Threat Lab

Girl Scouts and OpenText empower future leaders of tomorrow with cyber resilience

The transition to a digital-first world enables us to connect, work and live in a realm where information is available at our fingertips. The children of today will be working in an environment of tomorrow that is shaped by hyperconnectivity. Operating in this...

World Backup Day reminds us all just how precious our data is

Think of all the important files sitting on your computer right now. If your computer crashed tomorrow, would you be able to retrieve your important files? Would your business suffer as a result? As more and more of our daily activities incorporate digital and online...

3 Reasons We Forget Small & Midsized Businesses are Major Targets for Ransomware

The ransomware attacks that make headlines and steer conversations among cybersecurity professionals usually involve major ransoms, huge corporations and notorious hacking groups. Kia Motors, Accenture, Acer, JBS…these companies were some of the largest to be...

How Ransomware Sneaks In

Ransomware has officially made the mainstream. Dramatic headlines announce the latest attacks and news outlets highlight the staggeringly high ransoms businesses pay to retrieve their stolen data. And it’s no wonder why – ransomware attacks are on the rise and the...

An MSP and SMB guide to disaster preparation, recovery and remediation

Introduction It’s important for a business to be prepared with an exercised business continuity and disaster recovery (BC/DR) plan plan before its hit with ransomware so that it can resume operations as quickly as possible. Key steps and solutions should be followed...

Podcast: Cyber resilience in a remote work world

The global pandemic that began to send us packing from our offices in March of last year upended our established way of working overnight. We’re still feeling the effects. Many office workers have yet to return to the office in the volumes they worked in pre-pandemic....

5 Tips to get Better Efficacy out of Your IT Security Stack

If you’re an admin, service provider, security executive, or are otherwise affiliated with the world of IT solutions, then you know that one of the biggest challenges to overcome is efficacy. Especially in terms of cybersecurity, efficacy is something of an amorphous...

How Cryptocurrency and Cybercrime Trends Influence One Another

Typically, when cryptocurrency values change, one would expect to see changes in crypto-related cybercrime. In particular, trends in Bitcoin values tend to be the bellwether you can use to predict how other currencies’ values will shift, and there are usually...

Are antivirus testing scores a true reflection of our Mac product efficacy? You decide…

In a world full of new malware and various types of cyber threats continuing to pop up on a daily basis, the average consumer has reached a point where a good antivirus security solution is an absolute must; even when dealing with so called “immune” operating systems like Mac OSX. However with so many antivirus products to choose from for the Mac, how is the average consumer supposed to make sound decisions about which product will give them the best protection and the greatest peace of mind?

These days, most consumers in the market for a new product simply jump on Google and look for general product reviews; however with so many mixed results, and an array of product features to choose from and compare, the antivirus playing field can quickly become very confusing and overwhelming. As an alternative, another source of information that consumers turn to for data about antivirus solutions are third party antivirus (AV) testing companies. For years these companies have performed baseline comparative tests on many of the most popular AV products in an effort to test the product’s malware detection and remediation capabilities, as well as looking at how machine performance is affected by the product being installed and run on the user’s machine. In recent years they have also started to do testing for AV products being developed for the Mac OSX platform. The results of these tests are typically published with an overall bottom-line score for each product being tested, which is based on the product’s overall malware/virus detection percentage.

As a result, the average consumer looking at these tests will use some type of previous brand recognition or family/friend influence, in conjunction with the AV testing scores, in order to make a swift decision on the “best” antivirus software for their needs. It is easy for the human psyche to say, “Oh this product scored 100%, so it must be good.” The issue with this type of decision making process is that unfortunately the assumption is made that all AV products are created equal, and that the Mac AV testing platform and testing methodology creates a true simulation of real world execution and installation of the malware being tested. This could not be further from the truth.

In order to test the true efficacy of an antivirus product, AV testing companies should actually be installing the malware and executing the viruses in question, in order to see how the antivirus product handles an actual simulation of an end-user infection. Unfortunately, the reality of the situation is that AV testing companies generally do not use “real world” simulations of malware executions and installs when testing Mac AV products. Instead they perform their tests using a method called “zoo testing,” which involves putting hundreds of malicious file samples into a folder and then putting that folder somewhere on the testing PC before running their test. Often these files do not even reside inside of the full Mac bundles necessary for execution or have even had their executable bit stripped from the binary, in effect making them benign to any system. The issue here is that none of the malware is actually executed or installed on the testing machine, nor does it constitute any kind of real threat to the system. In addition, this type of approach is often easily “gamed” by AV companies that are simply looking to do well on the test.

