Please Share

Showing posts with label virus. Show all posts
Showing posts with label virus. Show all posts

Wednesday, May 26, 2010

British Scientist Infects Himself With Computer Virus...

Well not himself but a chip implanted within himself. Dr. Mark Gasson from the University of Reading contaminated a modified RFID chip, similar to those used to chip your pets, and is experimenting with the infected device and systems that it may connect to. The ramifications, as Dr. Gasson explains in this BBC video clip, could be extensive as more and more uses for the chips are found and more devices are scanning for the data contained within the chips.

"This type of technology has been commercialised in the United States as a type of medical alert bracelet, so that if you're found unconscious you can be scanned and your medical history brought up." says Dr. Gasson. An infected chip could hold an entirely different payload than that which is intended for use by the system scanning it. 


Can you say Minority Report?

Monday, November 23, 2009

New iPhone Worm Targets Netherlands Users

A new worm detected that targets the iPhone is specifically directed at users in the Netherlands who use their device to do online banking with Dutch online bank ING Direct according to security company F-Secure.

"It's the second iPhone worm ever and the first that's clearly malicious - there's a clear financial motive behind it," F-Secure research director Mikko Hypponen told the BBC.

"It's fairly isolated and specific to Netherlands but it is capable of spreading."

The worm again attacks iPhones which have been "jail-broken" and have SSH (secure shell), a file-transfer program that enables users to remotely connect to their phones, installed.

I wonder how long it will be before we see Microsoft adds poking fun at iPhone's security? "I'm a Windows Mobile, and I'm a iPhone OS"

Monday, November 9, 2009

iPhone/iPod Touch Owners Rickrolled By ikee Worm

A self-propagating program believed to be the first iPhone worm, that changes an iPhone's (or iPod Touch's) wallpaper to a picture of Rick Astley with the message "ikee is never going to give you up", has been unleashed in Australia. Known as "ikee" the worm only affects devices that have been jail-broken, have had SSH installed (a program that allows users to make changes to the phone's file system), and who's owners have not changed the default root password after installing SSH.

"What's clear is that if you have jail-broken your iPhone or iPod Touch, and installed SSH, then you must always change your root user password to something different than the default, 'alpine'," wrote Graham Cluley of security firm Sophos.

"In fact, it would be a good idea if you didn't use a dictionary word at all."

Source: BBC

Friday, July 10, 2009

North Suspected In South Korea / US Denial Of Service Attacks

The South Korean government is warning that about 20,000 computers infected by a virus as part of an alleged denial of service (DOS) attack are expected to have their data destroyed by the vicious code, starting today. The DOS affected high profile sites in both South Korea and the United States including the South Korean Spy Agency, a bank and a top newspaper as well as the US Treasury Department, Secret Service, Federal Trade Commission and the Transportation Department.

According to the CBC "Hong Hyun-ik, an analyst at the Sejong Institute think-tank, said the attack could have been done by either North Korea or China, adding that he "heard North Korea has been working hard to hack into" South Korean networks."

Monday, June 22, 2009

Malware Authors Set Traps Via Twitter

According to CNN, "Cyber criminals have been targeting Twitter users by creating thousands of messages (tweets) embedded with words involving trending topics and malicious URLs," Sean-Paul Correll, a threat researcher for Panda Labs. These are not new attacks but a new way of luring the unsuspecting in.

"The fundamental fact is cyber criminals are highly organized with sophisticated corporate structures and business chains," said Michael Fraser, director of the Communications Law Centre at the University of Technology Sydney in Australia.

"They have R&D departments, strong distribution networks and Web sites for the discerning cyber criminal," Fraser said.

This stuff isn't going away anytime soon folks, so keep your patch levels up and your anti-virus current...

Friday, February 13, 2009

Microsoft Offers Reward For Worm Creator's Identity

George Stathakopulos from Microsoft's Trustworthy Computing Group has told the BBC that a $250,000 reward is being offered by the company to find who is behind the Downadup/Conficker virus. "Our message is very clear - whoever wrote this caused significant pain to our customers and we are sending a message that we will do everything we can to help with your arrest," said Mr Stathakopulos. One estimate has as many as 12 million computers being affected globally by Conficker/Downadup since it appeared in October.

On three other occasions Microsoft has offered such rewards. Rewards of $250,000 were offered for information leading to the creators of Blaster, MyDoom and Sobig worms. The perpetrators of those threats have never been caught.

