Showing posts with label attacks. Show all posts
Showing posts with label attacks. Show all posts

Thursday, July 16, 2020

Trend Micro Research Discovers Botnet Battle for Home Routers


Trend Micro Incorporated, a global leader in cybersecurity solutions, today released new research warning consumers of a major new wave of attacks attempting to compromise their home routers for use in IoT botnets. The report urges users to take action to stop their devices from enabling this criminal activity.

There has been a recent spike in attacks targeting and leveraging routers, particularly around Q4 2019. This research indicates increased abuse of these devices will continue as attackers are able to easily monetize these infections in secondary attacks.

"With a large majority of the population currently reliant on home networks for their work and studies, what's happening to your router has never been more important," said Jon Clay, director of global threat communications for Trend Micro. "Cybercriminals know that a vast majority of home routers are insecure with default credentials and have ramped up attacks on a massive scale. For the home user, that's hijacking their bandwidth and slowing down their network. For the businesses being targeted by secondary attacks, these botnets can totally take down a website, as we've seen in past high-profile attacks."

Trend Micro's research revealed an increase from October 2019 onwards in brute force log-in attempts against routers, in which attackers use automated software to try common password combinations. The number of attempts increased nearly tenfold, from around 23 million in September to nearly 249 million attempts in December 2019. As recently as March 2020, Trend Micro recorded almost 194 million brute force logins.

Another indicator that the scale of this threat has increased is devices attempting to open telnet sessions with other IoT devices. Because telnet is unencrypted, it's favored by attackers – or their botnets – as a way to probe for user credentials. At its peak, in mid-March 2020, nearly 16,000 devices attempted to open telnet sessions with other IoT devices in a single week.

This trend is concerning for several reasons. Cybercriminals are competing with each other to compromise as many routers as possible so they can be conscripted into botnets. These are then sold on underground sites either to launch Distributed Denial of Service (DDoS) attacks, or as a way to anonymize other attacks such as click fraud, data theft and account takeover.

Competition is so fierce that criminals are known to uninstall any malware they find on targeted routers, booting off their rivals so they can claim complete control over the device.

For the home user, a compromised router is likely to suffer performance issues. If attacks are subsequently launched from that device, their IP address may also be blacklisted – possibly implicating them in criminal activity and potentially cutting them off from key parts of the internet, and even corporate networks.

As explained in the report, there's a thriving black market in botnet malware and botnets-for-hire. Although any IoT device could be compromised and leveraged in a botnet, routers are of particular interest because they are easily accessible and directly connected to the internet.

Trend Micro makes the following recommendations for home users:

Make sure you use a strong password. Change it from time to time.
Make sure the router is running the latest firmware.
Check logs to find behavior that doesn't make sense for the network.
Only allow logins to the router from the local network.

Thursday, October 1, 2009

Banks, social networks new target for computer viruses

Cyber criminals are increasingly focusing their attacks on the hundreds of millions of users of social networks and on loopholes in bank security systems, security software vendors said on Wednesday. At the same time, spam e-mail messages rose sharply in the third quarter, Symantec Corp said.

And as Facebook reached 300 million accounts in September, social networks and social media continued to attract criminals, smaller research firm F-Secure said in its quarterly virus report. "As Twitter has grown in popularity, it has been increasingly targeted by worms, spam and account hijacking," F-Secure said.

Cyber criminals choose targets that are widely used, allowing them to go after the largest number of potential victims. "Cyber criminals continue to follow the money," said Yuval Ben-Itzhak, technology chief at a small security software vendor Finjan, who on Wednesday revealed a new method criminals use to steal money from bank accounts and hide their tracks.

Finjan said it expects a growing trend of using new software that forges on-screen bank statements, concealing the true transaction amount to dupe account holders and their banks, and then sends the stolen money to money mules accounts.

"With the combination of using sophisticated Trojans for the theft and money mules to transfer stolen money to their accounts, they minimize their chances of being detected," Ben-Itzhak said.

The amount of spam in all e-mail traffic rose to 88.1 percent in the third quarter from 81 percent a year ago, said Symantec's MessageLabs in its quarterly report. MessageLabs said botnets are now responsible for sending 87.9 percent of all spam. Hackers take advantage of the PC vulnerability by booby- trapping websites with a malicious code that loads onto computers.

Infected PCs are commandeered into a botnet, a network of hijacked computers. They are used for identity theft, spamming and other cyber crimes. "Over the past year, we have seen a number of ISP's (Internet service providers) taken offline for hosting botnet activity resulting in a case of sink or swim and an ensuing shift in botnet power," MessageLabs analyst Paul Wood said in a statement.

"However, this won't always be the case as botnet technology has also evolved since the end of 2008 and the most recent ISP closures now have less of an impact on resulting activity as downtime now only lasts a few hours rather than weeks or months as before," Wood said.

Agencies

Saturday, April 25, 2009

Has Conficker attacked thousands of PCs globally?

A malicious software programme known as Conficker that many feared would wreak havoc on April 1 is slowly being activated, weeks after being dismissed as a false alarm, security experts said.

Conficker, also known as Downadup or Kido, is quietly turning thousands of personal computers into servers of e-mail spam and installing spyware, they said.

The worm started spreading late last year, infecting millions of computers and turning them into "slaves" that respond to commands sent from a remote server that effectively controls an army of computers known as a botnet.

Its unidentified creators started using those machines for criminal purposes in recent weeks by loading more malicious software onto a small percentage of computers under their control, said Vincent Weafer, a vice president with Symantec Security Response, the research arm of the world's largest security software maker, Symantec Corp.

