Showing posts with label Kaspersky. Show all posts
Showing posts with label Kaspersky. Show all posts
Thursday
Kaspersky warns of more fake supply chain attacks
More fake supply chain attacks are expected given the heightened cyberheist activities of the notorious Lazarus group, Russian cybersecurity firm Kaspersky Lab AO said Thursday.
Seonsgu Park, Kaspersky’s senior security researcher in the Global Research and Threat Analysis Team (GReAT), warned that more fake supply chain attacks are expected.
“With major attacks up its sleeves—such as the Bangladesh Bank heist and the WannaCry ransomware, to name a few—the Lazarus group is like a constant presence in the world of cybersecurity and it is getting quite adept at hiding and spreading its evil schemes,” said Park.
Kaspersky found that the Lazarus group—an advanced persistent threat (APT)—has developed new malicious operations which at first glance looks like a supply chain.
Dubbed as AppleJesus, the APT’s attack compromised users through the Trojanized trading application Celas Trade Pro, developed by a legitimate company Celas Limited.
Once Trojanized, a software is infected by a malware which, once activated, enables cybercriminals to spy on users, steal sensitive data, and gain backdoor access to systems.
“The extensive effort it exerts to create malware for the supposedly safer MacOS environment, and the intricate details needed to create a legitimate-looking application and software company, prove it is far from stopping,” said Park.
“There are more attacks to come, and we had better be ready because it won’t get any easier,” he warned.
Kaspersky said individuals should be more prudent in choosing third-party vendors and more cautious in trusting legitimate-looking software applications, certificates, and developers.
“We have observed how the Lazarus group has constantly evolved—from waging cyber espionage campaigns worldwide to financial attacks against major banks. Last year, we warned that they are not after your data anymore. And indeed, they aren’t,” said Park.
“These state-backed attackers are now ramping up the sophistication of their attacks and widening their reach to steal more money and trick the cybersecurity industry,” he said. —Jon Viktor Cabuenas/VDS, GMA News
source: gmanetwork.com
Saturday
Beware of malware posing as WhatsApp for PC
Users of desktop computers and laptops may want to think twice before downloading and installing a supposed PC version of the popular mobile app WhatsApp.
Security vendor Kaspersky Labs said, emails spreading online claim WhatsApp for PC is available and that the recipient already has 11 invitations from friends in his account.
"If the victim clicks on the link, it will lead him/her to a hacked server in Turkey and will then be redirected to a Hightail (Yousendit) account to download the initial Trojan, which in the system looks like a 64-bit installation file," Kaspersky researcher Dmitry Bestuzhev said in a blog post.
But the malware in reality will download a new Trojan that targets banking data.
According to Bestuzhev, the malware comes from a server in Brazil, with the recently downloaded banker having the icon of an mp3 file.
The malware also has some anti-debugging features to make analysis harder.
"Once running, the malware reports itself to the cybercriminals’ infections statistics console and when open, a local port 1157 sends stolen information in the Oracle DB format. In addition, it downloads new malware into the system; some samples are 10Mb in size. This is the classic style of a Brazilian-created malware," Bestuzhev said. — KDM, GMA News
source: gmanetwork.com
Labels:
Computers,
Dmitry Bestuzhev,
Gadgets,
Kaspersky,
Laptops,
Malware,
Mobile App,
PC,
Tech News,
Technology,
Trojan,
WhatsApp,
World News
Wednesday
Kaspersky AV inadvertently cuts off WinXP users' Internet access
Many users of computers running Microsoft's Windows XP and Kaspersky's antivirus software found themselves cut off from the Internet this week, a tech site reported.
A report on The Next Web cited Twitter posts and forum posts by unhappy users whose Internet access was blocked by Kaspersky's update (version 8.1.0.831).
"Kaspersky Lab has fixed the issue that was causing the Web Anti-Virus component in some products to block Internet access. The error was caused by a database update that was released on Monday, February 4th, at 11:52 a.m., EST," The Next Web quoted Kaspersky as saying in a statement.
It also said the problem was limited to x86 systems with the following Kaspersky Lab products installed:
Kaspersky Anti-Virus for Windows Workstations 6.04 MP4
Kaspersky Endpoint Security 8 for Windows
Kaspersky Endpoint Security 10 for Windows
Kaspersky Internet Security 2012 and 2013
Kaspersky Pure 2.0
"Kaspersky Lab would like to apologize for any inconvenience caused by this database update error. Actions have been taken to prevent such incidents from occurring in the future," Kaspersky said in its statement to The Next Web.
Before the fix was issued, The Next Web noted users complained they could not access internal (company networks) or external (on the Internet) websites, even as many noted Windows 7 did not appear to be affected.
Some users tried rolling back the update while others disabled Kaspersky's Web protection for the moment.
Others manually unblocked the ports 80, 443, and any ports they may have been using for a proxy.
But as of Tuesday morning (in the US), Kaspersky has since issued an update to address the problem.
"The bad news is that in many cases it will require user intervention: the update should install automatically but some users will have to disable the Web protection component first," The Next Web said.
The Next Web noted this was not the first occasional problem caused by faulty updates.
It said the last major one was in May 2012, when Avira crippled PCs by blocking critical Windows processes and third-party software. That was eventually fixed with an update. — TJD, GMA News
source: gmanetwork.com
Subscribe to:
Posts (Atom)



