Showing posts sorted by relevance for query malware. Sort by date Show all posts
Showing posts sorted by relevance for query malware. Sort by date Show all posts

22 February 2021

New malware found on 30,000 Macs has security pros stumped

A previously undetected piece of malware found on almost 30,000 Macs worldwide is generating intrigue in security circles, and security researchers are still trying to understand precisely what it does and what purpose its self-destruct capability serves.

Once an hour, infected Macs check a control server to see if there are any new commands the malware should run or binaries to execute. So far, however, researchers have yet to observe delivery of any payload on any of the infected 30,000 machines, leaving the malware’s ultimate goal unknown. The lack of a final payload suggests that the malware may spring into action once an unknown condition is met.

Also curious, the malware comes with a mechanism to completely remove itself, a capability that’s typically reserved for high-stealth operations. So far, though, there are no signs the self-destruct feature has been used, raising the question of why the mechanism exists.

www.arstechnica.com


26 May 2018

FBI tells router users to reboot now to kill malware infecting 500k devices


The FBI is advising users of consumer-grade routers and network-attached storage devices to reboot them as soon as possible to counter Russian-engineered malware that has infected hundreds of thousands devices.

Researchers from Cisco’s Talos security team first disclosed the existence of the malware on Wednesday. The detailed report said the malware infected more than 500,000 devices made by Linksys, Mikrotik, Netgear, QNAP, and TP-Link. Known as VPNFilter, the malware allowed attackers to collect communications, launch attacks on others, and permanently destroy the devices with a single command. The report said the malware was developed by hackers working for an advanced nation, possibly Russia, and advised users of affected router models to perform a factory reset, or at a minimum to reboot.


19 February 2025

Hackers planted a Steam game with malware to steal gamers’ passwords

Last week, Valve removed a game from its online store Steam because the product was laced with malware

After the removal of the game, which was called PirateFi, security researchers analyzed the malware and found that whoever planted it modified an existing video game in an attempt to trick gamers into installing an info-stealer called Vidar.

Marius Genheimer, a researcher who analyzed the malware and works at SECUINFRA Falcon Team, told TechCrunch that judging by the command and control servers associated with the malware and its configuration, “we suspect that PirateFi was just one of multiple tactics used to distribute Vidar payloads en masse.”

“It is highly likely that it never was a legitimate, running game that was altered after first publication,” said Genheimer. 

In other words, PirateFi was designed to spread malware. 

Be careful out there folks - watch where you go, what you install. There are some bad people on the InterWebs. If you have installed this game please take expert advice ASAP.

www.techcrunch.com


13 May 2017

"Accidental hero" finds kill switch to stop spread of WannaCry RansomWare cyber-attack


An “accidental hero” has halted the global spread of the WannaCry ransomware, reportedly by spending a few dollars on registering a domain name hidden in the malware.

However, a UK cybersecurity researcher tweeting as @malwaretechblog, with the help of Darien Huss from security firm Proofpoint, found and activated a “kill switch” in the malicious software.

The switch was hardcoded into the malware in case the creator wanted to stop it spreading. This involved a very long nonsensical domain name that the malware makes a request to – just as if it was looking up any website – and if the request comes back and shows that the domain is live, the kill switch takes effect and the malware stops spreading.

“I saw it wasn’t registered and thought, ‘I think I’ll have that’,” he is reported as saying. The purchase cost him $10.69. Immediately, the domain name was registering thousands of connections every second.

The kill switch won’t help anyone whose computer is already infected with the ransomware, and and it’s possible that there are other variants of the malware with different kill switches that will continue to spread.


24 November 2025

Microsoft's New Windows AI Feature Comes With Warnings About Malware and Data Theft

ITSFOSS.COM - If you ask me, Microsoft has been one of the biggest driving forces behind Linux adoption in recent years. The way they've been handling Windows, with its forced updates, aggressive telemetry, and questionable AI features, has sent more people to Linux than any marketing campaign ever could.

