New malware steals users' money through mobile phones: Report

Agencies
September 10, 2017

New Delhi, Sep 10: A new malware Xafecopy Trojan has been detected in India which steals money through victims' mobile phones, cyber security firm Kaspersky said in a report.

Around 40 per cent of target of the malware has been detected in India.

"Kaspersky Lab experts have uncovered a mobile malware targeting the WAP billing payment method, stealing money through victims' mobile accounts without their knowledge," the report said.

Xafecopy Trojan is disguised as useful apps like BatteryMaster, and operates normally. The trojan secretly loads malicious code onto the device.

Once the app is activated, the Xafecopy malware clicks on web pages with Wireless Application Protocol (WAP) billing - a form of mobile payment that charges costs directly to the user's mobile phone bill. After this the malware silently subscribes the phone to a number of services, the report said.

The process also does not require user to register a debit or credit card or set up a user-name and password.

The malware uses technology to bypass 'captcha' systems designed to protect users by confirming the action is being performed by a human. In the captcha system, websites show a set of some letter or numbers which are required to be manually filled by the user.

"Xafecopy hit more than 4,800 users in 47 countries within the space of a month, with 37.5 per cent of the attacks detected and blocked by Kaspersky Lab products targeting India, followed by Russia, Turkey and Mexico," the report said.

Experts at Kaspersky Lab have found traces showing that cyber criminals gang promulgating other trojans are sharing malware code among themselves.

"Our research suggests WAP billing attacks are on the rise. Xafecopy's attacks targeted countries where this payment method is popular. The malware has also been detected with different modifications, such as the ability to text messages from a mobile device to premium-rate phone numbers, and to delete incoming text messages to hide alerts from mobile network operators about stolen money," Kaspersky Lab Senior Malware Analyst Roman Unuchek said.

Kaspersky Lab, Managing Director- South Asia, Altaf Halde said that Android users need to be extremely cautious in how they download apps.

"It is best not to trust third-party apps, and whatever apps users do download should be scanned locally with the Verify Apps utility. But beyond that, Android users should be running a mobile security suite on their devices.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
July 19,2020

New Delhi, Jul 19: Indian equities will be driven by a host of factors like corporate earnings, coronavirus cases trend and geo-political developments this week, according to analysts.

Market participants will also keenly watch the progress of monsoon, with experts saying that the farm sector revival will play a key role in lifting the coronavirus-hit economy.

"With no major event, the ongoing earnings season and global cues will continue to dictate the market trend. Besides, the progress of monsoon will also be closely watched," Ajit Mishra, VP - Research, Religare Broking, said.

Globally, the rising coronavirus infections and geo-political tensions have created uncertainty on the economic recovery front.

With India's COVID-19 cases fast approaching the 11 lakh mark, the third-highest behind the US and Brazil, and the death toll nearing 27,000, participants are expected to tread cautiously going forward.

At global level, confirmed COVID-19 cases have crossed 1.4 crore and deaths totalled about 6 lakh.

Markets globally will closely follow developments on the trade and political level between the US and China, according to analysts.

"We would continue witnessing stock-specific action as the earnings season unfold. Though the near-term momentum looks positive, we would advise traders to be cautious, given flaring US-China trade relations, persistent rise in virus cases and implementation of fresh lockdowns in parts of the country," said Siddhartha Khemka, Head - Retail Research, Motilal Oswal Financial Services Ltd.

HDFC Bank will remain in focus on Monday after having announced its June quarter earnings on Saturday.

The lender reported 19.6 per cent rise in its standalone net profit at Rs 6,658.62 crore for April-June 2020; while its income rose to Rs 34,453.28 crore during the quarter.

Other major companies to announce their quarterly results this week are Axis Bank, Bajaj Finance, Hindustan Unilever Limited, Bajaj Auto and ITC.

"Going ahead market participants will closely track the development related to covid vaccine, the rising infection of coronavirus, development on economic activities, corporate earnings and US-China relationship," said Sumeet Bagadia, Executive Director, Choice Broking.

On weekly basis, the Sensex gathered 425.81 points or 1.16 per cent, and the Nifty gained 133.65 points or 1.24 per cent.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
July 18,2020

New Delhi, Jul 18: India's national cybersecurity agency CERT-in, has warned people of credit card skimming spreading across the world through e-commerce platforms.

Attackers are typically targeting e-commerce sites because of their wide presence, popularity and the environment LAMP (Linux, Apache, MySQL, and PHP), the Computer Emergency Response Team (CERT-In) said in a notice on Thursday.

Recently, attackers targeted sites which were hosted on Microsoft's IIS server running with the ASP.NET web application framework, it said.

Some of the sites affected by the attack were found to be running ASP.NET version 4.0.30319, which is no longer officially supported by Microsoft and may contain multiple vulnerabilities, CERT-In said.

