Showing posts with label attacks. Show all posts
Showing posts with label attacks. Show all posts

Feds are Suspects in New Malware That Attacks Tor Anonymity



Security researchers tonight are poring over a piece of malicious software that takes advantage of a Firefox security vulnerability to identify some users of the privacy-protecting Tor anonymity network.

The malware showed up Sunday morning on multiple websites hosted by the anonymous hosting company Freedom Hosting. That would normally be considered a blatantly criminal “drive-by” hack attack, but nobody’s calling in the FBI this time. The FBI is the prime suspect.

“It just sends identifying information to some IP in Reston, Virginia,” says reverse-engineer Vlad Tsrklevich. “It’s pretty clear that it’s FBI or it’s some other law enforcement agency that’s U.S.-based.”

If Tsrklevich and other researchers are right, the code is likely the first sample captured in the wild of the FBI’s “computer and internet protocol address verifier,” or CIPAV, the law enforcement spyware first reported by WIRED in 2007.

Court documents and FBI files released under the FOIA have described the CIPAV as software the FBI can deliver through a browser exploit to gathers information from the target’s machine and send it to an FBI server in Virginia. The FBI has been using the CIPAV since 2002 against hackers, online sexual predator, extortionists and others, primarily to identify suspects who are disguising their location using proxy servers or anonymity services, like Tor.

Commercial DDoS Services Proliferate, are responsible for many recent attacks

http://www.darkreading.com/threat-intelligence/commercial-ddos-services-proliferate-are/240157965
Responsibility for many recent attacks
Imagine a service where, for as little as $10, you can hire a provider to launch a distributed denial-of-service (DDoS) attack against any website you choose.Now imagine that there are as many as 40 such services across the globe, serving customers as young as age 12.

It's no flight of imagination, according to Lance James, head of intelligence at Vigilant by Deloitte, a provider of security event management and threat intelligence services. It's the real deal, and these commercial "booter" services are growing rapidly.

Dropbox, WordPress used as cloud cover in new APT attacks

The cyberespionage gang out of China who recently hacked into media outlet networks is now using Dropbox and WordPress in its attacks rather than via traditional email phishing attacks and server compromise, new research has found.
http://www.darkreading.com/attacks-breaches/dropbox-wordpress-used-as-cloud-cover-in/240158057
WordPress used as cloud cover in new APT attacks

http://www.darkreading.com/attacks-breaches/dropbox-wordpress-used-as-cloud-cover-in/240158057
Dropbox used as cloud cover in new APT attacks


The so-called DNSCalc gang, which breached The New York Times during the fall of 2012 and again in early 2013, appears to be the culprit behind a new wave of attacks targeting individuals and groups associated with the Association of Southeast Asian Nations (ASEAN) Member Nations. The group's new M.O.: using Dropbox to distribute its malware and WordPress for the initial stage of the command-and-control (C&C).