Malware - Infoworld http://www.infoworld.com/t/2111 en Citadel banking malware is evolving and spreading rapidly, researchers warn http://www.infoworld.com/d/security/citadel-banking-malware-evolving-and-spreading-rapidly-researchers-warn-186083?source=rss_malware <!--paging_filter--><p>A computer Trojan that targets online banking users is evolving and spreading rapidly because its creators have adopted an open source development model, according to researchers from cyber threat management firm Seculert.</p> <p>Called Citadel, the new piece of malware is based on ZeuS, one of the oldest and most popular online banking Trojans. ZeuS was abandoned by its creator in late 2010, and its source code leaked online a few months later.</p> Security Malware Thu, 09 Feb 2012 16:06:49 +0000 admin 186083 at http://www.infoworld.com Spammers impersonate well-known developers to publish rogue apps on Android Market http://www.infoworld.com/d/security/spammers-impersonate-well-known-developers-publish-rogue-apps-android-market-186021?source=rss_malware <!--paging_filter--><p>Spammers are impersonating well-known Android software developers in order to distribute rogue apps through the official Android Market.</p> <p>Security researchers from antivirus firm Trend Micro <a href="http://blog.trendmicro.com/trending-scams-seen-in-the-android-market/" target="_blank">have identified</a> a developer named Rovio MobiIe Ltd. in the Android Market, which had a significant number of rogue applications in its portfolio.</p> Mobile Technology Security Android Mobile Apps Malware Wed, 08 Feb 2012 22:04:16 +0000 admin 186021 at http://www.infoworld.com Facebook malware scam takes hold http://www.infoworld.com/d/security/facebook-malware-scam-takes-hold-185739?source=rss_malware <!--paging_filter--><p>A "worrying number" of Facebook users are sharing a link to a malware-laden fake CNN news page reporting the U.S. has attacked Iran and Saudi Arabia, <a href="http://nakedsecurity.sophos.com/2012/02/03/us-attacks-iran-and-saudi-arabia-malware-spreads-via-facebook-status-updates/">security firm Sophos said Friday</a>.</p> Security Facebook Malware Social Networking Sat, 04 Feb 2012 00:05:44 +0000 admin 185739 at http://www.infoworld.com Symantec warns of Android Trojans that mutate with every download http://www.infoworld.com/d/security/symantec-warns-of-android-trojans-mutate-every-download-185664?source=rss_malware <!--paging_filter--><p>Researchers from security vendor Symantec <a href="http://www.symantec.com/connect/blogs/server-side-polymorphic-android-applications" target="_blank">have identified</a> a new premium-rate SMS Android Trojan horse that modifies its code every time it gets downloaded in order to bypass antivirus detection.</p> <p>This technique is known as server-side polymorphism and has already existed in the world of desktop malware for many years, but mobile malware creators have only now begun to adopt it.</p> Mobile Technology Security Android Mobile Apps Mobile Security Malware Fri, 03 Feb 2012 12:31:43 +0000 admin 185664 at http://www.infoworld.com Google finally scans malware-ridden Android Market http://www.infoworld.com/d/security/google-finally-scans-malware-ridden-android-market-185654?source=rss_malware <!--paging_filter--><p>In an effort to improve security in its Android Market, Google has been using a service providing automated scanning of applications submitted to the mobile application store, Google revealed on Thursday afternoon.</p> <p>Code-named Bouncer, the service scans the market for potentially malicious software without disrupting the user experience or requiring developers to submit to an application approval process, said <a href="http://googlemobile.blogspot.com/2012/02/android-and-security.html" target="_blank">Hiroshi Lockheimer, vice of engineering for Android, in a blog post</a>:</p> Mobile Technology Security Android Mobile Security Malware Fri, 03 Feb 2012 11:00:00 +0000 Paul Krill 185654 at http://www.infoworld.com Business is booming for 'malware as a service' merchants http://www.infoworld.com/d/security/business-booming-malware-service-merchants-185503?source=rss_malware <!--paging_filter--><p>They are well organized. They pay close attention to product quality, working hard to make it effective and scalable. They are all about customer service, providing after-sales support. They even solicit the help of their customers in product development.</p> <p>All admirable qualities. But <a href="http://www.csoonline.com/topic/43404/identity-theft-prevention" target="_blank">all in the service of theft</a>.</p> Security Anti-virus Cyber Crime Data Loss Prevention Malware Wed, 01 Feb 2012 17:22:32 +0000 admin 185503 at http://www.infoworld.com Hackers infect WordPress 3.2.1 blogs to distribute TDSS rootkit http://www.infoworld.com/d/security/hackers-infect-wordpress-321-blogs-distribute-tdss-rootkit-185370?source=rss_malware <!