Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Tuesday, June 20, 2017

Watch out Mac owners...Someone is offering Mac ransomware on the Dark Web!

In the wake of the WannaCry, a flawed piece of malware that spread virally that could've done much more damage than it did, it seems like everyone wants to jump on the ransomware bandwagon.

And if you're a malware developer, what better place to try your luck if not with Mac computers, where most user still believe they are safe by default and seem to have their guard down? That seems to be the thinking of an unknown cyber criminal who developed two new type of malicious software for Apple computers: MacSpy and MacRansom.

Despite some people's misguided beliefs (fueled in part by Apple's marketing) there's been plenty of Mac malware, even ransomware. But MacRansom and MacSpy show once again that bad guys are starting to target Macs more and more, even offering them as a service to others.

At the end of May, an unknown cyber criminal, or group of criminals, launched two sites offering MacSpy and MacRansom as services, meaning they marketed them as malware that they would sell and then offer support for.

BleepingComputer writer Catalin Cimpanu first spotted the sites. Some researchers, as well as security firms Fortinet and AlienVault have since then analyzed the samples of the ransomware and the spyware or backdoor.

While both pieces of malware aren't that sophisticated, they prove that more and more malicious hackers want to target Macs.

The bottom line: users should not assume that just because they're using a Mac they're inherently safe.

Source: BleepingComputer

Wednesday, January 25, 2017

Don't fall victim to the 'Free Wi-Fi' scam...Those wireless connections could be a trap.

The next time you're at an airport looking for a wireless hot spot, and you see one called "Free Wi-Fi" or a similar name, beware - you may end up being victimized by the latest hot-spot scam hitting airports across the country.

You could end up being the target of a "man in the middle" attack, in which a hacker is able to steal the information you send over the Internet, including usernames and passwords. And you could also have your files and identity stolen, end up with a spyware-infested PC and have your PC turned into a spam-spewing zombie. The attack could even leave your laptop open to hackers every time you turn it on, by allowing anyone to connect to it without your knowledge.

First, let's take a look at how the attack works. You go to an airport or other hot spot and fire up your PC, hoping to find a free hot spot. You see one that calls itself "Free Wi-Fi" or a similar name. You connect. That's it - you've been compromised!

The problem is that it's not really a hot spot. Instead, it's an ad hoc, peer-to-peer network, possibly set up as a trap by someone with a laptop nearby. You can use the Internet, because the attacker has set up his PC to let you browse the Internet via his connection. But because you're using his connection, all your traffic goes through his PC, so he can see everything you do online, including all the usernames and passwords you enter for financial and other Web sites.

In addition, because you've directly connected to the attack PC on a peer-to-peer basis, if you've set up your PC to allow file sharing, the attacker can have complete run of your PC, stealing files and data and planting malware on it.

You can't actually see any of this happening, so you'd be none the wiser. The hacker steals what he wants to or plants malware, then leaves, and you have no way of tracking him down.

All that is bad enough, but it might not be the end of the attack. Depending on how you've connected to that ad hoc network, the next time you turn on your PC, it may automatically broadcast the new "Free Wi-Fi" network ID to the world, and anyone nearby can connect to it in ad hoc peer-to-peer mode without your knowledge - and can do damage if you've allowed file sharing.

While some of these ad hoc networks advertising themselves as available for connection may be attributable to Windows behavior that the PC's user is unaware of, wireless ad hoc attacks may be more common that you think. Security company Authentium, Inc. has found dozens of ad hoc networks in Atlanta's airport, New York's LaGuardia, the West Palm Beach, FL, airport and Chicago's O'Hare. Internet users have reported finding them at LAX airport in Los Angeles.

Authentium did an in-depth survey of the ad hoc networks found at O'Hare, visiting on three different occasions. It found more than 20 ad hoc networks each time, with 80% of them advertising free Wi-Fi access. The company also found that many of the networks were displaying fake or misleading MAC addresses, a clear sign that they were bent on mischief.

"You connect to one of these networks at your own peril," says Corey O'Donnell, vice president of marketing at Authentium. "And you would have no way of tracking down how you were attacked, because you would have thought you were at an ordinary hot spot connection. Enterprises are also at risk, because if someone uses a corporate laptop to connect to one of these networks and gets infected, when he plugs back in to the enterprise network, the whole network is put at risk."

Friday, February 20, 2015

Lenovo in hot water after shipping laptops with malware pre-installed.

Computer maker Lenovo has been shipping laptops pre-packaged with malware that makes you more vulnerable to hackers - all for the sake of serving you advertisements.

Made by a company called Superfish, the software is essentially an Internet browser add-on that injects ads onto websites you visit.

Besides taking up space in your Lenovo computer, the add-on is also dangerous because it undermines basic computer security protocols.

That’s because it tampers with a widely used system of official website certificates. That makes it hard for your computer to recognize a fake bank website, for instance.

