Posts

Showing posts with the label Computer Security

RIPlace Evasion Technique exploits Windows 10 and antiviruses

Image
Ransomware attacks are getting common nowadays. The ability to change a few lines of code and emulate the same ransomware with different names makes it a deadly weapon for hackers. A similar process known as RIPlace Evasion technique was discovered by leading security researchers at the endpoint protection firm Nyotron. This method is effective against devices that run the latest computer security solutions and updated system patches. Read on to know more about this advanced ransomware technique . How does the RIPlace Evasion Technique Work? RIPlace Evasion technique was discovered by Cybersecurity experts in Nyotron around the spring of 2019. During that time, this new ransomware bypass method was not taken seriously since it was not being used for Ransomware attacks . However, the whole process is catastrophic for computing devices. Here is how it works: Almost all ransomwares function by opening and reading the files. Then the files are encrypted and th...

Dharma ransomware Variant Hit Garage of Canadian Domain Registration Authority

Image
A recent  Cyber attack on a parking garage  used by the  Canadian Internet Registration Authority  (CIRA) made evident that even strangest of the places can be attacked by  Ransomware . This Cyber Attack on parking lot allowed people to park their vehicles for free after CIRA’s systems were infected by the Ransomware. Computer Security researchers asserted that the ransomware responsible for this strange incidence is a variant of the   Dharma Ransomware  family, renowned to  infect computers  that have exposed their Remote Desktop Services on the net. Insight into the Attack on CIRA Canadian Internet Registration Authority (CIRA) is a  non-profit organization  that represents the Canadian domains on an international level & manages the . CA country code top-level domain  (ccTLD). The parking garage of CIRA is maintained by  Precise Parklink , Automated Parking revenue Control System to  verify people ente...

127 Million Stolen User Databases Put on for Sale on Dream Market

Image
The ever-growing advancements in technology have intriguingly transformed human’s life & turned everything digital. However, the pacing advancements have also paved a way for an  increase in the purloin of social media & bank records  and their sale in the Dream Market, the Dark Web app. One such Data Breach incidence was brought to light earlier this week wherein  620 million user accounts  were stolen from over  16 companies  and sold at colossal  20,000 US Dollars in Bitcoin . The individual selling records stolen from the latest data breach goes by the name of Gnosticplayers. Surprisingly, the same seller has now put up another hefty batch of  127 million users accounts  holding their origin from  8 distinct companies  on sale on the Dream Market Marketplace. The total selling amount set by the individual for the entire collection of 127 million accounts is  $14,500 in bitcoin . DREAM MARKET Dream Market r...

How to Remove BlackRouter Ransomware?

Image
Ransomware attacks continue to dominate the cyber security landscape this year, with businesses paying millions of dollars to unlock encrypted files. Research reveals that almost 40% of successful malware based attacks involve Ransomware. Moreover, when it comes to Ransomware & its distribution, the threat intelligence strategy is not much needed making it popular among threat actors. The world has seen its fair share of Ransomware attacks- the  WannaCry  being the deadliest of all. Ransomware is a ubiquitous security threat with one aim- extract payments from victims. Its impact continues to be significant with global organizations held to ransom every day. There are many variants of Ransomware with new strains appearing with regularity denying users access to important files until ransom is paid. Recently researchers discovered a new Ransomware called BlackRouter being promoted as a Ransomware-as-a-service in a hacking channel on telegram by an Iranian Developer. Ori...

Android Nemesis MobSTSPY goes global via Google Play

Image
An Android Spyware disguised as games & utilities struck more than 100,000 victims in 196 countries before being taken out of Google Play. Detected as  ANDROIDOS_MOBSTSPY  & dubbed  MobSTSPY,  the malware initially grabbed attention when it was masqueraded as a called  Flappy Birr Dog . While it is common to find unarmed goods in third party app stores,  MobSTSPY  managed to infiltrate the authentic & reliable App Store i.e. Google Play with at least six different apps in 2018. These apps include: FlashLight, HZPermis Pro Arabe, Win7imulator, Win7Launcher, and Flappy Bird Flappy Birr Dog These apps pose as legitimate & claim to be torches, games & tools for productivity. Some of these have seen 10,000 download from users around the world. Though malware invasion in devices is common, but what makes this case more interesting is the widespread distribution of its applications. Among the countries where the malware is sca...

