Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Friday, April 12, 2013

SECURITY - Online Gaming Firms Targeted by Malware

"'Winnti' Malware Targeting Online Gaming Firms" by Chloe Albanesius, PC Magazine 4/12/2013

News of game-related hacks are nothing new; they have dominated headlines in recent years, from the massive Sony PlayStation Network takedown to the more recent hack of The War Z.

Attacks on gaming firms might not be isolated incidents, however.  Researchers at Kaspersky Lab this week said they uncovered a series of targeted attacks originating in China that are taking aim at Web-based gaming companies.

"According to our estimations, this group has been active for several years and specializes in cyber attacks against the online video game industry," Kaspersky said in a blog post.  "The group's main objective is to steal source codes for online game projects as well as the digital certificates of legitimate software vendors.  In addition, they are very interested in how network infrastructure (including the production of gaming servers) is set up, and new developments such as conceptual ideas, design and more."

Kaspersky started investigating the group - known as Winnti - in the fall of 2011 at a behest of a computer game publisher that detected malware on its network.  The malware was pushed out to users via a standard update, prompting concern that the company was spying on its users.

"However, it later became clear that the malicious program ended up on the users' computers by mistake; the cybercriminals were in fact targeting the companies that develop and release computer games," Kaspersky said.

Once installed on someone's computer, the hackers could control that machine without the user's knowledge.  The malware was "the first time we saw Trojan applications for the 64-bit version of Microsoft Windows with a valid digital signature," Kaspersky said.  Previous incidents of digital signature abuse had only hit 32-bit systems.

The digital certificate in question belonged to South Korea-based KOG, which also produced MMPRG, like Kaspersky's client.  Ultimately, the certificate was revoked, but "over the next 18 months we discovered more than a dozen similar compromised digital certificates."

Kaspersky said that its research suggests that at least 35 companies from around the world have been infected by Winnti malware at some point in time, with a "strong focus" on Southeast Asia.

Friday, December 9, 2011

SECURITY - Pentagon Seeks Hacker Help

"Pentagon asks hackers for help with cyber security" by Joseph Straw, Daily News 11/8/2011

The Pentagon agency that invented the Internet is asking the hacker community for help in eliminating Defense Department computer vulnerabilities.

The Defense Advanced Research Projects Agency, or DARPA, hosted a meeting this week for defense stakeholders and civilian computer experts, acknowledging that it has to start thinking differently about cyber security, Wired.com reported.

And the computer networks that run U.S. infrastructure are so vulnerable to cyber attack that the White House should think twice before even attacking emerging adversaries, a national security expert said.

Richard Clarke, who advised ex-Presidents Bill Clinton and George W. Bush, added that U.S. defense networks are "as porous as a colander."

Their Goliath scale leaves them especially vulnerable to tiny attacks, the Associated Press and Wired reported.

Clarke, who claims his early 2001 warnings to the Bush administration about the emerging threat of Al Qaeda went unheeded, issued the new warnings as tensions escalate between the U.S., Israel and their shared adversary Iran.

Last month Wired reported that a mundane virus called a key logger - one that surreptitiously records keyboard typing - was found on the computers used to remotely pilot Air Force drones targeting terrorists overseas.

In 2009 national security officials disclosed that Russian and Chinese agents had penetrated the U.S. electric grid and left behind software to help map the systems.

Monday, July 11, 2011

MALWARE - Rootkit Threat to NTFS Loader

I'm posting this because of the high danger of this type of malware.

"New Rootkit Infects NTFS Loader" by Lucian Constantin, Softedia 7/6/2011

Security researchers from Kaspersky Lab have identified a new piece of malware which writes malicious code to the NTFS boot loader.

The threat which Kaspersky detects as Cidox, features two rootkit drivers, one for 32-bit versions of Windows and one for 64-bit ones.

As part of its infection routine Cidox determines the version of the operating system and copies the relevant driver to the empty sectors at the beginning of the drive.

It only infects NTFS partitions and determines the active one by looking at the MBR code. It then proceeds to replace the Extended NTFS IPL (Initial Program Loader) code. The original one is encrypted and saved at the end.

This is part of a special technique that leverages Windows kernel features to load the malicious driver into the system.

The driver has the purpose of hooking into several processes including svchost.exe, iexplore.exe, firefox.exe, opera.exe and chrome.exe via a special DLL.

"This library modifies any browser output, substituting it with its own. As a result, the user sees a browser window displaying an offer to renew the browser due to some malicious programs allegedly detected on the system," Kaspersky's Vyacheslav Zakorzhevsky explains.

This threat is effectively a form of scareware, as the user is asked to pay for the browser renewal by sending an SMS message to a premium rate number.

In order to appear more convincing, there are custom pages for each browser borrowing design elements from other official ones displayed by their developers.

This is one of the most sophisticated scareware threats currently in the wild, but at the moment it only appears to target Russian-speaking users.

It seems that malware authors are increasingly using advanced techniques. One of the most dangerous threats at the moment, the TDL4 rootkit, infects the MBR (master boot record) in order to hide itself.

NOTE: Although I could NOT find the exact references to "Trojan-Dropper.Win32.Cidox" stated in the Zakorzhevsky article, Microsoft Malware Protection Center had the following references:

Note the Softedia article says "new" but I found references to NTFS Loader threats, at several virus sites, back in 2009.

Friday, February 11, 2011

SECURITY - NSS Labs Report

Anti-Virus Utilities will never stop all malware. It's a race between protection software/hardware and publishers of malware.

