Skip to main content

Posts

Showing posts with the label #android

🔥 Best Tools to protect your online privacy these days 🔥

Privacy should be the top priority of anyone doing their business online, especially on Telegram , Darknet Most of you may know many of the tools mentioned in this post but I feel compiling a good list never hurts Step 1 - VPN Staying anonymous should be a second nature to everyone online. You can use free/paid software for that. One should look for a VPN that does not keep logs and even the country they are based from is also know for pro-privacy rules. Top free software: TOR/TAILS Your own proxy/vpn setup using linux scripts and VPS Top paid VPN software: iPredator (Sweden) Mullvad (Sweden) ProtonVPN (Switzerland) ExpressVPN (British Virgin Islands) NordVPN (Panama) - LQ but adding it Step 2 - Emails Use email providers that protect user privacy and also have encryption methods implemented in their mail system. You can use any of the above emails to register on forums, buy subscriptions and even for personal use irl to protect your privacy: Protonmail.com Tutanota.com Yandex.com Post...

Chinese Phone Maker Gionee Found Guilty of Implanting Malware in More Than 20 Million Devices

A Chinese court has found phone manufacturer Gionee guilty of intentionally implanting malware in more than 21.75 million smartphones to generate revenue from users. Shenzhen Zhipu Technology, a subsidiary of Gionee, together with its partner, Beijing Baice, implanted a Trojan Horse program in Gionee smartphones via an update to the Story Lock Screen app in 2018, according to an official document released by the People’s Court of Yiwu City, Zhejiang Province.  The software is installed on the affected phones without users’ knowledge through a hot code push functionality, which allows an automatic update to mobile apps when the server is updated, without going through any app reviews. A hot update plugin called “Dark Horse Platform” was proposed by Baice in December 2018 to increase the efficiency of the “pull method”, which is used to launch the app and boost daily active user count. The SDK version of the Story Lock Screen app was upgraded with Trojan plugins while the Dark Horse ...

Chinese Threat Actor 'Mustang Panda' Updates Tools in Attacks on Vatican

A Chinese threat actor tracked as Mustang Panda was observed using an updated arsenal of tools in recent attacks, Proofpoint’s security researchers revealed on Monday. Also referred to as TA416 and RedDelta, the threat group is known for the targeting of entities connected to the diplomatic relations between the Vatican and the Chinese Communist Party, along with entities in Myanmar, and the new campaign appears to be a continuation of that activity. Some of the observed toolset updates, Proofpoint says, include the use of a new Golang variant of the PlugX malware loader, in addition to the constant use of PlugX. While attribution remains fairly simple, automatic detection is more difficult. “This may represent efforts by the group to continue their pursuit of espionage objectives while maintaining an embattled toolset and staying out of the daily Twitter conversation popular amongst threat researchers,” Proofpoint notes. Phishing lures used in recent attacks show a focus on the relati...

FBI in Threat Warning After Surge in Spoofed Domains.

 The FBI is warning internet users to be on high alert for website and email domains masquerading as those of the crime-fighting agency. The Bureau claimed in a Public Service Announcement that it has detected multiple threat actors registering fake domains mimicking legitimate FBI ones, which could be the precursor to a new campaign. Cyber-criminals typically register domains that look identical to those of their victims, but which contain very small differences, such as an alternative TLD after the dot, or a slightly different spelling. Internationalized Domain Names (IDNs) also offer opportunities to use Cyrillic and other letters that look very similar to Roman alphabet characters. Internet users could visit such sites of their own accord or be prompted to do so via phishing emails which also use spoofed domains to appear more trustworthy. “Spoofed domains and email accounts are leveraged by foreign actors and cyber-criminals and can easily be mistaken for legitimate websites o...

Stantinko Proxy Trojan Masquerades as Apache Servers

A threat group tracked as Stantinko was observed using a new version of a Linux proxy Trojan that poses as Apache servers to remain undetected. Initially detailed in 2017, Stantinko is believed to have been operating since at least 2012, ensnaring infected systems into a botnet mainly used in massive adware campaigns, but also for backdoor activities, brute-force attacks, and more. Previously, the Stantinko group was mainly known for the targeting of Windows systems, but recent attacks show that they are also focusing on evolving their Linux malware, with a new proxy Trojan that masquerades as httpd, the Apache Hypertext Transfer Protocol Server found on many Linux servers. “We believe this malware is part of a broader campaign that takes advantage of compromised Linux servers,” Intezer’s security researchers say. Detected by a single anti-virus engine on VirusTotal, the sample is an unstripped 64-bit ELF binary that, upon execution, validates a configuration file. Should this file be ...

Vietnam-Linked Cyberspies Use New macOS Backdoor in Attacks

Trend Micro’s security researchers have identified a new macOS backdoor that they believe is used by the Vietnamese threat actor OceanLotus. Also referred to as APT-C-00 and APT32, and believed to be well-resourced and determined, OceanLotus has been observed mainly targeting government and corporate entities in Southeast Asia. Earlier this year, the group engaged in COVID-19 espionage attacks targeting China. Compared to previous malware variants associated with OceanLotus, the newly discovered sample shows similarities in dynamic behavior and code, clearly suggesting a link to the threat actor. A document used in the campaign features a Vietnamese name, which has led researchers to believe that users from Vietnam have been targeted with the new malware. The observed sample masquerades as a Word document but it is an app bundled in a ZIP archive, which features special characters in its name, in an attempt to evade detection. The app bundle, Trend Micro explains, is seen by the operat...