--paging_filter--><p>Hackers are compromising WordPress 3.2.1 blogs in order to infect their visitors with the notorious TDSS rootkit, according to researchers from Web security firm Websense.</p> <p>It's not clear how the websites are being compromised, but there are publicly known exploits for vulnerabilities that affect WordPress 3.2.1, which is an older version of the popular blog publishing platform.</p> Security Internet Hacking Malware Tue, 31 Jan 2012 15:30:40 +0000 admin 185370 at http://www.infoworld.com Update: Industry group pushes new spec to eliminate phishing http://www.infoworld.com/d/security/industry-group-pushes-new-spec-eliminate-phishing-185255?source=rss_malware <!--paging_filter--><p>Companies such as Facebook, Google, and PayPal are pushing for widespread use of a new technical specification, DMARC, that could make it harder for phishers to reach their victims.</p> Security Malware Phishing Mon, 30 Jan 2012 14:02:06 +0000 admin 185255 at http://www.infoworld.com Drive-by-download attack exploits critical vulnerability in Windows Media Player http://www.infoworld.com/d/security/drive-download-attack-exploits-critical-vulnerability-in-windows-media-player-185185?source=rss_malware <!--paging_filter--><p>Security researchers from antivirus vendor Trend Micro have come across a Web-based attack that exploits a known vulnerability in Windows Media Player.</p> <p>"Earlier today, we encountered a malware that exploits a recently (and publicly) disclosed vulnerability, the MIDI Remote Code Execution Vulnerability (CVE-2012-0003)," Trend Micro threat response engineer Roland Dela Paz said in a <a href="http://blog.trendmicro.com/malware-leveraging-midi-remote-code-execution-vulnerability-found/" target="_blank">blog post</a> on Thursday.</p> Microsoft Windows Security Microsoft Application Security Malware Patch Management Fri, 27 Jan 2012 17:36:16 +0000 admin 185185 at http://www.infoworld.com Goal of new security service: More involvement from ISPs, carriers http://www.infoworld.com/d/security/goal-of-new-security-service-more-involvement-isps-carriers-185004?source=rss_malware <!--paging_filter--><p>There's a war underway throughout our networks, with <a href="http://www.csoonline.com/article/608663/krebs-fcc-must-make-isps-crack-down-on-spammers-and-malware" target="_blank">carriers and ISPs in the thick of it</a>. But for fear of network disruptions or increased cost of service, many ISPs and carriers have shied away from securing the traffic that flows through their wires.</p> Security Data Loss Prevention Mobile Security Malware Network Security Vulnerability Assessment Wed, 25 Jan 2012 17:29:22 +0000 admin 185004 at http://www.infoworld.com 2011: The year Mac malware got interesting http://www.infoworld.com/t/malware/2011-the-year-mac-malware-got-interesting-184927?source=rss_malware <!--paging_filter--><div style="padding: 8px; background: none no-repeat scroll center top #ffffff; position: relative; float: right; width: 243px; height: 182px;"><img src="http://www.infoworld.com/sites/infoworld.com/files/media/image/Apple_Security_hp.jpg" alt="2011: The year Mac malware got interesting" width="243" height="182" align="right" /></div> <p>For years, security professionals have argued that Mac OS X is just as prone to digital attack as the latest Windows system. Yet, Mac users have felt safer because, let's face it, few attackers focus on Macs.</p> Security Mac OS X Anti-virus Malware Social Engineering Tue, 24 Jan 2012 21:37:38 +0000 InfoWorld Tech Watch 184927 at http://www.infoworld.com Twitter acquires antimalware company Dasient http://www.infoworld.com/d/the-industry-standard/twitter-acquires-antimalware-company-dasient-184855?source=rss_malware <!--paging_filter--><p>Twitter has acquired Internet security firm Dasient, the Sunnyvale, California startup said on its blog on Monday.</p> <p>Dasient, which describes itself as a cloud-based Web antimalware technology company, introduced in 2010 a service to protect advertisement networks and publishers from malicious ads.</p> Applications Security The Industry Standard Twitter M&A Malware Social Networking Tue, 24 Jan 2012 12:11:41 +0000 admin 184855 at http://www.infoworld.com Researchers expose flaws in popular industrial control systems http://www.infoworld.com/d/security/researchers-expose-flaws-in-popular-industrial-control-systems-184629?source=rss_malware <!--paging_filter--><p>Researchers showcased unpatched security flaws in software used to control critical industrial systems by oil, gas, water, and electrical distribution plants at the 2012 SCADA Security Scientific Symposium (S4) on Thursday.</p> <p>The vulnerabilities ranged from information disclosure and privilege escalation bugs to remote denial-of-service (DoS) and arbitrary code execution flaws.</p> Security Hacking Malware Vulnerability Assessment Fri, 20 Jan 2012 16:13:07 +0000 admin 184629 at http://www.infoworld.com Smarter hypervisor use can lead to a 'big, big change' in security http://www.infoworld.com/d/cloud-computing/smarter-hypervisor-use-can-lead-big-big-change-in-security-184525?source=rss_malware <!