And they are at it again with a new Artificial intelligence feature that could be tricked into installing malware on your system.

Microsoft is rolling out a new experimental feature called "Copilot Actions" to Windows Insiders. They pitch it as an AI agent that handles tasks you describe to it. Organize vacation photos, sort your Downloads folder, extract info from PDFs, that sort of thing.

It is currently available in Windows 11 Insider builds (version 26220.7262) as part of Copilot Labs and is off by default, requiring admin access to set it up.

But here's the catch. Copilot Actions isn't just suggesting what to do. It runs in a separate environment called "Agent Workspace" with its unique user account, clicking through apps and working on your files.

Microsoft says it has "capabilities like its own desktop" and can "interact with apps in parallel to your own session." And that's where the problems start.

In a support document, Microsoft admits that features like Copilot Actions introduce "novel security risks." They warn about cross-prompt injection (XPIA), where malicious content in documents or UI elements can override the AI's instructions.

The result? "Unintended actions like data exfiltration or malware installation."

Yeah, you read that right. Microsoft is shipping a feature that could be tricked into installing malware on your system.

Microsoft's own warning hits hard: "We recommend that you only enable this feature if you understand the security implications."

www.itsfoss.com


23 August 2023

Google Chrome to warn when installed extensions are malware

Google is testing a new feature in the Chrome browser that will warn users when an installed extension has been removed from the Chrome Web Store, usually indicative of it being malwareAn unending supply of unwanted browser extensions is published on the Chrome Web Store and promoted through popup and redirect ads.

These extensions are made by scam companies and threat actors who use them to inject advertisements, track your search history, redirect you to affiliate pages, or in more severe cases, steal your Gmail emails and Facebook accounts.

The problem is that these extensions are churned out quickly, with the developers releasing new ones just as Google removes old ones from the Chrome Web Store.

Unfortunately, if you installed one of these extensions, they will still be installed in your browser, even after Google detects them as malware and removes them from the store.

Due to this, Google is now bringing its Safety Check feature to browser extensions, warning Chrome users when an extension has been detected as malware or removed from the store and that they should be uninstalled from the browser. This feature will go live in Chrome 117.

www.bleepingcomputer.com


20 May 2021

Craig Federighi (Apple Senior Vice President of Software Engineering): "we have a level of malware on the Mac that we don’t find acceptable"

 

Remember that oldie but goldie: "Macs don't get viruses" - yeh right! Apple's software supremo Craig Federighi on Wednesday condemned the security of macOS in an astonishing attempt to defend the walled garden that is the iOS App Store.

It's the latest twist in the ongoing Epic v Apple bench trial in which Cupertino is accused of illegally monopolizing app distribution and payments for iPhones and iPads. Federighi took the stand to argue that because Apple does not control the availability of software on macOS to the extent that it controls what applications are available from its iOS Store, Macs suffer as a consequence. He said the level of malware on Macs is unacceptable, and criticized the security protections in the desktop operating system.

..."And as I say, today, we have a level of malware on the Mac that we don’t find acceptable and is much worse than iOS. Put that same situation in place for iOS and it would be a very bad situation for our customers."...

Federighi's statement may seem shocking, particularly to those who bought Apple's Mac laptops and desktops on security grounds. The Mac's operating system isn't totally insecure, and is a cousin of iOS. iOS isn't bug or malware free, either. However, the argument appears to be that macOS is more open, it isn't as locked down as iOS, and thus it's more vulnerable to malicious software that can take over the computer.

www.theregister.com


12 September 2016

"Seagate Central" NAS devices become malware distributors


Sophos researchers say they've uncovered a malware strain that targets Seagate's network-attached storage appliances and turns them into distribution points for cryptocurrency-mining malware.

Attila Marosi, a senior threat researcher, explains the attack in a document titled Cryptomining malware on NAS servers (PDF).

