Authors of the MacDefender malware issued a new version Tuesday that works around an Apple (NSDQ:AAPL) security update designed to block it.
Earlier Tuesday, Apple released a security a update for Mac OS X 10.6.7, update 2011-003, that included malware detection and removal for the MacDefender phishing attack and its variants.
However, by about 9 p.m. PST, a new variant was detected, said Chester Wisniewski, a senior security advisor at U.K.-based Sophos.
"We noticed it in the U.K. and started seeing samples that were not detected in the Apple update,” Wisniewski said. “We weren't surprised because we thought it wouldn’t take the bad guys long to modify the malware.”
The malware is called “scareware” because it tries to frighten users into thinking a virus has invaded their computer, then tricks users into entering their credit card numbers to purchase fake security software.
Wisniewski said he wasn't surprised that Apple’s security update was circumvented. Apple has been targeted less than Microsoft historically and is less experienced at fighting off attacks, he said, adding that Apple is now re-evaluating its security response.
“We are seeing the re-invention of the wheel on the Apple platform for security,” he said. “Clearly the bad guys have been innovating a lot to be able to do this. They must be making money and want to make more. This is the first time criminals have really targeted Apple.
“My advise to all Mac users is to run some antivirus,” Wisniewski added.
Apple representatives could not be reached for comment Wednesday.
However, one Apple managed services provider said MacDefender does not pose a large-scale threat.
Alberto Palacios, systems engineer with Create More Inc., a San Francisco, Calif.-based MSP, said his company has received just one emergency call for help from a home user who then figured out how to remove the malware himself.
“I don’t think [MacDefender] is a big deal because, quite honestly, it’s a user-initiated issue," Palacios said. "You have to click a button that says, ‘Install this on my computer.’
"It’s malware not a virus, so it’s due to bad user behavior. I don’t think it says anything bad about Apple," he added. "We haven’t had any businesses contact us, just home users. It’s relatively easy to take care of. We had one emergency call from a client who was a home user and within five minutes he called back and said, ‘I took care of it myself.’ “
SOURCE
http://www.crn.com/
Friday, June 3, 2011
Google Points To China As Source Of 'Targeted' Gmail Phishing Attack
Chinese officials are on the defensive after Google fingered China as the source of a sophisticated phishing attack targeting many high profile Gmail account holders, including U.S. government officials. But security experts says the attack, if true, continues a growing trend of sophisticated attacks used by nation states for cyber espionage purposes.
In a blog post Wednesday, Google (NSDQ:GOOG) said that it discovered a targeted phishing campaign appearing to be sourced from Jinan, China , affecting hundreds of Gmail users, including senior U.S. government officials, Chinese political activists, officials in South Korea and other Asian countries, as well as military personnel and journalists.
Google said that the phishing campaign, executed by stealing users' passwords, was launched in an effort to infiltrate users' Gmail accounts and monitor their activity.
"The goal of this effort seems to have been to monitor the contents of these users' e-mails, with the perpetrators apparently using stolen passwords to change peoples' forwarding and delegation settings," Google said in a blog post Wednesday.
During that attack, victims were compelled to open an e-mail appearing to come from someone they knew. The e-mail message used social engineering techniques with highly personalized content to entice them to click on links that took them to malicious sites impersonating the Gmail login screen.
"The telltale sign to note here was the fact that it took them back to a Gmail login screen after they were already in their account. That's never a good sign," said Fred Touchette, senior security analyst for AppRiver. "The fake log-in screen in these attacks also had multiple flaws that should have clued the victims to the fact that something was amiss as well."
Google said that it had already "detected and disrupted" the campaign aimed at hacking into military Gmail accounts, adding that the victims and appropriate government authorities have been notified.
China has since emphatically denied Google's allegations that the spear phishing attack originated in the world's most populous country, calling the search giant's claims "unacceptable."
"Blaming these misdeeds on China is unacceptable," said Hong Lei, Chinese foreign ministry spokesman in a news conference, according to The Telegraph .
Meanwhile an editorial, published by, Xinhua, the official Chinese news agency , said that Google's "groundless" accusations were damaging diplomatic relations and trust between the two countries, stating that "it was too imprudent for the online giant to lash out at others without solid proof to support its accusations.
"The chimerical complaints by Google have become obstacles for enhancing global trust between stakeholders in cyberspace," Xinhua said, adding "It is a real pity that Google's baseless complaints have distressed mutual trust and the efforts to establish new global governance in cyberspace, letting real online criminals obtain illegal profits without being punished."
Xinhua said that this was the second time that "Google arbitrarily pointed its finger at China," citing last year's allegations that the Chinese government perpetrated a hacker attack against the search giant, and elicited the help of the U.S. National Security Agency, which Xinxua said was "a serious threat to Internet neutrality.
"It is not appropriate for Google, a profit-first business, to act as an Internet judge," Xinhua said.
However, security experts say that this particular attack is likely continuing a trend of phishing campaigns that are being used as weapons in more comprehensive cyber espionage efforts.