Without getting too technical, in recent years advancing technologies in the antivirus industry have continued to make leaps and bounds in terms of the detection and remediation methods and backend systems that are being used to detect malicious activity and protect end users from security breaches on their machines. Webroot has been a pioneer in implementing technologies that are forward-thinking, adaptive and have brought our product efficacy to unprecedented levels. Unfortunately, in order to actually be correctly tested on the effectiveness of these newer methods and technologies, it requires AV testing companies to install real infections, rather than a zoo of files that can’t even be executed. AV testing companies have been reluctant to adapt their Mac testing methodologies to changing technologies and approaches. So, what does this say about the validity of AV test scores? Does this approach make AV testing results a useful tool for sound consumer decision making when deciding on a Mac security solution?

AV testing has been a big concern for many companies over the years. We all want our products to perform at a high level and carry a positive market leading reputation. For many AV companies this has been true to the extent that they focus their primary client development efforts towards malware detection for AV tests, rather than real life infections. Isn’t this approach a detriment to the effectiveness of the product for the end-user? Here at Webroot, due to known issues in the AV testing climate, we have shifted priorities in order to drive our efforts and innovation into developing the best security products and customer experience that we can attain. We believe that our excellent standard for real world efficacy, in addition to the many value added features that are built into our products, bring the greatest value to our customer base.

10 Tips for Improving Your Home Router Security

With the recent news of router vulnerabilities, we thought it would be an excellent time to provide a few tips for improving your home router security. While nothing is hack-proof in the world we live in, you can take many steps to deter attackers from targeting you. I have arranged this from easy to do, to increasingly technical.

Simple steps to secure your home router

  • Create a unique login. Most routers use a default login username such as “admin”, and a password that is usually just “password”. Be sure to change the login information (username and password) to something unique to you. Please note that this is different than your WiFi name and password.
  • Create a username and password for your connection (WiFi). Consider changing it from the default to something that is not personally identifiable. Ideally, you DO NOT want your the manufacturer (Netgear. Linksys, etc.) or address as your WiFi name. Choosing WPA2 over WPA or WEP is also advisable. A long passphrase as your password that contains more than 20 characters is important here. REMINDER: you can disable the SSID broadcast so that only users that know your network name can connect. If you plan on having guests, create an entirely different Guest network. It is never advisable to give the credentials to your main connection.
  • Avoid using WiFi Protected Setup (WPS). WPS is a nice convenience, but it leaves your WiFi network vulnerable. Malicious actors can use this to attempt connection with a PIN, possibly leaving you open to brute-force attacks.
  • Keep router firmware up-to-date. Unlike your computer, your router doesn’t send reminders for new updates. It will be up to you to make sure you’re logging into your router regularly to check for updates.

 

Don't Get Hacked

More complex security tips

  • Disable Remote Administrative Access. In addition, consider disabling administrative access over Wi-Fi. An Admin should only be connecting via a wired Ethernet connection.
  • Change the default IP ranges. Almost every router has an IP resembling 192.168.1.1 and changing this can help prevent Cross-Site Request Forgery (CSRF) attacks.
  • Restrict access via MAC addresses. Your router gives you the capability to specify exactly what devices you want to connect so that others are not permitted. You can usually identify the address of the specific device in the Admin Console of the router.
  • Change from the standard 2.4-GHz band, to the 5-GHz band. If the devices you use are compatible, it is generally advisable to make this change. Taking this step will decrease the range of the signal and could stop a potential attacker that is farther away from your router from discovering it.
  • Disable Telnet, PING, UPNP, SSH, and HNAP. You can close them entirely, but I generally advise putting them into what is referred to as “Stealth” mode. This stops your router from responding to external communications.
  • Log out! This does not just apply to routers, though. You should log out of any website, utility, or console when you are done using it.

These router security tips should help protect your WiFi data from cybercriminals desiring to hinder your online activities.

Tech Support Scams Continue

We’re regularly asked about phone calls from “Microsoft” claiming that your computer is infected, and whether or not it is a scam – it is. Sometimes it’s a call from another “tech support” company, or a warning message on your screen. The truth is that Microsoft and other companies will not contact you to tell you that you have a computer problem through a phone call, email, or a pop-up warning message.

