<?xml version="1.0" encoding="iso-8859-1" ?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<atom:link href="http://www.securelist.com/en/rss/weblog" rel="self" type="application/rss+xml" />
<title>Securelist / Blog</title>
<link>http://www.securelist.com/en/</link>
<description></description>
<lastBuildDate>22 May 2013 22:12:52 +0400</lastBuildDate>
<image>
<title>Securelist / Blog</title>
<url>http://www.securelist.com/en/rss/klogo.gif</url>
<link>http://www.securelist.com/en/</link>	
</image>
	<item>
		<author>webmaster@securelist.com (Jorge Mieres )</author>
		<description>&lt;p&gt;&lt;b&gt;Jumcar&lt;/b&gt; is the name we have given to a family of malicious code developed in Latin America  particularly in Peru  and which, according to our research, has been deploying attack maneuvers since March 2012.&lt;/p&gt; &lt;p&gt;After six months of research we can now detail the specific features of Jumcar. We will communicate these over the following days. Essentially the main purpose of the malware is stealing financial information from Latin American users who use the home-banking services of major banking companies.  Of these, 90% are channeled in Peru through phishing strategies based on cloning the websites of six banks.&lt;/p&gt;  &lt;p&gt;Some variants of the Jumcar family also target two banks in Chile, and another in Costa Rica.&lt;/p&gt;&lt;p&gt;&lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208195042.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt; &lt;center&gt;&lt;i&gt;&lt;font size=&quot;2&quot;&gt;Percentage of the phishing attacks by countries&lt;/font&gt;&lt;/i&gt;&lt;/center&gt;</description>
		<guid>http://www.securelist.com/en/blog/208195041/Jumcar_From_Peru_with_a_focus_on_Latin_America_First_part</guid>
		<link>http://www.securelist.com/en/blog/208195041/Jumcar_From_Peru_with_a_focus_on_Latin_America_First_part</link>
		<pubDate>20 May 2013 08:06:07 +0400</pubDate>
		<title>Jumcar. From Peru with a focus on Latin America [First part]</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Stefano Ortolani)</author>
		<description>&lt;p&gt; Fostering knowledge exchange among different generations of security researchers is maybe one of the best traits of a good security conference. Judging by its attendance, NoSuchCon can easily claim to be one of these. It's rare to see such a mix of young researchers and old gurus exchanging ideas and getting to know each other. Organized this year in Paris, NoSuchCon takes place in the premises of the &lt;strong&gt;Espace Oscar Niemeyer&lt;/strong&gt;; admittedly, indeed a nice move putting a security conference within an art exposition center (congrats to the organizers :)) .  &lt;/p&gt;&lt;p&gt;&lt;p class=c&gt; &lt;div style=&quot;width:350px; font-size:80%; text-align:center; margin: 0px auto;&quot;&gt; &lt;img src=&quot;images/pictures/klblog/208195040.jpg&quot; width=&quot;350&quot; border=&quot;1&quot;&gt; Espace Oscar Niemeyer  &lt;/div&gt; &lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/208195029/NoSuchCon_2013</guid>
		<link>http://www.securelist.com/en/blog/208195029/NoSuchCon_2013</link>
		<pubDate>18 May 2013 16:00:51 +0400</pubDate>
		<title>NoSuchCon 2013</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Fabio Assolini)</author>
		<description>&lt;p&gt;Now cybercriminals from Brazil are also interested in Bitcoin currency. In order to join the horde of phishers on the lookout for the virtual currency they have applied their best malicious technique: malicious PAC on web attacks, and phishing domains.&lt;/p&gt;&lt;p&gt;&lt;p&gt;The malicious usage of PAC (Proxy Auto-Config) among Brazilian black hats is not something new  weve known about it since 2007. Generally, these kind of malicious scripts are used to redirect the victims connection to a phishing page of banks, credit cards and so on. We described these attacks in detail &lt;a href=&quot;http://www.securelist.com/en/blog/2106/Benign_Feature_Malicious_Use&quot;&gt;here&lt;/a&gt;. In 2012 a Russian Trojan banker called &lt;a href=&quot;http://www.securelist.com/ru/blog/207764045/Tochechnyy_banker&quot;&gt;Capper&lt;/a&gt; also started using the same technique. When its used in drive-by-download attacks, it becomes very effective.&lt;p&gt;&lt;p&gt;&lt;p&gt;After registering the domain &lt;b&gt;java7update.com&lt;/b&gt;, Brazilian criminals started attacking several websites, inserting a malicious iframe in some compromised pages:&lt;/p&gt;&lt;p&gt;&lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208195034.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/208195033/Malicious_PACs_and_Bitcoins</guid>
		<link>http://www.securelist.com/en/blog/208195033/Malicious_PACs_and_Bitcoins</link>
		<pubDate>17 May 2013 17:58:17 +0400</pubDate>
		<title>Malicious PACs and Bitcoins</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Kurt Baumgartner)</author>
		<description>&lt;P&gt; Microsoft released a long list of updates for Microsoft software today. The most interesting appear to be those patching Internet Explorer and the kernel software vulnerabilities. In all, ten critical &quot;use-after-free&quot; vulnerabilities are patched in IE along with one important Information Disclosure vulnerability, and three elevation of privilege vulnerabilities are being patched as well. Almost all of these IE vulnerabilities were reported by external security researchers working through HP's Zero Day Initiative. &lt;/P&gt; &lt;P&gt; The recent Internet Explorer 8 0day implemented with ROP to work across ASLR-protected Windows 7, hosted on the compromised Department of Labor website and others, was used as a part of a targeted attack watering hole campaign suggested to be run by known threat actor &quot;DeepPanda&quot;. This IE 0day was reported by the guys over at FireEye and iSight Partners. It is being patched with Security Bulletin MS13-038. The others may not have been actively used by threat actors, but as always, it is very important for all Internet Explorer users to update these asap and avoid being a victim of the more common financially motivated mass-exploitation schemes.  &lt;/P&gt; &lt;P&gt; A bit less sexy but very important for organizations to update are the three &quot;Important&quot; kernel escalation of privilege vulnerabilities. While these have not yet been known to be publicly exploited, EoP are actively deployed for post-exploitation purposes and are a significant part of any infiltration exercise. All three of these problems were reported by external security researchers, to whom Microsoft extended a &quot;thanks&quot;. &lt;/P&gt; &lt;P&gt; Organizations should also be aware that Http.sys in Windows 8, Windows RT and Windows 2012 is vulnerable to denial of service attacks, but exploiting this bug appears to be very difficult. Accordingly, they are rating it &quot;Important&quot;. &lt;P&gt; Other client side apps are being patched with &quot;Important&quot; rated updates as well, including Word, Publisher, and more. More information on all of these updates can be found over at Microsoft's &lt;a href=http://technet.microsoft.com/en-us/security/bulletin/ms13-may target=_blank&gt;summary&lt;/a&gt;. &lt;/P&gt; &lt;P&gt; Also today, Adobe's PSIRT pushed &lt;a href=http://blogs.adobe.com/psirt/2013/05/adobe-security-bulletins-posted-7.html target=_blank&gt;several important updates&lt;/a&gt; in ColdFusion (in the crosshairs for persistent attackers on organizations) and both of their big client side apps Flash and Reader/Acrobat. &lt;/P&gt;</description>
