Authors of the MacDefender malware issued a new version Tuesday that works around an Apple (NSDQ:AAPL) security update designed to block it.
Earlier Tuesday, Apple released a security a update for Mac OS X 10.6.7, update 2011-003, that included malware detection and removal for the MacDefender phishing attack and its variants.
However, by about 9 p.m. PST, a new variant was detected, said Chester Wisniewski, a senior security advisor at U.K.-based Sophos.
"We noticed it in the U.K. and started seeing samples that were not detected in the Apple update,” Wisniewski said. “We weren't surprised because we thought it wouldn’t take the bad guys long to modify the malware.”
The malware is called “scareware” because it tries to frighten users into thinking a virus has invaded their computer, then tricks users into entering their credit card numbers to purchase fake security software.
Wisniewski said he wasn't surprised that Apple’s security update was circumvented. Apple has been targeted less than Microsoft historically and is less experienced at fighting off attacks, he said, adding that Apple is now re-evaluating its security response.
“We are seeing the re-invention of the wheel on the Apple platform for security,” he said. “Clearly the bad guys have been innovating a lot to be able to do this. They must be making money and want to make more. This is the first time criminals have really targeted Apple.
“My advise to all Mac users is to run some antivirus,” Wisniewski added.
Apple representatives could not be reached for comment Wednesday.
However, one Apple managed services provider said MacDefender does not pose a large-scale threat.
Alberto Palacios, systems engineer with Create More Inc., a San Francisco, Calif.-based MSP, said his company has received just one emergency call for help from a home user who then figured out how to remove the malware himself.
“I don’t think [MacDefender] is a big deal because, quite honestly, it’s a user-initiated issue," Palacios said. "You have to click a button that says, ‘Install this on my computer.’
"It’s malware not a virus, so it’s due to bad user behavior. I don’t think it says anything bad about Apple," he added. "We haven’t had any businesses contact us, just home users. It’s relatively easy to take care of. We had one emergency call from a client who was a home user and within five minutes he called back and said, ‘I took care of it myself.’ “
SOURCE
http://www.crn.com/
Friday, June 3, 2011
Google Points To China As Source Of 'Targeted' Gmail Phishing Attack
Chinese officials are on the defensive after Google fingered China as the source of a sophisticated phishing attack targeting many high profile Gmail account holders, including U.S. government officials. But security experts says the attack, if true, continues a growing trend of sophisticated attacks used by nation states for cyber espionage purposes.
In a blog post Wednesday, Google (NSDQ:GOOG) said that it discovered a targeted phishing campaign appearing to be sourced from Jinan, China , affecting hundreds of Gmail users, including senior U.S. government officials, Chinese political activists, officials in South Korea and other Asian countries, as well as military personnel and journalists.
Google said that the phishing campaign, executed by stealing users' passwords, was launched in an effort to infiltrate users' Gmail accounts and monitor their activity.
"The goal of this effort seems to have been to monitor the contents of these users' e-mails, with the perpetrators apparently using stolen passwords to change peoples' forwarding and delegation settings," Google said in a blog post Wednesday.
During that attack, victims were compelled to open an e-mail appearing to come from someone they knew. The e-mail message used social engineering techniques with highly personalized content to entice them to click on links that took them to malicious sites impersonating the Gmail login screen.
"The telltale sign to note here was the fact that it took them back to a Gmail login screen after they were already in their account. That's never a good sign," said Fred Touchette, senior security analyst for AppRiver. "The fake log-in screen in these attacks also had multiple flaws that should have clued the victims to the fact that something was amiss as well."
Google said that it had already "detected and disrupted" the campaign aimed at hacking into military Gmail accounts, adding that the victims and appropriate government authorities have been notified.
China has since emphatically denied Google's allegations that the spear phishing attack originated in the world's most populous country, calling the search giant's claims "unacceptable."
"Blaming these misdeeds on China is unacceptable," said Hong Lei, Chinese foreign ministry spokesman in a news conference, according to The Telegraph .
Meanwhile an editorial, published by, Xinhua, the official Chinese news agency , said that Google's "groundless" accusations were damaging diplomatic relations and trust between the two countries, stating that "it was too imprudent for the online giant to lash out at others without solid proof to support its accusations.
"The chimerical complaints by Google have become obstacles for enhancing global trust between stakeholders in cyberspace," Xinhua said, adding "It is a real pity that Google's baseless complaints have distressed mutual trust and the efforts to establish new global governance in cyberspace, letting real online criminals obtain illegal profits without being punished."
