IMPORTANT NOTIFICATION

This site is an archive of Simon's first blog.
Current writing and commentary is now published at
simonedwards.com.
Showing posts with label malware from legitimate sources. Show all posts
Showing posts with label malware from legitimate sources. Show all posts

Tuesday, 2 November 2021

The Coming Mac Threat (Revisited)

Foreword

The following article was written and published in 2008. The first iPhones were less than six months old and Apple's OS X operating system was just seven years old. The previous year Apple launched a version of OS X that could run on Intel systems. The following year OS X could *only* run on Intel systems. This could have made life easier for attackers, as they faced a familiar underlying system.

A lot has changed since then. According to some statistics the use of OS X (now MacOS) has risen between 2009 and 2021 from below 4% to around 16%. This is clearly a significant rise, but with around 75% of computer users still staring at Windows, the value to an attacker of MacOS exploits is still relatively low.

Attackers have targets and the chances of a valuable one using a Mac is now five times as likely. We've seen news reports of exploits targeted Apple-based devices. NSO's Pegasus spyware is now widely recognised as being a threat that targeted civilians, including journalists.

Thursday, 26 February 2015

Vulnerable security software

Last week the Superfish debacle became news and PC manufacturer Lenovo was slammed for pre-installing adware on new laptops.

Since then I've had people ask me about how dangerous this stuff actually is and whether or not security software that works in similar ways poses similar threats.

Monday, 8 December 2014

Pre-infected smartphones

Some Android mobile phones are being sold pre-infected with malware.

According to a blog post by Lookout's Jeremy Linden, "DeathRing is a Chinese Trojan that is pre-installed on a number of smartphones most popular in Asian and African countries."

Some of the most important points from his report include:

  • Detections are moderate in volume.
  • Detections are global.
  • The Trojan pretends to be a ringtone app.
  • The Trojan downloads SMS and WAP content.
  • The downloaded content can be used to trick users.
  • Most of the affected devices are counterfeit or uncommon models (in the West).
  • Anti-malware software cannot remove it.
The main lesson to learn here is to buy non-counterfeit devices from reputable sources. You might also consider installing an anti-malware product to alert you to problems. And watch for unexpected charges on your mobile phone bill.

[Image: Sad Android by Justin Marden]

Thursday, 14 March 2013

Seagate website infects visitors

A website run by hard disk manufacturer Seagate has been infecting visitors with malware for nearly a month (at least).

According to a report from Sophos:
SophosLabs has been tracking an infection of Mal/Iframe-AL on Seagate's blog since late February.
SophosLabs informed Seagate of the issue back in February, but at the time of writing the site remains infected.
Apparently the technical culprit is a couple of dodgy web server components (Apache modules) that are directing visitors to malicious websites using iFrames.

The malicious sites are using Blackhole exploit toolkits to infect victims' systems.

Sunday, 6 January 2013

Film scanner bundled with botnet

German coffee chain Tchibo has admitted to selling a film slide scanner that is infected with malware.

The company, which carries a range of gadgets alongside hot drinks, distributed a Hama scanner, the drivers for which were infected with the Conficker worm.


The is not the first time that consumer electronics have been accompanied by malicious code:

18/03/2010 Energizer Trojan keeps going

Monday, 17 September 2012

Malware on new PCs not installed at factory

Microsoft has reported that some new computers are infected with malware.

The mainstream and technical media has taken up this disturbing story and published nearly identical versions, complete with the same quotes.

Sadly they often miss the main point of this incident.

What most stories on this subject claim: malware is pre-installed on new computers at the factory.

What Microsoft's document actually states: malware was found on a computer bought from a shop.

In the report's own words:
"Microsoft’s researchers purchased a Windows laptop computer from computer reseller in Shenzhen, China, which had been carelessly or intentionally infected with Nitol.A."
The Guardian's story uses the headline, "Malware being installed on computers in factories, warns Microsoft" and opens with, "Criminals are installing malware on PCs before they leave the factory, according to Microsoft."

The BBC's version of events claims that, "Malware inserted on PC production lines, says study" continuing with the same flawed statement, "Several new computers have been found carrying malware installed in the factory, suggests a Microsoft study."

The Daily Mail's over-long headline warns that, "Hacker warning as research finds malware installed on computers before they even leave the production line". The report then uses the now-familiar, albeit grammatically incorrect, opening gambit of, "Criminals are installed malware on PCs before they even leave the factory."

There are a vast number of cookie cutter stories very similar to those above on the web.

Microsoft never made this claim, though. In fact its initial research was into the security of supply chains, rather than the internal security of factories. It is far more likely for a small business on the low-margin retail end of the line to engage in this sort of criminal activity than it is for a major manufacturer to compromise itself in this way.

