Viry a Červi

$2.07bn? That's one Dell of a deal to offload infosec biz RSA

The Register - Anti-Virus - 18 Únor, 2020 - 18:30
Texan tech giant hacks off part of security real estate, sells to consortium

Dell Technologies is flogging its infosec business RSA for $2.075bn as it tries to reduce its longstanding debt.…

Kategorie: Viry a Červi

Active Exploits Hit Vulnerable WordPress ThemeGrill Plugin - 18 Únor, 2020 - 18:27
Websites using a vulnerable version of the WordPress plugin, ThemeGrill Demo Importer, are being targeted by attackers.
Kategorie: Viry a Červi

Shipping is so insecure we could have driven off in an oil rig, says Pen Test Partners

The Register - Anti-Virus - 18 Únor, 2020 - 17:45
Not many stranger things happen at sea

Penetration testers looking at commercial shipping and oil rigs discovered a litany of security blunders and vulnerabilities – including one set that would have let them take full control of a rig at sea.…

Kategorie: Viry a Červi

Malware and HTTPS – a growing love affair

Sophos Naked Security - 18 Únor, 2020 - 14:32
HTTPS web encryption - blessing or curse? A new SophosLabs report looks at how much the crooks love TLS.

Hacker Scheme Threatens AdSense Customers with Account Suspension - 18 Únor, 2020 - 14:26
Scam threatens to flood sites using Google’s banner-ad program with bot and junk traffic if owners don’t pay $5K in bitcoin.
Kategorie: Viry a Červi

Council returns to using pen and paper after cyberattack

Sophos Naked Security - 18 Únor, 2020 - 12:44
Ten days after a suspected ransomware attack, residents of the English borough of Redcar and Cleveland must be starting to wonder when their Council’s IT systems will return.

AI filter launched to block Twitter cyberflashing

Sophos Naked Security - 18 Únor, 2020 - 12:35
A small but determined group of Twitter users think it is a good idea to direct message (DM) pictures of male genitals to complete strangers.

IOTA shuts down network temporarily to fight wallet hacker

Sophos Naked Security - 18 Únor, 2020 - 12:12
Popular cryptocurrency IOTA has temporarily shut down its entire network after a hacker stole funds from ten of its highest-value users.

Sensitive plastic surgery images exposed online

Sophos Naked Security - 18 Únor, 2020 - 12:04
Researchers at VPN advisory company vpnMentor have found yet another online data exposure caused by a misconfigured cloud database.

Lenovo, HP, Dell Peripherals Face Unpatched Firmware Bugs - 18 Únor, 2020 - 12:00
A lack of proper code-signing verification and authentication for firmware updates opens the door to information disclosure, remote code execution, denial of service and more.
Kategorie: Viry a Červi

AZORult spreads as a fake ProtonVPN installer

Kaspersky Securelist - 18 Únor, 2020 - 11:00

AZORult has its history. However, a few days ago, we discovered what appears to be one of its most unusual campaigns: abusing the ProtonVPN service and dropping malware via fake ProtonVPN installers for Windows.

Screenshot of a fake ProtonVPN website

The campaign started at the end of November 2019 when the threat actor behind it registered a new domain under the name protonvpn[.]store. The Registrar used for this campaign is from Russia.

We have found that at least one of the infection vectors is through affiliation banners networks (Malvertising).

When the victim visits a counterfeit website and downloads a fake ProtonVPN installer for Windows, they receive a copy of the Azorult botnet implant.

The Website is an HTTrack copy of the original ProtonVPN website as shown below.

Once the victim runs the implant, it collects the infected machine’s environment information and reports it to the C2, located on the same accounts[.]protonvpn[.]store server.