Ryuk Ransomware attack cripples major Newspaper publications in the US

Image
Ryuk ransomware is believed to be the culprit behind the impeded printing & delivery of major newspaper publications in the United States i.e.  Los Angeles Times and Tribune Publishing. The malware attack on Tribune Publishing’s software systems was discovered on 28 th  December 2018. The abuse on the software delayed weekend distribution of the newspaper & affected Tribune publications throughout the country. Among the publications affected include: Baltimore Sun, Capital Gazette, Chicago Tribune, Hartford Courant, Wall Street Journal, New York Times, Carroll County Times, Lake County News-Sun, the South Florida Sun Sentinel & Post-Tribune. The  Los Angeles Times & San Diego Union-Tribune  that were formerly part of Tribune Publishing newspapers were also slammed by the Ransomware. The print editions of the affected newspapers were published on Saturday without obituary section & paid classified ads according to the publications. The...

How to Remove JungleSec Ransomware?

Image
Guide to Remove Junglesec Ransomware JungleSec is the new name of a  Ransomware  virus that is infecting victims through an  unsecured IPMI cards  (Intelligent Platform Management Interface) from early November. This treacherous malware has been created by cyber criminals with the sole motive of swindling innocent users & minting shady money. Once the system is infected by this perilous Junglesec Ransomware, it  encrypts files & stipulates a ransom  of several hundred dollars from the user. The prime operating system targeted by it is Linux. Junglesec, an encryption Ransomware  Trojan  was first detected by the PC security researchers on 19 th June 2018. They revealed that Junglesec Ransomware is a  variant of HiddenTear Ransomware , an open-source encryption Ransomware program released in 2015. This threat was initially meant for educational purposes; however criminals skillfully adapted it to  execute harmful attacks , ...

BMW Lottery Email Scam is Back – This time it is M240i

Image
Claim Your Car and Check with your Winning Code Does the subject of the email appeal you? If yes, then you surely are clueless of  Email scams . Falling for an email scam is something that can happen to anyone. It’s a frightening concept & often results in undiluted panic. Crafted to appear legitimate, fraudulent emails disguise renowned banks or other trusted sources with the main motive being to yank user’s chain. A recent instance of hoax emails compel users to provide their  full name, address & mobile numbers  in lieu to winning a free 2018 BMW 2 Series M240i . The  BMW Lottery Scam  tricks you to think that you have won a BMW car. However, users are required to reply to the email with the personal information it demands to claim the prize. A reply to the email may appear secure & healthy; however, it definitely entraps users in an array of negatives. It is not uncommon that threat actors may reply to the email to seek more informa...

User Account Timeline Manipulation overlooked by Facebook!

Image
A Polish security researcher & analyst with the Twitter username ‘Lasq’ revealed that the Social Media Giant, Facebook is afflicted by  Clickjacking Bug , which automatically add  spam links  on the Facebook user’s wall. The security professional discovered a technique used by miscreant & used Bug bounty program to submit the report to the company. According to the resources, the ongoing Spam Campaign on Facebook seems to have a prolonged life as Facebook has denied dismissing Clickjacking Bug because it does not alters the state of the account. Behavior of Clickjacking Bug The Polish security expert began to analyze the Spam Campaign on Facebook after he observed many of his friends broadcasted a link to a website with amusing pictures. The Facebook users had to confirm that they were at least 16 years old before they could access humorous content. Once the user clicks on the button, he will be  redirected to a page  with amusing &  c...

Microsoft security update released: Internet Explorer RCE Zero-Day vulnerability patched

Image
Microsoft’s bequest browser, Internet Explorer, may compel you to reboot your PC soon. The remote code execution  IE Zero-day  vulnerability in Internet explorer scripting engine allows threat actors to  execute arbitrary code in the context of the user . Manipulators who successfully exploited the  IE Zero-day  vulnerability could leverage security privileges of the logged in user & execute malevolent code to corrupt system memory. In other words, if you are logged on with administrative user rights, this vulnerability could be exploited to take full control of an affected system. Threat actors can leverage this opportunity to: Deploy malicious code on user’s system. Install malicious programs. View, change, or delete data Create new accounts with full user rights This  Zero-day vulnerability  is tracked as  CVE-2018-8653  & can further be exploited in the following ways: In Web-based scenarios,  attackers coul...

