Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts
Wednesday, June 29, 2011
LULZSEC LEAVES BEHIND ONE LAST PARTING SHOT WITH MALWARE, TROJANS AND VIRII
The small group of hackers known as Lulz Security, or simply “LulzSec,” would never disband without one final round of fun. BGR reported on Monday that the group’s reign of terror was coming to an end after 50 lul-filled days. During that period of time, LulzSec released data stolen in a series of online breaches with targets ranging from Sony to the U.S. Government.
In its coup de grĂ¢ce, LulzSec released a stash of stolen data from a variety of targets, including AT&T, Disney and the U.S. Navy. But data obtained through online breaches wasn’t the only thing LulzSec stuffed into the file; a directory named “BootableUSB” also contained a variety of malware including trojans and worms. While “LulzSec” is no more and its notorious Twitter account now sits dormant, members of the well-known hacktivism group “Anonymous Operations” have confirmed that LulzSec is gone in name only — the six LulzSec members have been absorbed by Anonymous, according to the group’s official Twitter feed.
Wednesday, June 1, 2011
APPLE CRACKING DOWN ON MALWARE WITH QUARANTINE LIST
Preconceptions aside, Apple products do occasionally spread viruses, and not just the biological kind, which is why Cupertino saw fit to equip Mac OS X 10.6 Snow Leopard with a quarantine function to safely set malware aside. This week, however, Apple's kicking those digital white blood cells into high gear, updating that quarantine list daily with a new background process.
The company's primarily got its crosshairs on the recent MacDefender scare, of course, but on the off-chance malware starts coming out of the woodwork, it sounds like you won't have to wait for a formal security update to be forewarned of the dangers. If privacy's your primary concern, however, you can also opt-out
Labels:
Apple,
cupertino,
macdefender,
malware,
quarantine,
snow leopard,
virus
Thursday, May 26, 2011
APPLE FINALLY ADMITS MALWARE ISSUE; POSTS REMOVAL INSTRUCTIONS FOR 'MAC DEFENDER'
Mac users have recently been targeted by a phishing scam that falsely claimed their computers were infected with a virus. Upon being redirected to an illegitimate website, users were instructed to install “Mac Defender,” which was malware masquerading as an antivirus application.
Until recently, Apple had reportedly instructed its AppleCare support reps to deny any existence of the problem and said reps should “not remove or uninstall any malware” found on a computer. On Tuesday, however, Apple finally acknowledged the issue and posted instructions on its support forums that cover how to avoid and remove the Mac Defender malware.
REMOVAL INSTRUCTIONS:
- Move or close the Scan Window
- Go to the Utilities folder in the Applications folder and launch Activity Monitor
- Choose All Processes from the pop up menu in the upper right corner of the window
- Under the Process Name column, look for the name of the app and click to select it; common app names include: MacDefender, MacSecurity or MacProtector
- Click the Quit Process button in the upper left corner of the window and select Quit
- Quit Activity Monitor application
- Open the Applications folder
- Locate the app ex. MacDefender, MacSecurity, MacProtector or other name
- Drag to Trash, and empty Trash
Labels:
Apple,
instructions,
mac defender,
malware,
removal,
trojan,
virus
Saturday, May 21, 2011
APPLE INSTRUCTS SUPPORT REPS TO REFUTE MALWARE AND DENY ASSISTANCE
AppleCare representatives can do a lot of things for Mac owners suffering software issues… except when it comes to malware. In an internal support article leaked to ZDNet, Apple instructs its call center representatives on how to handle calls from users reporting that they have a machine infected with the “Mac Defender” malware trojan.
As you can see below, Apple is definitely taking the hands-off approach. “AppleCare does not provide support for the removal of the malware,” reads the memo. “You should not confirm or deny whether the customer’s Mac is infected or not.” Apple certainly isn’t the first company to instruct its support representatives to shy away from virus/malware assistance, but it is notable as it is the first major Mac OS X virus that — thanks to some moderate social engineering — is propagating. Apple has yet to issue a public statement about the software’s existence or infection levels.
Labels:
Apple,
applecare,
assistance,
malware
Sunday, March 6, 2011
GOOGLE RESPONDS TO ANDROID APP MALWARE
On March 1, news broke that dozens of malicious applications had made their way to Android Market, each infected with a rootkit that could grant hackers deep access to Android devices that installed them. Google removed the malicious applications from Android Market within a few minutes of being notified, but has otherwise remained silent on the situation.
Google has now confirmed that 58 malicious applications were uploaded to Android Market, and that they were downloaded onto around 260,000 devices before Google removed the apps Tuesday evening. That number sounds alarmingly high, but Google believes that only device-specific information, namely the phone’s IMEI number, was compromised — and that no personal data or account information was ever transferred. Given that these apps were getting root access, this could have been a lot worse. Now the cleanup begins.
Beginning tonight, Google is going to invoke a special ‘remote kill’ function that allows it to remove these malicious applications from any affected Android devices with no action required from the user. Google will also be issuing a fully automated Android Market security update to infected devices that should remove the rootkit (again, no user action will be required). All affected users will be receiving email notifications about the situation as well.
Unfortunately, while Google can remotely fix affected devices, it can’t automatically patch the security hole that made the exploit possible in the first place. That’s because the hole exists on the system level, so it requires a system upgrade to resolve — and it’s up to the carriers and hardware manufacturers to deploy the fix. Google is issuing a patch and informing its partners that it is urgent, but who knows how long it will take the carriers to push it to users.
As if to underscore this problem, Google says that the exploit was actually already fixed in recent versions of Android, and that it only affects version 2.2.1 and lower. Unfortunately the vast majority of Android devices are still running older versions of the OS because of the aforementioned sluggish carrier updates.
Beyond these software updates, Google says that it’s taking steps to try to prevent similar malicious apps from making it onto Android Market.
Labels:
Android,
Android Marketplace,
malware,
trojan,
virus
Thursday, March 3, 2011
MORE MALWARE DISCOVERED IN ANDROID MARKETPLACE APPS
We reported yesterday on Google pulling 21 apps from the Android Marketplace due to malware. Now, we are learning additional apps have been pulled for the same reason. Google has removed 29 more apps and more could be pulled. Google discovered the "DreamDroid" virus in the additional apps it pulled yesterday.
Unlike Apple's locked down App Store, Google's Android Marketplace is open for all, which allows for malware, virii and trojans to appear more readily. Google does have a section in its terms of service which addresses this issue, but the company relies on others to police its Marketplace and inform it of any offending apps.
Sunday, February 13, 2011
MICROSOFT FINALLY DISABLES USB AUTO-RUN IN PRE-WINDOWS 7 COMPUTERS
Microsoft has finally released the long awaited update which will disable the auto-run feature for USB devices. That behavior has been blamed for the spread of malware in recent years -- including the infamous Conficker worm -- and Microsoft had actually already made it possible to disable the functionality back in November of 2009, albeit only through an update available from its Download Center website. It's now finally pushed the update out through the Windows Update channel, though, which should cause it to be much more broadly deployed (particularly in large organizations). As explained in a rather lengthy blog post, however, Microsoft has decided to simply make it an "important, non-security update" rather than a mandatory update, as it doesn't technically see AutoRun as a "vulnerability" -- it was by design, after all.
Subscribe to:
Posts (Atom)







