Google Search

Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Thursday, June 12, 2014

Mobile malware, Gameover, CryptoLocker, and SSL/TLS holes - 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

• How long has mobile malware been around?

• Is it really game over for Gameover and CryptoLocker?

• Which cryptographic security libraries need patching?

Find all the answers in this week's 60 Sec Security - 07 June 2014.

? Can't view the video on this page? Watch directly from YouTube.

Follow @duckblog

Tags: 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, Android, cabir, caribe, cryptolocker, doj, FBI, gameover, gnutls, heartbleed, Mobile, openssl, Patch, ransomware, rce, simplelocker, Symbian, takedown


View the original article here

Thursday, June 5, 2014

Computer security: Reducing risks of malware infections

Installing computer security software, updating applications regularly and making sure not to open emails from unknown senders are just a few examples of ways to reduce the risk of infection by malicious software, or "malware." However, even the most security-conscious users are open to attack through unknown vulnerabilities, and even the best security mechanisms can be circumvented as a result of poor user choices.

"The reality is that successful malware attacks depend on both technological and human factors," says Professor Jos? Fernandez. "Although there has been significant research on the technical aspects, there has been much less on human behaviour and how it affects malware and defence measures. As a result, no one at the present time can really say how important these factors are. For example, are users who are older and less computer-savvy more open to infection?" It is therefore necessary to take a closer look at the impact that both technological and human factors have on the success or failure of protective mechanisms.

To answer this type of question, Prof. Fernandez and his team drew inspiration from the clinical trial method to design the first-ever study applied to computer security. In a fashion similar to medical studies that evaluate the effectiveness of a particular treatment, their experiment was aimed at assessing the performance of anti-virus software and the likelihood that participants' computers would become infected with malware. The four-month study involved 50 subjects who agreed to use laptops that were instrumented to monitor possible infections and gather data on user behaviour. "Analyzing the data allowed us not only to identify which users were most at risk, based on their characteristics and behaviour, but also to measure the effectiveness of various protective measures," says Polytechnique student Fanny Lalonde L?vesque, who is writing her master's thesis on this project.

This pilot study provided some very interesting results on the effectiveness of computer defences and the risk factors for infection. For example, 38% of the users' computers were exposed to malware and 20% were infected, despite the fact that they were all protected by the same anti-virus product, which was updated regularly. With regard to the users themselves, there did not seem to be any significant difference in exposure rates between men and women. In addition, the most technically sophisticated users turned out to be the group most at risk… This result may seem counter-intuitive, as it contradicts the opinion of some computer experts who argue that people should have a kind of "Internet license" before going online. "The results of this study provide some intriguing insights. Are these 'expert' users at higher risk because of a false sense of security, or because they are naturally curious and therefore more risk-tolerant? Further research is needed to understand the causes of this phenomenon, so that we can better educate and raise awareness among users," says Professor Fernandez. In the future, this type of study will help provide scientific data to support decision-making on security management, education, regulation and even computer security insurance. A second phase, which will involve hundreds of users over a period of several months, is already being prepared.

The initial results of this experiment were presented at the ACM Conference on Computer and Communications Security (CCS), which took place November in 2013 in Berlin, Germany.


View the original article here

Wednesday, May 28, 2014

New technique targets C code to spot, contain malware attacks

Researchers from North Carolina State University have developed a new tool to detect and contain malware that attempts root exploits in Android devices. The tool improves on previous techniques by targeting code written in the C programming language -- which is often used to create root exploit malware, whereas the bulk of Android applications are written in Java.

Root exploits take over the system administration functions of an operating system, such as Android. A successful Android root exploit effectively gives hackers unfettered control of a user's smartphone.

The new security tool is called Practical Root Exploit Containment (PREC). It refines an existing technique called anomaly detection, which compares the behavior of a downloaded smartphone application (or app), such as Angry Birds, with a database of how the application should be expected to behave.

When deviations from normal behavior are detected, PREC analyzes them to determine if they are malware or harmless "false positives." If PREC determines that an app is attempting root exploit, it effectively contains the malicious code and prevents it from being executed.

"Anomaly detection isn't new, and it has a problematic history of reporting a lot of false positives," says Dr. Will Enck, an assistant professor of computer science at NC State and co-author of a paper on the work. "What sets our approach apart is that we are focusing solely on C code, which is what most -- if not all -- Android root exploits are written in."

"Taking this approach has significantly driven down the number of false positives," says Dr. Helen Gu, an associate professor of computer science at NC State and co-author of the paper. "This reduces disturbances for users and makes anomaly detection more practical."

The researchers are hoping to work with app vendors, such as Google Play, to establish a database of normal app behavior.

Most app vendors screen their products for malware, but malware programmers have developed techniques for avoiding detection -- hiding the malware until users have downloaded the app and run it on their smartphones.

The NC State research team wants to take advantage of established vendor screening efforts to create a database of each app's normal behavior. This could be done by having vendors incorporate PREC software into their app assessment processes. The software would take the app behavior data and create an external database, but would not otherwise affect the screening process.

"We have already implemented the PREC system and tested it on real Android devices," Gu says. "We are now looking for industry partners to deploy PREC, so that we can protect Android users from root exploits."

The paper, "PREC: Practical Root Exploit Containment for Android Devices," will be presented at the Fourth ACM Conference on Data and Application Security and Privacy being held March 3-5 in San Antonio, Texas. Lead author of the paper is former NC State graduate student Tsung-Hsuan Ho. The paper was co-authored by Daniel Dean, a Ph.D. student in Gu's lab at NC State.

