Showing posts with label browser. Show all posts
Showing posts with label browser. Show all posts

Sunday, December 15, 2019

Trend Micro warns of Trickbot’s updated password-grabbing module targeting more apps, services

Researchers from Trend Micro’s Security Intelligence have reported on a sudden increase of Trickbot’s activities in Japan, and Trend Micro researchers have found updates to the password-grabbing (pwgrab) module and possible changes to the Emotet variant that drops Trickbot.

Trickbot has been one of the most active banking trojans in 2019. The malware is constantly being improved with new and updated modules, and the threat actors behind it are still churning out new ones. Previous Trickbot reports involved behavior that compromises services and platforms to collect credentials from browser, Outlook, WinSCP, and FileZilla. 


Trend Micro’s latest report of changes to its pwgrab module found additional credential-stealing capabilities for remote access applications such as remote desktop protocol (RDP), virtual network computing (VNC), and PuTTY platforms. 

The most recent iterations (detected by Trend Micro as TrojanSpy.Win32.TRICKBOT.TIGOCER) targeted a slew of credentials from TeamViewer, OpenSSH, OpenVPN, Git, KeePass Password Manager, SSH private key files, SSL certificate files, and Bitcoin wallet files.

Due to its modular nature, Trickbot can and will surely morph into something more in order to add to its features, and cybercriminals will surely look into other possible iterations to make a profit. 


To address this challenge, enterprises can look into sourcing third-party security services offering managed detection and response (MDR), such as Trend Micro Managed XDR, which offers a wide scope of visibility and expert security analytics by integrating detection and response functions across networks, endpoints, emails, servers, and cloud workloads. Organizations will have access to the whole knowledge base of Trend Micro, including prior analysis of other Trickbot variants and other similarly sophisticated threats.

Moreover, enterprises can benefit from security technology that employs a multilayered approach to mitigate the risks brought by threats like Trickbot. 

Trend Micro XGen security provides a cross-generational blend of threat defense techniques to protect systems from all types of threats, including banking trojans, ransomware, and cryptocurrency-mining malware. It features high-fidelity machine learning on gateways and endpoints, and protects physical, virtual, and cloud workloads. 


With capabilities like web/URL filtering, behavioral analysis, and custom sandboxing, XGen security protects against today’s threats with various capabilities: bypassing traditional controls; exploiting known, unknown, or undisclosed vulnerabilities; or stealing or encrypting personally identifiable data. Smart, optimized, and connected, XGen security powers Trend Micro’s suite of security solutions.

Thursday, December 12, 2019

Kaspersky finds zero-day exploit in Windows OS used in targeted attack, part of malicious WizardOpium operation

Kaspersky automated detection technologies have found a Windows zero-day vulnerability. The exploit based on this vulnerability allowed attackers to gain higher privileges on the attacked machine and avoid protection mechanisms in the Google Chrome browser. The newly discovered exploit was used in the malicious WizardOpium operation.

Zero-day vulnerabilities are previously unknown bugs in software, which, if found by criminals first, enable them to operate unnoticed for an extended period of time, inflicting serious and unexpected damage. Regular security solutions do not identify the system infection nor can they protect users from a yet-to-be-recognized threat.


The new Windows vulnerability was found by Kaspersky researchers as a result of a separate zero-day exploit. In Nov 2019, Kaspersky’s Exploit Prevention technology, which is embedded in most of the company’s products, detected a zero-day exploit in Google Chrome. 

This exploit allowed attackers to execute arbitrary code on a victim’s machine. Upon further research of this operation, which the experts called ‘WizardOpium,’ another vulnerability was discovered, this time in Windows OS.


It emerged that the newly discovered Windows zero-day elevation of privileges (EoP) exploit, CVE-2019-1458, was embedded into a previously discovered Google Chrome exploit. It was used to gain higher privileges in the infected machine as well as to escape the Chrome process sandbox – a component built to protect the browser and the victim’s computer from malicious attacks.
  
Detailed analysis of the EoP exploit showed that the abused vulnerability belongs to the win32k.sys driver. The vulnerability could be abused on the latest patched versions of Windows 7 and even on a few builds of Windows 10 (new versions of Windows 10 have not been affected).