These scams are nothing new. We blogged about this previously in April of 2013 and a lot has changed in the malware world since then, but these scams continue. That we’re bringing these scams up again tells you one thing though – people continue to fall for them – don’t let yourself become a victim of one of these scammers.

If you’re contacted by one of these scammers, hang up, don’t click that link, and don’t call that number. Usually they’ll try to get them to let you access your computer remotely – don’t let them, and certainly don’t give them any personal information or a credit card number.

As long as you don’t let them log on to your computer remotely or download and install any software because of these scams you probably don’t have anything to worry about. These scammers don’t typically install malware on your computer; the scam is to get you to pay for tech support that you don’t actually need.

More information can be found on scams using the Microsoft name at the following links:

http://www.microsoft.com/security/online-privacy/msname.aspx

http://www.microsoft.com/security/online-privacy/avoid-phone-scams.aspx

http://www.microsoft.com/security/online-privacy/avoid-phone-scams.aspx

Dow Jones Data Breach

In a letter to customers sent today, Dow Jones & Co has revealed that its services were breached, possibly exposing the credit and debit card information of customers. Reportedly only impacting “fewer than 3,500 individuals,” the information provided shows that the unauthorized accesses took place between August 2012 and July 2015.

“In today’s world – where literally anyone connected to the Internet is vulnerable – it’s no longer just a question of spending, it’s a question of processes and skills. Following the Dow Jones breach, I’m heartened that the CEO has publically said that no company is immune to cyberattacks. Solely recognizing that all organizations need comprehensive security solutions is the first step to reducing the onslaught of breaches we’ve witnessed over the last few years,” said Grayson Milbourne, Security Intelligence Director of Webroot.

“As large company breaches have revealed, security isn’t always a question of budget but also a question of skills and background checks. The name of the game is to find out what is going on in an environment and reduce the risk. Overall, there is a clear trend of attacks that aim to compromise companies who store vast amounts of user data. These businesses need to prepare for continued attacks by updating their security policies and systems to be on high alert.”

While Dow Jones & Co is reporting the information has been possibly compromised, they are also reporting that no evidence is pointing toward the information actually being used in authorized manners.

Avoid Unwanted Applications

Has your home page changed? Are you getting pop-up ads that are “Provided by” some company you’ve never heard of? Are your search results coming from a different search engine? Welcome to the world of Potentially Unwanted Applications (PUAs.) While they can be annoying, PUAs are easily avoided.

The easiest way to avoid PUAs is to only install programs from their official download sites. Third-party download sites continue to be one of the main sources for PUAs. If you search for software downloads, chances are you will end up on a third-party site rather than an official download page and end up inadvertently installing PUAs.

When installing software, always pay attention to the install process – don’t just click “next” until the install is complete. Most installers allow you to opt-out of installing optional software, but they don’t always make it easy. Pay attention to any available install options, and always choose a custom install when possible. Watch for “skip” or “decline” buttons that will allow you to not install bundled applications. Look for check boxes that ask you if you want to install additional applications of change your home page or search settings. If you follow these suggestions it will help you to avoid installing PUAs.

Phishing Attacks and Lessons Learned

Phishing attacks have been a prevalent, and often quite successful method of obtaining sensitive data from unsuspecting victims for quite a few years now. These attacks are extremely common through email and usually only require the user to click on a link contained within, and enter the information requested. Due to the simplicity of obtaining potentially valuable data from users, many companies have been instituting security training  for these types of attacks by using phishing tests to determine their employees’ ability to discern a real email from a possible phish.

With the latest breach coming from the United States’ Office of Personnel Management, the question remains of what could have been done to prevent such a high-security organization from making a simple mistake that could be catastrophic? The answer seems to be increasing the amount of security training that is taking place within these organizations, in regards to phishing attacks and basic online security.

Unfortunately, many users continue to fail these types of tests, while still holding high-level security clearance. This is likely due to the lack of reprisal for the user, aside from more security training sessions, which allows the poor behaviour to carry on. Paul Beckman, CISO for the Department of Homeland Security, has a different idea about consequences for these individuals, who are often senior managers or other C-level employees. He states, “Someone who fails every single phishing campaign in the world should not be holding a TS SCI with the federal government”, and suggests that these employees should have their security clearance removed until such time that they can prove to be responsible with extremely sensitive information.

Beckman said he hopes to move forward with the discussion of cracking down on repeat offenders, but it will all take more time and getting more CISOs on board. Meanwhile, these types of attacks are becoming more personal and thus, more difficult to prevent against.

