Posts

Showing posts with the label hackers story

Found Malware Uses 7 NSA Hacking Tools, Where WannaCry Uses 2

Image
Found Malware Uses 7 NSA Hacking Tools, Where WannaCry Uses 2 A security researcher has identified a new strain of malware that also spreads itself by exploiting flaws in Windows SMB file sharing protocol, but unlike the WannaCry Ransomware that uses only two leaked NSA hacking tools, it exploits all the seven. Last week, we warned you about multiple hacking groups exploiting leaked NSA hacking tools, but almost all of them were making use of only two tools: EternalBlue and DoublePulsar. Now, Miroslav Stampar, a security researcher who created famous 'sqlmap' tool and now a member of the Croatian Government CERT, has discovered a new network worm, dubbed  EternalRocks , which is more dangerous than WannaCry and has no kill-switch in it. Unlike WannaCry, EternalRocks seems to be designed to function secretly in order to ensure that it remains undetectable on the affected system. However, Stampar learned of EternalRocks after it infected his SM...

Gang Cyber Crime Arrested for Infecting Over 1 Million Phones with Banking Trojan

Image
Cyber Crime Gang Arrested for Infecting Over 1 Million Phones with Banking Trojan The Russian Interior Ministry announced on Monday the arrest of 20 individuals from a major cybercriminal gang that had stolen nearly $900,000 from bank accounts after infecting over one million Android smartphones with a mobile Trojan called "CronBot." Russian Interior Ministry representative Rina Wolf said the arrests were part of a joint effort with Russian IT security firm Group-IB that assisted the massive investigation. The collaboration resulted in the arrest of 16 members of the Cron group in November 2016, while the last active members were apprehended in April 2017, all living in the Russian regions of Ivanovo, Moscow, Rostov, Chelyabinsk, and Yaroslavl and the Republic of Mari El. Targeted Over 1 Million Phones — How They Did It? Group-IB first learned of the Cron malware gang in March 2015, when the criminal gang was distributing the Cron Bot malware disguised as Viber and Google Pla...

Malware Easily Bricked The Smart TV Running Google TV 2017

Image
Malware Easily Bricked The Smart TV Running Google TV ​There’s a good chance you don’t remember Google’s own smart TV platform called Google TV, but although this was pretty much a failure, there still are people out there who actually bought devices running it. The number of TVs powered by Google TV, however, is declining, and this Christmas, for example, at least one smart TV went dark unexpectedly. Darren Cauthon took to Twitter to reveal that his LG smart TV running Google TV was infected with malware when his family tried to install a movie streaming application. Judging from the photo he posted, this looks like a form of ransomware which requires him to pay to have access to the device restored. Related This Exploit Can Root Your Android Device But since the ransomware wasn’t necessarily developed for TVs, but for Android devices such as tablets and smartphones, it’s now completely bricked and no workaround seems to be able to restore it. Booting obviously leads to the same ranso...

Poweliks: inception all over again real hackers story live 2

Image
Currently, it is pouring rain outside, I’ve watched every interesting show on Netflix and I need to find an excuse not to clean my apartment. I consider writing a blog post on a Sunday afternoon a great excuse not to wave the cleaning fairy’s wand. I don’t feel like writing a pure malware reverse engineering blog though, so I decided to give this blog a little twist. I infected a virtual machine with some interesting malware called Poweliks. The goal of this blog is to extract indicators of compromise (IOC’s) out of this  Poweliks sample , making use of the infected machine, a memory dump and the sample itself. This approach is a more dynamic malware analysis approach (i.e. analyzing the malware by running it), rather than a full malware reverse-engineering approach (analyzing the static sample). The reason why I find Poweliks interesting enough to blog about, is because  Poweliks does not leave any trace on the file system : it hides itself exclusively in the registry and mem...