Mondelez says cyber-attack affected systems up and running

(Reuters) - Mondelez International Inc, the world's second-largest confectionary company, said on Thursday that most of its systems affected by the global cyber attack were up and running.


from Reuters: Technology News http://ift.tt/2tRSuO8

U.S. judge allows Twitter lawsuit over surveillance to move forward

SAN FRANCISCO (Reuters) - A U.S. judge ruled on Thursday that a lawsuit filed by Twitter Inc seeking the right to reveal the extent of U.S. government surveillance requests could move forward.


from Reuters: Technology News http://ift.tt/2tX1GBZ

Qualcomm accuses Apple of infringing six patents in iPhone, iPad

WASHINGTON (Reuters) - Chipmaker Qualcomm Inc will ask the U.S. International Trade Commission to bar Apple Inc from selling some iPhones and iPads in the United States on the grounds that they infringe on six Qualcomm patents.


from Reuters: Technology News http://ift.tt/2tWRc5k

Airbnb says had proposed alternative to forcing Paris hosts to register rentals

PARIS (Reuters) - Short-term rental website Airbnb said on Thursday it had proposed for Paris and other large French cities to create automated limits to ensure its hosts did not rent their property beyond the 120 days a year legal limit for a main residence in France.


from Reuters: Technology News http://ift.tt/2sRjHfY

Wikileaks Unveils CIA Implants that Steal SSH Credentials from Windows & Linux PCs

WikiLeaks has today published the 15th batch of its ongoing Vault 7 leak, this time detailing two alleged CIA implants that allowed the agency to intercept and exfiltrate SSH (Secure Shell) credentials from targeted Windows and Linux operating systems using different attack vectors. Secure Shell or SSH is a cryptographic network protocol used for remote login to machines and servers securely


from The Hacker News http://ift.tt/2tltm1E

Microsoft to cut 'thousands' of jobs: source

(Reuters) - Microsoft Corp plans to cut "thousands" of jobs, with a majority of them outside the United States, a person familiar with the matter told Reuters.


from Reuters: Technology News http://ift.tt/2tQkVft

CopyCat Rooting Malware Hijacks 14 Million Android Devices

A newly uncovered malware strain has already infected more than 14 Million Android devices around the world, earning its operators approximately $1.5 Million in fake ad revenues in just two months. Dubbed CopyCat, the malware has capabilities to root infected devices, establish persistency, and inject malicious code into Zygote – a daemon responsible for launching apps on Android, providing


from The Hacker News http://ift.tt/2sKFWZJ

Venture firm Felix looks beyond Farfetch to where luxury meets tech

GOULT, France (Reuters) - Felix Capital, an early investor in firms ranging from luxury retailer Farfetch to Gwyneth Paltrow's lifestyle company Goop, has closed its second fund of $150 million, which it will invest in tech savvy companies in the luxury industry.


from Reuters: Technology News http://ift.tt/2sKmjkz

How the CopyCat malware infected Android devices around the world

Check Point researchers identified a mobile malware that infected 14 million Android devices, rooting approximately 8 million of them, and earning the hackers behind the campaign approximately $1.5 million in fake ad revenues in two months.

The malware, dubbed CopyCat by Check Point mobile threat researchers, uses a novel technique to generate and steal ad revenues. While CopyCat infected users mainly in Southeast Asia, it  spread to more than 280,000 Android users in the United States.

CopyCat is a fully developed malware with vast capabilities, including rooting devices, establishing persistency, and injecting code into Zygote – a daemon responsible for launching apps in the Android operating system – that allows the malware to control any activity on the device.

Researchers first encountered the malware when it attacked devices at a business protected by Check Point SandBlast Mobile. Check Point retrieved information from the malware’s Command and Control servers, and conducted a full reverse engineering of its inner workings, which are detailed in a comprehensive technical report.

A breakdown of how pervasive the CopyCat malware campaign isThe CopyCat campaign reached its peak between April and May 2016. Researchers believe the campaign spread via popular apps, repackaged with the malware and downloaded from third party app stores, as well as phishing scams.  There was no evidence that CopyCat was distributed on Google Play, Google’s official app store.

In March 2017, Check Point informed Google about the CopyCat campaign and how the malware operated. According to Google, they were able to quell the campaign, and the current number of infected devices is far lower than it was at the time of the campaign’s peak. Unfortunately, devices infected by CopyCat may still be affected by the malware even today.

