Friday 4 November 2016

DDoS attacks so powerful entire countries can be cut from the internet

Liberia has become the latest victim of the Mirai botnet



There has been another worrying development when it comes to massive-scale DDoS attacks, with the latest victim being an entire country – Liberia over in Africa, to be precise.
And as you won’t be surprised to hear if you’ve been following these stories, this is another assault which leverages the Mirai botnet to fire tons of traffic at the victim – that’s been the source of all these big attacks since the first massive volley against security researcher Brian Krebs (which reached some 620Gbps).
As ZDNet spotted, apparently the Mirai botnet employed in the attacks against Liberia is known as Botnet #14, and security expert Kevin Beaumont observesthis is the largest such botnet – consistently capable of producing over 500Gbps – which appears to also be the source of the recent massive attack on Dyn.
The hit on Dyn, which is a DNS provider, caused a massive web outage a fortnight ago, knocking out all manner of sites including Twitter, Netflix and Spotify.
Liberia has apparently suffered at the hands of a number of DDoS attacks which are short by nature, but worrying because they’re pretty much taking the entire country offline.

Glaring weakness 

As Beaumont observes, that’s because Liberia relies on a single pipe for its internet access, and so has a single point of failure (and it’s not the only country like this). Websites hosted in Liberia were downed, and a journalist Beaumont spoke to said that internet connectivity was going offline at times matching the DDoS blasts.
Beaumont noted: “The attacks are extremely worrying because they suggest a Mirai operator who has enough capacity to seriously impact systems in a nation state.”
The truth is that few people are on the internet in Liberia anyway – only around one in 20 of the population – but ZDNet also managed to get some confirmation from a person returning to the country, who said they experienced ‘minor interruptions’ to their internet usage on Wednesday evening.
But given the low-profile target country and the very short nature of the attacks, it seems that this is just the botnet’s owner(s) testing out firepower against a nation. It’s what might come next that’s worrying, of course, when the DDoS cannons are aimed and let loose with a sustained barrage.
As we saw with the Dyn affair, the sort of damage these large-scale attacks can now muster is quite frightening. And worse still, there’s the prospect of Mirai being cranked up in terms of its potential power as more easily compromised IoT devices (security cameras, DVRs, routers and so on) are hacked and join the massing botnet ranks.
The other major concern is the use of possible DDoS amplification techniques, such as the one we reported on last month, which could potentially be used to inflict assaults of 35Tbps or even more by seriously powering up these botnet-based attacks.
Source: http://www.techradar.com/

Saturday 25 January 2014

Cyber Threats Hit Record Levels

Cyber threats and vulnerabilities have reached their highest level for more than a decade, networking equipment specialist Cisco's latest security study reveals. 

According to the Cisco 2014 Annual Security Report, which became available this week, cumulative annual alert totals rose by 14% on the year in October 2013. The IT major says that the malicious activity witnessed is at its highest level since the firm began tracking it back in 2000 as the targets of such attacks are failing to address the challenges of the quickly evolving threat landscape.

According to the report, there is a dire need for security professionals worldwide. This, coupled with the lack of adequate systems at most enterprises, leaves organisations without the necessary resources to address cyber attacks. Cisco has estimated that the global shortage of security experts will exceed one million this year.

A startling finding of the study is that all 30 of a sample of the biggest multinational company networks generated visitor traffic to websites with malware, with 96% reviewing communicated traffic to hijacked servers and 92% transmitting traffic to empty web pages, which is also usually associated with exposure to malicious activity, Cisco noted.

And it seems that malicious attacks are widening their scope among verticals. In the past two years, sectors that had remained relatively unscathed by malicious breaches, such as agriculture and mining, witnessed a substantial rise in malware encounters, the IT company said.

The research found that Multipurpose Trojans prevailed in web-delivered malware last year, accounting for 27% of all encounters, and, among programming languages, Java is still the primary target of online criminals.

In addition, Android turned out to be by far the most targeted mobile platform, accounting for 99% of all mobile malware.

Source: www.misco.co.uk

Saturday 28 September 2013

Pirate Bay Co-Founder’s Sentence Cut In Half

Pirate Bay co-founder Gottfrid Svartholm Warg
Pirate Bay co-founder Gottfrid Svartholm Warg's prison sentence for hacking and fraud has been reduced from two years to one. (Photo: Reuters)
Pirate Bay co-founder, Gottfrid Svartholm Warg had his prison sentence for hacking and fraud reduced from two years to one. A Swedish appellate court made the decision on Wednesday after finding that one of the hacking charges against Svartholm Warg lacked sufficient evidence, the Associated Press reported. Namely, charges relating to the hacking of Nordea Bank AB were dismissed, while other hacking charges were upheld.

The Pirate Bay co-founder's sentence was cut in half because the Svea Court of Appeal said it could not rule out Svartholm Warg's claim that others could have remotely accessed his computer to hack into the Nordea Bank AB's servers. While the court dismissed the bank hacking charges, it upheld the conviction against Svartholm Warg of hacking into the servers of two other companies, Applicate and Logica, which handle sensitive information for Sweden's police force and tax authority. The Wall Street Journal reported that Svartholm Warg was originally convicted of hacking into all three companies' servers in June, resulting in the two-year sentence.  
The Pirate Bay is one of the world's biggest free file-sharing websites, giving millions of users a way to illegally download music, movies and software. Since launching the site in 2003, Svartholm Warg and fellow co-founder Fredrik Neij have been embroiled in controversy. In 2009, the co-founders, along with company spokesman Peter Sunde and businessman Carl Lundstrom, were given one-year sentences for copyright violation by a Swedish court and ordered to pay 46 million kronor ($6.5 million) in damages to the entertainment industry.
Svartholm Warg left the country while appealing that ruling. He was arrested in Cambodia in 2012 and deported back to Sweden after an international arrest warrant was issued against the Pirate Bay co-founder, per the AP. He served out his first sentence for copyright violation while under detention over his hacking charges.
But while the Pirate Bay co-founder might have had his sentence reduced in Sweden, he might not be out of hot water yet. Decrypted Tech reported that Svartholm Warg is facing extradition to Denmark, as he is a suspect in a breach that resulted in the theft of driving records and social security numbers. The Danish authorities expect to have Svartholm Warg in custody in a few days.

