listen more to learn more.

Saturday, September 24, 2016

Xiny Android Trojans Can Infect System Processes

Mobile malware from the Xiny family of Android Trojans are capable of infecting the processes of system applications and of downloading malicious plug-ins into the infected programs, Doctor Web researchers warn.

These threats, researchers say, have been designed to download and delete various programs from the compromised systems, functionality that requires root privileges. Once they achieve the required privileges, the Trojans can silently download and install software onto devices, while also being capable of displaying annoying advertisements.
The Android.Xiny Trojans emerged in March 2015 and are being distributed through popular websites, and even official application stores. These malicious programs have an immutable APK file, an innovative mechanism for ensuring that the Trojan cannot be deleted, Doctor Webresearchers say.
The most recent improvement the Android.Xiny Trojans have received, however, is the ability to inject themselves into system applications, which allows them to launch various malicious plug-ins. One of the threats that includes this functionality is Android.Xiny.60, which extracts several malicious components (/xbin/igpi; /lib/igpld.so; /lib/igpfix.so; and/framework/igpi.jar) from its resource folder and copies them to system directories soon after installation.
The malware uses the igpi module (detected as Android.Xiny.61) to inject the igpld.so library (Android.Xiny.62) into the system application processes of Google Play (com.android.vending) and Google Play Services (com.google.android.gms, co.google.android.gms.persistent). Moreover, the malicious module can be injected into Android’s Zygote process, researchers say.
After infecting the Zygote process, Xiny.62 can track the launch of any new applications and can inject the igpi.jar malicious module (Android.Xiny.60) into them. The module is also injected in the system processes of Google Play and Google Play Services applications after they have been infected.
This modus operandi isn’t new, as it was previously observed being employed by the Triada Android Trojan detailed earlier this year. Because the Zygote process contains system libraries and frameworks that almost all apps use and is a template for each new app, and because it could enter this process, Triada was able to run in each application on the device.
The malicious igpi.jar module was designed to download plug-ins and launch them in the infected environment. It is also capable of sending various information about the device to the command and control (C&C) server: IMEI, IMSI, MAC address of the network adapter, OS version, mobile device model, current system language, and application package name.
The malicious plug-ins would work as part of the infected app, with disastrous results, depending on the infected process, researchers say. It can download the software-installation module into the Google Play process, can intercept and send messages when infecting a messenger, and can infect a banking program to “steal confidential information, such as logins, passwords, credit card numbers, etc., and even covertly transfer money to cybercriminal-owned bank accounts,”
The good news, researchers say, is that no distributions of these malware modules have been observed as of now. However, cybercriminals could create them at any time, which could result in massive attacks fueled by these Trojans.


DDoS Attacks Are Primary Purpose of IoT Malware

As the Internet of Things (IoT) market expands, the number of malware threats targeting the segment is rising as well. The ultimate goal for many of these IoT threats is to build strong botnets in order to launch distributed denial of service (DDoS) attacks, Symantec researchers say.