"The espionage angle has been brought to light progressively more lately, which is unsettling to most that it is happening, but unfortunately this isn't all that new either. We're just now starting to find out about them," said Fred Touchette, senior security analyst at AppRiver. "We have seen more and more directed spear phishing attacks against individuals and/or specific companies over the past few years. This is troubling news because they are usually harder to notice due to their customization but in no way will this affect eh cast net style approach of phishing."
Meanwhile, security solution providers say that the Gmail phishing attack doesn't necessarily imply that Google (NSDQ:GOOG) fell short in its security implementations.
"This isn't new. This isn't Google being hacked. This is people hacking themselves. It's just a phishing attack,' said Leo Bletnitsky, CEO of Las Vegas-based Las Vegas Med IT and Desktop Valet. "Nobody should be doing anything confidential over Gmail anyway. You assume that Google is indexing everything anyway."
Bletnitsky said that to prevent becoming the victim of a phishing attack, he regularly tells his customers to check the URLs and avoid clicking unfamiliar links, as well as questioning apps or Web sites that request users to re-enter a password when they're already logged in to a site.
"If something is behaving differently than it did before, you have to question it," he said.
The recent Gmail attack marks another point of contention in a tumultuous history between China and the search giant. Google's relations with China took a nosedive with a massive targeted attack on the search giant in January 2010, known as Operation Aurora , targeting Google source code and intellectual property.
Meanwhile, Touchette said that it was unclear if Google's previous history with China contributed to the swiftness of its public accusations.
"While it is slightly unusual that Google has made public this particular attack, it's hard to tell whether their past issues with China have had a role in the reason they did so," Touchette said. "I don’t think they're personally overhyping the situation, but rather letting everyone else take care of that for them."
SOURCE
www.crn.com
In a blog post Wednesday, Google (NSDQ:GOOG) said that it discovered a targeted phishing campaign appearing to be sourced from Jinan, China , affecting hundreds of Gmail users, including senior U.S. government officials, Chinese political activists, officials in South Korea and other Asian countries, as well as military personnel and journalists.
Google said that the phishing campaign, executed by stealing users' passwords, was launched in an effort to infiltrate users' Gmail accounts and monitor their activity.
"The goal of this effort seems to have been to monitor the contents of these users' e-mails, with the perpetrators apparently using stolen passwords to change peoples' forwarding and delegation settings," Google said in a blog post Wednesday.
During that attack, victims were compelled to open an e-mail appearing to come from someone they knew. The e-mail message used social engineering techniques with highly personalized content to entice them to click on links that took them to malicious sites impersonating the Gmail login screen.
"The telltale sign to note here was the fact that it took them back to a Gmail login screen after they were already in their account. That's never a good sign," said Fred Touchette, senior security analyst for AppRiver. "The fake log-in screen in these attacks also had multiple flaws that should have clued the victims to the fact that something was amiss as well."
Google said that it had already "detected and disrupted" the campaign aimed at hacking into military Gmail accounts, adding that the victims and appropriate government authorities have been notified.
China has since emphatically denied Google's allegations that the spear phishing attack originated in the world's most populous country, calling the search giant's claims "unacceptable."
"Blaming these misdeeds on China is unacceptable," said Hong Lei, Chinese foreign ministry spokesman in a news conference, according to The Telegraph .
Meanwhile an editorial, published by, Xinhua, the official Chinese news agency , said that Google's "groundless" accusations were damaging diplomatic relations and trust between the two countries, stating that "it was too imprudent for the online giant to lash out at others without solid proof to support its accusations.
"The chimerical complaints by Google have become obstacles for enhancing global trust between stakeholders in cyberspace," Xinhua said, adding "It is a real pity that Google's baseless complaints have distressed mutual trust and the efforts to establish new global governance in cyberspace, letting real online criminals obtain illegal profits without being punished."
Xinhua said that this was the second time that "Google arbitrarily pointed its finger at China," citing last year's allegations that the Chinese government perpetrated a hacker attack against the search giant, and elicited the help of the U.S. National Security Agency, which Xinxua said was "a serious threat to Internet neutrality.
"It is not appropriate for Google, a profit-first business, to act as an Internet judge," Xinhua said.
However, security experts say that this particular attack is likely continuing a trend of phishing campaigns that are being used as weapons in more comprehensive cyber espionage efforts.
"The espionage angle has been brought to light progressively more lately, which is unsettling to most that it is happening, but unfortunately this isn't all that new either. We're just now starting to find out about them," said Fred Touchette, senior security analyst at AppRiver. "We have seen more and more directed spear phishing attacks against individuals and/or specific companies over the past few years. This is troubling news because they are usually harder to notice due to their customization but in no way will this affect eh cast net style approach of phishing."
Meanwhile, security solution providers say that the Gmail phishing attack doesn't necessarily imply that Google (NSDQ:GOOG) fell short in its security implementations.
"This isn't new. This isn't Google being hacked. This is people hacking themselves. It's just a phishing attack,' said Leo Bletnitsky, CEO of Las Vegas-based Las Vegas Med IT and Desktop Valet. "Nobody should be doing anything confidential over Gmail anyway. You assume that Google is indexing everything anyway."
