Are you the publisher? Claim or contact us about this channel


Embed this content in your HTML

Search

Report adult content:

click to rate:

Account: (login)

More Channels


Showcase


Channel Catalog


Channel Description:

Internet security threat updates and insights.

older | 1 | (Page 2) | 3 | 4 | .... | 40 | newer

    0 0

    By Nathan Collier Earlier this year, the SMS Trojan Foncy was discovered targeting French-speaking Android Users. Now, we’ve come across a new Trojan targeting them using a similar SMS scam.  The app pretends to be an app called BlackMart Alpha, which is already a little shady since it’s used to download apps that may otherwise [...]

    nathancolliernathancollier

    11

    22

    33

    0 0

    By Dancho Danchev Think you’ve received an online greeting card from 123greetings.com? Think twice! Over the past couple of days, cybercriminals have spamvertised millions of emails impersonating the popular e-card service 123greetings.com in an attempt to trick end and corporate users into clicking on client-side exploits and malware serving links, courtesy of the Black Hole [...]

    ddanchevddanchev

    Spam_123greetings_exploits_malware_BlackHole_exploit_kitSpam_123greetings_exploits_malware_BlackHole_exploit_kit

    Spam_123greetings_exploits_malware_BlackHole_exploit_kit_01Spam_123greetings_exploits_malware_BlackHole_exploit_kit_01

    Spam_123greetings_exploits_malware_BlackHole_exploit_kit_02Spam_123greetings_exploits_malware_BlackHole_exploit_kit_02

    0 0

    By Joe McManus Last week Adobe announced that they would no longer be supporting Flash for Android. Adobe will be removing Flash from the Android Marketplace and users should be wary of fake Flash apps for their Android Devices.  Now to be fair to Adobe, they are not taking flash away from the Android platform [...]

    armandoorozcoarmandoorozco

    flash_example1aflash_example1a

    flash_example1_websiteflash_example1_website

    flash_example2flash_example2

    flash_example3flash_example3

    0 0

    By Dancho Danchev Remember the IRS (Internal Revenue Service) themed malicious campaign profiled at Webroot’s Threat Blog earlier this month? Over the past 24 hours, the cybercriminals behind the campaign resumed mass mailing of the same IRS email template, exposing millions of users to the threats posed by the social engineering driven campaign. More details: [...]

    ddanchevddanchev

    IRS_spam_malware_exploits_Black_Hole_Exploit_KitIRS_spam_malware_exploits_Black_Hole_Exploit_Kit

    IRS_spam_malware_exploits_Black_Hole_Exploit_Kit_01IRS_spam_malware_exploits_Black_Hole_Exploit_Kit_01

    0 0

    By Dancho Danchev Over the last couple of hours, cybercriminals have started spamvertising millions of emails pretending to be coming from HP ScanJet scanner, in an attempt to trick end and and corporate users into downloading and viewing the malicious .html attachment. Upon viewing, the document loads the invisible iFrame script, ultimately redirecting the user [...]

    ddanchevddanchev

    HP_ScanJet_email_spam_exploits_malware_Black_Hole_Exploit_KitHP_ScanJet_email_spam_exploits_malware_Black_Hole_Exploit_Kit

    0 0

    By Dancho Danchev British users, beware! Cybercriminals are currently mass mailing millions of emails impersonating the Royal Mail Service in an attempt to trick users into executing the malicious attachment found in the email. Once they do so, the malware opens a backdoor on the targeted hosts allowing cybercriminals to take complete control over the [...]

    ddanchevddanchev

    RoyalMail_spam_email_malwareRoyalMail_spam_email_malware

    0 0

    By Dancho Danchev Over the past 24 hours, cybercriminals have spamvertised millions of emails impersonating Intuit Market, in an attempt to trick end and corporate users into clicking on the malicious links found in the emails. Upon clicking on them, users are exposed to the client-side exploits served by the Black Hole web malware exploitation [...]

    ddanchevddanchev

    Intuit_spam_email_exploits_malware_Black_Hole_Exploit_KitIntuit_spam_email_exploits_malware_Black_Hole_Exploit_Kit

    0 0

    By Dancho Danchev Cybercriminals are currently spamvertising millions of emails impersonating PayPal, in an attempt to trick PayPal users into executing the malicious attachment found in the emails. Using ‘Notification of payment received‘ subjects, the campaign is relying on the end user’s gullibility in an attempt to infect them with malware. Once executed, it grants [...]

    ddanchevddanchev

    PayPal_spam_payment_notification_malwarePayPal_spam_payment_notification_malware

    0 0

    By Dancho Danchev Cybercriminals are currently mass mailing millions of emails impersonating the United Parcel Service (UPS) in an attempt to trick users into downloading and executing the malicious file hosted on a compromised web site. More details: Sample screenshot of the spamvertised email: Spamvertised URL: hxxp://buzzstar.co.uk/JUVNEFNQVI.htm Actual download location of the malicious archive: hxxp://buzzstar.co.uk/Label_Copy_UPS.zip [...]

    ddanchevddanchev

    UPS_Print_Shipping_Label_spam_malwareUPS_Print_Shipping_Label_spam_malware

    0 0

    By Dancho Danchev Over the past 24 hours, cybercriminals started spamvertising millions of emails impersonating the United Parcel Service (UPS) in an attempt to trick end and corporate users into previewing a malicious .html attachment. Upon previewing it, a tiny iFrame attempts to contact a client-side exploits serving a landing URL, courtesy of the Black [...]

    ddanchevddanchev

    UPS_Wire_Transfer_Spam_Email_Malware_Black_Hole_Exploit_KitUPS_Wire_Transfer_Spam_Email_Malware_Black_Hole_Exploit_Kit

