Privacy

A New Android Spyware Masquerades as a 'System Update' (techcrunch.com) 20

Security researchers say a powerful new Android malware masquerading as a critical system update can take complete control of a victim's device and steal their data. From a report: The malware was found bundled in an app called "System Update" that had to be installed outside of Google Play, the app store for Android devices. Once installed by the user, the app hides and stealthily exfiltrates data from the victim's device to the operator's servers. Researchers at mobile security firm Zimperium, which discovered the malicious app, said once the victim installs the malicious app, the malware communicates with the operator's Firebase server, used to remotely control the device. The spyware can steal messages, contacts, device details, browser bookmarks and search history, record calls and ambient sound from the microphone, and take photos using the phone's cameras. The malware also tracks the victim's location, searches for document files and grabs copied data from the device's clipboard. The malware hides from the victim and tries to evade capture by reducing how much network data it consumes by uploading thumbnails to the attacker's servers rather than the full image. The malware also captures the most up-to-date data, including location and photos.
Piracy

Courts Sentence Men for Pirating Thousands of Movies and TV Shows, Including Via Plex (torrentfreak.com) 78

An anonymous reader shares a report: Following the dismantling of several private trackers in 2020, a man has been sentenced for sharing thousands of TV shows and movies via now-defunct torrent site DanishBits. In a separate case, another man has been convicted of sharing 9,440 movies with a relatively small circle of family and friends using the popular Plex media server.
Microsoft

Gen Z Is Getting Screwed By Remote Work, Microsoft Survey Finds (cnet.com) 110

"A new study from Microsoft, released Monday, found that among the more than 31,000 workers it surveyed, 73% hoped remote work options would continue when the pandemic ends," reports CNET. "Even Gen Z applicants were slightly more likely to apply for a job with remote options than for one strictly in an office," even though they feel that they're losing out on the career growth that happens in the office. CNET reports: Gen Z workers, born roughly between the mid-1990s and mid-2010s, responded to Microsoft's surveys generally by saying they're more stressed and find they're struggling more than their peers. They tend to be single, since they're younger, leading them to feel isolated. And since they're early in their careers, they don't have financial means to create a good workspace at home if their employer won't pay for it. And they're not having those in-person meetings that sometimes help them land in career advancing projects, or even to get in good with the boss.

"Without hallway conversations, chance encounters, and small talk over coffee, it's hard to feel connected even to my immediate team, much less build meaningful connections across the company," wrote Hannah McConnaughey, a product marketing manager at Microsoft who's a Gen Z worker. "Networking as someone early in their career has gotten so much more daunting since the move to fully remote work -- especially since switching to a totally different team during the pandemic!"

Employees also say they want flexibility rather than fully remote jobs. Of the workers Microsoft surveyed, 73% said they want remote work options to stay, with 46% saying they plan to move now that they can work remotely. Still, 67% said they want more in-person work or collaboration too. In short: We don't seem to know what we want yet. [...] In its conclusions, Microsoft suggests companies invest in technology that helps bridge the physical and digital worlds, so teams can work remotely and in the office. Additionally, it says Gen Z employees need more career support.

Security

A Security App's Fake Reviews Give Us a Window Into 'App Store Optimization' (vice.com) 17

A company that makes an email app that helps users encrypt their emails paid for fake reviews in an attempt to get more people to download its products, according to leaked emails obtained by Motherboard. An anonymous reader shares a report: The CEO of pEp, a Luxembourg-based company that makes the pEp email encryption apps for Android and iOS, commissioned a marketing company to write fake reviews that he himself wrote in the summer of last year. Leon Schumacher asked the marketing company Mobiaso to post 40 five-star reviews in English, French, and German to the Google Play Store. Schumacher included an Excel spreadsheet that contained the specific text that he wanted Mobiaso to use. "Super easy privacy," one fake review said. "One of the best mail applications. I have never had problems and I suggest it all the time to friends," another said.

