Showing posts with label Beware. Show all posts
Showing posts with label Beware. Show all posts

Monday, 9 September 2013

Beware Android Trojans hitching a ride on botnets

A dangerous Trojan that targets Google's Android mobile operating system has gained new nefarious capabilities even as a new banking malware takes aim at the OS, according to security researchers.

Kaspersky Lab reported that mobile botnets are being used to distribute the Obad.a Trojan, which can gain administrative rights on an Android device—allowing its masters to do pretty much anything they want with a handset.

Meanwhile, Eset revealed that a bad app it discovered earlier this month—Hespernet—is actually a mobile banking Trojan along the lines of Zeus and SpyEye, but with significant implementation differences that make it a new malware family.

The Obad.a Trojan has been closely watched by Kaspersky since the beginning of the summer, but it wasn't until recently that researchers uncovered the unusual distribution method its handlers have been deploying.

"For the first time, malware is being distributed using botnets that were created using completely different mobile malware," Kaspersky researcher Roman Unuchek wrote in a blog.

botnet

Such distribution techniques are common in the desktop world, but their arrival in the mobile space is another indicator that Android is becoming the mobile equivalent of Windows for hackers.

"This approach, like other aspects of the Obad operation, mimics what we've been seeing in the desktop ecosystem," Roel Schouwenberg, a senior researcher at Kaspersky, said in an email.

"In the Windows and Linux world, it's very common for malware and botnets to install other types of malware for pay," he added. "So it's likely that we'll see further adoption of this strategy in the mobile space as well."

Handsets are initially infected with the botnet software SMS.AndroidOS.Opfake.a through a poisoned link in an SMS message.

The link promises to deliver a new MMS message to the target. If clicked, the botware will be downloaded and the target asked to run it. If the target complies, SMS messages with the same MMS pitch will be sent to everyone on the target's contact list. In addition, the botware will download Obad.a, which sets up a backdoor on the handset that allows a botmaster to remotely control the device.

Other more conventional means are also used to distribute Obad.a, including SMS spam, links to fake Google Play stores and redirection from poisoned websites.

That kind of multi-vector infection strategy isn't common yet in the mobile world. "Right now, Obad is setting a new standard," Schouwenberg said. "We're still quite a bit away from multiple infection vectors being the norm rather than the exception."

Up to now, Obad.a activity has been directed at populations in the states of the old Soviet Union, although there has been some spillover into other countries. "For now, other countries are not where the attackers' focus seems to be," Schouwenberg said.

Hesperbot also appears to have a limited geographic distribution—primarily Turkey and the Czech Republic. However, the campaign, may expand. "It's quite likely we'll see more instances of this as time goes by," Eset Security Evangelist Stephen Cobb said in an interview. "I would expect we'll see more attacks in more countries."

Hesperbot is spread by luring targets to an infected website with a poisoned link embedded in an email or SMS message. The Czech scam sent targets to a website closely modeled on the landing page of the country's postal service.

"The aim of the attackers is to obtain login credentials giving access to the victim's bank account and to get them to install a mobile component of the malware on their Symbian, Blackberry or Android phone," Eset researcher Robert Lipovsky wrote in a blog.

trojan horse

He described Hesterbot as a very potent banking Trojan with features such as keystroke logging, creation of screenshots and video capture, setting up a remote proxy, creating a hidden VNC server on an infected system, intercepting network traffic and HTML injection.

Other banking Trojans, like Zeus and SpyEye, perform those functions, too; what sets Hesperbot apart is its use of new code to do those tasks. "It's not made with SpyEye or Zeus code," Evangelist Cobb said. "That might sound like a technical distinction, but the fact that someone went to the trouble to write a brand-new banking Trojan is indicative of the appeal that remains for the software."

That appeal will likely grow. "As more mobile capabilities are rolled out and mobile payments become more widespread and ubiquitous, malware is going to follow," said George Tubin, senior security strategist at Trusteer, an IBM company. "We're right at the beginning of it now."

