The german hacker club CCC claims that they found a trojan malware used by german federal police (german source).
It seems that the software has many security issues and, even worse, has abilities which are illegal under german law.
The interesting question is now: Does it really originate from german authorities? Of course they deny that. And if so, how would one prove that? It seems that the trojan uses command servers outside of germany. At the moment it is unclear who operates these machines.
I do not expect that this will ever be resolved completely. It's way too embarrassing.
Update: The Bavarian Government accepted responsibility for the trojan. Antivirus vendors claim that it would be caught be heuristic malware detectors. Looks like there is an egg on someone's face.
Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts
Monday, 10 October 2011
Wednesday, 27 April 2011
Experimental attack on mTAN
F-Secure reports (link in german) that the trojan SpyEye has a new attack on the mTAN online banking security system. Users of infected PCs are tricked into installing malware on their Symbian mobile phones.
In order to do so, the attacker needs the phone's IMEI number, which is not a security credential in itself, but a user should become suspicious nowadays if their bank wants to know their IMEI number. Therefore I suggest to categorize this attack as experimental.
The urgent question behind this is: why did the Symbian developers base the security of their operating system on IMEI numbers?
Wednesday, 2 March 2011
Malware on Android
As everyone reports: there has been malware on Google's Android market. I have to add that such a thing removes the remaining security from SMS-TANs or similar two factor authentication schemes. One way out of that problem would be to use an additional trusted execution environment on smart phones.
Monday, 8 November 2010
ZeuS uses unpatched IE exploit
The Eleonore toolkit, which is the tack vector for the ZeuS malware, got support for the
recent CSS vulnerability of IE 8 which is still not fixed. This means that there will be more broken webservers distributing the exploit and bigger damage to affected users.
recent CSS vulnerability of IE 8 which is still not fixed. This means that there will be more broken webservers distributing the exploit and bigger damage to affected users.
Position:Zeppelinstraße,München,Deutschland
Monday, 1 November 2010
ZeuS Botnet under Reorganisation
Reuters reports that the author of the ZeuS botnet announced that he will stop developing and maintaining ZeuS. Probably he has sold the sources and the customer base to a competing botnet , Spy Eye. Spy Eye has been fighting hard against ZeuS, but could not overtake ZeuS.
One may safely assume that the ZeuS author will use this sabbatical to come back with something even more dangerous, as it was the case in 2007 and 2008 when he also took a break.
Sunday, 15 August 2010
Smartphones Not Ready for Mobile TANs
In the last weeks we had an outbreak of security issues with smart phones. The most famous was the pdf font bug that hit the iPhone and other iOS devices which was fixed by Apple with iOS 4.0.2. This one was really dangerous because it could infect iPhones just by opening an infective web site.
Then we had a rootkit for Android phones. A first criminal exploitation was a Trojan, also for Android, that sent text messages to premium numbers.
Of course there is much more. The reason for this is, of course, that there is no magical security for telephones. Old-style telephone-and-SMS-only phones were simply too dumb to be hacked (if we disregard the occasional bluetooth hack). Modern smartphones are normal computers that happen to contain a radio baseband chip.
However, we have that security feature M-TAN or Mobile TAN for online banking. When a M-TAN user has entered their transaction into the online banking website, they get a SMS with some details on the transaction and the M-TAN number. If the details of the transaction look good, they enter the M-TAN into the web site to complete the transaction.
So, here is the criminal master plan:
- own as many PCs as you get
- own as many smartphones as possible
- match smartphones and PCs
- start phony transactions on the PC
- capture the resulting SMS
- send the M-TAN to the Trojan on the PC
- Profit
Sounds complicated, but if everyone has a backup of their smart phone on the PCs step 3 should be quite easy and the only remaining issue for the criminal is whether they find enough matches so that the plan is worth the effort.
A promising version of this plan would be to attack the smart phone via the infected PC. In iPhone speak this would be called the "trojan jailbreak". If this can be done without the user noticing it, the M-TAN is completely broken.
I don't recommend using M-TANs on a smartphone.
Labels:
android,
apple,
e-crime,
malware,
mobile phone,
real world,
vulnerability
Wednesday, 9 December 2009
Phishing Damage Estimations
Trusteer operatates the anti-phishing browser plugin Rapport. Based on measurements performed by Rapport, they were able to estimate the average damage done by phishing. A succesful phishing attack is counted if the Rapport plugin detects that the user tries to enter credentials into a phishing web site.
Assuming that each successful phishing attack steals between 500$ and 2000$ they arrive at an average damage of 2$ to 9$ per online banking user per year.
This seems a lot but it also explains why banks seem to take phishing so lightly: Any kind of security token will certainly cost more per user and year.
What about Rapport itself? It seems to be well suited here if it helps against phishing and costs the bank less than the 9 Dollars mentioned above. Which is no surprise, as all the numbers come from Trusteer. I would like to know whether it also helps against trojans and man-in-the-middle attacks.
Labels:
browser,
e-commerce,
e-crime,
malware,
phishing
Sunday, 8 November 2009
PhoneSnoop Turns BlackBerries into Bugs
A simple BlackBerry program called PhoneSnoop will turn your BlackBerry into a bug. The attacker will install it on a BlackBerry he found lying around. Then calling the BlackBerry from a preconfigured telephone number will put the Balckberry into SpeakerPhone mode and all conversations near the affected BlackBerry can be overheard at the remote end of the call.
This is not a security issue of the BlackBerry operating system, because the root cause here is that the attacker had full control over the phone when he installed the software. For a minimum level of security, the BlackBerry should be configured to require a password ofter a short period of inactivity.
However, the morale here is that you shouldn't think "I don't have sensitive information on my telephone, so I don't need to secure it".
Tuesday, 6 October 2009
The URLZone Trojan
RSA Fraud Action Research Lab publish an article about a online-banking trojan called URLZone. This trojan has an interesting new feature:
It can determine if whether requests for new "mules" come from a botnet member or a security company. If the request comes from a security company or researcher, the server will respond with account data of innocent people, thus protecting their mules from prosecution.
The accounts are people who received a legitimate transfer from a URLZone victim before.
'Mules' are the people who receive payments from infected PCs and forward them to the gangster's accounts. That's money-laundering, and not only criminal, but also quite dangerous. The fake mule responses will put innocent people under suspicion of money laundering.
Sunday, 13 September 2009
Linux Botnet
The Register reports a new linux server botnet originally reported here. It is not yet clear how the servers are infectected. The purpuse of these servers is to serve malware from an additional webserver installed on listening on port 8080. It seems to me that people look at their web forum security again very closely: Not only can be used to exploit a server, but also if it is possible to post links at public discussion sites it is also possible to post links to such malware.
Labels:
e-crime,
malware,
server security,
web security
Saturday, 29 August 2009
MacOS X is not Invulnerable
Apple has fixed a nasty longstanding bug. This bug seems to enable user space programs to overwrite arbitrary locations in the kernel memory. The impact of this depends on how easy it is to guess the location of the target. A technique called Address Space Layout Randomization is expected to help here. Attackers need to guess the location of target variables or code for many computers in order to create a worm or rootkit that spreads using this vulnerability. However, it seems that the kernel memory is not randomized so all macs prior to the latest version of Leopard are vulnerable.
Sunday, 19 July 2009
Joanna Rutkowska on Processor-Level Security
Tomshardware runs an interview with Joanna Rutkowska on malware targetet against the BIOS and even the processor firmware. The issue here is that the operating system can't defend itself against malware targetting lower layers of the system like the processor firmware. Here Joanna sees a task for the vendors of BIOSes and firmware.
Subscribe to:
Posts (Atom)