A malware built to display porn ads within mobile apps, including a large number of children’s games, has been uncovered in Google Play.
Check Point researchers have found the new and nasty malicious code, dubbed AdultSwine, hiding in around 60 game apps. So far, they’ve been downloaded between 3 million and 7 million times.
AdultSwine does a range of things, starting with displaying ads from the web that are often highly inappropriate and pornographic. However, it also attempts to trick users into installing fake security apps and tries to dupe users to register and pay for premium services. It’s also built to be flexible, so its authors in the future could expand their sites to other malicious activities, such as credential theft.
The inappropriate ads being displayed come from two main sources, Check Point said: mainstream ad providers and the malicious code’s own ad library (where the porn ads stem from). All of these are displayed to children on a rotating basis while they play the infected games.
On the scareware front, AdultSwine displays an ad that claims the user’s device is infected by a virus.
“Should the user press the notification of ‘Remove Virus Now’ he is redirected to an app in the Google Play Store with a somewhat questionable connection to virus removal,” said the researchers in an analysis. “An experienced eye could easily foresee this tactic, though a child playing a game app is easy prey for such nefarious apps.”
When it comes to the fraudulent premium services, AdultSwine initially displays a pop-up ad saying that the user is entitled to win an iPhone by simply answering four short questions. If the user clicks through, the malicious code eventually asks him to enter his phone number to receive the “prize,” which, of course, is a ploy. The malware then uses the number to register for premium services.
“Although for now this malicious app seems to be a nasty nuisance, and most certainly damaging on both an emotional and financial level, it nevertheless also has a potentially much wider range of malicious activities that it can pursue, all relying on the same common concept,” Check Point warned. “Indeed, these plots continue to be effective even today, especially when they originate in apps downloaded from trusted sources such as Google Play.”
To avoid victimization, parents should examine the apps that their kids download and educate their children on fraud and how to spot it.
Source: Info-Security
Malware Serves Up Porn Ads in Kids' Apps
South Korea Considers a Bitcoin Ban, Sparking Outrage
South Korean regulators are mulling a ban on cryptocurrency trading, sparking outrage across the nation.
The justice minister, Park Sang-ki, said this week that the government was preparing legislation to halt the trading of Bitcoin, Monero and other virtual money.
Trading is a popular pastime in South Korea, the world’s most wired country. Its young, tech-savvy populace has seized on virtual currency as a way to earn cash amid an economy that offers dwindling job prospects for millennials, despite its relative wealth as a nation. With Bitcoin pricing exploding over the last few months, many people have earned quite a bit. About a third of the 941 office workers surveyed in December by Saramin, a South Korea-based job portal, have traded virtual currency; out of those, more than 80% made money from it, and about 20% made a whopping average return of 425% on their investment, according to the survey.
The average Korean investor owns around 5.66 million won ($5,260) in virtual currencies.
“Tax it as much as you want but don’t shut it down. My life depends on it,” one petitioner wrote on the president’s website, according to Reuters. The petition there has drawn more than 120,000 signatures against a ban, as of Friday.
Regulators are concerned that the casino-like, speculative nature of the virtual marketplace has resulted in a bubble that is destined to burst, and they worry that economic catastrophe for whole swaths of the population could follow.
“On one hand, there is a growing part of their population who has adopted cryptocurrencies and are using them to great success both for investment purposes and for direct business uses as well,” Nathan Wenzler, chief security strategist at AsTech, told Infosecurity. “These advocates are becoming more reliant on cryptocurrencies and typically support their use as being an inevitable trend that will only become more heavily adopted as time goes on. However, there are those that claim it's too risky and too volatile, and should the cryptocurrency market collapse, the government of South Korea would have to pick up the slack for the economic damage that would cause.”
There’s another dimension as well, according to Joseph Carson, chief security scientist at Thycotic, a Washington, D.C., based provider of privileged account management (PAM) solutions, having to do with cryptocurrency mining and taxation.
“China announcing they are going to clamp down on bitcoin mining…impacts China’s energy consumption and we could see a ripple effect around the world,” he said via email. “With the end of many countries’ tax years looming, the expectation is that many will dump Bitcoin to ensure they do not get hit with a huge capital gains tax bill. This could be seen as the wall at the end of the tunnel.”