Bletnitsky said that to prevent becoming the victim of a phishing attack, he regularly tells his customers to check the URLs and avoid clicking unfamiliar links, as well as questioning apps or Web sites that request users to re-enter a password when they're already logged in to a site.
"If something is behaving differently than it did before, you have to question it," he said.
The recent Gmail attack marks another point of contention in a tumultuous history between China and the search giant. Google's relations with China took a nosedive with a massive targeted attack on the search giant in January 2010, known as Operation Aurora , targeting Google source code and intellectual property.
Meanwhile, Touchette said that it was unclear if Google's previous history with China contributed to the swiftness of its public accusations.
"While it is slightly unusual that Google has made public this particular attack, it's hard to tell whether their past issues with China have had a role in the reason they did so," Touchette said. "I don’t think they're personally overhyping the situation, but rather letting everyone else take care of that for them."
SOURCE
www.crn.com
New Microsoft Support Scam Downloads Malware
A new version of the Microsoft Support scam has emerged, attempting to convince users to install a malicious application claiming to "fix" their machines, according to SANS Institute researchers.
The latest version occurs when a scammer calls victims, impersonating Microsoft support personnel, and attempts to get them to directly install a Teamviewer application -- allegedly to fix the machine, but which ultimately takes control of the users' computer and sifts through files for information to steal.
"The scam is obviously still working. It seems they have figured out that users can't be trusted to click a link, but installing remote control software and getting you to install the malware for them is ok,' said SANS Institute researcher Mark Hofman, in a blog post.
In another version of the support con, the scammers on the other end of the phone would attempt to get the victim to click through the event viewer to "find something red." Once a problem was identified, users would be directed by phony support personnel to a Web site where they would be directed to download malware after submitting credit card information.
"Strangely enough there is usually something red in most people's event log log," Hofman said. 'However, do not despair if you don’t have anything red, yellow is just as bad."
While Microsoft support scams have been around for a while, new versions have surfaced in the last six months that actually attempt to download malware by convincing the user to install an application, or bringing them to a malicious link, experts say.
In general, users are told there is something wrong with their computer and are typically taken through various screens indicating various warning and alerts to corroborate the claim, before being swayed to download or update software such as computer care warranties. The victim is then encouraged to submit credit card numbers in order to purchase the phony software, that is either bogus or malicious.
In one instance, reported by the U.K.'s Guardian , the scammer said that she was from "Windows Service Centre" based in East London, and claimed that she had found numerous error reports that had come through the computer causing latency issues.
In previous Microsoft support schemes, scammers call victims claiming to be from the Microsoft support center, and falsely alerting them that their computers are inundated with viruses. The phonyhelp desk personnel would then convince the user to provide credit card information in exchange for bogus helpdesk advice, however no malware would be downloaded.
Meanwhile, Microsoft says that it will never make unsolicited calls or e-mails offering help services in exchange for money.
"We do not send unsolicited email messages or make unsolicited phone calls to request personal or financial information or fix your computer," Microsoft said on its Web site ."If you receive an unsolicited email message or phone call that purports to be from Microsoft and requests that you send personal information or click links, delete the message or hang up the phone."
Source:
http://www.crn.com/Monday, May 23, 2011
Rogue Apps Might Spoil Your Fun around Champions League Final
Placing a bet in favor of your favorite team around the Champions league final can get real ugly for your bank account
E-mail lotteries, last minute tickets bargains, surprise ticket winnings and promo vacation package for the Champions League final are flooding the Internet this month. It may be difficult for you to be able to filter all that’s coming to you these weeks, since all these scams are ever more perfected as they prove to be extremely rewarding for the crooks.
Taking advantage by the increased search queries placed with popular search engines around highly-mediatized events such as football cup finals, concerts, royal weddings or famous people’s death, cyber-criminals set up both old and new traps for enthusiastic and curious computer users. The Champions League final is no exception to the rule as various baits are thrown at fans who might get lured into taking a costly “opportunity”.
These past years, our labs saw a couple of social engineering-based scams especially crafted to take advantage of fans around important soccer competitions. One of them is the Champions League E-mail Lottery according to which “the Local Organizing Committee of the European Champions League” was “glad to announce to the world the giving away of the sum of SEVEN HUNDRED THOUSAND UNITED STATES DOLLARS to 100 lucky email addresses all over the world.” The users’ e-mails were claimed to have been randomly chosen “through a computer ballot system drawn from over 1,500,000 companies and individual E-mail addresses database”. All they need to do was fill in a form with a lot of sensitive data amongst which name, address, e-mail, occupation, country and credit card info. The crooks were this way able to put their hands on a large amount of info, which later on could be used for malicious activities such as spam, money mulling or impersonations.
Another malicious initiative spotted around the Champions League final was a spam campaigns meant to target UK-based football fans that were of course eager to get a ticket to the final. The scam ran like this: the users had to send an SMS message to a short telephone number and vote for their favorite team in order to sign-up for a free-ticket lottery. This SMS, however, cost the UK football fans “£5 excluding VAT," which alone brought the crooks a significant gain. Needless to say, that no one ever won a ticket to the final out of that scam.