"Can we speed up today and do 12 ratings per day do 7 reviews per day (Please use the Texts below for the right countries (that I forwarded already per earlier e-mail)," Schumacher wrote in an email to Mobiaso. pEp, short for Pretty Easy Privacy, develops email encryption apps for both iOS and Android, where it has more than 10,000 installs, according to the stats on the Google Play Store. The company, through its foundation, also funded a new library to encrypt emails using PGP, the decades old technology that allows users to encrypt emails and other files. Mobiaso advertises "iOS reviews" and "Android installs" on its website. One of the services the company offers is App Store Optimization, or ASO, which includes fake reviews. The service has several price tiers, ranging from $160 to $450. Only the two most expensive tiers include fake reviews. "Each app developer/advertiser should remember that without a good ASO search optimization, your target audience wouldn't even find or open your app page," Mobiaso says.

Microsoft

Microsoft Defender Antivirus Now Automatically Mitigates Exchange Server Vulnerabilities (zdnet.com) 19

"Microsoft has implemented an automatic mitigation tool within Defender Antivirus to tackle critical vulnerabilities in Exchange Server," reports ZDNet: On March 18, the Redmond giant said the software will automatically mitigate CVE-2021-26855, a severe vulnerability that is being actively exploited in the wild. This vulnerability is one of four that can be used in a wider attack chain to compromise on-premise Exchange servers.

Microsoft released emergency fixes for the security flaws on March 2 and warned that a state-sponsored threat group called Hafnium was actively exploiting the bugs, and since then, tens of thousands of organizations are suspected to have been attacked. At least 10 other advanced persistent threat (APT) groups have jumped on the opportunity slow or fragmented patching has provided.

The implementation of a recent security intelligence update for Microsoft Defender Antivirus and System Center Endpoint Protection means that mitigations will be applied on vulnerable Exchange servers when the software is deployed, without any further input from users. According to the firm, Microsoft Defender Antivirus will automatically identify if a server is vulnerable and apply the mitigation fix once per machine.

The article also points out Microsoft also released a one-click mitigation tool earlier this week, which is "still readily available as an alternative way to mitigate risk to vulnerable servers if IT admins do not have Defender Antivirus."
Security

Acer Hit by $50 Million Ransomware Attack (bleepingcomputer.com) 39

Computer maker Acer has been hit by a ransomware attack "where the threat actors are demanding the largest known ransom to date, $50,000,000," writes Bleeping Computer: Yesterday, the ransomware gang announced on their data leak site that they had breached Acer and shared some images of allegedly stolen files as proof...

In response to BleepingComputer's inquiries, Acer did not provide a clear answer regarding whether they suffered a REvil ransomware attack, saying instead that they "reported recent abnormal situations" to relevant law enforcement and data protection authorities... In requests for further details, Acer said "there is an ongoing investigation and for the sake of security, we are unable to comment on details."

PC Magazine reports that data from Advanced Intel's Andariel cyberintelligence platform "was able to link the possible breach to the Microsoft Exchange issue."
Crime

Russian Man Admits Ransomware Plot Against Tesla In Nevada (apnews.com) 25

A Russian man has pleaded guilty in the U.S. to offering a Tesla employee $1 million to cripple the electric car company's massive electric battery plant in Nevada with ransomware and steal company secrets for extortion, prosecutors and court records said. The Associated Press reports: In a case that cybersecurity experts called exceptional for the risks he took, Egor Igorevich Kriuchkov pleaded guilty Thursday in U.S. District Court in Reno. Prosecutors alleged that Kriuchkov acted on behalf of co-conspirators abroad and attempted to use face-to-face bribery to recruit an insider to physically plant ransomware, which scrambles data on targeted networks and can only be unlocked with a software key provided by the attackers. Typically, ransomware gangs operating from safe havens hack into victim networks over the internet and download data before activating the ransomware.

