Showing posts with label Virus. Show all posts
Showing posts with label Virus. Show all posts

How Hackers Use Trending Topics like "Olymics 2012" Against You



As July makes its way into August, the 2012 Summer Olympics in London will spend a couple of weeks at center stage. Much of the live action will happen as Americans are at work, and millions of fans will be following the Games online.
A recent survey by SpectorSoft Corporation of Vero Beach, Fla., a maker of computer and mobile-device monitoring and recording software, found that 40 percent of employees plan to follow the Olympics from their workplace computers. Plenty more will be checking out the results on whatever Internet-connected device they have handy.

Big events like the Olympics, presidential elections and the NCAA basketball championships are prime time for cybercriminals because of the scope of interest, drawing the attention of even people who are only casual observers of sports or politics.
But these events only happen periodically, and we know the bad guys don't take a year, or four, off. Instead, online criminals depend on current events and trending topics in order to develop the next wave of social-engineered attacks.
"In the past, we have seen [criminals] leverage the death of a celebrity or a popular event like Black Friday to send phishing emails on that topic, or use black-hat SEO [search engine optimization] techniques and even purchase keywords so their malicious site appears high on search results," explained Brendan Ziolo, VP of marketing at Kindsight, a digital-security company based in Mountain View, Calif.
"Because the user is anxious to see this news or get the latest specials," Ziolo said, "they click on the links without thinking and become infected."



ou would think that after a while, we would become a lot more immune to, or at least more aware of, social-engineered attacks, but the opposite appears to be true.
According to Ziolo and Kindsight's Q2 Malware Report, email that drives users to a malicious website, which then infects visitors with malware via a drive-by download, was the most common attack method in April, May and June of this year.
"The main infection method continues to be email messages luring victims to websites running a variety of exploit kits," Ziolo said. "The victim would typically receive an email message from a business or the government informing them of an issue with their account. This would contain a reasonable-looking link to a website.
"The website would actually host an exploit kit such as Blackhole. This would probe their system and attempt to infect it," Ziolo said.
The use of trending topics to socially engineer an attack needs be successful from the criminal's point of view.
Social-engineering tricks require a lot of time and effort, said Costin Raiu, director of global research and analysis at Kaspersky Lab in Moscow.
"What is standard at the moment is this," Raiu said. "We have automatic bots that scan sites such as Google Trends, Google News and Twitter trends, looking for the topics people like to talk about. Then the bad guys will generate Web pages on the fly on those particular topics and add exploit code into the pages."



Read more..

A new Trend of Mobile Virus effective in iOS and Android Platform



This application is called ‘Find and Call’ and can be found in both the iOS Apple App Store and Android’s Google Play. This is a Trojan that uploads a user’s phonebook to remote server. The 'replication' part is done by the server - SMS spam messages with the URL to the application are being sent from the remote server to all the contacts in the user’s address book.

If user launches this application he will be asked to register in the app using his email address and cell phone number (both fields won’t be checked for validity). If user wants to ‘find friends in a phone book’ his phone book data will be secretly (no EULA/ terms of usage/notifications) uploaded to remote server.

Both apps are also able to upload user’s GPS coordinates to the same server but such ‘feature’ is not that new for both malicious and legal apps to be honest.

So, what happens next? User will be able to continue using the application but at the same time the application steals data from the device (phone book and cell phone numbers) which are uploaded to a remote server to be used for SMS spam campaigns. Each phone book entry will receive SMS spam message offering to click on the URL and download this ‘Find and Call’ application. It is worth mentioning that the ‘from’ field contains the user’s cell phone number. In other words, people will receive an SMS spam message from a trusted source.

Small F.A.Q.
  • 1. Are these apps malicious?
  • Yes.
  • 2. Why?
  • Both apps upload user’s phone book to remote server and use it for SMS spam. That’s why we detect them as Trojan.AndroidOS.Fidall.a and Trojan.IphoneOS.Fidall.a
  • 3. Who created them?
Good question. There are actually some more interesting details. The website of this app allows you (after logging in to your account) to ‘enter’ your social network accounts, mail accounts (it seems that these details will also be used) and even PayPal (!) to add money to your account.

So be very cautious  when you are downloading apps. Be sure to view the user reviews about the app before you downloading them.


Read more..
 

Tec Hound Copyright © 2012