Euphoria, friends, favorite team might end up badly. For this year, I would like you to imagine the following scenario: it is Saturday, 28th of May and you are with your friends watching the confrontation between FC Barcelona and Manchester United FC. The game turns out to be as you’ve anticipated and you decide even to place a bet. But make sure this bet doesn’t cost you too much in the end. Wi-Fi enabled mobile phones present a high risk with respect to the privacy of your data transfer. The login credentials can be intercepted somewhere in between your smartphone, PC or laptop and the betting website.
The Internet is full of rogue applications containing dodgy code meant to steal sensitive data from your smartphone. All these applications are “malformed” versions of legal apps (such as Photo Editor,Scientific Calculator, Super History Eraser, Super Guitar Solo, APP Uninstaller only to name a few) which could easily make them pass as safe since some of the users have already downloaded a few of the legit ones. This is what we call hiding in plain sight.
Google has banned a lot of these dangerous applications from the Android Market in order to protect the unwary users from becoming targets. However, it is not safe to say that all the malicious apps are out, since around events their number usually starts growing and they become targeted, thus harder to spot. And once downloaded onto the mobiles, these well-disguised spies “agents” start gathering critical data that is immediately sent to crooks while also leaving a backdoor open for future remote wrong-doings.
Some other applications impersonate e-banking or stock manipulation services, but instead they are mere phishing tools that simply deprive you of your credentials first to either rob you or steal your identity later on. So should you decide to place a bet via your smartphone and you are not paying attention to the app you are using in this direction, then you might end up accessing a page that has been spoofed or had been created for such events only that is designed to take your credentials and end up with your money and/or your identity.
Spam and phishing carrying e-mails may also bombard you these days around the Champions league finals. Crooks may feed you either a nice story about you being the lucky winner of a premium ticket to the final at Wembley or links towards your favorite online betting website, where you can make a fortune. But whatever you do, firstly make sure that you land on the right page by checking the browser’s URL bar and also look for the presence of a security certificate. Manually entering the website’s address may prove to be a blessing in this case as compared to taking a chance and clicking a link received through instant messaging services or via mail.
Crooks come up with various scams created to meet the exact need and interest of a variety of computer & smartphone users. That is why you need to proceed with caution when you decide to buy a ticket from eBay, for instance. It is possible that, although advertised, the item doesn’t exist and chances are that you end up paying for something that will never be delivered to you. Moreover, never consider yourself as lucky as to win a ticket if you’ve never signed up for such a contest.
Last, but not least, if you’re a fan of “Artificial Intelligence”-based predictions, be careful as to what prediction software you’re using. Around sports events, malware creators usually come up with rogue “sports prediction software”, which are highly expensive applications that randomly display the “probable” scores. Other such applications which are distributed for free can carry malware, so make sure that you’ve scanned them with an updated antivirus before using them.
http://www.malwarecity.com/blog/rogue-apps-might-spoil-your-fun-around-champions-league-final-1078.html
E-mail lotteries, last minute tickets bargains, surprise ticket winnings and promo vacation package for the Champions League final are flooding the Internet this month. It may be difficult for you to be able to filter all that’s coming to you these weeks, since all these scams are ever more perfected as they prove to be extremely rewarding for the crooks.
Taking advantage by the increased search queries placed with popular search engines around highly-mediatized events such as football cup finals, concerts, royal weddings or famous people’s death, cyber-criminals set up both old and new traps for enthusiastic and curious computer users. The Champions League final is no exception to the rule as various baits are thrown at fans who might get lured into taking a costly “opportunity”.
These past years, our labs saw a couple of social engineering-based scams especially crafted to take advantage of fans around important soccer competitions. One of them is the Champions League E-mail Lottery according to which “the Local Organizing Committee of the European Champions League” was “glad to announce to the world the giving away of the sum of SEVEN HUNDRED THOUSAND UNITED STATES DOLLARS to 100 lucky email addresses all over the world.” The users’ e-mails were claimed to have been randomly chosen “through a computer ballot system drawn from over 1,500,000 companies and individual E-mail addresses database”. All they need to do was fill in a form with a lot of sensitive data amongst which name, address, e-mail, occupation, country and credit card info. The crooks were this way able to put their hands on a large amount of info, which later on could be used for malicious activities such as spam, money mulling or impersonations.
Another malicious initiative spotted around the Champions League final was a spam campaigns meant to target UK-based football fans that were of course eager to get a ticket to the final. The scam ran like this: the users had to send an SMS message to a short telephone number and vote for their favorite team in order to sign-up for a free-ticket lottery. This SMS, however, cost the UK football fans “£5 excluding VAT," which alone brought the crooks a significant gain. Needless to say, that no one ever won a ticket to the final out of that scam.