With other companies able to learn lessons based off the circumstances surround the OPM hack though, we hope too see a continued shift towards education and understanding from the largest corporations down to the standard internet user. Maintaining awareness and understanding of the threats on the internet, especially effective ones such as phishing, is the first step in moving towards safer browsing habits.

History of Mac Malware

The subject that fan boys of each side love to argue about.  Mac malware.  The fact is that malware for Mac is real and it continues to grow as a problem.  In 2012 Apple removed the statements “It doesn’t get PC viruses” and “A Mac isn’t susceptible to the thousands of viruses plaguing Windows-based computers.”  I would like to shed light on the malware from beginning to now in hopes that it will bring an understanding of why security is needed on all operating systems, including your Mac.

macmalware11982 – The first threat that occurred was the Elk Cloner (this however did not actually affect the Mac) which would cause the Apple II to boot up with a poem:

Elk Cloner: The program with a personality

It will get on all your disks
It will infiltrate your chips
Yes, it’s Cloner!

It will stick to you like glue
It will modify RAM too
Send in the Cloner!

1987-2003

There were a few different malware families that came out but being as they are using an operating system that is not really used I won’t go into great detail.  In 1987 nVIR virus began to infect Macintosh computers.  In 1988 HyperCard viruses started to gain traction. HyperCard was software created by Apple to execute scripts immediately on opening.  MDef was discovered in 1990.  MDef infected application and system files on the Mac.  In 1995 Microsoft released a virus that would infect both PC and Mac users via Microsoft Word called Concept.  In 1996 Laroux, the first Excel macro virus was found but didn’t actually do anything to Macs until Excel ’98 was released.  In 1998 Both AutoStart 9805 and Sevendust were discovered.

2004-Present – This brings us into the modern operating system we all know and love OS X. Also the time frame where threats are created that can still affect systems in use today.

2004 – Renepo was found. It had the ability to disable a system firewall, and it would try to copy itself to /System/Library/StartupItems.

macmalware22004– Amphimix a program which is also a MP3 file. When launched it displays a dialog box which reads “Yep, this is an application. (So what is your iTunes playing now?)” It then loads itself into iTunes as an MP3 file called “Wild Laugh”, playing four seconds laughter.

 

macmalware32006 – Leap is widely considered to be the original Mac Trojan. Leap used iChat to spread itself; forwarding itself as a latestpics.tgz file to the contacts on the machine. Inside the Gzipped Tar File (.tgz) was an executable file masked as a JPEG. When executed, it infected all Cocoa applications.

2006 – Inqtana was the second worm for Mac OSX. The worm propagated through a vulnerability in unpatched OSX systems.

2008 was a big year for Mac malware… Apple published an advisory to use antivirus software. They removed the statement from its website after being up for about two weeks.

2008 – BadBunny is a multi-platform worm written in several scripting languages and distributed as an OpenOffice document containing a macro.  It spreads itself by dropping script files that affect the behavior of popular IRC (Internet Relay Chat) programs, causing it to send the worm to other users.

2008 – RSPlug is a Trojan that changed DNS to send users to malicious servers. It originally spread as a video codec that was downloaded from various porn websites.

2008 – AppleScript.THT tries to disable security software, steal user’s passwords, turn on file sharing, take screenshots of the desktop, and take a photo of the user via the built-in camera.  The malware exploits a vulnerability with the Apple Remote Desktop Agent, which allows it to run as root.

macmalware42008 – MacSweeper, Mac’s first ‘rogue’ application (a fake antivirus misleading users by reporting infections that doesn’t exists). When the infected user tried to remove the “infections”, MacSweeper asked to provide credit card details and pay $39.99 for a “lifetime subscription serial key.”

I won’t lie, before I got into threat research, I ended up with this on my Mac…

2008 – Hovdy tried to install itself to /Library/Caches. It disabled syslog/system updates, stole password hashes, open ports in the firewall, disabled security software, installed LogKext keylogger and started web server, VNC, and SSH. It also tried to get root access by way of ARDAgent vulnerability.

2009 – Iservice was discovered in a pirated version of iWork ’09. It copied itself to /usr/bin/iWorkServices and tried to execute a HTTP request. Updated variants were later found in a pirated versions of many high use programs.

August 28, 2009 – Apple released an anti-malware tool called XProtect,at release it could protect a Mac against only two threats (RSPlug and Iservice).