--paging_filter--><p>To gain insight on the months ahead as they relate to IT attacks, <a href="http://www.csoonline.com/topic/43400/malware-cybercrime">malware</a>, cloud security, and the <a href="http://www.csoonline.com/podcast/457065/why-virtualization-security-is-such-a-mess">impact of virtualization on security</a>, we recently chatted with Simon Crosby, former CTO of Citrix Systems' data center and cloud business.</p> Cloud Computing Data Center Security Virtualization Cloud Security Virtual Desktop Malware Thu, 19 Jan 2012 16:19:08 +0000 admin 184525 at http://www.infoworld.com McAfee to patch spam relay problem in cloud product http://www.infoworld.com/d/security/mcafee-patch-spam-relay-problem-in-cloud-product-184515?source=rss_malware <!--paging_filter--><p>McAfee expects to patch by Thursday two problems with its SaaS Total Protection antimalware service, one of which lets an attacker use a computer as a spam relay.</p> <p>SaaS Total Protection is a hosted security service from Intel-owned McAfee. Clients sign up for the service, which provides features such as a firewall, antivirus scans and antispam services that run in McAfee's data centers.</p> Cloud Computing Security McAfee Anti-spam SaaS Malware Patch Management Thu, 19 Jan 2012 13:41:55 +0000 admin 184515 at http://www.infoworld.com Sykipot Trojan hijacks Department of Defense authentication smart cards http://www.infoworld.com/d/security/sykipot-trojan-hijacks-department-defense-authentication-smart-cards-184077?source=rss_malware <!--paging_filter--><p>A variant of the Sykipot Trojan Horse hijacks U.S. Department of Defense (DoD) smart cards in order to access restricted resources.</p> Security E-government Authentication Endpoint Protection Intrusion Detection Malware Vulnerability Assessment Fri, 13 Jan 2012 14:00:21 +0000 admin 184077 at http://www.infoworld.com Microsoft planning real-time feed of valuable threat data http://www.infoworld.com/d/security/microsoft-planning-real-time-feed-valuable-threat-data-184022?source=rss_malware <!--paging_filter--><p>Microsoft has had a great deal of <a href="http://www.pcworld.com/businesscenter/article/190269/microsoft_uses_legal_system_to_combat_botnet.html" target="_blank">success taking down botnets</a> in recent years. A fringe benefit of those takedowns is that Microsoft gets to collect oodles of very valuable data. Now, Microsoft is preparing to offer that threat intelligence as a real-time feed that partners can use to evaluate threats and develop better defenses.</p> Security Malware Fri, 13 Jan 2012 11:00:00 +0000 admin 184022 at http://www.infoworld.com Public attack code aimed at Windows Web servers works, says Symantec http://www.infoworld.com/d/security/public-attack-code-aimed-windows-web-servers-works-says-symantec-183885?source=rss_malware <!--paging_filter--><p>Researchers at Symantec yesterday confirmed that working attack code published Jan. 6 can cripple Web servers running Microsoft's ASP .Net.</p> <p>The proof-of-concept exploit was published last Friday on GitHub, a site that hosts software projects, and has been used in the past by hackers to distribute their work.</p> Microsoft Windows Security Microsoft Windows Malware Wed, 11 Jan 2012 22:16:29 +0000 admin 183885 at http://www.infoworld.com Carrier IQ detection tool converted to premium SMS Trojan http://www.infoworld.com/d/security/carrier-iq-detection-tool-converted-premium-sms-trojan-183864?source=rss_malware <!--paging_filter--><p>Android malware writers are taking advantage of the controversy surrounding Carrier IQ's smartphone tracking software in order to distribute a premium SMS Trojan, security researchers from Symantec warn.</p> <p>"Android.Qicsomos is a modified version of an open source project meant to detect Carrier IQ on a device, with additional code to dial a premium SMS number," said Symantec malware analyst Irfan Asrar in a <a href="http://www.symantec.com/connect/blogs/day-after-year-mobile-malware" target="_blank">blog post</a> on Tuesday.</p> Mobile Technology Security Mobile Apps Malware Wed, 11 Jan 2012 16:42:54 +0000 admin 183864 at http://www.infoworld.com Symantec investigates possible leak of Norton AntiVirus source code http://www.infoworld.com/d/the-industry-standard/symantec-investigates-possible-leak-norton-antivirus-source-code-183345?source=rss_malware <!--paging_filter--><p>Symantec is investigating claims by a group of hackers that they are in possession of source code for its Norton AntiVirus product.</p> <p>The group, which uses the name "The Lords of Dharmaraja," claims to have stolen Symantec source code and documentation from the servers of Indian intelligence agencies, along with intellectual property from other software companies that have contracts with the Indian government.</p> Security The Industry Standard Symantec Anti-virus Intellectual Property Malware Thu, 05 Jan 2012 22:58:40 +0000 admin 183345 at http://www.infoworld.com