Showing posts with label virus. Show all posts
Showing posts with label virus. Show all posts

Bug in Broadcom WiFi Chip Put iPhone And Android Phones At Risk


Google Project Zero is a team of professionals at Google, who keeps hunting in mainstream software and anti-virus products for bugs. According to UK International Business Times, the Google project team has discovered a vulnerability that could enable hackers to take control of the users device completely.

Apple device users can overcome this threat by updating the device to the latest iOS 10.3.1. If you are not in a situation to update your device, it is recommended to turn off your Wi-Fi connection.
Samsung users are in a real threat now since the company has not yet come up with a patch to this vulnerability.

Apple recommends its users to check if their devices are updated to the latest version by heading on to settings -> general -> software updates. If they have not yet received it, users can manually download the update from iTunes.

Netflix Scam Tries To Steal iPhone Users Credit Card Details


Having an iPhone with you is nice, having a Netflix account also has no problem. But as of now if you are having them both, then there is something to be alarmed, there is a new email scam that is ​​using a fake iTunes bill to fool you into giving the details of your credit card

Like any phishing scheme, these fraudulent emails contain fake bills for products you may not remember having purchased. The emails seem to originate from Apple, and they appear to contain receipts for purchases that you'd normally get in your email – if you have an Apple ID account and buy stuff from Apple's digital stores.

This particular receipt concerns Netflix, and it tries convince you that someone impersonating you has gained access to your Apple account to subscribe to Netflix. Naturally, you'll want to put a stop to it by clicking the available “refund” or “manage subscriptions” links in that email.

You'll then get to a website that looks like Apple's where you have to enter your account and credit card details for the refund. But what really happens is that those details are delivered straight to the scammers. And they'll then put it to good use, meaning that you can expect real warnings from your bank in the near future.

Android Adware Nearly Impossible To Remove

Lookout has found a new form of adware that can root the device automatically after installation, and then disguise itself as a system application. This makes it impossible to any normal method to eliminate it; even factory resetting the device won't help.


This is a new, more sophisticated version of typical adware, which constantly pushing advertisements on the user. Most users probably will not even know they are infected. It is an effective family of Trojan viruses.


Lookout discovered that this family of Trojans hides inside a legit apps like Candy Crush, Google Now, Facebook, NYTimes, Okta, Twitter, WhatsApp, Snapchat, and more than 20,000 others. Non-Infected versions of these applications are available on the Google Play store; users will be infected only if they are installing apps from outside play store. Since most instances of this malware leave the host app virtually unaltered, users may not notice the sneaky little culprit that snuck in on it.

Once the malware gets into a device, it will be "almost impossible" to get rid of, and that the only solution for most consumers is buying a new phone. Adware with this kind of power is obviously a security risk. Apps usually do not have access to files created by other applications, but root access bypasses this protection and could highlight the infected devices to fraud and identity theft.

Although this malware is dangerous, the probability of being infected by it is probably quite low. As already mentioned, these infected apps are found in third party stores, so if you stick to official channels - you should have little to worry about.

New Tricky iPhone Malware Spreading In China And Taiwan

A new kind of malware that show full screen ads thrives on Apple devices in China and Taiwan. The development follows reports last month that apps loaded with malware should be removed from the company's App Store.


The malicious software, called YiSpecter, is reportedly able to "install and start random iOS apps, replaces the existing apps with those it downloads, capes carrying other apps to display ads, modify Safari default search engine, bookmarks and open pages, and upload the device information, "according to US-based cyber security company Palo Alto Networks.

Victims of YiSpecter are reportedly tricked into infection by making them to download what appears to be a "private version" or "Version 5.0" of a popular but now defunct media player, called QVOD.


In China, QVOD was popular for its ability to enable users to share pornographic content. Pornography is illegal in China, but there is a vast underground network of secret sites and third-party apps to circumvent those laws. The offices of the app developer, Kuaibo, were raided by police in 2014.

YiSpecter is able to make use of private application programming interfaces (APIs) to install itself on infected machines and then trick iOS 'Springboard, software that manages things like app icons on the home screen, to prevent users remove. The malware this deception a step further by using the same name and logos of the system apps. It does not even need the iPhone or iPad to be jailbroken (the term used to describe the process unlocking a device, allowing you to install unauthorized apps require).

Ryan Olson, director of threats of Palo Alto Networks, told The Wall Street Journal that the culprit appears to be a China-based mobile advertising service and that Apple had made from this new threat.

The news comes two weeks after the XcodeGhost attack caused Apple to attract a large number of reliable, high-profile apps from China's app store.

New Malware Affects Wordpress Websites

Bad news for those who use Wordpress for their business or personal websites. According to security firm Sucuri, a not-so-inconsiderable number Wordpress installations affected by a new "visitorTracker_isMob" piece of malware in the past two weeks. Visitors who try to go to these sites are redirected to a new page that their system probes for all kinds of weaknesses. If found there, said the system is compromised, and it only gets worse from there.


"This malware campaign is interesting, the ultimate goal is to use as many malicious sites as possible to redirect all their visitors to a nuclear Exploit Kit landing page. The landing pages will seek a wide range of available browser exploits to infect the computers of unsuspecting visitors' reads Sucuri's blog post.

"If you think about it, the compromised websites are only means the criminals to gain access to as many end desktops as they can. What is the easiest way to reach out to endpoints? Websites, of course."

The best things you can do to protect yourself against this type of attack to make sure that your system is updated. This also applies to the installation of the latest updates OS that Microsoft or Apple offers, as well as any updates to other critical software related to your web browsing such as Java (which you have just downright off) and Adobe Flash (which you do not need 't use anyway). Make sure you use antivirus and anti-malware apps on a regular basis, too.

According to Sucuri, about 95 percent of infected websites it detects all running WordPress. This put about 17 percent or so already in Google's blacklists (and other malware blacklists).

As for Wordpress administrators, Sucuri has some tips for protecting your own sites at the Visitor Tracker malware.

"If you're a WordPress user, make sure all your plugins updated, including premium ones. I also recommend checking your site via our free Security / Malware Scanner (Site Check) to check if you currently affected by this campaign. If you are an administrator and have access to your server, you can use the following command (grep) to search for the infection to your files, "reads the company blog post.

New ATM Malware Released To Steal Your Banking Details

Security researchers have discovered a new piece of malware called Backdoor.ATM.Suceful that infects ATMs and can steal your banking information.


Discovered by security firm FireEye Labs, malware directly targeted cardholders rather than banks. The virus can run on multiple types of ATM, including those made by Diebold and NRC, and is claimed to provide a powerful range of disturbing characteristics. In particular, FireLab emphasizes that the software can read the data from the glide strip and chip of a card, enter the encrypted PIN, delete the automatic sensors to avoid detection and to keep the map of user in the machine. Full enough, then.

FireEye identified the malware after it was transferred to the online tool VirusTotal. Stamped with a creation date of 25 August 2015, the researchers believe that the malware may still be in the development phase. Indeed, Backdoor.ATM.Suceful has not been observed in the wild. But given its characteristics in combination have "never seen before in ATM malware" it would not be too long before he slips into ATMs - in Russia or elsewhere.

While it is impossible to know whether an ATM is affected by malicious software by simply looking at it, FireLab's advice is to "keep the contact number for your bank in your phone and call while keeping eyes to the ATM "if your card is retained And if you notice anything suspicious at an ATM, do not use it - just walk away.

Kategori

Kategori