Wednesday, 8 July 2015

BatteryBot Pro App

A new form of mobile malware designed with multiple malicious intentions has appeared, in the form of a spoofed app that is a copy of legitimate app BatteryBot Pro.

The fake app will provide the same functionality to the victim found in the original version of BatteryBot Pro, but also performs malicious activity in the background. Most notably, though the app seems to be working normally, at the back-end it tried to load various ad libraries, ultimately delivering a click-fraud campaign. According to Zscaler, other functions include ad fraud, premium SMS fraud, and the installation of additional malicious APKs.

On the SMS front, the app is stealthy. The main activity screen is identical to original app, but when the user clicks on `View Battery Use,` the malware sends requests to its command and control server to retrieve short codes for premium-rate SMS numbers. Messages are then sent—charges for which will show up on the user's bill.

The app was removed from the Play Store as soon as Google became aware of its malicious intent, but for those who already downloaded it, they may be out of luck. Upon installation of the malicious app, it demanded administrative access, which allows the malware developer to obtain full control access of the victim`s device. And its being run with administrator privileges means the user cannot delete the app after installation.

`While in some of the scenarios we were able to manually delete the app, the malware authors have taken care to ensure persistence,` said Shivang Desai, the Zscaler researcher that discovered the app. `The malware silently installs an app with a package name of com.nb.superuser, which runs as a different thread and resides on the device even if the app is forcefully deleted.`

Spoofed Android apps are all too common. One way users can protect themselves is looking for and being wary of excessive permissions. While the legit BatteryBot Pro app demanded minimal permissions, the fake app demanded full admin access to obtain total control of the victim`s device.

`Malware authors tend to follow one of the following two methods for malware development: Create a malware app from scratch, or compromise a legit app by embedding malicious modules into it,` Desai said. `With Android being open source and an Android app being easily reversible, most of the malware developers tend to stick with the second option.`

Read original article

Verisign Cloud DNS

Verisign has introduced its DNS Firewall, a managed, cloud-based service that offers protection from unwanted content, malware and advanced persistent threats (APTs), along with the ability to customize filtering.

`Defending against cyber-threats is not only critical, but increasingly difficult and expensive,` said Michael Kaczmarek, senior director of product management for Verisign's recursive DNS service, in a blog. `Just a quick glance at today's news headlines and it is clear that these threats present numerous challenges to internet users and the organizations that both serve and employ them.`

For example, in 2014, McAfee Labs observed a 75% year-over-year increase in new malware equating to 387 new threats per minute. Further, the Ponemon Institute estimates the average data breach costs large organizations $3.8 million per event.

The service employs real-time feeds from multiple sources, including Verisign's own iDefense Security Intelligence Service feeds for in-depth country-specific and regional threats. It also makes use of Verisign's patented bot-net detection algorithm feeds that predict a variety of potential threats, and threat indicator feeds from various third-party sources.

On the filtering front, it includes a variety of out-of-the-box content filters, including the ability to define customized white and black lists to tailor traffic navigation.

Also, organizations can identify affected devices inside the network border, without the need for individualized client installs.

The company said that the launch represents a new approach to firewalls. `Most solutions either require extensive investment or do not meet an organization's constantly evolving needs,` said Kaczmarek. `Traditional, appliance-based security solutions can require organizations to shell out considerable amounts of money, both in up-front capital expenditure and in on-going maintenance fees. Conversely, many managed cloud-based offerings do not provide the critical capability to customize the solution based on an organization's specific business environment and security needs. Finally, do-it-yourself (DIY) open-source solutions suffer from constant patching and maintenance problems.`

Read original article

Cisco Acquires OpenDNS

Cisco has announced plans to expand its threat detection and attack-blocking portfolio via the $635 million purchase of cloud security firm OpenDNS.

See Also: Preparing for OCR Audits: Presented by Mac McMillan of the HIMSS Privacy and Policy Task Force

Founded in 2005, OpenDNS runs a network of domain name servers that route Web traffic - competing with Internet service providers, telecommunications carriers, as well as Google - allowing users to reach websites more quickly, as well as help block advanced attacks and phishing campaigns. The company offers free services, as well as a cloud-based enterprise security product called Umbrella, and currently operates 25 data centers around the world.

Cisco says it plans to include the OpenDNS capabilities as part of a cloud-delivered platform designed to prevent, detect and mitigate attacks and breaches.