2010 – HEllRTS (aka HellRaiser) is a Trojan that allows control of a computer by a remote user. The remote user has the ability to transfer files, pop up chat messages, display pictures, and even restart or shut down the infected machine.

2010 – Boonana, a Trojan that spread via social media and email disguised as a video. It runs as a Java applet, which downloads its installer to the machine.  After installed it starts running in the background and communicating with a variety of servers such as command and control servers.

2011 – MacDefender, another rogue like MacSweeper that installs itself into the /Application folder and wants you to pay them for the “infections” to be removed from your mac.

macmalware52011/2012 – Flashback was disguised as a Flash player download and targets a Java vulnerability on Mac OS X. The system is infected after the user is redirected to a compromised bogus site, where JavaScript code causes an applet containing an exploit to load. The Flashback malware was the largest attack to date, hitting more than 600,000 Mac computers.

2013 – Lamadai, a backdoor Trojan, targeted NGOs (Non-Government Organizations) and exploited a Java vulnerability to drop further malware code.

2013 – Hackback spied on victims and was designed to take a list of certain file types, find all files matching those types, compress them into a zip located in /tmp/ and upload them to a remote server.

2014 – LaoShu went viral via spam emails posing as a notification from FedEx. It contacts a remote server sending system information, files, and screenshots. It is important to note that it is signed with a valid Apple developer ID certificate.

2014 – CoinThief is designed to steal Bitcoins from infected machines, and is disguised as legitimate apps.  The source code was on Github for a while under an app named StealthBit.

macmalware6

It’s worth mentioning that these have been the main threats seen on the Mac and not all of them.  There are many smaller variants and proof of concepts that are not listed.  Also, that I didn’t include any adware variants such as Genieo or VSearch on here, but I did write about in my last blog.  Even after seeing all of these there will still be those that refuse to believe that their mac is vulnerable to attack, but trust me it will only get worse from here.  Apple is increasing their market share and with that comes an opportunity for malware writers to make more money.

The most difficult question in computer security

Whenever I think of security awareness, there is one question that haunts me: How do we educate the not-so-technically inclined about security? It seems like a simple enough question, we know the basic tips and tricks, it’s second nature to many of us. Keeping Windows fully patched and up to date pretty much takes care of itself with the proper settings in Windows Update. Many other applications check for updates regularly by default. Running antivirus software should be a no-brainer and if you run a cloud-based AV solution like Webroot SecureAnywhere you don’t even need to worry about updates.

Then you try to explain how to identify a suspicious email to that friend or family member that always comes to you for computer support. You came prepared with sample emails complete with circles and arrows and highlighted text. You explain how to  check email headers, hover over links to check where they actually go, and look for obvious spelling and grammatical errors. To the non-techie this can seem like a bunch of techno-babble that they will not remember.

The technical approach is simply not going to work on some people. Yo can suggest treating any email that they were not expecting to receive, is from an unknown sender, and contains a link or an attachment as suspicious. This can work, but has it’s own issues. People order products over the internet all the time. Order and shipment confirmation emails are something people expect, so when someone receives a fake email claiming to be from a shipping company it can be quite effective. These emails may be obviously suspicious to you, but you said to be suspicious of emails that they were not expecting, remember? It tends to just get more complicated from there. We want to educate and help develop healthy suspicions, not distrust and paranoia.

So how do we explain how to identify a suspicious email in simple terms that even the less technical people can understand? This is a question that we need to continue to ask ourselves, and we each need to do our part in educating others on security issues.

As a note, tomorrow begins National Cyber Security Awareness Month and with that, we will be posting regular security tips to keep you and your family safe while online.

Heartbleed continues to put devices at risk

Over a year has now passed since we were first alerted to a flaw in the OpenSSL cryptography library, widely used in the implementation of Transport Layer Security (TLS) protocol. The bug CVE-2014-0160, was quickly dubbed “Heartbleed” (http://heartbleed.com/) after a missing bounds check in the TLS heartbeat extension. Despite the passing of time and the high profile nature of the flaw, IoT crawler Shodan has recently discovered the vulnerability still exists on over 200,000 internet connected devices.

Shodan (http://www.shodanhq.com/) launched in 2009, is a search tool that seeks out internet-of-things (IoT) and other internet connected devices collecting the information returned by these devices to build up a picture of what services are being offered. The data can then displayed in a variety ways including by geo-region breakdown. This is great tool for IT and security teams and unfortunately also for the bad guys.

