Skip to main content

Posts

Showing posts with the label Virus

Brown-Forman is the latest high-profile victim of Ransomware

US hard liquor giant Brown-Forman is the latest high-profile victim of ransomware criminals. Even if the company’s name doesn’t ring a bell, some of its products are well-known to spirits drinkers worldwide: Brown-Forman is a multi-billion dollar business that owns Jack Daniel’s whiskey, Finlandia vodka, and other global brands. It’s a multi-billion dollar business, headquartered in Louisville, Kentucky – a US state that’s famous for American whiskey, better known as bourbon – and you can see why today’s big-money ransomware crooks might go after a company of that size and sort. According to the business media site Bloomberg, which claims to have received an anonymous tip-off from the crooks behind the attacks, the ransomware crooks involved are the infamous REvil or Sodinokibi gang. The REVil crew make up one of what you might call a “new wave” of ransomware operators who practice three-stage attacks that end in double-barrelled blackmail: First, they break into a victim’s network and...

US UK Cybersecurity Agencies Warn Of QSnatch Malware Actively Exploiting QNAP Devices

Recently, the US and UK cybersecurity agencies have issued a joint security alert about an ongoing malware attack. The QSnatch malware is actively targeting QNAP devices and has infected thousands of them already.   Users must ensure updating their devices with security fixes to avoid exploitation. US UK Cybersec Warn Of QSnatch Malware In a joint alert from the United States Cybersecurity and Infrastructure Security Agency (CISA) and the United Kingdom’s National Cyber Security Centre (NCSC) have warned of active QSnatch malware attacks. Briefly, they presented their findings regarding a new strain of QSnatch malware. While the malware vector remains unknown, the firms believe that it attacks a vulnerable device as the malicious code runs with it. The malware affects the device firmware whilst allowing the attacker to connect with the C&C by using a domain generation algorithm (DGA).  It keeps generating different domain names to communicate with the C&C. QSnatch exhi...

Kaspersky: North Korean hackers are behind the VHD ransomware

North Korean hackers return to actively deploying ransomware after the huge WannaCry debacle. Antivirus maker Kaspersky said in a report today that hackers associated with the North Korean regime are behind a new ransomware strain known as VHD. The report details two incidents to which Kaspersky was privy, where intruders gained access to companies' networks and deployed the VHD ransomware. Kaspersky experts say that tools and techniques used during the two intrusions link the attackers to Lazarus Group -- a generic name given to hackers working for the Pyongyang regime. This included: the use of the MATA (Dacls) malware framework to deploy VHD as a final payload the use of techniques to move across a victim's internal network that were previously observed in past Lazarus campaigns "The data we have at our disposal tends to indicate that the VHD ransomware is not a commercial off-the-shelf product; and as far as we know, the Lazarus group is the sole owner of the MATA fram...

Chinese APT Group Attacks India and Hong Kong With New Variant of MgBot Malware & Android RAT

Chinese state-sponsored hacking group targets India and Hong Kong with a unique phishing attack designed to convince the target. The campaign uses multiple documents with the filename ‘Mail security check’ and “Boris Johnson Pledges to Admit 3 Million From Hong Kong” in the attack. The document with the name ‘Mail security check’ targets India and the document with “Boris Johnson Pledges to Admit 3 Million From Hong Kong” targeting Hongkong. According to Malwarebytes  analysis , this new campaign is operated by a Chinese state-sponsored actor, who has been active since at least 2014. Spear-Phishing to Install MgBot Malware The campaigns found to be active since July 2, in the first campaign attacker group uses the Cobalt Strike variant delivered through a weaponized word document. A day after the first attack the APT group changed their template to drop, a loader called MgBot that make use of Application Management (AppMgmt) Service on Windows to deliver the final payload. The camp...

BlackRock Malware steals credit card details, password from 337 android apps

New Android malware has been discovered that steals data such as credit card details, password from 337 applications. This included some of the popular apps such as Amazon, Gmail, Uber, Netflix, and more. Highlights The malware was discovered by a mobile security firm Threatfabric. The malware is being distributed as fake Google update packages offered on third party websites. The malware is capable of performing intrusive operations such as Perform SMS floods, start specific apps, show custom push notifications, perform SMS floods, sabotage mobile antivirus apps. About the malware The malware is based on the leaked source code of another malware Xerxes. Again, xerxes is based on the strains of other malwares. Blackrock is completely enhanced with stealing passwords and credit card details. It collects data through overlays. Working of the malware The Malware asks for credit card setails and login credentials before the user enters the app. It asks for phone’s accessibility feature. It...