The work was supported by the National Security Agency; U.S. Army Research Office grant W911NF-10-1-0273; National Science Foundation grants CNS-1149445, CNS-1253346, and CNS-1222680; IBM Faculty Awards and Google Research Awards.

Cite This Page:

North Carolina State University. "New technique targets C code to spot, contain malware attacks." ScienceDaily. ScienceDaily, 4 March 2014. .North Carolina State University. (2014, March 4). New technique targets C code to spot, contain malware attacks. ScienceDaily. Retrieved May 5, 2014 from www.sciencedaily.com/releases/2014/03/140304141856.htmNorth Carolina State University. "New technique targets C code to spot, contain malware attacks." ScienceDaily. www.sciencedaily.com/releases/2014/03/140304141856.htm (accessed May 5, 2014).

View the original article here

Monday, April 28, 2014

SSCC 144 – iOS malware, fingerprint security, WhatsApp privacy, hacking the taxman [PODCAST]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Apple, Data loss, Featured, iOS, Law & order, Malware, Podcast, Privacy, Security threats, Social networks, Vulnerability

News, opinion, advice and research!

Here's our latest security podcast, featuring Sophos experts and Naked Security writers Chester Wisniewski and Paul Ducklin.

(Audio player above not working for you? Download to listen offline, or listen on Soundcloud.)

Follow @NakedSecurity

Follow @duckblog

Tags: "Canada Revenue", "Galaxy 5S", baby panda, chester wisniewski, chet chat, cra, data breach, data leakage, Galaxy, heartbleed, ios, krebs, LaCie, Malware, Paul Ducklin, Samsung, sophos security chet chat, sscc, unflod, WhatsApp


View the original article here

Thursday, December 26, 2013

Infecting iOS, OpenX backdoor, toilet hole, Android malware - 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Are Apple's iPhones really impervious to malware attack? What do you do if your software ends up pre-infected with a backdoor? What strength of password is appropriate for a toilet? And when will we get firmware updates for the Android code verification holes?

Watch this week's 60 Second Security and find out more!

? Can't view the video on this page? Watch directly from YouTube. Can't hear the audio? Click on the Captions icon for closed captions.

(If you enjoyed this video, you'll find plenty more on the SophosLabs YouTube channel.)

http://twitter.com/duckblog

Tags: 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, ad server, Android, Apple, Backdoor, bluetooth, ios, iPad, iPhone, lixil, Malware, master key, OpenX, PHP, toilet


View the original article here

Sunday, December 15, 2013

Malware alert while seeking child abuse images at work earns US man 5 years in jail

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Hands on computer. Image courtesy of ShutterstockA five-year jail term has been handed to a US man found downloading and watching child abuse imagery at work.

Investigators at the Seattle branch of the Social Security Administration where he worked were apparently alerted to his activities when his company computer was hit by a malware attack.

Thomas J. Barrett, 50, of Lynnwood, WA, seems to have been seriously addicted to grotesque photos and videos of underage girls being assaulted, with over 3,700 items found on his system.

In between browsing for fresh material for his collection, he also researched possible penalties for such activities, and alternated between porn and work time to keep his habits from his colleagues, indicating at least some awareness of just how wrong his behaviour was.

On one of his trawls through the seedier side of the web, a malware alert brought administrators' attention to what was going on, and subsequent investigations included setting up a spy camera monitoring his workstation.

The investigators were then exposed to the unedifying sight of Barrett "fondling himself" at his desk. He was arrested in January, but remains free on bail until his sentence comes into force.

Barrett's defense team claimed his time in the US Army sparked his addiction, with a visit to Europe opening an "evil door" in his delicate mind.

This is the second time in as many weeks that we've reported on malware playing a significant part in bringing paedophiles to book.

Before anyone gets the wrong idea, there's nothing noble about being a malware author or purveyor; it's still a nasty and criminal business, just perhaps not quite as nasty as these chaps.

Follow @VirusBtn

Follow @NakedSecurity

Image of man surfing web courtesy of Shutterstock.


View the original article here

Saturday, November 23, 2013

Opera breached, has code cert stolen, possibly spreads malware - advice on what to do

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Featured, Malware

Norwegian-based Opera, makers of one of the most popular browsers outside the Big Four, has announced a scary-sounding network intrusion.

The official story is still somewhat unclear.

But here are the relevant paragraphs from Opera's official mea culpa document:

On June 19th we uncovered, halted and contained a targeted attack on our internal network infrastructure. Our systems have been cleaned and there is no evidence of any user data being compromised. We are working with the relevant authorities to investigate its source and any potential further extent. We will let you know if there are any developments.

The current evidence suggests a limited impact. The attackers were able to obtain at least one old and expired Opera code signing certificate, which they have used to sign some malware. This has allowed them to distribute malicious software which incorrectly appears to have been published by Opera Software, or appears to be the Opera browser.

It is possible that a few thousand Windows users, who were using Opera between 01.00 and 01.36 UTC on June 19th, may automatically have received and installed the malicious software. To be on the safe side, we will roll out a new version of Opera which will use a new code signing certificate.

The title of the article is Security breach stopped, but that doesn't sound quite right to me.

The conclusions I reached, based on the announcement above, were:

The network was breached.A code-signing key was stolen.Malware has been signed with it and circulated.At least one infected file was posted on an Opera server.That file may have been downloaded and installed by Opera itself.Cleanup and remediation has now been done at Opera.

