Showing posts with label Trojan. Show all posts
Showing posts with label Trojan. Show all posts

Sunday, December 15, 2019

Trend Micro warns of Trickbot’s updated password-grabbing module targeting more apps, services

Researchers from Trend Micro’s Security Intelligence have reported on a sudden increase of Trickbot’s activities in Japan, and Trend Micro researchers have found updates to the password-grabbing (pwgrab) module and possible changes to the Emotet variant that drops Trickbot.

Trickbot has been one of the most active banking trojans in 2019. The malware is constantly being improved with new and updated modules, and the threat actors behind it are still churning out new ones. Previous Trickbot reports involved behavior that compromises services and platforms to collect credentials from browser, Outlook, WinSCP, and FileZilla. 


Trend Micro’s latest report of changes to its pwgrab module found additional credential-stealing capabilities for remote access applications such as remote desktop protocol (RDP), virtual network computing (VNC), and PuTTY platforms. 

The most recent iterations (detected by Trend Micro as TrojanSpy.Win32.TRICKBOT.TIGOCER) targeted a slew of credentials from TeamViewer, OpenSSH, OpenVPN, Git, KeePass Password Manager, SSH private key files, SSL certificate files, and Bitcoin wallet files.

Due to its modular nature, Trickbot can and will surely morph into something more in order to add to its features, and cybercriminals will surely look into other possible iterations to make a profit. 


To address this challenge, enterprises can look into sourcing third-party security services offering managed detection and response (MDR), such as Trend Micro Managed XDR, which offers a wide scope of visibility and expert security analytics by integrating detection and response functions across networks, endpoints, emails, servers, and cloud workloads. Organizations will have access to the whole knowledge base of Trend Micro, including prior analysis of other Trickbot variants and other similarly sophisticated threats.

Moreover, enterprises can benefit from security technology that employs a multilayered approach to mitigate the risks brought by threats like Trickbot. 

Trend Micro XGen security provides a cross-generational blend of threat defense techniques to protect systems from all types of threats, including banking trojans, ransomware, and cryptocurrency-mining malware. It features high-fidelity machine learning on gateways and endpoints, and protects physical, virtual, and cloud workloads. 


With capabilities like web/URL filtering, behavioral analysis, and custom sandboxing, XGen security protects against today’s threats with various capabilities: bypassing traditional controls; exploiting known, unknown, or undisclosed vulnerabilities; or stealing or encrypting personally identifiable data. Smart, optimized, and connected, XGen security powers Trend Micro’s suite of security solutions.

Friday, December 13, 2019

Kaspersky reports that malware variety grew by 13.7 percent this year, driven by surge in web skimmers

The number of unique malicious objects detected by Kaspersky’s web antivirus solution rose by 13.7 percent this year, compared to last year, reaching 24,610,126. The growth was mainly influenced by a 187 percent rise in web skimmer files. 

Other threats, such as backdoors and banking Trojans detected in-lab, also grew, while the presence of miners dropped by more than half. These trends demonstrated a shift in the type of threats used by attackers on the web, who search for more effective ways to target users, according to the new Kaspersky Security Bulletin: Statistics of the Year report.


In 2018, unique malicious objects (including scripts, exploits and executable files) detected by Kaspersky’s web antivirus solution totaled 21,643,946, rising to 24,610,126 this year. The growth reflects an increase in the number and variety of HTML pages and scripts with hidden data loading – usually used by unscrupulous advertisers. Yet, most notably, the growth was also partially caused by online skimmers, sometimes referred to as sniffers, where scripts are embedded by attackers in online stores and used to steal users’ credit card data from websites.

The growth of online skimmers’ unique files (scripts and HTML) detected by Kaspersky web antivirus equaled 187 percent, reaching 510,000. At the same time, the number of threats detected by web antivirus has risen five-fold (by 523 percent), totaling 2,660,000 in 2019. 

Web skimmers also entered the top 20 malicious objects detected online, taking 10th place in the overall ranking. The share of new backdoors and banking Trojan files, among all types of threats detected in-lab, also grew by 134 percent and 61 percent to reach 7,644,402 and 739,551 respectively.

Nevertheless, the number of unique malicious URLs detected by Kaspersky web antivirus fell by half (50.5 percent) in comparison to 2018, from 554,159,621 to 273,782,113. This shift was largely caused by significant decrease of hidden web miners, even though several detections related to them (including Trojan.Script.Miner.gen, Trojan.BAT.Miner.gen, Trojan.JS.Miner.m), can still be seen in the top 20 web malware threats.


