LATEST THREATS

Phone Users Are Vulnerable, Too

It has now been demostrated through research that a possible attack methods by creating mobile phone rootkits malware that burrows deep into the operating system.
The researchers were able to hit three specific mobile features, attacking the battery (to keep the user from turning on the phone), GPS services (to snag location data), and voice and messaging (to listen to voice messages and retrieve old texts).

If your smartphone were to be infected in any of those ways, you probably wouldn't even notice--even if you're a sophisticated user. Because security software generally sees operating systems as trustworthy, rootkits tucked deep within an OS can go undetected for a long time. In fact,desktop antimalware have only recently started to scan for rootkits.
The researchers built their rootkits for Neo Freerunner smartphones, which run the Openmoko Linux-distribution operating system. Google Android uses Linux, and therefore could be attacked right away. The Rutgers team says that with a little work the Linux rootkits could be ported to the Apple iPhone OS, Windows Mobile, and Symbian OS.

The simplest rootkit, which targets a smartphone's battery, would need only to enable Bluetooth or the phone's GPS function to drain the power--and it could do so without your even realizing it. Unless you carefully studied your smartphone, you might not see the tiny icons indicating that multiple power-draining services were enabled. If your phone were infected, you'd find yourself having to recharge it more often--or, when you needed it most, your phone would be dead.

More sinister is the rootkit that grants third-party access to your GPS information. Even when you're not using your mobile phone, the GPS service keeps tabs on your whereabouts; such information, when exposed to a less-than-trustworthy person, would take stalking to a new level.
The most harmful rootkit, however, would access your voice and text messages. If your phone were so compromised, whenever you sent or received a new text message, a cybercriminal would get a copy, too.



BEWARE ATTACK BY ROGUE FACEBOOK APP

Another attack using rogue facebook applications hit users' PCs with massive assault,Like previous attack, this scam uses a sex-oriented video as bait.The scam is spread through Facebook messages touting "Distracting Beach Babes" videos that include a link to the malicious application. Users who click on the link are asked to allow the application to access their profiles, and let it send messages to friends and post it on their walls. Once approved, the application instructs users to download an updated version of FLV Player, a popular free Windows media player, to view the video.

This new attack is almost identical to the one that generated several hundred malicious software report to antivirus vendor AVG Technologies sometime ago.The nature of the malware that masquerades as FLV Player, it was most likely the result of the notorious hotbar malware , a toolbar that inserts itself into Internet Explorer and displays pop-up ads and links.

I'm beginning to wonder if the cybercriminals deliberately launch these campaigns on the weekends, imagining that anti-virus researchers and Facebook's own security team might be snoozing.Facebook users have used the service to warn others of the ongoing attacks.



KOOBFACE CHANGES ITS TRICKS


The Koobface worm is a case study of how swiftly cybercriminals react to emerging trends. Koobface first appeared in the fall of 2008 just as social networks were getting hot. Its creators initially sent Facebook users friendly messages asking them to click on a link to see a video.
Doing so called up another message asking the recipient to click on an executable file — a small computer program — needed to upgrade a video player required to view the video. In a classic bait-and-switch, clicking on the file instead turned over control of the PC to the attackers. The worm then automatically sent similar viral messages from the victim's account to his or her Facebook friends.


Persuading someone to click on the malicious file was huge; it meant the victim was intentionally choosing to run the bad code. So no actual hack of the computer's hard drive was needed.They've tricked you into doing their dirty work.
Koobface's controllers continually refine their pitch, often tying come-ons to celebrity news; they've pioneered new ways to quickly alter the bad code just enough to counteract antivirus filters designed detect malicious programs and block them.
And they've aggressively extended their attacks to large and small social networks, including MySpace, Twitter, Hi5, Bebo, MyYearbook and Friendster.Their inventiveness is astonishing.
Thus far, the gang has been content to generate revenue mainly by routing promotions for worthless anti-virus protection or fake drugs to each computer they infect.The business model is simple, 'low-effort, quick money.