"Attack" is being kind: Marosi notes that the NAS at the heart of the problem - the "Seagate Central" - has a public folder that can be written to by default when remote access is enabled. All you need to do to access that folder is FTP in with publicly-published credentials.


23 May 2023

IT - buy cheap & live to regret it...

 

Potentially millions of Android TVs and phones come with malware preinstalled. The bane of low-cost Android devices is showing no signs of going away.

Overall, Android devices have earned a decidedly mixed reputation for security. While the OS itself and Google's Pixels have stood up over the years against software exploits, the never-ending flow of malicious apps in Google Play and vulnerable devices from some third-party manufacturers have tarnished its image.

On Thursday, that image was further tarnished after two reports said that multiple lines of Android devices came with preinstalled malware that couldn’t be removed without users taking heroic measures.

The first report came from security firm Trend Micro. Researchers following up on a presentation delivered at the Black Hat security conference in Singapore reported that as many as 8.9 million phones comprising as many as 50 different brands were infected with malware. First documented by researchers from security firm Sophos, Guerrilla, as they named the malware, was found in 15 malicious apps that Google allowed into its Play market.

Guerrilla opens a backdoor that causes infected devices to regularly communicate with a remote command-and-control server to check if there are any new malicious updates for them to install. These malicious updates collect data about the users that the threat actor, which Trend Micro calls the Lemon Group, can sell to advertisers. Guerrilla then surreptitiously installs aggressive ad platforms that can deplete battery reserves and degrade the user experience.

The moral of this story is: do not buy cheap tech devices from brands you've never heard off before! Household brands are fine, such as: Sony, LG, Samsung (other brands are available 😉). If you buy cheap & unbranded tech - you're inviting the thieves to move in with you! Remember - these devices sit on your home and/or work network with access to any data flowing through that network. If these devices are used to log in to your email, bank, etc - they will have access to your credentials... It just isn't worth the risk to save a few quid!

www.arstechnica.com


07 October 2016

Attack allows Mac malware to piggyback on your webcam, while it's in use


A new attack allows Mac malware to record video and audio whenever a victim legitimately turns on their webcam, without drawing attention to itself.
Now it's no surprise that malware would leverage webcams in an attempt to spy on OS X users. A victim could blurt out personal information which attackers could use for identity theft, or peeping toms could secretly record footage with the intention of blackmailing the unwitting victim.
That explains why some of the recent malware samples for OS X, including Eleanor and Mokes, come equipped with the ability to record video and audio content from infected computers.


11 January 2019

When a cheap smartphone costs more than you thought: pre-installed malware calling premium rate numbers!


A weather app that comes preinstalled on Alcatel smartphones contained malware that surreptitiously subscribed device owners to premium phone numbers behind their backs.

The app, named "Weather Forecast-World Weather Accurate Radar" was developed by TCL Corporation, a Chinese electronics company that among other things owns the Alcatel, BlackBerry, and Palm brands.

The app is one of the default apps that TCL installs on Alcatel smartphones, but it was also made available on the Play Store for all Android users --where it had been downloaded and installed more than ten million times.

But at one point last year, both the app included on some Alcatel devices and the one that was available on the Play Store were compromised with malware. How the malware was added to the app is unclear. TCL has not responded to phone calls requesting comment made by ZDNet this week.

According to Upstream, most of the behavior they've seen originated only from two types of smartphones, Pixi 4 and A3 Max models. However, the company doesn't have a worldwide view into infected devices, and many more could still be infected, especially users who downloaded the app from the Play Store.

All in all, the company says it detected and blocked over 27 million transaction attempts across seven markets, which would have created losses of around $1.5 million to phone owners if they hadn't been blocked.


18 September 2017

CCleaner 5.33 infected with Malware!


Version 5.33 of the CCleaner app offered for download between August 15 and September 12 was modified to include the Floxif malware, according to a report published by Cisco Talos.

