Tag: malware

  • Paper: VBA is not dead!

    Gabor Szappanos looks at the resurgence of malicious VBA macros that use social engineering to activate. Macro malware had long been assumed dead. After all, macros are disabled by default in modern versions of Microsoft Office , which means they do not automatically execute upon opening a file. However, macro malware has recently made a…

  • NCA issues alert on CryptoLocker ransomware

    Malware demands $1,000 ransom to decrypt files. This weekend, the UK’s National Crime Agency (NCA) issued an alert about the ‘CryptoLocker’ ransomware – following a similar alert from US-CERT 10 days earlier. CryptoLocker is a particularly nasty piece of malware. Once it has infected a machine, it searches for files of any of 70-odd formats,…

  • Open letter asks AV companies for openness on surveillance malware

    Old issue has become hot topic again following Snowden revelations. A group of experts in privacy and digital rights has sent an open letter ( pdf ) to a number of anti-virus companies, asking them to be clear about their detection of government surveillance software both in the past and in future cases. The experts,…

  • Thousands of websites affected by nameserver hijack redirecting visitors to malware

    DNS caching causes attack to have a long tail. Yesterday, visitors to thousands of Dutch websites were served an ‘under construction’ page that, through a hidden iframe, was serving the Blackhole exploit kit. The sites were hosted by three hosting companies that share both a parent company and, more importantly in this case, nameservers for…

  • Compromised Yahoo! accounts continue to spread Android malware

    Problem likely to be on Yahoo!’s side. In recent weeks, we have noticed an uptick in the amount of spam sent from compromised Yahoo! accounts; we have reasons to believe the problems are on Yahoo! ‘s side, rather than that of its users’. Spam sent from compromised accounts is notoriously hard to filter: the sender…

  • AV Test releases Android test data

    30 mobile solutions tested for malware protection and speed hit. Independent test organization AV-Test has released its latest report, covering the Andriod platform. This major test of mobile solutions included 30 contenders, with offerings of varying complexity. As well as rating malware detection, false alarms and performance, extra points were given for including additional security…

  • India believed to be source of sophisticated surveillance campaigns

    In-depth investigations find widespread worldwide snooping, Pakistan primary target. Several reports have emerged recently covering a highly organised campaign of targeted espionage malware that has been seen in many countries around the world and stealing data from many industries. Close investigation has provided strong hints that the campaign originated in India, with Pakistan the most…

  • Commoditization increasingly seen in mobile malware

    Number of malicious samples and families increase, as Android remains most popular mobile platform. As the number of mobile malware samples in existence continues to grow faster than ever, the mobile threat landscape is looking more and more like that of Windows . Five years ago, a poll of visitors to this website found that…

  • Program turns anti-analysis tools against the malware

    Users cautioned to be wary of a false sense of security. Could you defeat VM-aware malware by making your system aware of VM-aware malware? Tricks to frustrate researchers and make automatic analysis more difficult are a common feature of today’s malware. One such trick is to make the malware ‘VM-aware’: it won’t run if it…

  • Flame worm one of the most complex threats ever discovered

    Malware possibly used for cyber-espionage. The jury is out on whether ‘Flame’ (also known as ‘Flamer’ or ‘Skywiper’) is ‘the most lethal cyberweapon to date’ as some have claimed , or just a highly complex and sophisticated piece of malware. But simply from looking at the volume of security vendors’ blog posts dedicated to the…