Only one in 20 computers bought by Microsoft was infected.

In its report Microsoft claims to have found a copy of malware known as Nitol on just one of 20 computers that a researcher purchased. Three other PCs contained a few files that (unspecified) anti-virus software detected as being malware. This does not necessarily equate to an infection, though. In fact, as Microsoft notes, "The computer that contained the Nitol virus was the only one that was actively running."

Microsoft has published an article about its findings, which links to the document mentioned above, on its blog.

While this particular piece of research has been misrepresented, there have been verified cases of malware being installed at factories in the past:


18/03/2010 Energizer Trojan keeps going

Monday, 26 March 2012

How many dollars is a 'Like' worth?

Criminals are selling Facebook recommendations (by clicking the Like button) for $27 per 1,000 'Like's.

Companies that wish to increase their visibility by promoting their profiles can pay individuals or groups to click the Like button using multiple accounts.

The particularly sinister part to this story is that the criminals don't set up lots of their own accounts. They have found it more efficient to take over victims' accounts and abuse those instead.

In a post on Kaspersky Labs' blog, which actually focusses on a security issue with Google Chrome extensions, Fabio Assolini notes that an extension called Trojan.JS.Agent.bxo is hosted on the official Google Chrome Web Store.

The malicious extension gains control of the victim's Facebook profile. Among other features, including the inevitable ability to spread itself, "the script also has commands to use the profile of the victim to 'Like' some pages."

The reason for this ability is to make money. Fabio includes a screenshot from a website that clearly offers a Likes-for-cash service.

Wednesday, 30 November 2011

Mobile rootkit update: video

One week ago Trevor Eckhart reported that HTC phones were loaded with secret software designed to monitor pretty much anything on a smartphone. The story of potential wholesale monitoring was disturbing and was made more so by the legal threats made against him at the time for disclosing the issue.

Eckhart has now released video footage showing how the software is hidden and, most interestingly, the level of logging that it provides. Essentially he monitors the monitor and discloses the information that it collects.

This information includes details (including the text of) SMS messages, the handset's location and even records of the specific handsets buttons that are pressed by the user - in real-time. 


Friday, 25 November 2011

Stuxnet explained: video

Stuxnet is one of the most interesting pieces of malicious code found in the last few years.

It provides significant evidence that nation states are using computers to undermine each other.

The well-made video below explains what Stuxnet is (a weapon in code form), what it did and poses some questions about the future.

It suggests, incorrectly as far as I know, that the source code is available. Thus far it is not "open source", as claimed in the video.

This is one of many pieces of recent media that explores the concept of cyber war. It is a controversial area, largely because there is little proof. Stuxnet is tangible evidence, which is why security companies are so excited about it.

Cold war, cyber war or simply war?

Eugene Kaspersky has just written an interesting article that poses the view that this type of cyber war, in which malicious code is used as a form of weapon, is a series of acts of international aggression. He believes that it is tantamount to cyber terrorism.

Malicious code such as Stuxnet can do a few things but one of the most interesting characteristics is its capacity for sabotage. In the Cold War of the 1980s there were claims of sabotage, but rarely anything as direct as the tasks that Stuxnet is capable of carrying out.

One similar incident involved the Trans-Siberian pipeline back in 1982. The US is said to have planted a logic bomb that resulted in a massive explosion. Rather than introducing a virus from a network or USB key, the theory goes that US programmers planted the malicious code into a program that they knew would be stolen by the Russians.


Stuxnet: Anatomy of a Computer Virus from Patrick Clair on Vimeo.

Wednesday, 23 November 2011

Pre-installed rootkit spies on mobile users

Rootkit software is pre-installed on mobile handsets sold by major network operators.

The software allows a remote administrator to spy on an individual, checking their location, what software they are running on the phone and what keys they are pressing.

This news comes from Trevor Eckhart, who recently brought attention to a logging application that is pre-installed on HTC devices. That program opened up the possibility of an attack against a phone. His latest discovery is potentially more serious and sinister. Possibly that is why he has been threatened with legal action.

In an article posted on Android Security Test, Eckhart notes that:
"Carrier IQ (CIQ) sells rootkit software included on many US handsets sold on Sprint, Verizon and more. Devices supported include android phones, Blackberries, Nokias, Tablet devices and more."
The company says that its solutions have "revolutionized the way mobile operators and device vendors gather and manage information from end users." The question is, what is this information used for? CIQ claims that it's for troubleshooting and other diagnostic purposes.

Eckhart notes that the level of power the software provides to external administrators is high:
"...instead of seeing dropped calls in California, they now know 'Joe Anyone's' location at any given time, what he is running on his device, keys being pressed, applications being used."
This information was reported last week in various places, but today it seems that Eckhart is facing possible legal action over copyright infringement. CIQ apparently did not take kindly to the distribution of some training material, or Eckhart's characterisation of its software as a rootkit.

