23.3.16

New self-protecting USB trojan able to avoid detection


By Tomáš Gardoň posted 23 Mar 2016 - 02:49PM
A unique data-stealing trojan has been spotted on USB devices in the wild – and it is different from typical data-stealing malware. Each instance of this trojan relies on the particular USB device on which it is installed and it leaves no evidence on the compromised system. Moreover, it uses a very special mechanism to protect itself from being reproduced or copied, which makes it even harder to detect.
In this article we will examine the technical details of this interesting malware.
”What really sets this malware apart is its self-protection mechanism.”
Where other malware uses ‘good old-fashioned approaches’ like Autorun files or crafted shortcuts in order to get users to run it, USB Thief uses also another technique. This method depends on the increasingly common practice of storing portable versions of popular applications such as Firefox, NotePad++ and TrueCrypt on USB drives.
The malware takes advantage of this trend by inserting itself into the command chain of such applications, in the form of a plugin or a dynamically linked library (DLL). And therefore, whenever such an application is executed, the malware will also be run in the background.
What really sets this malware apart, however, is its self-protection mechanism.
The protection mechanism
The malware consists of six files. Four of them are executables and the other two contain configuration data. To protect itself from copying or reverse engineering, the malware uses two techniques. Firstly, some of the individual files are AES128-encrypted; secondly, their filenames are generated from cryptographic elements.
The AES encryption key is computed from the unique USB device ID, and certain disk properties of the USB drive hosting the malware. Hence, the malware can only run successfully from that particular USB device.
The name of the next file in malware execution chain is based on actual file content and its creation time. It is the first five bytes of SHA512 hash computed from mentioned attributes (file content concatenated with eight bytes of the creation time).
Because of this, filenames are different for every instance of this malware. Moreover, copying malware to a different place will replace the file creation time so that malicious actions associated with the previous locality cannot be reproduced. For a better understanding of the naming technique, please see the image below.
It was quite challenging to analyze this malware because we had no access to any malicious USB device. Moreover, we had no dropper, so we could not create a suitably afflicted USB drive under controlled conditions for further analysis.
Only the submitted files can be analyzed, so the unique device ID had to be brute-forced and combined with common USB disk properties. Moreover, after successful decryption of the malware files, we had to find out the right order of the executables and configuration files, because the file copying process to get the samples to us had changed the file creation timestamp on the samples.

The execution flow of malware is quite simple. Each loader, in turn, loads and executes the following loader identified by computed hash according to the naming technique described above. However the execution must always start with the first stage loader, otherwise the malware terminates itself.

21.3.16

Tech Giants to Boost Encryption


Some of the most prominent names in tech are pursuing the development of much tougher encryption technologies, it has been revealed.

According to the Guardian, Google, Facebook and Snapchat are reportedly bolstering their respective encryption services, which they have been doing for some time now.
The newspaper said that these security initiatives preempt the latest highly publicized legal battle between Apple and the US Department of Justice.
This particular case, which centers on the FBI wanting access to an iPhone belonging to one of the two attackers in December’s San Bernardino shooting, has become “the battleground” in the privacy versus security debate.

Breaking the news, the Guardian’s technology reporter, Danny Yadron, said that these “projects could antagonize authorities just as much as Apple’s more secure iPhone”.
“The efforts come at a crossroads for Silicon Valley.”
“The efforts come at a crossroads for Silicon Valley. Google, Facebook, Snapchat, Amazon, Microsoft and Twitter have all signed on to legal briefs supporting Apple in its court case,” he went on to say.
“At the same time, some of the companies have shown an increased willingness to help the government in its efforts to fight the spread of Islamic extremist propaganda online – often using their services.”
In his exclusive, Mr. Yadron stated that there is renewed internal interest in Google’s End to End project; while Facebook is boosting WhatsApp’s security so that encryption covers voice calls. Meanwhile, Snapchat is said to be developing a “secure messaging system”.

