New, scarier ransomware 'EternalRocks' found

May 23, 2017

San Francisco, May 23: After a host of different ransomware attacks that hit enterprises across the globe, security researchers have now identified a new strain of malware "EternalRocks" that is more dangerous than WannaCry and is potentially tougher to fight.EternalRocks

According to the researchers, "EternalRocks" exploits the same vulnerability in Windows that helped WannaCry spread to computers. It also uses a NSA tool known as "EternalBlue" for proliferation, Fortune reported on Sunday.

"...it also uses six other NSA tools, with names like EternalChampion, EternalRomance, and DoublePulsar (which is also part of WannaCry)," the report said.

In its current form, "EternalRocks" does not have any malicious elements -- it does not lock or corrupt files, or use compromised machines to build a botnet -- but leaves infected computers vulnerable to remote commands that could `weaponise` the infection at any time.

"EternalRocks" is stronger that WannaCry because it does not have any weaknesses, including the kill switch that a researcher used to help contain the ransomware.

EternalBlue also uses a 24-hour activation delay to try to frustrate efforts to study it, the report noted.

The last 10 days have seen a wave of cyber attacks that have rendered companies helpless around the globe.

First it was WannaCrypt or WannaCry that spread by taking advantage of a Windows vulnerability that Microsoft released a security patch for in March. It encrypted files on infected machines and demanded payment for unlocking them.

WannaCry had some loopholes that made it easier to slow and circumvent.

After facing a massive "WannaCrypt" ransomware attack, another type of malware quietly started generating digital cash from machines it infected.

Tens of thousands of computers were affected globally by the "Adylkuzz attack" that targeted machines, let them operate and only slowed them down to generate digital cash or "Monero" cryptocurrency in the background.

"Monero" -- being popularised by North Korea-linked hackers -- is an open-source cryptocurrency created in April 2014 that focuses on privacy, decentralisation and scalability.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
February 5,2020

San Francisco, Feb 5: After a German artist, Simon Weckert, demonstrated how he "hacked" Google Maps with 99 smartphones and a wagon to create "virtual traffic jams" on the streets of Berlin, Google responded to the incident saying it "appreciates" creative use of maps.

Admitting that it has not quite cracked travelling by wagon, the tech giant also hinted that it might use cases like this to improve how its maps work.

"We appreciate seeing creative uses of Google Maps like this as it helps us make maps work better over time," 9to5Google quoted a Google spokesperson as saying.

In a YouTube video, Weckert showed that he put 99 smartphones with Google Maps onto a small wagon cart and then wheeled that cart around various streets in Berlin, including outside the Google office, Android Authority reported on Monday.

The smartphones "apparently fooled Google Maps" into thinking that there was a high concentration of users on those streets.

Because the second-hand phones were in a cart, Maps was further tricked into believing that the traffic was slow-moving.

As a result, the navigation app started showing virtual traffic jams by turning green streets to red in the online navigational tool, showcasing how digital technology can have a real impact on the real world.

"Traffic data in Google Maps is refreshed continuously thanks to information from a variety of sources, including aggregated anonymised data from people who have location services turned on and contributions from the Google Maps community," the Google spokesperson said.

"We've launched the ability to distinguish between cars and motorcycles in several countries including India, Indonesia and Egypt, though we haven't quite cracked travelling by wagon," the statement added. After a German artist, Simon Weckert, demonstrated how he "hacked" Google Maps with 99 smartphones and a wagon to create "virtual traffic jams" on the streets of Berlin, Google responded to the incident saying it "appreciates" creative use of maps.

Admitting that it has not quite cracked travelling by wagon, the tech giant also hinted that it might use cases like this to improve how its maps work.

"We appreciate seeing creative uses of Google Maps like this as it helps us make maps work better over time," 9to5Google quoted a Google spokesperson as saying.

In a YouTube video, Weckert showed that he put 99 smartphones with Google Maps onto a small wagon cart and then wheeled that cart around various streets in Berlin, including outside the Google office, Android Authority reported on Monday.

The smartphones "apparently fooled Google Maps" into thinking that there was a high concentration of users on those streets.

Because the second-hand phones were in a cart, Maps was further tricked into believing that the traffic was slow-moving.

As a result, the navigation app started showing virtual traffic jams by turning green streets to red in the online navigational tool, showcasing how digital technology can have a real impact on the real world.

"Traffic data in Google Maps is refreshed continuously thanks to information from a variety of sources, including aggregated anonymised data from people who have location services turned on and contributions from the Google Maps community," the Google spokesperson said.