There seems to be a recent spate of legal threats against security researchers.

Tuesday, 8 November 2011

Apple unable to vet all apps

Charlie Miller sends a remote
command to vibrate his iPhone
A researcher has found a security hole that could allow unauthorised access to Apple iPhones.

The embarrassing part of this news, for Apple, is that someone was able to sneak a potentially malicious application through its code auditing process.

iPhone users rely on Apple to check through all third-party programs for security issues. Once Apple has verified that an app is malware-free, and only then, it is allowed into the iPhone Apps Store.

Charlie Miller, a well-known security researcher, wrote a stock ticker app that contained a nasty surprise. Once installed it was able to download further code. This was software that Apple had not had a chance to check.

In a video demonstration, Miller shows how the Trojan would allow an attacker remote access to an iPhone. He downloads the address book and issues a command to make the unit vibrate from a reverse shell.

Reports suggest that Apple has retaliated by banning Miller from its iOS development program. Apparently he planned to present his findings, including a live exploitation of a phone, at the SysCan conference in Taiwan.

UPDATE (08/11/2011): SecurityWeek reports that the vulnerability is due to iOS not enforcing code signing for the Nitro JIT compiler.


Tuesday, 4 October 2011

Linux may be rooted

Linux developers have been asked to check their systems for signs of rootkits. The warning comes after Linux leaders discovered that important servers had been compromised.

The advice given to developers is to re-install their operating systems. Alternatively the alerting email lists three Linux anti-rootkit tools. Then it's a matter of double-checking the package signatures and other onerous tasks.

The rootkit tools mentioned are:

The email thread includes some useful and interesting tips for securing Linux systems, and handling those that one suspects as being compromised.

HTC logger exposes Android user data

A "massive security vulnerability in HTC Android devices" has been found. The possible consequences are significant.

A researcher has found that software added by HTC to its Android devices exposes the following data:

  • Phone numbers
  • GPS data
  • SMS messages
  • Email messages
  • Addresses
  • Much more...
Basically Trevor Eckhart has found that HTC preinstalls a logging application that 'sniffs' a lot of information from the phone. It provides access to its own logs in a fairly loose manner. The upshot is that other applications could use the logger as a proxy and so read the above data.

Technical details, including a video showing a proof of concept attack, are available from Android Police.



UPDATE: An HTC spokesperson said that the company is "working very diligently to quickly release a security update that will resolve the issue on affected devices." Users will be able to download the fix over-the-air.

Thursday, 18 March 2010

Energizer Trojan keeps going

A Trojan has been found in software associated with a USB battery recharger made by Energizer. The Energizer Duo Charger charges batteries, "via a USB port or AC wall-outlet" and its progress can be monitored by software that is downloaded from the manufacturer's website during installation. According to a report on The Register this software contains a Trojan.

Energizer has taken the model off sale and claims to be investigating further into the matter.

US-CERT has published some technical information that notes how the standard Windows firewall will protect systems, assuming that the user does not click the Unblock button when prompted.

Monday, 22 February 2010

Online adverts infect PCs

Adverts on legitimate websites have been installing malware on victims' PCs for the last few days. All major online advertisement services have been affected. Visiting a site that uses any of the following services could potentially compromise your computer, with the end result being the installation of spyware and other unwelcome software:
  • advertangel.com
  • bannerconnect.net
  • bannerimg.com
  • bidsystem.com
  • doubleclick.net
  • globaltakeoff.net
  • googleadservices.com
  • jambovideonetwork.com
  • myspace.com
  • openx.net
  • specificclick.net
  • unanimis.co.uk
  • vuze.com
  • xtendmedia.com
  • yieldmanager.com
  • zedo.com
  • vestraff.com
Note the inclusion of Google's DoubleClick and GoogleAdServices services, as well as Yahoo!'s Yieldmanager service.

This situation, which highlights the risks involved when advertising companies sub-contract the content they distribute, has been reviewed by a number of security companies, including F-Secure and ALWIL Software (of Avast! anti-virus software fame).

F-Secure notes the chain of events that took one individual from a legitimate site to a fake anti-virus Trojan. In this example the advert traffic starts with Google's GoogleAdServices.com domain, moves through DoubleClick and Yieldmanager only to end up at a site hosting pharmaceutical goods and a link to the rogue anti-virus site. The following is F-Secure's initial analysis:

+partner.googleadservices.com
++pubads.g.doubleclick.net
+++ad.bannerconnect.net
++++ad.yieldmanager.com
+++++("pharmacy" site that contains a link to a Rogue-hosting site)
++++++The Rogue-hosting site

ALWIL Software refers to this scenario as ad-poisoning and notes that, "The most compromised services are yieldmanager.com (Yahoo) and fimserve.com (FOX Audience Network) which covers more than 50% [of ALWIL's dataset]."