That sounds a bit more like Security breach not stopped to me.

How else could a signed-and-infected file have been automatically downloaded by an already-installed instance of Opera?

Anyway, wouldn't Opera's auto-update have failed or produced a warning due to the expired certificate?

Until Opera has worked out the answer to these questions, Opera users probably want to assume the worst.

The good news is that the malware involved is widely detected by anti-virus tools, and the period of possible exposure via Opera itself was at most 36 minutes.

? According to Opera, Sophos products block the offending file as Mal/Zbot-FG.

So, if you are an Opera for Windows user:

Download a fresh copy of the latest version (since the buggy download appears to be a thing of the past).Make sure your anti-virus is up to date.If you can spare the time, do an on-demand ("scan now") check of your computer.

If we find out more detail about whether malware was distributed by existing Opera installations or not, we'll let you know.

Sophos can help with an emergency cleanup of your Windows PC.

You can use the standalone Sophos Virus Removal Tool to detect and clean malware. This tool can be used alongside your existing anti-virus. (Free download, no registration required.)

You can download a fully-functioning evaluation version of Sophos EndUser Protection for Windows and use it for malware detection, prevention and clean-up. (Free download, registration required.)

Or you can use the Sophos Bootable Anti-Virus utility. SBAV requires you to download a Windows program to create and then use a bootable CD or USB key, so some technical expertise is recommended. The advantage of SBAV is that it is immune to malware already on your PC, as it runs from a self-contained Linux-based operating system. (Free download, no registration required.)

Follow @duckblog


View the original article here

Friday, November 22, 2013

Google adds (some) malware and phishing info to Transparency Report

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

World wide web. Image courtesy of ShutterstockGoogle has expanded its Transparency Report data to include stats from their 'Safe Browsing' system, which keeps tabs on where malware and phishing sites are hosted.

The data is a little short on definition, but it does give some interesting insights into which hosting providers are doing the worst job of keeping their IP space clean.

The twice-yearly Transparency Report has traditionally covered more politically-sensitive topics - which countries are blocking access to Google services, and who's been asking Google to provide data on their users (or "product"), or to take stuff down that might be found offensive for some reason, or in breach of copyright.

Some of this stuff is interesting in itself, not least when it very nearly names-and-shames dodgy political and judicial figures trying to abuse their authority and silence their critics.

There's also quite a big question mark hanging over just how "transparent" it all is, in the light of the whole PRISM brouhaha.

For the most part it seems fairly detailed and fine-grained though, or at least gives the impression of trying to be, as far as "the man" will let them, with some of the data even provided as spreadsheets for proper looking at by proper science-y types.

The new data is based on the Safe Browsing programme, which combines scanning by Google and reports from the wider web world to keep tabs on where the bad stuff is at; browsers use the data to filter search results, to protect their users from potential malware and phishing.

It's a little less detailed; much of it consists of little graphs showing trends of malware and phishing spotted over time. Some is rather hard to find much value in, data for related topics covering wildly different time periods and thus hard to compare.

Some of the graphs seem more useful, but may not be; an apparently clear, if somewhat loose, correlation between the number of malware sites and phishing sites picked up at any given time may imply a definite link between the two activities, but could also simply be showing how hard the Google scanning crew were working that week.

The one graph which does seem clear is the contrast between "attack" and "compromised" sites - i.e., sites deliberately set up to get you, versus legitimate sites that have been taken over by the bad guys. The graph shows actual attack sites on the increase recently, but still barely registering - it seems the compromised sites outnumber them massively, and always have.

Again, there is, of course, room for some sampling bias here - it's quite possible that the attack sites are better at hiding from Google, and of course they have no legit owners or admins to spot the compromise and report it.

Some numbers are available for these graphs, but they require some mouse skills to hover over the exact spot you're interested in.

The real detail is on the "Malware Dashboard" page though. This breaks down the sites recorded by the Safe Browsing scheme by Autonomous System (AS - basically an ISP or other large-ish body responsible for a subsection of the internet).

Google malware dashboard

It provides a rather undramatic world map highlighting which geographic regions are especially malware-ridden (nowhere's that much worse than anywhere else, it turns out), but then also breaks down the data by AS, including details of how many threats have been spotted in each.

The clear leader recently, using the default three-month view, is one called "Webair Internet Development", a US-based ISP on which Google has found 43% of sites checked have been malicious.

Looking at a sample of the domains they host seems to confirm some old stereotypes - it seems to be remarkably popular with gambling, pharmacy and porn sites, with domain names like "top3casino", "247-pharmacy" and "seemyass" jumping out of the list.

This impression is reversed by checking into the next two in the list though, American Access Integrated Technologies and Spain's True Records; both are listed as hosting 40% bad sites, but both are apparently hosting a random selection of legit-sounding domains (although, of course, there seems to be a fair amount of porn in both).

Again we come back to sampling error though.

The Webair listing says 43%, but as you may have spotted, that's 43% of sites checked. In the period covered, Google has only actually looked at 2% of the sites hosted there. So, it all comes down to how good the Safe Browsing team are at deciding which sites to check.

If they're super hot and have pinpointed all the bad stuff in the whole AS with just a few misses, we've got 43% of 2%, aka 0.86% - not such bad guys after all.

On the other hand, if they're really terrible and have foolishly started their scanning with the handful of clean sites on a seriously malware-riddled section, it could be as high as 98.86% danger.

That's the problem with stats, really - and we're not even considering whether the results of the Safe Browsing checks could be in error.

