/* ---- Google Analytics Code Below */
Showing posts with label Malware. Show all posts
Showing posts with label Malware. Show all posts

Friday, May 12, 2023

Meta Says ChatGPT-Themed Malware Is Beginning to Spread

Meta Says ChatGPT-Themed Malware Is Beginning to Spread

It's a classic trick deployed by bad actors—latch onto the most recent buzzword to fool people into clicking on something.    By Josh Norem May 5, 2023  in Extremetech

One of the hallmarks of being a savvy PC operator is keeping your guard up for known threats. We're always careful about what we click on, what we download, and what sites we visit. Now we will need to add a new threat to our mental library, which appears related to the Internet's newest hot ticket item—ChatGPT. Meta has published a new threat advisory detailing actions it has taken lately on malware, and it rings the alarm bell on malware masquerading as OpenAI's ChatGPT chatbot.

The social media company's latest threat analysis warns about malware promising to provide some type of "AI functionality." It says so far, in 2023, it discovered 10 malware families disguised as a generative AI program that attempts to access people's accounts. The goal is to take over a computer so that it can run unauthorized ads from compromised machines. These ads are how they make money by making people buy fake software/malware.

These programs have been caught targeting file-sharing platforms, including Dropbox, Google Drive, Mega, MediaFire, Discord, Atlassian’s Trello, Microsoft OneDrive, and iCloud. In addition, phony browser extensions have also been spotted, even on official app stores. Though Meta doesn't name which stores, it's not hard to guess. These browser extensions are also promoted on both social media and paid search results, which is something we've seen before. ... ' 

Friday, March 17, 2023

ChatGPT Powered Polyorphic Malware Bypasses Filters

Security issues to be resolved. 

ChatGPT Powered Polymorphic Malware Bypasses Endpoint Detection Filters    By Guru- March 15, 2023

The number of monthly users of ChatGPT exceeded 100 million at the end of January, which sets a new record for the fastest-growing app since it was launched at the end of 2022.

OpenAI’s ChatGPT is a natural language processing tool that uses AI to process text and is developed by OpenAI. However, recent research revealed that ChatGPT could build code that can be used maliciously.

Jeff Sims, who works at the HYAS Institute, has created a polymorphic keylogger using artificial intelligence called “Blackmamba,” which uses Python to tweak its program randomly based entirely on the input that has been taken from the user.

As a result of Jeff’s malicious prompt, text-davinci-003 created a keylogger in Python 3. To accomplish this, Jeff had to use the python exec() function to “dynamically execute Python code at runtime.”

Writing Unique Python Scripts

Whenever ChatGPT / text-davinci-003 is called, a unique Python script is written for the keylogger. Consequently, as a result, it becomes polymorphic, making it harder for the EDRs to block the result.

In addition, the hackers could use ChatGPT to modify the code, resulting in a highly evasive code that was difficult to detect. 

Even they were also able to generate programs that could be used by ransomware and malware developers to launch attacks.

Jeff’s BlackMamba keylogger is being used to collect sensitive information over trusted channels, using MS Teams as a malicious communication platform.  .... ' 

Thursday, January 12, 2023

ChatGPT Is Enabling Script Kiddies to Write Functional Malware

Have heard this several times this week,   Not quite ready yet, but could go that way ...  Might as they say help.   A concern. 

ChatGPT Is Enabling Script Kiddies to Write Functional Malware

In Ars Technica, Dan Goodin, January 6, 2023

Participants in cybercrime forums, some with little or no coding experience, are using ChatGPT, an artificial-intelligent (AI) chatbot launched in November in beta form, to write potential malware, according to a report from security firm Check Point Research. One participant, for example, credited ChatGPT with providing a “nice [helping] hand” to what was claimed to be the first script that person had written. The script, Check Point researchers found, could "easily be modified to encrypt someone's machine completely without any user interaction." Check Point researchers themselves developed malware with full infection flow with the help of ChatGPT; they wrote, "The hard work was done by the AIs, and all that's left for us to do is to execute the attack."  ... '

Friday, July 29, 2022

Selling Zero Days?

Too weird, wouldn't it be directly caught doing this?

0-days sold by Austrian firm used to hack Windows users, Microsoft says

Windows and Adobe Reader exploits said to target orgs in Europe and Central America.

