Custom Search

The “Red October” Campaign – An Advanced Cyber Espionage Network Targeting Diplomatic and Government Agencies

Here’s a link to the full paper (part 1) about our Red October research. During the next days, we’ll be publishing Part 2, which contains a detailed technical analysis of all the known modules. Please stay tuned.

During the past five years, a high-level cyber-espionage campaign has successfully infiltrated computer networks at diplomatic, …

Java 0day Mass Exploit Distribution

Just a quick note, it’s only the second week of January, but early 2013 brings with it the first Java 0day mass exploit distribution of the year.

There appears to be multiple ad networks redirecting to Blackhole sites, amplifying the mass exploitation problem. We have seen ads from legitimate sites, especially in the UK, …

Browser Add-ons Add Fraudulent Data

Contributor: Wahengbam RobinSingh

Phishers continue to devise diverse strategies to improve their chances of harvesting users’ confidential information. Symantec constantly monitors and keeps track of these phishing trends. In November 2012, Symantec observed a phishing site that loaded a malicious browser add-on. The malicious add-on, if installed, would lead users to phishing sites even when a …

Romanian Google, Yahoo Users Redirected to Defacement Page

Earlier today, visitors of web pages associated with Google and Yahoo search were instead being redirected to a defacement page.

Preliminary investigation reveals that neither Google, nor Yahoo servers have been hacked or otherwise compromised. Instead, the attackers have somehow changed the authoritative DNS records for the affected domains (which are maintained by registrar RoTLD) …

Dancing Penguins – A Case of Organized Android Pay Per Install

For years, cyber criminals have organized their operations and traded resources through discussion forums and auction sites. One popular item to trade is access to virus infected PCs for cash. These trading schemes are often called pay-per install (PPI) programs. We have recently started an investigation on a new type of pay-per install program, this …

Botnet command server hidden in Tor

The analyzed bot:

Despite the novel way of C&C-communication, the other features of the analyzed bot are quite common these days. It offers several possibilities for DDoS attacks, can download and execute other malware, and can act as SOCKS proxy to anonymize the attacker.

What is it about?

One of the biggest challenges …

Russian Android Gangs Keep Scamming Along

It's been a while since we looked at the Android malware space (I think the last one was here), so when someone asked about it yesterday, I pulled up some log traffic to take a look.

It looks like Russia and China continue to be hotbeds for unofficial app download sites, where you're definitely taking …

The “Nitro” Campaign and Java Zero-Day

The security community has been focused on the new Java zero-day exploits that appear to have been taken from a Chinese exploit pack (known as Gondad or KaiXin) used in targeted attacks by the “Nitro” cyber-espionage campaign and then incorporated into criminal operations using the BlackHole Exploit Kit. While the connections between these developments are …

80% of “Olympic” domains are scams and spam

Today we looked at all identified domains containing the string “olympics“, which had been accessed by our customers over the course of a day. It turns out that 80% of them are scams or spam and they can be classified into three main categories.

Typo squatting

Spammers can take advantage of users making mistakes when typing …

“Your Photos” spam / moskow-carsharing.ru

This terse spam leads to malware on moskow-carsharing.ru:

From: [redacted] Sent: venerdi 3 agosto 2012 17:09 To: [redacted] Subject: Your Photos

Hi, your photos – http://www.[redacted].com/upload.htm

 The malicious payload is at [donotclick]moskow-carsharing.ru:8080/forum/showthread.php?page=5fa58bce769e5c2c (report here) hosted on the following IPs:

67.227.183.77 203.80.16.81 213.170.99.11

The following domain names are also related and should be blocked:

ipadvssonyx.ru leprisoruim.ru …

yg-network.org / Keyya Ltd domain scam

This is part of a domain scam that has been going on for years..

from:     Angela info@gytrademark.com to:     sales@[redacted].com date:     3 August 2012 03:21 subject:     Notice of Internet Intellectual Property

Dear Manager,

(If you are not the person who is in charge of this, please forward this to your CEO,Thanks)

This email is from China …

?RunForestRun?, ?gootkit? and random domain name generation

Recently, we came across web malware that - instead of injecting an iframe pointing to a fixed existing address - generates a pseudo-random domain name, depending on the current date. This approach is not new and is widely used by botnets in C&C domain name generation, yet it’s not very common for the web malware we?ve seen …

MapleSoft Customers Targeted By Attackers Following Data Breach

Over the last few weeks, there have been reports of various websites that have had their databases breached and customer data stolen by attackers through various means. A lot of the focus has been on how password dumps have been appearing online. There has always been the concern that attackers who obtain access to customer …

The end of DNS-Changer

FBI’s “Operation Ghost Click” was discussed earlier by my colleague Kurt here and here and now it comes to an end.

Next Monday, 9th of July, at 06:00 (MEZ) the temporary DNS-servers setup by FBI will be shut down. But still there are still thousands of infected machines – one can wonder, what will happen …

Pseudorandom domain name generation and the Blackhole exploit kit

In this post I want to highlight one of the script injections we have been tracking for the past month or so, which is being used to redirect web traffic to exploit sites (running the Blackhole exploit kit). Two factors make this particular script injection worthy of discussion, namely:

large scale attacks. Many legitimate sites …