He added, “I’m sure South Korea does not want to see their economy crash and significant GDP wiped overnight in value. The world is watching with huge anticipation.”
Then there are the cybersecurity concerns: For one thing, illicit mining of cryptocurrency by cybercriminals is skyrocketing and is responsible in many ways for the exploding value of currencies like Monero. Also, hacks on exchanges are not infrequent. In July, personal details on 30,000 people were stolen from South Korea-based crypto-currency exchange Bithumb, leading to the theft of funds from their Bitcoin and Ethereum accounts. The company, one of the largest exchanges for virtual currencies in the world, said the data theft happened after an employee's PC was hacked. From there, the hackers used the information to text and call users to con them out of their authentication codes, which were then used to steal funds from the accounts.
Another South Korean Bitcoin exchange, YoBit, was forced to close in December after suffering two major cyber-attacks in one year. It claimed it was “very sorry” but filed for bankruptcy after it suffered the December attack, less than eight months after the first.
In any event, South Korea has much to consider.
“By entertaining the notion of a ban on cryptocurrency trading, South Korea is evaluating whether or not the government can successfully manage the risk of what would happen if those cryptocurrencies collapsed while also promoting what they state is less immoral behaviors due to their view that cryptocurrency trading is akin to gambling and may lead to even worse offenses,” said Wenzler. “This ban, though, would impact a growing number of citizens and could cause a huge backlash against the government, both immediately and in any voting situation. At this point, it may be too early to guess at what a ban on cryptocurrency trading would do to South Korea, either economically or politically, but as the number of South Koreans who use cryptocurrencies increases, this issue will become more challenging to address at a national level.”
Source: info-security
SCADA Apps Riddled With Major Flaws
Mobile applications used in industrial control system (ICS) environments are shot through with vulnerabilities, exposing mission critical processes and infrastructure to attack, according to new research.
IOActive teamed up with IoT specialist Embedi to study 34 mobile applications used in Supervisory Control and Data Acquisition (SCADA) systems — selected at random from the Google Play store.
The number of these apps is growing all the time, so the researchers wanted to see if they’re unduly exposing organizations to the risk of external attack or accidental insider threats.
They found a staggering 147 vulnerabilities altogether — an increase of 1.6 per app from 2015, when the team found 50 issues in 20 such apps.
The top five security weaknesses were: code tampering (94% of the apps studied), insecure authorization (59%), reverse engineering (53%), insecure data storage (47%) and insecure communication (38%).
IOActive explained that the problem comes down to developers rushing apps to market without incorporating security by design.
“There’s not much an end-user can do to fix bugs in a mobile application themselves. The fixes will need to be done by the vendors,” IOActive principal security consultant, Jason Larsen, told Infosecurity.
“A good start would be transparency. If an application is built using secure programming practices and has gone through a review, documenting that would go a long way.”
In fact, attackers don’t even need physical access to the victim’s smartphone. If a user downloads a fake malicious app by mistake then that malware could attack the vulnerable application, the firm claimed.
IOActive recommended SCADA app developers to think carefully about security, noting the OWASP Top 10, OWASP Mobile Top 10 2016, and the 24 Deadly Sins of Software Security could help guide them through best practices.
“This is simply a continuation of the current Industrial Internet of Things (IIoT) trend,” warned IOActive security consultant, Alexander Bolshev. “Over the past two years, the number of applications on Google Play Store has doubled, and some of these applications have been installed 1000-10,000 times.”
Source: info-security
macOS Malware Creator Charged With Spying on Thousands of PCs Over 13 Years
The U.S. Justice Department unsealed 16-count indictment charges on Wednesday against a computer programmer from Ohio who is accused of creating and installing spyware on thousands of computers for more than 13 years.
According to the indictment, 28-year-old Phillip R. Durachinsky is the alleged author of FruitFly malware that was found targeting Apple Mac users earlier last year worldwide, primarily in the United States.
Interestingly, Durachinsky was just 14 years old when he programmed the first version of the FruitFly malware, and this full-fledged backdoor trojan went largely undetected for several years, despite using unsophisticated and antiquated code.
The malware was initially discovered in January 2017 by Malwarebytes and then Patrick Wardle, an ex-NSA hacker, found around 400 Mac computers infected with the newer strain of FruitFly. However, Wardle believed the number of infected Macs would likely be much higher.