DAN GOODIN  in ArsTechnica

Microsoft said on Wednesday that an Austria-based company named DSIRF used multiple Windows and Adobe Reader zero-days to hack organizations located in Europe and Central America.

Multiple news outlets have published articles like this one, which cited marketing materials and other evidence linking DSIRF to Subzero, a malicious toolset for “automated exfiltration of sensitive/private data” and “tailored access operations [including] identification, tracking and infiltration of threats.”

Members of the Microsoft Threat Intelligence Center, or MSTIC, said they have found Subzero malware infections spread through a variety of methods, including the exploitation of what at the time were Windows and Adobe Reader zero-days, meaning the attackers knew of the vulnerabilities before Microsoft and Adobe did. Targets of the attacks observed to date include law firms, banks, and strategic consultancies in countries such as Austria, the UK, and Panama, although those aren’t necessarily the countries in which the DSIRF customers who paid for the attack resided.

“MSTIC has found multiple links between DSIRF and the exploits and malware used in these attacks,” Microsoft researchers wrote. “These include command-and-control infrastructure used by the malware directly linking to DSIRF, a DSIRF-associated GitHub account being used in one attack, a code signing certificate issued to DSIRF being used to sign an exploit, and other open source news reports attributing Subzero to DSIRF.”   ....(more) ...

Saturday, April 16, 2022

Energy Malware Sabotage

 Note link to PLCs, common in all industry. 

U.S. Warns Newly Discovered Malware Could Sabotage Energy Plants

The Washington Post, Joseph Menn, April 13, 2022

U.S. officials warn of newly discovered malware that could infiltrate industrial facilities and cause explosions at energy plants. Investigators said the Pipedream malware can target virtually any power plant by manipulating common equipment found in nearly all complex industrial plants, such as the programmable logic controllers (PLCs) that link industrial operations. Private security experts who analyzed Pipedream in tandem with government agencies suspect it is Russian and targets liquefied natural gas plants; they said building effective countermeasures would take months or years. Federal agencies are advising the energy sector and others to deploy monitoring programs, and to impose multifactor authentication for remote logins. ... ' 

Sunday, December 19, 2021

Malware Developers Turn to 'Exotic' Programming Languages to Thwart Researchers

Not sure I understand this.  Could be either way.  More experts likely to know advanced methods and patterns and thus more insight in finding malware?   Or is better to have a larger number of trainees doing the work, likely to find subtle security flaws. 

 Malware Developers Turn to 'Exotic' Programming Languages to Thwart Researchers

ZDNet, Charlie Osborne, July 27, 2021

Cybersecurity service provider BlackBerry's Research & Intelligence team has found that malware developers are increasingly employing "exotic" coding languages to foil analysis. A report published by the team cited an "escalation" in the use of Go (Golang), D (DLang), Nim, and Rust to "try to evade detection by the security community, or address specific pain-points in their development process." Malware authors are experimenting with first-stage droppers and loaders written in these languages to evade detection on a target endpoint; once the malware has bypassed existing security controls that can identify more typical forms of malicious code, they are used for decoding, loading, and deploying malware. The researchers said cybercriminals’ use of exotic programming languages could impede reverse engineering, circumvent signature-based detection tools, and enhance cross-compatibility over target systems..... ' 

Monday, November 08, 2021

Banking Malware Threats

Banking malware threats surging as mobile banking increases – Nokia Threat Intelligence Report

Press Release Banking malware threats surging as mobile banking increases – Nokia Threat Intelligence Report 8 November 2021 Espoo, Finland – The Nokia 2021 Threat Intelligence Report announced today shows that banking malware threats are sharply  .... ' 

Read in GlobeNewswire: https://apple.news/Aek0q2gjPRPW3S_iM0DNGQA

Saturday, August 21, 2021

Time to Remove Malware

Two Months to Remove Malware Apps from App Store     By New Scientist, August 19, 2021

An analysis by researchers at Boston University and the antivirus software company Norton found that it takes an average of 77 days from detection for Google to remove apps that potentially contain malware from the Google Play Store.   The researchers reviewed 8.8 million daily scans from 11.7 million users of antivirus apps, all on Android smartphones.  ... 

New Scientist Article

Sunday, August 08, 2021

The Target of Malware

 Am a recent user of Discord, so this surprised me.  But it is a way to get inside quickly.   Also note Sophos Labs, new to me.   Here just the intro.