`The acquisition will extend our ability to provide customers enhanced visibility and threat protection for unmonitored and potentially unsecure entry points into the network, and to quickly and efficiently deploy and integrate these capabilities as part of their defense architecture,` says Hilton Romanski, a former J.P. Morgan investment banker and M&A specialist who is now Cisco`s CTO and chief strategy officer, in a blog post. `This acquisition builds on Cisco`s security strategy, adding broad visibility and predictive threat intelligence from OpenDNS` cloud platform, accessed by more than 65 million users daily.`

Analyst Adrian Sanabria IT market research firm 451 Research says via Twitter that he hasn`t `seen this much conversation/buzz created by an M&A deal since FireEye/Mandiant.`

David Ulevitch, the founder and CEO of OpenDNS, says in a blog post that his company had previously entertained - and rejected - other acquisition offers. `We didn`t decide to sell OpenDNS. We decided to sell OpenDNS to Cisco. That`s an important distinction,` he says. `Cisco is not buying OpenDNS for our individual components, but for the whole.`

OpenDNS will become part of the Cisco Security Business Group, which is led by Senior Vice President and General Manager David Goeckeler. He tells The Wall Street Journal that OpenDNS will give Cisco better information about threats. `It provides us a global visibility,` Goeckeler says. `We get a lot more intelligence about what is happening in the world.`

Cisco says it expects to close the deal in October.

Cisco`s Security Acquisitions

Cisco`s move to acquire OpenDNS follows the networking giant making one of the largest security deals in history when it spent $2.7 billion in 2013 to buy Sourcefire, and in 2014 acquired malware-detection technology firm ThreatGrid. Those deals were all spearheaded by Romanski.

Cisco has not been shy about using its cash - the company reported $52 billion in cash and investments on its 2014 annual report - to snap up information security firms. `The purchase continues Cisco`s practice of paying rich multiples as it shops in information security,` says research director Brenon Daly at 451 Research, in a blog post. `Cisco has now acquired 18 security companies in the past decade and a half, mostly smaller startups.`

Cisco`s acquisition of OpenDNS also follows the networking giant contributing to the $35 million investment the security firm raised in May 2014 as part of its oversubscribed C-round funding; the company had only set out to raise $20 million. Before Cisco moved to acquire OpenDNS, the 10-year-old startup had raised $51 million in funding.

Read original article

Tuesday, 7 July 2015

Hacking Teams data dump

Privacy and human rights advocates are having a field day picking through a massive leak purporting to show spyware developer Hacking Team`s most candid moments, including documents that appear to contradict the company`s carefully scripted PR campaign.

`Imagine this: a leak on WikiLeaks showing YOU explaining the evilest technology on earth! :-),` Hacking Team CEO David Vincenzetti wrote in a June 8 e-mail to company employees including Walter Furlan, whose LinkedIn profile lists him as the international sales engineer of the spyware developer. `You would be demonized by our dearest friends the activists, and normal people would point their fingers at you.`

Other documents suggested the US FBI was among the customers paying for software that allowed targets to be surreptitiously surveilled as they used computers or smartphones. According to one spreadsheet first reported by Wired, the FBI paid Hacking Team more than $773,226.64 since 2011 for services related to the Hacking Team product known as `Remote Control Service,` which is also marketed under the name `Galileo.` One spreadsheet column listed simply as `Exploit` is marked `yes` for a sale in 2012, an indication Hacking Group may have bundled some sort of attack code that remotely hijacked targets` computers or phones. Previously, the FBI has been known to have wielded a Firefox exploit to decloak child pornography suspects using Tor.

Security researchers have also scoured leaked Hacking Team source code for suspicious behavior. Among the findings, the embedding of references to child porn in code related to the Galileo.

Still another document boasts of Hacking Team`s ability to bypass certificate pinning and the HTTP strict transport security mechanisms that are designed to make HTTPS website encryption more reliable and secure. `Our solution is the only way to intercept TOR traffic at the moment,` the undated PowerPoint presentation went on to say.

Elsewhere, the document stated: `HTTPS Everywhere enforces https and could send rogue certificates to the EFF SSL Observatory.` HTTPS Everywhere is a browser extension developed by the Electronic Frontier Foundation that ensures end users use HTTPS when connecting to a preset list of websites. The statement appears to be a warning that any fraudulent certificates Galileo relies on could become public if used against HTTPS Everywhere users when they have selected an option to send anonymous copies of HTTPS certificates to EFF`s SSL Observatory database.

Yet another document airing Hacking Team`s private dealings is one purportedly prepared by private investigation firm Kroll. It details Hacking Team`s dealings with a US-based contractor suspected of secretly working for a company that competes with Hacking Team in the market for active interception products. The arrangement appeared to be a violation of non-compete clauses signed by the contractor.

The spoils of the Hacking Team compromise go on an on, and also purportedly include the now-compromised GPG key Hacking Team engineer Christian Pozzi. The document dump—said to be 400 gigabytes in size by the person who made them public—originally came in the form of a BitTorrent download. Since then, the leak has been mirrored on sites here and here. The privacy consultant who set up the latter site has reported receiving a legal notice demanding he remove the leaked documents. Even if the mirror sites remove the content, there`s little chance of containing the damage to the reputation of Hacking Team and its many customers. Expect this story to stick around for at least the next week or two and possibly much, much longer.

Read original article

Hacking Team hacked

Italian security and surveillance firm Hacking Team appears to have itself fallen victim to a security breach. Hacking Team produces software which is used by governments around the world as part of their surveillance programs. The company has been criticized for facilitating invasions of privacy, and, over the weekend, its Twitter feed was taken over, resulting in its name and profile picture being changed to read Hacked Team.

