Latest: Digital For Tech News Click Here


Showing posts with label infected. Show all posts
Showing posts with label infected. Show all posts

Wednesday, 9 April 2014

Most Sophisticated Android Bootkit Malware ever Detected; Infected Millions of Devices

0 comments

Most Sophisticated Android Bootkit Malware ever Detected; Infected Millions of Devices


Hardly two month ago we reported about the first widely spread Android Bootkit malware, dubbed as 'Oldboot.A', which infected more than 500,000 Smartphone users worldwide with Android operating system in last eight months, especially in China.Oldboot is a piece of Android malware that's designed to re-infect Mobile devices even after a thorough cleanup. It resides in the memory of infected devices;  It modify the devices’ boot partition and booting script file to launch system service and extract malicious application during the early stage of system’s booting.Yet another alarming report about Oldboot malware has been released by the Chinese Security Researchers from '360 Mobile Security'. They have discovered a new variant of the Oldboot family, dubbed as 'Oldboot.B', designed exactly as Oldboot.A, but new variant has advance stealth techniques. Especially, the defense against with antivirus software, malware analyzer, and automatic analysis tools. "The Oldboot Trojan family is the most significant demonstration of this trend." researchers said.Oldboot.B, Android Bootkit malware has following abilities:It can install malicious apps silently in the background.It can inject malicious modules into system process.Prevent malware apps from uninstalling.Oldboot.B can modify the browser's homepage.It has ability to uninstall or disable installed Mobile Antivirus softwares.


INFECTION & INSTALLING MORE MALWARE APPSOnce an Android device is infected by Oldboot.B trojan, it will listen to the socket continuously and receive and execute commands received from the attacker's command-and-control server.Malware has some hidden ELF binaries, that includes steganographically encrypted strings, executable codes and configuration file downloaded from C&C server, located at az.o65.org (IP is 61.160.248.67).After installation, Oldboot Trojan install lots of other malicious android applications or games in the infected device, which are not manually installed by the user.Oldboot.B architecture includes four major Components, those automatically executes during the system startup by registering itself as a service in the init.rc script:Most Sophisticated Android Bootkit Malware ever Detected; Infected Millions of Devices1) boot_tst - uses remote injection technique to inject an SO file and a JAR file to the 'system_server' process of the Android system, continuously listen to the socket, and execute commands sent.Most Sophisticated Android Bootkit Malware ever Detected; Infected Millions of Devices2) adb_server - replaces pm script of Android system with itself and used for anti-uninstallation functionality.Most Sophisticated Android Bootkit Malware ever Detected; Infected Millions of Devices3) meta_chk - update the configuration file, download and install Android Apps promoted in the background. The Configuration file is encrypted, that greatly increases the time required to analyze.To evade detection, meta_chk destroys itself from the file system, and left with only the injected process. Android Antivirus software does not support the process memory scan in the Android platform, so they cannot detect or delete the Oldboot Trojan which resides in the memory.Most Sophisticated Android Bootkit Malware ever Detected; Infected Millions of Devices4) agentsysline - module written in C++ programming language, run as a daemon in the background to receive commands from command-and-control server. This component can uninstall anti-virus software, delete the specific files and enable or disable network connection etc.Most Sophisticated Android Bootkit Malware ever Detected; Infected Millions of DevicesPROBLEMS FOR SECURITY RESEARCHERSTo increase the problem of malware analyzers:It add some meaningless code and trigger some behavior randomly.Check for SIM card availability in the device, and it will not perform certain behavior if there is no SIM card to fool sandbox or emulators.Check for the existence of antivirus software, and may uninstall the anti-virus software before doing anything malicious.Malware uses the steganography techniques to hide its configuration file into images:Most Sophisticated Android Bootkit Malware ever Detected; Infected Millions of Devices


"But after some analysis, we found that the configuration of meta_chk is hidden in this picture, which contains the command will be executed by meta_chk and other information." researchers said. The size of this configuration file is 12,508 bytes."Depending on the commands sent from the C&C server, it can do many different things, such as sending fake SMS messages or phishing attacks, and so on. Driven by profit, the Oldboot Trojan family changes very fast to react to any situation."Oldboot.B is one of the most advanced Android malware that is very difficult to remove, but antivirus firm 360 Mobile Security also released Oldboot detection and removing tool for free, you can download it from their website.To avoid infection, Smartphones users should only install apps from trusted stores; make sure the Android system setting 'Unknown sources' is unchecked to prevent dropped or drive-by-download app installs; don't use untrusted custom ROMs and install a mobile security app.

Continue reading →

Dumb Ransomware Developer leaves Decryption Keys on Infected Computers

0 comments

Dumb Ransomware Developer leaves Decryption Key on Victim System


So, How do Hackers compromise a Website? Simply by exploiting the flaws in it, that means they took advantage of the error in the developers’ code. Now, this time the hackers itself has left behind a crucial flaw in its malware code which can be exploited by us to help save our computer systems.Believe me, it’s not an April Fools’ joke! A malicious software program that holds the victims’ computer files hostage by wrapping them with strong encryption until the victim pays a ransom fee to get them decrypted, has a critical flaw in its malware code itself that it leaves the decryption key on the victim’s computer.The Anti-virus firm Symantec examined a sophisticated malware program dubbed as CryptoDefense (Trojan.Cryptodefense) ransomware, which appeared in the end of the last month.CryptoDefense is one of the complex malware programs that include a number of effective techniques, including Tor anonymity tool usage and Bitcoin digital currency to extort money from victims. CryptoDefense uses Microsoft’s infrastructure and Windows API to generate the encryption and decryption keys, the antivirus firm wrote on its blog.CryptoDefense encrypts files using public-key cryptography, a strong RSA 2048 encryption in order to ensure files are held to ransom and transmits the private key in plain text back to the attacker’s server, so that as soon as the ransom amount is paid by the victim, the attacker will release the private keys to decrypt the files.