Floxif is a malware downloader that gathers information about infected systems and sends it back to its C&C server. The malware also had the ability to download and run other binaries, but at the time of writing, there is no evidence that Floxif downloaded additional second-stage payloads on infected hosts.


18 March 2019

Do you use WinRAR zipping tool? Better update now - to close this security vulnerability


After being a staple on PCs for so many years, last month it was discovered that WinRAR, software used to open .zip archive files, has been vulnerable for the last 19 years to a bug that’s easily exploited by hackers and malware distributors. Fortunately, the software has been patched with the recent release of version 5.70, but after being unchecked for so long and installed by so many people, a new wave of malware is taking advantage.

Check Point, the security researchers that revealed the WinRAR bug, explain that the software is exploited by giving malicious files a RAR extension, so that when opened they can automatically extract malware programs. These programs are installed in a PC’s startup folder, allowing them to start running anytime the computer is turned on, all without the user’s knowledge.

So: if you use WinRAR - check what version you are using. If anything less than v5.70 - then go here - download the latest version & install the update. Or better still, do what Donline does: use 7-Zip.


01 March 2022

Tech news related to Putin's invasion of Ukraine

 

SecurityWeek: Twitter will put warnings on tweets sharing links to Russian state-affiliated media, the platform said Monday, as Kremlin-tied outlets are accused of spreading misinformation on Moscow's invasion of Ukraine.

Pressure is on social media giants to squelch misleading or false information about the attack, which has drawn fierce international condemnation.

Kremlin-run media outlets RT and Sputnik have both faced accusations of using false narratives in an effort to argue in favour of war.

=============

Microsoft: Several hours before the launch of missiles or movement of tanks on February 24, Microsoft’s Threat Intelligence Center (MSTIC) detected a new round of offensive and destructive cyberattacks directed against Ukraine’s digital infrastructure. We immediately advised the Ukrainian government about the situation, including our identification of the use of a new malware package (which we denominated FoxBlade), and provided technical advice on steps to prevent the malware’s success. (Within three hours of this discovery, signatures to detect this new exploit had been written and added to our Defender anti-malware service, helping to defend against this new threat.) In recent days, we have provided threat intelligence and defensive suggestions to Ukrainian officials regarding attacks on a range of targets, including Ukrainian military institutions and manufacturers and several other Ukrainian government agencies. This work is ongoing.

=============

Reuters: Germany's Enercon on Monday said a "massive disruption" of satellite connections in Europe was affecting the operations of 5,800 wind turbines in central Europe.

It said the satellite connections stopped working on Thursday, knocking out remote monitoring and control of the wind turbines, which have a total capacity of 11 gigawatt (GW).

"The exact cause of the disruption is not yet known. The communication services failed almost simultaneously with the start of the Russian invasion of Ukraine," Enercon said in a statement.

In other news, BBC reports: European gas prices have risen after the approval of the Nord Stream 2 pipeline to Germany was halted because of Russia's actions in Ukraine.


27 October 2016

Blue screen of death with a support number? Beware the malware scam


A new tech support scam displays a fake blue screen of death (BSoD) in an effort to trick users into installing malware on their Windows computers.
In this particular case, Hicurdismos masquerades as Microsoft Security Essentials, the anti-malware product that came pre-installed on all machines with Windows 7 and earlier.

28 July 2020

Have a QNAP NAS? Make sure the firmware is up-to-date to safeguard against Qsnatch malware!


The number of QNAP network-attached storage (NAS) boxes infected with the data-stealing QSnatch malware has reached 62,000, the US and UK governments warned today.

A joint statement from America's Cybersecurity and Infrastructure Security Agency (CISA) and Britain's National Cyber Security Centre (NCSC) said the software nasty, first spotted in October, has increased its infection count from 7,000 devices that month to tens of thousands by mid-June, 2020, with "a particularly high number of infections in North America and Europe." It is estimated 7,600 hijacked QNAP boxes were in America, and 3,900 in the UK.