Looking at the longer term, by turning the dial up to the maximum 1 year, the top five are all in the 80s and 90s, apart from number 1 which, rather intriguingly, is listed as "unknown" - they know it's the biggest, but can't say why.

All this top five also list the % of the total AS scanned as "unknown". Not much for those real science-y people to play with here unfortunately.

So what's the use of it all?

Well, the actual data on whether or not your site is listed is made available to site admins, which is helpful, but there's nothing new here. The main value of this new regular report, it would seem, is to highlight potentially dodgy providers.

So, if you're running a website and your provider comes high up in one of these lists, get in touch with them. Ask them, hey, what's up, are you some sort of haven for crooks, or just incompetent?

If they really are dirty, you might just get them to clean up their act. If not, you'll at least be helping keep them on their toes.

And if you've somehow got your mum's flower arranging club website registered with a Russian 'bulletproof' provider, then maybe this should give you fair warning it's time to move it on.

Follow @VirusBtn
Follow @NakedSecurity

Images of world wide web courtesy of Shutterstock.


View the original article here

Tuesday, October 8, 2013

Android malware in pictures - a blow-by-blow account of mobile scareware

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Thanks to Nagy Ferenc László of SophosLabs for the
behind-the-scenes work that he put into this article.

Fake anti-virus, also suggestively known as scareware, tricks you into paying money by pretending to find threats such as viruses and Trojans on your computer.

The scan to find the "threats" is free; the cleanup part is not.

If you do pay up, the software then pretends to remove the non-existent threats so you may not even realise that you've been scammed, on the principle that all's well that ends well.

But not only are you out of pocket, typically between $40 and $100, you're also led into a false sense of security, because the clean bill of health provided after you've paid is as bogus as the infection report at the start.

This sort of scam is most common on Windows, with OS X a long way back in second place. But other operating systems aren't exempt from the depredations of cybercriminals.

SophosLabs recently acquired an Android scareware sample going by the entirely hokum name of Android Defender. It's not particularly polished, and it crashed quite a bit as we played with it, but it does show that the scammers have an active interest in the Android ecosystem.

I thought I'd give you a guided tour of what it looks like. That way, you'll have some pointers that I hope will help you determine real from fake security software in future.

I started by creating a fresh Android 4.2.2 emulator image and firing it up.

Then I installed the malicious APK (Android Package file). In real life, you might be encouraged to download it from a handy website; I just used the Android Debug Bridge (adb) to inject it from my research computer into the emulated image.

You can see the application icon at top left, since its name conveniently starts with 'A'.

I launched it to see what would happen. It advised me that my device "is at risk of being infected," which is an understatement: my device is already infected, because Android Defender is on it.

I'm invited to buy, but there's no serious pressure yet.

The inital scan quickly suggests I have a problem.

Two viruses, one Trojan and a Malware, to be precise.

You might be inclined to believe this report, since the "threats" found are Android malware names you might have heard of.

But it's all smoke and mirrors. You don't have to be a Java coder, or even a programmer at all, to spot in the source code below that the app is using the Math.random() function to build up a list of virus names to report later.

The malware names are field-updatable, stored in Russian and in English in an XML data file that is part of the malware's APK file.

This is about as close to "malware identities" (also known as signatures, patterns or definitions) as you will find in the app.

There isn't anything to help the product actually locate viruses in infected files. There's just a list of names: when you're choosing randomly even on uninfected devices, recognition patterns just aren't needed.

Most of the viruses on the list are existing Android malware names, in order to add a ring of verisimilitude. But somehow the Windows-only virus Conficker managed to get in there.

The pressure on me to register the product is increasing, because it's now time to think about cleaning up the malware.

So I gave it my best shot, and tried to "activate" the software.

The buy page wasn't working, so I can't tell you how much the scammers intended to charge.

But it didn't matter, because I had an activation code up my sleeve from the source code itself.

We saw this happy-go-lucky attitude to activation in early Mac scareware.

Was the activation system this simplistic for experimental convenience, or is it just a prototyper's indolence? We shall probably never know.

The product crashed after I clicked the Activate button, but when I started it up again, I found that the activation had worked and my device was "fully protected."

The next system scan is no longer a scary red but a go-ahead green.

Better still, the app is pretending to have "eliminated" the malware it "detected" earlier.

In fact, the software builds a small sqlite database in which it remembers what viruses it has "found", and whether it has fraudulently "cleaned" them, so it will be consistent in its dishonesty.

There's a half-hearted privacy manager tool built in to the app, presumably because that's the sort of feature that other Android security products provide.

And there's an update page, though the crooks forgot to translate that part properly.

The update pretends to work, even listing signature files it supposedly downloaded from the internet.

(In my case, it couldn't have downloaded anything from outside - I tested in with my device in Airplane Mode, which inhibits all outbound connections. That cuts you off in the emulator, just as it would on a real device.)

Updates are only simulated once a day, in order to appear more realistic.

The app pretends that its pattern database has increased in size every time you update. Once again, the Java pseudorandom number generator is used behind the scenes.

I don't imagine you installed this progam, but if you did, you need to remove it right away.

And you couldn't have installed it without first telling your device that you wanted the freedom to go looking for software outside Google's own official Play Store.

I'd suggest, if you did so (since it ended badly enough for you to get this malware!) that you turn "Unknown sources" off once again.

And you might want to consider installing a proper Android security tool in which the detection and the cleanup are free.

Sophos Security and Antivirus is available from the Play Store, so you don't need to enable "Unknown sources" to install it.

