android pill pusherThe plot of the Android malware story thickens. SophosLabs has discovered the latest way to monetize mobile malware, using it as a spam botnet.

Historically mobile malware has made money from capturing SMS messages used for online banking authentication and sending premium-rate SMS messages to collect the subscription fees.

The messages appear to originate from compromised Google Android smartphones or tablets. All of the samples at SophosLabs have been sent through Yahoo!'s free mail service and contain correct headers and DKIM signatures.

The first samples we analyzed were text only, but some other samples also contain images. An example pharmacy spam reads:

Incredible National Rx Store
Now offering medications for Weight Loss, Diabetics, Pain Reduction!!!
Reduced Prescription's
Viagra+Cialis Super Active, Alprazolam, Vicodin etc...
Pick Up You're Meds for 75% Off Today

Sent from Yahoo! Mail on Android

Some of the image spams not only have a graphic, but an animated one!

Android spam with animated pharma GIF

You can imagine the cellular phone bill you might receive if your phone is being used to download and spam out thousands of these messages.

Even if you thought you were going to buy some counterfeit Viagra from criminals because you are too embarrassed to see your physician, it is still a classic bait and switch. The URL leads to a knock-off "herbal Viagra" the performs miracles with no side effects.

It is likely that Android users are downloading Trojanized pirated copies of paid Android applications. The samples we analyzed originated in Argentina, Ukraine, Pakistan, Jordan and Russia.

The widespread nature of source devices is unusual as most Android malware is not downloaded from Google Play, but localized "off market" download sites.

Sophos Mobile SecurityAndroid users should exercise caution when downloading applications for their devices and definitely avoid downloading pirated programs from unofficial sources. Google, Amazon and others may not be perfect at keeping malware off of their stores, but the risk increases dramatically outside of their ecosystems.

Considering the risks, why not give Sophos Mobile Security for Android a try? It's free and also allows you to track your device if it is lost or stolen. You can find it on Google Play.

Update: It is important to note that we do not have the malware, so it is not confirmed that it originates from Android devices. For more information read our follow up with all of the details.

Special thanks to Savio Lau at SophosLabs Vancouver for spotting this spam and performing the research necessary for this post.

Follow @chetwisniewski

View the original article here