Posts

Showing posts with the label cybersecurity

Chrome 69: A Boon or a Bane?

Image
WWW (World Wide Web) or the Web was invented by Tim Berners-Lee in 1989. This is an information space (network of online content) of interlinked HTML pages that can be accessed over the internet. Since 1989, the Web has continued to evolve and been a centre of development to the Information Age. It has become the primary tool that billions of people use today to interact. Google Chrome  celebrated its tenth anniversary previously this month & redesigned its browser & gave it a major facelift. However, with the extricate of the latest version of  Chrome 69 ,  Google  has decided to omit  www sub-domain  from the URL displaying in the  Browser Address Bar (URL Bar). Furthermore, the new  Chrome 69  also removed “m.” sub-domain that is used for web pages specifically designed for mobile browsers. The removal of sub-domains  initiated a wave of concern and outrage  among the users and security experts. But a  ...

Adware Bundling hits Popular website platforms – Cloned!

Image
Cloned website Pushing Adware An  adware  delivery ploy was uncovered recently that involved the distribution of adware programs via clone websites that use legitimate looking domains.  The deceit came to light when a phony website  keepass.fr  was discovered that replicated the official site  keepass.info .  Keepass  is an open source password manager tool that helps users to manage their passwords for Windows network logon, websites FTP password, email account, online passwords etc in a secure manner. InstallCore adware is pushed when apps from this clone website are installed The clone of Keepass password manager app appears legitimate and is fully functional. However it is infected with the malicious  InstallCore adware . InstallCore is an adware program that bundles popular legitimate applications along with malicious third party applications. The user is lured to install the application that comes with a popular title with...

In-app currencies of Mobile games used for Money Laundering by Cyber Crooks!

Image
Mobile Games are now more popular then PC games. Mobile games generate billions of dollars in revenue. Cyber crooks have found a way to exploit the in-game currency to launder real money without the fear of being tracked by government agencies.     The cyber crooks have created a system where they use fake Apple accounts and fake gaming profiles to carry out transactions using stolen credit or debit cards. These game accounts are then sold online for real money and it is transacted using online E-wallet apps. The operation came to light when the researchers stumbled upon a MongoDB database that was left exposed on the internet without any login or password. The free access to this database revealed that it had details of more than 150,000 unique card details which recorded the card number, expiration date and the CVV. The MongoDB database revealed that the details on the sheet were not some ordinary company data but something else entirely. Upon closer inspection,...

LabCorp, US’ Biggest Testing Laboratories suffers major cyber security breach

Image
Healthcare organizations are becoming the targets of hackers now days due to highly sensitive data they deal with. The gathered data is worth minting money by selling it online rather than extorting users by stealing their email- password combos. Labcorp (Laboratory Corporation of America) , a leading global life sciences company and the largest clinical laboratories suffered one such major cyber security breach over the weekend! The firm headquartered in Burlington, North Carolina, runs large network of labs and health care centers across the world and provides diagnostic, drug development and other health care services to more than 115 million patients every year. The annual turnover of the company is estimated to be more than $10 billion. Labcorp, a fortune 500 company, is known to deliver world class forensic, genetic- specialized test facilities, diagnostic solutions performing routine tests; the most common tests being blood tests, HIV tests and urine analysis. ...

How to remove PoisonFang Ransomware from the system?

Image
What is PoisonFang? PoisonFang is a harmful program that is categorized as a  ransomware . This piece of code was developed as an academic research project at the Technion Israel Institute of Technology. Omer Cohen and Tal Porat developed the Poisonfang Ransomware as part of a ransomware project. As nothing is termed safe on the internet, cyber criminals managed to steal this project. PoisonFang ransomware is used by these criminals to threaten innocent computer users for ransom by encrypting their files. This is a new threat which does not share any links with code from other popular ransomware. Poisonfang ransomware is distributed using Spam email attachments, malicious links, Torrents and Peer-to-peer networks etc. The attachments contained in the spam emails download the PoisonFang Ransomware virus payload into the system once it is opened. Malicious links and fake websites can be used to infect the system with Poisonfang ransomware. Torrents can be used to embed the ...

