Showing posts with label Flashback. Show all posts
Showing posts with label Flashback. Show all posts

Thursday, 3 May 2012

Flashback Malware-Symantec

Flashback was earning about $10K per day

People often wonder about what motivates the creators of malware. In the case of the Flashback malware that infected several hundred thousand Macs, it turns out that the motivator was money. A post on the Symantec official blog listed the stages of infection from Flashback:

  1. A user visits a compromised website.
  2. The browser is redirected to an exploit site hosting numerous Java exploits.
  3. CVE-2012-0507 is used to decrypt and install the initial OSX.Flashback.K component.
  4. This component downloads a loader and an Ad-clicking component.
That ad-clicking component is what made the money for the scoundrels who wrote the malware. As the Symantec post explains, the malware specifically targets searches made on Google. Depending on the search query, the malware redirected the Mac user to another page chosen by the attacker, and the attacker received revenue from the click-through. Since Google never received the intended ad click, they lost revenue. Symantec analyzed a similar botnet last year and determined that about 25,000 infected machines could net the attacker about US$450 per day. Based on the breadth of the Flashback attack, they estimated that the malware was earning its creators almost $10,000 per day. If you haven't updated your Mac to counteract a possible Java malware attack, or run Apple's free tool for removing the malware from Macs that don't have Java installed, be sure to run Software Update as soon as possible to protect yourself. [via Macworld]Flashback was earning about $10K per day originally appeared on TUAW - The Unofficial Apple Weblog on Tue, 01 May 2012 12:30:00 EST. Please see our terms for use of feeds.Source | Permalink | Email this | Comments read more..

Wednesday, 2 May 2012

Flashback Malware

Flashback Malware's Ad-Click Hijacking Detailed, Could Reap $10,000/Day

Antivirus firm Symantec has published a new blog post examining how the Flashback malware affecting hundreds of thousand of Macs has been generating revenue for its authors by hijacking users' ad clicks. According to the report, the widespread nature of the infection means that malware authors could have been generating up to $10,000 per day from the scheme at its peak based on previous analysis of malware click redirection.The Flashback ad-clicking component is loaded into Chrome, Firefox, and Safari where it can intercept all GET and POST requests from the browser. Flashback specifically targets search queries made on Google and, depending on the search query, may redirect users to another page of the attacker's choosing, where they receive revenue from the click . (Google never receives the intended ad click.)Symantec's work on the ad-click hijacking aspect of Flashback comes after Russian firm Dr. Web, which was responsible for the initial publicity about the malware, published its own report examining some of the early data on infected computers seeking to connect to command-and-control servers.
The report looks at nearly 100,000 connections that came in on April 13, finding that close to two-thirds of the infected machines identified themselves as running Mac OS X Snow Leopard, which was the last version of OS X to ship with Java enabled by default. OS X Lion does not include Java by default, and thus was responsible for only 11% of infections seen during the survey period.
Flashback infection share vs. operating system usage share (Data via Dr. Web, Chart via Computerworld)
As noted by Computerworld, OS X Lion represents nearly 40% of OS X copies currently in use, suggesting that Apple's decision to remove Java from the default Lion install is indeed helping to limit infections on Apple's newest machines.[W]hile Snow Leopard's and Leopard's infection rates are higher than their usage shares, the opposite's true of OS X 10.7, or Lion. The 2011 OS accounted for 39.6% of all copies of OS X used last month, yet represented only 11.2% of the Flashback-compromised Macs.Dr. Web's data on OS kernel versions being reported from infected Macs also demonstrates that many Mac users do not keep their systems up-to-date, with roughly 25% of Snow Leopard and Lion systems seen in the survey reporting themselves as at least one version behind Apple's most recent updates (10.6.8 for Snow Leopard and 10.7.3 for Lion). read more..

Tuesday, 1 May 2012

Flashback Malware-Security Vendor-Snow Leopard-Drive Space

Security vendor: Snow Leopard users most prone to Flashback infection

Of the Macs that have been infected by the Flashback malware, nearly two-thirds are running OS X 10.6, better known as Snow Leopard, Russian antivirus firm Dr. Web says. read more..


Delete Dropbox cache to recover drive space

If you use Dropbox to share files with co-workers and clients, you might be surprised to find yourself running out of room on your hard drive. Here's how to find and delete the offending files. read more..

