Report

Spam Carrying WikiLeaks Worm

Published: December 7, 2010 Reading time: 2 min

Symantec Connect: WikiLeaks.org is in the news after their recent publications linked to leaked government documents. Spammers are now leveraging the current level of interest with social engineering techniques to infect users’ computers. Symantec is observing a wave of spam spoofing WikiLeaks to lure users into becoming infected with a new threat. The spam email has subject line “IRAN Nuclear BOMB!” and spoofed headers. The “From” header purports to originate from WikiLeaks.org, although this is not in fact the case, and the message body contains a URL. This URL downloads and runs WikiLeaks.jar which has a downloader ‘WikiLeaks.class’ file. The downloader pulls the threat from http://ugo.file[removed].com/226.exe. Symantec detects this threat as W32.Spyrat. ...

Continue Reading

Taking a look at fake Amazon receipt generators

Published: December 7, 2010 Reading time: 3 min

Sunbelt Blog: Above, you can see a vaguely optimistic VirusTotal user summary in relation to a file that’s been doing the rounds for about a month or two. Here is the file in question: A “receipt generator”, I hear you ask – what do people want with one of those? The answer, of course, is rather straightforward: This is a particularly interesting scam, as it doesn’t target regular PC users – it targets the people who sell you things, such as the merchants on the Amazon marketplace. This is what the would-be social engineer sees when they fire up the program: ...

Continue Reading

After More Than 24 Hours Offline, Tumblr Is Back

Published: December 7, 2010 Reading time: 1 min

Mashable: Tumblr has returned to the web after a full day’s, err, vacation. The popular blogging/reblogging platform went down yesterday afternoon during some planned maintenance; the exact reasons for the outage are unknown, but Tumblr has mentioned database cluster issues. Rumors aside, the downtime had nothing whatsoever to do with a 4chan-led DDoS attack. The official company blog states a fact of life for any successful startup: Keeping up with at-scale traffic on a startup’s budget and infrastructure is hard, hard work, “more work than our small team was prepared for,” the blog reads. ...

Continue Reading

Twitter Trend Poisoning Cookbook

Published: December 7, 2010 Reading time: 7 min

Symantec Connect: We have become familiar enough with malware creators poisoning popular search engine terms through SEO techniques in order to deliver their malicious files to a greater pool of unsuspecting users. Other popular services such as Twitter have not escaped the watchful eyes of the miscreants. This attack involves pumping out many of the same tweets with different accounts to push them into the Twitter trending list. That way more people are likely to see them even if the individual user accounts being used to send the tweets don’t have that many followers. Incidentally many of the accounts used in this attack don’t have that many followers and are quite fresh – meaning they are probably fake accounts set up specifically for the purpose of spamming tweets. ...

Continue Reading

Google Opens Doors to E-Bookstore

Published: December 7, 2010 Reading time: 7 min

The New York Time: The Google e-bookstore is finally open. Tom Turvey, head of strategic partnerships at Google, said he thought the book business should have diversity of retail points After years of planning and months of delays, the search giant Google started its e-book venture on Monday, creating a potentially robust competitor in the digital book market to Amazon, Barnes & Noble and Apple. ...

Continue Reading

WikiLeaked Cable Says 2009 Brazilian Blackout Wasn’t Hackers, Either

Published: December 7, 2010 Reading time: 4 min

Wired: SAO PAULO — Despite widespread speculation at the time, a massive power outage that left 18 out of the 26 Brazilian states in the dark for up to six hours last year was not the result of a cyber attack, according to a classified diplomatic cable published by WikiLeaks last week. The Nov. 10, 2009, blackout came just two days after the CBS News magazine 60 Minutes reported that an earlier outage in the Brazilian state of Espirito Santo in 2007 was the work of hackers. And it came just one day after Threat Level reported that, no, it wasn’t. ...

Continue Reading

FTC is considering “do not track” mechanism for web users

Published: December 6, 2010 Reading time: 2 min

The U.S. Federal Trade Commission (FTC) has accepted a preliminary staff report that lays out a framework for Internet privacy and suggests a “do not track” mechanism – possibly a persistent cookie installed on browsers. The agency was careful to point out that the commissioners see privacy measures as a balancing act. The news release quotes FTC chairman Jon Leibowitz: “Technological and business ingenuity have spawned a whole new online culture and vocabulary – email, IMs, apps and blogs – that consumers have come to expect and enjoy. The FTC wants to help ensure that the growing, changing, thriving information marketplace is built on a framework that promotes privacy, transparency, business innovation and consumer choice. We believe that’s what most Americans want as well.” ...

Continue Reading

Hackers use malware to break into computers of over 50 pop stars

Published: December 6, 2010 Reading time: 2 min

According to The Telegraph, German prosecutors are accusing two local hackers of breaking into the computers of over 50 pop stars, including Lady Gaga, Kelly Clarkson, Justin Timberlake and Ke$ha. (Wouldn’t you have to be pretty brave to blackmail Lady Gaga? She can be, um, scary. ) Ralf Haferkamp, from the Duisburg prosecutor’s office, said in an interview with Deutsche Welle that the hackers, two boys of 17 and 23 from the West of Germany, infected the machines with malware in order to steal all sorts of files. ...