The situation is particularly messy because Taiwan-based QNAP has not, to the best of our knowledge, disclosed exactly how the malware breaks into vulnerable boxes, advising simply that owners should ensure the latest firmware is installed to prevent future infection. Judging from conversations people have had with the manufacturer's support desk, it appears there was a remotely exploitable hole in the firmware, perhaps down to the operating system level, which was fixed in November.


10 May 2017

Emergency patch released for critical security hole in Microsoft’s malware scanner


You know a security hole is serious if Microsoft issues a patch for it just hours before the company is scheduled to release its regular bundle of Patch Tuesday updates.

Microsoft has issued an update for the Microsoft Malware Protection Engine, addressing a security vulnerability that could allow remote code execution if one of Microsoft’s anti-virus products scans a boobytrapped file. As Microsoft warns in its advisory, an attacker could exploit the vulnerability to seize control of a victim’s PC.

In short, running Microsoft’s anti-virus software would have protected against a raft of malware, but it may also have made your computer more vulnerable.


28 March 2019

Hackers hijacked ASUS software updates to install backdoors on thousands of computers


Researchers at cybersecurity firm Kaspersky Lab say that ASUS, one of the world’s largest computer makers, was used to unwittingly install a malicious backdoor on thousands of its customers’ computers last year after attackers compromised a server for the company’s live software update tool. The malicious file was signed with legitimate ASUS digital certificates to make it appear to be an authentic software update from the company, Kaspersky Lab says.

ASUS, a multi-billion dollar computer hardware company based in Taiwan that manufactures desktop computers, laptops, mobile phones, smart home systems, and other electronics, was pushing the backdoor to customers for at least five months last year before it was discovered, according to new research from the Moscow-based security firm.

The researchers estimate half a million Windows machines received the malicious backdoor through the ASUS update server, although the attackers appear to have been targeting only about 600 of those systems. The malware searched for targeted systems through their unique MAC addresses. Once on a system, if it found one of these targeted addresses, the malware reached out to a command-and-control server the attackers operated, which then installed additional malware on those machines.

Kaspersky Lab said it uncovered the attack in January after adding a new supply-chain detection technology to its scanning tool to catch anomalous code fragments hidden in legitimate code or catch code that is hijacking normal operations on a machine. The company plans to release a full technical paper and presentation about the ASUS attack, which it has dubbed ShadowHammer, next month at its Security Analyst Summit in Singapore. In the meantime, Kaspersky has published some of the technical details on its website.


10 February 2017

Macs don't get viruses?...


Hackers are menacing Apple Mac users with Word documents laced with malicious macros that install malware.

Security researchers spotted a rash of poisonous files doing the rounds earlier this week, one of which was titled "U.S. Allies and Rivals Digest Trump's Victory – Carnegie Endowment for International Peace.docm." Apple fans who opened the document on a Mac are prompted to enable macros.

If enabled, the file executes a function, coded in Python, that downloads a malware payload to infect the machine. The Python code is taken from the open-source EmPyre project, a pure Python post-exploitation agent. The tactic is used to push persistent malware onto compromised Macs.


17 July 2017

Apple Malware secretly installs "Signal" as part of scheme to steal users' banking credentials


New Mac Malware is mysteriously pushing the Signal private-messaging app onto victims' mobile devices as part of a scheme to steal their banking credentials.

The threat, which goes by the name OSX/Dok, uses phishing mail laden with a malicious application as its attack vector. Those who crafted this campaign purchase Apple certificates (US $99) to sign their malicious application. Such willingness helps the malware bypass Gatekeeper's ever-watchful gaze.

Upon successful installation, OSX/Dok modifies the OS settings with a shell command that disables security updates. It also alters the local host file so that all communication with various Apple websites, as well as VirusTotal, gets redirected to the local machine. These changes prevent the machine from contacting outside services that the victim could use for detection and recovery.

Read more here: www.grahamcluley.com