Malware increasingly targets Discord for abuse

SophosLabs Uncut•Android malware•Discord•Information Stealers•Ransomware

Criminals abuse a successful chat service to host, spread, and control malware targeting their users.

22 JULY 2021

By Sean Gallagher, Andrew Brandt

Threat actors who spread and manage malware have long abused legitimate online services. As we found during our investigation into the use of TLS by malware, more than half of network traffic generated by malware uses TLS encryption, and 20 percent of that involved the malware communicating with legitimate online services.

During the timeframe of that research, we found that four percent of the overall TLS-protected malware downloads came from one service in particular: Discord. The growing popularity of the game-centric text and voice chat platform has not failed to draw the attention of malware operators.

Discord operates its own content delivery network, or CDN, where users can upload files to share with others. The service also publishes an API, enabling developers to create new ways to interact with Discord other than through its client application. We observed significant volumes of malware hosted in Discord’s own CDN, as well as malware interacting with Discord APIs to send and receive data. ... '

Sunday, July 25, 2021

Hiding Malware in Artificial Neurons

 My areas of interest have always included machine learning, neural networks, steganography and security.    So I read this in interest. Not sure how it would work in practice.  Following up.

(When I say I am following up, I may or may not include findings in latter posts at my discretion.  I will if I think its particularly useful.   Do let me know if you have interest) 

ACM NEWS

Researchers Hid Malware Inside an AI's 'Neurons' And It Worked Scarily Well   July 23, 2021

The authors concluded that a 178MB AlexNet model can have up to 36.9MB of malware embedded into its structure without being detected using a technique called steganography. ... 

Neural networks could be the next frontier for malware campaigns as they become more widely used, according to a new study. 

According to the study, which was posted to the arXiv preprint server  on Monday, malware can be embedded directly into the artificial neurons that make up machine learning models in a way that keeps them from being detected. The neural network would even be able to continue performing its set tasks normally.

"As neural networks become more widely used, this method will be universal in delivering malware in the future," the authors, from the University of the Chinese Academy of Sciences, write.

View Full Article

Wednesday, May 19, 2021

Malware Tricks

 Recorded Future, a podcast and text. With a look to the future of cybersecurity. This is an area where you are likely to see advanced tech applied, for good and bad.  

Malware Party Tricks and Cybersecurity Trends

APRIL 26, 2021 •  Caitlin Mattingly

This week we welcome back to our program security pioneer Graham Cluley. After starting his career writing the original version of Dr. Solomon’s Antivirus Toolkit for Windows, Graham moved on to senior positions at Sophos and McAfee. In 2011 he was inducted into the Infosecurity Europe Hall of Fame. These days, he’s an independent blogger, podcaster and media pundit.

Our conversation takes a sometimes nostalgic look back at the origins of computer malware, what it was like fighting the good fight back then, how things have developed over the years, and what he thinks the future may hold.   ... " 

Wednesday, February 03, 2021

More on Solarwinds Malware

Schneier provides more 'Solarwinds' News this morning,  lots of links to other analyses and opinions. Including some suggestions for addressing these kinds of threats, but as yet untested.   Includes analyses by big targets/players in security, like Microsoft and Google.   Worth following for updates. 

Tuesday, December 22, 2020

More on SolarWind: A Kill Switch

 FireEye on the SolarWind backdoor, from last week.

And work by Microsoft on the problem:

FireEye, Microsoft create kill switch for SolarWinds backdoor  By Lawrence Abrams in BleepingComputer

Microsoft, FireEye, and GoDaddy have collaborated to create a kill switch for the SolarWinds Sunburst backdoor that forces the malware to terminate itself.

This past weekend it was revealed that Russian state-sponsored hackers breached SolarWinds and added malicious code to a Windows DLL file used by their Orion IT monitoring platform.

This malicious DLL is a backdoor tracked as Solarigate (Microsoft) or Sunburst (FireEye) and was distributed via SolarWinds' auto-update mechanism to approximately 18,000 customers, including the U.S. Treasury, US NTIA, and the U.S. Department of Homeland Security.  

