Custom Search

A new ransomware trojan variant with children pornography

We wrote about the ransomware trojan (aka BKA Trojan) and its new methods of blackmailing people to pay: claim in the name of an official institution that the user did something illegal, like storing children pornography pictures on his computer.

The new variant of the BKA trojan attempts to blackmail the owners of infected computers …

Lock, stock and two smoking Trojans-2

It has been three years since we published Lock, stock and two smoking Trojans in our blog. The article describes the first piece of malware designed to attack users of online banking software developed by a company called BIFIT. There are now several malicious programs with similar functionality, including:

Trojan-Spy.Win32.Lurk Trojan-Banker.Win32.iBank Trojan-Banker.Win32.Oris Trojan-Spy.Win32.Carberp Trojan-Banker.Win32.BifiBank Trojan-Banker.Win32.BifitAgent …

Boston Aftermath

While many are still in shock after the Boston Marathon bombings on 16 April, it didn’t take long for cyber criminals to abuse that tragic incident for their dirty deeds.

Today we already started receiving emails containing links to malicious locations with names like “news.html”. These pages contain URLs of non-malicious …

Backdoor Uses Evernote as Command and Control Server

With its rich functionality and accessibility, Evernote is a popular note-taking tool users. Unfortunately, it may also provide the perfect cover for cybercriminals’ tracks.

We recently uncovered a malware that appears to be using Evernote as a communication and control (C&C) server. Detected as BKDR_VERNOT.A, the malware attempted to connect to Evernote via https://evernote.com/intl/zh-cn, which …

Early Version of MiniDuke Ran on Chinese Time

Bitdefender antimalware researchers have come across samples of a previously-unrecognized version of the MiniDuke virus which, as it turns out, was active as early as May 2012 – and it wants to know what time it is in China.

Incoming search terms for the article: miniduke …

Fake Antivirus Renewal Email Rises from the Dead

Over the last few years, many reports, white papers, and blogs have been released detailing targeted attacks. For example, some attacks employ sophisticated infection methods, such as watering hole attacks, and some rely on exploit code hidden in document files mixed with social engineering schemes. Some time ago, when the malware world was still …

Malware spammed out widely posing as income tax email

A malware campaign has been spammed out widely, seemingly taking advantage of an important date in the US tax system’s calendar.

January 31st is the deadline for US employers to deliver the W-2 form to all of their workers, used to help calculate the total wages earned by an individual during the course of the year.

So, …

The BKA/Ransom Trojan comes now with child pornography

The so called “BKA Trojan” (BKA stands for German Federal Criminal Police) malware which is also known as the Ransom trojan in other countries, has found a more convincing way to fool computer users to pay. Now, together with other eight possible misdeeds,  the user is accused of hosting and distributing child pornography materials from his computer. …

God horses are floating clouds: The story of a Chinese banker Trojan

In China these days, e-commerce has become an important part of daily life, especially among young people. According to a report from CNNIC (China Internet Network Information Center), the number of Chinese e-commerce users reached 242 million at the end of the December 2012. This is nearly half of all Chinese internet users.

Because of …

Malicious Spam Emails Target Nightclub Disaster in Santa Maria

Tweet

Symantec Security Response has observed that spammers are distributing malicious emails that attempt to lure users into viewing a video of the incident that killed 233 people recently in a horrific tragedy at a popular nightclub in Santa Maria, Brazil. The malicious email is in Portuguese and invites unsuspecting users to click on …

Downloader Targets Down Under

At the time of this blog post, and for the past five days, we have noticed an increase in spam containing malware that targets Australians. The attackers behind this malicious spam campaign appear to have no specific target in mind other than compromising a large base in Australia for reasons still unknown. Symantec Security Response …

Unsophisticated Wiper Malware Makes Headlines

Iran CERT recently announced that it uncovered a possible targeted attack using a malware that wipes files that will run on certain predefined time frame. They noted its efficiency in performing its routines despite its simplistic design.

The way this malware was created was also deemed unusual, as the author wrote a series of batch files …

The post might not bring exactly what you expect for Christmas

With the holidays and presents season approaching, most of us are thinking what presents to order for Christmas. Many people prefer to order them online than to spend hours chasing presents in a mall. I know I am one of those…

This fact is also known by cyber criminals who are doing anything to get …

Fake delivery notification gets confused, has nice lie down

Looks like some scammers had a bit of a mix-up while counting out their cash on a gold plated yacht.

Click to Enlarge

Here’s the contents of the mail. The text in bold is a not-very-subtle clue:

“The UPS Office“:

Order: SD-5468-482485468 Order Date: Monday, 2 December 2012, 11:23 AM Dear …