Euphoria, friends, favorite team might end up badly. For this year, I would like you to imagine the following scenario: it is Saturday, 28th of May and you are with your friends watching the confrontation between FC Barcelona and Manchester United FC. The game turns out to be as you’ve anticipated and you decide even to place a bet. But make sure this bet doesn’t cost you too much in the end. Wi-Fi enabled mobile phones present a high risk with respect to the privacy of your data transfer. The login credentials can be intercepted somewhere in between your smartphone, PC or laptop and the betting website.
The Internet is full of rogue applications containing dodgy code meant to steal sensitive data from your smartphone. All these applications are “malformed” versions of legal apps (such as Photo Editor,Scientific Calculator, Super History Eraser, Super Guitar Solo, APP Uninstaller only to name a few) which could easily make them pass as safe since some of the users have already downloaded a few of the legit ones. This is what we call hiding in plain sight.
Google has banned a lot of these dangerous applications from the Android Market in order to protect the unwary users from becoming targets. However, it is not safe to say that all the malicious apps are out, since around events their number usually starts growing and they become targeted, thus harder to spot. And once downloaded onto the mobiles, these well-disguised spies “agents” start gathering critical data that is immediately sent to crooks while also leaving a backdoor open for future remote wrong-doings.
Some other applications impersonate e-banking or stock manipulation services, but instead they are mere phishing tools that simply deprive you of your credentials first to either rob you or steal your identity later on. So should you decide to place a bet via your smartphone and you are not paying attention to the app you are using in this direction, then you might end up accessing a page that has been spoofed or had been created for such events only that is designed to take your credentials and end up with your money and/or your identity.
Spam and phishing carrying e-mails may also bombard you these days around the Champions league finals. Crooks may feed you either a nice story about you being the lucky winner of a premium ticket to the final at Wembley or links towards your favorite online betting website, where you can make a fortune. But whatever you do, firstly make sure that you land on the right page by checking the browser’s URL bar and also look for the presence of a security certificate. Manually entering the website’s address may prove to be a blessing in this case as compared to taking a chance and clicking a link received through instant messaging services or via mail.
Crooks come up with various scams created to meet the exact need and interest of a variety of computer & smartphone users. That is why you need to proceed with caution when you decide to buy a ticket from eBay, for instance. It is possible that, although advertised, the item doesn’t exist and chances are that you end up paying for something that will never be delivered to you. Moreover, never consider yourself as lucky as to win a ticket if you’ve never signed up for such a contest.
Last, but not least, if you’re a fan of “Artificial Intelligence”-based predictions, be careful as to what prediction software you’re using. Around sports events, malware creators usually come up with rogue “sports prediction software”, which are highly expensive applications that randomly display the “probable” scores. Other such applications which are distributed for free can carry malware, so make sure that you’ve scanned them with an updated antivirus before using them.
http://www.malwarecity.com/blog/rogue-apps-might-spoil-your-fun-around-champions-league-final-1078.html
In front of your computer you should always fasten your seatbelt
Three things that cars and computers have in common – when it comes to security, of course.
Ever since I started dealing with computers I couldn't help noticing that the majority of users actually falls into two large categories, according to their attitude towards computer security: the league of “I don't need an antivirus, what difference does it make anyway?” and the congregation of “I have an antivirus, what else should I care about?”.
Sure, I can see their points, as both societies have enough supportive arguments. However, my daily practice tells me that, actually none of them is completely right. As I enjoy driving a lot, I'll try to use an analogy with a car and its safety system to be more explicit.
You can always drive a car without airbags, seatbelts and other security measures that prevent you from getting hurt in case of an accident. But, as I (unfortunately) know from my own experience, whether you're involved in a frontal collision or a slight bump – God forbid! – it's always better to actually have these protective devices on.
Now try to imagine this scenario: you’re at home, in front of your computer, querying a search engine for breaking news about a recent event. Your TV is running loud, your kids have turned the living room upside-down and your wife is screaming for your help from the kitchen – pretty much the idea of a “quiet evening at home” most of us have. You turn your head because you couldn’t actually understand what she’s saying, your hand slips to the right and your finger accidentally clicks a link displayed on the search results page. Baaang! Your computer just got its frontal impact test by running against a minivan of malware served by poisoned URLs. No security installed onto your system means no seatbelt and no airbags.
Remember that old joke with the guy who had a new car with cruise control, ABS, EBD, ESP – plus other three-or-four-letter-abbreviations of security systems- and crashed it at the first turn right (or was it left?) as he believed his car was supposed to steer by itself with all that stuff on it? Sure thing, you can pack a computer with all state-of-the-art security thinking that you don't need anything else. But the truth is that the human factor is still key, whether we talk about driving or protecting data.
Picture this: you and your laptop are both comfortably nested on the couch and you’re surfing your favorite social networking platform. You've got word from a pal about an app that can spit out the number of people having visited your page and you want to install it too. And, just as, in your car, you hit the gas to get even faster to your favorite holiday resort while simply ignoring all those road signs that warn you about speed limitations, curbs and other dangers, when on your computer, you overlook any clue telling you that the magic app is actually a scam meant to take over your account and hijack your browser. Baaang! You've smashed yourself onto the slope of frauds because you didn't want to be reasonable enough, paid no attention to the road in front of you, and solely relied on your system.