"Expect this to be long-term, slowly changing," he said of the worm. "It's not going to be fast, aggressive."

Conficker installs a second virus, known as Waledac, that sends out e-mail spam without knowledge of the PC's owner, along with a fake anti-spyware program, Weafer said. The Waledac virus recruits the PCs into a second botnet that has existed for several years and specializes in distributing e-mail spam.

"This is probably one of the most sophisticated botnets on the planet. The guys behind this are very professional. They absolutely know what they are doing," said Paul Ferguson, a senior researcher with Trend Micro Inc, the world's third-largest security software maker.

He said Conficker's authors likely installed a spam engine and another malicious software program on tens of thousands of computers since April 7.

He said the worm will stop distributing the software on infected PCs on May 3 but more attacks will likely follow. "We expect to see a differen
t component or a whole new twist to the way this botnet does business," said Ferguson, a member of The Conficker Working Group, an international alliance of companies fighting the worm.

Researchers had feared the network controlled by the Conficker worm might be deployed on April 1 since the worm surfaced last year because it was programmed to increase communication attempts from that date. The security industry formed the task force to fight the worm, bringing widespread attention that experts said robably scared off the criminals who command the slave computers.

The task force initially thwarted the worm using the Internet's traffic control system to block access to servers that control the slave computers. Viruses that turn PCs into slaves exploit weaknesses in Microsoft's Windows operating system. The Conficker worm is especially tricky because it can evade corporate firewalls by passing from an infected machine onto a USB memory stick, then onto another PC.

The Conficker botnet is one of many such networks controlled by syndicates that authorities believe are based in eastern Europe, Southeast Asia, China and Latin America.

Agencies

Thursday, November 27, 2008

Mumbai attacks: Are other cities not vulnerability?

Whatever group lies behind the attacks in Mumbai, security experts say one thing has been made abundantly clear: a massive city can be reduced to mayhem if a group of men is well-enough armed and prepared to die.

Rather than hijacking planes as in September 11, or smuggling delicately wired car bombs into a city, the Mumbai gunmen chose a frontal style of armed assault, killing more than 100 people, wounding around 250 and causing immense panic in a thriving city of 13 million.

Security specialists say the attack was probably months in the planning and appears to have been finely tuned in its execution, but it ultimately relied on only an estimated 25 gunmen lightly armed with assault rifles and hand-grenades.

Their ability to roam around and sustain the attack, while all the while being willing to die in the onslaught, made it all the more difficult to combat and far more drawn out than an instantaneous suicide bomb attack might have been.

"It's virtually impossible to stop 20 guys with guns from attacking anywhere in the world if they are prepared to die," said Sajjan Gohel, an analyst with the Asia-Pacific Foundation, an independent security and intelligence group based in London.

"That is the thing about the fedayeen strategy," he said, using an Arabic term used to describe self-sacrificial gunmen who have operated in Iraq, Kashmir and across the Muslim world.

"It's even more effective than a suicide mission. With a suicide mission, you blow up your explosives and you're gone. With a fedayeen attack, you try to last out as long as possible, killing as many people as possible," he told Reuters.

Nearly 20 hours after the attack began late on Wednesday night, Indian soldiers and the militants were still exchanging gunfire and more than 100 people were trapped inside the Taj Mahal hotel, one of two five-star hotels popular with Western tourists and businessmen that were targeted in the assault.

Indian authorities closed stock, bond and foreign exchange markets, schools were shuttered and panicked foreigners on holiday or on business were desperate to flee, reducing India's business powerhouse to a tense, semi-warzone.

"Men armed with automatic weapons are able to run amok and keep the situation going for much, much longer," Henry Wilkinson, a senior analyst with Janusian Security Risk Management, a London-based consultancy, told Reuters.

"Whether it's intended or not, that creates an extended drama which is all the more terrifying."

AL QAEDA

Given the boldness of the assault, its high-level of planning and the fact that foreigners were specifically targeted, security specialists believe there is likely to have been a degree of inspiration from or link to external groups allied to Al Qaeda, such as the Pakistan-based Lashkar-e-Taiba.

They say the tactics are different from the more common, post-9/11 attacks seen in Iraq and Afghanistan, but still bear similar hallmarks.

"It's very interesting that they didn't go in using car bombs, it was more of a direct armed assault on a city," said Wilkinson. "It's very reminiscent of the attacks in Saudi Arabia in 2003, when the gunmen were going around trying to find Westerners and kill them."

Wilkinson highlighted the fact the Mumbai gunmen appeared to have used only assault rifles and hand-grenades, giving them much more mobility and freeing them up to take hostages.

"I would suggest that using guns and hand-grenades was a deliberate choice... The amount of planning and training they must have done to carry out such an attack is impressive."

Such an assault might be mounted virtually anywhere in the world, he said, making cities in Europe and the United States vulnerable, even if such an outcome remains unlikely.

In London in 2005 four suicide bombers killed 52 people on public transport and brought the city to a standstill.

Both attacks underline just how hard it is for democratic states to protect themselves against such attacks without draconian security measures and powerful intelligence.

"I can't see any reason -- if there is a terrorist group that has the capability... attacks like this in Europe or the United States can't be discounted," he said.

One advantage for Indian authorities and any intelligence services called in to help investigate the Mumbai attacks is that at least nine gunmen are reported to have been seized.

In a suicide bombing, forensics can help investigators establish only so much. In this case, those detained are likely to reveal much more intelligence about who plotted the attack.

"The fact that a few of them have been seized is highly significant," said Wilkinson. "I think a lot more information about these attacks and who was behind them is going to come to light."

Source: Reuters

Total Pageviews