As part of a coordinated disclosure with Microsoft and SolarWinds, FireEye released a report on Sunday with an analysis of the supply chain attack and how the Sunburst backdoor operates.  This research revealed that the Sunburst backdoor would connect to a command and control (C2) server at a subdomain of avsvmcloud[.]com to receive 'jobs', or commands to execute. ... " 

(as the article suggests, the malware may have created other backdoors, so this will not necessarily remove the problem) 

Sunday, September 06, 2020

Ransomware Attacks more Sophisticated

Continued concern of these, facilitated by the openness of our systems to external manipulation.  what is the solution?    The ability to detect particular kinds of patterns of activity that will lead to massive changes in value.   Nice discussion in the FortiGuard doc linked to below:

Ransomware attacks grow in sophistication, according to latest report from FortiGuard Labs  By Mark Albertson in SiliconAngle

When it comes to ransomware attacks, newly released information from FortiGuard Labs shows that the malware’s quality is higher than ever before.

The latest semiannual “FortiGuard Labs Global Threat Landscape” report, released in August, showed that attacks on internet of things and operational-technology devices were “evolving to become more targeted and more sophisticated.”

This was not good news for firms like fitness tracking manufacturer Garmin Inc., which reportedly paid $10 million last month in a recently disclosed ransomware attack.

“We’ve seen things like Master Boot Record, or MBR, ransomware,” said Derek Manky (pictured, left), chief of security insights and global threat alliances at FortiGuard Labs. “This is persistent; it sits before your operating system when you boot up your computer, so it’s hard to get rid of it. It’s prolific, and we’re seeing not only ransomware attacks for data, we’re starting to see ransom for extortion, for targeted ransom cases that are going after critical business.”   .... " 

Monday, June 15, 2020

Baking Anti-Malware into CPUs

Continued back and forth, the article is skeptical about how well this will work.  But something must be done,

Intel will soon bake anti-malware defenses directly into its CPUs
Control-Flow Enforcement Technology will debut in Tiger Lake microarchitecture.
By Dan Goodin in ArsTechnica

The history of hacking has largely been a back-and-forth game, with attackers devising a technique to breach a system, defenders constructing a countermeasure that prevents the technique, and hackers devising a new way to bypass system security. On Monday, Intel is announcing its plans to bake a new parry directly into its CPUs that’s designed to thwart software exploits that execute malicious code on vulnerable computers.

Control-Flow Enforcement Technology, or CET, represents a fundamental change in the way processors execute instructions from applications such as Web browsers, email clients, or PDF readers. Jointly developed by Intel and Microsoft, CET is designed to thwart a technique known as return-oriented programming, which hackers use to bypass anti-exploit measures software developers introduced about a decade ago. While Intel first published its implementation of CET in 2016, the company on Monday is saying that its Tiger Lake CPU microarchitecture will be the first to include it. ... "

Friday, April 24, 2020

Zoom Continues the Climb, with New Vulnerability

Looks to be something that can be easily patched once understood.    Now that Zoom is under the microscope, this is a good thing.

Zoom passes 300M daily users as new security vulnerability discovered

By Duncan Riley in SiliconAngle

Zoom Video Communications Inc. continues to surge in popularity during the COVID-19 pandemic even as yet another security vulnerability has been revealed.

Chief Executive Officer Eric Yuan revealed during a webinar on April 22 that the company now has more than 300 million daily users, up 50% from 200 million users it had at the beginning of the month.

“Clearly, the Zoom platform is providing an incredibly valuable service to our beloved users during this challenging time,” Yuan said. “We are thrilled and honored to continue to earn the trust of so many enterprises, hospitals, teachers and customers throughout the world.”

Zoom has been the No. 1 app of the pandemic, with millions using the videoconferencing service as they’re forced to work from home. After surging to the top of app charts in March, Zoom still remains at the top on both iOS and Android, according to data from App Annie.

With that popularity has come increased scrutiny over its security and Zoom has struggled. Various security vulnerabilities have been uncovered and there’s yet a new one.

Detailed Wednesday by Daniel Petrillo at Morphisec Technologies Ltd., the newly discovered vulnerability in the Zoom app allows potential attackers to record Zoom sessions and capture text chats without the knowledge of meeting participants...... ' 

Thursday, February 20, 2020

Microsoft Defender Expands

Been a user of Defender for some time now, as long as it has been available..  It seems to work,   at least in the fact that no malware has gotten through recently, that I know about.   Good to have multiple capabilities at work.