"The fact that such a risk was taken could, perhaps, suggest that this was an intelligence operation aimed at obtaining information rather than an extortion operation aimed at obtaining money," said Brett Callow, a cybersecurity analyst at anti-virus software company Emsisoft. "It's also possible that the criminals thought the gamble was worth it and decided to roll the dice," Callow said. The FBI said the plot was stopped before any damage happened.
Although Kriuchkov says the Russian government was aware of his case, prosecutors and the FBI have not alleged ties to the Kremlin.

"His guilty plea to conspiracy to intentionally cause damage to a protected computer could have gotten him up to five years in prison and a $250,000 fine," the report says. "But he's expected to face no more than 10 months under terms of his written plea agreement."
United States

US Grid At Rising Risk To Cyberattack, Says GAO 69

Distribution systems within the U.S. electrical grid are increasingly vulnerable to cyberattack, a government watchdog said in a report released Thursday. The Hill reports: In the report, the Government Accountability Office (GAO) noted that the Department of Energy's cybersecurity strategy has predominantly focused on generation and transmission systems. The watchdog recommended further attention to risks facing distribution systems, those parts of the grid that actually carry power directly to customers. Those aspects of the grid, the report states, "are becoming more vulnerable to cyberattacks, in part due of the introduction of and reliance on monitoring and control technologies." "However, the scale of potential impacts from such attacks is not well understood," it states.

Distribution systems' vulnerability is increasing due to their industrial control systems, which have increasingly been incorporating remote access. As a result, they can give bad actors access to them. The systems the report analyzed generally are not covered by federal cybersecurity standards but have in some cases taken independent action on them. Energy Department officials told GAO investigators they were unaware of any assessments underway analyzing how a cyberattack would affect distribution systems, saying the impact would likely be less significant than on generation and transmission. However, the report notes, depending on which distribution was affected it could have nationwide effects.
Piracy

Police Warn Students To Avoid Sci-Hub (bbc.com) 150

Police have warned students in the UK against using the Sci-Hub website, which they say lets users "illegally access" millions of scientific research papers. Specifically, the police say the website could "pose a threat to their personal information and data." The BBC reports: The police are concerned that users of the "Russia-based website" could have information taken and misused online. The Sci-Hub says its website "removes all barriers" to science. It offers open access to more than 85 million scientific papers and claims that copyright laws should be abolished and that such material should be "knowledge to all." It describes itself as "the first pirate website in the world to provide mass and public access to tens of millions of research papers."

But Max Bruce, the City of London Police's cyber protection officer, has urged universities to block the website on their network because of the "threat posed by Sci-Hub to both the university and its students." "If you're tricked into revealing your log-in credentials, whether it's through the use of fake emails or malware, we know that Sci-Hub will then use those details to compromise your university's computer network in order to steal research papers," he said. "Students should be aware that accessing such websites is illegal, as it hosts stolen intellectual property," said Det Insp Kevin Ives. He warned that visitors to the website, whose Twitter account has been suspended, are "very vulnerable to having their credentials stolen."

Facebook

Instagram, WhatsApp, and Facebook Messenger Are Down for Many (theverge.com) 30

Instagram, WhatsApp, and Facebook Messenger are down for many right now. From a report: More than 123,000 users have reported issues with Instagram on DownDetector. More than 23,000 users have reported issues with WhatsApp on DownDetector, too, and the service is down for one Verge staffer's family, who is based in Europe. Facebook Messenger seems to be affected as well, with more than 5,000 reports of problems on DownDetector. When navigating to Instagram's website, I saw a white page with the message "5xx Server Error." And when I redownloaded Instagram to my phone and tried to log in, I hit an error there, too.
Security

The US Government Finally Gets Serious About IoT Security (ieee.org) 66

An anonymous reader quotes a report from IEEE Spectrum, written by Stacey Higginbotham: The IoT Cybersecurity Improvement Act of 2020 has given the nation an excellent framework that will influence IoT security across the world. So, what's to like about the law? Two things, as it turns out. First, the law isn't focused on securing individual devices by dictating password requirements or encryption standards, both of which will need to evolve. Instead, it relies on the National Institute of Standards and Technology (NIST) to set many of the requirements that government agencies have to follow when purchasing connected devices. These policies see overall security as the sum of several parts, requiring specific prescriptions for device, cloud, and communication security.