Compared to the record levels observed in 2015, when eight new malware families emerged, new IoT-focused malware appear to have decreased this year, although the security of IoT devices hasn’t improved much. These products are easy targets for cybercriminals and victims often don’t even realize they were infected.
IoT Malware Growth
Chart: New IoT malware families by year (Source:Symantec)
Although these attacks were initially predicted to target the user, it appears that cybercriminals are interested in something else: using hijacked devices as part of botnets to launch DDoS attacks against various targets. In fact, most of the malicious applications built to target IoT can either launch DDoS attacks or can download malware that includes the functionality.
Over the past several months alone, researchers detailed DDoS incidents involvingpowerful botnets of IoT devices, includingmassive sustained attacks against properties and organizations affiliated with the Olympics.Thousands of CCTV devices worldwide were abused in similar attacks, and malware families such as BASHLITE and Linux/Mirai were observed actively ensnaring CCTV cameras, home routers and other type of compromised devices into botnets.
Just this week, security blogger Brian Krebs said that his site had been targeted in an attack that peaked at 665 Gbps, which he believes was powered by an IoT botnet.
IoT Malware Power DDoS Attacks
According to Symantec, attacks that originate from multiple IoT platforms simultaneously might be observed in the future, mainly because more and more embedded devices are connected to the Internet. IoT malware, researchers say, mostly targets non-PC embedded devices, because they might not include advanced security features.
“Embedded devices are often designed to be plugged in and forgotten after a very basic setup process. Many don’t get any firmware updates or owners fail to apply them and the devices tend to only be replaced when they’ve reached the end of their lifecycle. As a result, any compromise or infection of such devices may go unnoticed by the owner and this presents a unique lure for the remote attackers,” Symantec says.
The security company also reveals that over one third of IoT attacks (34%) seen this year originated from China, with the United States following rather close at over one quarter of attacks (26%). Russia (9%), Germany (6%), and the Netherlands (5%) round up top five, followed by Ukraine, Vietnam, the United Kingdom, France, and South Korea (Symantec also admits that attackers might also use proxies to hide their real IP addresses).
IoT malware attempts to log into Internet-facing devices using pre-defined combinations of default usernames and passwords, the most common of which are “root” and “admin”. These combinations differ based on the targeted systems: when attacking Ubiquiti routers, the malware would use combinations of username: ubnt and password: ubnt, but it would switch to username: pi and password: raspberry combinations when targeting Raspberry Pi devices.
To infect IoT products, attackers scan for random IP addresses with open Telnet or SSH ports, when attempting to brute-force the device. Targeted platforms include x86, ARM, MIPS, and MIPSEL, and attackers compile their malware as cross-platform solutions, and even build variants for less used architectures, such as PowerPC, SuperH and SPARC.
“One interesting feature seen on a variety of IoT malware is the ability to kill other processes, specifically processes belonging to other known malware variants. In some older variants this feature might have been used just to eliminate the potential malware competitor from the infected device,” Symantec says. IoT malware might behave like this mainly to ensure the device’s resources aren’t used by other software.
Some of the most prevalent malware families targeting embedded devices includeLinux.Darlloz (aka Zollard), Linux.Moose, Linux.Pinscan / Linux.Pinscan.B (aka PNScan), and Linux.Wifatch (aka Ifwatch) –which don’t include DDoS capabilities –, along with Linux.Aidra / Linux.Lightaidra, Linux.Xorddos(aka XOR.DDos), Linux.Gafgyt (aka GayFgt, Bashlite) Linux.Ballpit (aka LizardStresser), Linux.Dofloo (aka AES.DDoS, Mr. Black), Linux.Kaiten / Linux.Kaiten.B (aka Tsunami), Linux.Routrem (aka Remainten, KTN-Remastered, KTN-RM), and Linux.LuaBot – which can launch various types of DDoS attacks.
Some of the threats that lack DDoS capabilities might still install DDoS-capable malware, researchers say. “DDoS attacks remain the main purpose of IoT malware. With the rapid growth of IoT, increased processing power in devices may prompt a change of tactics in future, with attackers branching out into cryptocurrency mining, information stealing, and network reconnaissance,” Symantec concludes.


Cybercriminals Developing Biometric Skimmers for ATM Attacks

Banks are improving ATM authentication mechanisms in an effort to prevent fraud, but cybercriminals have already started developing the tools and techniques they need to bypass these modern security systems.

