Showing posts with label Malware. Show all posts
Showing posts with label Malware. Show all posts

Saturday, August 26, 2017

New Faketoken Virus Access Private Data By Copying Ridesharing Apps

New Faketoken Virus Access Private Data By Copying Ridesharing Apps

Faketoken virus steals private data
Hello everyone! This is to inform you about a Trojan Virus currently active online called "Faketoken".

Faketoken has been distributed and affected some Android devices through Ridesharing apps so you should be careful and more proactive when using such apps on your devices.

It is quite certain that Malware creators will continue creating and distributing their dangerous viruses as there is no sign of them stopping. Some of them has made thousands and millions of dollars through these malicious activities and while you can't stop them completely, you can protect your devices and always be very careful when dealing with some sensitive online activities.

How Faketoken Operates on Mobile Phones

Some Ridesharing apps have been discovered to be harboring mobile Trojan horses. These malwares steal bank data by impersonating the interfaces of these ridesharing apps.

According to Kaspersky Labs, if your ridesharing app asks you to re-enter your credit card information after you have already input it upon installation, you should proceed with caution. The malware responsible for this is known as the Faketoken Trojan, and apparently it has been around for a while now but more active and taking toll on many phones at the moment.

According to Kaspersky, the latest version of the Faketoken Trojan is called Faketoken.q. The company revealed that the malware infects phones through bulk SMS , where it prompts the user to download images. Once the user downloads the image, the Faketoken Trojan installs all its necessary parts, and begins to monitor everything done on the phone. Now, once the malware detects an app whose interface it can simulate, it overlays the app with its own screen. Then, instead of proceeding as usual, the app prompts you to enter your credit card information.

Some sensitive apps like mobile banking apps, Android Pay, the Google Play Store, and of course ridesharing apps has been infected already. However, the Virus is more popular in Russia but I am spreading this information globally as it could be unleashed to other parts of the world to cause more havoc.

Safety Tips to Prevent Faketoken Virus

Kaspersky recommends that you go to Android settings and prevent the installation of apps from unknown sources.

✔ Simply go to Settings
✔ Tap on Security
✔ Then uncheck Unknown Sources.

On a more serious note, you need to be aware of the permissions an app requests before installation, even if you download the app from a presumably safe source, like Google Play Store. Also, it would be prudent to install an antivirus app on your phone.

It is highly recommended that you read app permission and requests to know what the app can do on your phone before installing it. Some apps that requires the permission to access sms, call log, override other apps, galleries and some other sensitive information should be carefully examined before installation proceeds. So always feel free to apply this principle and you should at least minimize the chances of being attacked by this dangerous and malicious malware currently in circulation.

Thursday, August 24, 2017

Google Blocks 500 Malware-infected Android Apps From Play Store

Google Blocks 500 Malware-infected Android Apps From Play Store

Malware
Google has blocked 500 android apps from the Play Store as these apps are reportedly being used by cybercriminals to spy on users and also to infect their mobile devices with malware.

Security firm, Lookout was the one who discovered that the infected apps all had the lgexin ad SDK installed into them. This gives third parties unauthorised access to private information in users' devices. The apps themselves also managed to be downloaded over 100 million times from the Google Play Store as many of them fell into popular categories such as weather, health and fitness, travel and games.

However, it is quite possible that app developers may not be responsible for the malware infection added by hackers as this is not the first time cybercriminals have used an SDK to spread malicious codes.

Read Also:

Lookout also gave details as to why the app developers were likely unaware of the malware present in their applications.
“It is likely many app developers were not aware of the personal information that could be exfiltrated from their customers' devices as a result of embedding Igexin's ad SDK. It required deep analysis of the apps' and ad SDK's behavior by our researchers to make this discovery. Not only is the functionality not immediately obvious, it could be altered at any time on the remote server.”
In an attempt to prevent apps from being able to deliver malware to mobile devices, Google recently introduced Google Play Protect which will be built into the latest version of its mobile OS, Android O.

Lookout has informed Google of its discover and all of the affected apps have now been removed from the Play Store.

Friday, August 11, 2017

Malware Written Into DNA For The First Time

Malware Written Into DNA For The First Time

DNA
The fact that our molecular makeup can be adapted feels a little like the scientific community is playing an elaborate practical joke on us, but a team of security researchers working out of the University of Washington has gone one further and managed to hack a computer using code written into a synthesised DNA strand.

The hack was done as a call to arms to the genetic data processing community to ensure best practices, and to prompt a discussion about the regulations around DNA sequencing.
To understand how they managed to create the DNA malware, you need to know a little about genetic sequencing. Don’t worry, it's not too complicated.

DNA is built up of foundational units called nucleotides. These nucleotides are classified by the computers that can read genetic sequencing using letters such as A, C, G, and T. Once data can be processed into an order that carries meaning, you can basically order it so that it carries any message.