Office 365 stung by Email Phishing

Image
Phishing email campaigns are a renowned tool that is prominently used by the cyber phishing criminals. They keep sending phishing email tenaciously with the hope of reeling potential victims in their pitched net. These opportunistic cyber phishing criminals never cease to craft e-mails & websites that look legitimate ones. Perceiving the illicit or fake message can be strenuous task to a non-technical eye. Imagine a careless click on a phishing mail can let the cyber criminals take over your entire Office 365 account. Yes, a recently discovered Email phishing Scam professing as Office 365 Non-Delivery Notification is being used by the scammers to steal user’s login credentials by redirecting them to a malignant page. This new Office 365 Phishing attack was brought to light by ISC Handler Xavier Mertens. Insight in to New Office 365   Phishing attack Xavier Mertens, the security researcher, says that the Email phishing Scam was discovered while he was reviewing the lates...

Google+ – The Titanic got second Iceberg!

Google’s semi-obsolete Social Network platform, Google+, is in the negative spotlight again as it has exposed personal information of around 52.5 million Google+ users second time this year! Google+ has suffered this ruinous Data Breach for a record second time in consecutive three months. The Tech Giant, Google said in a blog post on Monday that software amendments introduced to Google+ in November 2018 had a bug enclosed in Google+ People API. The Large spread of this Bug in Google+ took place in form of an update released by Google making them the evil eye. Insight in to First Pernicious Data Breach of Google+ This Internet-based Social Network was launched by Google in June 2011 in order to serve as a social spine for different services of Google like Adwords and YouTube. Google integrated distinct unique features to Google+ in order to make it stand out of the crowd of popular social networking services. Alas, the fame of Google+ & Google’s efforts to hike up Google+ wen...

Quora Falls to Cyber Attack

Image
Quora, the renowned open platform & question-and-answer website, reported that a data breach may have compromised data of around  100 million Quora users . The real culprit behind this Quora data breach is a malevolent third party that gained unauthorized access to one of Quora’s systems on 30 th  November 2018. Quora in Action Adam D’Angelo, co-founder & CEO of Quora, reacted to the incident & said that Quora is investigating to find the precise causes of this catastrophe and retained an elite digital forensic firm to assist them. In addition to that Adam informed that the company is logging out & unplugging Quora users who may have been impacted by this security breach to prevent any further damage to Computer Security. The company is notifying users with relevant & important details via e-mail & urging them to change the passwords. A FAQ list about Quora data breach has been set up by the company which can be referred to by Quora users. W...

Dell Systems under Radar of Information Stealers

Image
Technological advancements have made the world a great and convenient place to live in.  There is no denying the fact of how the evolution of technology has made our lives easier. Today’s world is to a great extent shaped by innovations made possible by computer science. The incredible speed, accuracy & storage offered by computers have human life faster and efficient. The present global age is the consequence of the computer age. However, too much reliability on computers is the major downside of this empowering invention. The world today is experiencing a global change in the way people live and their lifestyles. Dependence on computers for everything has led to a drastic decline in the ability of a person to think, make decisions, their reasoning abilities & memory. Over the past decade, the web has been embraced by millions of businesses as an inexpensive channel to communicate and exchange information with prospects and transactions with customers. No wonder we...

Online JavaScript Library’s Popularity utilized in stealing Cryptocurrency

Image
A widely used Node.js code library listed in NPM’s warehouse of repository has been infected to include crypto-coin-stealing malware. npm is the most widely used package manager for Javascript programming language. It is the default package manager for an open source, cross platform JavaScript run-time environment Node.js. The library in question, Event-Stream, is a popular Javascript library that scores over two million downloads every week by application programmers. The projects that use event-stream in some way should undergo a thorough check to ensure that you didn’t install and fetch the dodgy version during testing or deployment. This vandalism is a stark reminder of dangers associated with reliable and complex webs of dependencies in software. Without proper precautions taken throughout the whole chain, an app’s security can be broken by modifying any component. The Event-Stream npm package was originally created & maintained by Dominic Tarr, a New-Zeland base...

Now VLC site Under the Radar!