Saturday, 21 April 2012

Unofficial Apple Weblog-Flashback Infections

Flashback infections down from over half a million to under 150,000 in eight days

According to Symantec, the OSX.Flashback.K infection is declining each day. The current number of infected Macs is now around 140,000, down from 600,000 a week ago. If you think you may be infected, you can run a Flashback removal tool from either Kapersky or F-Secure. Apple also has a tool for Lion users without Java installed. OS X users should install the latest Java update from Apple which will protect you from a future infection.Flashback infections down from over half a million to under 150,000 in eight days originally appeared on TUAW - The Unofficial Apple Weblog on Wed, 18 Apr 2012 09:37:00 EST. Please see our terms for use of feeds.Source | Permalink | Email this | Comments read more..

Thursday, 19 April 2012

Flashback Malware-Symantec

Flashback Malware Still Affecting over 100,000 Macs

While Apple has pushed out several software updates to detect the Flashback malware and remove it from infected systems, Symantec noted late yesterday that over 100,000 machines remain afflicted by the issue as detected by their sinkhole operation to redirect server traffic.
Symantec pegged the number at approximately 142,000 as of Monday, listing a rough estimate of "over 99,000" as yesterday's data was still coming in. Those numbers are down from a peak of over 600,000 machines two weeks ago, but a substantial number of machines are still infected by the malware.The statistics from our sinkhole are showing declining numbers on a daily basis. However, we had originally believed that we would have seen a greater decline in infections at this point in time, but this has proven not to be the case. Currently, it appears that the number of infected computers has tapered off, but remains around the 140,000 mark.
As there have been tools released by Symantec and other vendors in the past few days concerning this threat, the infection numbers should have seen a dramatic decrease by now.Symantec also takes a look at the domain name generator that allows infected machines to connect to their command-and-control servers to receive instructions. The generator uses a list of 14-character strings rotated each day, coupling each string with one of five top-level domains (.com, .net, .info, .in, or .kz) to find its instructions.
The report also claims that Flashback-infected systems can receive updated command-and-control server locations through Twitter, although no details on that process are provided. A similar claim was made for earlier versions of Flashback, although there has apparently been no demonstration of the Twitter delivery method actually being used. read more..

Tuesday, 17 April 2012

Malware Removal-Java Updates-Flashback

Apple Releases Flashback Removal Tool for Macs Running OS X Lion without Java

Following yesterday's release of fresh Java updates to remove the Flashback malware system from Macs running OS X Lion and Snow Leopard, Apple today released a standalone Flashback malware removal tool to clean infections from OS X Lion systems without Java installed.About Flashback malware removal tool
This Flashback malware removal tool that will remove the most common variants of the Flashback malware.
If the Flashback malware is found, a dialog will be presented notifying the user that malware was removed.
In some cases, the Flashback malware removal tool may need to restart your computer in order to completely remove the Flashback malware.
This update is recommended for all OS X Lion users without Java installed.While the most dangerous method of attack for Flashback exploits a security hole in Java that Apple has now patched, various versions of the malware have also used social engineering and other tricks in attempting to gain access to users' systems.
With OS X Lion not having Java included by default, users of Apple's latest operating system who have found themselves infected through other means and do not have Java installed can use the new tool to clean their systems without needing to install Java.
The update weighs in at 356 KB and requires OS X Lion without Java installed. read more..

Monday, 16 April 2012

Automatic Execution-Java Implementation-Java Applets-Flashback-Java Web

Apple Releases Java Update to Remove Flashback Malware

Apple just released Java for OS X 2012-003, an update to the Java implementation in OS X. The update removes "the most common variants of the Flashback malware." Interestingly the update disables the automatic execution of Java applets, and, if automatic execution is re-enabled, will again disable it if no applets have been run for "an extended period of time".
It was reported earlier this week that Apple was in the process of creating software to remove Flashback. It's been claimed that the Flashback malware infected more than 600,000 Macs at its peak, though there have been a number of programs created to quickly and easily cleanse infected machines.
This Java security update removes the most common variants of the Flashback malware.
This update also configures the Java web plug-in to disable the automatic execution of Java applets. Users may re-enable automatic execution of Java applets using the Java Preferences application. If the Java web plug-in detects that no applets have been run for an extended period of time it will again disable Java applets.
This update is recommended for all Mac users with Java installed.
For details about this update see: http://support.apple.com/kb/HT5242
The update can be downloaded via Software Update. A separate Java for Mac OS X 10.6 Update 8 is available for users on Mac OS X Snow Leopard. read more..