The notice also included a list of best practices for website developers including the use of the latest version of ASP.NET web framework, IIS web server and database server.

The advisory is based on research by Malwarebytes which found that this skimming campaign likely began sometime in April this year.

Credit card skimming has become a popular activity for cybercriminals over the past few years, and the increase in online shopping during the pandemic means additional business for them, too, Malwarebytes said in a blog post, adding that attackers do not need to limit themselves to the most popular e-commerce platforms.

Researchers from global cybersecurity and anti-virus brand Kaspersky had warned in December last year that more cybercriminal groups will target online payment processing systems in 2020. 

It said that over the past couple of years, so-called JS-skimming (the method of stealing of payment card data from online stores), has gained immense popularity among attackers. 

Kaspersky researchers in their report said they are currently aware of at least 10 different actors involved in these type of attacks.

Their number will continue to grow during the next year, the report said, adding that the most dangerous attacks will be on companies that provide services such as e-commerce as-a-service, which will lead to the compromise of thousands of companies.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
March 25,2020

In an unprecedented crisis despite Prime Minister Narendra Modi assuring the continuation of essential services like food and groceries, online marketplaces like Flipkart and Amazon along with delivery platforms like Bigbasket, Grofers and FreshToHomes hit a major blockade on Wednesday as local authorities shut warehouses and sent delivery boys back, even harassed them.

Millions of people across cities were left helpless at homes as essential items like fruits and vegetables, dairy and milk, meat and fish etc did not reach their doors despite placing orders well in advance. Later, the orders went dry.

While Grofers' warehouse in Faridabad was closed by the local law enforcement agencies, Bigbasket complained that the police stopped its delivery partners and "some of them were even beaten up by for no fault of theirs".

"We are not operational due to restrictions imposed by local authorities on movement of goods in spite of clear guidelines provided by central authorities to enable essential services. We are working with the authorities to be back soon,' Bigbasket tweeted.

In a statement to IANS, Bigbasket said that it will help to have better coordination between the Centre and state, and between the state and local police to "ensure that our delivery vans and bikes don't get stopped by the police. Bigbasket and bb daily are not taking new orders".

Furious people stormed the social media platforms, writing their plight to NITI Aayog CEO Amitabh Kant on Twitter.

"Sir, all e-commerce are down. Believe me I tried everything (Grofers, Bigbasket, Flipkart, Amazon, Big Bazaar), no delivery till 31st March or Server Down or No Service. Need to think how we can enable them through digital India," tweeted one user.

Kant tweeted back to Bigbasket: "They should give me specifics - State & location. I will act on it by getting in touch with concerned authorities & sorting it out. Govt guidelines exempt them. We will ensure that citizens are not impacted".

Kant also responded to Grofers: "Cold storages & Warehouses as well as delivery of all essentials goods including food, pharma thru E-Commerce are exempted under MHA order. I have spoken to CS & DGP, Haryana . They have taken immediate action to ensure that supply chains efficiently function for the citizens".

The subscription-based hyperlocal delivery startup FreshToHome sent messages to its customers, saying that despite the government declaring food delivery as essential, "we are facing hardships in continuing our operations".

"Please bear with us as we are working hard to unblock local authority hurdles," said the FreshToHome team.

Reports later surfaced that the Department for Promotion of Industry and Internal Trade (DPIIT) has initiated talks with the state Chief Secretaries asking them not to restrict movement of people engaged in home delivery of essential items, mentioned in the list of exempted items circulated by the Home Ministry.

Meanwhile, Flipkart said it has temporarily suspended its operations and services - including grocery items. The marketplace has decided to halt all orders from March 25 for all three supply chains -- groceries, non-large goods and large items.

"Flipkart has temporarily suspended orders as we assess the possibilities of operating in the lockdown. We are prioritising the safety of our delivery executives and seeking the support of the local governments and police authorities to meet the needs of our customers as they stay home during this lockdown," Rajneesh Kumar, Chief Corporate Affairs Officer, Flipkart, said in a statement.

E-commerce giant Amazon said the company has to "temporarily stop taking orders and disable shipments for lower-priority products.

"For all pending customer orders on lower-priority products, we are reaching out to customers and giving them a choice to cancel their orders, and receive a refund for prepaid items," said the company.

Witnessing a surge in demand, supermarket chain Biz Bazaar entered the fray, with launching doorstep delivery services in major cities like Delhi, Mumbai, Bengaluru and Gurugram.

However, within no time, Big Bazaar was flooded with calls, forcing the company to issue a statement, saying that "In light of the recent announcement, we are receiving an unprecedented number of requests for doorstep delivery. There could be a delay due to the restrictions on movements".

Already battling massive surge in demand, the online delivery platforms faced other issues too, including zero access to several high-rises across the country which have gone under complete lockdown with all entry and exit gates locked.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.