{ "config: ": [ "MachineID :", "EXE_PATH :", "Windows :", "Computer(Username) :", "Screen:", "Layouts:", "LocalTime:", "Zone:", "[Soft]", "Host: User-Agent: Accept: ; charset=Content-Type: HTTP/1.0POST text/*utf-8text/htmlHTTP/Proxy-AuthenticateAcceptContent-TypeContent-Lengthrealmhttp::Connection::connect: using proxy %1%http::Connection::connect: testing %1% for proxy routing" ] }

In their greed, the threat actors have designed the malware to steal cryptocurrency from locally available wallets (Electrum, Bitcoin, Etherium, etc.), FTP logins and passwords from FileZilla, email credentials, information from locally installed browsers (including cookies), credentials for WinSCP, Pidgin messenger and others.

We have been able to identify a few samples associated with the campaign:

Filename MD5 hash ProtonVPN_win_v1.10.0.exe cc2477cf4d596a88b349257cba3ef356 ProtonVPN_win_v1.11.0.exe 573ff02981a5c70ae6b2594b45aa7caa ProtonVPN_win_v1.11.0.exe c961a3e3bd646ed0732e867310333978 ProtonVPN_win_v1.11.0.exe 2a98e06c3310309c58fb149a8dc7392c ProtonVPN_win_v1.11.0.exe f21c21c2fceac5118ebf088653275b4f ProtonVPN_win_v1.11.0.exe 0ae37532a7bbce03e7686eee49441c41 Unknown 974b6559a6b45067b465050e5002214b

Kaspersky products detect this threat as HEUR:Trojan-PSW.Win32.Azorult.gen

Tutanota cries 'censorship!' after secure email biz blocked – for real this time – in Russia

The Register - Anti-Virus - 17 Únor, 2020 - 19:00
Move over, there's plenty of room on Putin's naughty step

Fresh from last week's controversy with a US telco, German secure email biz Tutanota has declared today that the Russian authorities have pulled the plug on its services.…

Kategorie: Viry a Červi

Severe vuln in WordPress plugin Profile Builder would happily hand anyone the keys to your kingdom

The Register - Anti-Virus - 17 Únor, 2020 - 15:46
Remote attackers were able create their own admin accounts

A vulnerability in a popular WordPress user role plugin lets any random person create an admin-level account on targeted websites.…

Kategorie: Viry a Červi

Google pulls 500 malicious Chrome extensions after researcher tip-off

Sophos Naked Security - 17 Únor, 2020 - 13:07
Google has abruptly pulled over 500 Chrome extensions from its Web Store that researchers discovered were stealing browsing data and executing click fraud and malvertising.

Google forced to reveal anonymous reviewer’s details

Sophos Naked Security - 17 Únor, 2020 - 13:02
A court has forced Google to reveal the details of an anonymous poster who published an unpalatable review of a dentist.

Senator calls for dedicated US data protection agency

Sophos Naked Security - 17 Únor, 2020 - 12:55
The US needs a data protection agency of its own, and Kirsten Gillibrand wants to be the one that makes it happen.

Police bust alleged operator of Bitcoin mixing service Helix

Sophos Naked Security - 17 Únor, 2020 - 12:45
The Ohio man is charged with running a Bitcoin mixer to launder over $300m—now worth $3.6b—on behalf of Dark Net crooks trying to hide out.

Monday review – the hot 24 stories of the week

Sophos Naked Security - 17 Únor, 2020 - 12:13
Get yourself up to date with everything we've written in the last seven days - it's weekly roundup time.

New paper: LokiBot: dissecting the C&C panel deployments

Virus Bulletin News - 17 Únor, 2020 - 10:38
First advertised as an information stealer and keylogger when it appeared in underground forums in 2015, LokiBot has added various capabilities over the years and has affected many users worldwide. In a new paper researcher Aditya Sood analyses the URL structure of the LokiBot C&C panels and how they have evolved over time.

Read more
Kategorie: Viry a Červi

It is with a heavy heart we must inform you, once again, folks are accidentally spilling thousands of sensitive pics, records onto the internet

The Register - Anti-Virus - 17 Únor, 2020 - 08:04
Plus: Iranians accused of hacking IT service providers to get at their customers

Roundup  Everything is insecure and everything is broken, exhibits A through Z:…

Kategorie: Viry a Červi
Syndikovat obsah