In a report published on Thursday, Kaspersky Lab researchers analyze current and future ATM authentication systems and how they can be targeted by malicious actors.
One increasingly popular authentication method involves biometrics, which includes voice, fingerprint, iris pattern, palm geometry and facial recognition. Some major banks have already started rolling out such systems, including HSBC, which recently announced selfie-based identification, and Barclays, which introduced voice-based authentication. Asurvey commissioned by Visa shows that two-thirds of European consumers are ready to use biometrics for making payments.
However, cybercriminals are already working on ways to bypass biometric authentication and experts warn that there are certain disadvantages to this new system.
Biometric authentication can rely on information stored on a card or provided directly. In both cases, the information is first stored in a biometric database for comparison. One problem, according to Kaspersky, is that the more this biometric data is used, the more likely that it will get stolen and, unlike passwords, fingerprints and iris patterns cannot be changed easily if they are compromised.
Cybercriminals are also working on developing biometric skimmers that can be used to obtain the valuable data directly from individuals or from cards. Fraudsters could create special devices that can extract biometric data from stolen bank cards.
Another attack method involves mounting special skimmers on top of the ATM’s biometric reader to collect fingerprints or other data. Kaspersky said it’s aware of 12 manufacturers of fake fingerprint readers and three manufacturers of palm and iris recognition equipment.
According to the security firm, the first biometrical skimmers were made available for testing in September 2015 and a second wave is expected to hit the European Union at any moment. The first series of tests led to the discovery of various bugs, including the inefficiency of GSM modules for transferring the stolen data due to its size. Newer skimmers use other technologies for retrieving the stolen information.
Another way for cybercrooks to obtain biometric data is to steal it directly from the financial organization’s database. As shown by recent incidents, the networks of banks are often not as secure as they should be.
As in classic skimming operations, the stolen biometric data can be used directly or sold for a profit on the black market.
“In general, network-based attacks against ATMs will be a headache for the security personnel of financial organizations in the coming years simply because, based on our penetration testing experience, the network infrastructure of a bank is very often built in a way that a hacker can exploit to gain access and take control of some critical parts of the network, including the network of ATMs,” Kaspersky researchers explained in theirreport.
“And this situation is not going to change any time soon, due to many reasons, one of which is the sheer size of financial organizations’ networks and the time-consuming and expensive task of upgrading them,” they added.


Kosovo Hacker Linked to IS Group Gets 20 Years in U.S. Prison

A computer hacker who helped the Islamic State group by providing stolen personal data on more than 1,000 US government and military workers was sentenced Friday to 20 years in prison.

Ardit Ferizi, a 20-year-old citizen of Kosovo known by his hacking moniker "Th3Dir3ctorY," was sentenced in a US federal court in Virginia, the Justice Department said.
"This case represents the first time we have seen the very real and dangerous national security cyber threat that results from the combination of terrorism and hacking," said John Carlin, assistant attorney general for national security.
"This was a wake-up call not only to those of us in law enforcement, but also to those in private industry," his statement read.
Malaysian police arrested Ferizi in September 2015 on behalf of a provisional US arrest warrant. The suspect was extradited to the United States for prosecution.
The so-called "terrorist hacker" pleaded guilty in June in US court for his role in the IS group's targeting of US government personnel for attacks.
He admitted he had given hacked data to an IS member who posted a 30-page document on Twitter -- a virtual hit list containing names, email addresses, email passwords, locations and phone numbers for about 1,300 US military and other government personnel.
The Twitter message containing the document read: “NEW: U.S. Military AND Government HACKED by the Islamic State Hacking Division!”
"We are in your emails and computer systems, watching and recording your every move, we have your names and addresses, we are in your emails and social media accounts," the document said in part, according to the Justice Department.
"We are extracting confidential data and passing on your personal information to the soldiers of the (caliphate), who soon with the permission of Allah will strike at your necks in your own lands!"


Friday, September 23, 2016

Disaster Recovery: Confidence High, Experience Low

With everything moving to the cloud, it is little surprise that Disaster Recovery (DR) is now also offered as cloud-based DRaaS. The majority of organizations still employ on-premise DR, but cloud usage is growing. A new survey investigates how and why UK businesses are employing DR; how they rate their existing DR readiness, and whether they are considering a move to cloud.

