Posts

TESLACRYPT

Image
TeslaCrypt  also know as  EccKrypt  is one of the ransomwares that is widely seen . It encrypts certain files and demands ransom to decrypt the files. TeslaCrypt uses AES symmetric algorithm to encrypt files. Teslacrypt 4 features  RSA  algorithm for encrypting data. TeslaCrypt evolved from a ransomware targeting gamers, but this is not only a  severe threat, but also one that is capable of far wider data leakage. The first version of TeslaCrypt emerged in March 2015, then TeslaCrypt2.0 was launched in November 2015.They launched TeslaCrypt 3.0 in January 2016, and now the fourth version is out. TeslaCrypt is spread using exploit kits such as Angler exploit kit, Neutrino exploit kit. Using Angler, Adobe flash is exploited then it downloads TeslaCrypt as a payload. Using Neutrino, it redirects users to malicious pages that hosts exploit files targeting various vulnerabilities. Once exploited, it delivers a Trojan downloader an...

STUXNET

Image
T hree years after it was discovered, Stuxnet, the first publicly disclosedcyberweapon, continues to baffle military strategists, computer security experts, political decision-makers, and the general public. A comfortable narrative has formed around the weapon: how it attacked the Iranian nuclear facility at Natanz, how it was designed to be undiscoverable, how it escaped from Natanz against its creators’ wishes. Major elements of that story are either incorrect or incomplete. That’s because Stuxnet is not really one weapon, but two. The vast majority of the attention has been paid to Stuxnet’s smaller and simpler attack routine — the one that changes the speeds of the rotors in a centrifuge, which is used to enrich uranium. But the second and “forgotten” routine is about an order of magnitude more complex and stealthy. It qualifies as a nightmare for those who understand industrial control system security. And strangely, this more sophisticated attack came first. The simpler, m...

METAPHOR- Another stagefright

Image
METAPHOR  - “ N orthBit” is a Israeli software research company, claimed that it had properly exploited the Android bug and  is described as the " W orst E ver D iscovered". S tagefright is a multimedia playback library, which is written in C++. It is built inside the Android OS to process, record and play multimedia files such as videos. Millions of Android users could be at risk from this ' Stagefright ' flaw. Researchers claim to have made a working exploit that can remotely take control of a device and spy on victims within 10 seconds. Metaphor give hackers the ability to inject malware that can copy, steal and delete data on the device, take over the smartphone's microphone, camera for spying purposes and even track a user's movements via GPS. HOW IT WORKS : Victims are sent a message linking to a website containing a video file that crashes the phone's media software and force it to restart.  Then, Jav...

USB THIEF

Image
T he Researchers at ESET have found a data - stealing USB Trojan which leaves no trace on the compromised system. Nicknamed as USB Thief (detected as Win32/PSW.Stealer.NAI trojan), this is the most complex trojan ever discovered, it uses encryption and self-protection procedures to infect and hide. The trojan binds on the USB stick using the USB drive's details as an encryption key using  AES 128 encryption. If the trojan is copied to another USB, the encryption breaks  and the content cannot be determined. The malware injects itself as a plugin or a dynamically linked library (DLL) file. When the victim launches the app from an infected USB, the Trojan starts executing in the background. As the malware is executed using a USB device, it does not leave any trace on the machine. The Trojan consists of six files. Four files are executables and the other two contain the configuration data. To protect it from reverse engineering, it uses two techniques. ...