24th August 2017

Solution Corner: Malwarebytes for Android

People have become increasingly reliant on their mobile devices in recent years. Smartphones and tablets have revolutionized daily life. Unfortunately, such rapid growth has also attracted criminals, bringing Android up to par with Windows in terms of infection rates. Android threat landscape A rapidly increasing group of threats on Android devices are so-called screen lockers, a form of ransomware that attempts to hold your device hostage by locking the screen with a ransom message and making it unusable. Android ransomware rose by nearly 140% globally from Q1 to Q2 of this year alone. Trojan malware is also on the rise, increasing by 10% in that same timeframe, with many of the threats in this category being banking Trojans. Such malware poses a significant risk, allowing attackers to potentially clean out an unfortunate victim’s bank account. Potentially unwanted programs (PUPs) are also a growing threat, accounting for nearly half of all Android threat detections in the first ha..
24th August 2017

Solution Corner: Malwarebytes for Mac

Mac users have been told for years: Macs don’t get viruses. Even Apple said so, in their famous Get a Mac ads that aired a decade ago. Wow, that’s so cool! It’s good to know we’re all safe. Now, on a different topic, can you tell me why Safari is going to a Russian search engine instead of Google? And I keep getting pop-ups telling me to “clean your Mac from junk!” Mac threat landscape Unfortunately, this old “wisdom” has never been true. There has almost always been malware for the Mac. The first widespread virus was the Elk Cloner virus, which actually infected the Apple II, prior to any PC malware. Some of the earliest malware affected the first Macs in the mid-1980s. The switch to a completely new architecture in Mac OS X, in 2001, killed all the old “Classic” Mac malware, but it didn’t take long for more to start appearing, starting with the MW2004 trojan a few years later. The only reason the myth that Macs can’t get infected with malware has persisted is that, until recently, ..
21st August 2017

A week in security (August 14 – August 20)

Last week, we gave some security tips for parents and kids aimed at the new school term. We also took a peek at the inside of the Kronos malware, focusing on how it works and protects itself. And, once again, we spotted a return of Locky ransomware with two new flavors at once, diablo6 and Lukitus. Below are notable news stories and security-related happenings from last week: Latest updates for Consumers The US government is seeking to unmask every person who visited an anti-Trump website in what privacy advocates say is an unconstitutional “fishing expedition” for political dissidents. A search warrant was issued to Dreamhost, a company hosting a website that was used to coordinate protest against the US president’s inauguration. Hackers hit Scottish Parliament with brute force cyber-attack. Staff at the Scottish parliament have been advised to change passwords as a result of the attack, performed by a yet unknown external source. An ex-Secret Service agent who stole Bitcoins from t..
14th August 2017

Week in Security (August 7 – August 13)

Last week, we explained how security certificates work and how malware authors have used them to block security software from being downloaded and executed. We also showed how the Magnitude exploit kit is spreading a Cerber ransomware variant that uses binary padding in an attempt to get skipped, because of its file size, during antivirus scans. Latest updates for Businesses Password rules have been way too complicated says the man that invented those rules and regrets it. These rules have now been updated. Locky made another comeback (maybe we should call it Rocky), this time using the diablo6 extension. And another ransomware that came back is the disk-encrypting Mamba. Microsoft and Kaspersky seem to get closer to burying the hatchet concerning the claim by the Russian anti-virus company that the US software giant was unfairly promoting the use of Windows Defender over third-party security products. Salesforce fired two of its senior security engineers after their talk at DEF CON. ..
7th August 2017

A week in security (July 31 – August 6)

Last week we explored some basic PowerShell commands, dived into the new methods used by TrickBot, and wrote at length about the Magnitude exploit kit redirection chain. Our teams were busy at both BlackHat and DefCon, and outside of those famous hallways, we also took time to fire up some basic PowerShell programs. Naturally the two big security events have consumed most of the column inches this past week, but even so there’s still a couple of notable security stories floating around. Latest updates for Consumers WannaCrypt victims paid out over $140k in Bitcoin to get files unscrambled: Victims of Ransomware continue to pay the price (source: The Register) Web Developer for Chrome compromised: A timeline of how a Chrome extension was taken over by bad actors (source: Blog on Chris Pederick) iOS users beware: You’re the biggest target for mobile phishing attacks: Keep a close eye on your trusty Apple devices (source: TechRepublic) Nigerian man charged in US phishing scam: Contra..