The reason I'm posting this old article reference, there is a Newsnet post that quotes an Inquirer article, but the article did NOT provide links to NSS Labs source. Which is why The Inquirer is NOT a creditable source on this subject.

"NSS Labs Finds Most Endpoint Security Products Lack Vulnerability-Based Protection" Report NSS Labs 3/12/2010

Excerpt

NSS Labs, Inc., the leading independent security testing organization, today announced the results of its evaluation of seven popular consumer endpoint security products in protecting the vulnerability exploited in the recent “Operation Aurora” attack conducted against Google and at least 30 other organizations. This test—the first of its kind in the industry—was designed to identify which products truly shielded the underlying Microsoft Windows Internet Explorer vulnerability (CVE-2010-0249) against additional attack variants. Products that defended the vulnerability versus simply stopping a single variant or its malicious payload are considered to have a more effective security model.

In its Austin, Texas facility, NSS Labs created variants of the Operation Aurora attack and tested the anti-malware software to see which of the seven products stopped the exploits and malicious code payloads. Given the level of visibility of the attack and the time that has passed since its initial discovery, it was thought that most, if not all, of the products would cover the vulnerability. However, only one out of seven tested products correctly thwarted multiple exploits and payloads, demonstrating vulnerability-based protection (McAfee).

"Generally, there are multiple ways to successfully exploit a vulnerability," said Rick Moy, president of NSS Labs. “This test case underscores the need for IT security vendors to provide greater vulnerability-based protection. Rather than reactively blocking individual exploits or malware, vendors should focus on minimizing their customers’ risk of exposure by insulating the vulnerability.”

Products tested included:
  • AVG Internet Security, version 9.0.733

  • ESET Smart Security 4, version 4.0.474.0 (see caution below)

  • Kaspersky Internet Security 2010, version 9.0.0.736

  • McAfee Internet Security 2010 with SecurityCenter, version 9.15.160

  • Norton Internet Security 2010, version 17.0.0.136

  • Sophos Endpoint Protection for Enterprise - Anti-Virus version 9.0.0

  • Trend Micro Internet Security 2010, version 17.50.1366.0000

A full report of the test and its findings is available here. Additionally, Vikram Phatak, CTO of NSS Labs will be discussing the test and demonstrating the Operation Aurora exploit on March 13, 2010 at BSidesAustin, to be held at Norris Conference Centers.

COMMENT:
  • I do NOT recommend "Security" nor "Internet" suites for home users because they tend to be resource hogs

  • I DO recommend a good Antivirus, that is not part of a suite

  • At home on my WinXP SP3 desktop system I use ESET NOD32 Antivirus 4, which is very fast, uses little resources; and includes Antivirus, anti-Trojan, anti-spyware protection.

CAUTION: ESET recently came out with ESET NOD32 Antivirus 5 and since I could "upgrade" for free, I tried it. In the next 5 days after upgrading I had problems I never had before, and my system became unstable. I was using the same settings I had for NOD32 Av 4. I did try changing settings. But after 5 days of instability, I uninstalled NOD32 Av 5 and reinstalled NOD32 Av 4. My system is back to being stable.

With NOD32 Av 5 I noted from its look-and-feel, that is likely written with Win7 in mind. I suspect that ESET did not fully test Av 5 on a Win XP system.

Friday, August 27, 2010

PC SECURITY - Windows DLL Exploits

"Windows DLL exploits boom; hackers post attacks for 40-plus apps" by Gregg Keizer, ComputerWorld 8/25/2010

Excerpts

Publish exploits to subvert Firefox, Chrome, Word, Photoshop, Skype, dozens more

Some of the world's most popular Windows programs are vulnerable to attacks that exploit a major bug in the way they load critical code libraries, according to sites tracking attack code.

Among the Windows applications that are vulnerable to exploits that many have dubbed "DLL load hijacking" are the Firefox, Chrome, Safari and Opera browsers; Microsoft's Word 2007; Adobe's Photoshop; Skype; and the uTorrent BitTorrent client.

"Fast and furious, incredibly fast," said Andrew Storms, director of security operations for nCircle Security, referring to the pace of postings of exploits that target the vulnerability in Windows software. Called "DLL load hijacking" by some, the exploits are dubbed "binary planting" by others.

On Monday, Microsoft confirmed reports of unpatched vulnerabilities in a large number of Windows programs, then published a tool it said would block known attacks. The flaws stem from the way many Windows applications call code libraries -- dubbed "dynamic-link library," or "DLL" -- that give hackers wiggle room they can exploit by tricking an application into loading a malicious file with the same name as a required DLL.

If attackers can dupe users into visiting malicious Web sites or remote shares, or get them to plug in a USB drive -- and in some cases con them into opening a file -- they can hijack a PC and plant malware on it.

Even before Microsoft described the problem, published its protective tool, and said it could not address the wide-ranging issue by patching Windows without crippling countless program, researcher HD Moore posted tools to find vulnerable applications and generate proof-of-concept code.
----
Until patches are available, Microsoft has urged users to download the free tool that blocks locks DLLs from loading from remote directories, USB drives, Web sites and an organization's network.

CAUTION - Make sure you understand this MS tool BEFORE loading. If you are NOT SURE, just wait until "patches" (Microsoft Updates) come through.

Needless to say, if you are running a top-of-the-line Antivirus/Antispyware Utility, they should protect you already.