So, if once the files have been encrypted, without access to the private key, victims will not be able to decrypt the files. But here they stumbled, the CryptoDefense’ developer failed to realize that the private key is also left concealed on the user’s computer in a file folder with application data.“Due to the attacker’s poor implementation of the cryptographic functionality they have, quite literally, left their hostages a key to escape,” Symantec wrote.Despite the dumb mistake of the malware developer, it is not sure that it will left the users untouched, because some technical skills is required to figure out the decryption keys.


Dumb Ransomware Developer leaves Decryption Key on Victim System


CryptoDefense is been sent out as spam emails, or masquerade itself as a PDF file and once installed in the system, it attempts to communicate with either of the four domains and uploads a profile of the infected machine, the firm wrote.The Cyber Criminals demand either $500 or €500 that has to be paid within four days and if victim doesn't pay the ransom in the given time frame, the ransom doubles itself.According to the firm, it is estimated that the cybercriminals received more than $34,000 worth of Bitcoin in just a month, which shows the effectiveness of their scam.Symantec said it has blocked 11,000 unique CryptoDefense ransomware infections in more than 100 countries, with the majority of the infection attempts are noticed in the U.S. followed by the U.K., Canada, Australia, Japan, India, Italy and the Netherlands.

Continue reading →

Wednesday, 26 March 2014

Operation Windigo: Linux malware campaign that infected 500,000 Computers Worldwide

0 comments
Operation Windigo: Linux malware campaign that infected 500,000 Computers WorldwideIn late 2013, Security Researchers identified thousands of Linux systems around the world infected with the OpenSSH backdoor trojan and credential stealer named Linux/Ebury, that allows unauthorized access of an affected computer to the remote attackers.Antivirus Firm ESET's Reseacher team has been tracking and investigating the operation behind Linux/Ebury and today team uncovers the details [Report PDF] of a massive, sophisticated and organized malware campaign called 'Operation Windigo', infected more than 500,000 computers and 25,000 dedicated servers.
'We discovered an infrastructure used for malicious activities that is all hosted on compromised servers. We were also able to find a link between different malware components such as Linux/Cdorked, Perl/Calfbot and Win32/Glupteba.M and realized they are all operated by the same group.' ESET reported.Malware used in Operation Windigo:Linux/Ebury – an OpenSSH backdoor used to keep control of the servers and steal credentials.Linux/Cdorked – an HTTP backdoor used to redirect web traffic. We also detail the infrastructure deployed to redirect traffic, including a modified DNS server used to resolve arbitrary IP addresses labeled as Linux/Onimiki.Perl/Calfbot – a Perl script used to send spam.The Group behind the attacks may have been active since December 2012, using a modified version of OpenSSH, an open source alternative to proprietary Secure Shell Software (SSH) to infect thousands of servers and desktop computers, apparently, stole user credentials on system and SSH private keys for outgoing SSH connections.
"According to our analysis, over 25,000 servers have been affected over the last two years. More than 10,000 of them are still infected today." ESET reported, "using the Linux/Ebury OpenSSH backdoor"
Hackers have accessed a wider range of compromised machines, used them to redirect half of a million web visitors to malicious websites and abusing the server bandwidth to send more than 35,000,000 spam messages per day. If victim will use a Smartphone to surf the malicious link from Spam mails, they will be redirected to Porn sites, with the intention of making money.
High-profile Targets: Report listed some affected high profile servers and companies, including cPanel (famous web hosting control panel) and Linux Foundation’s kernel.org (main repository of source code for the Linux kernel).
Operation Windigo: Linux malware campaign that infected 500,000 Computers WorldwideESET Researchers collaborated with CERT-Bund, the European Organization for Nuclear Research (CERN), the Swedish National Infrastructure for Computing and other agencies to fight against this malware campaign.Affected Operating systems include Linux, FreeBSD, OpenBSD, OS X, and even Windows (with Perl running under Cygwin) and affected countries are US, Germany, France, Italy, Great Britain, Netherlands, Russian Federation, Ukraine, Mexico and Canada.
How to Check, if you have been compromised? If you use only 'ssh -G' command, a clean server will print: 'ssh: illegal option -- G', but an infected server will only print the usage.

Administrators can use the following UNIX/Linux command to check:

$ ssh -G 2>&1 | grep -e illegal -e unknown > /dev/null && echo "System clean" || echo "System infected"
If your system or server was also compromised in the same campaign, it's recommended to re-install the system or re-set all passwords and private OpenSSH keys.Follow me on Google+, Twitter or Facebook or Contact via Email.

View the original article here

Continue reading →
 
Copyright © 2013 MyBloggerBlog Template All Right Reserved
Designed by MyBloggerBlog | Powered by Blogger