Showing posts with label antivirus. Show all posts
Showing posts with label antivirus. Show all posts

Thursday, March 2, 2023

US Marshals Service suffer Ransomware breach, TikTok Bans continue to grow

US Marshals computer system hit by ransomware attack

The US Marshals Service computer system suffered a major breach last month.  The incident was discovered on February 17 and the affected system was disconnected.  It was determined that the hackers stole personnel data and info about investigation targets.

On the same date CNN reported a breach in an FBI computer system at the agency's New York field office.

The attacks are the latest in a trend targeting government agencies and has some questioning cybersecurity protocols at the Justice Department.

These attacks should serve as a warning to all computer users to be vigilant about maintaining security firewalls and software.

https://apnews.com/article/marshals-hackers-ransomware-breach-cybercrime-67de6b7f0f30445ab2eb341679f857bb


Here are the countries that have bans on TikTok

The number of U.S. States banning the use of TikTok on government devices has now grown to over 25.  The ban applies only to government devices.

However, it's not just the U.S. that has banned the use of TikTok.  Other countries include;

INDIA

TAIWAN

CANADA

EUROPEAN UNION

PAKISTAN

AFGHANISTAN

The U.S., India, Taiwan, Canada and the European Union, cite national security concerns.

Pakistani authorities have temporarily banned TikTok at least four times since October 2020, citing concerns that app promotes immoral content.

Afghanistan’s Taliban leadership banned TikTok and the game PUBG in 2022 on the grounds of protecting youths from “being misled.”

Who is monitoring your devices?

https://apnews.com/article/tiktok-ban-privacy-cybersecurity-bytedance-china-2dce297f0aed056efe53309bbcd44a04


Tuesday, July 9, 2019

Microsoft warns about Astaroth malware campaign, Hackers steal $3 million from Bank in Bangladesh.

Microsoft warns about Astaroth malware campaign

New hard-to-detect Astaroth campaigns spotted using fileless execution and living-off-the-land techniques.

Malware writers have found a new way to circumvent your anti-virus software.  They are using a technique called "living off the land."  This involves using legitimate tools to download code and process the illegal activity completely in the memory of the computer without using files.

The Microsoft Team behind Windows Defender ATP spotted the attacks.  A member of the team said they were alerted when a huge and sudden spike in usage of the WMIC tool, "Windows Management Instrumentation Command-Line" tool.  WMIC is a powerful tool that complements the existing management and administration utilities and tools.  It is a command line shell much like the CMD command.

The sudden spike was indicative of a pattern that occurs during malware campaigns.



When Microsoft looked closer, it discovered a malware campaign that consisted of a massive spam operation that was sending out emails with a link to a website hosting a .LNK shortcut file.

If users were careless to download and run this file, it would launch the WMIC tool, and then a plethora of other legitimate Windows tools, one after the other.

The tools would all download additional code and pass their output to one another, executing solely in memory -- in what's called fileless execution -- and without saving any files on disk, making the job of classic antivirus solutions harder, as they would have nothing to file on disk to scan.

What is a .LNK file, these are files that point to the location of an executable file typically located on a hard drive.  Your desktop shortcuts are examples of this.  However in the case of the malware email, the .LNK file points to a URL on the internet where the malicious file is stored.

The end result of this attack is that the Astaroth trojan is downloaded and run.  It is a known info-stealer that can dump credentials for a wide category of apps and uploaded the stolen data to a remote server.

This trojan first appeared in 2018.  Earlier this year it was used in malware attacks targeting European and Brazilian users in February, this year.

The next step in the evolution of modern antivirus products is shifting from a classic file signature detection mode of operation to a behavioral-driven approach, where they can also detect "invisible" actions like fileless (in-memory) execution and living-off-the-land techniques where legitimate tools are abused for bad operations.

Be very careful opening emails from people you do not know, especially those containing links to external sites.

To read the full story click on this link;

https://www.zdnet.com/article/microsoft-warns-about-astaroth-malware-campaign/?ftag=TREc64629f&bhid=2219791


In other hacking and malware news;

Sodinokibi ransomware is now using a former Windows zero-day

The Sodinokibi malware uses a former Windows Zero-day vulnerability to carry out its attack on infected hosts.