"We've launched the ability to distinguish between cars and motorcycles in several countries including India, Indonesia and Egypt, though we haven't quite cracked travelling by wagon," the statement added.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
March 15,2020

Cybercriminals continue to exploit public fear of rising coronavirus cases through malware and phishing emails in the guise of content coming from the Centers for Disease Control and Prevention (CDC) in the US and World Health Organisation (WHO), says cybersecurity firm Kaspersky.

In the APAC region, Kaspersky has detected 93 coronavirus-related malware in Bangladesh, 53 in the Philippines, 40 in China, 23 in Vietnam, 22 in India and 20 in Malaysia. 

Single-digit detections were monitored in Singapore, Japan, Indonesia, Hong Kong, Myanmar, and Thailand. 

Along with the consistent increase of 2019 coronavirus cases comes the incessant techniques cybercriminals are using to prey on public panic amidst the global epidemic, the company said in a statement. 

Kaspersky also detected emails offering products such as masks, and then the topic became more commonly used in Nigerian spam emails. Researchers also found scam emails with phishing links and malicious attachments.

One of the latest spam campaigns mimics the World Health Organisation (WHO), showing how cybercriminals recognise and are capitalising on the important role WHO has in providing trustworthy information about the coronavirus.

"We would encourage companies to be particularly vigilant at this time, and ensure employees who are working at home exercise caution. 

"Businesses should communicate clearly with workers to ensure they are aware of the risks, and do everything they can to secure remote access for those self-isolating or working from home," commented David Emm, principal security researcher.

Some malicious files are spread via email. 

For example, an Excel file distributed via email under the guise of a list of coronavirus victims allegedly sent from the World Health Organisation (WHO) was, in fact, a Trojan-Downloader, which secretly downloads and installs another malicious file. 

This second file was a Trojan-Spy designed to gather various data, including passwords, from the infected device and send it to the attacker.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
January 3,2020

Giving each and every app access to personal information stored on Android smartphones such as your contacts, call history, SMS and photos may put you in trouble as bad actors can easily use these access to spy on you, send spam messages and make calls anywhere at your expense or even sign you up for a premium "service", researchers from cybersecurity firm Kaspersky have warned.

But one can restrict access to such information as Android lets you configure app permissions. 

Giving an app any of these permissions generally means that from now on it can obtain information of this type and upload it to the Cloud without asking your explicit consent for whatever it intends to do with your data.

Therefore, security researchers recommend one should think twice before granting permissions to apps, especially if they are not needed for the app to work. 

For example, most games have no need to access your contacts or camera, messengers do not really need to know your location, and some trendy filter for the camera can probably survive without your call history, Kaspersky said. 

While decision to give permission is yours, the fewer access you hand out, the more intact your data will be.

Here's what you should know to protect your data.

SMS: An app with permission to send and receive SMS, MMS, and WAP (Wireless Application Protocol) push messages, as well as view messages in the smartphone memory will be able to read all of your SMS correspondence, including messages with one-time codes for online banking and confirming transactions.

Using this permission, the app can also send spam messages in your name (and at your expense) to all your friends. Or sign you up for a premium "service." You can see and conrol which apps have these rights by going to the settings of your phone.

Calendar: With permission to view, delete, modify, and add events in the calendar, prying eyes can find out what you have done and what you are doing today and in the future. Spyware loves this permission.

Camera: Permission to access the camera is necessary for the app to take photos and record video. But apps with this permission can take a photo or record a video at any moment and without warning. Attackers armed with embarrassing images and other dirt on you can make life a misery, according to Kaspersky.

Contacts: With permission to read, change, and add contacts in your address book, and access the list of accounts registered in the smartphone, an app can send your entire address book to its server. Even legitimate services have been found to abuse this permission, never mind scammers and spammers, for whom it is a windfall.

This permission also grants access to the list of app accounts on the device, including Google, Facebook, and many other services.

Phone: Giving access to your phone means permission to view and modify call history, obtain your phone number, cellular network data, and the status of outgoing calls, add voicemail, access IP telephony services, view numbers being called with the ability to end the call or redirect it to another number and call any number.

This permission basically lets the app do anything it likes with voice communication. It can find out who you called and when or prevent you from making calls (to a particular number or in general) by constantly terminating calls. 

It can eavesdrop on your conversations or, of course, make calls anywhere at your expense, including to pay-through-the-nose numbers, Kaspersky warned.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.