Posts

Showing posts with the label InfoSec

RIPlace Evasion Technique exploits Windows 10 and antiviruses

Image
Ransomware attacks are getting common nowadays. The ability to change a few lines of code and emulate the same ransomware with different names makes it a deadly weapon for hackers. A similar process known as RIPlace Evasion technique was discovered by leading security researchers at the endpoint protection firm Nyotron. This method is effective against devices that run the latest computer security solutions and updated system patches. Read on to know more about this advanced ransomware technique . How does the RIPlace Evasion Technique Work? RIPlace Evasion technique was discovered by Cybersecurity experts in Nyotron around the spring of 2019. During that time, this new ransomware bypass method was not taken seriously since it was not being used for Ransomware attacks . However, the whole process is catastrophic for computing devices. Here is how it works: Almost all ransomwares function by opening and reading the files. Then the files are encrypted and th...

127 Million Stolen User Databases Put on for Sale on Dream Market

Image
The ever-growing advancements in technology have intriguingly transformed human’s life & turned everything digital. However, the pacing advancements have also paved a way for an  increase in the purloin of social media & bank records  and their sale in the Dream Market, the Dark Web app. One such Data Breach incidence was brought to light earlier this week wherein  620 million user accounts  were stolen from over  16 companies  and sold at colossal  20,000 US Dollars in Bitcoin . The individual selling records stolen from the latest data breach goes by the name of Gnosticplayers. Surprisingly, the same seller has now put up another hefty batch of  127 million users accounts  holding their origin from  8 distinct companies  on sale on the Dream Market Marketplace. The total selling amount set by the individual for the entire collection of 127 million accounts is  $14,500 in bitcoin . DREAM MARKET Dream Market r...

Dell Systems under Radar of Information Stealers

Image
Technological advancements have made the world a great and convenient place to live in.  There is no denying the fact of how the evolution of technology has made our lives easier. Today’s world is to a great extent shaped by innovations made possible by computer science. The incredible speed, accuracy & storage offered by computers have human life faster and efficient. The present global age is the consequence of the computer age. However, too much reliability on computers is the major downside of this empowering invention. The world today is experiencing a global change in the way people live and their lifestyles. Dependence on computers for everything has led to a drastic decline in the ability of a person to think, make decisions, their reasoning abilities & memory. Over the past decade, the web has been embraced by millions of businesses as an inexpensive channel to communicate and exchange information with prospects and transactions with customers. No wonder we...

Online JavaScript Library’s Popularity utilized in stealing Cryptocurrency

Image
A widely used Node.js code library listed in NPM’s warehouse of repository has been infected to include crypto-coin-stealing malware. npm is the most widely used package manager for Javascript programming language. It is the default package manager for an open source, cross platform JavaScript run-time environment Node.js. The library in question, Event-Stream, is a popular Javascript library that scores over two million downloads every week by application programmers. The projects that use event-stream in some way should undergo a thorough check to ensure that you didn’t install and fetch the dodgy version during testing or deployment. This vandalism is a stark reminder of dangers associated with reliable and complex webs of dependencies in software. Without proper precautions taken throughout the whole chain, an app’s security can be broken by modifying any component. The Event-Stream npm package was originally created & maintained by Dominic Tarr, a New-Zeland base...

Now VLC site Under the Radar!

Image
VideoLan.org is the official website for downloading famous VLC media player, VLMC & other professional & developer projects. This popular website is displaying a ruinous warning in Bing, an internet search engine which is owned & operated by Microsoft. The warning is displayed when users hover the cursor over the first hyperlink on the page:  VLC media player – Official Site . It states “ Site might be dangerous ” followed by another baleful warning that “ it could lead you to malicious software that can harm your device ”. VLC media player is a renowned free, open-source & portable media server that is capable of playing almost all multimedia files & DVDs, VCDs & Audio DCs. This cross-platform multimedia player is widely used by people from all over the world as it is free & available for desktop operating systems & mobile platforms like Android, Windows, iOS & Tizen. In addition to that, it can be downloaded from any digital dist...