The presence of programs that secretly generate cryptocurrency on users’ computers (called ‘local’ miners) has also been steadily declining over the year. The number of users’ computers affected by attempts to install miners dropped by 59 percent, from 5,638,828 to 2,259,038.

Eighty-five percent of web threats were detected as malicious URL. This detection name is used to identify links from Kaspersky’s black list. It includes links to web pages containing redirects to exploits, sites with exploits and other malicious programs, botnet command and control centers, extortion websites, and others.

“The volume of online attacks has been growing for years, but in 2019 we saw a clear shift from certain types of attacks that are becoming ineffective, to the ones focused on gaining clear profit from users,” said Vyacheslav Zakorzhevsky, head of anti-malware research at Kaspersky. “This is partly due to users becoming more aware of the threats and how to avoid them, and organizations steadily becoming more responsible. A good example is miners, which have lost their popularity due to lower profitability and cryptocurrencies’ fight against covert mining. This year we also witnessed growth in zero-day exploits, showing products remain vulnerable and are used by attackers for sophisticated attacks, and this trend is likely to continue in the future.”

Friday, December 6, 2019

Kaspersky shockingly finds that ransomware is now targeting back-up data

Kaspersky researchers identified on Thursday a new type of ransomware attack, Network Attached Storage (NAS), which is actively growing in popularity. Targeting NAS poses new risks for back-up data usually stored on devices. With NAS largely perceived as a secure technology, users often remain unprepared for the possibility of infection, putting their data at higher risk.

Encryption ransomware is a malware that applies advanced encryption methods so files cannot be decrypted without a unique key. This leaves the infected device owner stuck with a locked device and a demand to pay a ransom in order to regain access to files. 


While users are typically infected with ransomware via email or exploit-kits planted on websites, the new type of attacks on NAS devices use a different vector. Ransomware operators scan ranges of IP addresses looking for NAS devices accessible via the web. 

Although only web interfaces protected with authentication are accessible, a number of devices have integrated software with vulnerabilities in it. This allows attackers to install a Trojan using exploits, which will then encrypt all data on the devices connected to the NAS.


During the third quarter this year, Kaspersky products detected and repelled encryption ransomware attacks on 229,643 Kaspersky products users, which is 11 percent less than during the same period last year. Although the total number of affected users slightly decreased, the report shows that the number of new encryption ransomware modifications grew from 5,195 in the third quarter of last year to 13,138 in the third quarter this year marking 153 percent growth. This development signals cybercriminal interest in this type of malware as means of enrichment.

At the same time, the infamous WannaCry Trojan family retained first place among the most popular Trojans with over a fifth of attacked users having been targeted with malware identified as belonging to this group. 


The top three most popular verdicts that account for almost half of users attacked by cryptors were Trojan-Ransom.Win32.Wanna (20.96 percent users attacked), Trojan-Ransom.Win32.Phny (20.01 percent) and Trojan-Ransom.Win32.GandCrypt (8.58 percent).

Tuesday, December 3, 2019

Kaspersky releases its financial threat predictions for 2020, as fintech, mobile banking and e-commerce are likely to intensify

According to Kaspersky experts, financially motivated cyberthreat actors may start to target investment apps, online financial data processing systems and upcoming cryptocurrencies in 2020. Additionally, experts predict they may offer paid access to banks’ infrastructures and develop new strains of mobile banking malware based on leaked source code.

Financial cyberthreats are considered to be some of the most dangerous, as their impact usually results in direct financial losses for victims. 2019 has seen some significant developments in the industry and also in how financial attackers operate. 


These events allowed Kaspersky researchers to suggest several important potential developments for the financial threat landscape for 2020. 

Fintech is under attack. Mobile investments apps have become more popular among users around the globe, and this trend won’t go unnoticed by cybercriminals in 2020. Not all of these apps utilize best security practices, like multi-factor authentication or protection of the app connection, which may give cybercriminals a potential way to target users of such applications

Kaspersky research and monitoring of underground forums suggests that the source code of some popular mobile banking Trojans was actually leaked into the public domain. Previous similar cases of malware source code leakage such as Zeus and SpyEye that resulted in an increased number of new variations of these Trojans. In 2020 this pattern may repeat.


In 2020, Kaspersky experts expect an increase in the activity of groups specialised in criminal-to-criminal sale of network access to banks in the African and Asian regions, as well as in Eastern Europe. Their prime targets are small banks as well as financial organizations recently bought by big players who are rebuilding their cybersecurity system in accordance with the standards of their parent companies. it is also expected that the same banks may become victims of targeted ransomware attacks, as banks are among those organizations that are more likely to pay a ransom than accept the loss of data.