The malware is capable of advanced surveillance on macOS devices with the ability to remotely take control of webcams, microphones, screen, mouse, and keyboards, as well as install additional malicious software.
Since the source code of Fruitfly also includes Linux shell commands, the researchers believe the malware would work just fine on Linux operating system.
From 2003 to January 2017, Durachinsky used spyware, which was later named FruitFly, to gain access to thousands of computers belonging to individuals, companies, schools, a police department, and a subsidiary of the U.S. Department of Energy.
Durachinsky allegedly used the malware to steal the personal data of victims, including their tax records, banking records, medical records, login credentials, photographs, Internet searches, and potentially embarrassing communications.
"He is alleged to have developed computer malware later named “Fruitfly” that he installed on computers and that enabled him to control each computer by accessing stored data, uploading files, taking and downloading screenshots, logging a user’s keystrokes, and turning on the camera and microphone to surreptitiously record images and audio," the DoJ says.
Besides installing Fruitfly, Durachinsky is also accused of producing child pornography, as in some cases, the malware alerted him if a user typed any pornography term. It’s likely such action would prompt recording.
Durachinsky is facing charges of Computer Fraud and Abuse Act violations, Wiretap Act violations, production of child pornography, and aggravated identity theft.
However, the charges are merely allegations at this time, and the defendant is presumed innocent unless proven guilty beyond a reasonable doubt in a court of law.
Source: TheHacker News
As Cloud Looms, Security Tops IT Resilience Investment
When it comes to investments in IT resilience, cybersecurity initiatives top the to-do list for most IT departments, as cloud leads the way as the No. 1 threat concern.
According to Syncsort’s 2018 State of Resilience report, which surveyed 5,632 IT professionals globally, ongoing, high-profile hacking attacks, data breaches, disruptive natural disasters and escalating storage and data accessibility needs are top concerns for most businesses. Overall, security is the top initiative that most companies will pursue in the next 24 months (49%). The majority of professionals chose virus protection (71%), malware protection (67%), patch management (53%), and intrusion detection and prevention (IDP, 52%) as their top organizational investments in security today.
IT pros see cloud as the top security challenge: The report found that IT leaders are entrusting critical applications to the cloud, but with concerns. About 43% identify it as their top security challenge for the coming year.
“Certainly, the shared resource pools and always-on features of cloud have introduced the possibility of new security breaches – including data loss, weak identity management, insecure APIs, denial of service attacks, account hijacking and advanced persistent attacks, which infiltrate systems over a period of time,” the firm said in the report.
The second greatest perceived challenge for IT departments is the increasing sophistication of attacks (37%). “Cunning criminals have sharpened their craft, conducting exploratory raids over months, invading systems, hiding their tracks, and deploying malware that can fool customers with bogus messages or extract and steal valuable data – the lifeblood of most companies.”
Ransomware meanwhile appeared as the No. 3 challenge confronting respondents, though Syncsort’s analysis was dubious as to the actual impact: “IT professionals are naturally aware of this phenomenon, as a result of worldwide media coverage. Yet, a considerable majority of professionals in this study had never been attacked by ransomware or were not aware that they had been; a miniscule number had paid to get data back, as mentioned in a subsequent section of this report. It remains to be seen whether ransomware is the flavor of the moment or will be a recurring trend.”
Despite these concerns, internal security audits are infrequent, the report found. Nearly two-thirds of companies perform security audits on their systems, but the most common schedule was to do it on an annual basis (39%). Another 10% of respondents audit every two years or more, which, given an ever-changing IT environment, could expose a company to risk.
The report also found that data sharing is seen as critical but challenging. About half (53%) of companies surveyed have multiple databases and share data to improve business intelligence, largely through scripting (42%), followed by backup/restore/snapshot processes and FTP/SCP/file transfer (38% each). The average company uses two different methods, adding to the complexity. In turn, this bolsters security concerns.
“IT leaders are under immense pressure to provide an enterprise infrastructure that can sustain severe threats and secure vital information while enabling data accessibility and business intelligence,” said Terry Plath, vice president, Global Services, Syncsort. “Business resilience requires the right mix of planning and technology, and this survey did a thorough job of uncovering how businesses are tackling this increasingly complex and multi-faceted challenge.”