Sunday, 8 April 2012

Malicious Website-Trojan

How to find/remove the Flashback trojan

According to Russian antivirus firm Dr. Web, over 600,000 Macs worldwide are infected with the Mac flashback trojan. The trojan can be installed if you visit a malicious website, and it will attempt to connect your Mac to a botnet. Fifty-seven percent of infected machines are located in the US and 20 percent are in Canada. There are even 24 infected machines supposedly connected to the botnet from Apple's Cupertino campus. This trojan targets a Java vulnerability in Mac OS X that was recently patched. It should be noted that in OS X 10.7 Lion, Java isn't included by default; only those who have deliberately installed it are potentially vulnerable to this exploit (or those running Snow Leopard or earlier OS X versions). If you installed it at some point but no longer have a reason to run Java, you should probably turn it off completely or at a minimum disable it in Safari. F-Secure has provided a set of diagnostics that'll let you know if you have been infected. If you have the malware on your machine, F-Secure's page can walk you through the steps to remove the infection. Thanks to everyone who sent this in. [Via The Loop]How to find/remove the Flashback trojan originally appeared on TUAW - The Unofficial Apple Weblog on Thu, 05 Apr 2012 10:15:00 EST. Please see our terms for use of feeds.Source | Source | Permalink | Email this | Comments read more..

Monday, 27 February 2012

Vulnerabilities-Installation-Trojan Horse-Flashback-Malware

Flashback Trojan Returns With a Multi-Pronged Infection Strategy

Last year, we profiled a Mac trojan horse known as "Flashback" that was masquerading as a Flash Player installer. While Apple has taken steps to protect users from the threat using its File Quarantine system under which users' computers initiate daily checks for updated malware definitions, the malware's authors have continued to tweak the trojan to improve its ability to both infect systems and evade detection.Security firm Intego has issued a report on a new variant of the trojan, known as Flashback.G, which adopts a multi-pronged strategy in attacking users' systems. The first two methods rely on vulnerabilities in Java, and while the vulnerabilities are patched in systems running up-to-date versions of Java, outdated systems can be silently infected through these security holes.Flashback.G's self-signed certificate seeking to trick users into allowing installationOn up-to-date systems lacking the Java vulnerabilities, Flashback.G presents a self-signed certificate claiming to be from Apple in an attempt to fool users into allowing the trojan to be installed on their systems. Once installed, the trojan begins searching for user names and passwords it can relay to the malware's authors.This malware patches web browsers and network applications essentially to search for user names and passwords. It looks for a number of domains – websites such as Google, Yahoo!, CNN; bank websites; PayPal; and many others. Presumably, the people behind this malware are looking for both user names and passwords that they can immediately exploit – such as for a bank website – as well as others that may be reused on different sites.Notably, Intego reports that the trojan aborts its own installation if it detects the presence of any of several antivirus applications on a user's Mac, presumably seeking to remain below the radar while focusing on vulnerable systems.Intego recommends that users on Mac OS X Snow Leopard make sure that Java is fully up-to-date by running a check through Software Update, and for all users to be aware of the social engineering trick the trojan uses in attempting to gain permission for installation. The company of course also recommends that users equip their systems with antivirus software.While malware has not been a tremendous threat to Mac users so far, its presence has been growing. Apple has stepped up its efforts to combat malware by enhancing its File Quarantine system to provide for the daily definition checks. OS X Mountain Lion will see another significant step with the introduction of Gatekeeper, a system by which users can limit installation of apps to sources such as the Mac App Store and developers who have registered with Apple as "identified developers".Apple's Developer-ID program will utilize digital signatures on applications to link applications with a specific developer. If the developer is later discovered to be distributing malware or otherwise behaving improperly, installations of its existing apps can be deactivated by Gatekeeper. Gatekeeper does have its limitations, however, as it only scans applications downloaded through a handful of mechanisms such as browsers and can not detect applications that are modified by malware after their initial launch. read more..