It is increasingly evident that when it comes to encryption, neither tech companies nor governments and law enforcement bodies are willing to back down over key areas.
Apple, for example, remains committed to encryption in its purest sense, stating that the introduction of any kind of backdoor compromises its integrity.
“There have been people that suggest that we should have a backdoor,” Apple’s CEO Tim Cook said at the end of 2015.
“But the reality is if you put a backdoor in, that backdoor’s for everybody, for good guys and bad guys.”

20.3.16

FBI warn that automobiles are vulnerable to cyberattacks

The Federal Bureau of Investigation (FBI) has issued a public service announcement warning drivers that automobiles are “increasingly vulnerable” to cyberattacks.

The announcement, which was made in partnership with the Department of Transportation and the National Highway Traffic and Safety Administration, cites a study from August 2015 in which researchers identified vulnerabilities in a radio module of a MY2014 passenger vehicle.
In the study, the researchers found that they were able to manipulate door locks, turn signals and even disable brakes when the car was travelling at slow speeds.
They were also able to modify vehicle functions by hacking the electrical control units in the car. These ECUs control various vehicle functions including steering, braking and acceleration, as well as windshield wipers and headlights.

“While the identified vulnerabilities have been addressed, it is important that consumers and manufacturers are aware of the possible threats and how an attacker may seek to remotely exploit vulnerabilities in the future,” the FBI said.
The bureau also warned that in addition to vehicles being attacked through their ECUs, vulnerabilities also exist in mobile devices – such as a cellular phone or tablet connected to the vehicle via USB, Bluetooth or Wi-Fi, or within a third-party device connected through a vehicle diagnostic port. 
This announcement comes eight months after a group of security researchers successfully shut down a Jeep Cherokee travelling at 70mph by hacking into its controls, prompting a 1.4 million product recall.

The FBI advises that consumers protect themselves by maintaining an awareness of the latest recalls and updates affecting their motor vehicles and avoid making unauthorized modifications to their vehicles software. 

14.3.16

ESET waarschuwt voor een golf van besmette e-mails


In Luxemburg was Nemucod goed voor 59% van de malware, in België was dit ‘slechts’ 36%

14 maart 2016 - ESET®  waarschuwt de gebruikers voor een steeds groter aantal besmette e-mails die malware in attachment bevatten waardoor ransomware gedownload en op het toestel geïnstalleerd wordt. Als het attachment geopend wordt, worden de bestanden op het toestel van het slachtoffer versleuteld en wordt ‘losgeld’ gevraagd om die te decrypteren.
De telemetrie van ESET ontdekte dat het om JS/TrojanDownloader.Nemucod  malware gaat en registreerde een uitzonderlijk hoge verspreiding ervan in Europa, Noord-Amerika, Australië en Japan. In Luxemburg werd ontdekt dat Nemucod maar liefst goed was voor 59% van de malware.In België was dit slechts 36%.

Nemucod wordt wijd verspreid door e-mails met zip bestanden. Die e-mails zijn in een vertrouwelijke stijl geschreven en doen zich voor als facturen, gerechtelijke stukken of andere officiële documenten.  De aanvallers willen dat gebruikers het attachment openen. Daarin zit  een bestand in JavaScript dat, eens geopend, Nemucod op de PC van het slachtoffer installeert.  Nemucod is gekend voor het downloaden van een hele waaier aan andere malware beschikbaar ‘in-the-wild’.

Door Nemucod wordt momenteel hoofdzakelijk ransomware zoals TeslaCrypt of Locky gedownload. Deze versleutelen de data op de computer van het slachtoffer en vragen dan losgeld,” zegt Peter Stancik, security evangelist bij ESET.
Ransomware als TeslaCrypt en Locky gebruikt voor het versleutelen dezelfde standaarden als deze die door financiële instellingen worden gebruikt  voor online betalingen. 