Saturday 14 September 2013

61% Of Malware Attack Victims Lose Some Data Forever


Most IT users know that malware is dangerous but few are fully aware of the havoc it can wreak. A new survey from B2B International and Kaspersky Lab reveals the true scale of the malware problem: just 39% of victims manage to fully restore the data lost as a result of a breach.


As Kaspersky Lab points out, a quarter of malware attacks succeed in stealing or corrupting confidential information. In the case of 17% of victims all data is lost forever, while 44% manage a partial retrieval. This is cause for concern, considering the importance we attach to our data, Kaspersky Lab said. Among the survey respondents, 56% declared that they deemed their information more valuable than the machine storing it. The poll also showed that 10% of affected users have resorted to the services of outside experts in the effort to restore their lost data.

But a data recovery specialist may not always achieve complete success and sometimes nothing can be done. Even an expert will be helpless if the attackers have used a file encryptor. This malicious program encrypts the files on the user's computers and requires a unique key for decryption. This is the type of program known as ransomware because the attackers typically demand payment in return for the decryption key.


Computers and mobile devices have become an integral part of daily life so it would be virtually impossible not to store confidential information on digital devices. However, users can minimise the risk of data loss through regular back-ups and reliable anti-malware protection, Kaspersky Lab said.



Sunday 21 April 2013

'BadNews' Android malware in approved apps may have been downloaded 9 million times!


A new breed malware has been discovered within at least 32 Android apps, which may have been downloaded up to nine million times!
The so-called 'BadNews' malware was outed by security firm Lookout Mobile Security in a blog post on Friday and the affected apps have now been removed by Google.
All of the apps found to contain the malicious code had been approved by Google, but it appears that the harmful elements had been added after the fact, disguised as updates.
Apps containing the BadNews code have been reporting back to a server and revealing sensitive information like the phone number and handset serial number.

'Bad guys are smart'

The affected apps include English and Russian-language games, dictionaries, wallpapers and were able to make it past the Google Bouncer software that scans the Play store for harmful apps.
Marc Rogers, principal security researcher for Lookout, told Ars Technica: "You can't even say Google was at fault in this because Google very clearly scrutinized all these apps when they want in.
"But these guys were cunning enough to sit there for a couple of months doing absolutely nothing and then they pushed out the malware.
"This is a wakeup call for us in the industry to say: 'Bad guys are smart as well and they'll take a look at the security models we put in place and they'll find weaknesses in them. That's exactly what they've done here."


Saturday 16 February 2013

Facebook site infiltrated!


The Facebook security teams has confirmed that the social networking site was targeted in a "sophisticated attack" last month.

The digital intrusion apparently occurred when a small number of Facebook personnel visited a compromised mobile developer website.

"The site hosted an exploit which then allowed malware to be installed on these employee laptops. The laptops were fully-patched and running up-to-date anti-virus software. As soon as we discovered the presence of the malware, we remediated all infected machines," a Facebook rep explained.

"After analyzing the compromised website where the attack originated, we found it was using a 'zero-day' (previously unseen) exploit to bypass the Java sandbox (built-in protections) to install the malware. We immediately reported the exploit to Oracle, and they confirmed our findings and provided a patch on February 1, 2013, that addresses this vulnerability."

Interestingly, Facebook says it wasn't not alone in the above-mentioned attack, as other sites were infiltrated as well.

However, the rep was also quick to point out that the social networking site had found "no evidence" of compromised user data.

"As part of our ongoing investigation, we are working continuously and closely with our own internal engineering teams, with security teams at other companies, and with law enforcement authorities to learn everything we can about the attack, and how to prevent similar incidents in the future," the rep added.


Source: www.tgdaily.com/


Saturday 17 November 2012

Ransomware - A Major Threat To Internet Security

Ransomware is emerging as a major cybercrime strategy, threatening to oust fake anti-virus software as the most popular cyber-attack next year, new research by IT security firm Symantec shows.

A total of 2.8% of victims of ransomware pay a "ransom" of up to £280 to regain access to their computers which have been blocked by cryptoviruses. Victims are tricked into making the payments after receiving fake messages that look like they have been issued by police authorities. Such messages often tell users they must pay a penalty for browsing illegal content.



Cybercriminals pocket £3 million annually from blackmailing users to pay to free their PCs from the malicious software, with one criminal group having tried to plague 495,000 computers in just 18 days, Symantec said, as quoted by IT Pro.

The first cases of ransomware were found in 2009 and were mainly limited to Eastern Europe and Russia.

However, this type of cybercrime is spreading to Western Europe, the USA and Canada, Symantec said. Criminal gangs have been traced back to a single unidentified person who apparently creates ransomware on request.

As consumer demand shifts to mobile devices and the cloud, cyber-attacks will increasingly focus on Secure Sockets Layer (SSL) certificates used by mobile apps, Symantec believes. Meanwhile, according to an earlier report by IT Pro, security experts have identified a new malware strand that steals image files from PCs and dispatches them to a remote server.