Last week, we had given previews of some of our findings from an analysis of 10,000 Android apps to a few reporters including Tim Wilson at DarkReading, Rob Westervelt at SearchSecurity, and Sean Kerner at InternetNews.com. Since then, we've been glad to see a high level of interest in our findings from other reporters as well! We'll be releasing our full set of findings at the BlackHat security conference on August 4 in Las Vegas, but until then, following is a preview of some of the findings that we thought would be of interest to the community:
Saturday, July 23, 2011
Tuesday, May 31, 2011
Debunking The Myths Of Mac And Mobile Malware
Writing malware, as with writing any other type of software, involves costs and benefits. Like any software developer, malware authors want to reach as many users as they can, usually by creating a program that is easy and fast to deploy and can be written with minimum effort. But with malware, these costs and benefits aren’t as obvious as many observers think.
Monday, March 7, 2011
The Dasient Q4 Malware Update: Significant Rise in Malvertising Attacks, Social Networking Sites Easy Distribution Platforms for Malware
Q4 2010 was a quarter in which we saw continued growth of web malware and malvertising attacks targeting legitimate sites. In this report, we focus on (1) quantitative measurements around web malware and malvertising, (2) analysis surrounding the most significant attacker domains for the quarter, and (3) results from some experiments we conducted on the potential impact that web malware could have on social media networks.
Tuesday, February 22, 2011
New financial malware hijacks online banking session after user logs out
There are many reports today about a new, sophisticated type of financial malware called “OddJob” that will hijack a user’s session after they have logged out of their online banking account to commit fraud. According to reports from Trusteer, there are a few things that are noteworthy about the attack:
Tuesday, February 8, 2011
New Funding, New Website, New Research
It's been an exciting week for us. We raised new funding by Google Ventures, launched a new website and Neil and team have published new research on the widgetization of the web.
Malware is one of the fastest growing threats on the Internet today. We are thrilled that the additional funding by Google Ventures will help support our mission and commitment to keep the Internet safe and malware-free for users and online businesses. For more details on the this partnership read the press release here.
Malware is one of the fastest growing threats on the Internet today. We are thrilled that the additional funding by Google Ventures will help support our mission and commitment to keep the Internet safe and malware-free for users and online businesses. For more details on the this partnership read the press release here.
Monday, February 7, 2011
NASDAQ Exchange website infected with malware
According to various sources, a website operated by Nasdaq was compromised and infected with web based malware. Reports of the attack surfaced last week. The target of this attack are the roughly 10,000 executives that use the Nasdaq information portal Directors Desk. It appears that attackers were able to inject drive-by-download malware onto the website. Although sources familiar with the matter claim that the exchange’s trading platforms were not affected, the risks of this attack are nonetheless very high. Visitors to the website would have been exposed to malware which could at a later time log their keystrokes and steal passwords to sensitive trading accounts or other information.
Thursday, December 23, 2010
Fast Forward: Dasient's Security Predictions for 2011
As we wrap up 2010 and reflect on some of the major security headlines of the year - Aurora, Zeus, WikiLeaks, Stuxnet - it's hard to look at 2011 without wondering how much worse it will get before it gets better. The reality is that cybercriminals are innovative, creative, and fast. We need to do better as a community to counter the threat they pose to our organizations and to the Internet as a whole. Following are Dasient's Top 5 Security Predictions for 2011:
1) There will be a large botnet cyber war that Zeus will end up winning. Zeus will hold its ground against other botnets that try and attack it. Botnets have been around for over a decade, but have evolved significantly since Tribe Flood Network (TFN), Trin00 and similar tools that were used to attack Amazon, Yahoo, and E*Trade in 2000. While only thousands of clients were used to cripple large web sites 10 years ago, the size of botnets have expanded to hundreds of thousands or millions of clients, have become multi-application (e.g., are used to send email spam, and do keystroke logging in addition to DDoS), and the growth of botnets has utilized more and more automated technology. Compromised machines that make up botnets have become a commodity, and while there are still lots of vulnerable, uncompromised machines that are available for the taking, attackers will eventually start to “butt-heads.” While there has been some early indications that attackers have patched machines that they have infected to prevent other attackers from stealing their infected machines, 2011 will likely be the year that large botnets will start more aggressively competing to sustain their growth, and users will get caught in the middle. Zeus has proven its ability to grow to sizes more significant than other botnets, and is also one of the more profitable botnets that targets financial institutions. We expect to see a botnet cyberwar in 2011, and predict that Zeus will come out on top.
2) Human mules will be replaced by malware that do the equivalent job of transferring balances between bank accounts using keystroke-logged credentials. Today, once user credentials such as bank account usernames and passwords are logged on compromised client machines, those credentials are shipped off to botmaster servers, aggregated, and provided to human mules. The human mules most often don’t know they are mules, but think they are doing “work-at-home” types of jobs in which part of their job responsibility is to make monetary transfers between bank accounts. In 2010, we saw some significant arrests of hundreds of such human mules. Just as system architects work to eliminate points of failure when building resilient systems, the cybercriminals will do the same for their operations. If human mules can be arrested and can get in the way of transferring money from the stolen accounts to the cybercriminal’s accounts, they’ll replace the humans with additional malware for that purpose. Writing software to automatically make transfers betweeen bank accounts does require good coding, management of session data, and other such technical details, but can be done rather simply with today's attack and automation tools. As such, like many areas of businesses today, humans will be taken “out-of-the-loop” to scale cybercriminal operations.