Customers started spotting this on their Lenovo computers in mid 2014.

After facing a fierce backlash by customers and computer security experts this week, Lenovo acknowledged that "user feedback was not positive." As of January, Lenovo has stopped pre-loading the software on new computers, a company spokesman said. Lenovo also promised it "will not pre-load this software in the future" and said it disabled the feature on its servers, which essentially kills the program on everyone’s computer.

Source: Yahoo Tech

Monday, January 26, 2015

SCAM ALERT: fake court notice email making its rounds.

Internet scammers are sending emails claiming to come from a real law firm called Baker & McKenzie. The email states you are scheduled  to appear in court and should click a link to view a copy of the court  notice. The email is not from Baker & McKenzie and has no connection  to the firm. It is an attempt by cyber criminals to trick you into  trying to prevent a negative consequence. If you click on the link, you download and install malware.

In the recent past there have been a series of these court appearance malware attacks that claim to be from law firms or government entities.  If you get one of these scams, do not click any links or open any  attachments, delete these emails.





Friday, October 3, 2014

JP Morgan Chase admits to a significant data breach.

Today, JP Morgan Chase revealed that information on 76 million households and 7 million businesses was stolen from their systems due to malware on an employee laptop. This is added to the Home Depot and Target breaches. Here are a few things you can do to protect your personal information...
  • Change all banking passwords
  • Do not reuse passwords amongst banks
  • Monitor all of your accounts (even those not with JP Morgan)
  • Ask for alerts:
    • Daily balance via email & text message
    • Alerts for transactions over $500 (or whatever level you desire)
    • Alerts for number of daily transactions
    • Alerts when balance falls below a certain amount
  • Use 2-factor authentication
  • Avoid using debit cards
  • Minimize online banking
Demand Chase hold it’s software and security vendors accountable for their lapses - after all, they spend millions (if not billions) of dollars on this software. We as individuals cannot force Microsoft, Adobe, Oracle, Cisco, and other software manufacturers to improve their security. It will take a large customer like JP Morgan Chase to force the software industry to deliver secure, hardened software.

Sources:
NYTimes.com
BusinessInsider.com

Tuesday, September 9, 2014

The Web's newest scam: Jennifer Lawrence nude pictures.

There is a new (true) current event which unfortunately is the ultimate click bait. A hacker got into Apple's iCloud and hacked the account of Jennifer Lawrence and many other celebrities. Apparently, she had taken nude pictures of herself and they are all out there now. You would think these celebs would have learned by now, but no. Apple has patched a bug that would allow brute force attacks on iCloud, and this may have been how the hack was done, or it could be simply a guessed password.

The cyber criminals are already working on campaigns to exploit this event and these are going to be very enticing phishing attacks over the next few months.
 

This weekend, it was all over the news that hackers leaked nude pictures of Jennifer Lawrence and other celebrities. The news is true, and the pictures are out there. The problem is that the bad guys are going to use this to trick people into clicking on links and open attachments, which will infect your computer with malware. Do not get curious and fall for these scams.

Tuesday, July 23, 2013

Do you really need antivirus software?

Do you need antivirus software on your PC? If you're not sure of the answer to that question, then the short answer is yes. The longer answer is that security software is only one piece of what should be a simple, straightforward, and systematic approach to your PC's health.