So, what I'm trying to say is that truth is somewhere in between. Overall, there are three little things you should always remember, whether they refer to your car or your computer: Some security is always better than no security at all. No matter how much security you have, you'll never have enough. With your seatbelt fastened, always be alert and watch the road, someone's waiting for you at home (or to get back in front of your computer)!
Safe driving and surfing everybody!
http://www.malwarecity.com/blog/in-front-of-your-computer-you-should-always-fasten-your-seatbelt-1077.html
Ever since I started dealing with computers I couldn't help noticing that the majority of users actually falls into two large categories, according to their attitude towards computer security: the league of “I don't need an antivirus, what difference does it make anyway?” and the congregation of “I have an antivirus, what else should I care about?”.
Sure, I can see their points, as both societies have enough supportive arguments. However, my daily practice tells me that, actually none of them is completely right. As I enjoy driving a lot, I'll try to use an analogy with a car and its safety system to be more explicit.
You can always drive a car without airbags, seatbelts and other security measures that prevent you from getting hurt in case of an accident. But, as I (unfortunately) know from my own experience, whether you're involved in a frontal collision or a slight bump – God forbid! – it's always better to actually have these protective devices on.
Now try to imagine this scenario: you’re at home, in front of your computer, querying a search engine for breaking news about a recent event. Your TV is running loud, your kids have turned the living room upside-down and your wife is screaming for your help from the kitchen – pretty much the idea of a “quiet evening at home” most of us have. You turn your head because you couldn’t actually understand what she’s saying, your hand slips to the right and your finger accidentally clicks a link displayed on the search results page. Baaang! Your computer just got its frontal impact test by running against a minivan of malware served by poisoned URLs. No security installed onto your system means no seatbelt and no airbags.
Remember that old joke with the guy who had a new car with cruise control, ABS, EBD, ESP – plus other three-or-four-letter-abbreviations of security systems- and crashed it at the first turn right (or was it left?) as he believed his car was supposed to steer by itself with all that stuff on it? Sure thing, you can pack a computer with all state-of-the-art security thinking that you don't need anything else. But the truth is that the human factor is still key, whether we talk about driving or protecting data.
Picture this: you and your laptop are both comfortably nested on the couch and you’re surfing your favorite social networking platform. You've got word from a pal about an app that can spit out the number of people having visited your page and you want to install it too. And, just as, in your car, you hit the gas to get even faster to your favorite holiday resort while simply ignoring all those road signs that warn you about speed limitations, curbs and other dangers, when on your computer, you overlook any clue telling you that the magic app is actually a scam meant to take over your account and hijack your browser. Baaang! You've smashed yourself onto the slope of frauds because you didn't want to be reasonable enough, paid no attention to the road in front of you, and solely relied on your system.
So, what I'm trying to say is that truth is somewhere in between. Overall, there are three little things you should always remember, whether they refer to your car or your computer: Some security is always better than no security at all. No matter how much security you have, you'll never have enough. With your seatbelt fastened, always be alert and watch the road, someone's waiting for you at home (or to get back in front of your computer)!
Safe driving and surfing everybody!
http://www.malwarecity.com/blog/in-front-of-your-computer-you-should-always-fasten-your-seatbelt-1077.html
New malware revives Mac vs. Windows security debate
(Wired.com) -- A new piece of malware has caused an uptick in Apple customers reporting infected machines, renewing a timeless debate on the state of Macintosh security versus Windows.
The trojan horse is called Mac Defender. It's a web pop-up containing a spoof message that tells customers their machines are infected by a virus and they must install anti-virus software. If customers agree to install the software, the program sporadically loads porn websites on their computer.
ZDNet writer Ed Bott was first to spot a long thread of complaints in Apple's support forums related to Mac Defender, with at least 200 posts of customers reporting they've been infected by the malware.
"I've done similar searches in the past ... [and] I have never found more than one or two in-the-wild reports," Bott wrote. "This time, the volume is truly exceptional."
Furthering his case, Bott in a follow-up article quoted an AppleCare technician who claims that phone calls to AppleCare support have grown four to five times recently, and the majority of the calls are related to Mac Defender.
Customers and technology observers have debated for years whether the Mac is truly more secure than a Windows PC.
The general consensus among security researchers is that there's nothing about the Mac that makes it inherently more secure than Windows -- indeed, the Mac platform has been easily penetrated in the Pwn2Own hacking contest in years past. But Windows has always been a juicier target for malicious hackers because it has much larger market share than the Mac.
As a result, when customers switch from a Windows to a Mac, they're often under the impression that they're switching to a more secure, sterile environment where they won't need to install expensive, resource-hogging anti-virus software. While it's not true that the Mac is more secure, theplatform is generally "safer" because fewer people target it, security researchers have told Wired.com in the past.
Bott's discovery renews this debate: A new piece of malware seems to be fooling more Mac customers than past examples. So does this change the scenario? Should Mac customers install anti-virus software by default like most Windows customers do?