		<guid>http://www.securelist.com/en/blog/208195028/Microsoft_Updates_May_2013_Slew_of_Internet_Explorer_Critical_Vulnerabilities_Kernel_EoP_and_Others</guid>
		<link>http://www.securelist.com/en/blog/208195028/Microsoft_Updates_May_2013_Slew_of_Internet_Explorer_Critical_Vulnerabilities_Kernel_EoP_and_Others</link>
		<pubDate>14 May 2013 22:06:28 +0400</pubDate>
		<title>Microsoft Updates May 2013 - Slew of Internet Explorer Critical Vulnerabilities, Kernel EoP, and Others</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Dong Yan)</author>
		<description>&lt;p&gt;In China telecom fraud has become an increasingly common crime. Last year there were more than 170,000 telecom fraud cases, causing the loss of over $12.5 billion. The fraudsters usually call their victims and trick them into transferring cash to a criminal gang via an ATM. But recently a new breed of telecom fraud, which combines phishing sites and backdoor Trojans, has emerged.&lt;/p&gt; &lt;p&gt;Last week the police from the Dongcheng sub-branch of Beijing&amp;#8217;s Public Security Bureau asked us to help investigate a telecom fraud case. The victim was defrauded of $100,000. After our investigation, the fraudsters&amp;#8217; tactics were laid bare.&lt;/p&gt;&lt;p&gt;&lt;h2&gt;So how does the scam work? How was the victim deceived? &lt;/h2&gt;&lt;p&gt;&lt;p&gt;First you get a call from a &amp;#8216;public prosecutor&amp;#8217; saying that you are implicated in a financial crime and you must help with the investigation. Of course, you deny everything, but the &amp;#8216;public prosecutor&amp;#8217; advises you to check if you are listed in an official database as a suspected criminal. To do this, they tell you to visit the &amp;#8220;Supreme Procuratorate&amp;#8217;s&amp;#8221; website, which is, of course, a phishing site:&lt;/p&gt;&lt;p&gt;&lt;p class=c&gt;&lt;a href=&quot;http://www.securelist.com/en/images/pictures/klblog/878.png&quot; target=_blank&gt;&lt;img src=&quot;http://www.securelist.com/en/images/pictures/klblog/878.png&quot; border=0 width=600 alt=''&gt;&lt;/a&gt;&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/877/Telecom_fraud_phishing_and_Trojans_combined</guid>
		<link>http://www.securelist.com/en/blog/877/Telecom_fraud_phishing_and_Trojans_combined</link>
		<pubDate>13 May 2013 11:15:00 +0400</pubDate>
		<title>Telecom fraud - phishing and Trojans combined</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Michael)</author>
		<description>&lt;p&gt;The Counter eCrime Operations Summit VII (CeCOS VII) engages questions of operational challenges and the development of common resources for the first responders and forensic professionals who protect consumers and enterprises from the electronic-crime threat every day.     The annual event, organized by the Anti-Phishing Working Group (APWG) is this time held in Buenos Aires, Argentina.&lt;/p&gt;  &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208194250.jpg&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt; </description>
		<guid>http://www.securelist.com/en/blog/208194246/CeCOS_VII</guid>
		<link>http://www.securelist.com/en/blog/208194246/CeCOS_VII</link>
		<pubDate>27 Apr 2013 00:49:47 +0400</pubDate>
		<title>CeCOS VII</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Kirill Kruglov)</author>
		<description>&lt;p&gt;The experience of many information security officers shows that only a small portion of security incidents take place as a result of meticulously planned and sophisticated targeted attacks, while most incidents are due to a lack of effective security and control measures. This post begins a series of publications about IT security threats associated with the use of legitimate software.&lt;/p&gt; &lt;h1&gt;TeamViewer&lt;/h1&gt; &lt;p&gt;Hugely popular, easy-to-use and practical, remote access tools have been appreciated by system administrators and developers alike, as well as by anyone who has ever needed to log on to a work computer from a remote location, whether traveling on business, working from home, or caught out by an emergency while on vacation. However, unregulated use of this software poses a threat to corporate security and may lead to security incidents.&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/876/Security_policies_remote_access_programs</guid>
		<link>http://www.securelist.com/en/blog/876/Security_policies_remote_access_programs</link>
		<pubDate>25 Apr 2013 19:44:00 +0400</pubDate>
		<title>Security policies: remote access programs</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Sergey Golovanov)</author>
		<description>&lt;p&gt;It has been three years since we published &lt;a href=&quot;http://www.securelist.com/en/blog/139/Lock_stock_and_two_smoking_Trojans_bank_robbery_in_the_21st_century&quot;&gt;Lock, stock and two smoking Trojans&lt;/a&gt; in our blog. The article describes the first piece of malware designed to attack users of online banking software developed by a company called BIFIT. There are now several malicious programs with similar functionality, including:&lt;/p&gt; &lt;ul&gt; &lt;li&gt;Trojan-Spy.Win32.Lurk   &lt;li&gt;Trojan-Banker.Win32.iBank &lt;li&gt;Trojan-Banker.Win32.Oris &lt;li&gt;Trojan-Spy.Win32.Carberp &lt;li&gt;Trojan-Banker.Win32.BifiBank &lt;li&gt;Trojan-Banker.Win32.BifitAgent &lt;/ul&gt; &lt;p&gt;In spite of its functionality no longer being unique, the last program on the list caught our attention.&lt;/p&gt;  &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/862.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;br/&gt;&lt;em&gt;Words and strings used by Trojan-Banker.Win32.BifitAgent&lt;/em&gt;&lt;/p&gt; &lt;p&gt;&lt;p&gt;This particular piece of malware has a number of features that set it apart from other similar programs.&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/861/Lock_stock_and_two_smoking_Trojans_2</guid>
		<link>http://www.securelist.com/en/blog/861/Lock_stock_and_two_smoking_Trojans_2</link>
		<pubDate>22 Apr 2013 20:24:00 +0400</pubDate>
		<title>Lock, stock and two smoking Trojans-2</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Vicente Diaz)</author>
		<description>&lt;p&gt; What a week for being in Boston! I was heading to Source Conference the very same day the blast happened.  Its hard to describe all the intense emotions when I arrived. As president Obama said today to the city of Boston: You will run again. All my best to you guys, stay strong. &lt;/p&gt; &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208194238.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot; height=400 weight=400&gt;&lt;/p&gt; &lt;p&gt; In my presentation in Source I talked about fraud in Twitter.  These days we find a lot of spam bots in this social network, both blindly sending unsolicited direct messages to other users or doing some previous semantic analysis, depending on your tweets, for a more targeted message. &lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/208194237/Is_digital_marketing_the_new_spam</guid>
