Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Monday, April 20, 2009

First Mac botnet found

Researchers have found malware in pirated copies of Apple's iWork ’09 and Adobe Photoshop CS4. What's worse, the malware has created the first botnet for Macs.

The Mac OS has been overdue for malware attention by hackers and "safe" only due to much lower market share than IBM-clone PCs. Mac users can expect to see more such attacks.

Friday, April 03, 2009

Beware Antivirus 2009

Beware of fake antivirus software. And beware of a pop-up notice that you have a virus or "might have" a virus (unless the pop-up notice comes from software you already own).

A type of software that tricks you into installing it, then demands payment "or else" is called ransomware. And it's spreading.

One nasty piece of ransomeware seems to be a legitimate program called Antivirus2009. But after you install the software, it encrypts several document types. Then when you try to open one of the encrypted files, it pops up an alert and offers to sell you FileFix Pro 2009, which it says can decrypt the file.

So you get duped into downloading the fix. But it decrypts only one document. After that, it demands that you pay $50 to buy the software to decrypt the rest of your files (that the Antivirus 2009 encrypted).

Beware of "something for nothing". Be paranoid. Check out reviews of software at trusted sites before you download and install any.

Wednesday, February 04, 2009

Malware worms its way into social networking

Social network site users tend to be more trusting than they should be about emails from "friends". They seem to assume that since they have to login to the account that messages from others are "safe". Criminals know that.

So with increasingly sophisticated social engineering, criminals are successfully attacking social networking services. Angry Facebook members created a special facebook page for victims of the Koobface worm.

Malicious software "scrapes" Facebook for all the user data it can find. People who give out real names, addresses, email addresses, and other information may find it cropping up in the hands of criminals. We teach kids to be wary of strangers, but then we turn around are and much too trusting in our online behavior ourselves. Parents, schools, and churches all need to start educating kids and even other adults about being wary of online personas and of being careful not to release personal information. Criminals now "mine" data from multiple sites to "fill in the picture" about victims identities and personal information.

Government agencies normally let their employees do personal surfing, yet they are starting to block access from the government offices to social networking sites. Why? It just too unsafe, at least for now.

Part of the challenge is that in order for social networking sites to be "fun", they have to encourage their members to share information. The default for most social networking sites is to be "open" rather than to have tight security. And most people are much more gullible online than in the "real world". So social networking sites like FaceBook and MySpace may continue to be a rich feeding ground for criminals.

If you insist on risking use of a social networking site, it might be a good idea to subscribe to a service that tracks your credit card actions as well as actions taken that relate to your credit rating. For example, you'd get an alert if someone was applying for a loan or credit card and using your credit record. And make sure to keep your Antivirus, AntiSpyware, and Firewall software up to date. You might also want to add prayer to the list. You may need it.

Wednesday, January 28, 2009

Be paranoid!

Be very wary of emails you did not expect to get and of any web pages they may link to. Just because an email or web page looks nice or is interesting or you are just plain curious is no reason to start clicking away.

A case in point is the recent malware that pretends to be about President Obama (or for you Irish folks, O'Bama). The Microsoft Malware Protection Center (MMPC) blog has more about this Waledac Trojan, including pictures of an email and the malicious web page.

Remember, it's perfectly OK to be paranoid -- the bad guys really out to get you!

Saturday, December 20, 2008

Infected web pages increase

During 2008, the rate at which the number of web pages infected with malicious software (malware) increased rose from one every 14 seconds to one ever 4.5 seconds. [See "Forecast: Security Threats for 2009"]

So what can you do?

  • Don't "assume" a web site is safe to visit.
  • Don't "assume" a link in an email is safe to click on.
  • Don't "assume" an email from a friend was really sent by them.
  • Use anti-phishing software, antivirus software, and anti-spam software.
  • Keep all your computer programs updated. If there is a security patch available for any of your programs, install the patch.
  • Use a program like Secunia's free Personal Software Inspector to check for program updates.
  • Use a program like Driver Detective to check for updates to program driver files.

Firefox less secure?

Firefox has often been touted as fundamentally "more secure" than Internet Explorer. If you have been led to believe that, you need to look at some cold, hard facts:
  • From March to September 2005 (yes, even as early as 2005), FireFox had 40 vulnerabilities to IE's 10. [ZDNet article]
  • From April through September 2005, the number of published Firefox exploits was 11 compared to IE's 6.
  • The most recent FireFox-related security problem is that some Russian criminals are using it to add malicious software as a "Plug-In". The malware detects when you connect to any of over 100 banks and then steals your account name and password, sending them to the criminals. [read the SC Magazine article]
  • In terms of vulnerability numbers reported in March 2008, Opera had the most, followed by Safari, FireFox, then Internet Explorer.

The biggest problem with malware is not the browser, it's the person using the browser. People are either too trusting of links and unknown sites or just think they will never get attacked.

Friday, November 28, 2008

Beware nasty Mebroot trojan

Beware of malware called Sinowal (also as Mebroot) captures bank and similar data. A gang of Internet criminals have been using this and even morphing the malware to temporarily fool antivirus software.

