Custom Search

New rogue security products to watch out for

Fake AV operators continue to change the graphic interface design on their malicious creations.

Clones we’ve seen recently include “XP Antispyware Pro 2013,” “XP Defender 2013,” “XP Security 2013″ and “XP Antivirus Pro 2013.”

Download pages are detected by at least three AVG LinkScanner signatures.

Since this is the time of year that legitimate AV …

Android Malware Family Downloads Paid Media and Apps

We spotted a family of Android malware that downloads apps and paid media files without users’ consent, leaving victims with unwanted charges. These are Trojanized versions of the legitimate weather forecast tool GoWeather and are detected by Trend Micro as ANDROIDOS_TROJMMarketPlay.

During our research, we acquired three samples of this malware family. One of the samples …

What the FBI didn’t tell us about the hotel malware threat

If you follow the field of computer security chances are that you saw the warning issued by the FBI’s Internet Crime Complaint Center (IC3) this week about using hotel internet connections.

Here’s the full text of the advisory, with some responses sprinkled throughout from yours truly:

Malware Installed on Travelers’ Laptops Through Software Updates on Hotel …

New Mass Injection Wave of WordPress Websites on the Prowl

The Websense® ThreatSeeker® Network has detected a new wave of mass-injections of a well-known exploit that we've been following in Security LabsTM for months. The majority of targets are Web sites hosted by the WordPress content management system. At the time of writing, more than 200,000 Web pages have been compromised, amounting to close to 30,000 …

Gift card mania: Fake Starbucks gift cards spreading on Facebook can lead to malware – More and more scamsters misuse popular brands to lure users to visit their websites

The fake campaign is spreading via Facebook walls around the globe. The texts used in the announcements are English, which increases the chance that a large number of Facebook users accept the “bait message”.

Starbucks has been used in a similar campaign already last year and they warned their customers not to …

Cybercriminals Leverage Whitney Houston’s Death

News of Whitney Houston’s sudden demise spread like wildfire in the Internet. Countless tweets, Facebook wall posts, and news items circulated regarding the singer’s death at age 48. Given the massive attention that Houston’s death generated, cybercriminals are naturally out there taking advantage of this unfortunate incident.

We have uncovered two web threats shortly after …

One-Click Billing Fraud Scheme Through Android App Found

In the past we’ve reported about one-click billing fraud schemes starting to target smartphone users. The scheme, as its name suggests, tricks a victim into registering and paying for a certain service after being falsely led to a specific website. The past attack we saw involved a website wherein target victims were asked to pay …

Malicious script blocks browsers on iPhone, iPad and iPod touch

Doctor Web’s engineers received a number of requests from iPad users who were troubled by blocking pop-up windows displayed as they visited certain sites in Safari and other browsers. Investigation into the problem revealed that pop-ups were brought up by malicious JavaScript code embedded into web-pages by criminals.

Earlier Doctor Web issued a report about …

Spammers Leverage Amy Winehouse’s Death to Send Virus

The five-time Grammy award winner Amy Winehouse was found dead in London on July 23rd. Symantec has already observed spammers who are trying to capitalize on related news headlines by sending out malicious threats less than a day after the news was released.

The two samples given below are examples that we have observed. …

Just Click No-On Facebook Scams

The scam waves in Facebook continue, as expected. For example the recent “brother raped his sister” theme has been changed a bit and sent along for a new run on the social network.

It’s the same content that has been used with similar themes over the last few weeks, only the scammers have just added …

Krebs/Danchev Trojan Pushes Adult Website

Complete malware analysis is often limited by real-world circumstances.

Many of the trojans that we analyze will attempt to connect to a remote server for further instructions. At this point, we know that the software is not legitimate and should be blocked from installation on our customer’s computers. We don’t really need to examine it …

Spyware celebrates Google’s 13th birthday!

Websense Security Labs® ThreatSeeker® network has noticed a typosquatting activity targeting google.com. Typosquatting is a popular Internet behavior that generates domain names based upon misspelling famous brand names. It is often abused by scammers to host malware and phishing content on these misspelled domains. Apparently, the Anticybersquatting Consumer Protection Act(ACPA)  was enacted in 1999 to fight …