Friday, February 6, 2009

Fake Parking Tickets - Real Viruses

Using a clever bit of social engineering, hackers in in Grand Forks, North Dakota have placed tickets on vehicles citing fake traffic violations and referring the "offender" to a website that claimed to have photos of the alleged violation, but which actually tricked users into downloading a virus.

"According to internet security watchdog The SANS Institute, the website then had photos of cars in various car parks around Grand Forks and instructed users to download a tool bar to find photos of their own vehicle.

But the tool bar was actually an executable file which installed a Trojan virus that then displayed a fake security alert when the PC was rebooted. The fake alert then prompted the user to install fake anti-virus software."

It still amazes me how easily we are duped into falling for these tricks... clever though!

Source: BBC

Saturday, January 17, 2009

Windows Worm Spreads To 3.5 Million PCs

A Windows worm known as Conficker, Downadup, or Kido which was first discovered in October has a new viral variant that is causing concern amongst security firms. Even though Microsoft's MS08-067 patch protects users from the worm it has propegated to some 3.5 million machines worldwide.

According to Microsoft, the worm works by searching for the "services.exe" file and then becomes part of that code. It copies itself into the Windows system folder as a random dll fileand gives itself a 5-8 character name, such as piftoc.dll. The worm then modifies the Windows Registry to run the infected dll file as a service. Once up and running, it creates an HTTP (web) server, resets your machine's System Restore point (making it harder to recover from) and proceeds to download files from a malicious web site.

"There was a new variant released less than two weeks ago and that's the one causing most of the problems," Kaspersky Lab's security analyst, Eddy Willems told the BBC.

"The replication methods are quite good. It's using multiple mechanisms, including USB sticks, so if someone got an infection from one company and then takes his USB stick to another firm, it could infect that network too. It also downloads lots of content and creating new variants though this mechanism."

"Of course, the real problem is that people haven't patched their software. If people do patch their software, they should have little to worry about," he added.

Tuesday, December 23, 2008

Most Spam Served From The US

ars technica has an interesting story about the origin of spam. Citing the most recent Sophos report, the article says that the US hosts 37 percent of all malware sites followed by China (27.7 percent) and Russia (9.1 percent). Also of note is the rise in frequency of infected e-mails. In 2007 the ratio of infected e-mails to non-infected was 1 in 909, in 2008 the numbers were 1 in 714. 

Friday, December 12, 2008

Federal Trade Commission Target Scareware Dealers

The U.S. Federal Trade Commission has gone to the courts in an attempt to stop two companies, Innovative Marketing, Inc. and ByteHosting Internet Services, LLC. from distributing software that they've dubbed "scareware". The companies operate webpages that run a fake "scan" proportedly looking for security problems. The scan returns many ficticious results and prompt the users to pay for removal software that affectively does nothing. Typically the scans report evidence of viruses, spyware and/or illegal pornography. "However," said the FTC, "the scans were entirely false." Yuval Ben-Itzhak, chief technology officer at security firm Finjan says "People are paying 40-60 dollars for bogus software which does nothing,"

A US District court has granted an injunction which stops the companies from advertising their software, and has also asked firms hosting the websites to block customers from accessing them. It has also frozen the assets of the companies so the cash can be reclaimed and refunds given to those caught in the scam.

BBC story here.

Saturday, December 6, 2008

Koobface Virus Targets Facebook Users

With 120 million users Facebook is increasingly becoming the target of virus writers. Facebook users are being advised that a new threat has been uncovered which is being dubbed the Koobface virus. The virus is propagated via Facebook's messaging system and shows up as a message with subject headers like, “You look just awesome in this new movie,” upon opening the message the user is directed to a website which prompts them to download a file that it claims is an update of Adobe's Flash player. Once infected the virus takes users to contaminated sites when they try to visit search engines from Google, Yahoo, MSN and Live.com. Facebook is telling members to delete contaminated e-mails and has provided directions on how to clean infected computers at http://www.facebook.com/security.

Globe and Mail story.

Saturday, November 1, 2008

Cache Of Stolen Financial Data Found By Security Lab

RSA FraudAction Research Lab reported on Friday that it had uncovered a large cache of credit card numbers and online bank account logins and passwords that have been accumulated over the past two-and-a-half years. The researchers say that a technically sophisticated trojan horse program, the Sinowal Trojan, likely originating in Russia is responsible. “Only rarely do we come across crimeware that has been continually stealing and collecting personal information and payment card data, and compromising bank accounts as far back as 2006. And in addition to its longevity, Sinowal has also been evolving at a dramatic pace – its rate of attacks spiked upwards from March through September of this year.” according to the researchers.