Infowars Store Affected by Magecart Credit Card Stealing Hack

Image
Magecart credit card skimming attack Ever wondered what it takes to get scammed @ Infowars store? Nothing! Absolutely Nothing! Customers facing Scams is an everyday facade here! A recently discovered attack at Infowars web site involves a new tactic. A malware embedded in the conspiracy site’s checkout process records customer’s credit card details and transmits them to threat actor’s remote servers. In today’s golden age of online shopping, people usually prefer to receive products at their doorsteps by punching in credit card details in ecommerce websites. Threat actors leverage this lucrative opportunity to yank the chain of innocent consumers by unethical means. Consumers remain unaware of the fact that the well-known & vetted websites that they blindly rely on can swindle them of their hard earned money. What is Magecart? Attacks on websites with the purpose of stealing user financial details are not new. Magecart credit card skimming attack has been recent...

Tesla Backs Up Car Security Firmware

Image
Tesla is an American based automotive and Energy Storage company founded in 2003. This Multi National Corporation specialises in designing, manufacturing and selling electric cars, battery products and electric vehicle power train components. The sole motive of this premium electric-car brand is to accelerate world’s transition to sustainable energy and move towards zero- emission future. Tesla is renowned worldwide for its security-aware attitude. The infamous hardware and firmware manufacturer is known to focus on improving the security of their products and service offerings. Taking the security advantage to the next level, Tesla recently disclosed its safety and protection guidelines. As per the disclosed guidelines, Tesla Backs Up Car Security Firmware. The manufacturer of the infamous electric vehicles welcomes researchers to probe software in its cars for security bugs. Directives for Engagement  The participating researchers need to register themselves as wel...

Abandoned Domains Susceptible to Identity Thefts

Image
Do you aspire to take your unbeknownst website to the top level of Fame? Do you seek Internet presence for your business or organization? Do you yearn to add credibility to your online business and give it a unique identity? Successful registration of a domain name for your website can add a feather to its cap. Domain names now days are deemed as online real estate. It is considered vital to have an online presence for your business to flourish to new heights. It provides a platform for the potential customers to make successful business transactions without worrying about the limitations that would have restrained them otherwise. The geographic location is considered to be one of these limitations. There shouldn’t be any denial to the fact that Domain name designs and business growth go hand in hand! Technically a domain name cannot be bought forever. Based on the Domain registration and web hosting company, you can register a domain for up to 10 years. When a domain nam...

How to Get Rid of Dharma Cmb Ransomware?

Image
Guide to Remove Dharma Cmb Ransomware Once again infamous Dharma ransomware hits the headlines with its new variant. This new cmb extension variant of Dharma ransomware is all set to begin an immeasurable  infection campaign. This detrimental  ransomware family was first discovered by Michael Gillespie when he noticed samples uploaded to  ID Ransomware . ID Ransomware  is a website that enables victims identify  the ransomware that has encrypted their files. The Identification is done with specialized  techniques. This includes assessing: The ransom note that victims upload in the website. Modified file name patterns of the encrypted files This cmb  variant of Dharma ransomware encrypts the system files and appends the infected file name with  .cmb extension . The entire format of the extension appears as  .id-[id].[email].cmb . For instance, a file called  Happy.jpg  after encryption would be renamed as  H...

Brazilian Banks in a fix: Hackers Exploiting DLink Routers to Redirect Users to Fake Brazilian Banks

Image
Hackers have adopted a clever approach to swindle users of their hard earned money without letting them have a slightest clue. The loopholes in the DLink DSL modem routers have been ingeniously leveraged by cyber miscreants to deceive users. Let us check the process of handling user based queries & requests for web pages and routines over internet after we get acquainted with the following terms: DSL (Digital Subscriber Line): High Speed digital data transfer between servers and systems using telephone lines. DNS Server (Domain Name System ): It is a service on multiple servers  to resolve the browsing URL that the user inputs to IP (Internet Protocol) Addresses where the website is found. Let us now proceed and understand how a web page is displayed when a user inputs a URL Every single URL on the internet has an IP address assigned to it. The IP address points to the computer that hosts the server of the website we are requesting to access. When a user enters a URL (w...

New WhatsApp Vulnerability Surfaced: Attackers can now Alter Messages in Chats

Image
Whatsapp is a Worldwide leader of cross platform messaging allowing users to send text messages, images, user location and other media files for free. It also provides provision to place audio calls, video calls and has recently launched a new feature that enables users to place group audio and video calls. Founded in 2009, Whatsapp has become a renowned communication platform with over 1.5 billion users, 1 billion groups and 65 billion messages exchanged every day. Its ability to support end to end encryption, a feature launched in 2016, has been very well received by users as they are now assured that the information that they exchange is safe and secure. Taking into account the huge fan following of Whatapp, the Tech Giant has become a target of cyber crime activities. It recently suffered the issue pertaining to Fake News & instigating messages spread that is alleged to have triggered a series of horrific lynching incidents. Read Full Article Click Here

How to Remove .tedcrypt (Jigsaw) Files Virus?