Similar techniques have been used to store data on DNA, but in this instance the team encoded the sequence with a piece of malware that it knew would infect the computer. This is significant because it had created the exploit it was aiming for and then reverse engineered the malware.

This does mean that in order for someone with malicious intent to actually use this technique they would have to know an exploit and then work towards it. In the paper, the team goes so far as to say: “We have no reason to believe that there have been any attacks against DNA sequencing or analysis programs.”

But this is the point of the work that security researchers do: to head off issues before they happen. Speaking to TechCrunch, professor Tadayoshi Kohno, who has a history of working on unusual attacks for embedded devices like pacemakers, had this to say:

“One of the big things we try to do in the computer security community is to avoid a situation where we say, ‘Oh shoot, adversaries are here and knocking on our door and we’re not prepared‘.”

Thursday, August 10, 2017

Russian Hacker Sentenced To 4 Years in Prison For Spreading Linux Malware

Russian Hacker Sentenced To 4 Years in Prison For Spreading Linux Malware

Hacker in Action
A Russian man accused of infecting tens of thousands of computer servers worldwide to generate millions in fraudulent payments has been imprisoned for 46 months (nearly four years) in a United States' federal prison.

41-year-old Maxim Senakh, of Velikii Novgorod, was arrested by Finnish police in August 2015 for his role in the development and maintenance of the infamous Linux botnet called Ebury that siphoned millions of dollars from victims worldwide.

Senakh was extradited to the United States in February 2016 to face charges and pleaded guilty in late March this year after admitting of creating a massive Ebury botnet and personally being profited from the scheme.

First spotted in 2011, Ebury is an SSH backdoor Trojan for Linux and Unix-style operating systems, such as FreeBSD or Solaris, which gives attackers full shell control of an infected machine remotely even if the password for affected user account is changed regularly.

Senakh and his associates used the malware to build an Ebury botnet network of thousands of compromised Linux systems, which had the capacity of sending over 35 million spam messages and redirecting more than 500,000 online visitors to exploit kits every day.

Senakh fraudulently generated millions of dollars in revenue running spam campaigns and committing advertising click frauds.

Working within a massive criminal enterprise, Maxim Senakh helped create a sophisticated infrastructure that victimized thousands of Internet users across the world," said Acting U.S. Attorney Brooker.
"As society becomes more reliant on computers, cyber criminals like Senakh pose a serious threat. This Office, along with our law enforcement partners, is committed to detecting and prosecuting cyber criminals no matter where they reside.


Ebury first came into headlines in 2011 after Donald Ryan Austin, 27, of El Portal, Florida, installed the Trojan on multiple servers owned by kernel.org and the Linux Foundation, which maintain and distribute the Linux operating system kernel.

Austin, with no connection to the Ebury criminal gang, was arrested in September last year and was charged with 4 counts of intentional transmission causing damage to a protected computer.

Senakh was facing up to a combined 30 years in prison, after pleading guilty to conspiracy to commit wire fraud as well as violate the Computer Fraud and Abuse Act.

However, a US judge on Thursday sentenced Senakh to 46 months in prison, the Department of Justice announced on Thursday. The case was investigated by the Federal Bureau of Investigation's field office in Minneapolis.

Senakh will be deported back to Russia following his release from the U.S. prison

Sunday, July 9, 2017

Beware: CopyCat Malware Infects 14M Android Devices

Beware: CopyCat Malware Infects 14M Android Devices

There is a new dangerous Android malware in circulation right now called CopyCat and it has reportedly infected over 14 million devices globally.

At the moment, 280,000 Android devices has been affected by CopyCat in the US alone.

Though Google has been tracking the malware since 2015 and the company has updated PlayProtect to block CopyCat. However, millions of devices are still getting attacked via third-party app downloads and phishing attacks.

HOW COPYCAT MALWARE WORKS

The CopyCat virus pretends to be a popular app to confuse you and once it is downloaded on your phone, the app collects data about the infected device and downloads rootkits to ease root the phone, essentially eliminating the security system.

Then, CopyCat downloads fake apps, as well as taking control of the device’s
Zygote , (launcher for every app on your phone). Immediately the malware has control of the Zygote, your phone is in its total control and it knows every app you download, as well as every app you open. After that, the malware can now be able to replace the
Referral ID on your apps with its own, which redirects ad revenue to the hackers instead of to your app’s creators. So far, CopyCat has helped hackers make over $1.5 million.

HOW TO BE SAFE

✔ It's advisable to use an updated Android phone with new OS version especially if it's your main phone for carrying out sensitive transactions and works.
✔ Also, you should endeavor to always install apps from Playstore or trusted sites.
✔ Be very careful when collecting apps from your friend's phones or via laptops
✔ Ensure your memory card isn't used on another person's phone or laptop. Alternatively, make sure you format an SD card before using on your phone.
✔ Be careful when installing apps shared on social media like whatsapp and telegram.

Don't fall a victim. Stay safe!!!