NIST's initial rules include today's best practices, such as having an over-the-air device update program, unique IDs for each device so it can be identified on a network, and a way for authorized users to change features related to access and security. The recommendations also include logging the actions taken by an IoT device or its related app, and clearly communicating the specifics of a device's security to the user. The other reason to like the law is that it remains adaptive and flexible by requiring NIST to assess the best practices for cybersecurity for connected devices every five years. Hacks, by their nature, are also adaptive and flexible, and so preventing them needs equally adaptable legislation. That means buying IoT devices that can receive over-the-air software updates, for example, to patch up any newly discovered exploits.
"Unfortunately, the law isn't airtight," writes Higginbotham. She worries that the waiver process for devices needed for national security or research could be abused. There's also a loophole that exempts devices that are secured using "alternative and effective methods." The law doesn't clarify what agency evaluates the efficacy of these alternative methods or how that evaluation is made.
Security

Security Researcher Hides ZIP, MP3 Files Inside PNG Files On Twitter (threatpost.com) 24

A security researcher has discovered a novel steganography technique for hiding data inside a Portable Network Graphics (.PNG) image file posted on Twitter, a tactic that could be exploited by threat actors to hide malicious activity. Threatpost reports: Researcher David Buchanan heralded his discovery on Twitter earlier this week, accompanied by a photo declaring: "Save this image and change the extension to .zip!" He made the source code for his method available in a ZIP/PNG file attached to the image as well as on a post on GitHub that explains his methodology.

Specifically, Buchanan demonstrated how he could hide both MP3 audio files and ZIP archives within the PNG images hosted on Twitter. The reason he was successful is because while Twitter strips unnecessary data from PNG uploads, they don't remove trailing data from the DEFLATE stream inside the IDAT chunk if the overall image file meets the requirements to avoid being re-encoded, he explained. There are some requirements for both the images used to obscure files and the files being hidden inside them for his method to work, Buchanan explained.

"The cover image must compress well, such that the compressed filesize is less than (width * height) -- size_of_embedded_file," he wrote in his post. "If the cover image does not have a palette, then it must have at least 257 unique colors (otherwise Twitter will optimize it to use a palette)." Resolution on images can be up to 4096 x 4096, although Twitter will serve a downscaled version by default for images greater than 680 x 680 depending on certain factors, Buchanan wrote. The image also should not have any unnecessary "metadata chunks," he added. For embedded files, the total output file size must be less than potentially 5MB, but kept under 3MB to be on the safe side, otherwise Twitter will convert the PNG to a JPEG file, Buchanan explained. Moreover, if the embedded file is a ZIP, then the offsets are automatically adjusted so that the overall file is still a valid ZIP, he said. "For any other file formats, you're on your own," Buchanan added, noting that many will work without special parameters, including PDF and MP3 files.

IOS

iOS Developers Targeted With New XcodeSpy macOS Malware (therecord.media) 7

Security researchers have uncovered a new type of macOS malware that has been used in the wild to attack iOS software developers through trojanized Xcode projects. From a report: Named XcodeSpy, the malware consists of a malicious Run Script that was added to a legitimate Xcode project named TabBarInteraction. Security firm SentinelOne, which analyzed the malware in a report published today and shared with The Record, said the malicious script ran every time the Xcode project was built, installing a LaunchAgent for reboot persistence and then downloading a second payload, a macOS backdoor named EggShell. "The backdoor has functionality for recording the victim's microphone, camera and keyboard, as well as the ability to upload and download files," said Phil Stokes, macOS malware researcher at SentinelOne.