And yes, it does actually look for threats before it reports them.

If it finds a threat, there aren't any demands. Just a warning and an instant "Uninstall" button.

In the words of many a Naked Security video and podcast, thanks for listening, and until next time, stay secure!

Follow @duckblog


View the original article here

Saturday, October 5, 2013

Android malware, Liberty Reserve, CSAW, Legal ransomware - 60 Sec Security [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Watch our 60 Second Security videos and arm yourself with anecdotes you can use when your friends or colleagues ask you, "Do I really need to worry about things like privacy and security?"

Here you go: the latest security stories in just 60 seconds.

In this episode:

(If you enjoyed this video, you'll find plenty more on the SophosLabs YouTube channel.)

http://twitter.com/duckblog

Tags: 60 Sec Security, 60 Second Security, 60 Seconds, 60SS, Android, cloud, CSAW, Fake anti-virus, Liberty Reserve, Money Laundering, piracy, ransomware, scareware


View the original article here

Friday, September 20, 2013

Inside the "PlugX" malware with SophosLabs - a fascinating journey into a malware factory...

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Featured, Malware

Join SophosLabs Principal Researcher Gabor Szappanos (Szappi) as he takes you on a fascinating journey into the PlugX malware factory.

This is a malware family that keeps evolving as the criminals in charge of it churn out new variants.

Just like legitimate software, malware has major version upgrades and point releases.

In this paper, Szappi looks at the recently-released Version 6.0 of the PlugX malware framework.

You'll enjoy Szappi's paper because it's not so technical as to get bogged down in researcher-only jargon, yet not so high-level as to skip over the details that help you to understand how virus writers think.

Szappi writes clearly and logically, taking apart and explaining the numerous and deliberately-distinct phases in the malware's infection mechanism.

Splitting up malware means that each step does only a small piece of the overall work, in order to avoid looking suspicious on its own.

The aim is to reduce the chance of being flagged as dangerous by heuristic defences that expect more complex behaviour.

Szappi even uses some debugging features left behind in the malware to estimate the size of the programming project behind it, using a statistical technique first used in anger during the Second World War.

The Allies used it to convert observations from the field into reliable estimates of how many tanks the Nazis had at their disposal; now it's turned against the PlugX crew.

And Szappi describes how, and why, the malware carries around with it a pirated copy of a legitimate, digitally-signed application (this one is from Chinese social media outfit Tencent) to help it do its dirty work.

A fascinating paper, well worth reading: clearly written, interesting, and informative.

Download now

Follow @duckblog


View the original article here

Thursday, August 29, 2013

US Department of Labor website hacked, serves malware, now fixed

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

You may have read about the US Department of Labor "getting hacked".

It's true, but fortunately the story is not quite as gory as it sounds in those two fateful words.

A subdomain of the Department's main website, running off a separate server - what's known colloquially as a microsite - was modified to serve up malware.

There's a sort of double irony here, because news about the breach broke on May Day, which is Labour Day in much of the world, though not in the United States, where it is celebrated in September.

The affected microsite was www.sem.dol.gov, which is currently (2013-05-02T10:22Z) offline.

SEM stands for Site Exposure Matrices, but the "site" in the name refers not to websites but to worksites.

The SEM "is a repository of information on toxic substances present at Department of Energy sites and other locations where radiation exposure is a possible hazard.

We've already seen speculation that the radiation-related nature of the SEM site tells us that this is a targeted attack, and certainly the site is not one you would expect to draw a lot of traffic.

On the other hand, of course, it might just be that the site was attacked because it was vulnerable while other parts of the Department of Labor site were not.

? Many organisations use microsites for special purposes, such as conducting one-off marketing campaigns or, as in this case, for presenting specialised data. Often, this is to avoid bothering the IT team with change requests for the main website, or in order to try something new. If you use microsites this way, make sure you don't take any security shortcuts while you are "innovating".

The attack used a malicious JavaScript file to get your browser to download a file called bookmark.png.

This sounds like an image file, but is in fact a Windows program with the first byte altered so that it can't run by itself.

In theory, your browser shouldn't do anything more than simply, and harmlessly, download the offending file.

But the malicious JavaScript then uses the function called helo() in the script above in an effort to trigger the CVE-2012-4792 remote code execution vulnerability in Internet Explorer.

The attackers hope that this will trick your browser into jumping over its security checks to modify and run the downloaded malware program without asking you.

The exploit seems to have borrowed both code and concept from a publicly-available Metasploit module that gives more detail (perhaps a little too much for some readers' comfort) about this exploit.

The good news is that if you've patched Windows recently, or if you are using Internet Explorer 9 or 10, you should be safe, since the vulnerability will be fixed, the exploit won't work and the non-functional bookmark.png file will do you no harm.

? Sophos security products block the drive-by-download exploit script as Troj/ExpJS-IT and the "payload" executable as Troj/Agent-ABOB.

The attack also uses a malicious script file that includes what are known as anti-anti-virus techniques.

This means that the attacker actively attempts to evade detection by interfering with the operation of one or more of the anti-virus tools you may be running.

If you're using BitDefender, the script even tries to connect to the local web console to reconfigure the product on your behalf.

? Sophos security products block this malicious script as Troj/ExpJS-IV.

To summarise:

A patched version of Windows should be immune to the exploit used in this attack.Internet Explorer later than version 8 should be immune.The hacked site is off the air and unlikely to reappear until it is clean and safe.An up-to-date anti-virus ought to block the malicious files, even on an unpatched computer.