Xinhua said that this was the second time that "Google arbitrarily pointed its finger at China," citing last year's allegations that the Chinese government perpetrated a hacker attack against the search giant, and elicited the help of the U.S. National Security Agency, which Xinxua said was "a serious threat to Internet neutrality.
"It is not appropriate for Google, a profit-first business, to act as an Internet judge," Xinhua said.
However, security experts say that this particular attack is likely continuing a trend of phishing campaigns that are being used as weapons in more comprehensive cyber espionage efforts.
"The espionage angle has been brought to light progressively more lately, which is unsettling to most that it is happening, but unfortunately this isn't all that new either. We're just now starting to find out about them," said Fred Touchette, senior security analyst at AppRiver. "We have seen more and more directed spear phishing attacks against individuals and/or specific companies over the past few years. This is troubling news because they are usually harder to notice due to their customization but in no way will this affect eh cast net style approach of phishing."
Meanwhile, security solution providers say that the Gmail phishing attack doesn't necessarily imply that Google (NSDQ:GOOG) fell short in its security implementations.
"This isn't new. This isn't Google being hacked. This is people hacking themselves. It's just a phishing attack,' said Leo Bletnitsky, CEO of Las Vegas-based Las Vegas Med IT and Desktop Valet. "Nobody should be doing anything confidential over Gmail anyway. You assume that Google is indexing everything anyway."
Bletnitsky said that to prevent becoming the victim of a phishing attack, he regularly tells his customers to check the URLs and avoid clicking unfamiliar links, as well as questioning apps or Web sites that request users to re-enter a password when they're already logged in to a site.
"If something is behaving differently than it did before, you have to question it," he said.
The recent Gmail attack marks another point of contention in a tumultuous history between China and the search giant. Google's relations with China took a nosedive with a massive targeted attack on the search giant in January 2010, known as Operation Aurora , targeting Google source code and intellectual property.
Meanwhile, Touchette said that it was unclear if Google's previous history with China contributed to the swiftness of its public accusations.
"While it is slightly unusual that Google has made public this particular attack, it's hard to tell whether their past issues with China have had a role in the reason they did so," Touchette said. "I don’t think they're personally overhyping the situation, but rather letting everyone else take care of that for them."
SOURCE
www.crn.com
In a blog post Wednesday, Google (NSDQ:GOOG) said that it discovered a targeted phishing campaign appearing to be sourced from Jinan, China , affecting hundreds of Gmail users, including senior U.S. government officials, Chinese political activists, officials in South Korea and other Asian countries, as well as military personnel and journalists.
Google said that the phishing campaign, executed by stealing users' passwords, was launched in an effort to infiltrate users' Gmail accounts and monitor their activity.
"The goal of this effort seems to have been to monitor the contents of these users' e-mails, with the perpetrators apparently using stolen passwords to change peoples' forwarding and delegation settings," Google said in a blog post Wednesday.
During that attack, victims were compelled to open an e-mail appearing to come from someone they knew. The e-mail message used social engineering techniques with highly personalized content to entice them to click on links that took them to malicious sites impersonating the Gmail login screen.
"The telltale sign to note here was the fact that it took them back to a Gmail login screen after they were already in their account. That's never a good sign," said Fred Touchette, senior security analyst for AppRiver. "The fake log-in screen in these attacks also had multiple flaws that should have clued the victims to the fact that something was amiss as well."
Google said that it had already "detected and disrupted" the campaign aimed at hacking into military Gmail accounts, adding that the victims and appropriate government authorities have been notified.
China has since emphatically denied Google's allegations that the spear phishing attack originated in the world's most populous country, calling the search giant's claims "unacceptable."
"Blaming these misdeeds on China is unacceptable," said Hong Lei, Chinese foreign ministry spokesman in a news conference, according to The Telegraph .
Meanwhile an editorial, published by, Xinhua, the official Chinese news agency , said that Google's "groundless" accusations were damaging diplomatic relations and trust between the two countries, stating that "it was too imprudent for the online giant to lash out at others without solid proof to support its accusations.
"The chimerical complaints by Google have become obstacles for enhancing global trust between stakeholders in cyberspace," Xinhua said, adding "It is a real pity that Google's baseless complaints have distressed mutual trust and the efforts to establish new global governance in cyberspace, letting real online criminals obtain illegal profits without being punished."