Trivial note: I first wrote about this type of problem three years ago, when I created this blog. In fact, I wrote Spyware Through Google Adverts within days of starting.

Thursday, 26 November 2009

Symantec's website hacked

One of Symantec's web servers has been compromised, according to unu123456's blog. Infosecurity reports that the site in question is a Japanese support site, which was hacked with an SQL injection attack. According to this report:

Over 70 000 customers' details were allegedly in the hacked Symantec table, although Unu said that he extracted just five samples, which were obfuscated on the website to avoid compromise. He also claims to have exposed over 152 000 product serial numbers from the hacked Symantec website.

This is not the first time that a high profile security company has suffered a potentially embarrassing hack. The very same individual claims to have compromised a Kaspersky server in February this year, while servers belonging to Trend Micro and AvSoft were also hacked in 2008. In AvSoft's case its download section actually included malware, which will have caused more than a few red faces in Delhi.

Tuesday, 27 October 2009

Infected gaming gadgets

Last month the support website for Razer, a gaming hardware manufacturer, was compromised and its archive of downloadable drivers infected with threats including a Trojan and a worm.

I only found out about this yesterday while having lunch with Trend Micro's Rik Ferguson, who told me about his discovery of the problem.


Monday, 19 October 2009

Rogue Anti-Virus Software

I've spent the last couple of months locating malicious websites and testing anti-virus software, and one thing that's very clear is that fake anti-virus programs are all over the place. The ones we've seen tend to install themselves automatically, as a 'drive-by download', although it's perfectly possible to download and install them directly from certain websites intentionally.

When Symantec announced that it has identified 250 different types we thought it might be useful to write a news story about it and to use video footage taken in my virus lab to illustrate what these fake anti-virus programs look like. As you'll see if you click through to the story (or the video below), they are pretty convincing!



Sunday, 23 November 2008

The Complete Internet Security Handbook 2009

If you want to keep your family safe and your data private then The Complete Internet Security Handbook 2009 is the book for you. It includes the following:

What do you want to protect?
Learn how to manage risk and provide the best protection you can for the people and things you care about the most.

Cyber-criminals
Why do viruses, hackers, spam and fake bank websites exist? Discover the criminal underworld of the internet and find out how the scammers and conmen operate.

Chapter 1: Basic Desktop Protection
Take advantage of Windows' built-in security features and protect your computer for free.

Chapter 2: Viruses
Learn how to avoid viruses, recognise them when they appear and remove infections from your computer.

Chapter 3: Hackers, spies and other criminals
Prevent the bad guys on the internet from gaining control of your computer, internet connection and personal details.

Chapter 4: Spam and how to avoid it
Is your email inbox overwhelmed with annoying messages? We'll show you how to regain control and banish spam forever.

Chapter 5: Protect your child
The internet is a great educational resource, but threats abound. Ensure your kids stay safe online with our comprehensive guide.

Chapter 6: Lost and stolen
Reduce the chances of computer theft and encrypt your files to keep them private, even if they are stolen.

Chapter 7: Accidents and malfunctions
Discover the easiest way to keep your files safe and find out how to recover them if the worst happens.

Chapter 8: Personal privacy
Learn how to prevent your personal data falling into the wrong hands.

Chapter 9: Scams, fraud and hoaxes
Learn how to protect yourself against identity theft, email hoaxes and fake websites designed to steal your money.

BONUS CHAPTER: Wireless networking
They are convenient, but how safe are wireless networks? We show you how to build and bullet-proof your network.

The Complete Internet Security Handbook 2009 is available now from Borders and costs £7.99. It will also be available in WHSmiths from 27/11/2008. Amazon is currently selling it for £6.39 (as of 23/11/2008).

ISBN: 1-906372-18-7
Cover price: £7.99
Edited and (mostly) written by Simon Edwards.

Thursday, 9 October 2008

Infected Asus Eee PCs

The desktop version of the Asus Eee PC has been sold pre-infected with a virus. According to an Asus press release [Japanese], the following models contain malware, which may attempt to steal online games usernames and passwords:

Model number: EEEBOXB202-B; UPC code: 610839761807
Model number: EEEBOXB202-W; UPC code: 610839761814
Model number: EBXB202BLK/VW161D; UPC code: 610839530526
Model number: EBXB202WHT/VW161D-W; UPC code: 610839531202
Model number: EBXB202BLK/VK191T; UPC code: 610839547753


Dancho Danchev has published more details on the Zero Day blog.