		<link>http://www.securelist.com/en/blog/208194237/Is_digital_marketing_the_new_spam</link>
		<pubDate>22 Apr 2013 09:54:12 +0400</pubDate>
		<title>Is digital marketing the new spam?</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Dmitry Tarakanov)</author>
		<description>&lt;p&gt;While researching PlugX propagation with the use of Java exploits we stumbled upon one compromised site that &lt;p&gt;hosted and pushed a malicious Java applet exploiting the CVE 2013-0422 vulnerability. The very malicious Java &lt;p&gt;application was detected heuristically with generic verdict for that vulnerability and it would have been hardly &lt;p&gt;possible to spot that particular site between tons of other places where various malicious Java applications were &lt;p&gt;detected with that generic verdict. But it was a very specific search conducted back then and this site appeared in &lt;p&gt;statistics among not so many search results. Well, to be honest it was a false positive in terms of search &lt;p&gt;criteria, but in this case it was a lucky mistake.&lt;/p&gt;&lt;p&gt;&lt;p&gt;The infectious website was an Internet resource named - &lt;i&gt;minjok.com&lt;/i&gt; and it turned out to be a news site in &lt;p&gt;Korean and English languages covering mostly political events around the Korean peninsula. We notified an editor of &lt;p&gt;this site about the compromise and although he has not responded, the site got closed after a while.&lt;/p&gt;&lt;p&gt;&lt;p&gt;This is how &lt;i&gt;minjok.com&lt;/i&gt; is described at &lt;a href=&quot;http://www.northkoreatech.org/the-north-korean-website-&lt;p&gt;list/minjok-tongshin/&quot;&gt;http://www.northkoreatech.org/the-north-korean-website-list/minjok-tongshin/&lt;/a&gt;:&lt;/p&gt;&lt;p&gt;&lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208194232.jpg&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;  &lt;i&gt;&lt;b&gt;Description of minjok.com&lt;/b&gt;&lt;/i&gt;&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/208194231/An_ambush_for_peculiar_Koreans</guid>
		<link>http://www.securelist.com/en/blog/208194231/An_ambush_for_peculiar_Koreans</link>
		<pubDate>19 Apr 2013 14:24:37 +0400</pubDate>
		<title>An ambush for peculiar Koreans</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Michael)</author>
		<description>&lt;p&gt;While many are still in shock after the Boston Marathon bombings on 16 April, it didn't take long for cyber criminals to abuse that tragic incident for their dirty deeds.&lt;/p&gt;  &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208194229.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt;   &lt;p&gt;Today we already started receiving emails containing links to malicious locations with names like &quot;news.html&quot;. These pages contain URLs of non-malicious youtube clips covering the recent event. After a delay of 60 seconds, another link leading to an executable file is activated.&lt;/p&gt;  &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208194230.jpg&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt;  &lt;p&gt;The malware, once running on an infected machine, tries to connect to several IP addresses in Ukraine, Argentina and Taiwan.  Kaspersky Lab detects this threat as &quot;Trojan-PSW.Win32.Tepfer.*&quot;.  &lt;p&gt;MD5sums of some of the collected samples:  5EA646FFDC1E9BC7759FDFC926DE7660  959E2DCAD471C86B4FDCF824A6A502DC &lt;/p&gt; &lt;p&gt;Our thoughts and prayers are with our colleagues in Massachusetts and others affected by the tragic events in Boston.&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/208194228/Boston_Aftermath</guid>
		<link>http://www.securelist.com/en/blog/208194228/Boston_Aftermath</link>
		<pubDate>17 Apr 2013 08:02:51 +0400</pubDate>
		<title>Boston Aftermath</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Dmitry Tarakanov)</author>
		<description>&lt;p&gt;Continuing our investigation into Winnti, in this post we describe how the group tried to re-infect a certain gaming company and what malware they used. &lt;p&gt;After discovering that the company-s servers were infected, we began to clean them up in conjunction with the company-s system administrator, removing &lt;p&gt;malicious files from the corporate network. This took a while because it was not clear at first exactly how the cybercriminals had penetrated the corporate &lt;p&gt;network; we couldn-t find a way to completely stop attacks penetrating the network and malicious files kept appearing. An analysis performed by the gaming &lt;p&gt;company itself led us to the conclusion that the infection started after establishing working contacts with a South Korean gaming company. This was also &lt;p&gt;confirmed by our research: &lt;a href=/en/analysis/204792287/Winnti_More_than_just_a_game&gt; as we wrote before&lt;/a&gt;, the Winnti group is most active in East Asia and we identified 14 infected gaming companies in South Korea.&lt;/p&gt;&lt;p&gt;&lt;p&gt;In the course of our efforts to remove the infection, the gaming company sent us suspicious files that were appearing on their computers. Many of these &lt;p&gt;files were samples of Winnti malware. As soon as information about the malicious files was added to our antivirus databases, our products were used to remove &lt;p&gt;Winnti malware from the gaming company-s corporate network. However, the attackers reacted very rapidly: new malware samples mysteriously appeared on &lt;p&gt;computers from which the infection had been completely removed the previous day. Eventually, though, our efforts proved successful and further access to the &lt;p&gt;gaming company-s computers was denied to the attackers.&lt;/p&gt;&lt;p&gt;&lt;p&gt;However, just as we expected, it was too early to celebrate. Exactly one month after the gaming company-s network had been cleaned, the Winnti group &lt;p&gt;returned. The system administrator sent us suspicious files, which had been attached to messages sent to company employees. This was run-of-the-mill &lt;p&gt;spearphishing: the attackers introduced themselves as computer game developers and pretended to be looking for opportunities related to working with large &lt;p&gt;publishers.&lt;/p&gt;&lt;p&gt;&lt;p class=c&gt;&lt;img src=&quot;http://www.securelist.com/en/images/vlweblog/207767110.jpg&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/208194224/Winnti_returns_with_PlugX</guid>
		<link>http://www.securelist.com/en/blog/208194224/Winnti_returns_with_PlugX</link>
		<pubDate>15 Apr 2013 16:30:00 +0400</pubDate>
		<title>Winnti returns with PlugX</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Roel)</author>