Microsoft’s Defender security software is coming to iOS and Android
It’s available for Linux today.    By  Christine Fisher, @cfisherwrites in Engadget

Despite Apple and Google's best efforts, malware and malicious apps are still a big concern on iOS and Android. So today, Microsoft announced that it's bringing its Defender Advanced Threat Protection (ATP) to the mobile operating systems. In other words, Microsoft is stepping in to fix a problem that Apple and Google can't seem to resolve.   .... " 

Friday, October 11, 2019

The Future of Malicious Online Activity

Recent events have been troublesome here.     We like to trust our machines, but the more autonomous and 'intelligent' they are,  leads to lest trust and more complexity.  Malware can use autonomy and intelligence as well.   Data can be used to determine where it is coming from and the patterns of its use.

Decade of Cybersecurity Data Could Predict Future Malicious Online Activity
CSIRO (Australia)   By Chris Chelvan

Researchers from Australia’s Commonwealth Scientific and Industrial Research Organization (CSIRO) Data61 digital research network and Macquarie University, in collaboration with Nokia Bell Labs and the University of Sydney, have developed a comprehensive dataset of the global cybersecurity threat landscape from 2007 to 2017. The purpose of the FinalBlacklist dataset is to help cybersecurity specialists derive new insights on cybersecurity threats, and potentially predict future malicious online activity. The team collected 51.6 million reports of such malicious online activity involving 662,000 unique IP addresses worldwide. The data was categorized using machine learning techniques into six classes: malware, phishing, fraudulent services, potentially unwanted programs, exploits, and spamming. Said Macquarie University’s Dali Kaafar, "Our analysis revealed a consistent minority of repeat offenders that contributed a majority of the mal-activity reports. Detecting and quickly reacting to the emergence of these mal-activity contributors could significantly reduce the damage inflicted.”  ...' 

Tuesday, July 23, 2019

Secure Cloud Architecture for Smart Cities

Having seen how municipalities are being attacked by malware, this is becoming essential.

A Secure Cloud Architecture for Smart Cities
Government Computer News
Stephanie Kanowitz   Syracuse University
July 11, 2019

Syracuse University researchers have issued a new blueprint designed to help smart cities and communities create a hybrid cloud architecture that upholds confidentiality, access control, least privileges, and security of personally identifiable information. The Smart City and Community Challenge cloud privacy security rights inclusive architecture action cluster developed the framework, which is designed to back up critical systems in the event of attacks. The architecture employs a three-tiered data/risk classification scheme, with workflows applied to data depending on its classification. Officials then assign probability, impact, and overall ratings to each risk, and install mitigation controls. The researchers first tested the architecture by applying it to a network of city-owned smart streetlights in Syracuse, NY; other projects under consideration for the architecture include catch-basin monitoring and water-metering projects, in addition to others involving the ethics of artificial intelligence, facial recognition, and machine learning.  ... " 

Friday, July 19, 2019

Will Malware Use AI?

 Very Likely.  Should we also be looking for the traces of AI online to identify Malware?   Fraud?   Scams?  While this example is about malware. Consider that malware is just some code that takes advantage of a context, data, architecture and results to provide an advantage.  Ultimately this will be AI vs AI.  Need to be ready for that.

Report sees peril in cybercriminals’ looming use of AI
By Paul Gillen in SiliconAngle

A new report this week by anti-malware vendor Malwarebytes Inc. paints an ominous picture of the potential impact of artificial intelligence technologies such as machine learning and deep learning once criminals have the skills and incentive to use them.
That hasn’t happened yet, but the report’s authors suggest it could be as little as a year or two before AI-powered malware makes its way into the wild.

“Almost by definition, cybercriminals are opportunistic,” the report noted. “You only need one smart cybercriminal to develop malicious AI in an attack for this method to catch on."

Malwarebytes Lab Director Adam Kujawa drew an analogy to ransomware, which was detected as early as 2010 but was considered only a screen-locking nuisance until 2013, when Cryptolocker debuted with the ability to encrypt files. “Suddenly we saw a lot of variants emerging,” Kujawa said. “For the most part we don’t see a move by criminals en masse until one version completely destroys its target.

In the short term, the advantage is to the good guys, who are using AI to supplement human labor. In the field of malware, for example, machine learning can be used to create “smart detections that can capture future versions of the same malware, or other variants in the same malware family,” the report’s authors note.  ... "