Oh, and one more thing.

If you use microsites for special-purpose content, take care to avoid introducing special purpose risks at the same time!

Follow @duckblog


View the original article here

Saturday, August 17, 2013

The Redkit malware exploit gang has a message for security blogger Brian Krebs

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Brian Krebs Brian Krebs

Award-winning security blogger Brian Krebs is loved by everyone on the internet... apart from the criminals.

The fact that Krebs has shut down spam operations, helped dismantle botnets, given the notorious Russian Business Network more than the odd headache, has made him plenty of enemies in the internet underground.

Just last month, online crooks launched a DDoS (distributed denial-of-service) attack against Krebs's blog, and sent an armed SWAT team around to his house.

So, I was interested to hear from SophosLabs researcher Fraser Howard what he had uncovered inside the latest version of the Redkit exploit kit what appeared to be a message for Brian Krebs.

Message for Brian Krebs

Crebs, its your fault

What's that famous quote?

"Say anything you want about me as long as you spell my name right!".

In this particular case, the Redkit gang were struck by a double attack of both poor spelling and lousy grammar - but I doubt tireless cybercrime reporter Krebs will lose much sleep over it.

Sophos products are proactively detecting the redirects which point to the exploit site as Troj/JSRedir-R and Troj/Iframe-JG.

The landing page of the exploit kit is detected as Troj/ExpJS-II, and Sophos proactively protects against the Java vulnerability (CVE=2012-4681) that this version of Redkit tries to exploit as Exp/20124681-C.

http://twitter.com/gcluley

Thanks to SophosLabs Principal Researcher Fraser Howard for alerting me to this message.


View the original article here

Wednesday, July 31, 2013

Mac malware found in malformed Word documents - is China to blame?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Our friends at F-Secure have blogged today about a boobytrapped Word document, that appears to be designed to infect computer systems running Mac OS X.

The malicious Word file, examined by the experts in SophosLabs, claims to be about the "6th International Uyghur Women's Seminar & 1st World Uyghur Women's Congress", run by the International Uyghur Human Rights & Democracy Foundation.

Boobytrapped Word file

Vulnerabilities, exploited in malformed Word documents, install malicious code onto the recipients' computer and a legitimate-seeming Word file with content relevant to the victim is displayed as a smoke screen.

It's clear that the attack is targeted against Uyghur Mac users, and we have seen similar attacks in the past.

Sophos products detect the malware as OSX/Agent-AADL and Troj/DocOSXDr-B.

The obvious question people are likely to ask is... are China to blame for this attack? After all, we have seen several attacks in the past which have targeted minority groups in the country.

There's no 100% proof connecting this attack with the-powers-that-be in Beijing, but you would be a brave man to bet against it.

All Mac users need to keep in mind that its important that all computers, regardless of operating system, are properly secured - and to be on their guard against attacks.

Whether it's likely that you aren't in China's good books or not, there are more and more cybercriminals investigating how they might infect the many Mac computers out there.

It is true that there is much less malware for OS X than there is for Windows, but that's not going to make you feel any better if you end up targeted in an attack like this.

Mac users, just like Windows users, need to ensure that they install the latest security patches and keep their software properly up-to-date.

If you're not already doing so, run anti-virus software on your Macs. If you're a home user, there really is no excuse at all as we offer a free anti-virus for Mac consumers.

Follow @gcluley

View the original article here

Sunday, July 28, 2013

Warning! Hackers are exploiting Texas explosion news to spread malware

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Once again, cybercriminals are leaping at the opportunity to take advantage of breaking news stories to spread malware.

The latest example, coming just days after malware authors exploited interest in the Boston Marathon bombings, concerns the fatal explosion in the small community of West, Texas, of a fertiliser plant.

Here's an example of one of the malicious emails intercepted by SophosLabs, with the subject line "CAUGHT ON CAMERA: Fertilizer Plant Explosion Near Waco, Texas".

Malicious email

Other messages have been seen using the subject line "Raw: Texas Explosion Injures Dozens".

Clicking on the link contained inside the emails takes unsuspecting computer users to a webpage that contains a series of embedded YouTube videos.

Video website designed to infect visiting computers

Harmless enough, you might think. However, the webpage also contains a 640x360 pixel iFrame, that attempts to suck in malicious content from another site, designed to infect your computer. The attack uses the Redkit exploit kit to take advantage of vulnerabilities on visiting PCs in order to infect them with malware.

The Redkit exploit kit uses a PHP shell hosted on compromised websites to run its operations.

Firstly, Redkit bounces first level redirects to the next compromised server, and then malicious content delivering PDF or JAR (Java Archive) exploits are served up from a command & control server.

Sophos protects against the attack, detecting the injected malicious iFrames as Troj/ExpJS-II and Troj/Iframe-JG.

It seems clear that whoever is behind this malware attack was also being the attempt to infect computers with malware using the disguise of a news story about the Boston bombing earlier this week.

The criminals behind this attack couldn't care less that innocent people have died in Texas and Boston. Their only interest is making money by exploiting the computers of news-hungry internet users.

Don't make life easy for malicious hackers - and always go to legitimate news outlets for breaking news rather than rely upon unsolicited emails.

Follow @gcluley

Thanks to SophosLabs researchers Paul Baccas and Fraser Howard, and Naked Security reader Nick Burns, for their assistance with this article.