The vulnerability, a privilege escalation flaw known as CVE-2018-8453, had been patched in the October 2018 Patch Tuesday Microsoft security updates after it had previously been used by a state-sponsored hacking group known as FruityArmor since August 2018.

I know updates can be a pain but with so many ransomware attacks occurring today, it is imperative that you patch/update your systems so they remain safe from attack.

https://www.zdnet.com/article/sodinokibi-ransomware-is-now-using-a-former-windows-zero-day/

'Silence' hackers hit banks in Bangladesh, India, Sri Lanka, and Kyrgyzstan, allegedly stole $3 million from Bangladesh's Dutch Bangla Bank.

In a report shared with ZDNet prior to publication, Group-IB tied the Dutch Bangla Bank incident to a group of hackers known as "Silence."


The group, which ZDNet previously covered in a September 2018 piece, has been active since 2016 and has historically targeted banks in Russia, former Soviet states, and Eastern Europe.

https://www.zdnet.com/article/silence-hackers-hit-banks-in-bangladesh-india-sri-lanka-and-kyrgyzstan/


DFORCE - Intel 8th & 9th Generation computers with Solid State Drives



Thursday, November 15, 2018

Email and Identity Theft - Has your information been Pawned?

There are always evolving threats to your online security.  Whether a phishing email, an email with a malware attachment/download or a compromised website, chances are you will experience at least one attempt each day.  Security software, firewalls, and antivirus software can provide a high degree of protection but it is no guarantee that your credentials will not be compromised.  You must be vigilant of phishing attempts and compromised websites.

A lot of attempts to steal your info is to spoof the email of someone you know to gain your confidence.  It may include an attachment that when clicked on takes you to a filesharing site, DropBox, Microsoft Sharepoint or OneDrive and ask you to log in.  It is easy to steal the source code of a website and mimic that site on a malicious web page.  Once you log in, BAM, they have your info which they will use to compromise your authentic email or access your online account.

Another ploy I have seen recently are emails that include a compromised password that is a real password that the user has or still uses.  The email states that they have private info about you that will be revealed publicly unless you pay a ransom to a Bitcoin wallet.  These wallets are very real and untraceable, so do not fall for this extortion attempt.

I have been contacted by users wanting to know if these are real because the email contains a current or past used password.  Again, they are only extortion attempts.  The next question is how did they get the password.  Below is a chart of information courtesy of "haveIbeenPawned.com".  Your identity and information are all over the web.  It is at your bank, LinkedIn, MySpace, Facebook etc.  This chart lists the largest data breaches thus far of user data at major corporations and websites.  And remember, these are just the largest, not nearly all.

Beneath the chart is links that you can use to check to see if your email has been pawned and your information was included in any of the compromised sites.

I have included the "haveIbeenPawned" website in a past blog post.  If you don't practice good password security yet and your email has been pawned please start today.  No one to blame but yourself.




https://haveibeenpwned.com/

https://www.lifelock.com/breach-detection?promocode=BreachEraser&nc=breachnortoneraser


Microsoft, Linux developers, and Apple are constantly releasing updates and patches to their operating systems to fix known and new exploits as they are found.  If you are using Windows XP then you have not received a security update since April 8, 2014.

Web browsers are evolving and getting better at warning the user that a website is not safe.  Google Chrome is good at warning you that a website is not safe and Mozilla Firefox will soon start alerting you to a breached site.  These browser updates don't necessarily happen automatically.  You should check if an update is available periodically and if so, install it.

If you are using Windows XP then you are using a way out of date, non-secure browser to navigate the internet.  I would not advise using an XP machine for financial transactions.

Support for Windows 7 extended support ends January 14, 2020.  Many software vendors will end support before that.

It isn't only the operating systems but recently flaws in Intel Processors have been exploited.

https://www.forbes.com/sites/davealtavilla/2018/01/03/intel-processor-bug-leaves-all-current-chips-vulnerable-and-its-fix-saps-performance/#74f5a918570a

One last thing, it's all software that you use whether Adobe Acrobat/Flash Player, Java, MS Office, or browsers.  Hackers use exploits in all of these to gain access to your computer and info.  It is imperative that you patch and update your systems to remain secure.



NEW INTEL GENERATION 8 & 9 based WORKSTATIONS


Monday, February 22, 2016

Ramsomware - Hollywood Presbyterian Hospital pays $17,000 to unlock computers. ABC news reports.