But this is far from being the end of the story. Whoever is responsible for the security breach also released a torrent file that provides access to 400GB of company data. Included in the cache are emails, source code, and confidential documents. The files reveal who the company has been dealing with including a number of countries known for their oppressive regimes.

Invoices leaked from the stash of documents via the hacked Twitter account show that Hacking Team provided services for countries such as Egypt and Sudan. This includes providing surveillance equipment as well as software for gaining remote access to computers. We`ve heard a lot about Hacking Team since the explosion of the NSA surveillance debacle. A secret manual published last year showed just how to use the company`s various tools to spy on people, get around encryption.

Working through all of the documents that have been leaked since Sunday`s breach, CSO reports that Hacking Team`s list of customers includes:

Egypt, Ethiopia, Morocco, Nigeria, Sudan, Chile, Colombia, Ecuador, Honduras, Mexico, Panama, United States, Azerbaijan, Kazakhstan, Malaysia, Mongolia, Singapore, South Korea, Thailand, Uzbekistan, Vietnam, Australia, Cyprus, Czech Republic, Germany, Hungary, Italy, Luxemburg, Poland, Russia, Spain, Switzerland, Bahrain, Oman, Saudi Arabia, and UAE.

Hacking Team has gained the attention of human rights groups for its apparent willingness to work with countries engaged in human rights abuse, and those looking to spy on journalists, and people opposed to the government.

The attackers have not been afraid to rub a little salt in the wound. As well as the name change to Hacked Team, the security firm`s description was also edited to read:


Developing ineffective, easy-to-pwn offensive technology to compromise the operations of the worldwide law enforcement and intelligence communities.

Control of the account has since been regained.

In addition to invoices, the leaked cache of data also reveals many of the passwords used by clients. With examples such as Passw0rd, Pas$w0rd, and Passw0rd!, it seems clear that security is not viewed with as much importance by all.

Hacking Team was very slow to respond to the attack. Eventually, Christian Pozzi from the company took to Twitter to hit out at the perpetrators. He also defended Hacking Team, suggesting that what was being posted by the attackers was not to be believed, and also tried to discourage people from downloading the data but suggesting that the torrent contained a virus. It`s not clear how long it will take Hacking Team to regain control of its accounts, but Pozzi insisted that police are currently investigating. His Twitter account has subsequently been taken offline.

Read original article

Plex Forum hacked

ALERT! Internet movie and television enthusiasts, who have been using the PLEX media servers and the PLEX forums for their daily dose of entertainment, it`s time to check in your private credentials. PLEX, an online movie and TV library forum has announced that their servers have been hacked on the morning of 2nd July, 2015; which has left registered email addresses, user ids and passwords vulnerable.

The company has clarified that only the accounts that have been used for accessing the services of PLEX forums have been compromised. Yet, it added that the accounts that were created through social media hyperlinks and were never used to access the forums are most probably vulnerable to data breach. The company has however stated that their has been no breach of credit card information as it is never stored in the servers


Read original article

Monday, 6 July 2015

CryptoWall 3.0 Attacks

A fresh drive-by campaign that abuses vulnerabilities in the Google Drive platform is serving up CryptoWall 3.0.

Heimdal Security uncovered the campaign, where an initial payload is delivered through the popular Google Drive platform before downloading and running the ransomware from a long list of compromised webpages.

On the enemy pages, several malicious scripts force the user to a narrow selection of dedicated domains used in the campaign (more than 80 active domains),` explained Heimdal spokesperson Andra Zaharia, in a blog.

These domains make use of a commercial exploit kit known as RIG, which will try to abuse vulnerabilities in JavaJRE, Adobe Reader, IE and Flash Player. RIG was the most prevalent exploit kit used in 2014 by cybercriminals according to Heimdal, accounting for 25% of all exploit kits used.

`The low price for use of the RIG exploit kit likely contributed to its popularity in 2014,` Zaharia said. `RIG rental sent criminals back only $150 a week compared to, for example, $750 a week for Neutrino.`

If the victim's system is not fully updated the EK will drop a file that contacts a series of predefined Google drive URLs before delivering the main objective.

A total of 45 compromised websites are used as delivery platforms.

CryptoWall 3.0 encrypts a variety of data files on the local hard drive and available network drives with a RSA2048 key. The communication then takes place via Tor gateways for anonymity.

`Antivirus detection is low in this campaign, which is deftly released and goes undetected past most endpoint security solutions because of its delivery method,` said Zaharia.

CryptoWall, a variant of last year's CryptoLocker, came back in its third generation form six months ago, and has been dispersed in at least three strong campaigns since. Unlike its predecessors, it is polymorphic, and has an advanced and extensive infrastructure that can evade detection and take-down attempts.

Users can take steps to protect themselves with the usual vigilance. `Drive-by attacks can also happen while viewing an email or if the user clicks on a deceptive pop-up window on a website,` Zaharia said. `Be very careful about which online destination you access, whether they're websites or popular services such as Google Drive, which is being used in this particular CryptoWall campaign. Never click on links in e-mails received from people you don't know.`

Read original article