		<description>&lt;p&gt;Today is the second and last day of Infiltrate 2013 which is taking place in Miami Beach. It's my first time at Infiltrate and so far I've been really impressed with the quality of the conference.&lt;/p&gt;&lt;p&gt;&lt;p&gt;The opening keynote by Chris Eagle definitely set the tone for the rest of the con, with a very clear focus on offense. Chris shared his own view on various issues concerning how the US Armed Forces - and the Navy in particular - deal with educating people on cyber.&lt;p&gt;&lt;p&gt;One of the bits I found particularly interesting was the &lt;a href=&quot;http://en.wikipedia.org/wiki/Title_10_of_the_United_States_Code&quot;&gt;Title 10&lt;/a&gt; issue. Many of the experts creating cyber-tools, which would make them best equipped to handle them, are civilians. However under Title 10, only military personnel can actually 'pull the trigger'. You can see how this can be problematic.&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/208194226/Hello_from_Infiltrate_2013</guid>
		<link>http://www.securelist.com/en/blog/208194226/Hello_from_Infiltrate_2013</link>
		<pubDate>12 Apr 2013 21:51:22 +0400</pubDate>
		<title>Hello from Infiltrate 2013</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Kurt Baumgartner)</author>
		<description>&lt;P&gt; A new-ish Flash exploit has been on the loose for attacks around the web. This time, the attackers have compromised a caregiver site providing support for Tibetan refugee children and are spreading backdoors signed with Winnti stolen certificates delivered with Flash exploits - the compromised web site is the NGO &quot;Tibetan Homes Foundation&quot;. Previously, FireEye identified similar &lt;a href=http://www.fireeye.com/blog/technical/cyber-exploits/2013/02/lady-boyle-comes-to-town-with-a-new-exploit.html target=_blank&gt;&quot;Lady Boyle&quot; related malicious swf&lt;/a&gt; exploiting CVE-2013-0634. A notification has been sent to the contacts of the web site, but apparently the malicious footer.swf file is still hosted at the Foundation's web site, so please do not visit it just yet. Also, be sure to update your Flash player to the latest version. &lt;/P&gt; &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208194220.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt; &lt;P&gt; This site certainly appears to be a classic example of a &quot;watering hole&quot; attack. F-Secure pointed out another &lt;a href=http://www.f-secure.com/weblog/archives/00002524.html target=_blank&gt;Lady Boyle watering hole&lt;/a&gt; set up against a related Uyghur group, which has been targeted in tandem following the early March World Uyghur Congress. The delivered backdoors are shown to be signed with Winnti-stolen digital certificates in the F-Secure post, including the stolen MGAME certificate. &lt;/p&gt; &lt;P&gt; Here is an example of those same stolen certs reused for the backdoors in the Tibetan Homes Foundation incident. We see both the MGAME cert and the ShenZehn certs signing the backdoors, here are screenshots of the latter: &lt;/P&gt; &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208194221.PNG&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt; &lt;P&gt; Our products detect the Flash exploit+payload as &lt;a href=https://www.virustotal.com/en/file/6f313c9dd05a654fc9e197ab55fdcab0ac397f765e8a66cc1c1f5475697d795d/analysis/ target=_blank&gt;Exploit.SWF.CVE-2013-0634.a&lt;/a&gt;. Here is a heatmap of our worldwide detections. Note that not all of these detections are Lady Boyle related, I estimate that at least a  third of them are: &lt;/P&gt; &lt;P&gt; &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208194222.PNG&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt; &lt;/P&gt; &lt;P&gt; Other sites hosting the Lady Boyle swf exploit over the past couple of months have included &quot;tibetangeeks.com&quot;, who recently cleaned up their site and posted a cooperative plea to their attackers, and &quot;vot.org&quot; or the &quot;Voice of Tibet&quot; which is also cleaned up. Currently cleaned up but previously serving &quot;Exploit.SWF.CVE-2013-0634.a&quot; were Uyghur related sites &quot;istiqlaltv.com&quot; and &quot;maarip.org&quot;, with the same &quot;LadyBoyle&quot; swf path as the Tibetan Homes Foundation, i.e.: &lt;BR&gt; hxxp://maarip.org/uyghur/footer(.)swf &lt;BR&gt; &lt;/P&gt; &lt;P&gt; &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208194223.PNG&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt; &lt;/P&gt; &lt;P&gt; So, what we have is an active watering hole campaign implementing a fairly new Flash exploit and abusing digital certificates that were stolen as a part of the ongoing &lt;a href=http://www.securelist.com/en/blog/855/Winnti_FAQ_More_than_just_a_game target=_blank&gt;Winnti targeted attack campaigns&lt;/a&gt; on game developers and publishers. &lt;/P&gt; &lt;P&gt; Related md5:  &lt;BR&gt; BD9FD3E199C3DAB16CF8C9134E06FE12 &lt;BR&gt; 215CEC7261D70A5913E79CD11EBC9ECC &lt;BR&gt; 12181311E049EB9F1B909EABFDB55427 &lt;BR&gt; &lt;/P&gt;</description>
		<guid>http://www.securelist.com/en/blog/208194218/Winnti_Stolen_Digital_Certificates_Re_Used_in_Current_Watering_Hole_Attacks_on_Tibetan_and_Uyghur_Groups</guid>
		<link>http://www.securelist.com/en/blog/208194218/Winnti_Stolen_Digital_Certificates_Re_Used_in_Current_Watering_Hole_Attacks_on_Tibetan_and_Uyghur_Groups</link>
		<pubDate>12 Apr 2013 04:31:18 +0400</pubDate>
		<title>Winnti-Stolen Digital Certificates Re-Used in Current Watering Hole Attacks on Tibetan and Uyghur Groups</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Dmitry Tarakanov)</author>
		<description>&lt;p&gt;During our &lt;a href=&quot;http://www.securelist.com/en/analysis/204792287/Winnti_More_than_just_a_game&quot;&gt;research on the Winnti group&lt;/a&gt; we discovered a considerable amount of Winnti samples targeting different gaming companies. Using this &lt;a href=&quot;http://www.securelist.com/en/analysis/204792286/Winnti_1_0_technical_analysis&quot;&gt;sophisticated malicious program&lt;/a&gt; cybercriminals gained remote access to infected workstations and then carried out further activity manually.&lt;/p&gt; &lt;p&gt;Naturally, we were keen to find out how the malicious libraries spread across a local network. To do so, we tracked the attackers- activity on an infected computer.&lt;/p&gt; &lt;h2&gt;1&lt;sup&gt;st&lt;/sup&gt; attempt: virtual machine #1&lt;/h2&gt; &lt;p&gt;At the beginning of the investigation we ran the malicious programs on a virtual machine, which worked fairly well - we even spotted some cybercriminal activity. But they quickly realized it wasn-t a computer they wanted to net. Once that was the case, the attackers- servers stopped responding to requests from bots working on virtual machines.&lt;/p&gt; &lt;p&gt;This is what we managed to learn at this stage of our monitoring.&lt;/p&gt; &lt;p&gt;First of all, the perpetrators looked at what was happening on the victim-s desktop. After that they enabled the remote command line and used it to browse the root folder of the current disk, searched for the file winmm.dll, and checked the operating system version. The ListFileManager plugin then came into play. It works with the file system and the attackers used it to browse the folders C:\Windows and C:\Work. Then they tried to restart the computer, but made a mistake in the parameters of the ?shutdown command, having typed ?shutdown /t /r 1 (the computer should have been restarted in 1 second), but after a while they shut the computer down completely with the use of the correct command ?shutdown /s /t 1.&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/851/The_Winnti_honeypot_luring_intruders</guid>
