Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Monday, 3 March 2014

Businesses told to lockdown Bitcoin wallets against malware threat

Malware designed to steal digital currency from Windows PCs has risen with Bitcoin value since beginning of last year, says studyBusinesses considering accepting Bitcoins or other forms of cryptocurrency should be prepared to battle a rising number of malware aimed at emptying digital wallets.

[Why security pros should care about Bitcoin's troubles]
That's the takeaway from a new study by SecureWorks, computer maker Dell's security unit. Researchers found that the number of malware targeted at stealing cryptocurrency from Windows PCs increased along with the rise in value of Bitcoin since the beginning of 2013.

As of January of this year, SecureWorks had identified on the Internet 100 unique families of malware capable of stealing wallet files or digital currency from users' exchange accounts. The increase in the number of cryptocurrency-stealing malware made it "one of the fastest-growing categories of malware," the study said.

While Bitcoin is not the only type of cryptocurrency, it is the most popular and the most valuable. The price has ranged from a high of roughly $1,150 in early December to a low of $420 Feb. 25. Bitcoin's price on Thursday was about $565. Other digital currencies include Namecoin, Litecoin, Dogecoin, PPCoin and Mastercoin.

The recent shutdown of Mt. Gox, which once had the largest market share of all digital currency exchanges, highlights the risk of cryptocurrency traded over the Internet. The Bitcoin exchange closed this month after cybercriminals stole $400 million. The heist is under investigation by U.S. federal authorities.

The rising popularity of digital currency has led to its adoption by retailers. Overstock.com became the first major online retailer to accept Bitcoins, and industry observers expect others to follow. The site SpendBitcoins lists many places on the web where people can spend their digital currency.

To protect the digital wallets used in conducting transactions, SecureWorks researchers recommend the use of a "split wallet," which has a portion of the file on the computer connected to the Internet and the rest on a system with no network connection.

The file kept on the Internet-enabled system would let the business track its running balance and perform transactions with customers. On the offline system is the private key for authorizing a transaction before it is transmitted.

Electrum is an example of a split wallet done through software. Examples of hardware-based products include Hardware Wallet and Trezor, which plans to release its product soon.

By using the proper security, businesses can significantly reduce the risk of accepting digital currency, Pat Litke, security researcher for Dell SecureWorks' Counter Threat Unit, said.

"It's simply a matter of understanding how to do it safely, and that's where the general population falls short," Litke said.

[Ransomware like Cryptolocker uses Bitcoin, other virtual currencies for payment]
The SecureWorks study found several categories of PC malware targeting digital currency. One form searched an infected system's hard drive for the typical file names used for wallets, such as "wallet.dat." The file was copied and then sent to a remote server.

Another malware family would set up a man-in-the-middle-like attack in which the address of the recipient in a transaction is altered, so the money goes into the thief's account.

Best CCNA Training and CCNA Certification and more Cisco exams log in to Certkingdom.com


Monday, 18 March 2013

NotCompatible' Android malware rears its ugly head, again

NotCompatible' Android malware rears its ugly head, again
Mobile security vendor Lookout says Android malware is showing signs of sudden activity

The "NotCompatible" malware, designed to infect Android devices and turn them into unwitting Web proxies, is suddenly showing a sharp uptick in activity, according to mobile security vendor Lookout.

The malware is essentially a simple network proxy, which pretends to be a system update in order to get unwitting users to install it. The idea seems to be gaining access to protected networks through victims' infected Android devices. It was named for its apparent command-and-control server, at notcompatibleapp.eu.

Last weekend saw the number of detections for NotCompatible rise to 20,000 per day as of last Sunday and Monday, wrote researcher Tim Strazzere, who said that the malware had been largely dormant since it was discovered in May 2012.

But while the initial discovery saw the malware being installed by hacked websites, the latest wave of NotCompatible is being spread by email spam. The usual subject line is "hot news," and the infected messages appear to contain links to fake weight-loss articles.
NotCompatible malware
Credit: Lookout Security
The hacked Web page that can contain the NotCompatible malware.

"Depending on the user's Android OS Version and browser, they may be prompted about the download. Many stock browsers will transparently trigger a download to the device /Downloads folder whereas Chrome displays a confirmation dialog," wrote Strazzere.

Lookout said there is little chance of direct harm to infected devices, and victims must allow NotCompatible to be installed for it to function, further minimizing the overall threat to the majority of Android users. The best advice for safety is simply to never allow any .apk whose provenance you're even a little bit unsure of to be installed on your phone.

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com