A new worrisome malware is in town! The malware which is designed to steal victims credentials such as passwords is now on sale by a Russian hacker. The malware which is available for as little as $7, providing wannabes with a worryingly easy entry point into the world of cybercrime.
Ovidiy Stealer is regularly updated by its Russian-speaking authors and the malware has hit targets around the world including the UK, the Netherlands, India, and Russia. Despite its low price the malware is designed to avoid analysis and detection. This a worrisome feature for small, medium and big organizations - How can you fight what you don't know?.
Discovered by guys from proofpoint, the malware is spread via a number of methods, including malicious email attachments, file-hosting websites, and even within software packages. This is a perfect malware for "Yahoo Boys" in Nigeria to operate with, as it features some of their attack Vectors.
It comes with functionality to target multiple applications, but buyers are able to purchase a version of the malware which only focuses on a single browser if they so wish.
If the malware is able to find passwords in its targeted applications, it will send them to the gang using it, putting the victim and their organisation at risk of compromise, especially if the same password is used across multiple accounts. In simple term, if the malware finds it's way to your PC, every website you have accessed being banks or your social media accounts, the login password credentials will be automatically sent to the attackers! That's trouble enough to be afraid of.
Payment for the malware is taken by RoboKassa, the Russian equivalent of PayPal.
For more details on Ovidiy Stealer head over to ZDNET
Ovidiy Stealer - The New Password Stealing Malware
Meet The Nigerian CEO Of Reach Robotics & Builder Of World’s First Gaming Robots - Silas Adekunle
Silas Adekunle told his alma mater he got the idea to build the robots while studying there, teaching maths and science in local schools on the university’s partnership scheme. and noticed how unpopular science, technology is.
He noticed the students didn’t really like studying science, technology, engineering, and maths (STEM) subjects. Many schoolchildren didn’t plan on pursuing careers in these areas. So he decided to try and bring them on board by teaching robotics.
Silas Adekunle told his alma mater he got the idea to build the robots while studying there, teaching maths and science in local schools on the university’s partnership scheme. and noticed how unpopular science, technology is.
He noticed the students didn’t really like studying science, technology, engineering, and maths (STEM) subjects. Many schoolchildren didn’t plan on pursuing careers in these areas. So he decided to try and bring them on board by teaching robotics.
“Robotics ties in many aspects of STEM, and who doesn’t like robots?” he said.
Source: lunbeynija
Android Malware Alert - Why You Need To Upgrade To Android 7.1
Recently, google released an upgrade to Android 7.1 Nougat. Addition to the upgrade include a great new feature that will protect users from the threat of malware hidden away in one of their apps.
The latest version of Android contains a secret ‘panic mode’ that kicks in if malicious software tries to lock a user’s screen without permission. The feature, called “panic detection”, looks for multiple presses of the back button. If the phone record four consecutive button presses in a row, it automatically overrides whatever is on the screen and returns a user to the home screen.
(adsbygoogle = window.adsbygoogle || []).push({});
The feature was introduced as some malware apps are capable of disabling the back button and other buttons. If you realise something is wrong with your phone, you might start panicking and furiously pressing the back button to see if your Android phone responds. That’s when the Google failsafe will kick in - Android 7.1 Nougat would realise your back button isn’t behaving normally. Then override whatever that is causing the issue. Google kept this feature a secret as they don’t want hackers to find out, but it was discovered by some XDA Developers.
After google released android 7.1 updates not all OEMs have updated their devices. The list of mobile phones getting Android 7.1 Nougat ( some devices like Pixel X & XL already got the update) update are:
- Google Pixel
- Google Pixel XL
- Nexus 5X
- Huawei Nexus 6P
- LG V20
- Samsung Galaxy Note 7
- Samsung Galaxy Note 7 Duos
- Samsung Galaxy S8
- Samsung Galaxy S8 Plus
- Samsung Galaxy S7
- Samsung Galaxy S7 Edge
- Samsung Galaxy S7 Active
- Samsung Galaxy Note 5
- HTC 10
- LG G5
- LG G6
- General Mobile GM 5
Source: UK Express
Social Engineering (Part 2) - The desire to be helpful to others
One of the most popular targets for social engineers is an organization’s customer care representative that provide information and support to external customers because they tend to be easily accessible to an attacker. This can also take place in a social sphere where the attacker presents itself as a vulnerable person in need of help. On the process vital information could be divulged from the target that will be helpful in carrying out the attack. While companies typically attempt to train these employees to guard confidential information and access to the company’s systems by providing detailed conversation scripts, social engineers have found that these employees are easy to manipulate. As a follow up to Part One of this series, hackers carry out a thorough recon on any of their targets before exploit.
.........A clouded mind is quite easy to be socially engineered.Customer care representatives spend every day continually helping a never-ending line of customers and psychological research has shown that it is incredibly difficult in this situation to question the validity of every interaction. Instead the employee will try every means possible to resolve whatever issue the customer is facing even if it deviates from policy put in place to prevent social engineering.
For example a social engineer could take advantage of this by feigning a poor ability to communicate in English using igbo in hopes that a call center employee will circumvent the policy in place to better assist the troubled “customer”. If successful, the social engineer may be able to bypass security questions put in place to verify the caller’s identity.
The first step in preventing attacks such as this, is to reduce the workload of customer care representatives by getting more people to do the job - a clouded mind is quite easy to be socially engineered.The next step is providing quarterly training and bulletins on social engineering attacks to keep employees abreast with modern techniques employed by hackers.
Kindly leave a comment below and don't forget to share!