Many people will deem 200,000 vulnerable devices on the internet as unacceptable, and in many ways it is. At the same time I think it is important for us all to understand why this happens and why there is currently no easy fix. I believe we will see vulnerabilities like Heartbleed in the wild for many years to come. Whereas I do believe there is a certain level of ignorance to the threat, I also believe there are many other factors.

There are users who aware their devices are vulnerable, not realizing their device uses the buggy version of OpenSSL, or even uses SSL for communication. There will be others that haven’t heard of Heartbleed and many not understanding the tech details, the fix, or the ramifications. Sometimes putting two and two together is little more difficult that we’d like to think. Hey, we are asking users to understand and fix their devices, when at present they still haven’t changed the device’s default admin password – even worst, they’ve not realized their device is even connected to the internet.

Ignorance and even arrogance with regards to the lack of patching has been observed. Not patching a device when possible, believing it is unlikely to be exploited is simply not acceptable. We need to move away from setup and configure once, then leave alone. Users need to research, revisit and understand the devices on the network and especially those connected to the internet.

Search engines like Shodan mean that susceptible devices are less likely to go under the radar – it also highlights the appetite the business and personal sector have for security. Once the configuring and setup of these devices required a certain skill level. That’s all changed now, especially with WPS and other technologies, many devices are completely ‘plug and play’. The complexities of such systems are hidden from the user – even if patches are available for said devices, I very much doubt many users would know how to install them.

There are also many manufacturers that focus on the delivering of ‘cheap’ affordable technology, OEM and unbranded to an untrained eye in many cases. These cheaper offerings normally come at a price – limited aftercare. Put simply you’ll be lucky to ever see manufactures release new firmware and software updates after purchasing and that’s if the vendor still exists.

The mobile phone industry has used a similar business model for years, after a while updates stop, if they even started – meaning customers will need to go out and purchase the a new handset/hardware to have the latest and most secure software. What we are left with is millions of vulnerable internet connected devices. Most devices, especially legacy devices, the ones most likely to be at risk have no OTA (over the air) update capabilities, many do not even include a manual update feature – many are not even capable of running the newer firmware and software.

There’s a lot of bad news, but it doesn’t mean a certain level of protection cannot be offered – something the Shodan results are unable to factor in. Internet connected devices need continuous monitoring to detect common attacks, the use of automated vulnerability scanning solutions, the use of tools like Shodan. There are many possible ways to mitigate risk, like the separating of networks. Heartbleed has been a big wake up call, the number of probable vulnerable devices, the extra media attention along with the slick branding propelled this security risk from the geeks and IT and security professionals all the way to the boardroom. It’s important not to be fooled in to thinking this is only an IoT issue, a proportion of the devices highlighted belong to the more traditional internet infrastructure hardware group. That said, the mass adoption of IoT will only make future vulnerabilities more difficult to correct.

I don’t see these current findings as a ‘we haven’t patched Heartbleed’ issue, it’s another example of what happens without regulation and standardization, without user education and best practices, coupled with the ‘security as an afterthought’ mentality.

ORX Locker

Only a month has gone by since the last RaaS (Ransomware as a Service) came to light. It looks this new business model that was first introduced by TOX a few months ago is spreading fairly rapidly. The idea is that now ALL malware authors of ranging skill can now create encrypting ransomware on a easy to use platform. This latest variant called ORX Locker is no different.

Simply enter in the desired info (price, identifiers, time limit, ect.) and the site will generate a new binary tailored to your specifications. The hackers are still responsible for distributing the malware, but renting time on many operational botnets and email phishing campaigns is also fairly easy to do in the underground darknet marketplace.

Once a victim is infected there is no GUI popup once all files are encrypted. It just changes the extension of all encrypted files to “.LOCKED” so you have a nice surprise when you try open one of your compromised files. Instructions on how to get your files back are left on your desktop as locally stored web page.

Special instructions are given to show a novice user how to connect to onion links and pay the ransom. Once you successfully connect to the darknet then the payment page is presented.

The instructions are clear on what you need to do to get your files back. Bitcoin is the criminal industry standard now and you’ll have a hard time paying for any ransom without it. While some ransoms will also accept the legacy money mules like ukash and moneypak, that is quickly dying out in favor of a better fee structure bitcoin launderers offer. Once you’ve paid you just download their tools and it will unlock all of your files using the AES 256 key that was generating during encryption.