$13.5 million worth of digital token stolen in Bancor, a Cryptocurrency start-up

Image
Bancor, an- Israel based company that runs a ‘decentralized’ crypt-o-currency mining & exchange network that allows users to convert between two tokens like an exchange without involving any counterparty. The network allows all kinds of virtual coins to be bought and sold instantly. A standard crypt-o-currency exchange involves exchange of tokens between two parties. A Bancor protocol in contrast works on an alternative trading mechanism that uses smart contracts to create smart tokens. Smart Contract: A smart contract is a computer program that digitally facilitates, verifies, or enforces the negotiation or performance of a contract without involving third parties. These transactions can be tracked and are irreversible. Smart Token: A smart token can be considered as a coin that holds the monetary value of other compatible virtual coins.For instance, it works on the same principle as of a central bank that holds foreign currency reserves and converts between them as requir...

How to Remove Boris Ransomware?

Image
What is Boris Ransomware and how does it work? Boris  Ransomware  is a file encryption malware that encrypts files using AES-256 cipher algorithm and is based on the infamous HiddenTear Ransomware family. Once installed on the system via malicious websites, spam email attachments the ransomware scans the PC to search for files with the following extensions and encrypts them with the sophisticated cypher algorithm. .PNG, .GIF, .JPG, .PDF, .XLR, .XLS, .XLSX, .SQL, .APK, .COM, .EXE, .JAR,.CAD Files, .CSS, .HTML .PHP,.DOC, .DOCX, .LOG, .TXT, .CSV, .KEY, .PPT .PPTX and many more. The encrypted files are appended with [decode77@sfetter.com].boris extension. For instance a file named “abc.pdf” would be renamed to “abc.pdf.[decode77@sfetter.com].boris” which is completely unusable. Victims are informed about this unfortunate circumstance by dropping a ransom note file “README.txt” that does not disclose much and reads as: There are two version known of this ransom no...

How to Remove SmartEasyMaps Browser Hijacker?

Image
Guide to remove SmartEasyMaps Browser Hijacker SmartEasyMaps  is a malicious browser extension considered to be a  browser hijacker . As the name suggests this malicious toolbar deceives user by claiming to provide: Search Maps:  Free maps, driving directions, live satellite images and street view maps Get easy Directions:  The domain alleges to find the fastest routes for to and fro movement. It also claims to help users to learn the mileage from city to city, traffic conditions, GPS maps, maps with street views, printable maps and much more. Turn-by-Turn Directions:  To exhaustive riders tired of getting stuck in road congestion the malicious toolbar affirms to provide turn-by-turn driving directions, guide the riders with the fastest route for their destination, and much more. The malicious extension undergoes stealth installation in the system and once infiltrated modifies browser settings. It replaces browser homepage, search engine and ...

How to remove “Yahoo Customer Reward Program” Scam POP-UP?

Image
Guide to remove “Yahoo Customer Reward Program Scam” Pop- up Yahoo Customer Reward Program  , the pop-up message that appears during user browsing sessions may appear alluring and tempt users to click on it. However, the pop- up is deceitful and is a part of a scam campaign that aims to steal user personal information and financial credentials. In order to look legitimate and trick users, the scam could feature official logo of the company. Insights from official sources reveal that Yahoo does not provide direct customer support emails, phone number or reward programs to its clients. Scammers usually adopt the common practice of impersonating popular brands or websites to entrap users in their malicious campaign. Users are therefore recommended to refrain from clicking on such deceiving pop- ups as it may lead to compromising their confidential data or make their computer susceptible to other system infections. The main reason why “Yahoo Customer Reward Program” pop-up is di...

How to remove GeoSmartDNS Adware from the Computer?