Data breech Defence data stolen from Italian naval electronics; two arrested

The Italian naval data was compromised as a group of men tried to steal the defence data from the Italian aerospace and electronics group Leonardo, the interior ministry reported on Saturday. The company, Leonardo, has a wide array of activities in Italian naval electronics, network and protection systems, electronic warfare and global communications. Leonardo noticed a serious computer hack. This was followed by a detailed investigation by a Naples prosecutor. "At the end of a complex investigation by the Naples prosecutor into a serious computer attack against Leonardo .. a former worker and a company director were arrested," a ministry statement said. In the investigation, it was found out that a programme was inserted into dozens of work computers through a USB stick that allowed the hackers to gather data on several projects over a period of two years. This also included many strategic projects. The hack took place at the company's plant in Pomigliano d'Arco, nea...

MetaMask phishing steals cryptocurrency wallets via Google ads

  Over the past week, users of the MetaMask cryptocurrency wallet have been losing funds to a phishing scam that lured potential victims through Google search ads. MetaMask has a community of more than one million users. The site offers an Ethereum cryptocurrency wallet in the browser via a browser extension that lets distributed applications read from the blockchain. When installing the legitimate extension, you can either import an existing wallet or create a new one along with the secret seed phrase that allows access to the wallet. MetaMask users find empty wallets Although it is unclear how many MetaMask users fell for the scam, some say they ended up with empty wallets after clicking on a fraudulent search ad being promoted as the MetaMask site. The phishing/ad scam is still active, with a new domain constantly being promoted via Google search ads. On Wednesday, MetaMask alerted its community of the scam and recommended the use of direct links to the legitimate meta...

Major Power Outage in India Possibly Caused by Hackers

The outage occurred in mid-October and it impacted the Mumbai metropolitan area, causing significant disruption to traffic management systems and trains. It took two hours to restore power just for essential services, and up to 12 hours to restore power in some of the affected areas. Authorities immediately said sabotage could not be ruled out and the Mumbai Mirror reported on Friday that a cyber police unit found evidence suggesting that the incident may have been caused by a cyberattack. According to the  Mumbai Mirror , investigators found multiple suspicious logins into the servers linked to power supply and transmission utilities. It’s believed that manipulation of these servers may have triggered the outage. The activity was traced to several South Asian countries and investigators are trying to determine if it was part of a coordinated effort. The paper learned from its sources that threat actors — in many cases profit-driven cybercriminals — have been targeting power utilit...

Botnets have been silently mass-scanning the internet for unsecured ENV files

  Drawing little attention to themselves, multiple threat actors have spent the past two-three years mass-scanning the internet for ENV files that have been accidentally uploaded and left exposed on web servers. ENV  files, or  environment files , are a type of configuration files that are usually used by development tools. Frameworks like Docker, Node.js, Symfony, and Django use ENV files to store environment variables, such as API tokens, passwords, and database logins. Due to the nature of the data they hold, ENV files should always be stored in protected folders. "I'd imagine a botnet is scanning for these files to find stored credentials that will allow the attacker to interact with databases like Firebase, or AWS instances, etc.," Daniel Bunce, Principal Security Analyst for SecurityJoes, told  ZDNet . "If an attacker is able to get access to private API keys, they can abuse the software," Bunce added. MORE THAN 1,100 ENV SCANNERS ACTIVE THIS MONTH AL...

Drupal sites vulnerable to double-extension attacks

  The 90s called. They want their vulnerability back. Image: Durpal Project // Composition: ZDNet The team behind the Drupal content management system (CMS) has released this week security updates to patch a critical vulnerability that is easy to exploit and can grant attackers full control over vulnerable sites. Drupal, which is currently the fourth most used CMS on the internet after WordPress, Shopify, and Joomla, gave the vulnerability a rating of " Critical ," advising site owners to patch as soon as possible. Tracked as  CVE-2020-13671 , the vulnerability is ridiculously simple to exploit and relies on the good ol' "double extension" trick. Attackers can add a second extension to a malicious file, upload it on a Drupal site through open upload fields, and have the malicious executed. For example, a malicious file like  malware.php  could be renamed to  malware.php.txt . When uploaded on a Drupal site, the file would be classified as a text file rather than...

What is CRAT ? How it affects your computer ? Safety !

It is a new version of a remote access trojan (RAT) family known as CRAT. Apart from the prebuilt RAT capabilities, the malware can download and deploy additional malicious plugins on the infected endpoint. One of the plugins is a ransomware known as "Hansom." CRAT has been attributed to the Lazarus APT Group in the past. The RAT consists of multiple obfuscation techniques to hide strings, API names, command and control (C2) URLs and instrumental functions, along with static detection evasion. The attack also employs a multitude of anti-infection checks to evade sandbox based detection systems. What's new? Cisco Talos has recently discovered a new version of the CRAT malware family. This version consists of multiple RAT capabilities, additional plugins and a variety of detection-evasion techniques. In the past, CRAT has been attributed to the Lazarus Group, the malicious threat actors behind multiple cyber campaigns, including attacks against the entertainment sector. Ind...