Wednesday, March 14, 2018

Backdoored Russian BitTorrent client MediaGet infect 400,000 users

Backdoored Russian BitTorrent client MediaGet infect 400,000 users 

A massive malware outbreak that attempted to infect over 400,000 users during a 12-hour period was caused by a backdoored Russian-based BitTorrent client named MediaGet.
Backdoored Russian BitTorrent client MediaGet infect 400,000 users

The outbreak happened last Tuesday, on March 6. Microsoft said that the Windows Defender team picked up and stopped a massive malware operation that came out of the blue and attempted to infect mostly Russian and Turkish users with the Dofoil (Smoke Loader) trojan.
Microsoft published an in-depth report of how the malware operated, revealing Dofoil would later try to download and install a Monero miner.
At the time, Microsoft did not reveal how Dofoil landed on users' computers, mainly because it was not entirely sure. Now, the company has published more details, and according to the Windows Defender team, the Dofoil malware landed on users' computers via a file named my.dat, created by mediaget.exe —the MediaGet BitTorrent client's binary.

MediaGet hack happened in mid-February

"Our continued investigation on the Dofoil outbreak revealed that the March 6 campaign was a carefully planned attack with initial groundwork dating back to mid-February," the Windows Defender team said today in a new report.
Microsoft alleges hackers broke into MediaGet's infrastructure, and sometimes between February 12 and 19, attackers managed to replace the official MediaGet installer with one that also included a backdoor.
Hackers then allowed for a two-week window so users would install or update to the new MediaGet versions, the one containing the backdoor.
Attackers started running first tests on March 1, by using the backdoor to plant malware on users' computers and sprung their main attack on March 6, when they delivered the Dofoil+coinminer malware combo.

During their attack, crooks also used a stolen digital certificate to sign the poisoned MediaGet update, in an attempt to avoid detection.
Microsoft said it notified both MediaGet and the company's whose certificate crooks have abused. Bleeping Computer could not reach MediaGet for additional comments on the incident, mainly to clarify how hackers broke into their network.

Supply chain attacks are very efficient

This incident is not the first time when hackers broke into websites to poison a BitTorrent client with malware. Previously, hackers breached the site of the Transmission BitTorrent client on two separate occasions. First, they distributed the KeRanger ransomware, and later the Keydnap infostealer malware, both incidents aimed at Mac users.
Hackers have also breached other software distribution websites in the past to insert malware into downloadable files. Other incidents include phpBB, Elmedia Player, HandBrake, and Linux Mint.
But, of course, the most prominent supply chain attack still remains the NotPetya ransomware outbreak —carried out via a tainted update for M.E.Doc, a Ukrainian accounting software program.

 Source

 
Share:

MAC Calendar App Mines Cryptocurrency in Exchange for Free Access to Premium Account

MAC Calendar App Mines Cryptocurrency in Exchange for Free Access to Premium Account



Apple pulled a calendar app from the Mac App Store after it introduced a feature to mine cryptocurrency. The app, Calendar 2, mined a cryptocurrency called Monero in the background.

It was found that a scheduling app, dubbed Calendar 2, was embracing cryptocurrency mining in exchange for free access to its app premium features, but the developer has to take it down from the Apple App Store following reports that it's not working as intended.
MAC Calendar App Mines Cryptocurrency in Exchange for Free Access to Premium Account

Cryptocurrency mining is not a new concept, but the technology has recently exploded after hackers found it a great way to make millions of dollars by hijacking computers to secretly perform cryptocurrency mining in the background without users' knowledge or consent.

Due to this cryptocurrency mining has emerged as one of the biggest threats in recent months, raising negative sentiments towards this alternative revenue scheme.

However, it seems that Apple has no problem with this alternative if app developers take user's consent to mine cryptocurrencies.

Developed by Qbix, Calendar 2 includes more features than the regular Calendar app that comes bundled with macOS, and cost $0.99 per month or $17.99 one-time fees via in-app purchases.

However, the app recently included a default feature that unlocks 'advanced' paid features of Calendar 2 by allowing the app to mine the digital currency known as Monero (XMR) for its developer in the background.

But unfortunately, the app contains two serious bugs: one that kept the Monero miner running, even if users tried to opt-out of the default setting, and a second issue that caused the miner to consume more CPU duty cycle than originally intended.

"It ate 200% CPU until I found it and killed it. I didn't expect a miner infection from an App Store vendor. Wow. It runs the xmr-stak Monero miner," one user on Twitter reported.

In response to the reports, Qbix founder Gregory Magarshak acknowledged the issues and decided to remove the mining function from his app, citing some issues with the miner's source code, the feature's buggy launch and a personal dislike for "proof of work" computing.

Even though the miner is removed from Calendar 2, it's unclear whether the cryptocurrency mining within apps breaches App Store terms of service, as Calendar 2's method of openly embracing mining in exchange of paid services is new to the Mac App Store.


Share:

Saturday, March 10, 2018

ISP Caught Deploying Crypto Mining Malware in Turkey, Syria and Egypt


ISP Caught Deploying Crypto Mining Malware in Turkey, Syria and Egypt



Sandvine PacketLogic devices

Turkey, Syria and Egypt Fingered


Fingers have been pointed at internet providers in Turkey and Syria which have been secretly injecting surveillance malware, while those in Egypt have been using the same technology to inject browser based mining malware.

According to reports ISPs in these three countries are using Deep Packet Inspection technology from Sandvine to intercept and manipulate web traffic and end users’ computers. The technology allows internet providers to prioritize, degrade, block, inject, and log various types of internet traffic on a packet by packet basis.

Turkey’s Telecom network has been using Sandvine PacketLogic devices to redirect hundreds of targeted users to malicious websites and spyware. Similar incidents were recorded in Syria whereby users have been redirected to spurious versions of antivirus software containing government malware.

In Egypt telecoms operators have taken a step further and are using the technology to secretly inject crypto mining scripts into every HTTP page that users accessed. Researchers at Citizen Lab found that providers were using a scheme called AdHose to covertly raise money by mining the anonymous altcoin Monero;


Share:

Wednesday, March 7, 2018

50,000 sites infected with cryptocurrency mining malware

The cryptocurrency mining malware infectious is getting out of hand: nearly 50,000 sites have been surreptitiously infected with crypto-jacking scripts, according to security researcher Troy Mursch from Bad Packets Report.

Relying on source-code search engine PublicWWW to scan the web for pages running crypto-jacking malware, Mursch was able to identify at least 48,953 affected websites. He adds that at least 7,368 of the compromised sites are powered by WordPress.

The researcher notes that Coinhive continues to be the most widespread crypto-jacking script out there, accounting for close to 40,000 infected websites – a stunning 81 percent of all recorded cases.
It is worth pointing out that Mursch was able to find at least 30,000 websites running Coinhive back in November last year.

50,000 sites infected with cryptocurrency mining malware
The researcher has also published a Cryptojacking campaign targeting WordPress sites document on PasteBin file


Reference

https://pastebin.com/gYkbVP8b
https://badpackets.net/how-to-find-cryptojacking-malware/
https://publicwww.com/


Share:

Popular Posts