He explained that improved security measures at larger banks have been driving cyber robbers downstream to mid- and small-sized banks. "Now, they'll also be moving into the mobile channel, because banks haven't deployed very sophisticated fraud detection technologies there yet," Tubin said.

Nevertheless, mobile infections can be avoided if a user is willing to avoid high-risk behavior. "They're not going to get infected if they stick to downloading apps from Google Play or their employer's app store," Randy Abrams, a research director at NSS Labs, said in an interview.

"There have been exceptions, and Google has allowed infected apps into their store," he continued, "but the majority of apps on Google Play are going to be very safe—as long as you don't consider compromising your privacy a safety issue."

John Mello writes on technology and cyber security for a number of online publications and is former managing editor of the Boston Business Journal and Boston Phoenix.
More by John P. Mello Jr


View the original article here

Monday, 19 August 2013

Beware spammers thriving in Facebook Groups

A couple of weeks ago I was flicking through Facebook on my iPad when I noticed this buffoon in my News Feed.

Suspicious news feed post.

Though the buffoon's post tells people to not leave comments, I posted one anyway. I cannot repeat what I said here; suffice it to say I got my point across.

There were in fact multiple postings from the buffoon in my feed that day – something I hadn't seen before. How in Zuckerberg's name did they get here? It has to do with how Facebook has designed its Groups feature. The short version: Because Facebook allows any friend to add you to any Group, it leaves the door wide open to spammers and says "come on in!"

Here's the longer version.

Apparently, at some point in the last month or so I got added to a Group called "Share Your Topics." If you visit that Group – and I don't recommend it – you will find all sorts of similar come-ons from slime merchants like the buffoon above. I was also added to another Group called Technology News where the buffoon also posts.

You can only be added to a Group by a member who is also on your friends list. But once you're there, you get to see posts from people who are most definitely not your friends – including buffoons like that one.

That's because, in its infinite wisdom, Facebook decided that if someone else wants to add you to an "open" Group on Facebook, you're in. And by "infinite wisdom" I really mean "blatant desire to grow its Groups feature as quickly as possible and clean up the mess later (maybe) if enough people complain."

After you're added to a Group, Facebook notifies you, which presumably gives you the option to subtract yourself. But if you miss that brief notification, you're subject to any spammy post anyone in that Group deigns to share until you leave.

These notifications are also supposed to show up in your Activity Timeline, along with the name of the soon-to-ex-friend who added you. But in my tests about half of these Group notifications did not show up – only God and Sheryl Sandberg know why. Neither Share Your Topics nor Technology News are listed in my Activity Log, so I don't know when I was added or who did it (though I have my suspicions).

As I've noted in the past, Facebook's tools for reporting abusers are notoriously frustrating. You can report a Group or a person for posting "inappropriate content." You can block the person, which doesn't stop the spamming but does keep you from seeing it. Or you can send them a polite (in my case impolite) note asking them to please stop what they are doing.

Alert the transgressor.

Good luck with that last one. I reported this guy and the Share Your Topics Group weeks ago. Nothing has changed.

Meanwhile, I've noticed that open Groups I voluntarily chose to join are now changing their privacy settings from open to closed. I asked one of the administrators why. His answer was simple: Spammers had invaded it.

If you're the administrator of a Facebook Group and you haven't locked it down yet, now would be a good time to do that. It's pretty easy. Go to the Group page, click the settings button in the upper right (the gear icon), and select Edit Group Settings from the drop down menu. From there you can pick exactly how open or closed you want the Group to be, and how much admin control you want over who can join and what they can say.

Administrators can lock down a Facebook Group.

A better solution would be for Facebook to change its Groups policies to make them opt in, not opt out, so people can't simply add you to whatever Group they feel like until you leave. Facebook should also make it much easier to report abusers, as Twitter has done. But I don't think Facebook has any interest in solving this problem. In the meantime, we'll remain at the mercy of buffoons like this guy.

Follow TechHive on Tumblr today.


View the original article here