19th March 2018

A week in security (March 12 – March 18)

Last week on Malwarebytes Labs, we took a look at the inner workings of a fileless attack, explored what happened in a zero day ransomware attack aimed at South Koreans, gave you hints and tips for avoiding cold calls, and took a deep dive into the secretive world of GrayKey. Other news The Equifax story just keep rumbling on. (Source: The Guardian) Some Meltdown and Spectre updates. (Source: The Register) VPN tests give some concerning results. (Source: vpn Mentor) The rich world of money laundering. (Source: Help Net Security) Critical vulnerabilities found in SecurEnvoy SecurMail. (Source: SEC Consult) An incredible story looking at Cambridge Analytica. (Source: The Guardian) Cybercrime as a service. (Source: ZDNet) Geopolitical events contributing to malware spikes. (Source: Enterprise Times) Preinstalled malware on 5 million Android devices? Whoops (Source: The Inquirer) Backdoored BitTorrent client causes malware attack on 400k PCs. (Source: Ars Technica) Stay safe, everyone! T..
15th March 2018

GrayKey iPhone unlocker poses serious security concerns

Ever since the case of the San Bernadino shooter pitted Apple against the FBI over the unlocking of an iPhone, opinions have been split on providing backdoor access to the iPhone for law enforcement. Some felt that Apple was aiding and abetting a felony by refusing to create a special version of iOS with a backdoor for accessing the phone’s data. Others believed that it’s impossible to give backdoor access to law enforcement without threatening the security of law-abiding citizens. In an interesting twist, the battle ended with the FBI dropping the case after finding a third party who could help. At the time, it was theorized that the third party was Cellebrite. Since then it has become known that Cellebrite— an Israeli company—does provide iPhone unlocking services to law enforcement agencies. Cellebrite, through means currently unknown, provides these services at $5,000 per device, and for the most part this involves sending the phones to a Cellebrite facility. (Recently, Cellebrit..
15th March 2018

New Monero mining malware discovered in Google Play

In November 2017, we detected a strain of malware known as JSMiner in Google Play. The Monero cryptomining capabilities were discovered inside the gaming application Cooee. At the time of discovery, we forecasted a rise in mobile mining malware as attackers shift their attention from PC to mobile. And this week, we identified two more cryptomining apps in Google Play: SP Browser and Mr. MineRusher with a combined subscriber base in the thousands.
12th March 2018

A week in security (March 05 – March 11)

Last week on Malwarebytes Labs, we paid homage to several women in tech, including some of our very own, on International Women’s Day and shared their stories. We also looked into an adware posing as an Android app that claims to live stream the 2018 Winter Olympics, exposed scammers that go by the name GeeksHelp, who were caught red-handed (again) after their first unmasking two years before, and gave you the steps on how to break encryption. Lastly, we spotlighted the impact of artificial intelligence (AI) and machine learning (ML) in cybersecurity, the importance of having a solid and tested incident response framework, and the reality that Mac malware does exist and that they have evolved. Other news Avid Twitter, Facebook, and Instagram user? Be wary of clicking links in your feed, as phishing campaigns are seen on the rise in social media platforms. (Source: Security Brief) Inexpensive Android smartphone models were pre-installed with the Triada Trojan, one of several advanced..
9th March 2018

Time to Tighten Up Device Security | Avast

Lawmakers urge better security for smart devices The first indication that internet of things (IoT) devices posed a real security threat came in October 2016 when a botnet — made up of devices such as security cameras infected with Mirai malware — attacked Dyn, a provider of DNS services.The attack came in the form of a DDoS (distributed denial of service) assault on Dyn’s servers. By firing off multiple requests every second, the attack took down websites all over the USA and Europe, as DNS servers were overrun with requests from millions of infected devices.