An Opinion Matters survey, which questioned 250 IT decision makers, was commissioned by iland. iland is a US-based cloud infrastructure provider with eight data centers in the US, UK and Singapore. In Gartner's 2016 Magic Quadrant for DRaaS it was placed squarely among the leaders.
The majority of outages are still caused by system failure (reported by 53% of respondents) closely followed by human error (52%). Cyber attacks are relatively low in comparison at 32%, while environmental issues (flood, storm, fire and power outages) are even lower at 20%.
What is immediately apparent from the survey is that DR is a necessity rather than a luxury -- 95% of respondents admitted to an outage over the last 12 months. Beyond the clear implication of these figures (that an outage will almost certainly happen), things get a bit confused. Confidence is high, but experience is poor. Ninety-eight percent of respondents claimed that employees would have post-disaster access to systems within 24 hours, while 27% claim access would be immediate.
Experience, however, throws doubt over such claims. Confidence in a successful DR failover was only substantiated in 38% of cases. Fifty-eight percent of respondents experienced issues during a failover. Forty percent had been confident in the process -- but 30% experienced issues, and 10% experienced significant issues.
There seems to be a clear understanding of the business impact of an outage. Eighty-three percent of respondents would expect 'significant impact' from an outage lasting hours. However, 4% predict 'catastrophic impact' within seconds, 2% within minutes, and 7% within hours. The obvious conclusion from such figures is that organizations are over-confident in their ability to mitigate a critical incident through disaster recovery.
"In today's business world, the question is no longer if a company will need to trigger a disaster recovery plan, but when," said Justin Giardina, CTO at iland. "This study shows there is work to be done, as teams seem to put too much confidence into inadequately tested systems."
Training and testing is indeed another confused issue. Nearly two-thirds of respondents claim to have a trained team and regular testing -- and yet the issues continue. The remaining 37% have either lightly trained or untrained teams, while testing is infrequent or non-existent.
Needless to say, DRaaS removes or limits organizations' need for trained on-premise staff; so iland was particularly interested in reasons for companies not to move to a cloud solution. Nearly two-thirds of the on-premise users cited concerns over security and compliance as reasons to stay on-premise. These are indeed complex issues, but in many cases established cloud providers can provide improved security -- especially in areas of limited data use in the cloud. Compliance, especially with national or regional data protection laws, is also complex -- but Monica Brink, director EMEA marketing at iland, confirmed that iland always adheres to the local laws pertaining, and has its own experts continuously monitoring new developments (such as GDPR).
Without these hindrances, DRaaS becomes an attractive proposition. Brink told SecurityWeek that an increasing number of companies, both large and small, are beginning to adopt DRaaS. The reality is that cloud is now offering lower costs and the potential for almost zero downtime with greater ease, reliability and efficiency.

Yahoo Pressed to Explain Huge 'State Sponsored' Hack

Yahoo faced pressure Friday to explain how it sustained a massive cyber-attack -- one of the biggest ever, and allegedly state-sponsored -- allowing hackers to steal data from half a billion users two years ago. 

The US online giant said its probe concluded that "certain user account information was stolen" and that the attack came from "what it believes is a state-sponsored actor."
The comments come after a report earlier this year quoted a security researcher saying some 200 million accounts may have been accessed and that hacked data was being offered for sale online.
"Yahoo is working closely with law enforcement on this matter," said Yahoo, adding it believes data linked to at least 500 million user accounts was stolen -- in what could be the largest-ever breach for a single organization.
Yahoo said the stolen information may have included names, email addresses, birth dates, and scrambled passwords, along with encrypted or unencrypted security questions and answers that could help hackers break into victims' other online accounts.
While there is no official record of the largest breaches, many analysts have called the Myspace hack revealed earlier this year as the largest to date, with 360 million users affected.
In 2014 a US firm specialised in discovering breaches said that a Russian group has hacked 1.2 billion usernames and passwords belonging to more than 500 million email addresses.
The firm, Hold Security, gave no details of the companies affected by the hack.
Ammunition for hackers
Computer security analyst Graham Cluley said the stolen Yahoo data "could be useful ammunition for any hacker attempting to break into Yahoo accounts, or interested in exploring whether users might have used the same security questions/answers to protect themselves elsewhere on the web."
He noted that while Yahoo said that it believes the hack was state-sponsored, the company provided no details regarding what makes them think that is the case.
"If I had to break the bad news that my company had been hacked... I would feel much happier saying that the attackers were 'state-sponsored,'" rather than teen hackers, Cluley said in a blog post.
University of Notre Dame associate teaching professor and data security specialist Timothy Carone told AFP that the Yahoo hack fit the "big picture" when it comes to cyberattacks launched by spy agencies in Russia, China, North Korea or other countries.
"It just smacks of traditional trade craft," Carone said. Chinese hackers have been accused of everything from stealing corporate secrets to an enormous breach of US government personnel files that affected a staggering 21.5 million people and reportedly led Washington to pull its intelligence operatives out of China.
North Korea is known to operate an army of thousands of elite hackers accused of launching crippling cyber-attacks on South Korean organisations and officials over the years.
But it was the high-profile hacking attack on Sony Pictures in December 2014 that shed light on the growing threat of the North's hacking capability, although Pyongyang denied responsibility for the attacks.
It appeared that looted Yahoo data did not include unprotected passwords or information associated with payments or bank accounts, the Silicon Valley company said.
Yahoo is asking affected users to change passwords, and recommending anyone who has not done so since 2014 to take the same action as a precaution.
Users of Yahoo online services were urged to review accounts for suspicious activity and change passwords and security question information used to log in anywhere else if it matched that at Yahoo.
"Online intrusions and thefts by state-sponsored actors have become increasingly common across the technology industry," Yahoo said in a statement.
"Yahoo and other companies have launched programs to detect and notify users when a company strongly suspects that a state-sponsored actor has targeted an account."
Yahoo being bought
Confirmation of the major cyber breach comes two months after Yahoo sealed a deal to sell its core internet business to telecom giant Verizon for $4.8 billion, ending a two-decade run as an independent company. It was not immediately clear if the data breach could impact the closing of the deal or the price agreed by Verizon.
"Frankly, the timing couldn't be worse for Yahoo," Cluley said. The telecom firm said it was reviewing the new information. "Within the last two days, we were notified of Yahoo's security incident," Verizon said in a statement.
"We will evaluate as the investigation continues through the lens of overall Verizon interests, including consumers, customers, shareholders and related communities."