“This type of attack requires vast resources. However, it gives significant advantages to the attackers and, as we can see, they are happy to exploit it,” said Anton Ivanov, security expert at Kaspersky. “The number of zero-days in the wild continues to grow and this trend is unlikely to go away. Organizations need to rely on the latest threat intelligence available at hand and have protective technologies that can proactively find unknown threats such as zero-day exploits.”

Saturday, December 7, 2019

Trend Micro reveals that Magecart group sets sights on Smith & Wesson, other high-profile stores

Trend Micro announced this week that the infamous credit card-skimming group Magecart has struck again. After incidents in the past few months that saw the threat actor go after customers of online shops and hotel chains, the group has set its sights on a new set of targets: high-profile stores, including firearms vendor Smith & Wesson (S&W).


According to security researcher, Willem de Groot of Sanguine Security, threat actors took advantage of the Black Friday rush by injecting credit card skimmers into the sites of a number of high-profile stores such as S&W. The group behind the attack injected the skimmer into S&W’s website on Nov. 27 — a couple of days before Black Friday, most likely in anticipation of the high volume of traffic going to the website. Note that the skimmer has been removed from the S&W store as of the time of writing.

The skimmer features an impressive list of capabilities, such as reverse engineering, a three-stage loader, and multiple layers of JavaScript obfuscation to hide its tracks. When a user visits the compromised website, the command-and-control (C&C) server initially sends harmless code — up until the actual payment process, when the skimmer begins its malicious routine. 


To make the skimming attack look more legitimate, a fake payment confirmation code is presented to the user. Behind the scenes, however, malicious code is already running, sneakily exfiltrating customer data such as payment information to the C&C server.

Sanguine Security notes that these attacks only worked for users which met various criteria, including using U.S.-based IP addresses, using non-Linux-based browsers, and not using the AWS platform.

The rise of Magecart highlights the need for vendors and other organizations to properly secure their websites and applications. Data theft via an attack such as the ones regularly performed by Magecart can mean monetary losses, not only for customers but also for the company whose website or application was compromised, especially given the potentially steep fines meted out to violators of data privacy laws such as the General Data Protection Regulation (GDPR).  


Organizations can minimize the chances of compromise by consistently applying the newest patches and updates to the software they use and by shoring up the authentication mechanisms provided to customers. Furthermore, it is recommended that IT and security teams proactively monitor their websites for any sign of malicious activities, such as unauthorized access or data exfiltration.

Tuesday, November 26, 2019

Kaspersky reports that fraudulent browser push notifications as a means of phishing and advertising are gaining popularity

Kaspersky research revealed that the monthly number of affected users has grown from 1,722,545 in January to 5,544,530 in September 2019. In total, during the first nine months of 2019, Kaspersky products protected more than 14 million users from attempts to allow websites to show unwanted notifications. Given that essentially every web user is a potential victim, this threat, although unsophisticated, requires additional attention.



Browser push notifications were introduced several years ago as a useful tool that kept readers informed with regular updates, but they are often used to bombard website visitors with unsolicited advertisements or even encourage them to download malicious software. 


The detected options include passing subscription consent off as another action, such as a CAPTCHA; switching the “accept” and “decline” buttons on subscription alerts mid-action; showing notifications from phishing copies of popular websites; and showing fraudulent subscribe pop-ups on websites.


Useful, user-friendly features, such as push notifications, are easy-to-use instruments for scams based on social engineering techniques, and therefore their growing popularity is not entirely unexpected. In light of the recent calendar invitations scam detected by Kaspersky, the company’s experts decided to dive deeper into push notification scams and phishing to find out how this tool can be abused.



Since a user’s consent is required in order to start sending notifications, attackers have come up with multiple, often out-of-the-box ways to trick and force people to sign up for subscriptions. 


To avoid receiving annoying notifications or scam ads, users can where possible, block all subscription offers, unless they come from popular and trusted websites, and be vigilant to ensure that they are not redirected to a fake website. If the user is unable to avoid an unwanted subscription, block it in the browser settings.


Adoption of a reliable security solution, like Kaspersky Security Cloud, which blocks ad and scam push subscription offers in browsers, can delete subscriptions that have already been approved, and has an anti-phishing feature.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...