Just how dangerous is it out there? Here's what you need to know:
  • No computing environment is immune. Every platform can be exploited by an attacker. This month's Mac OS X v10.6.5 and Security Update 2010-007 included well over 100 fixes to critical security vulnerabilities, many of which could lead to arbitrary code execution. These are exactly the same types of vulnerabilities that Windows malware writers take advantage of. Fortunately for Mac (and Linux) users, their worldwide market share is small enough that malware writers simply haven't bothered with them. If you use OS X on a Mac, I don't think you need to install security software, but that recommendation could change someday if Apple's platform continues to grow in popularity and attracts enough attention from bad guys.
  • Good behavior alone is not enough to protect you from attacks. Visiting porn sites and downloading pirated software puts you at a much higher risk of infection, but even legitimate web sites can be compromised, and seemingly innocent results in a search engine can lead to hostile sites.
  • Antivirus software is one layer among several. Depending on the type of threat, it can be very helpful, even if you consider yourself an expert PC user. But it is not a magic bullet, and it is no replacement for a well-rounded approach to security.
  • No antivirus software is perfect. It is literally impossible for any security product to identify every possible threat, especially when malware writers are constantly updating their products to avoid detection. Most of the leading antivirus programs can identify and block the overwhelming majority of threats you're likely to encounter online. The fact that they can't reach 100% protection is why security software is only one part of a layered security strategy.
  • Many types of malware are installed voluntarily. Among the most common threats are Trojans, which spread via social engineering. The job of a malware writer is to convince you to run his innocent-sounding program, which secretly does something other than its stated purpose. It might claim to be a new video playback plugin but actually turns out to be a program that hides on your PC and steals passwords or sends spam. Social engineering explains how an entire class of malicious fake antivirus programs made it onto the top 10 malware list for the first half of this year.
  • Malware writers make their living exploiting unpatched systems. One of the top 10 threats found and removed from Windows PCs in the first half of this year was Win32/Conficker. The vulnerability that Conficker exploits was blocked by a Microsoft patch released in October 2008. In fact, that's true of most of the top PC malware variants found in the wild. Four of the entries on the top 10 list for 2010 are based on vulnerabilities that were identified and patched in 2007 or 2008, and none of the others could have been installed without explicit user interaction on a fully updated copy of Windows.
  • It's not just Windows that needs patching. Some of the most effective malware vectors these days are coming through vulnerabilities in products like Adobe Flash and Reader, in the Java runtime, and in Microsoft Office. In most cases, the vulnerabilities were patched quickly by the software maker, but if you didn't apply that update, you remain vulnerable. Ironically, most of these exploited programs are cross-platform; in theory, malware authors can add code to their PDF or Java exploits that target Macs or Linux PCs. So far, they haven't done that. 
  • Attacks via zero-day exploits are rare. Zero-day exploits get a lot of publicity, but they rarely have a widespread impact. The worst variants of these attacks are the ones aimed at specific companies, like the targeted wave of attacks against Adobe, Google, and other high-profile companies in early 2010. And even those only succeeded because they exploited unpatched systems using an outdated browser.
If you want your Windows PC to be secure, here are the essential steps.
  1. Use a modern operating system. Sorry, folks—Windows XP simply isn't secure enough for ordinary people to use today. It was designed more than 10 years ago, and it lacks many of the core architectural changes that make later Windows versions more resistant to attacks. Address Space Layout Randomization and Data Execution Prevention are core features that block some classes of exploits completely. File and registry virtualization (a key part of the much-maligned and misunderstood User Account Control feature) prevents hostile programs from writing to system folders. Removable drive exploits, which have represented a very common vector for spreading malware recently, do not affect Windows 7 or Windows 8.
  2. Keep your OS up to date and backed up. Turn on Windows Update and make sure it's running properly. That single step will protect you from virtually all widespread malware attacks these days. If you're worried about a buggy update hosing your system (highly unlikely, but theoretically possible) make sure you have a full image backup on hand. Every version of Windows 7 allows you to perform a full image backup to an external hard drive; if you schedule that operation for the day before Patch Tuesday every month (or better yet, for every Monday), you'll be able to recover from any kind of problem. Oh, and leave the Windows Firewall turned on unless you've replaced it with a third-party alternative.
  3. Keep applications updated also. Adobe has greatly improved its updaters in the past year. If you're prompted to update to a new version of Flash or Reader, do it. Microsoft Office updates are delivered automatically through Microsoft Update; make sure that those are being installed as well. Remove unwanted programs that could represent a security threat. Many new PCs come with Java installed automatically. If you don't use it, remove it.
  4. Be suspicious of any new software. As I noted on the previous page, malware authors count on tricking you into installing software that claims to do one thing but actually takes over your system, stealing passwords or adding your system to a worldwide botnet. If you're not sure a program is safe, don't install it.
  5. Set up standard (non-administrator) accounts for unsophisticated users. That category includes kids, parents, employees, and all of your non-geek friends and family members. With a standard account a user needs to talk to you (and convince you to enter the administrator's password) before installing any new software. That conversation is an ideal opportunity to teach your family members and employees about the warning signs of potentially dangerous programs. (This is another good reason to upgrade from Windows XP, by the way, where running with a standard account is difficult because of badly written programs that require administrator rights; both Vista and Windows 7 do a better job of allowing those programs to run without compromising the integrity of the system).
  6. Use a modern browser. If you're still using Windows XP and Internet Explorer 6, stop it. I think IE8 is a good alternative, especially when coupled with Protected Mode (a security feature in Windows Vista and Windows 7). If you prefer to avoid IE altogether, that's a great choice. As I continuously explain to all of my clients, there are several good reasons to prefer alternative browsers such as Firefox or Google Chrome to any version of Internet Explorer. For starters, both Mozilla and Google have generally been faster at releasing updates to security issues than Microsoft.
  7. Install an antivirus program and keep it up to date. There are plenty of effective programs in this category that can run with a minimum of chatter and will block the overwhelming majority of threats. I recommend ESET NOD32 Antivirus to every client.
And one final word: Don't be paranoid. Common sense and the good practices outlined above will offer excellent protection for any consumer PC and leave you free to work and play in comfort.

*As an Inc. 5000 company, ESET has been pioneering the antivirus industry for 25 years. They have received awards from Information Security Magazine, SC Magazine, VMware, and countless other recognized names in the computer industry. IES is proud to be partnered with such a highly trusted and recognized company.