Magecarting 3.0 features more cybercriminal groups will target online payment processing systems. Over the past couple of years, so-called JS-skimming (the method of stealing of payment card data from online stores) has gained immense popularity among attackers. 

Currently, Kaspersky researchers are aware of at least 10 different actors involved in these type of attacks and experts believe that their number will continue to grow during the next year. The most dangerous attacks will be on companies that provide services such as e-commerce as-a-service, which will lead to the compromise of thousands of companies.


“This year has been one of many important developments,” says Yuriy Namestnikov, a security researcher at Kaspersky. “Just as we predicted at the end of 2018, it has seen the emergence of new cybercriminal groups like CopyPaste, new geography of attacks by Silence group and cybercriminals shifting their focus to data that helps to bypass antifraud systems in their attacks. Behavioral and biometrics data is on sale on the underground market. Additionally, we expected JS-skimmer base attacks to increase and they did. With 2020 on the horizon, we recommend security teams in potentially affected areas of the finance industry to gear up for new challenges. There is nothing inevitable in potential upcoming threats, it is just important to be properly prepared for them.”

In addition to financial sector, Kaspersky researchers identified other industries that will face new security related challenges in the upcoming year, such as the healthcare industry is advised to focus on protecting medical records and connected medical devices, as they are becoming the target of threat actors. 

Corporate security teams should pay more attention to cloud infrastructure and also to addressing growing risks of insiders accessing their networks. There are groups of criminals specializing on recruiting insiders through various techniques, including blackmail. 

Telecommunications and other industries that vastly use cellular communications should be prepared to assess and address risks that will come with wider adoption of 5G, which is expected to start in 2020. 

Monday, December 2, 2019

Kaspersky research confirms that cybercriminals have been stealing guests’ credit card data from hotels worldwide

Kaspersky’s research of the RevengeHotels campaign has confirmed that over 20 hotels in Latin America, Europe and Asia have fallen victim to targeted malware attacks. As a result, travelers’ credit card data, which is stored in a hotel administration systems including those received from online travel agencies (OTAs), is at risk of being stolen and sold to cybercriminals worldwide.

The RevengeHotels campaign includes different groups using traditional Remote Access Trojans (RATs) to infect businesses in the hospitality sector. The campaign has been active since 2015 but has increased its presence in 2019. At least two groups, RevengeHotels and ProCC, were identified to be part of the campaign, however more cybercriminal groups are potentially involved.


The main attack vector includes emails with crafted malicious Word, Excel or PDF documents attached. Some of them exploit CVE-2017-0199, loading it using VBS and PowerShell scripts. It then installs customized versions of various RATs and other custom malware, such as ProCC, on the victim’s machine that could later execute commands and set up remote access to the infected systems.

Each spear-phishing email is crafted with special attention to detail. The emails impersonate real people from legitimate organizations who make a fake booking request for a large group of people. 

It is worth noting that even careful users could be tricked to open and download attachments from such emails as they include an abundance of details (for instance, copies of legal documents and reasons for booking at the hotel) and looked convincing. The only detail that would reveal the attacker would be a typosquatting domain of the organization.

Once infected, computers can be accessed remotely, and not just by the cybercriminal group itself. Evidence collected by Kaspersky researchers shows that remote access to hospitality desks and the data they contain is sold on criminal forums on a subscription basis. 

Malware collected data from hospitality desk clipboards, printer spoolers and captured screenshots (this function was triggered using specific words in English or Portuguese). As hotel personnel often copied clients’ credit card data from OTA’s in order to charge them, this data could also be compromised.

Kaspersky telemetry confirmed targets in Argentina, Bolivia, Brazil, Chile, Costa Rica, France, Italy, Mexico, Portugal, Spain, Thailand and Turkey. However, based on data extracted from Bit.ly, a popular link shortening service used by the attackers to spread malicious links, Kaspersky researchers assume that users from many other countries have at least accessed the malicious link, suggesting that the number of countries with potential victims could be higher.


“As users grow wary of how protected their data truly is, cybercriminals turn to small businesses, which are often not very well protected from cyberattacks and possess a concentration of personal data,” said Dmitry Bestuzhev, head of global research and analysis team for Kaspersky Latin America. “Hoteliers and other small businesses dealing with customer data need to be more cautious and apply professional security solutions to avoid data leaks that could potentially not only affect customers, but also damage hotel reputations as well.”

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...