Windows Secrets contributing editor Woody Leonhard likens Mebroot to "a parasitic operating system that runs inside Windows". [Disclaimer: I subscribe to the paid version of "Windows Secrets" newsletter. Prior to that subscribed for years to the paid version of Fred Langa's "LangaList" newsletter, which is now integrated into Brian Livingston's "Windows Secrets" newsletter. I highly recommend Windows Secrets anyone concerned about or interested in PCs.]

Leonhard says that his experience is that a lot of systems get infected with Mebroot (Sinowal) because the owners did not keep up with Adobe Reader, Adobe Flash, or Apple Quicktime security patches. You can manually check for such patches, set the apps to automatically check for updates, or (even better), install the free Secunia Personal Software Inspector (PSI) and scan for programs that need updating.

In October 2008 Brian Krebs, Washington Post, alerted readers to the "virtual heist" going on. Mebroot infects the Master Boot Record (MBR) of your PC and sends personal data to its "owners". Krebs says that the criminals have stolen over half a million credit and debit card account in the past few years.

While Symantec lists the malware's risk as low, if your data gets stolen, it won't be a little thing to you. Here are some actions Symantec and I recommend to reduce your risk of malware infections:

  • Use a firewall
  • Enforce complex passwords for all users of your computer
  • Use the lowest level access privileges.
  • Never use an Administrator-level login account as your normal one. Always login as a lower level account and then "Runas" or login as the Administrator level only as needed. Vista security is a big advance in making this type security easier. Yes, you get pop-ups to login as Administrator, but that's much better than manually running a "runas" command and you don't need to know the runas command line syntax.
  • Disable Auto-play
  • Turn off "File Sharing"
  • Turn off and remove unnecessary system services
  • Always keep your programs patched (You can use the free Secunia PSI to monitor patch status)
  • Don't open email attachments unless you were expecting them. Contact the sender separately (not by a "Reply") and see if they really did send you that email and attachment.
  • Turn off Bluetooth via Windows Control Panel if you are not using it.
  • If you really need to use Bluetooth, make sure every Bluetooth device's visibility is set to "Hidden".

Saturday, October 20, 2007

Malicious emails contain fake Youtube link

US-CERT says that new variations of the Storm Worm have been appearing in email messages as fake YouTube video links.

The emails arrive with headers such as, "LOL, that is too cool..."

The email claims to be a video of you that has been discovered. The message contains a fake link to youtube.com. The link acually sends you to a malicious website that downloads and runs malware.

Thursday, September 27, 2007

Adobe Reader vulnerable

Adobe Reader has a serious vulnerability that could be exploited by a maliciously created PDF. The flaw could be exploited to take control of computers. So far, Adobe has no patch for it

Until this vulnerability is patched, do not open a PDF file you get unless it's from a trusted source and you were expecting the file.

If the source is trusted but the file unexpected, contact the sender before opening the PDF.

Wednesday, July 04, 2007

Microsoft Malware Protection Center

Microsoft offers a security portal page called "Microsoft Malware Protection Center". It lists and links to the top 10 most active malicious software families, most active family variants, most active email threats, and spyware/adware removed from PCs.

The site officially launches in "early July", but the links to threat information are already active.

Wednesday, April 11, 2007

Free Anti-Rootkit software

Rootkits are nasty buggers. Antivirus software doesn't detect them and they can be a bear to detect and destroy.

Now comes Anti-Rootkit Free from Grisoft, makers of AVG Antivirus Free Edition.

A test of the fast scan on a home computer took 10 minutes. The interface is attractive yet very simple to use.

Wednesday, January 24, 2007

Warning: Mailicious emails, web sites

A malicious bugger named Trojan.Peacomm is making the rounds. This nasty thing can hide its files and processes, making it quite hard to detect. It arrives:
  • As a file installed on your computer by other malware (malicious software) or
  • As a file you unwittingly download when visiting malicious URLs.
It is also currently arriving in email Spam, with the emails using subject lines related to specific events. A few example subject lines:

A killer at 11, he's free at 21 and kill again!
Naked teens attack home director.
230 dead as storm batters Europe.
Radical Muslim drinking enemies's blood.
Chinese missile shot down Russian satellite
Saddam Hussein alive!
Venezuelan leader: "Let's the War beginning".
Fidel Castro dead.

Be paranoid -- people really are out to get you!

Get more information at Symantec Security Response ...

Friday, November 24, 2006

Tis the season ... to be paranoid

It's OK to be paranoid if people really are out to get you. And that's the case with "greeting card" attacks. As the Christmas season nears, the number of attacks involving faked greeting cards rises.

The attack arrives in your inbox as a message (perhaps looking like it's from a friend) with a link to a "Greeting Card". If you click on the link, you may even see some sort of online greeting. But along with the greeting comes a Trojan. You have been attacked.

Prevention tips:
  • Don't open email messages from strangers
  • Don't assume a message from a friend is really from that person, especially if it has links or an attachment you didn't expect to receive.
  • If you get a message like above from a friend, send them a separate email and ask if they really sent the one with the link or attachment.
  • Don't "reply" to a suspicious message -- you could be replying to the attacker.
  • When in doubt, delete.

Friday, August 04, 2006

Fake Google toolbar spreads virus

Surf Control reports that computer hackers are now using a Google Toolbar look-alike application. The fake app tries to lure you into installing a malicious program. Be paranoid. Be very, very paranoid.