		<link>http://www.securelist.com/en/blog/851/The_Winnti_honeypot_luring_intruders</link>
		<pubDate>11 Apr 2013 17:23:00 +0400</pubDate>
		<title>The Winnti honeypot - luring intruders</title>
	</item>
	<item>
		<author>webmaster@securelist.com (GReAT)</author>
		<description>&lt;p&gt; Today Kaspersky Lab's team of experts published a detailed research report that analyzes a sustained cyberespionage campaign conducted by the cybercriminal organization known as Winnti. &lt;/p&gt;&lt;p&gt;&lt;p&gt;According to report, the Winnti group has been attacking companies in the online video game industry since 2009 and is currently still active. &lt;/p&gt; &lt;p&gt;The group's objectives are stealing digital certificates signed by legitimate software vendors in addition to intellectual property theft, including the source code of online game projects. &lt;/p&gt; The attackers' favorite tool is the malicious program we called &quot;Winnti&quot;. It has evolved since its first use, but all variants can be divided into two generations: 1.x and 2.x. Our publication describes both variants of this tool.&lt;/p&gt;&lt;p&gt;&lt;p&gt;In our report we publish &lt;a href=analysis/204792286/Winnti_1_0_technical_analysis&gt;&lt;b&gt;an analysis of the first generation&lt;/b&gt;&lt;/a&gt; of Winnti.&lt;/p&gt;&lt;p&gt;&lt;p&gt;The second generation (2.x) was used in one of the attacks which we investigated during its active stage, helping the victim to interrupt data transfer and isolate infections in the corporate network. The incidents, as well as results of our investigation, are &lt;a href=downloads/vlpdfs/winnti-more-than-just-a-game-130410.pdf&gt;&lt;b&gt;described in the full report&lt;/a&gt; (PDF)&lt;/b&gt; on the Winnti group. &lt;/p&gt;&lt;p&gt;&lt;p&gt;The Executive Summary is available &lt;a href=analysis/204792287/Winnti_More_than_just_a_game&gt;&lt;b&gt;here&lt;/b&gt;&lt;/a&gt;.&lt;/P&gt;&lt;p&gt;&lt;p&gt;&lt;b&gt;Is this research about a gaming Trojan from 2011?  Why do you think it is significant?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;This research is about a set of  industrial cyberespionage campaigns and a criminal organization   which massively penetrates   many software companies and plays a very important role in the success of cyberespionage campaigns of other malicious actors.&lt;/p&gt; &lt;p&gt;&lt;p&gt;It is important to be aware of this threat actor to understand the broader picture of cyberattacks coming from Asia. Having infected gaming companies that do business in the MMORPG space, the attackers potentially get access to millions of users. So far, we don't have data that the attackers stole from common users but we do have at least 2 incidents where the Winnti malware was planted on an online game update servers and these malicious executables were spread among a large number of the online gamers. The samples we  observed seemed not to be malware targeting end user gamers, but a malware module which accidentally got into wrong place. Hoever, the potential for attackers to misuse such access to infect hundreds of millions of Internet users creates a  major global risk.&lt;/p&gt; &lt;p&gt;&lt;p&gt;It's important to understand that many gaming companies do business not only in gaming, but very often they are also developers or publishers of different other types of software. We have tracked an incident where a compromised company served an update of their software which included a Trojan from the Winnti hacking team. That became an infection vector to penetrate another company, which in turn led to a personal data leak of large number of its customers.&lt;/p&gt; &lt;p&gt;&lt;p&gt;So far, this research is dedicated to a malicious group that not only undermines trust in fair gameplay but has a serious impact on trust in software vendors in general, especially in the regions where the Winnti group is active at the moment.&lt;/p&gt;&lt;p&gt;&lt;p&gt;&lt;b&gt;What are the malicious purposes of this Trojan?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;The Trojan, or to be precise, a penetration kit called Winnti includes various modules to provide general purpose remote access to  compromised machines. This includes general system information collection, file and process management, creating chains of network port redirection for convenient data exfiltration and remote desktop access.&lt;/p&gt;&lt;p&gt;&lt;p&gt;&lt;b&gt;Is this attack still active?&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;Yes, despite active steps to stop the attackers by the revocation of digital certificates, detection of the malware and an active investigation,  the attackers remain active, with at least several victim companies around the world being actively compromised.&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/855/Winnti_FAQ_More_than_just_a_game</guid>
		<link>http://www.securelist.com/en/blog/855/Winnti_FAQ_More_than_just_a_game</link>
		<pubDate>11 Apr 2013 17:21:16 +0400</pubDate>
		<title>Winnti FAQ. More than just a game</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Kurt Baumgartner)</author>
		<description>&lt;P&gt; Microsoft released two Bulletins this month patching 3 critical vulnerabilities. Along with these immediate issues, they released five other Bulletins rated &quot;Important&quot;. It appears that the two critical Bulletins address use-after-free vulnerabilities that can all be attacked through Internet Explorer. &lt;/P&gt; &lt;P&gt; For the Windows workstation environments, all versions of Internet Explorer need to be patched asap, including v10 preview running on Windows RT. The patch for Internet Explorer 10 on Windows RT is available at the &quot;Windows Update&quot; site. &lt;/P&gt; &lt;P&gt; In addition to the privately reported vulnerabilities in Internet Explorer code itself, the Remote Desktop Connection v6.1 Client and Remote Desktop Connection v7.0 Client ActiveX components on XP, Vista, and Windows 7 are vulnerable. Microsoft's SRD team expects to see exploits available within 30 days targeting CVE-2013-1296.  &lt;/P&gt; &lt;P&gt; Of the &quot;Important&quot; vulnerabilities, interesting to note is a privately reported Elevation of Privilege issue CVE-2013-0078, which is a bug in the Windows Defender anti-malware engine running on Windows 8 and Windows RT. This vulnerability could be used by an insider or determined adversary to gain further access, and not a type of vulnerability usually hit by mass exploitation kits. Within organizations, this is something to quickly address, but generally individuals do not need to urgently address this type of issue.  &lt;/P&gt; &lt;P&gt; See Microsoft's &lt;a href=http://technet.microsoft.com/en-us/security/bulletin/ms13-apr target=_blank&gt;Security Bulletin Summary for April 2013&lt;/a&gt; for the full list of this month's Bulletin releases. &lt;/P&gt;</description>