 What does CopyCat do?

CopyCat is an extensive campaign that infected  14 million devices globally, rooting 8 million of them, in what researchers describe as an unprecedented success rate. Check Point researchers estimate that the malware generated $1.5 million for the group behind the campaign.

Read the CopyCat research report

CopyCat uses state-of-the-art technology to conduct various forms of ad fraud, similar to previous malware discovered by Check Point, such as  Gooligan, DressCode, and  Skinner. Upon infection, CopyCat first roots the user’s device, allowing the attackers to gain full control of the device, and essentially leaving the user defenseless.

CopyCat then injects code into the Zygote app launching process, allowing the attackers to receive revenues by getting credit for fraudulently installing apps by substituting the real referrer’s ID with their own. In addition, CopyCat abuses the Zygote process to display fraudulent ads while hiding their origin, making it difficult for users to understand what’s causing the ads to pop-up on their screens. CopyCat also installs fraudulent apps directly to the device, using a separate module. These activities generate large amounts of profits for the creators of CopyCat, given the large number of devices infected by the malware.

What’s the big deal about adware?

The preponderance of malware focused on skimming profit from the ad industry, and the ingenious technical approaches deployed, indicate just how lucrative it is for cybercriminals to engage in adware campaigns. But adware poses a significant threat to users and businesses, alike, including:

  • Theft of sensitive information – Some adware, such as Gooligan, steal sensitive information from their victims, which can later be sold to third parties
  • Device rooting or jailbreaking – Adware frequently roots or jailbreaks devices, thereby breaking the built-in security mechanisms of Android or iOS, leaving victims defenseless to even the lowest level kind of hacks
  • Evolving attack objectives – The bad guys behind adware campaigns may refocus their attacks, spreading different types of malware to rooted or jailbroken devices, or use them to create Denial of Service attacks
  • Code sharing with hacking community – The sophisticated capabilities developed by adware developers can be adopted by other malware developers, and used to commit bigger crimes, as witnessed in the Vault 7 leak.

 Adware impacts businesses, too

For these reasons, adware such as CopyCat create risk to both private users and to the enterprise. Attackers need nothing more than a compromised mobile device connected to the corporate network to breach the business’ complete network and gain access to sensitive data. Mobile devices are an endpoint in your network, just like any laptop, and require the same level of protection. Adware that steals credentials to sensitive information, or roots devices and leaves them vulnerable to any type of attack, are exactly what an attacker looking to infiltrate a corporate network seeks.

countries where the CopyCat malware campaign hit hardest 

Who is behind CopyCat?

Surprisingly, several adware families were developed by firms connected to the ad industry. Such was the case with HummingBad and YiSpecter, developed by Yingmob, and the recent example of the Judy malware, developed by Kiniwini. It is unclear who is behind the CopyCat attack, however, there are several connections to MobiSummer, an ad network located in China. It is important to note that while these connections exist, it does not necessarily mean the malware was created by the company, and it is possible the perpetrators behind it used MobiSummer’s code and infrastructure without the firm’s knowledge.

The first connection between the company and the malware is the server, which operates both the malware and some of MobiSummer’s activity. In addition, some of the malware’s code is signed by MobiSummer itself, and some of the remote services used by the malware were created by the company. The malware also refrains from targeting Chinese devices, suggesting the malware developers are Chinese and want to avoid any investigation by local law enforcement, a common tactic in the malware world.

 What’s the impact?

Check Point researchers investigated one of the Command and Control servers, which was active between April and May 2016, and recorded over 14 million infected devices, 8 million of them rooted (54%). Fraudulent ads were display on 3.8 million of the infected devices (26%), while 4.4 million, or 30%, of the infected devices were used to steal credit for installing apps on Google Play. The Command and Control server also stored information collected about the infected devices, including brand, model, OS version, and country. Check Point researchers believe additional Command and Control servers operating CopyCat exist, indicating that the number of infected devices may be significantly larger.

Protect your enterprise   |   Protect your personal device

The revenue generated by the attackers is estimated to be more than $1.5 million, most of which was earned over the course of two months. The nearly 100 million ads displayed by the malware generated approximately $120,000. Since we can measure only how many devices claimed credit for fraudulent installations, and not how many times such an activity took place, we are conservatively assuming that each device has done so only once. Even so, the estimated revenue these actions yielded for the perpetrators is over $660,000. The largest revenue stream came from the 4.9 million fraudulent app installations conducted by the CopyCat, generating over $735,000.