Source: Threatpost
FBI Boss: We Don’t Want Backdoors, but We Do Want Access to Encrypted Devices
The FBI has nearly 7800 devices it can’t access because of encryption, according to its director, who repeated calls yesterday for tech providers to find a solution to the issue that doesn’t involve creating backdoors.
In a speech to the International Conference on Cyber Security, Wray claimed the Feds were unable to access 7775 encrypted devices last year — far higher than the 6900 figure touted in October.
He argued this was fast becoming an “urgent public safety issue” which would only get worse over time unless US technology companies engineer a “responsible” solution.
“We’re not looking for a ‘back door’ – which I understand to mean some type of secret, insecure means of access,” he said. “What we’re asking for is the ability to access the device once we’ve obtained a warrant from an independent judge, who has said we have probable cause.”
However, experts have argued that the only way to give the FBI what it’s asking for is indeed engineering a de facto backdoor.
This would put the privacy and security of hundreds of millions of devices potentially at risk if it fell into the wrong hands, and could even be abused by over-reaching law enforcers, whilst putting pressure on providers like Apple to do the same in countries with poor human rights records, the argument goes.
Whilst admitting a possible solution “isn’t so clear-cut,” Wray’s main line of argument was that US companies lead the world in innovation, so they should be able to find a way to allow law enforcers limited access to devices for which they have a warrant, without breaking security for law-abiding users.
He also claimed that US tech firms are already acceding to requests for customer data by foreign governments, although crucially didn’t go as far as to claim firms like Apple had broken their own encryption to do so.
“The FBI supports information security measures, including strong encryption,” said Wray. “But information security programs need to be thoughtfully designed so they don’t undermine the lawful tools we need to keep this country safe.”
The news comes as researchers unveiled a new end-to-end encrypted group chat protocol, dubbed Asynchronous Ratcheting Tree (ART).
Facebook and Oxford University teamed up on the project, which overcomes inadequacies in current solutions where if one member of the group is hacked then all conversations can be accessed.
This latest innovation in encrypted messaging is unlikely to go down well with law enforcers on either side of the Atlantic.
Source: Info-Sec
Reddit Users Lose Bitcoin Tips After Third-Party Breach
Reddit has confirmed that one of its email providers, Mailgun, has been breached, resulting in the hacks of user profiles and their linked cryptocurrency accounts.
Attackers infiltrated Reddit accounts using password reset emails sent via the third-party vendor. Several Redditors also reported that their Bitcoin Cash tip accounts had been emptied out.
Despite the alarming details, Reddit urged the public to maintain perspective, noting that the attackers “did not have access to either Reddit’s systems or to a Redditor’s email account,” adding that the number of confirmed impacted users is less than 20 so far.
“On 12/31, Reddit received several reports regarding password reset emails that were initiated and completed without the account owners’ requests,” Reddit explained in a post. “We have been working to investigate the issue and coordinating with Mailgun, a third-party vendor we’ve been using to send some of our account emails including password reset emails,” it continued. “A malicious actor targeted Mailgun and gained access to Reddit’s password reset emails….We know this is frustrating as a user, and we have put additional controls in place to help make sure it doesn’t happen again.”
Mailgun, for its part, said that it has identified the attack vector—an employee’s compromised email account—and has patched the issue.
“On January 3, 2018, Mailgun became aware of an incident in which a customer’s API key was compromised and immediately began diagnostics to help determine the cause and the scope of impact,” Mailgun CTO Josh Odom wrote in a post. “We immediately closed the point of access to the unauthorized user and deployed additional technical safeguards to further protect this sensitive portion of our application.”
He added that the attack affected less than 1% of Mailgun’s entire customer base.
Source:
Info-Security
Intel Tiger Lake CPUs to come with Anti-Malware Protection
Intel’s Tiger Lake CPUs will come with Control-flow Enforcement Technology (CET), aimed at battling common control-flow hijacking attacks. I...
-
Last April, Steven Schoen received an email from someone named Natalie Andrea who said she worked for a company called We Purchase Apps. She...
-
Intel’s Tiger Lake CPUs will come with Control-flow Enforcement Technology (CET), aimed at battling common control-flow hijacking attacks. I...
-
By Carl Herberger This is Part 2 of our series on the top 5 most dangerous DDoS attacks and how you can successfully mitigate them. ATTAC...