		<guid>http://www.securelist.com/en/blog/208194217/Microsoft_Updates_April_2013_3_Critical_Vulnerabilities</guid>
		<link>http://www.securelist.com/en/blog/208194217/Microsoft_Updates_April_2013_3_Critical_Vulnerabilities</link>
		<pubDate>09 Apr 2013 22:23:20 +0400</pubDate>
		<title>Microsoft Updates April 2013 - 3 Critical Vulnerabilities</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Tatiana Kulikova)</author>
		<description>&lt;p&gt;A large number of scam emails disguised as newsletters sent by the CNN television channel have been detected again. Sensational headlines are used in the messages to grab the attention of recipients (e.g., falling stock indexes, the election of a new Pope etc.). Users are asked to click on the links provided in the messages to get access to the complete versions of the articles. To make them look authentic, the emails also include links to real CNN pages, but of course the link with the main piece of news is fake. It leads to a compromised website which uses JavaScript to redirect the user to a site hosting malware - in this case, the Blackhole exploit kit.&lt;/p&gt;  &lt;p class=c&gt;&lt;img src=&quot;http://www.securelist.com/en/images/pictures/klblog/853.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt; &lt;p&gt;At the same time as the CNN newsletter scam, there has also been an epidemic of scam emails imitating Facebook notifications. In these emails, spammers suggested that users check out new comments on their photos. The mechanism used in the malicious link was the same as in the case described above. The most curious part, though, was that the scammers did not even bother to change the links. While in the former case the link included &amp;#8220;cnnbrnews.html&amp;#8221; after the domain name, the same ending in the link provided in fake Facebook messages looks out of place.&lt;/p&gt; &lt;p class=c&gt;&lt;img src=&quot;http://www.securelist.com/en/images/pictures/klblog/854.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt; &lt;p&gt;Unfortunately, this is the only part of the scam where the cybercriminals were careless. Emails containing the malicious links are still being distributed, so be cautious when handling suspicious messages.&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/852/Absent_minded_spammers</guid>
		<link>http://www.securelist.com/en/blog/852/Absent_minded_spammers</link>
		<pubDate>09 Apr 2013 17:42:00 +0400</pubDate>
		<title>Absent-minded spammers</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Dmitry Bestuzhev)</author>
		<description> Is it a Skype day? Or maybe a Bitcoin one? Or maybe just both-    I say this because right after I published my &lt;a href=&quot;http://www.securelist.com/en/blog/208194206/An_avalanche_in_Skype&quot;&gt;previous post&lt;/a&gt; about malware ongoing campaign on Skype, a mate from Venezuela sent me a screenshot of her Skype client with a similar campaign in terms of propagation but different in terms of origins and purposes. Here is the original screenshot:    &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208194211.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt; (Translation from Spanish: ?&lt;i&gt;&lt;b&gt;this is my favorite picture of you&lt;/b&gt;&lt;/i&gt;)   </description>
		<guid>http://www.securelist.com/en/blog/208194210/Skypemageddon_by_bitcoining</guid>
		<link>http://www.securelist.com/en/blog/208194210/Skypemageddon_by_bitcoining</link>
		<pubDate>04 Apr 2013 23:28:00 +0400</pubDate>
		<title>Skypemageddon by bitcoining</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Dmitry Bestuzhev)</author>
		<description> There is a new malicious ongoing campaign on Skype. Its active and kicking yet.     The infection vector is via social engineering abusing infected Skype by sending massive messages to the contacts like these ones:    &lt;b&gt;i don't think i will ever sleep again after seeing this photo&lt;/b&gt; &lt;i&gt;http://www.goo.gl/XXXXX?image=IMG0540250-JPG&lt;/i&gt;  &lt;b&gt;tell me what you think of this picture i edited&lt;/b&gt; &lt;i&gt;http://www.goo.gl/XXXXX?image=IMG0540250-JPG &lt;/i&gt;    Goo.gl short URL service shows that at the moment there are more than 170k clicks on the malicious URL and only 1 hour ago there were around 160k clicks. It means the&lt;b&gt; campaign is quite active with around 10k clicks per hour or with 2.7 clicks per second!    &lt;/b&gt;The most of victims come from Russia and Ukraine:    &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208194207.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/208194206/An_avalanche_in_Skype</guid>
		<link>http://www.securelist.com/en/blog/208194206/An_avalanche_in_Skype</link>
		<pubDate>04 Apr 2013 18:40:19 +0400</pubDate>
		<title>An avalanche in Skype</title>
	</item>
	<item>
		<author>webmaster@securelist.com (David)</author>
		<description>&lt;p&gt;Some of you may remember the virus wallpaper calendars that we published in previous years, listing a selection of significant events in the history of the IT security industry.&lt;/p&gt;&lt;p&gt;&lt;p&gt;Well, we're posting new versions for 2013.&lt;/p&gt;&lt;p&gt;&lt;p&gt;April's wallpaper is here.&lt;/p&gt;&lt;p&gt;&lt;p class=c&gt;&lt;a href=&quot;http://www.securelist.com/en/calendar&quot;&gt;&lt;img src=&quot;images/pictures/klblog/208194205.jpg&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/a&gt;&lt;br/&gt;&lt;span class=small&gt;clickable!&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;But be sure to check our &lt;a href=&quot;http://www.securelist.com/en/ http://www.securelist.com/en/calendar &quot;target=_blank&gt;calendar page&lt;/a&gt; each month as we'll be adding new wallpapers as we go through the year.&lt;/p&gt;&lt;p&gt;&lt;p&gt;We hope they'll be an interesting background for your desktop, as well as highlighting key security events from the past.&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/208194204/Virus_calendar_wallpapers_for_2013</guid>
		<link>http://www.securelist.com/en/blog/208194204/Virus_calendar_wallpapers_for_2013</link>
		<pubDate>04 Apr 2013 12:06:20 +0400</pubDate>
		<title>Virus calendar wallpapers for 2013</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Roel)</author>