Hoe kan men zich tegen deze bedreiging beschermen?
  •          Nooit attachments openen die worden doorgestuurd met e-mails van onbekende afzenders.
  •          Collega’s verwittigen die regelmatig e-mails krijgen van externe bronnen  zoals de financiële afdeling of human ressources.  
  •         Regelmatig back-ups maken. In geval van besmetting zal men makkelijker de data kunnen recupereren. Een externe schijf of een ander opslagmiddel moet niet constant met een PC verbonden blijven om te verhinderen dat de bestanden ook worden besmet.
  •          Regelmatig updates maken van het besturingssysteem en van de andere software die op het toestel gebruikt wordt. Als men nog steeds met Windows XP werkt, is het hoogtijd om over te stappen op een andere versie van Windows die regelmatig ondersteund wordt.  
  •          Alle updates van de beveiligingssoftware moeten geïnstalleerd worden. Idealiter moet de nieuwste versie geïnstalleerd zijn. In hun nieuwste versies hebben de leveranciers van beveiligingssoftware bijkomende beveiligingsparameters ingelast.
  •         De gebruikers van ESET zijn beschermd als ESET LiveGrid® Reputation System  aanstaat. Deze technologie beschermt de toestellen tegen ransomware door op een actieve wijze hun werkwijze te blokkeren.



12.3.16

Android smartphones can be unlocked with 2D-printed fingerprints

Android smartphones offering biometric security can be tricked into unlocking with 2D fingerprints, say researchers – and all you need is some glossy paper and an Inkjet printer.
According to a paper published by Michigan State University researchers Kai Cao and Anil Jain, fingerprint scanners on Android devices can be duped with a high-resolution photo of the owner’s fingerprint. Photos need only be flipped horizontally and then printed on a certain paper with photo-conductive ink cartridges.
The flaw doesn’t appear to be limited to just one model of smartphone, as researchers were able to fool a Samsung Galaxy S6 and Huawei’s Honor 7 using the same method.
Fingerprint sensors have become an increasingly common form of smartphone security since debuting on the iPhone 5s back in 2013. As ZD Net points out, though, no system is perfect, and the iPhone was breached within weeks using a latex material.
That hasn’t stopped developers experimenting with biometrics, just as it hasn’t stopped cybercriminals experimenting with potential hacks. As the Daily Mail reports, it was recently suggested that an iPhone could be broken into with Play-Doh – although it requires the phone’s owner to press their finger into the modeling material for five minutes.
Meanwhile fingerprint scanners aren’t the only biometrics that manufacturers are experimenting with – heartbeat monitors are being trialled as a way to provide secure banking, and even wearables that measure your gait.

According to the two Michigan State University researchers, these too could be susceptible to attack. “It is only a matter of time before hackers develop improved hacking strategies not just for fingerprints,” says the report, “but other biometric traits as well that are being adopted for mobile phones”

9.3.16

Android banking trojan masquerades as Flash Player and bypasses 2FA


By posted

Active users of mobile banking apps should be aware of a new Android banking trojan campaign targeting customers of large banks in Australia, New Zealand and Turkey. The banking malware, detected by ESET security products as Android/Spy.Agent.SI, can steal login credentials from 20 mobile banking apps.The list of target banks includes the largest banks in each of the three target countries (A full list can be found in the final section of this article). Thanks to its ability to intercept SMS communications, the malware is also able to bypass SMS-based two-factor authentication.

Read the article on 
http://www.welivesecurity.com/2016/03/09/android-trojan-targets-online-banking-users/?utm_source=feedburner&utm_medium=email&utm_campaign=Feed%3A+eset%2Fblog+%28ESET+Blog%3A+We+Live+Security%29