3) We’ll see the first significant HTML 5 abuses. The HTML5 standard has been in development for some time, and every major browser now includes some support for it. Some of the features include local browser storage in which web sites will be able to store more than just cookies on your machine, and support for inline videos without requiring third-party plug-ins such as Flash. With any new functionality comes increased attack surface, and the same will be true for HTML5. We expect to see things like malware authors stuffing malicious code into the local browser storage provided by HTML 5 and then executed via a browser vulnerability. In addition, as HTML 5 has native video tags, we expect to see zero-size video tags used to inject web-based malware, just as we see zero-size IFRAMES used today to do the same. As HTML5 implementations will be at their newest, cybercriminals will leverage bugs in the early implementations tospread malware.
4) Advanced IM threats will increase and be directed at the use of webcams and audio. Attackers have been using malware to do keystroke logging for years, but as the number of standard input devices on machines increase, so will the attackers' interest in them. Most PCs have built-in microphones, and while there has been some malware that automatically turns on and captures audio and video from these devices, we expect that webcam-logging and audio-logging will become just as popular as keystroke-logging. Malware authors will use the additional logging to build more “ransom-ware” in which they record sensitive conversations and pictures, and will then demand a ransom from individuals and companies by threatening to release the sensitive media onto the Internet or disclose to interested parties if the ransom is not paid.
5) As the use of social media web sites continues to grow, drive-by-downloads and rogue anti-virus will be used more aggressively on platforms such as Facebook and Twitter. This is evidenced by threats such as the Koobface botnet that continually targets Facebook, as well as the September XSS attack that targeted Twitter and
redirected users to porn and malware sites.
1) There will be a large botnet cyber war that Zeus will end up winning. Zeus will hold its ground against other botnets that try and attack it. Botnets have been around for over a decade, but have evolved significantly since Tribe Flood Network (TFN), Trin00 and similar tools that were used to attack Amazon, Yahoo, and E*Trade in 2000. While only thousands of clients were used to cripple large web sites 10 years ago, the size of botnets have expanded to hundreds of thousands or millions of clients, have become multi-application (e.g., are used to send email spam, and do keystroke logging in addition to DDoS), and the growth of botnets has utilized more and more automated technology. Compromised machines that make up botnets have become a commodity, and while there are still lots of vulnerable, uncompromised machines that are available for the taking, attackers will eventually start to “butt-heads.” While there has been some early indications that attackers have patched machines that they have infected to prevent other attackers from stealing their infected machines, 2011 will likely be the year that large botnets will start more aggressively competing to sustain their growth, and users will get caught in the middle. Zeus has proven its ability to grow to sizes more significant than other botnets, and is also one of the more profitable botnets that targets financial institutions. We expect to see a botnet cyberwar in 2011, and predict that Zeus will come out on top.
2) Human mules will be replaced by malware that do the equivalent job of transferring balances between bank accounts using keystroke-logged credentials. Today, once user credentials such as bank account usernames and passwords are logged on compromised client machines, those credentials are shipped off to botmaster servers, aggregated, and provided to human mules. The human mules most often don’t know they are mules, but think they are doing “work-at-home” types of jobs in which part of their job responsibility is to make monetary transfers between bank accounts. In 2010, we saw some significant arrests of hundreds of such human mules. Just as system architects work to eliminate points of failure when building resilient systems, the cybercriminals will do the same for their operations. If human mules can be arrested and can get in the way of transferring money from the stolen accounts to the cybercriminal’s accounts, they’ll replace the humans with additional malware for that purpose. Writing software to automatically make transfers betweeen bank accounts does require good coding, management of session data, and other such technical details, but can be done rather simply with today's attack and automation tools. As such, like many areas of businesses today, humans will be taken “out-of-the-loop” to scale cybercriminal operations.
3) We’ll see the first significant HTML 5 abuses. The HTML5 standard has been in development for some time, and every major browser now includes some support for it. Some of the features include local browser storage in which web sites will be able to store more than just cookies on your machine, and support for inline videos without requiring third-party plug-ins such as Flash. With any new functionality comes increased attack surface, and the same will be true for HTML5. We expect to see things like malware authors stuffing malicious code into the local browser storage provided by HTML 5 and then executed via a browser vulnerability. In addition, as HTML 5 has native video tags, we expect to see zero-size video tags used to inject web-based malware, just as we see zero-size IFRAMES used today to do the same. As HTML5 implementations will be at their newest, cybercriminals will leverage bugs in the early implementations tospread malware.
4) Advanced IM threats will increase and be directed at the use of webcams and audio. Attackers have been using malware to do keystroke logging for years, but as the number of standard input devices on machines increase, so will the attackers' interest in them. Most PCs have built-in microphones, and while there has been some malware that automatically turns on and captures audio and video from these devices, we expect that webcam-logging and audio-logging will become just as popular as keystroke-logging. Malware authors will use the additional logging to build more “ransom-ware” in which they record sensitive conversations and pictures, and will then demand a ransom from individuals and companies by threatening to release the sensitive media onto the Internet or disclose to interested parties if the ransom is not paid.
5) As the use of social media web sites continues to grow, drive-by-downloads and rogue anti-virus will be used more aggressively on platforms such as Facebook and Twitter. This is evidenced by threats such as the Koobface botnet that continually targets Facebook, as well as the September XSS attack that targeted Twitter and
redirected users to porn and malware sites.
Subscribe to:
Posts (Atom)