Xinhua said that this was the second time that "Google arbitrarily pointed its finger at China," citing last year's allegations that the Chinese government perpetrated a hacker attack against the search giant, and elicited the help of the U.S. National Security Agency, which Xinxua said was "a serious threat to Internet neutrality.
"It is not appropriate for Google, a profit-first business, to act as an Internet judge," Xinhua said.
However, security experts say that this particular attack is likely continuing a trend of phishing campaigns that are being used as weapons in more comprehensive cyber espionage efforts.
"The espionage angle has been brought to light progressively more lately, which is unsettling to most that it is happening, but unfortunately this isn't all that new either. We're just now starting to find out about them," said Fred Touchette, senior security analyst at AppRiver. "We have seen more and more directed spear phishing attacks against individuals and/or specific companies over the past few years. This is troubling news because they are usually harder to notice due to their customization but in no way will this affect eh cast net style approach of phishing."
Meanwhile, security solution providers say that the Gmail phishing attack doesn't necessarily imply that Google (NSDQ:GOOG) fell short in its security implementations.
"This isn't new. This isn't Google being hacked. This is people hacking themselves. It's just a phishing attack,' said Leo Bletnitsky, CEO of Las Vegas-based Las Vegas Med IT and Desktop Valet. "Nobody should be doing anything confidential over Gmail anyway. You assume that Google is indexing everything anyway."
Bletnitsky said that to prevent becoming the victim of a phishing attack, he regularly tells his customers to check the URLs and avoid clicking unfamiliar links, as well as questioning apps or Web sites that request users to re-enter a password when they're already logged in to a site.
"If something is behaving differently than it did before, you have to question it," he said.
The recent Gmail attack marks another point of contention in a tumultuous history between China and the search giant. Google's relations with China took a nosedive with a massive targeted attack on the search giant in January 2010, known as Operation Aurora , targeting Google source code and intellectual property.
Meanwhile, Touchette said that it was unclear if Google's previous history with China contributed to the swiftness of its public accusations.
"While it is slightly unusual that Google has made public this particular attack, it's hard to tell whether their past issues with China have had a role in the reason they did so," Touchette said. "I don’t think they're personally overhyping the situation, but rather letting everyone else take care of that for them."
SOURCE
www.crn.com
New Microsoft Support Scam Downloads Malware
A new version of the Microsoft Support scam has emerged, attempting to convince users to install a malicious application claiming to "fix" their machines, according to SANS Institute researchers.
The latest version occurs when a scammer calls victims, impersonating Microsoft support personnel, and attempts to get them to directly install a Teamviewer application -- allegedly to fix the machine, but which ultimately takes control of the users' computer and sifts through files for information to steal.
"The scam is obviously still working. It seems they have figured out that users can't be trusted to click a link, but installing remote control software and getting you to install the malware for them is ok,' said SANS Institute researcher Mark Hofman, in a blog post.
In another version of the support con, the scammers on the other end of the phone would attempt to get the victim to click through the event viewer to "find something red." Once a problem was identified, users would be directed by phony support personnel to a Web site where they would be directed to download malware after submitting credit card information.
"Strangely enough there is usually something red in most people's event log log," Hofman said. 'However, do not despair if you don’t have anything red, yellow is just as bad."
While Microsoft support scams have been around for a while, new versions have surfaced in the last six months that actually attempt to download malware by convincing the user to install an application, or bringing them to a malicious link, experts say.
In general, users are told there is something wrong with their computer and are typically taken through various screens indicating various warning and alerts to corroborate the claim, before being swayed to download or update software such as computer care warranties. The victim is then encouraged to submit credit card numbers in order to purchase the phony software, that is either bogus or malicious.
In one instance, reported by the U.K.'s Guardian , the scammer said that she was from "Windows Service Centre" based in East London, and claimed that she had found numerous error reports that had come through the computer causing latency issues.
In previous Microsoft support schemes, scammers call victims claiming to be from the Microsoft support center, and falsely alerting them that their computers are inundated with viruses. The phonyhelp desk personnel would then convince the user to provide credit card information in exchange for bogus helpdesk advice, however no malware would be downloaded.
Meanwhile, Microsoft says that it will never make unsolicited calls or e-mails offering help services in exchange for money.
"We do not send unsolicited email messages or make unsolicited phone calls to request personal or financial information or fix your computer," Microsoft said on its Web site ."If you receive an unsolicited email message or phone call that purports to be from Microsoft and requests that you send personal information or click links, delete the message or hang up the phone."
Source:
http://www.crn.com/
Subscribe to:
Posts (Atom)