Charlie Miller, a security researcher who has repeatedly won the annual Pwn2Own hacking contest by hacking Macs and iPhones, told Wired.com he doesn't think so.
Miller noted that Microsoft recently pointed out that 1 in 14 downloads on Windows are malicious. And the fact that there is just one piece of Mac malware being widely discussed illustrates how rare malware still is on the Mac platform, he said.
And while 200 posts complaining about Mac Defender in Apple's support forums may seem like a lot, that's still a small fraction of the millions of Mac customers in the world.
While Mac Defender does show that the problem is getting worse and people should be more wary about malware, it doesn't necessarily mean that every Mac user today should rush to buy anti-virus software, Miller said.
Ultimately, it's up to the customer because there's a trade-off involved. Anti-virus software will help protect your system from being infected, but it's expensive, uses system memory and reduces battery life.
"Mac malware is still relatively rare, but is getting worse," Miller said. "At some point soon, the scales will tip to installing antivirus, but at this point, I don't think it's worth it yet for most people."
In looking into the effects of Mac Defender, Wired.com's sister publication Ars Technica did a thorough investigation on the state of Mac malware, speaking with 14 Mac support specialists.
"The truth is hard to tease out," ArsTechnica's Jacqui Cheng wrote. "Partly because Mac OS X still makes up a comparatively small percentage of the global OS market share, and partly because Apple itself is a secretive company, it's not easy to find out whether malware on the Mac is indeed becoming more common, or it's simply being reported on more often."
The results were all over the map, with most certified Mac support specialists logging a low number of malware reports. But some Apple Genius Bar technicians noticed an uptick in malware instances, thanks to Mac Defender.
The trojan horse is called Mac Defender. It's a web pop-up containing a spoof message that tells customers their machines are infected by a virus and they must install anti-virus software. If customers agree to install the software, the program sporadically loads porn websites on their computer.
ZDNet writer Ed Bott was first to spot a long thread of complaints in Apple's support forums related to Mac Defender, with at least 200 posts of customers reporting they've been infected by the malware.
"I've done similar searches in the past ... [and] I have never found more than one or two in-the-wild reports," Bott wrote. "This time, the volume is truly exceptional."
Furthering his case, Bott in a follow-up article quoted an AppleCare technician who claims that phone calls to AppleCare support have grown four to five times recently, and the majority of the calls are related to Mac Defender.
Customers and technology observers have debated for years whether the Mac is truly more secure than a Windows PC.
The general consensus among security researchers is that there's nothing about the Mac that makes it inherently more secure than Windows -- indeed, the Mac platform has been easily penetrated in the Pwn2Own hacking contest in years past. But Windows has always been a juicier target for malicious hackers because it has much larger market share than the Mac.
As a result, when customers switch from a Windows to a Mac, they're often under the impression that they're switching to a more secure, sterile environment where they won't need to install expensive, resource-hogging anti-virus software. While it's not true that the Mac is more secure, theplatform is generally "safer" because fewer people target it, security researchers have told Wired.com in the past.
Bott's discovery renews this debate: A new piece of malware seems to be fooling more Mac customers than past examples. So does this change the scenario? Should Mac customers install anti-virus software by default like most Windows customers do?
Charlie Miller, a security researcher who has repeatedly won the annual Pwn2Own hacking contest by hacking Macs and iPhones, told Wired.com he doesn't think so.
Miller noted that Microsoft recently pointed out that 1 in 14 downloads on Windows are malicious. And the fact that there is just one piece of Mac malware being widely discussed illustrates how rare malware still is on the Mac platform, he said.
And while 200 posts complaining about Mac Defender in Apple's support forums may seem like a lot, that's still a small fraction of the millions of Mac customers in the world.
While Mac Defender does show that the problem is getting worse and people should be more wary about malware, it doesn't necessarily mean that every Mac user today should rush to buy anti-virus software, Miller said.
Ultimately, it's up to the customer because there's a trade-off involved. Anti-virus software will help protect your system from being infected, but it's expensive, uses system memory and reduces battery life.
"Mac malware is still relatively rare, but is getting worse," Miller said. "At some point soon, the scales will tip to installing antivirus, but at this point, I don't think it's worth it yet for most people."
In looking into the effects of Mac Defender, Wired.com's sister publication Ars Technica did a thorough investigation on the state of Mac malware, speaking with 14 Mac support specialists.
"The truth is hard to tease out," ArsTechnica's Jacqui Cheng wrote. "Partly because Mac OS X still makes up a comparatively small percentage of the global OS market share, and partly because Apple itself is a secretive company, it's not easy to find out whether malware on the Mac is indeed becoming more common, or it's simply being reported on more often."
The results were all over the map, with most certified Mac support specialists logging a low number of malware reports. But some Apple Genius Bar technicians noticed an uptick in malware instances, thanks to Mac Defender.
Though the conclusion is unclear, the moral of this story is to be wary that Mac malware is in the wild, and be cautious about installing sketchy software from unfamiliar sources. Mac Defender may be the first wake-up call for people who believed that Macs don't get viruses.