Image
Jigsaw, originally titled as “BitcoinBlackmailer” is a form of encryption ransomware was created in 2016. The ransomware was named Jigsaw based on the fact that the ransom note featured an image of of Billy the Puppet from the Saw film franchise. The malware is known to encrypt important user files which it deletes if the user fails to pay ransom to decrypt the files. Unlike its other variants like Jigsaw ransomware, .tedcrypt files virus displays the image of a teddy bear on the screen of the victims instead of the killer from the movie “Saw” and displays a ransom note written in Turkish. The ransom note declares that victims still have the chance to retrieve the files and threatens them to delete the files permanently if the ransom is not paid within 24 hours. The amount of ransom demanded by the cyber miscreants to receive the decryption key is not known yet. The Ransom note also states that trying alternative methods to retrieve the files like Deleting the Software, Shutting d...

Cryptojacking Campaign Alert! GitHub Account and Unofficial GitHub CDN Removed

Image
GitHub Attacked Cyber miscreants have inclined to GitHub and GitHub-related services to stealthily distribute cryptocurrency mining malware without user consent. Git is a tool, a revision control system to manage source code history. Git stores this information in a data structure called repository. GitHub is a static site hosting service of Git repository that aims to manage project or set of files, personal and organization pages. Cryptocurrency mining malware are developed to take over computers’ resources and harness the system’s processing power to generate revenue. According to the researches by renowned cyber security companies, a single cryptocurrency mining botnet (collection of internet- connected devices like PCs, mobiles, servers etc infected with the common type of malware without user knowledge) can earn up to $30,000 per month to its developers. Many cryptojacking campaigns have been identified in the past months that left GitHub attacked . For instance, forkin...

Shipping Company COSCO hit by ransomware attack at its American Network

Image
COSCO Shipping Company’s communication networks taken Offline Shipping Company  COSCO was hit by a ransomware infection  that left its  American networks crippled . The company had to take its other networks temporarily offline as a precautionary measure The company issued an official press release that stated that its local email and telephone networks were unable to work properly at the time due to local American network breakdown. It was not clear as to what the issue was that led to an operations shutdown at the American network of the COSCO Shipping network. Some maritime news websites contained information that the system breakdown or the operations shutdown was implemented due to a Ransomware infection that had infected some of the systems. The  source of this news was from the internal emails of COSCO  as seen by some maritime news sites. COSCO Shipping Network is taking Contingency Steps The  press release of 25 July 2018 from COSCO S...

Twitter played harsh with 143,000 Apps that violated its policies

Image
Twitter removed more than 143000 apps this year between April and June 2018 who breached company’s policies. The company has also promised to improve tools and processes to ensure overall safety and security for everyone. Twitter is an online social networking platform that enables users to interact with each other via messages known as “Tweets”. Developed and launched in the mid of 2006, the service gained worldwide popularity in a short period. As of 2016, Twitter had more than 300 million monthly active users and around 340 million tweets a day. The platform is also famous among businesses as it has helped them benefit from this social networking service. Also the app has enabled developers build careers in data science, learn coding and much more. Since the launch of this amazing online social networking platform, Twitter is proud of the contribution of the developers for discovering helpful and innovative use cases and produce delightful and fun experiences on Twitter. Twi...

Kronos Trojan hits the Banking Sector back with a new version

Kronos banking  Trojan  was first discovered in 2014. The malware capable of stealing banking credentials had its heydays back then. However, in 2016, suddenly the once daunting banking Trojan laid dormant and dropped off researchers’ hit list. Recent research reveals that the malware is back again with its revamped version. The Trojan did made to the headlines in 2017 but the attack samples appeared to be mild with limited activity. On 27 th  June 2018, the new variant got off the ground and is known to have launched four distinct campaigns since then targeting Germany, Japan and Poland and also one test campaign. The new Version of the Kronos Banking Trojan has been retooled with a few new incorporated features like a new command-and-control feature that is designed to work with an anonymizing network –  Tor . Tor is free software that enables anonymous communication. The software is intended to conceal Internet activity of the user to protect their privacy, gi...