This variant does not delete the VSS so as long as you have system restore enabled you can get your files back without paying the ransom. Just download a shadow copy tool like shadow explorer and you can restore files from a previous restore point. While the variant we analyzed showed no advanced techniques and is relatively simple in design, it remains a threat to unprotected systems and should be taken seriously. Improvement tweaks in the future are always possible and may “patch” the back doors it left open to your files.

  • MD5 Analyzed:89E1EFDC766E9C7D41305566993BA800
  • Additional MD5: D6ED4D4E8B1A95A224EBDD54529B3751
  • Additional MD5: 1914724AEEA3CA954322053DD883B14A

Webroot will catch this specific variant in real time before any encryption takes place. We’re always on the lookout for more, but just in case of new zero day variants, remember that with encrypting ransomware the best protection is going to be a good backup solution. This can be either through the cloud or offline external storage. Keeping it up to date is key so as not to lose productivity. Webroot has backup features built into our consumer product that allow you to have directories constantly synced to the cloud. If you were to get infected by a zero day variant of encrypting ransomware you can just restore your files back as we save a snapshot history for each of your files up to ten previous copies. Please see our community post on best practices for securing your environment against encrypting ransomware.

Security Advice is fundamentally the same

Thinking back on the changes in what we like to call the “threat landscape” over the years, a lot has changed. From the days of actual viruses and worms spreading their way through networks, to the rise of spyware and adware that slowed your computer to a crawl with pop-up ads and toolbars, to the scourge of encrypting ransomware that we see today.

As much as things have changed, the methods of distribution have remained fairly constant. The majority of malware we see is distributed via exploits or through some form of social engineering. While there seems to be no shortage of zero-day exploits being used, many of the exploits used to install malware have been patched for a long time. We see infections that use exploits that were patched years ago on a regular basis. Social engineering has certainly become more advanced, but users continue to click on malicious links or attachments in email messages.

The following is an updated to our Webroot Internet Security FAQ from around 2005. Some of the terminology may be a bit older but the information is still relevant today.

How can I prevent computer viruses? Take these steps to fortify your computer security against viruses right away:

  • Use anti virus protection and a firewall
  • Update your operating system regularly
  • Increase your browser security settings
  • Avoid questionable Web sites
  • Only download software from sites you trust
  • Practice safe email protocol
  • Don’t open messages from unknown senders
  • Immediately delete messages you suspect to be spam
  • Avoid free software and file-sharing applications
  • Get anti-spyware software protection

So while the types of threats out there are changing, the fundamentals are staying the same which luckily allows the potential victim to take similar approaches to rectifying the attack and staying safe online. As always, it is best to stay updated with newest trends in security, but always remember the core foundation of staying safe online.

AdBlock Plus exploit puts OSX users at risk

A visit to the Apple store will give any consumer a false sense of security, you will be told that by buying a Mac you are safe from threats and malware. I have even been told this even after I explain what I do for a career. A vast majority of Mac users still believe that they are safe from the threat of malware because of this, even though the magic myth of Mac immunity has long been disproven and really exploited in the past years with such concepts of Thunderstrike and root privilege exploits. However, most of the malware that we come across for Mac has been adware. The annoying pop ups or redirects that try to get you to spend money or download shady software.

Variants of VSearch and Genieo have been on top of the list for most downloaded Mac malware. Most people’s cure for this would be to install an ad blocker such as AdBlock Plus. I can’t blame them for this as I also run an ad blocker on my personal Mac. The downfall to this is that these adware companies have figured this out and added code to their program to allow their ads even with your blocker running. This is why the Mac community needs a strong security software on their machines. Researching one of these variants, we came across code that will search for your ad blocking program, download an exception text file and insert it into the settings of your ad blocker. Here is a sample of the exception text it downloaded.

[Adblock Plus 2.0] @@||search.yahoo.com^$document @@||bing.com^$document @@||genieo.com^$document @@||strtpoint.com^$document

This code allows their ads to run and the user is none the wiser. The adware creates its own rules for your security plugin. This is just the beginning of what could be a crucial change in the malware found on Macs. Malware may only be using exploits like this for advertisements currently but what is stopping it from using this same kind of exploit to send personal data out in the future? Putting your security in the hands of a software that only protects you from one type of malware simply isn’t enough anymore. It is easy to find articles that claim Apple computers are invincible but the fact is malware for Mac is real and it is getting increasingly better at ensuring its survival.