More Ransomware Plaguing Android
Android users have been warned again that they too can become victims of ransomware.
A Cryptolocker-style Android virus dubbed Simplocker has been detected by security firm Eset, which confirmed that it scrambles files on the SD cards of infected devices before issuing a demand for payment.
The message is in Russian and the demand for payment is in Ukrainian hryvnias, equating to somewhere between £15 and £20.
Naturally, the warning also accuses the victim of looking at rather unsavoury images on their phone. However, while the source of the malware is said to be an app called “Sex xionix”, it isn’t available at the Google Play Store, which generally means that anyone who sideloads it is asking for trouble.
Eset believes that this is actually more of a “proof of concept” than an all-out attack, and far less dangerous than Cryptolocker, but fully functional.
Robert Lipovsky of Eset said, “The malware is fully capable of encrypting the user’s files, which may be lost if the encryption key is not retrieved. While the malware does contain functionality to decrypt the files, we strongly recommend against paying up – not only because that will only motivate other malware authors to continue these kinds of filthy operations, but also because there is no guarantee that the crook will keep their part of the deal and actually decrypt them.”
Eset recommends the usual – use a malware app. It recommends its own, obviously, and advises punters to keep files backed up. Following such advice, said Lipovsky, ensures that ransomware is “nothing more than a nuisance”.
This is not the first Android cryptolocker style virus. Last month a similar virus was found, which Kaspersky said was “unsurprising, considering Android’s market share”.
Will Google’s Project Shield Work?
Google has opened Project Shield, its service for small websites that don’t have the forces to repel denial of service attacks that might come their way.
Google introduced the service on Google+, saying that it is aimed at websites that might otherwise be at risk of online disruption.
“Project Shield, [is] an initiative that enables people to use Google’s technology to better protect websites that might otherwise have been taken offline by “distributed denial of service” (DDoS) attacks. We’re currently inviting webmasters serving independent news, human rights, and elections-related content to apply to join our next round of trusted testers,” it said.
“Over the last year, Project Shield has been successfully used by a number of trusted testers, including Balatarin, a Persian-language social and political blog, and Aymta , a website providing early-warning of scud missiles to people in Syria. Project Shield was also used to protect the election monitoring service in Kenya, which was the first time their site stayed up throughout an election cycle.”
Interested websites should visit the Google Project Shield page and request an invitation to the experience. They should not try to do the same at Nvidia’s website, as they will probably just come away with a handheld games console. This will not offer much assistance against DDoS attacks.
According to a video shared by Google last night, Project Shield works by combining the firm’s DDoS mitigation technologies and Page Speed Service (PSS).
Are Russian Hackers Exploiting Android?
Comments Off on Are Russian Hackers Exploiting Android?
Russian mobile malware factories are working with thousands of affiliates to exploit Android users, a security company has claimed.
According to Lookout Mobile Security the system is so efficient that almost a third of all mobile malware is made by just 10 organisations operating out of Russia. These “malware HQs” are pumping out nasty toll fraud apps, largely aimed at Android users, which force the user to call premium rate numbers the report said.
Thousands of affiliate marketers are also profiting from the scheme and helping spread the malware by setting up websites designed to trick users into downloading seemingly legitimate apps. Affiliates can make up to $12,000 a month and are heavy users of Twitter.
The report’s release at the DEF CON 21 conference in Las Vegas indicated that Lookout Mobile Security are working with the spooks to bring the crooks down. The malware HQs had gone to great lengths to obfuscate and encrypt their code to make detection tricky, but their advertising was pretty brazen.
Kaspersky Finds New Malware
Kaspersky Lab has discovered three Flame spyware related malware threats that it said use “sophisticated encryption methods”.
Kaspersky claims that it uncovered the three new hostile programs while analysing a number of Command and Control (C&C) servers used by Flame’s creators.
“Sophisticated encryption methods were utilised so that no one, but the attackers, could obtain the data uploaded from infected machines,” the firm’s statement read.
“The analysis of the scripts used to handle data transmissions to the victims revealed four communication protocols, and only one of them was compatible with Flame.
“It means that at least three other types of malware used these Command and Control servers. There is enough evidence to prove that at least one Flame-related malware is operating in the wild.”
The discovery of the three programs indicates that Flame’s Command and Control platform was being developed in 2006, four years earlier than first thought.
Flame was originally uncovered in May targeting Iranian computer systems. The malware drew widespread concerns within the security industry regarding its advanced espionage capabilities.
The full scale of Flame and its overarching implications remain unknown, despite the ongoing joint research campaign being mounted by Kaspersky, IMPACT, CERT-Bund/BSI and Symantec.