EFF Warns Police, Courts About Unreliability of IP Addresses

A report published this week by the Electronic Frontier Foundation (EFF) warns about the misuse of IP addresses by police and courts, and makes recommendations on how such information can be used efficiently.

An increasing number of incidents shows that law enforcement often considers IP addresses a clear indicator of a person’s location or identity. For instance, several privacy activists maintaining Tor exit nodes in their homes have been raided by law enforcement investigating child pornography and other crimes. Internet mapping services that provide a default location when only limited information is available has also caused problems for innocent individuals.
Another issue is that police often overstate the reliability of IP address information when trying to obtain a warrant or subpoena. According to the EFF, law enforcement also often uses inaccurate metaphors to explain IP addresses, such as comparing them to physical mailing addresses and license plates.
Some judges have begun to realize that an IP address is not enough to determine someone’s guilt. In one such case, a federal court in Oregon dismissed a direct copyright infringement complaint against an individual who allegedly pirated a movie.
However, there is more work to be done and the report published by the EFF aims to teach law enforcement and courts on how to reliably use IP information when investigating crimes. The organization pointed out that improper use of such data is especially risky when trying to determine someone’s identity or physical location.
The EFF has advised police to treat IP information the same as tips received from anonymous informants. When it gets information from an anonymous informant, law enforcement must also demonstrate probable cause in order to obtain a warrant. Digital rights advocates believe the same skepticism must also be applied by courts and police when provided with IP addresses.
“Law enforcement must be required to investigate further, including identifying other electronic or physical evidence that corroborates their theory that evidence of the crime is likely to be found at the physical location that is associated with a particular IP address,” the EFF said in its whitepaper. “And courts must be informed of the technological limitations of the evidence so that they can independently ensure that IP address information is reliable before authorizing law enforcement intrusion into individual privacy.”
For a more reliable use of IP information, police and judges should ensure that the link between an IP and a location is based on data from an Internet services provider – rather than a mapping service that could be pointing to a default location – and physical surveillance of the property.
As for tying an IP to an identity, law enforcement and courts should make sure that the IP is not associated with a home or organization where several people use the same Internet connection, and that the IP is not associated with servers used to operate the Tor anonymity network.

Related Reading: Kernel.org Hacking Suspect Arrested in Florida

Related Reading: Two Men Arrested in U.S. for Hacking Emails of Top Officials

Related Reading: Alleged Operators of DDoS Service Arrested in Israel

Popular Posts

Contact

anmol3886@gmail.com