Showing posts with label Trojan. Show all posts
Showing posts with label Trojan. Show all posts

Sunday, 21 July 2013

Shadowlock Trojan demands odd ransom, Symantec says

Symantec has discovered a bizarre ransom Trojan that eschews the usual demand for payment in favor of asking its victims to fill in an online survey to get an unlock code.

Given the name Shadowlock by the security firm, the underlying engineering of the Trojan is much the same as any one of the numerous other examples of ransomware.

Infected Windows PCs display a dialogue box asking for the unlock code and the hint that they can find it after visiting a website linking to a list of different prize surveys or by downloading unnecessary software such as a media player.

The box won't clear until the survey code has been entered, and can't be closed using the task manager; attempts to delve into matters using the command prompt, PowerShell, Regedit, or MSConfig are also denied as is the ability to bypass it by invoking a restore point.

Entering the code incorrectly three times, or just attempting to close the dialogue, causes the system to shut down. Upon a reboot the same dialogue reappears after 20 seconds, the length of time the users have to try and shut it down using the Task Manager.

Shadowlock can also nix browsers and certain system tools as well as consume free resources and disable the Windows firewall.

Symantec was able to decompile the Trojan, which was built using .NET, well enough to discover some of its more eccentric secrets. For example, it also includes an Easter egg, a hidden routine that plays a the five-note theme from the 1976 alien abduction film Close Encounters of the Third Kind.
Other capabilities include being able to reverse mouse buttons and open the CD tray or open Windows utilities.

"It turns out the malware author has a sense of humor," wrote Symantec researcher, Fred Gutierrez in his blog on Shadowlock.

He speculates that the survey tactic might be an experiment to see much response it gets, or perhaps part of a genuine money-making scheme.


"These functions (as well as others) may find themselves being used in a future variant." 

Sunday, 7 July 2013

China sees rise in international Trojan and botnet attacks

China saw an increase in Trojan and botnet attacks coming from other countries in 2012, as the amount of mobile malware in the country also surged, according to a local security group.

During the year, a total of 73,000 Trojan and botnet command-and-control servers had hijacked 14.2 million host machines in the country. The number of Trojan and botnet servers marks an almost 60 percent increase from 2011.

Close to 13,000 of those servers were based in the U.S., the country also responsible for the largest number of Trojan and botnet attacks targeting China. South Korea was second, followed by Germany.

China's National Computer Network Emergency Response Technical Team (CNCERT) reported the figures on Thursday. They were later published by the nation's state press, Xinhua News Agency.
 
Both China and the U.S. have lately been at odds with one another over cyber security. Earlier this year, U.S. officials warned the country to stop with its alleged state-sponsored hacking attacks, a claim Chinese officials vehemently rejected.

Former U.S. National Security Agency contractor Edward Snowden has also complicated matters. The leaker has reportedly accused the U.S. government of hacking into Chinese telecommunication companies and universities. Last month, China's foreign ministry said it was "gravely concerned" about the alleged cyber espionage and has the matter brought up with the U.S.

Chinese officials have previously claimed the country is a major victim of cyber attacks. On Thursday, CNCERT reported that the Trojans and botnets targeting China were designed to steal data or to help facilitate other hacking attacks.

In addition, China is also witnessing a boom in mobile malware. CNCERT encountered close to 163,000 samples of mobile malware in 2012, an increase of 25 times from the previous year.

Most of the malware, at 82.5 percent, was designed for Google's Android OS. About 40 percent was also designed to steal funds from the user by secretly triggering fee-based services on the device.