Image
VideoLan.org is the official website for downloading famous VLC media player, VLMC & other professional & developer projects. This popular website is displaying a ruinous warning in Bing, an internet search engine which is owned & operated by Microsoft. The warning is displayed when users hover the cursor over the first hyperlink on the page:  VLC media player – Official Site . It states “ Site might be dangerous ” followed by another baleful warning that “ it could lead you to malicious software that can harm your device ”. VLC media player is a renowned free, open-source & portable media server that is capable of playing almost all multimedia files & DVDs, VCDs & Audio DCs. This cross-platform multimedia player is widely used by people from all over the world as it is free & available for desktop operating systems & mobile platforms like Android, Windows, iOS & Tizen. In addition to that, it can be downloaded from any digital dist...

Active XSS injection campaigns attack WP WordPress Plug-in

Image
WordPress (WP) is by far the most popular open source  Content management system  (CMS) used by approximately  75 million websites . The ease to deploy and upgrade this free tool makes it popular among web- savvy users and web- novices alike. Whether it’ a commercial site or a personal blog, the fact that WordPress doesn’t charge a penny makes it a preferable tool among people. The compatibility and flexibility of Word Press to host thousands of plugins and templates gives it an edge over its contemporaries. However, the popularity of this tool among users has made this popular tool a lucrative target among threat actors. Recent research reveals that vulnerability in a high profile WordPress plugin that is installed on more than 100,000 sites has come under active exploitation.   The vulnerability discovered in the popular AMP (Accelerated Mobile Pages) for WP plugin allows any registered user to perform administrative actions on a WordPress site. What is A...

Google Services- lost in transit or lost in translation?

Image
According to a News report by the Wall Street Journal, some of the web services provided by the internet Giant Google were temporarily unavailable for nearly 2 hours on 12thNovember 2018. The users trying to reach Google Services were rerouted to a sinuous path through operators existing in Russia, China and Nigeria. A Google spokesman wrote that a portion of web traffic was impacted due to incorrect routing of IP addresses, and passage to Google Services was affected. The issue was resolved at 2:35 pm on Monday and services began to operate as expected. However, the root cause of BGP Traffic Hijacking was external to Google and what exactly happened remains obscure. The issue was first noticed by a network monitoring company, ThousandEyes, when they could not connect to Google’s G suite & incorrect routing instructions redirected them to Russian network operator TransTelekom, China Telecom & Nigerian Network provider, MainOne. The issue became crucial when the entire w...

Infowars Store Affected by Magecart Credit Card Stealing Hack

Image
Magecart credit card skimming attack Ever wondered what it takes to get scammed @ Infowars store? Nothing! Absolutely Nothing! Customers facing Scams is an everyday facade here! A recently discovered attack at Infowars web site involves a new tactic. A malware embedded in the conspiracy site’s checkout process records customer’s credit card details and transmits them to threat actor’s remote servers. In today’s golden age of online shopping, people usually prefer to receive products at their doorsteps by punching in credit card details in ecommerce websites. Threat actors leverage this lucrative opportunity to yank the chain of innocent consumers by unethical means. Consumers remain unaware of the fact that the well-known & vetted websites that they blindly rely on can swindle them of their hard earned money. What is Magecart? Attacks on websites with the purpose of stealing user financial details are not new. Magecart credit card skimming attack has been recent...

HookAds Malvertising Uses Fallout Exploit Kit to Distribute Malware

Image
Another HookAds Malvertising Campaign has been reported to be active recently, which is redirecting the potential visitors to the Fallout Exploit Kit. Following the activation, the kit will strive to capitalize on the known susceptibilities in Windows to download & install malicious malware in the infected system. The malign malware include DanaBot banking  Trojan , GlobeImposter  Ransomware  and the Nocturnal information & data stealer. Insight in HookAds Malvertising Campaign The HookAds Malvertising Campaign acquires contemptible ad space on cheap quality ad networks that are commonly used by online games sites, adult web sites or blackhat SEO Sites. These pernicious ads include JavaScript that redirects the innocent visitors through a string of tempting sites. One such enticing site was discovered last week by Exploit Kit Expert nao_sec. The sites resemble the pages filled with online games, local advertisements or other low quality pages. Unawar...