View the original article here

Wednesday, May 29, 2013

NIST, US government's vulnerability database, brought down by ironic malware

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

NIST-Logo_170The US's national vulnerability database has been offline for days thanks to a multi-server infection by severely ironic malware.

Kim Halavakoski, chief security officer at Crosskey Banking Solutions, broke the news Wednesday night on his Google+ page.

Kim Halavakoski - Google+

Halavakoski said that he was trying to research vulnerability information from the National Vulnerability Database (NVD) and other websites operated by the National Institute of Standards and Technology (NIST).

Instead of results, he got what was still showing up as of Friday morning: a "Page not available" message.

Page not available

When he asked NIST what was up, a spokeswoman told him that the organization doesn't know when the database will be back up, but they're sweating bullets to get it back fast.

According to her statement, the public-facing NVD site and other NIST-hosted sites were taken offline when NIST discovered malware on two servers on Friday night.

NIST took the servers offline after a firewall picked up on suspicious activity and blocked "unusual" traffic from reaching the internet.

While investigating the malware, NIST discovered an unspecified software vulnerability.

So far, nothing vile has seeped out as a result. NIST says:

Currently there is no evidence that NVD or any other NIST public pages contained or were used to deliver malware to users of these NIST Web sites. NIST continually works to maintain the integrity of its IT infrastructure and acts to limit the impact of malware on its systems. We regret the impact this has had on our services.

An interesting note: in a subsequent post Thursday morning, Halavakoski noted that a site report shows that the day after NIST detected the malware, it switched its sites from IIS 7.5 to Linux and Apache.
Kim Halavakoski - Google +At any rate, beyond the Microsoft vs. open-source debate, the hack of a database that catalogs vulnerabilities is little short of "pure evil", to borrow Halavakoski's summation.

Those hackers really know how to hurt a security guy/girl. Good luck wiping your servers clean, NIST.

Follow @LisaVaas
Follow @NakedSecurity

Images from Kim Halavakoski


View the original article here

Tuesday, May 21, 2013

Germans bombarded in malware attack, shipment firm caught in crossfire forced to suspend email address

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

German malwareA particularly vociferous malware campaign has been forcefully spammed out in the last 24 hours, targeting German internet users.

The malicious emails, which have are intercepted by Sophos security products, contain an attachment which pretends to be a PDF file, and claim to come from an air shipment company and use the subject line "Luftfrachsendung AWB".

Here is an example of a typical email that was intercepted by the team at SophosLabs:

AWB malware

Hallo,

anbei der AWB bitte bestätigen ob alles Ok ist.

Danke

Mit freundlichen Grüßen

Attached to the emails is a file called AWB-Avis 123-12345678.pdf.zip (the numbers can vary) which carries the malicious payload.

Sophos products detect the attack as the Troj/Agent-AAJO and Troj/Agent-AANK Trojan horse.

Astrid, one of the translators here at Sophos, tells me that the German used in the emails isn't perfect (which might help raise suspicions) - but here's a rough translation for non-German speakers:

Hi,

Please confirm the enclosed AWB is OK.

Thank you

Yours sincerely

What makes the attack stand out from all of the other attacks that we have intercepted in the last few days is its sheer scale, dwarfing all the other malware attacks that SophosLabs has seen sent out via email in recent days.

The shipping company referenced in the email has posted a message on its website saying that it has had to suspend its normal info@ email address because of the sheer number of emails it is receiving, and has offered an alternative address for contact instead.

Warning

ATTENTION! Email Spam and Virus warning: Unknown parties are currently sending large quantities of spam emails with the false sender address of info@first-class-zollservice.de. The subject line reads "Airfreight shipment AWB". The email has an attachment that is infected with a Trojan!

We therefore advise that if you receive such an email, you delete it without opening. Please do not try to open the attachment!

For this reason, the info@email address has been disabled info@first-class-zollservice.de until further notice. You can contact us in the meantime, using the email address "24stunden@first-class-zollservice.de"

You have to feel some sympathy for an innocent company which has had its business disrupted by a cybercriminal scheme.

Make sure that you are reducing the risk of your computers being infected by malware in an attack like this.

As well as keeping your wits about you, and ensuring that you and your colleagues never open unsolicited attachments, always ensure that all of your computers are running up-to-date anti-virus software.

Follow @gcluley

View the original article here

Tuesday, April 23, 2013

Microsoft admits it was also hit by hackers, malware infects their Mac business unit

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Late on Friday, Microsoft published a statement on its security blog revealing that it was joining the growing list of well-known companies who had suffered at the hands of hackers.

Microsoft says that a "small number of computers", including some in the company's Mac business unit, were infected by malware.

microsoft-statement

As reported by Facebook and Apple, Microsoft can confirm that we also recently experienced a similar security intrusion.

Consistent with our security response practices, we chose not to make a statement during the initial information gathering process. During our investigation, we found a small number of computers, including some in our Mac business unit, that were infected by malicious software using techniques similar to those documented by other organizations. We have no evidence of customer data being affected and our investigation is ongoing.

This type of cyberattack is no surprise to Microsoft and other companies that must grapple with determined and persistent adversaries (see our prior analysis of emerging threat trends). We continually re-evaluate our security posture and deploy additional people, processes, and technologies as necessary to help prevent future unauthorized access to our networks.

If Microsoft is right, and the attack is similar to those which impacted the likes of Facebook and Apple, then a key part of the attack was the exploitation of a Java browser plug-in vulnerability.

Simply visiting an infected webpage with a browser which had Java enabled would be enough to silently infect computers via a drive-by download.