Image
What is GeoSmartDNS? GeoSmartDNS is a harmful entity that is a potentially unwanted program (PuP). It comes under the category of  adware . This program displays ads to the user, and for every click by the user on these ads, revenue is generated for the company called Greenteam, who made this malicious program. GeoSmartDNS infiltrates the system and affects the settings in the web browser to start displaying intrusive and unwanted ads during user browsing sessions. The GeoSmartDNS adware is installed into the user’s system through various distribution methods. These methods are designed to lure and trap unwary users into unwittingly allowing the malware entry into their system. GeoSmartDNS has a website that is used to distribute this adware . Its tagline says ‘Browse the Internet with no censorship’. Many users may fall for this gimmick but its motive is something different from what it makes the user believe. In one of its Supposed ‘Main features’ it highlights the fact...

‘Apple Security Virus Detected’ Scam Users of their login credentials!

Image
Many Apple iPhone users have been receiving a notification message alerting them that their iPhone has a Fake ‘  Apple Security Virus Detected  ’ threat. If they don’t take immediate action then their iPhone will be prone to viruses and there is a chance that they might end up losing all their data. This Notification is shown to the user if the Safari or Chrome Browser has been infected by an adware. The  adware displays these notifications to bait the user into giving out their login credentials for iCloud account or their banking details. Many users panic and are scared when they see this message as it is made to look authentic and is designed to feel that there really is a threat which is affecting their iPhone. The  user should not click ‘OK’  or have any kind of interaction with the notification message. If the user is not careful then the notification message can redirect the user to new threats or websites which can ask for login credentials in orde...

How to Remove King Ouroboros Ransomware from the Computer?

Image
What is King Ouroboros Ransomware? King Ouroboros is a file encrypting virus  that is categorized as a  ransomware . It is a dangerous and destructive malware that injects itself in the user’s system to encrypt the files with a powerful encryption key. The personal files of the user such as photos, videos, documents and other files are encypted with the ‘ .king_ouroboros ’ extension by the  King Ouroboros Ransomware . It uses a powerful AES-256 encryption algorithm to encrypt user files and then demands a ransom for the decryption key. After the data on the system is encrypted, the user is unable to open any files and is displayed with a ransom note. King Ouroboros Ransomware — Threat Behavior King ouroboros ransomware infiltrates into the user’s system through various methods of infiltration and infect the computer. These methods include spam email campaigns, fake software update notifications, peer to peer networks, websites that are unsecure & ...

Windows Net Proxy Auto Service Not A Windows Service But A

Image
Windows net proxy auto service  or WinNetSvc is a Potentially unwanted Program (PuP) that is categorized as an  adware . This threat infiltrates the system silently and changes the web browser settings. It then creates a service that communicates with remote servers. These servers contain all the user information that windows net proxy auto service has transmitted from your PC to the hackers. Read full Article 

How to remove TaksHostMiner torjan virus?

Image
TaksHostMiner  is a Crypto miner  Trojan  that seeks back door entry to attack the targeted system or a Network. This Trojan rely on unsuspected game plugins and infect the system when the plugin is executed. The Trojan was recently discovered and is known to have infected thousands of computer in one day. Steps to prevent the infiltration of TaksHostMiner Trojan in the system :-   follow step

VPNFilter IoT Attack-A Router Infection

Image
What is VPNFilter Malware? VPNFilter, a new multistage and modular malware, unlike most other IoT(Internet pf Things) threats is capable to maintain a persistent presence on an infected device even after the system reboot. The malware can ostensibly be used to collect victim’s personal information, permanently destroy device and launch attacks on other devices. Since 2007 this sophisticated malware has targeted half a million routers and network devices in around 54 countries. The infection contains the killswitch for routers that is capable of stealing victim’s logins and passwords information. It also possesses the potential to monitor industrial control systems and deprive all the devices from accessing internet. Group behind this mischievous activity The mischievous effort to design the vicious infection is attempted by a Russian hacking group, the Sofacy Group also known as Apt28 or Fancy Bear group. The group is believed to have targeted government, military and security org...