Social Engineering - I Love You With Hidden Agenda
We have heard so much about hacking of systems, accounts, organizations and so many other situations caused by a breach in security infrastructures.
In response to this threat, companies around the world are projected to invest over 150 billion dollars on IT security projects in 2017 in an attempt to protect their businesses.So why, despite these large investments, do we often constantly see large companies with strong IT systems suffer from service disruptions and leaked information? the answer lies in the persuasiveness of Social Engineering! According to Kevin Mitnick, described by the US government as one of the most dangerous hacker in the world, the cause of this could be because “it is much easier to trick someone into revealing a password for a system than to exert the effort of hacking into the system” (Alvin Cheung ACC 626).
Social Engineering, according to Mitnick, is the use of influence and persuasion to deceive people into divulging information. in the past we have heard so much of the infamous Nigerian prince as used by some fraudulent Nigerians called "yahoo yahoo". the secret is to be your friend, socialize with you and make you comfortable with them. Once they win your trust the exploit begins. This is the method these guys have been using against foreign folks for years. Taking advantage of the vulnerable old widow or the vulnerable young woman who just had a broken relationship or the want to get rich quick young man. In most cases they act like they are from other countries other than Nigeria. and yes identity theft is one major tactic they use in achieving this.
Another dangerous aspect of social engineering is taking advantage of company's employees, socializing with the sole hidden purpose of getting information or password that might allow this attackers or hackers get access to the target organization, either physically or remotely via the internet, compromising the security infrastructures in place. once they are in all sorts of activities from financial theft to propriety theft to important information that might be used to blackmail such organizations. in other to prevent all these from happening it is advisable that organization conduct ICT training from time to time, enlightening them on some of these methods used by hackers and for them to report any questionable activities they might encounter while carrying out their daily job activities. Ignorance is a weakness knowledge is strength!
Minimizing Data Consumption On Your Windows PC - Just like you are using your mobile phone
Imagine wanting to browse on your PC to experience that complete web experience but hell yeah like me you don't have enough data left on your mobile line. Today i will be showing you how to minimize data consumption on your PC when sharing your mobile internet data.
Step 1 (Disable unused services)
well, what are using using your PC for if not to use internet explorer or chrome or Firefox. it will surprise to you to know that those apps consume less data compared to other background services that run on your PC.
So we are going to disable every other services & apps that is not needed except your antivirus! - of course you know i'm an advocate of cyber security!
Go to Control Panel => security and maintenance => windows firewall, then look at the left pane you will find
"Allow an app or a feature through windows firewall".
click on it, but before you do make sure your windows firewall is turned on. Double click on 'change settings' then tick off every apps & services seen under 'Name' while leaving Chrome.exe, Google chrome, Firefox, your installed antivirus and its services, core networking, delivery optimization, internet connection sharing, Microsoft WiFi, network discovery, Windows defender security center, Windows firewall management, wireless display, wireless portable devices, and WLAN Service(both).
Do all that and enjoy minimum data consumption just like you are using your phone!
Step 2 (THE END)
please don't forget to click share...😉
Petya Ransomeware - The new trouble in town!
A massive cyberattack swept across computer networking systems worldwide this week, spanning across Europe, the Middle East, and the United States and affecting a variety of companies, from banking institutions to airlines to hospitals. The breach comes just weeks after the WannaCry Attack that hit at least 150 countries. The global Petya virus has “significantly affected” the worldwide operations of TNT Express, a subsidiary of FedEx that’s based in the Netherlands. Both the domestic and international shipping.
The virus that began spreading through European computer systems yesterday informed users that they could unlock their machines by paying a $300 ransom. But it looks like the program’s creators had no intentions of restoring the machines at all. In fact, a new analysis reveals they couldn't; the virus was designed to wipe computers outright.
Matt Suiche, founder of the cybersecurity firm Comae, writes in a blog post today that after analyzing the virus, known as Petya, his team determined that it was a “wiper,” not ransomware. “We can see the current version of Petya clearly got rewritten to be a wiper and not a actual ransomware,” Suiche writes.
The virus going around is a modified take on an earlier version of the Petya virus that was true ransomware. But Comae saw that code had been specifically modified to change it from a virus that encrypts a disk and demands a ransom into a virus that simply destroys the disk.
So then why purport to be ransomware? There’s no way to say for certain right now, but Suiche believes it was about hiding who was really behind the attack. “We believe the ransomware was in fact a lure to control the media narrative,” he writes, saying that ransomware suggests “some mysterious hacker group” being behind the virus “rather than a national state.”
That’s still speculation for now, but the virus did appear to primarily target Ukrainian infrastructure, including an electricity supplier, the central bank, the state telecom, and an airport. Analysis from Kaspersky Lab yesterday showed the virus remaining primarily in Ukraine.
This is call for companies in Africa and Nigeria especially, to start installing Various security patches on systems including the one in Microsoft’s MS17-010 bulletin. Also Antivirus and Anti-malware softwares need to be updated regularly to fight against such attacks.
Intel Tiger Lake CPUs to come with Anti-Malware Protection
Intel’s Tiger Lake CPUs will come with Control-flow Enforcement Technology (CET), aimed at battling common control-flow hijacking attacks. I...
-
Last April, Steven Schoen received an email from someone named Natalie Andrea who said she worked for a company called We Purchase Apps. She...
-
Intel’s Tiger Lake CPUs will come with Control-flow Enforcement Technology (CET), aimed at battling common control-flow hijacking attacks. I...
-
By Carl Herberger This is Part 2 of our series on the top 5 most dangerous DDoS attacks and how you can successfully mitigate them. ATTAC...