8.3.16

The women of ENIAC and the future of women in tech

In 1942, six mathematicians were selected to program a machine that would help the US army calculate complex wartime ballistics tables.
Using their combined mathematical and technical skill, these six programmers helped to create the Electronic Numerical Integrator And Computer (ENIAC) – one of the world’s first ever electronic computers.
They were also all women.
The ENIAC was hailed as a ‘giant brain’ in the contemporary media. Its capacity, with five thousand sums per second, was a thousand times faster than the calculators of the time. It is widely considered to be the grandparent of the computers that we all carry in our pockets today.
The efficiency of the machine owed a lot to its programming.
Before electronic computers existed, an applied mathematician would create models providing a general solution to a problem, which were published in large books called tables.
‘Computers’ (at the time, a job title) would then use these tables and perform arithmetic operations to generate accurate results.
The role of computer was largely considered to be a clerical job and was often assigned to women, especially during the war when many men had been enlisted.
The ENIAC was designed with hardware called function tables, which could be programmed to perform complex sequences of operations. Once the program had been figured out on paper it then had to be programmed into the ENIAC. This process took years.
Despite this, when the ENIAC was launched, the six programmers weren’t given any credit for their success. Kathleen McNulty, Frances Bilas, Betty Jean Jennings, Elizabeth Snyder, Ruth Lichterman and Marlyn Wescoff were not even invited to the launch party.
Remembering the female pioneers of computing
Their story was uncovered in the mid-1980s, when computer science graduate Kathy Kleiman, feeling discouraged about the lack of female role models in computing, set out to research the history of women in computer programming.
In her research she discovered a famous newspaper photo of the ENIAC. Only the men in the image were captioned.
When she asked around about the women in the photograph, “I was told they were models – Refrigerator Ladies’ – posing in front of the machine to make it look good,” she explained in an interview, “but that turned out to be far from the truth”.
The dwindling presence of women in computing
In the 1980s computers started regularly appearing in American homes. At the same time, the number of women studying computer science started to drop – from 37.1% in 1984 to 18% today.
One theory of why this might be is that personal computers first came in the form of toys that were almost entirely marketed to men and boys, therefore creating a narrative that computers were for boys.
At the same time, popular public figures, like Bill Gates and Steve Jobs, gave rise to the perception of computer programming as aspirational, respected and highly profitable.
This was great for computer science, but bad for women who were still being bundled into middle-earning clerical and secretarial work. And ironic, as women doing clerical work were instrumental in creating this new area of study.
The influence of unconscious bias on perception
Although much has improved for women since the 1980s, studies have shown that unconscious bias still affects the perceptions of whether or not women are competent enough to do jobs that are mentally and logically demanding.
A recent study found that on GitHub, an online platform where modified software is shared between users, code submitted by women was accepted more often than that submitted by men – but only when their gender was left ambiguous.
When a user’s gender became evident, the acceptance rate of code submitted by women dipped 10%.
Other studies have shown similar results. In 2012, a study at Yale University found that in considering applicants for a laboratory manager position, both male and female staff judged male candidates to be more competent and deserving of a higher salary. They were also more likely to hire them.
Empowering girls and women to get into computing
A consequence of historic gender inequality – and the constant undermining of women in tech – is that women like Kathy Kleiman interested in computer sciences just don’t have many role models.
Like the ‘computer geeks’ of the 1980s looking up to Steve Jobs and Bill Gates, girls need to know that there is a place for them to aim for.
Since Kathy Kleiman set up the ENIAC Programmers Project in 1985, a lot has been done to spotlight women in the tech industry and encourage girls to be interested in coding and computer sciences.
A 2015 documentary called ‘CodeGirl’ follows schoolgirls from groups across the world as they take part in an international competition to develop an app that solves a community problem.
Also in 2015, model Karlie Kloss backed a scholarship for a summer program for girls wanting to learn how to code. The resulting #KodewithKarlie made a significant impact on raising awareness of the position of women in the tech industry.
“I think it’s crucial that young women learn to code as early as possible, to ensure that we have a voice and a stake in what the world looks like,” said Ms. Kloss.
As well a providing a brighter future for girls, there is a growing realization that having women in the workforce is good for business.
Research amassed by the anthropologist Intel researcher Genevieve Bell has found that women are the lead adopters of technology, making them an important demographic in the tech industry and businesses.
In a hyper competitive market, it makes sense that broadening the talent pool can only reap positive affects.

Because if technology is mostly being designed by the male half of the population, we’re missing out on the innovations, solutions and creations that the other 51% of the population could bring to the table. The women of ENIAC certainly proved that, all those years ago.bb