Cerberus Malware Emerged On Play Store Impersonating Cryptocurrency Converter App

Once again, Cerberus malware has emerged as a threat to users after appearing on the Google Play Store. The malware posed as a cryptocurrency converter app to trick users, thus reaching thousands of downloads. Cerberus Posing As Cryptocurrency App Researchers from Avast found Cerberus malware appearing on Google Play Store. The malware hid behind a cryptocurrency converter app. As explained in their post, the app seemingly aims at Spanish users. It bears the name “Calculadora de Moneda” which translates as “Currency Calculator” in English. Considering the niche chosen, it seems that malware basically attempted to steal users’ banking data, which the users would need to enter while converting their cryptocurrency to fiat money. Briefly, the researchers observed that the app remained harmless for a few initial weeks, seemingly to gather users (or victims). This also allowed the app to escape security check by Google Play Protect. However, the app did bear malicious malware dropper code w...

Google Has Removed These Apps With Malware, Uninstall Them Now!

Google Has Removed These Apps With Malware, Uninstall Them Now! Data uploaded to hackers The  Google  PlayStore was hit with malware-ridden apps as the company recently removed 11 applications from its platform that were infected with the Joker malware. It was last year that the Joker malware has been reported and it was observed that it was spreading rapidly. As per the latest report by  Check Point’s research , a new variant of the malware has been discovered on the PlayStore. The update to the Joker malware can download additional threats to the device which subscribes the users to premium services of apps without their consent. You can also read more about the threat in a detailed report  here. Snapshot:- List of apps removed: com.imagecompress. android com.relax.relaxation.androidsms com.cheery.message.sendsms (two different instances) com.peason.lovinglovemessage com.contact.withme.texts com.hmvoice.friendsms com.file.recovefiles com.LPlocker.lockapps com.remin...

Joker Malware Bypasses Google Play Security to Attack Users

New Variant of Infamous Android Joker Malware Bypasses Google Play Security to Attack Users The Joker malware detected in early June 2019, it employs several tactics to bypass GooglePlay protection and to perform several malicious activities. The malware used to hide inside different apps and once users downloaded to the phone they got infected with the Joker malware. It aims to steal money from the user by signing for paid subscriptions, it interacts with the user’s SMS messages, contact lists, and other data from the device. Earlier it was observed that Joker malware hidden with 24 apps different apps, all the apps have been reported to Google and removed from the store. New Joker variant Check Point researchers discovered a new variant of Joker Dropper and Premium Dialer spyware in Google Play hidden with 11 apps that removed from Google Play on April 30, 2020. The updated version of Joker malware hides behind look like legitimate apps and downloads additional malware on the device....

Zoom ZERO-day Vulnerability

Zoom 0day Vulnerability Let Remote Attacker to Execute Arbitrary Code on Victim’s Computer A new remote code execution “0day” flaw with Zoom Client for Windows allows remote attackers to execute arbitrary code on Windows computer where the vulnerable version of Zoom client installed. The vulnerability was found by a researcher who wants to keep their identity private, the vulnerability can be exploited by an attacker by making the victim open the malicious document file. Zoom is a popular video conferencing software across the globe that are used by individuals across the globe to work from and to stay in touch with friends and family. Zoom 0day Vulnerability The vulnerability can be exploitable only on Windows 7 and other older versions of the Windows machine. Clients running on Windows 8 or Windows 10 are not affected. ACROS Security has  reported  the issue to Zoom and released a micropatch for its 0patch to prevent the exploitation until the Zoom releases an official fix. ...

Lucifer Malware Emerges As New Threat To Windows Devices

Lucifer Malware Targeting Windows Researchers from Palo Alto Networks’ Unit 42 division have found an active campaign of new malware in the wild. Dubbed ‘Satan’ by the threat actors, and ‘Lucifer’ by the researchers this malware exploits known bugs to infect Windows machines. Sharing the details in a post, the researchers explained that they caught two strains of Lucifer while analyzing the campaign. Yet, their functionalities predominantly remained the same, version 2 is more advanced. Briefly, Lucifer malware aims at cryptojacking by dropping XMRig on target devices, and DDoS attacks.  Moreover, the other functionalities are slightly different for the two versions. The Lucifer v.1 performs cryptojacking, DDoS attacks, brute-forcing credentials, and self-propagation. Whereas, Lucifer v.2, in addition to these capabilities, also exhibits anti-sandbox and anti-debugger functionalities. Also, the malware tends to drop EternalBlue, EternalRomance, and DoublePulsar backdoors (under cer...

New Java Based Ransomware Attack Windows & Linux Users

Tycoon Ransomware – New Java Based Ransomware Attack Windows & Linux Users Security experts have warned that hackers are using a new multi-platform Java ransomware “Tycoon” to target Windows and Linux users to lock down the files. We all know that hackers are constantly looking for new means to attack data centers and systems of normal users to steal essential data and information. Since Microsoft Windows is the most used OS, that’s why hackers are making it as their target. hackers are paying more and more attention to other operating systems as well, like macOS and Linux.  As hackers are betting massively on multi-platform malware and ransomware, that affects all the major platforms. The main goal of this critical vulnerability is to infect the SMBs in the software and education industries. Tycoon Ransomware Security experts at BlackBerry  Research  and Intelligence Team in association with KPMG’s UK Cyber ​​Response Services have named this ransomware as “Tycoon,” ...