Hollywood Presbyterian Hospital pays $17,000 to unlock computers

I have previously written posts regarding Ransomware.  Ransomware is malware that once on your system encrypts your data preventing you from being able to open or use your files.  Files targeted include Microsoft Office documents, PDFs, your pictures (jpeg) files and many more.  You will then see a message that your files have been locked and that you must pay a ransom to receive the key to unlock them.

I had reported previously about ransomware after seeing in the regional news about local businesses and police departments that had been hit by ransomware.  This past week ABC national news reported the news that Hollywood Presbyterian Hospital had paid $17,000 to a hacker to stop an attack on it's computer system.


One ransomware threat that has been in the news quite a bit lately is Crytolocker.  I have witnessed this attack twice at 2 different clients.  It often arrives via email disguised as a PDF or Zip file.  The people behind this attack have been emailing it to large numbers of people and it often arrives with a variety of other bad news, backdoor trojans, downloader, spammers and password stealers.  However email is not the only way these threats spread.

Another way the spread of Ramsomware is accomplished is by hacking a website and uploading a script which automatically generates hidden frames within a visitor's browser, this acts as a gateway between the visited site and a server that contains the Exploit Kit.  Wordpress and now Joomla, two open source web publishing tools have been exploited to spread the ransomware payload.

Once you receive the message it is too late.




Things you can do to protect yourself is to be sure you have a well thought out backup plan that includes having multiple dates of backup, i.e. if you are backing up to the same media and overwriting the previous days backup that is no good.  If you are hit by a cryptovirus and don't catch it prior to the backup you may end up having a backup of worthless data.

It is advisable to unplug external drives from the computer after a backup if that is your method.

Check your anti-virus and make sure your subscription is current and definitions are up to date.

The following link contains more detailed/technical info on protecting yourself.


Be proactive with your security and vigilant when surfing the internet.

New 6th Generation Intel Processors

30x Better 3D graphics vs. a 5 year old PC

Get Creative, Play Harder,striking visuals in higher resolution, faster frame rates, Ultra HD 4K multimedia experiences.  With a 6th generation Intel® Core™ processor inside, you can watch, play, and game like never before.  Bring the action to life.



6th Generation Intel CPUs

Monday, September 13, 2010

Patch Tuesday - Microsoft OneCare Live

Patch Tuesday

Here we go again, the eve of Patch Tuesday.  Patch Tuesday is the second Tuesday of each month, on which Microsoft releases security patches.  Patch Tuesday evolved out of "Windows Update" that started with Windows 98.

Initially the Windows Update system suffered from two problems. The first was that the less-experienced user was often unaware of Windows Update and did not run it.  Microsoft's solution to that was the "Automatic Update," which notified each user that an update was available for his system.  Secondly, the problem with Automatic Updates was that sometimes it broke previously working software programs which caused problems for customers with many copies of Windows.  IT techs not only had to update every Windows deployment in the company but also uninstall patches issued by Microsoft that broke existing functionality.

In order to reduce the costs related to the deployment of patches, Microsoft introduced "Patch Tuesday". Security patches are accumulated over a period of one month and then dispatched all at once on the second Tuesday of each month.  System administrators may prepare, troubleshoot and resolve any conflicts and decide the best appropriate course for their systems.

The contents of this month's Patch Tuesday updates can be found at the following link; http://www.microsoft.com/technet/security/Bulletin/MS10-sep.mspx

Also if you haven't already, you can sign up for an automatic notification from Microsoft that will be issued 3 days in advance, this link is; http://technet.microsoft.com/en-us/security/dd252948.aspx

Exploit Wednesday

Did you know that the day following Patch Tuesday has become known as Exploit Wednesday?  Malware writers analyze the patch and quickly develop code to attack new entry points knowing that there will be an entire month before Microsoft releases any patch to fix it.

Microsoft OneCare Live

Microsoft once had a for pay anti-virus/malware system, "OneCare" that is now available for free.  Not only does it scan for malware and viruses, it also has a Registry Check/Fix that works very well.  To do a full scan takes some time depending upon how many files you have on your system... so allow time for the scan to run.  Start it if you are going to be away from the computer for awhile.  It is well worth the time.  Click here for the Microsoft OneCare link.

TEST