Skip to main content

Posts

New Malware dubbed Name Emotet Hacks Nearby Wi-Fi Networks to New Victims!!

Emotet, the notorious trojan behind a number of botnet-driven spam campaigns and ransomware attacks, has found a new attack vector: using already infected devices to identify new victims that are connected to nearby Wi-Fi networks. According to  researchers at Binary Defense , the newly discovered  Emotet  sample leverages a "Wi-Fi spreader" module to scan Wi-Fi networks, and then attempts to infect devices that are connected to them. The cybersecurity firm said the Wi-Fi spreader has a timestamp of April 16, 2018, indicating the spreading behavior has been running "unnoticed" for close to two years until it was detected for the first time last month. The development marks an escalation of Emotet's capabilities, as networks in close physical proximity to the original victim are now susceptible to infection. How Does Emotet's Wi-Fi Spreader Module Work? The updated version of the malware works by leveraging an already compromised host to list all the ...

More than 1.9B Malicious App Installs in 2019 were blocked by Google Play Protect

Google continues to enhance the safety of Google Play with continuous improvements, enhancements, and teams to fight against malicious apps and developers. Google Play Protect is built-in malware protection for Android, it was introduced in the year 2017, aiming to detect malicious apps in the Google Play and off of user’s devices. According to Android Security & Privacy  report  2018, Google blocks more than 3.2 billion malicious apps installation. Starting from October 2018, Google announced a new policy update to limit the apps unnecessarily accessing sensitive information such as SMS and Call Log data. Google Play Protect scans over 100B apps Google Play protects scans more than 100B apps every day and alerts the users about the security measures and the steps that need to be taken. It also notified you if you have installed new or rarely installed apps in the ecosystem when the play protects is enabled it shows the following warning when the malicious ...

Around 1.7 Million Users Data were stolen by 500 Chrome Extensions!!

Google removed 500 malicious Chrome extensions from its Web Store after they found to inject malicious ads and siphon off user browsing data to servers under the control of attackers. These extensions were part of a malvertising and ad-fraud campaign that's been operating at least since January 2019, although evidence points out the possibility that the actor behind the scheme may have been active since 2017. The findings come as part of a  joint investigation  by security researcher Jamila Kaya and Cisco-owned Duo Security, which unearthed 70 Chrome Extensions with over 1.7 million installations. Upon sharing the discovery privately with Google, the company went on to identify 430 more problematic browser extensions, all of which have since been deactivated. "The prominence of malvertising as an attack vector will continue to rise as long as tracking-based advertising remains ubiquitous, and particularly if users remain underserved by protection mechanisms," s...

WhatsApp Bug Could Have Let Attackers Access Files On Your PCs

A cybersecurity researcher today disclosed technical details of multiple high severity vulnerabilities he discovered in WhatsApp, which, if exploited, could have allowed remote attackers to compromise the security of billions of users in different ways. When combined together, the reported issues could have even enabled hackers to remotely steal files from the Windows or Mac computer of a victim using the WhatsApp desktop app by merely sending a specially crafted message. Discovered by PerimeterX researcher Gal Weizman and tracked as  CVE-2019-18426 , the flaws specifically resided in WhatsApp Web, a browser version of the world's most popular messaging application that also powers its Electron-based cross-platform apps for desktop operating systems. In a  blog post  published today, Weizman revealed that WhatsApp Web was vulnerable to a potentially dangerous open-redirect flaw that led to persistent cross-site scripting attacks, which could have been triggered by se...

WiFi Hacking Tool Aircrack-ng 1.6 Released with New Features, Speed Up & Bug Fixes

Aircrack-ng 1.6 released with new features and a lot of improvements with Speed, memory usage and rate display. Aircrack-ng contains a complete set of tools to perform a Wi-Fi network security assessment. The tool focuses on multiple areas of WiFi security such as capturing packets, replay attacks, checking WiFi cards and driver capabilities for injection. Aircrack-ng 1.6 The most noticeable  change  with the new version is the rate display, with the new version “it takes into account the complexity of 802.11n/ac and calculates the maximum rate that can be achieved on the AP.” Aircrack-ng @aircrackng Aircrack-ng 1.6 released https:// aircrack-ng.blogspot.com/2020/01/aircra ck-ng-16.html  … 224 4:55 AM - Jan 26, 2020 Twitter Ads info and privacy 115 people are talking about this Now it includes the basic UTF-8 support for ESSID, so you will get the WPA3 or OWE network displayed correctly. Aircrack-ng...

Avast Anti-Virus Spying Millions of Users Browsing Activities, Every Click, Every Buy and Selling to Its Clients – Google, Microsoft, Pepsi

Anti-virus software firm Avast reportedly spying hundreds of millions of Users browsing activities including, every click, every purchase you made online, and selling the collected data into various clients that include Home Depot, Google, Microsoft, Pepsi, and McKinsey and many other companies. Avast is one of the leading security firms with more than 435 million active users per month, and well known for offering Free Anti-Virus software. The report claims that Avast has collected data from hundreds of millions of users, and then gives that to Jumpshot, a subsidiary of Avast that’s been offering access to user traffic from 100 million devices, including PCs and phones. Once the collected data will be handover to the Jumpshot, it repackages the collected data into different products and sells it into various largest companies in the world. Credits :  Motherboard In return, these companies are paid millions of dollars for Jumpsuit products such as “All Clicks Feed,” wh...

Darknet Market AlphaBay Moderator Pleads Guilty – 20 Years of Prison

Bryan Connor Herrell, 25, AlphaBay Moderator pleads guilty for his job role in the fraudulent organization. Herrell’s job role is to resolve disputes between vendors and purchasers. The AlphaBay was an illicit market place operated on the  darknet , vendors, and customers engaged in exchanging different types of illicit goods such as stolen identity information, credit card numbers and other illegal items. The market was taken down on 20 July 2017, as a result of law enforcement operations, led by the Federal Bureau of Investigation (FBI), the US Drug Enforcement Agency (DEA) and the Dutch National Police, with the support of  Europol . Websites takedown on 20 July 2017 Before takedown AlphaBay had more than 200 000 users, 40 000 vendors and more than 1 billion was transacted in the market since it was created. According to  court documents , Herrell went by the name “Penissmith” and “Botah” in the marketplace, his job role is to settle a dispute between the...