How does the malware operate?

Once installed, the malware lies in waiting until the device is restarted, so that a connection isn’t made between the installation of the app and the malicious activity. Once the device has restarted, CopyCat downloads an “upgrade” pack from an S3 bucket, a web storage service provided by Amazon. This pack contains six common exploits with which the malware attempts to root the device. If successful, CopyCat installs another component to the device’s system directory, an activity which requires root permissions, and establishes persistency, making it difficult to remove.

CopyCat then injects code into the Zygote process, from which all Android apps are launched. Since all apps in Android are processes launched from Zygote, injecting code directly into it allows the malware to infiltrate the activity of all running apps. This is the first adware  discovered using this technique, which was first introduced by the financial malware Triada.

After CopyCat compromises the Zygote process, it injects into the system_server process, and contains all Android services, such as PhoneManager, Packagemanager, etc., including ActivityManager. CopyCat then registers for several events on the system server. The malware uses two tactics to steal ad revenue – displaying fraudulent ads and stealing referrer IDs of apps installed from Google Play.


a flowchart depicting the inner workings of the CopyCat malware campaign

 

Displaying fraudulent ads

To display fraudulent ads, the malware uses “callActivityOnStart” and “callActivityOnStop,” which are executed each time a device activity launches. When an activity starts, the malware checks three things: whether the user is in China; whether the launched app is one of the predefined list of major apps, such as Facebook and WhatsApp (to avoid interfering with them); and whether enough time has passed since the last ad was displayed. If none of these conditions are met, the malware displays an ad from the ad libraries of Facebook, Admob, or UC. These predefined conditions are meant to minimize the user’s suspicion, while disguising the app that’s the source of the pop-up ads.

 Stealing app installation credits

The second tactic is even more complex, but carries more profits for the perpetrators. Advertisers are paid for displaying ads that lead to the installation of certain apps. There are several mobile analytics platforms that track these connections, and CopyCat scams Tune, a leading global platform globally, to fraudulently earn its revenue.

Read the CopyCat research report

CopyCat hooks into the “startActivityLockedStub” in the system_server process, and monitors it to detect the launching of the Google Play process. Once launching the process, CopyCat retrieves the package name of the app that the user is viewing on Google Play, and sends it to its Command and Control server. The server sends back a referrer ID suited for the package name. This referrer ID belongs to the creators of the malware, and will later be used to make sure the revenue for the installation is credited to them.

CopyCat blocks all install_referrer intents and replaces them with its own referrer ID, which was received from the Command and Control server previously.

 Installing fraudulent apps

CopyCat also operates a separate module that conducts fraudulent app installations based on its root permissions. This module operates on a very low level of the Android operating system, taking advantage of Android’s package manager. The package manager monitors specific directories: /system/app and /data/app.

When an APK file appears in one of these directories, the package manager installs it. The malware makes use of this process, and copies the APK files of the fraudulent apps it wants to install to the /data/app directory, from which the package manager will install it. The malware verifies whether the app was installed, and reports the result to the Command and Control server.

A list of the top 12 countries hardest hit by the CopyCat malware campaignHow could CopyCat root so many devices?

CopyCat successfully rooted over 54% of the devices it infected, which is very unusual even with sophisticated malware. CopyCat uses several exploits as part of its operation: CVE-2014-4321, CVE-2014-4324, CVE-2013-6282 (VROOT), CVE-2015-3636 (PingPongRoot), and CVE-2014-3153 (Towelroot). All of these exploits, relevant for Android versions 5 and earlier, are both widely used and very old, with the most recent discovered more than two years ago. Even though patches for these exploits were released, CopyCat successfully used them to root eight million devices. These old exploits are still effective because users patch their devices infrequently, or not at all. Following the QuadRooter vulnerabilities, we learned that 64% of Android users have old security patches, leaving them exposed to attack strategies that have already been patched.

 How to stay protected

Cutting-edge malware such as CopyCat requires advanced protections, capable of identifying and blocking zero-day malware by using both static and dynamic app analysis. Only by examining the malware within context of its operation on a device can successful strategies to block it be created. Users and enterprises should treat their mobile devices just like any other part of their network, and protect them with the best cybersecurity solutions available.