“It was problematic for us to estimate the amount of data stolen by Flame, even after the analysis of its Command and Control servers,” said Kaspersky’s chief security expert, Alexander Gostev.
Following the discovery of the three new related programs, Kaspersky’s chief malware expert Vitaly Kamluk told The INQUIRER that Flame is not the only one in this big family.
“There are others and they aren’t just other known malwares such as Stuxnet, Gauss or Duqu,” he said. “They stay in the shadows and no one has published anything about them yet. Others were probably used for different campaigns.”
Kamluk added that it is “very possible” there are more than the three listed in Kaspersky’s report.
“They started building RedProtocol, yet another ‘language’ for unknown malware. No known client types are using that one, which means that there is even more malware out there,” he added.
Will Help Desks Become Extinct?
Tom Soderstrom, CTO at NASA’s Jet Propulsion Laboratory (JPL), views everything through the clouds.
NASA’s JPL uses 10 public or private clouds to store everything from photos of Mars for public purview to top-secret data.
Pretty soon, Soderstrom told attendees of Computerworld‘s SNW conference, data stored by large enterprises like NASA will be measured in Exabytes; one Exabyte is equal to 1.5 billion CDs or a million terabytes.
And, he noted, the only place to store Exabytes of data is on public and private clouds.
The good news is that with data in the cloud, people will be able to “work with anyone, from anywhere, with any data, using any device at any time,” he said.
And the not-so-bad news is that IT help desks, as we know them, will become a thing of the past, and IT workers in general will have to rethink how they approach application development and security.
“Now the workforce and consumers of IT are becoming mobile. Have you ever called a help desk for your mobile device? What do you do? Probably, the first you do is Google or Bing it. If you can’t get the answer there, you ask your kids. If you can’t get your answer there, you ask your friends who are like you. For us, that’s the workgroup,” Soderstrom said.
BlackBerry Falls Behind In Workplace
September 30, 2011 by admin
Filed under Smartphones
Comments Off on BlackBerry Falls Behind In Workplace
More workers use iPhone and Android smartphones combined than BlackBerry devices, according to a survey of 1,681 U.S.-based workers released today by Forrester Research.
That finding highlights what many have known for a while about the entrenched workplace smartphone veteran: the BlackBerry faces trouble from its competitors.
The BlackBerry, made by Research in Motion, still leads among U.S. workers, with 42%, the survey said, with Apple’s iPhone accounting for 22% and Android devices, 26%.
The survey also found that nearly half, or 48% of the group, said that they chose the primary smartphone used for their work without considering what their company supports. Only 29% said they chose the smartphone from a list of phones the company supports, while 23% said they had no choice in the matter.
Often, corporate IT shops will choose BlackBerry smartphones when requiring a worker to use a specific smartphone, partly because of the perceived security benefits, many analysts, including at Forrester, have found. The growth in Android phones and the iPhone — many of them brought to workplaces by workers independently — are forcing IT shops to rethink that decision, however.
Ted Schadler, a Forrester analyst, said the survey points to two major trends. The first is that more workers than ever are bringing consumer-focused devices, such as Android and iPhone smartphones, to use for work, and more companies are supporting those devices.
Will HP Temporarily Resurrects The TouchPad?
September 3, 2011 by admin
Filed under Consumer Electronics
Comments Off on Will HP Temporarily Resurrects The TouchPad?
Hewlett Packard Co plans to produce “one last run” of TouchPads, days after declaring it will discontinue a line of tablets that failed to challenge Apple Inc’s domination of the booming market.
A day after the chief of HP’s personal devices division told Reuters the TouchPad might get a second lease on life, HP announced a temporary about-face on the gadget after being “pleasantly surprised” by the outsized demand generated by a weekend fire-sale.
HP slashed the price of its tablet to $99 from $399 and $499 the weekend after announcing the TouchPad’s demise on August 18, part of a raft of decisions intended to move HP away from the consumer and focus on enterprise clientele.
That ignited an online frenzy and long lines at retailers as bargain-hunters chased down a gadget that had been on store shelves just six weeks.
“The speed at which it disappeared from inventory has been stunning,” the company said. “We have decided to produce one last run of TouchPads to meet unfulfilled demand.”
HP may lose money on every TouchPad in its final production run. According to IHS iSuppli’s preliminary estimates, the 32GB version carries a bill of materials of $318.
“We don’t know exactly when these units will be available or how many we’ll get, and we can’t promise we’ll have enough for everyone. We do know that it will be at least a few weeks before you can purchase,” HP said in a blogpost.