    0 0

    By Dancho Danchev It didn’t take long before the cybercriminals behind the recently profiled ‘Intuit Marketplace’ themed campaign resume impersonating Intuit, with a newly launched round consisting of millions of Intuit themed emails. The theme this time? Convincing users that in order to access QuickBooks they would have to install the non-existent Intuit Security Tool. [...]

    ddanchevddanchev

    Intuit_Spam_Email_QuickBooks_Exploits_Malware_Black_Hole_Exploit_KitIntuit_Spam_Email_QuickBooks_Exploits_Malware_Black_Hole_Exploit_Kit

    0 0

    By Dancho Danchev Remember the recently profiled 123greetings.com themed malicious campaign? It appears that over the past 24 hours, the cybercriminals behind it have resumed spamvertising millions of emails pointing to additional compromised URls in a clear attempt to improve their click-through rates. More details: Sample screenshot of the spamvertised email: Sample screenshot of the [...]

    ddanchevddanchev

    123greetings_ecards_spam_exploits_malware_Black_Hole_Exploit_Kit123greetings_ecards_spam_exploits_malware_Black_Hole_Exploit_Kit

    123greetings_ecards_spam_exploits_malware_Black_Hole_Exploit_Kit_01123greetings_ecards_spam_exploits_malware_Black_Hole_Exploit_Kit_01

    0 0

    By Dancho Danchev Cybercriminals are masters of abusing legitimate infrastructure for their malicious purposes. From phishing sites and Black Hole exploit kit landing URLs hosted on compromised servers, abuse of legitimate web email service providers’ trusted DKIM verified ecosystem, to the systematic release of DIY spamming tools utilizing a publicly obtainable database of user names [...]

    ddanchevddanchev

    Skype_SMS_Flooder_DIY_ToolSkype_SMS_Flooder_DIY_Tool

    0 0

    By Dancho Danchev What happens when a cybercriminal cannot efficiently gain access to thousands of working accounts at popular Web services, either through data mining a botnet’s population, or through phishing campaigns? He’ll just start systematically abusing the legitimate services by automatically and efficiently registering thousands of bogus accounts, thanks to the easy to use [...]

    ddanchevddanchev

    Bogus_Accounts_For_SaleBogus_Accounts_For_Sale

    Bogus_Accounts_For_Sale_01Bogus_Accounts_For_Sale_01

    Bogus_Accounts_For_Sale_02Bogus_Accounts_For_Sale_02

    0 0

    PHP is an incredibly popular language for creating dynamic web applications — websites such as Facebook are built on it. This can be attributed to many reasons; it is easy to learn, easy to install and does not require the user to compile code. An unfortunate side effect of the ease of development with PHP [...]

    jmcmanuswebrootjmcmanuswebroot

    ImageImage

    securecodingexample2securecodingexample2

    0 0

    No matter what people think about it, the increasing exposure of Linux and OS X to malicious code is strictly related to the worldwide exposure of those operating systems on desktops and laptops. In the last couple of years, more and more home users decided to switch to Linux (e.g. Ubuntu Linux, just to name [...]

    eraserpxeraserpx

    Wirenet searching for sqlite databaseWirenet searching for sqlite database

    Wirenet taking screenshots on OSXWirenet taking screenshots on OSX

    Keylogging on LinuxKeylogging on Linux

    Shell bindingShell binding

    0 0

    By Dancho Danchev Over the past 24 hours, cybercriminals have launched yet another massive spam run, this time impersonating FedEx in an attempt to trick its customers into clicking on a malware and exploits-serving URL found in the malicious email. More details: Screenshot of the spamvertised email: Screenshot of a sample Java script obfuscation: Sample [...]

    ddanchevddanchev

    FedEx_spam_email_malware_exploits_Black_Hole_Exploit_kitFedEx_spam_email_malware_exploits_Black_Hole_Exploit_kit

    FedEx_spam_email_malware_exploits_Black_Hole_Exploit_kit_01FedEx_spam_email_malware_exploits_Black_Hole_Exploit_kit_01

    FedEx_Spam_Email_Exploits_Malware_Malicious_DomainsFedEx_Spam_Email_Exploits_Malware_Malicious_Domains

    FedEx_Spam_Email_Exploits_Malware_Malicious_Domains_01FedEx_Spam_Email_Exploits_Malware_Malicious_Domains_01

    0 0

    By Dancho Danchev In order to emphasize on the growing trend of cybercriminals abusing legitimate infrastructure for their malicious purposes, last week, I profiled a DIY SMS flooder using Skype’s SMS-sending capability to launch a DoS (denial of service attack) against a user’s mobile device. This week, I’ll continue providing factual evidence for the emergence [...]

    ddanchevddanchev

    ICQ_DIY_SMS_FlooderICQ_DIY_SMS_Flooder

    0 0

    By Dancho Danchev Cybercriminals are currently spamvertising millions of emails impersonating U.S Airways, in an attempt to trick users into clicking on the malicious links found in the legitimately looking emails. Let’s dissect the malicious campaign, and expose its dynamics. More details: Sample screenshot of the spamvertised US Airways themed email: Spamvertised compromised URL: hxxp://raintree.on.ca/depdetails.html [...]

    ddanchevddanchev

    US_Airways_spam_email_malware_exploits_Black_Hole_Explot_kitUS_Airways_spam_email_malware_exploits_Black_Hole_Explot_kit

    0 0

    By Brenden Vaughan A new zero-day vulnerability exploit has been identified in Microsoft’s Internet Explorer web browser versions 9 and below running on Windows XP, Vista and 7. Internet Explorer 10, which comes bundled with Windows 8, is not affected. The exploit could allow remote execution of malicious code from compromised websites. Referred to as [...]

    glhaldemanglhaldeman

older | 1 | (Page 2) | 3 | 4 | .... | 40 | newer