If we have to say it once, twice or a thousand times - we'll keep on saying it:

Because if you don't, yours might be the next company having to make any uncomfortable announcement about a security breach.

Like Facebook before it, Microsoft chose to release the news on a Friday afternoon, west coast time.

microsoft-170Although some might view the timing of the disclosure cynically, and speculate that the bad news was released just before the weekend to limit its pick-up by the press, the good news is that Microsoft says it has found no evidence that any customer data was compromised as a consequence of the attack.

Let's not forget who the real villains are in this story - it's the criminal gangs who infected legitimate websites, and spread malware designed to steal information from unsuspecting computer users.

Knowing Microsoft, I am confident that they will be sharing information with the authorities and doing everything they can to ensure that the culprits are brough to justice.

If you haven't already done so, patch your computers and consider running anti-virus software on your Macs as well as your PCs. Clearly some of the bad guys are targeting Mac OS X, knowing that many "cool" developers prefer to write their software on shiny Apple hardware as well as dull beige PCs.

Sophos has a free Mac anti-virus for home users if you want to give it a whirl.

Follow @gcluley

Microsoft image from Shutterstock.


View the original article here

Monday, April 22, 2013

BlackBerry warns of TIFF vulnerability that could allow malware to run on enterprise servers

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Blackberry Enterprise ServerIf you are responsible for administering the BlackBerry phones used by staff at your company, there's some imporant security news.

According to a BlackBerry security advisory published last week, vulnerabilities exist that could allow remote hackers to run malicious code on the BlackBerry Enterprise Server (BES) software run by many firms.

The flaw, which has been rated as "high severity", involves how BlackBerry's enterprise software handles TIFF image files on webpages, in emails, and in instant messages.

According to BlackBerry's advisory:

Vulnerabilities exist in how the BlackBerry MDS Connection Service and the BlackBerry Messaging Agent process TIFF images for rendering on the BlackBerry smartphone.

Successful exploitation of any of these vulnerabilities might allow an attacker to gain access to and execute code on the BlackBerry Enterprise Server.

Depending on the privileges available to the configured BlackBerry Enterprise Server service account, the attacker might also be able to extend access to other non-segmented parts of the network.

In short, a malicious hacker could create a boobytrapped TIFF image file and either trick a BlackBerry smartphone user into visiting a webpage carrying the image, or embed the malicious image directly into an email or instant message.

According to BlackBerry, the BlackBerry Messaging Agent flaw does not even require a user to click on a link or view an email for the attack to succeed.

The risk is that by exploiting the flaw, hackers might be able to plant malicious code on your BlackBerry Enterprise Server that opens a backdoor for remote access.

Depending on how your network infrastructure is set up - intruders might be able to see into other parts of your network and steal information.

Alternatively, the hackers' code might cause your systems to crash - perhaps interrupting communications.

It's important to underline that these are not vulnerabilities in BlackBerry smartphones themselves. Like other BlackBerry-related vulnerabilities we've seen in the past, the potential attack is against the BlackBerry Enterprise Server used by businesses.

As more and more companies are waking up to the risk of targeted attacks with the apparent intention of stealing data and spying on activities, such a vulnerability is clearly a serious concern.

The good news is that BlackBerry has not received any reports of attacks targeting its enterprise customers, but obviously it is still a very good idea for affected customers to update their software as soon as possible. The company has published workarounds for those businesses who may not be able to quickly update their installation of Blackberry Enterprise Server.

Follow @gcluley

View the original article here

Friday, April 19, 2013

More Mac malware attacking minority groups in China

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Microsoft WordOver the last year, SophosLabs, has talked about attacks against minority groups in China that use old vulnerabilities in Microsoft Office, that already have patches available for them.

We have seen several attacks in the past.

Earlier this week, the folks at AlienVault saw another attack using the same vulnerability in Office products on Mac OS X, targeting the Uyghur people of East Turkestan.

The vulnerability, known as MS09-027, was patched by Microsoft back in June 2009, and allowed remote code execution in Microsoft Word.

That means simply opening a boobytrapped Word document on an unpatched computer could run malicious code on your Mac. While you are distracted, reading the contents of a Word file, malware is being invisibly and silently installed onto your computer.

Contents of Word document

Although many Mac users might clutch onto the hope that their operating system will ask for an administrator's username and password before installing any software, you won't see any such message pop-up with an attack like this as it is a userland Trojan and you will not be prompted for administrator credentials.

This is because neither the /tmp/ nor /$HOME/Library/LaunchAgents folders on Mac OS X require root privileges. Software applications can run in userland with no difficulties, and even open up network sockets to transfer data.

Word DOC code

Sophos products detect the malicious documents as Troj/DocOSXDr-B and the dropped malware as the Mac Trojan horse OSX/Agent-AADL.

OSX/Agent-AADL obviously went through some development during this campaign because we saw three distinct versions. The first was the most interesting:

Word DOC Trojan code

In later versions of the Trojan, the function and variable names were stripped out and the shell script filenames were further hidden/obfuscated.

Once again, Mac users need to remember to not be complacent about the security of their computers. Although there is much less malware for Mac than there is for Windows, that is going to be no compensation if you happen to be targeted by an attack like this.

Mac users, just like Windows users, need to pay attention to the latest security patches and ensure that their software is kept properly up-to-date.

If you're not already doing so, run anti-virus software on your Macs. If you're a home user, there really is no excuse at all as we offer a free anti-virus for Mac consumers.

Follow @SophosLabs

View the original article here