But there is little stopping Koobface's controllers from renting out infected PCs to other criminals, a common practice.Horse-trading between botnet operators may result in changes in the way the victim's computer is used over time.







Beware the Rise of Ransomware

The latest spin on a ransom note isn’t composed of letters clipped out of a newspaper. Increasingly, criminals are unleashing brash attacks on your PC and its data through a type of malicious software called ransomware.

It’s exasperating enough when your computer is sluggish because of a virus, but what if the virus installs embarrassing pornography on your screen or encrypts your data so you can’t read it? Ransomware attacks often use these tactics to demand you pay a ransom to remove the pornography or to access your files.

Ransomware on the rise

There’s more and more documented evidence that this is going on.It’s more prevalent in the United Kingdom, which is sort of a staging or testing ground. It’s starting there and getting more momentum. which include ransomware and fake antivirus scareware scams,criminals are netting an estimated $150 million a year through these scams.Ransomware is actually scarier” than the scareware scams. “There’s nothing worse in the field of technology than having a criminal in control of your network. When a ransomware attack occurs, it can easily elevate from a potential data loss to potential identity theft to a data breach in the form of extortion.”

How ransomware works

These aggressive assaults begin in a similar manner to scareware. You’re duped into clicking on an infected popup advertisement or you visit an infected website. However, instead of just trying to trick you into buying fake antivirus software, the bad guys hold your computer hostage and attempt to extort payment.In some instances, ads for pornographic websites appear on your screen each time you try to click on a Web page. The ads cover a portion of the page you’re trying to view. Just imagine you’re sitting at work and that happens to you. One ransomware attack puts time pressure on the victim, stating that a piece of your data will be destroyed every 30 minutes if you don’t pay up. Another attack attempts to force you to purchase a program to de-encrypt your data.

The criminals often ask for a nominal payment, figuring you’ll be more likely to pay to avoid the hassle and heartache of dealing with the virus. They may ask for as little as $10 to be wired through Western Union, paid through a premium text message or sent through a form of online cash.

Protect yourself from ransomware
As with other attacks, you can work to avoid ransomware. Experts advise taking these steps to avoid attacks or protect yourself after an attack:

1.Use reputable antivirus software and a firewall. Maintaining a strong firewall and keeping your security software up to date are critical. It’s important to use antivirus software from a reputable company because of all the fake software out there.

2.Back up often. If you back up files to either an external hard drive or to an online backup service, you diminish the threat.If you back up your information, you should not be afraid to just turn off your computer and start over with a new install if you come under attack.I back up my data regularly, so every six months, I simply restore my computer’s system to default and starts afresh.I would highly recommend it.

3.Enable your popup blocker. Popups are a prime tactic used by the bad guys, so simply avoid even accidentally clicking on an infected popup. If a popup appears, click on the X in the right-hand corner. The buttons within a popup might have been reprogrammed by the criminals, so do not click on them.

4.Exercise caution. Don’t click on links inside emails, and avoid suspicious websites. If your PC does come under attack, use another computer to research details about the type of attack. But be aware that the bad guys are devious enough to create fake sites, perhaps touting their own fake antivirus software or their de-encryption program.

5.Disconnect from the Internet. If you receive a ransomware note, disconnect from the Internet so your personal data isn’t transmitted back to the criminals.Simply shut down the computer. If you have backed up your data, you can re-install software. If you don’t feel comfortable doing so or you are unable to start fresh, you may need to take your computer to a reputable repair shop.

6.Alert authorities. Ransomware is a serious form of extortion.Local police are probably not equipped to deal with this. “However,your local security outfit would want to know about it.”
Don’t be tempted to give in and pay the ransom.Paying them would be a mistake because they will further extort you and most likely not release your information. Taking precautions to protect your information and maintaining vigilance are the best solutions to avoid becoming a victim in the first place.

Next time you get an e-card, you better check who it is really from. Fake e-cards can contain dangerous malware.