Copyright 2010 Wired.com.
Friday, May 20, 2011
Mac Not Really Safe From 'Viruses' Afterall.
The first advanced DIY (Do-It-Yourself) crimeware kit aimed at the Mac OS X platform has just been announced on a few closed underground forums. Detailed information about this crimeware kit is not being leaked publicly and the authors of the kit are obviously trying to stay below the radar allowing only vetted users of the forums to see most of the content.
Crimeware kits have become a ubiquitous part of the malware scene in the last few years, but they have mainly been confined to the Windows platform. Now, reports are surfacing that the first such kit targeting Apple's Mac OS X operating system has appeared.
The kit is being compared to the Zeus kit, which has been one of the more popular and pervasive crimeware kits for several years now. A report by CSIS, a Danish security firm, said that the OS X kit uses a template that's quite similar to the Zeus construction and has the ability to steal forms from Firefox.
"The Danish IT-security company CSIS Security Group has just yesterday observed a new advanced Form grabber designed for the Mac OS X operating system being advertised on several closed underground forums. In the same way as several other DIY crimeware kits designed for PCs, this tool consists of a builder, an admin panel and supports encryption," Peter Kruse of CSIS said in a blog post.
"The kit is being sold under the name Weyland-Yutani BOT and it is the first of its kind to hit the Mac OS platform. Apparently, a dedicated iPad and Linux release are under preparation as well. The Weyland-Yutani BOT supports web injects and form grabbing in Firefox; however both Chrome and Safari will soon follow. The webinjects templates are identical to the ones used in Zeus and Spyeye."
In an email exchange, Kruse said that the builder component of the kit runs on Windows machines and the user has the option of specifying that he wants the malware to run on OS X. The builder will then create a Mac binary.
Malware authors and professional attack crews have steered clear of the OS X platform for the most part, for a variety of reasons. One of the main things holding up the development of Mac-specific attack tools, experts say, is the small market share Apple has, particularly in the enterprise. However, that is gradually changing and the attackers are beginning to follow.
In addition to the new crimeware kit, a Mac-specific scareware attack also popped up on Monday, targeting users who searched for some popular terms on Google. The MACDefenderscareware is appearing in search results for images of Osama bin Laden as well as in other places.
"In it's current incarnation, MACDefender shows up in the installed applications list, so can be uninstalled. If you have accidentally installed this, go ahead and uninstall it. I would not expect this 'uninstall' option to be a good long term protection strategy. I'd suggest that OSX users disable 'Open safe files after downloading', and also invest in a reasonable anti-malware suite. Installing a real anti-malware package is also a good idea," Rob VandenBrink of the SANS Internet Storm Center wrote in an analysis of the scareware.
Crimeware kits have become a ubiquitous part of the malware scene in the last few years, but they have mainly been confined to the Windows platform. Now, reports are surfacing that the first such kit targeting Apple's Mac OS X operating system has appeared.
The kit is being compared to the Zeus kit, which has been one of the more popular and pervasive crimeware kits for several years now. A report by CSIS, a Danish security firm, said that the OS X kit uses a template that's quite similar to the Zeus construction and has the ability to steal forms from Firefox.
"The Danish IT-security company CSIS Security Group has just yesterday observed a new advanced Form grabber designed for the Mac OS X operating system being advertised on several closed underground forums. In the same way as several other DIY crimeware kits designed for PCs, this tool consists of a builder, an admin panel and supports encryption," Peter Kruse of CSIS said in a blog post.
"The kit is being sold under the name Weyland-Yutani BOT and it is the first of its kind to hit the Mac OS platform. Apparently, a dedicated iPad and Linux release are under preparation as well. The Weyland-Yutani BOT supports web injects and form grabbing in Firefox; however both Chrome and Safari will soon follow. The webinjects templates are identical to the ones used in Zeus and Spyeye."
In an email exchange, Kruse said that the builder component of the kit runs on Windows machines and the user has the option of specifying that he wants the malware to run on OS X. The builder will then create a Mac binary.
Malware authors and professional attack crews have steered clear of the OS X platform for the most part, for a variety of reasons. One of the main things holding up the development of Mac-specific attack tools, experts say, is the small market share Apple has, particularly in the enterprise. However, that is gradually changing and the attackers are beginning to follow.
In addition to the new crimeware kit, a Mac-specific scareware attack also popped up on Monday, targeting users who searched for some popular terms on Google. The MACDefenderscareware is appearing in search results for images of Osama bin Laden as well as in other places.
"In it's current incarnation, MACDefender shows up in the installed applications list, so can be uninstalled. If you have accidentally installed this, go ahead and uninstall it. I would not expect this 'uninstall' option to be a good long term protection strategy. I'd suggest that OSX users disable 'Open safe files after downloading', and also invest in a reasonable anti-malware suite. Installing a real anti-malware package is also a good idea," Rob VandenBrink of the SANS Internet Storm Center wrote in an analysis of the scareware.
Subscribe to:
Posts (Atom)