New York Times article.
BBC News article.

Thursday, August 28, 2008

Space Station Laptop Hit By Virus

Nasa has confirmed that laptops carried to the ISS in July were infected with the Gammima.AG trojan designed to steal login names and passwords for a number of popular online games. No critical command or control systems are said to be at risk as the infected laptops are used to run nutritional programs and provide the astronauts with e-mail access. According to the BBC "The ISS has no direct net connection and all data traffic travelling from the ground to the spacecraft is scanned before being transmitted." and the infection is suspected to have gotten on board via a flash or USB drive owned by an astronaut and carried into space. Perhaps its time to review the IT security policy?

Friday, May 9, 2008

Firefox Plugin Infects Vietnamese Users Machines

Mozilla is increasing it's efforts to scrutinize user submitted plugins after it had discovered that a Vietnamese language pack on its official add-on page had been infected for months with rogue code. In mid-February the user submitted add-on passed Mozilla's scrutiny because the virus's signature was unknown at the time of testing. According to Wired's Threat Level blog "On Tuesday, a user named Hai-Nam Nguyen reported that anti-virus programs detected the Xorer Trojan inside the add-on. Firefox admins quickly confirmed the presence of the Trojan's code and removed the file the same day." It is unknown how many users actually installed the plugin but Mozilla says 16,667 people had downloaded the add-on since November 2007. The organization now intends to scan all of the user submitted add-ons each time virus definitions are updated, that seems a bit more proactive...

Saturday, March 15, 2008

Factory Installed Viruses - Getting More Than We Paid For?

The CBC has a story of new devices hitting store shelves with factory installed viruses and trojans. "Recent cases reviewed by the Associated Press include some of the most widely used tech devices: Apple iPods, digital picture frames sold by Target and Best Buy stores and TomTom navigation gear." The experts believe the threats are the result of lax quality control measures in the manufacturing process, the result of cost cutting measures in foreign manufacturing facilities. Ultimately, does not the responsibility lay with the company who commissions the work? I mean, if you are outsourcing work shouldn't you do your due diligence and have your own quality control checks in place?

Sunday, January 13, 2008

Stealthy Windows Virus Looks For Bank Info

The BBC Is reporting that security experts are worried about a particularly stealthy new virus that seems to be after bank account info. The Mebroot virus as it has been dubbed is a rootkit virus that hides itself deep in the Master Boot Record and later downloads other malicious programs such as key loggers in an attempt to hijack banking information. It is suspected that a Russian hacking group is behind the virus which was detected on about 5,000 machines in December, mostly in Europe. The virus installs itself via booby-trapped websites that use vulnerabilities in Internet Explorer. Yet again another reason to use Firefox!

Saturday, September 1, 2007

Celebrating 25 years of computer viruses

The Globe and Mail has an interesting story about the first computer virus, created by Rich Skrenta in the 9th grade as a prank, the “Elk Cloner” was a self replicating program that was in effect the world's first “boot sector” virus. Skrenta has gone on the bigger and better things as a coder and business man but will likely always be known for this dubious honor. Little did he know what he had started!

Friday, June 29, 2007

Danger Will Robinson!

Hopefully you all know not to trust e-mails asking you to download something, or for that matter not to open e-mails from anyone you don't know, or attachments to e-mails even if they come from someone you do know (unless you are expecting it, and then only after it's been scanned),... The Register has this warning that you should take heed of anyway.

Monday, May 28, 2007

OpenOffice.org target of virus writters?

In a recent press release OpenOffice.org has acknowledged that it is possible that virus writers may have targeted their open source office suite via it's macro support. The OpenOffice.org security team has apparently not received a copy of the reported virus, "SB/BadBunny-A", and will respond once they have had an opportunity to analyze the threat. While I have not personally tried the OpenOffice.org product I have heard good things about the software and support the idea of open source. I am sure that with Sun Microsystems behind it, it is a solid suite of products and should be considered a contender when you are looking for office software at home or a work. The price is definitely right! I will give it a download and a serious look once the virus threat has been addressed. I should stress that the other major office suites are constantly marked as targets of virus authors so my reservations for downloading at the moment are not because I think OpenOffice.org is more vulnerable than my current office suite. I'm also not inclined to open files from anyone that I don't know or that I am not expecting files from, even if I know them; this is just good practice.

Search

Google