Check Point customers are protected by SandBlast Mobile, and on the network front by Check Point Anti-Bot blade, which provides protection against this threat with the signature: Trojan.AndroidOS.CopyCat.

Protect your enterprise   |   Protect your personal device

The post How the CopyCat malware infected Android devices around the world appeared first on Check Point Blog.



from Check Point Blog http://ift.tt/2tVnOfS

Maersk says shipments back to normal next week after cyber attack

COPENHAGEN (Reuters) - Danish shipping giant A.P. Moller-Maersk expects container shipments to be back to normal early next week, it said on Thursday, as the impact of last week's cyber attack extends into its third week.


from Reuters: Technology News http://ift.tt/2uu6hbJ

The Real-World Impact of Bug Bounties and Vulnerability Research

Running the world’s largest vendor agnostic bug bounty program has afforded us the unique opportunity to purchase bugs of all varieties. The submissions to the Zero Day Initiative (ZDI) program range in severity from slightly annoying to hugely impactful. We wouldn’t have it any other way. Generally speaking, the goal of a bug bounty program is to acquire as many bugs as possible. What happens with the bugs once acquired changes depending on the bounty program. At the ZDI, we work not just to kill bugs, which is something we do at a higher rate than other organizations, but we also aim to disrupt the use of exploits used in advanced attacks.

Of course, detecting and defending against advanced persistent threats provides its own challenges. It’s rare that real-world scenarios are laid bare without a time of crisis response. Recently, the WikiLeaks dump of tools reportedly used by U.S. government agencies offered a prime example of the ZDI program altering attack methods. In fact, if the data provided by WikiLeaks is to be believed, the Central Intelligence Agency was forced to change their operational toolset for exploiting targets based on actions taken by the ZDI.

In 2010, the world was introduced to the Stuxnet virus after it caused substantial damage to centrifuges in the Iranian nuclear program. At its core, Stuxnet had three parts: a rootkit to hide itself, a worm to execute the main payload of its attack, and a link file that automatically executed to spread copies of the worm. Microsoft released several different security patches in response, including MS10-046, to address the vulnerability in link files. The patch enabled a whitelist check to ensure only approved files could be used, and many thought the implementation succeeded. However, according to the documents published on WikiLeaks, a tool called “EZCheese” exploited a similar bug in link files until 2015. That change resulted from a set of bugs coming through the ZDI program that showed the MS10-046 patch had failed. This forced a change of operational tactics to what was then an “unknown link file vulnerability (Lachesis/RiverJack) related to the library-ms functionality of the operating system.” Although not explicitly stated by Microsoft, this other link file bug was likely corrected with the release of CVE-2017-8464.

According to the released documents, both EZCheese and its successor Brutal Kangaroo were designed to attack air-gapped networks similar to Stuxnet. What some may not realize is that the link file could also be hosted on a remote drive viewable by the target.

When the ZDI acquires a bug, it isn’t just reported to the vendor for remediation. Information about the bug is provided to Digital Vaccine® Labs (DVLabs) within Trend Micro. They produce a DV filter for the vulnerability that allows TippingPoint customers to protect themselves while the vendor develops a patch for broader release. And yes, after deploying this filter (Digital Vaccine Filter 19340), hits were seen in Europe, South America, and Singapore. While it’s impossible to know the intent or full circumstances surrounding these filters being triggered, the low quantity indicates these were likely targeted attacks.

Earlier dumps from ShadowBrokers show this isn’t the first case of this happening. The vulnerability used by the exploit referred to as “Ewok Frenzy” was submitted to the ZDI program back in 2007. Even though a patch was made available for the exploit, it was reportedly used for almost a decade after our initial disclosure. Bug bounties show their value when they successfully kill vulnerabilities. Without a doubt, the ZDI program kills bugs. In fact, we’ve released 452 advisories this year (as of July 5) with 413 more in our upcoming queue. Each one represents a bug exposed to the light. In some cases, the exploit techniques required to exploit a bug can also be filtered. For example, another vulnerability listed in the documents, EasyBee, worked in the same manner as Ewok Frenzy, so the implemented DV filter covered both attacks.

