Showing posts with label duqu. Show all posts
Showing posts with label duqu. Show all posts

30 May 2012

2012 Threat Predictions: A Report by McAfee Labs


In the past few months we have witnessed enormous changes in cyber threats like mobile related threats, hacktivism, client-side exploitation, social-media exploitation, and targeted attacks.

As per 2012 Threat Predictions report by McAfee Labs,  more changes are expected in coming year in even the most established threat vectors as follow:
  • Industrial threats will mature and segment
  • Embedded hardware attacks will widen and deepen
  • Hacktivism and Anonymous will reboot and evolve
  • Virtual currency systems will experience broader and more frequent attacks
  • This will be the “Year for (not “of”) Cyberwar”
  • DNSSEC will drive new network threat vectors
  • Traditional spam will go “legit,” while spearphishing will evolve into the targeted messaging attack
  • Mobile botnets and rootkits will mature and converge
  • Rogue certificates and rogue certificate authorities will undermine users’ confidence
  • Advances in operating systems and security will drive next-generation botnets and rootkits

This report has also mentioned that "It’s time for extensive Penetration Testing and Emergency Response Planning that includes cyber components and networking with law enforcement at all levels."

2012 Threat Predictions report by McAfee Labs can be downloaded from here: http://www.mcafee.com/us/resources/reports/rp-threat-predictions-2012.pdf?eid=NAMWPGSCSC011

Solutions : www.xcyss.in

29 May 2012

Flame could be the most powerful virus ever


With cyber crime spreading across the globe, Russian security firm Kaspersky Lab, has just uncovered a massive cyber attack codenamed ‘Flame.’ The malicious program was detected as Worm.Win32.Flame and is believed to have been operational since 2010.........

On infecting a system, Flame begins with its set of complex operations, which is inclusive of sniffing the network traffic, taking screenshots, recording audio conversations, intercepting the keyboard, and even monitoring the display. The information is then sent to a network of command-and-control servers located in many different parts of the world.The first instance of the malware's activities was detected in Iran and the other countries affected by it are Israel, Sudan, Syria, Lebanon, Saudi Arabia and Egypt........

Flame is said to be the most advanced and complete attack-toolkits ever discovered. It has hit more than 600 targets ranging from individuals to businesses and government systems.............

Earlier we saw the Stuxnet computer virus that wreaked havoc on Iran's nuclear program and later the country detected the Duqu computer virus, which claimed to be based on Stuxnet. However, the new malware code is said to be 20 times larger than Stuxnet and the Flame package of modules is reportedly huge at 20 MB when completely deployed....................


Click here to read more ....
Solutions : www.xcyss.in

13 November 2011

SURWARE DuQu - a handiwork of Wednesday's Gang

Aleks of Kaspersky Lab Expert has Posted November 11, 12:09  GMT

The Duqu Saga Continues: Enter Mr. B. Jason and TV’s Dexter

Kaspersky Lab in hot chase of DUQU and in close coordination with Sudanese CERT has reveled new facts about this game changing SURVEILLANCE MALWARE (This family of malware , I like to call SURWARE pronounces similar to 'surveyor'). 

Kaspersky lab  found three ~DQ-type files, created on May 25, June 29 and August 24, all three dates were Wednesdays. This could be just a coincidence, maybe not. Still, based on this ‘coincidence’ Kaspersky Lab preferred to name the group behind Duqu as the Wednesday’s Gang :)


The report brings many new facets of this Surware which can be read at http://www.securelist.com/en/blog/208193243/The_Duqu_Saga_Continues_Enter_Mr_B_Jason_and_TVs_Dexter

Some of the key findings of the report are :


- For every victim, a separate set of attack files was created;
- Each unique set of files used a separate control server;
- The attacks were conducted via e-mails with a .DOC file attached;
- The mail-outs took place from anonymous mailboxes, probably via compromised computers;
- At least one e-mail address is known from which the mail-outs were conducted -bjason1xxxx@xxxx.com;
- For each victim, a separate DOC file was put together;
- The vulnerability exploit was contained in the font called “Dexter Regular”;
- The attackers changed the shellcode, and varied the range of dates for possible infection;
- After penetration into a system the attackers installed extra modules and infected neighboring computers;
- The presence on the systems of the files ~DF.tmp and ~DQ.tmp unambiguously points to an infection by Duqu.





Solutions : www.xcyss.in