Continue Reading

Stuxnet and WikiLeaks – What do they have in common?

Published: December 4, 2010 Reading time: 2 min

At first glance, two recent security stories, the Stuxnet attack on Iran’s nuclear industry and the WikiLeaks breach of US State Department communications, don’t seem to have much in common, but they do. They are united by a vector, a method of transmission and that vector is removable media. I am sure that the Iranians felt pretty secure with air-gapped systems, but like a spark from the burning house next door that finds its way into your shingles, the right USB found its way into the right PC and then suddenly all those uranium enrichment centrifuges running at 807-1210 hz started to act funny and fail in unexpected and reportedly fairly energetic ways (you can see some pics of failed centrifuges here http://web.mit.edu/charliew/www/centrifuge.html and here http://www.chem.purdue.edu/chemsafety/NewsAndStories/CentrifugeDamages.htm). ...

Continue Reading

Oficla downloads MBR Ransomware

Published: December 1, 2010 Reading time: 1 min

Avira TechBlog: We discovered a new ransomware threat which is downloaded by a Trojan of the Oficla family. This downloaded threat replaces the MBR (master boot record) of the hard disk with its own MBR which asks the user for a password and thus blocks the loading of the operating system. Upon starting the Oficla Trojan and successive execution of the downloaded payload the system will be rebooted and the user will be presented the ransom notice. ...

Continue Reading

Pirate Bay ruling sparks DDoS attacks against IFPI

Published: November 30, 2010 Reading time: 2 min

The Anonymous group takes revenge after legal decision against Pirate Bay founders v3.co.uk: An online collective known as Anonymous has carried out a distributed denial-of-service (DDoS) attack on the International Federation of the Phonographic Industry (IFPI) after the trade body welcomed the new court ruling against the founders of The Pirate Bay. The Swedish appeals court decision saw the jail terms of the men reduced but their fines increased in a move that IFPI chief executive Frances Moore argued should be the end of the debate around the issue. ...

Continue Reading

Iran: Computer Malware Sabotaged Uranium Centrifuges

Published: November 30, 2010 Reading time: 5 min

A security man stands next to an anti-aircraft gun as he scans Iran’s nuclear enrichment facility in Natanz, 300 kilometers [186 miles] south of Tehran, Iran, in April 2007. Wired: In what appears to be the first confirmation that the Stuxnet malware hit Iran’s Natanz nuclear facility, Iranian President Mahmoud Ahmadinejad said Monday that malicious computer code launched by “enemies” of the state had sabotaged centrifuges used in Iran’s nuclear-enrichment program. ...

Continue Reading

WikiLeaks Hit By Another DDoS Attack

Published: November 30, 2010 Reading time: 2 min

Controversial whistleblower website WikiLeaks was hit by another massive distributed denial of service (DDoS) attack earlier this morning. On Sunday, the site was taken down for several hours via a sustained DDoS attack, just hours before the release of thousands of secret U.S. documents. Responsibility for Sunday’s attack was claimed by a single hacker, the Jester, though many are skeptical that it was the work of just one person. Today’s attack, which was initially focused on http://cablegate.wikileaks.org/, has been much more intense. At 9:00 a.m. ET, WikiLeaks tweeted, “DDOS attack now exceeding 10 Gigabits a second.” ...

Continue Reading

Hacker Takes Responsibility for Wikileaks Takedown

Published: November 30, 2010 Reading time: 2 min

Mashable: The distributed denial of service (DDoS) attack that took down WikiLeaks as the site published secret U.S. embassy cables over the weekend could be the work of a single hacker, working for his own agenda. The hacker, called the Jester (or th3j35t3r), describes himself as a “hacktivist for good” and posts the message “TANGO DOWN” after a successful attack, together with a link of the sites he takes down. The focus of his attacks, the Jester claims in his Twitter Bio, is “obstructing the lines of communication for terrorists, sympathizers, fixers, facilitators, oppressive regimes and other general bad guys.” ...

Continue Reading

Kim Kardashian Tops Bing’s Most Popular Searches of 2010

Published: November 30, 2010 Reading time: 1 min

Mashable: Bing is getting an early start on the “best of 2010” lists, releasing its compilation of the year’s most popular search terms a little more than a month before the New Year. Reality TV star Kim Kardashian tops the list, which is dominated by celebrities; in fact, seven of the top 10 terms are people, as you can see in the list: Kim Kardashian Sandra Bullock Tiger Woods Lady Gaga Barack Obama Hairstyles Kate Gosselin Walmart Justin Bieber free Kardashian’s online dominance extends beyond searches, however. You may recall that a recent study pegged her as the celeb that gets the most traffic to their website via Twitter (despite not having the largest audience). ...

Continue Reading