You can question the veracity of these dumps or whether these exploits were ever actually in the wild, but the scramble by vendors to produce patches has been undeniable. The dumps show adversaries have a complexity and sophistication that requires constant vigilance from network defenders. It also shows how dedicated vulnerability research combined with a world-class bug bounty program increases security for everyone by changing the attack surface. While it’s true there is a difference between zero-day vulnerabilities and zero-day attacks, the value of having protection against bugs prior to their disclosure can’t be measured. The number of software bugs disclosed globally continues to increase year after year. The Zero Day Initiative will continue acquiring and researching zero-day vulnerabilities and working with vendors to increase the overall security posture of their products. We might not ever eliminate all government sponsored, marsupial-based exploits, but we sure can make it harder on them.



from Trend Micro Simply Security http://ift.tt/2stg28I

Russia jails hacker for spilling top government officials' secrets

MOSCOW (Reuters) - A Russian court sentenced a prominent hacker to two years in jail on Thursday after a secret trial which heard how he had accessed and leaked the email accounts of top government officials, Russian news agencies reported.


from Reuters: Technology News http://ift.tt/2sQqgzh

Dish, Amazon chiefs discuss wireless partnership: WSJ

(Reuters) - Dish Network Corp Chief Executive Charlie Ergen and Amazon.com Inc head Jeff Bezos have discussed a partnership to enter the wireless business, the Wall Street Journal reported, citing people familiar with the matter.


from Reuters: Technology News http://ift.tt/2tMqcVF

Watch Out for Malware If You're Interested in North Korean Missile Program

If you hold an interest in the North Korean Missile Program and are one of those curious to know capabilities of the recently tested North Korean long-range missile than you could be a target of a new malware campaign. North Korea claims to have conducted the first test of an intercontinental ballistic missile (ICBM), the Hwasong-14, on 3rd July, and US officials believe the country may have


from The Hacker News http://ift.tt/2utNaP6

Symantec to buy Israeli cybersecurity firm Fireglass

SAN FRANCISCO (Reuters) - Symantec Corp is acquiring Israeli cybersecurity startup Fireglass, the company said on Thursday, in a small deal designed to boost its products that protect corporate email and web browsing from threats.


from Reuters: Technology News http://ift.tt/2sPXRJA

ZDI-17-452: (0Day) Advantech WebOP Designer Project File Heap Buffer Overflow Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Advantech WebOP Designer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

from ZDI: Published Advisories http://ift.tt/2thbQeS

WordPress Statistics Cross Site Scripting

A XSS injection vulnerability exists in WordPress Statistics Plugin. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary commands on the affected system.

from Check Point Update Services Advisories http://ift.tt/2sCIOaQ

WordPress Statistics Plugin SQL Injection

An SQL injection vulnerability has been reported in WordPress Statistics Plugin. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.

from Check Point Update Services Advisories http://ift.tt/2sHNnvX

Samba Symlink Unauthorized File Access (CVE-2017-2619)

There exists a race condition vulnerability in Samba Symlink. This vulnerability is due to the way Symlink handles file access requests. A successful attack could lead to a file leak.

from Check Point Update Services Advisories http://ift.tt/2sluqzK

Microsoft Windows SMB Server SMBv1 Information Disclosure (CVE-2017-0271)

An information disclosure vulnerability exists in the SMB Server component of Microsoft Windows. The vulnerability is due to improper handling of SMBv1 requests. A remote, unauthenticated attacker could exploit the vulnerability by sending a crafted request to a target SMB server.

from Check Point Update Services Advisories http://ift.tt/2svX7xZ

Dell SonicWALL Scrutinizer methodDetail SQL Injection (CVE-2014-4977)

An SQL injection vulnerability exists in Dell SonicWALL Scrutinizer. A remote, authenticated attacker can exploit this vulnerability by sending a crafted request. Successful exploitation of this vulnerability can lead to arbitrary code execution in the context of SYSTEM for windows or as Apache for Linux on the target host.

from Check Point Update Services Advisories http://ift.tt/2tf6I9J

Scam URL With Multiple TLD

Many scam websites attempt to look like regular websites in order to steal information. One technique is to have multiple top level domains in the URL in order to confuse the user. A successful attack can lead to stolen information.

from Check Point Update Services Advisories http://ift.tt/2svdkDK

Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading

Cybersecurity researchers have uncovered a new phishing campaign that exploits social media private messages to propagate malicious payloads...