		<description>&lt;p&gt;&quot;If the Internet felt a bit more sluggish for you over the last few days in Europe, this may be part of the reason why.&quot; Well, &quot;a bit more sluggish&quot; for limited sets of communications in parts of Europe for a few days is not a broken internet, and is certainly not close to a critical infrastructure disaster.&lt;/p&gt;&lt;p&gt;&lt;p&gt;There's been a lot of attention for the recent reports regarding a DDoS attack against Spamhaus which reached a peak of 300gbps. Yes, such enormous amount of throughput definitely makes this one of the biggest DDoS attacks ever seen. DDoS attacks have seen an increase in popularity in recent times and there's no sign they'll go away anytime soon. Cyber-criminals, competitors, hacktivists and nation-state sponsored actors all have their motives to use DDoS attacks. In this case, a suspected entity behind these attacks is a Dutch hosting company called CyberBunker, whose owner denies being responsible, but claims to be a spokesman for the attackers. The conflict between Spamhaus and CyberBunker goes back to 2011 and has now escalated after Spamhaus blacklisted CyberBunker earlier this month. The timing and conflict is uncanny. And, Spamhaus is certainly under attack from some determined group capable of generating massive amounts of traffic, forcing them to move to hosting and service provider CloudFlare, known for effectively dissipating large DDoS attacks.&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/208194203/The_Biggest_DDoS_Ever_that_Almost_Broke_the_Internet</guid>
		<link>http://www.securelist.com/en/blog/208194203/The_Biggest_DDoS_Ever_that_Almost_Broke_the_Internet</link>
		<pubDate>30 Mar 2013 08:25:45 +0400</pubDate>
		<title>The Biggest DDoS Ever that &quot;Almost Broke the Internet&quot;?</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Ben Godwood)</author>
		<description>&lt;style&gt; pre {color:black} .mail {color:blue;text-decoration:underline;} &lt;/style&gt;&lt;p&gt;&lt;p&gt;Over the last few months we have seen a series of very similar targeted attacks being blocked in our Linux Mail Security Product. In each case the documents used were RTF and the exploit was CVE-2012-0158 (MSCOMCTL.OCX RCE Vulnerability).&lt;/p&gt;&lt;p&gt;&lt;p&gt;The attacks seem to be from the same group and most appear to be sent from Australia or Republic of Korea. The sender IP addresses vary but many are sent via &lt;em&gt;mail.mailftast.com&lt;/em&gt;. This domain is registered in China:&lt;/p&gt;&lt;p&gt;&lt;pre&gt;REGISTRANT CONTACT INFO liu runxin No.1,Nanjing Road Shanghai Shanghai 200001 CN Phone:         +86.2164415698 Email Address: &lt;span class=&quot;mail&quot;&gt;lishd2011@163.com&lt;/span&gt;&lt;/pre&gt;&lt;p&gt;&lt;p&gt;The documents are in three categories:&lt;/p&gt; &lt;ol&gt; &lt;li&gt;The first group of documents are related to articles on the Mens Health website. These are some example filenames:&lt;p&gt;&lt;pre&gt;EAT FOR BETTER SEX.doc How to last longer in bed.doc 6 Awkward Sex Moments, Defused.doc 9 ways to have better,hotter,and more memorable sex.doc 10 Ways to Get More Sex.doc&lt;/pre&gt;&lt;p&gt;&lt;li&gt;The second group are military related: &lt;pre&gt;Stealth Frigate.doc The BrahMos Missile.doc How DRDO failed India's military.doc&lt;/pre&gt;&lt;p&gt;&lt;li&gt;The third set have Cyrillic filenames: &lt;pre&gt;&amp;#1087;&amp;#1088;&amp;#1080;&amp;#1086;&amp;#1088;&amp;#1080;&amp;#1090;&amp;#1077;&amp;#1090;&amp;#1099; &amp;#1089;&amp;#1086;&amp;#1090;&amp;#1088;&amp;#1091;&amp;#1076;&amp;#1085;&amp;#1080;&amp;#1095;&amp;#1077;&amp;#1089;&amp;#1090;&amp;#1074;&amp;#1072;.doc &amp;#1057;&amp;#1087;&amp;#1080;&amp;#1089;&amp;#1086;&amp;#1082; &amp;#1091;&amp;#1095;&amp;#1072;&amp;#1089;&amp;#1090;&amp;#1085;&amp;#1080;&amp;#1082;&amp;#1086;&amp;#1074; &amp;#1088;&amp;#1072;&amp;#1073;&amp;#1086;&amp;#1095;&amp;#1077;&amp;#1081; &amp;#1075;&amp;#1088;&amp;#1091;&amp;#1087;&amp;#1087;&amp;#1099;(0603-2013).doc &amp;#1057;&amp;#1087;&amp;#1080;&amp;#1089;&amp;#1086;&amp;#1082; &amp;#1082;&amp;#1072;&amp;#1076;&amp;#1088;&amp;#1086;&amp;#1074;.doc &amp;#1055;&amp;#1088;&amp;#1080;&amp;#1075;&amp;#1083;&amp;#1072;&amp;#1096;&amp;#1077;&amp;#1085;&amp;#1080;&amp;#1077; &amp;#1052;&amp;#1048;&amp;#1054;&amp;#1052; &amp;#1058;&amp;#1045;&amp;#1049;&amp;#1050;&amp;#1054;&amp;#1042;&amp;#1054; 2013.doc&lt;/pre&gt;&lt;p&gt;&lt;/ol&gt;</description>
		<guid>http://www.securelist.com/en/blog/846/Military_Hardware_and_Mens_Health</guid>
		<link>http://www.securelist.com/en/blog/846/Military_Hardware_and_Mens_Health</link>
		<pubDate>29 Mar 2013 16:40:47 +0400</pubDate>
		<title>Military Hardware and Mens Health</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Costin Raiu)</author>
		<description>&lt;p&gt;In the past, we've seen targeted attacks against Tibetan and Uyghur activists on Windows and Mac OS X platforms. We've documented several interesting attacks (&lt;a href=&quot;https://www.securelist.com/en/blog/208193631/A_Gift_for_Dalai_Lamas_Birthday&quot;&gt;A Gift for Dalai Lamas Birthday&lt;/a&gt; and &lt;a href=&quot;https://www.securelist.com/en/blog/208194116/Cyber_Attacks_Against_Uyghur_Mac_OS_X_Users_Intensify&quot;&gt;Cyber Attacks Against Uyghur Mac OS X Users Intensify&lt;/a&gt;) which used ZIP files as well as DOC, XLS and PDF documents rigged with exploits.&lt;/p&gt; &lt;p&gt;Several days ago, the e-mail account of a high-profile Tibetan activist was hacked and used to send targeted attacks to other activists and human rights advocates. Perhaps the most interesting part is that the attack e-mails had an APK attachment - a malicious program for Android.&lt;/p&gt; &lt;p&gt;&lt;b&gt;The attack&lt;/b&gt;&lt;/p&gt; &lt;p&gt;On March 24th, 2013, the e-mail account of a high-profile Tibetan activist was hacked and used to send spear phishing e-mails to their contact list. This is what the spear phishing e-mail looked like: &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208194187.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt; &lt;p&gt;In regards to the message text above, multiple activist groups have recently organized a human rights conference event in Geneva. We've noticed an increase in the number of attacks using this event as a lure. Here's another example of such an attack hitting Windows users:&lt;/p&gt; &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208194196.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt; &lt;p&gt;Going back to the Android Package (APK) file was attached to the e-mail, this is pushing an Android application named &quot;WUC's Conference.apk&quot;.&lt;/p&gt; &lt;p&gt;This malicious APK is 334326 bytes file, MD5: 0b8806b38b52bebfe39ff585639e2ea2 and is detected by Kaspersky Lab products as &quot;Backdoor.AndroidOS.Chuli.a&quot;.&lt;/p&gt; &lt;p&gt;After the installation, an application named &quot;Conference&quot; appears on the desktop:&lt;/p&gt; &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208194194.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt; &lt;p&gt;If the victim launches this app, he will see text which &quot;enlightens&quot; the information about the upcoming event:&lt;/p&gt; &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208194195.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/208194186/Android_Trojan_Found_in_Targeted_Attack</guid>
		<link>http://www.securelist.com/en/blog/208194186/Android_Trojan_Found_in_Targeted_Attack</link>
		<pubDate>26 Mar 2013 16:14:19 +0400</pubDate>
		<title>Android Trojan Found in Targeted Attack</title>
	</item>
	<item>
		<author>webmaster@securelist.com (GReAT)</author>
		<description>&lt;p&gt;Earlier today, the Laboratory of Cryptography and System Security (CrySyS Lab), together with the Hungarian National Security Authority (NBF), published details on a &lt;a href=&quot;http://blog.crysys.hu/2013/03/teamspy/&quot;&gt;high profile targeted attack against Hungary&lt;/a&gt;. The details about the exact targets are not known and the incident remains classified.&lt;p&gt;&lt;p&gt;Considering the implications of such an attack, Kaspersky Labs Global Research &amp; Analysis Team performed a technical analysis of the campaign and related malware samples.&lt;p&gt;&lt;p&gt;You can read our short FAQ below and you can download our technical analysis paper linked at the end of the blogpost.</description>
		<guid>http://www.securelist.com/en/blog/208194185/The_TeamSpy_Crew_Attacks_Abusing_TeamViewer_for_Cyberespionage</guid>
		<link>http://www.securelist.com/en/blog/208194185/The_TeamSpy_Crew_Attacks_Abusing_TeamViewer_for_Cyberespionage</link>
		<pubDate>20 Mar 2013 21:23:19 +0400</pubDate>
		<title>The TeamSpy Crew Attacks - Abusing TeamViewer for Cyberespionage</title>
	</item>
	<item>
		<author>webmaster@securelist.com (GReAT)</author>
		<description>&lt;p&gt;Earlier today, reports of a number of &lt;a href=&quot;http://www.nknews.org/2013/03/south-korean-banks-broadcasters-paralyzed-by-cyber-attack/&quot;&gt;cyberattacks against various South Korean targets&lt;/a&gt; hit the news. &lt;p&gt;&lt;p&gt;The attackers, going by the handle Whois Team left a number of messages during the defacements:   &lt;center&gt; &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208194184.jpg&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt; &lt;/center&gt;</description>
		<guid>http://www.securelist.com/en/blog/208194183/South_Korean_Whois_Team_attacks</guid>
		<link>http://www.securelist.com/en/blog/208194183/South_Korean_Whois_Team_attacks</link>
		<pubDate>20 Mar 2013 16:09:52 +0400</pubDate>
		<title>South Korean 'Whois Team' attacks</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Fabio Assolini)</author>
		<description>&lt;p&gt;Microsoft recently &lt;a href=&quot;http://blogs.skype.com/2012/11/06/skypewlm/#fbid=wzZJQssfFV3&quot;&gt;announced&lt;/a&gt; the shutdown of its popular IM client MSN Messenger, which will be replaced by Skype, but its end represents the beginning of malicious attacks posing as the installer of the software. Cybercriminals already started to use this fact in their attacks, registering malicious domains, buying sponsored links on search engines, tricking users to download and install a malware masquerade as the MSN installer.&lt;/p&gt;&lt;p&gt;&lt;p&gt;MSN Messenger is still very popular in several countries; Microsoft &lt;a href=&quot;http://techcrunch.com/2012/11/06/end-of-an-era-windows-live-messenger-to-be-retired-users-transitioned-to-skype/&quot;&gt;informed&lt;/a&gt; that the service has more than 100 million users worldwide, approximately 30.5 million of them in Brazil. As an escalated migration of all users is planned, it's getting harder to find the installer of the program and this is the window of opportunity exploited by Brazilian cybercriminals aiming to infect users looking for the software.&lt;/p&gt;&lt;p&gt;&lt;p&gt;In a simple search on Google for &quot;MSN messenger&quot; the first result displayed is sponsored link of a malicious domain aiming to distribute the fake installer, which is actually a Trojan banker:&lt;/p&gt;&lt;p&gt;&lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208194179.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/208194178/The_end_of_MSN_Messenger_the_beginning_of_attacks</guid>
		<link>http://www.securelist.com/en/blog/208194178/The_end_of_MSN_Messenger_the_beginning_of_attacks</link>
		<pubDate>19 Mar 2013 15:27:02 +0400</pubDate>
		<title>The end of MSN Messenger, the beginning of attacks</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Roman Unuchek)</author>
		<description>&lt;p&gt;In mid-February 2013 a Kaspersky user from Malaysia asked us to check a Google Play application called My HRMIS &amp; JPA Demo developed by Nur Nazri.&lt;/p&gt;   &lt;p class=c&gt;&lt;img src=&quot;http://www.securelist.com/en/images/vlweblog/207764503.jpg&quot; alt=''&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;The user was suspicious about the large number of permissions required by the app, though its only stated function was to open four websites.&lt;/p&gt;&lt;p&gt;&lt;p class=c&gt;&lt;img src=&quot;http://www.securelist.com/en/images/vlweblog/207764504.jpg&quot; alt=''&gt;&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/845/Hello_from_Malaysia</guid>
		<link>http://www.securelist.com/en/blog/845/Hello_from_Malaysia</link>
		<pubDate>15 Mar 2013 18:48:00 +0400</pubDate>
		<title>Hello from Malaysia</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Stefano Ortolani)</author>
		<description>&lt;p&gt; Every year as Europe wakes up from the cold winter to the warm days of spring, BlackHat traditionally descends to Amsterdam. This years conference is taking place on March 14-15 at the NH Grand Hotel Krasnapolsky, right Dam Square, the heart of Amsterdam. As spring doesnt necessarily equal warm days here in Europe right now, the 500 or so BlackHat participants hit the conference rooms to attend quite a few interesting talks. Heres a summary of the best talks at BlackHat Europe 2013. &lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/208194175/Highlights_from_BlackHat_Europe_2013_in_Amsterdam</guid>
		<link>http://www.securelist.com/en/blog/208194175/Highlights_from_BlackHat_Europe_2013_in_Amsterdam</link>
		<pubDate>15 Mar 2013 18:41:50 +0400</pubDate>
		<title>Highlights from BlackHat Europe 2013 in Amsterdam</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Ben Godwood)</author>
		<description>&lt;p&gt;On March 4&lt;sup&gt;th&lt;/sup&gt; we spotted a large number of unusual emails being blocked by our Linux Mail Security product. The emails all contained the same PDF attachment (MD5: &lt;em&gt;97b720519aefa00da58026f03d818251&lt;/em&gt;) but were being sent from many different source addresses.&lt;/p&gt; &lt;p&gt;The emails were written in German and most were sent from German IP addresses. Below is a map showing the distribution of addresses:&lt;/p&gt; &lt;p class=&quot;c&quot;&gt;&lt;img src=&quot;images/pictures/klblog/838.jpg&quot; border=0 width=494 height=419 alt=''&gt;&lt;/p&gt; &lt;p&gt;The computer names referenced in the mail headers were often of the form Andreas-PC or Kerstin-Laptop (the names have been changed to protect the innocent) suggesting that they had been sent from German home computers.&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/837/Reminder_be_careful_opening_invoices_on_the_21st_March</guid>
		<link>http://www.securelist.com/en/blog/837/Reminder_be_careful_opening_invoices_on_the_21st_March</link>
		<pubDate>14 Mar 2013 19:23:00 +0400</pubDate>
		<title>Reminder: be careful opening invoices on the 21st March</title>
	</item>

</channel>
</rss>