While the XcodeSpy server infrastructure that controlled the LaunchAgent was down, Stokes said they were able to discover several instances of the EggShell backdoor uploaded on the VirusTotal web-based malware scanner. Stokes said SentinelOne first learned of this malware following a tip from an anonymous researcher, who found an instance of the EggShell backdoor on the network of a US-based company. "The victim reported that they are repeatedly targeted by North Korean APT actors and the infection came to light as part of their regular threat hunting activities," Stokes said, but the researcher told The Record they were not able to definitively link the malware to a nation-state operation beyond a reasonable doubt.

Security

4,300 Publicly Reachable Servers Are Posing a New DDoS Hazard To the Internet (arstechnica.com) 13

An anonymous reader quotes a report from Ars Technica: DDoS mitigation provider Netscout said on Wednesday that it has observed DDoS-for-hire services adopting a new amplification vector. The vector is the Datagram Transport Layer Security, or D/TLS, which (as its name suggests) is essentially the Transport Layer Security for UDP data packets. Just as TLS prevents eavesdropping, tampering, or forgery of TLS packets, D/TLS does the same for UDP data. DDoSes that abuse D/TLS allow attackers to amplify their attacks by a factor of 37. Previously, Netscout saw only advanced attackers using dedicated DDoS infrastructure abusing the vector. Now, so-called booter and stressor services -- which use commodity equipment to provide for-hire attacks -- have adopted the technique. The company has identified almost 4,300 publicly reachable D/LTS servers that are susceptible to the abuse.

The biggest D/TLS-based attacks Netscout has observed delivered about 45Gbps of traffic. The people responsible for the attack combined it with other amplification vectors to achieve a combined size of about 207Gbps. [...] The 4,300 abusable D/TLS servers are the result of misconfigurations or outdated software that causes an anti-spoofing mechanism to be disabled. While the mechanism is built in to the D/TLS specification, hardware including the Citrix Netscaller Application Delivery Controller didn't always turn it on by default. Citrix has more recently encouraged customers to upgrade to a software version that uses anti-spoofing by default.

Besides posing a threat to devices on the Internet at large, abusable D/TLS servers also put organizations using them at risk. Attacks that bounce traffic off one of these machines can create full or partial interruption of mission-critical remote-access services inside the organization's network. Attacks can also cause other service disruptions. Netscout's Hummel and Dobbins said that the attacks can be challenging to mitigate because the size of the payload in a D/TLS request is too big to fit in a single UDP packet and is, therefore, split into an initial and non-initial packet stream.

Communications

US Moves Toward Barring More Chinese Carriers On Security (bloomberg.com) 27

The U.S. Federal Communications Commission moved toward barring China Unicom (Hong Kong) and ComNet from the U.S., calling the Chinese telecommunications carriers a security risk controlled by the Beijing government. From a report: The action against two of China's three major telecommunications operators was decided by a 4-0 vote by agency. It continues a security crackdown that earlier touched Chinese gear makers Huawei Technologies and ZTE. In 2019, the FCC barred China Mobile Ltd. from the U.S. market over national security concerns. ComNet, a subsidiary of Pacific Networks, and the unit formally known as China Unicom (Americas) Operations Ltd. were told in April by the FCC to show they are independent from the Chinese government, or face a proceeding that could result in ejection from the U.S. market. With its vote Wednesday the FCC began those proceedings. China Unicom and Pacific Networks are indirectly and ultimately owned and controlled by the government of the People's Republic of China, the FCC said in news releases Wednesday. The companies may present evidence in proceedings set in motion, according to the news releases.
Games

Rockstar Pays $10,000 To Modder Who Fixed GTA Online Loading Times (gamesindustry.biz) 72

Rockstar Games has paid a modder $10,000 for identifying a way to make Grand Theft Auto Online load significantly faster. From a report: The modder, who goes by the handle 't0st,' recently posted their discovery of a single-thread CPU bottleneck that occurs in the PC version of the hit multiplayer mode. They created a fix they claim enables the game to load 70% faster, and included a message for Rockstar, advising that the issue "shouldn't take more than a day for a single dev to solve." Reports spread of t0st's discovery and Rockstar has confirmed not only that this works, but that it will release an official fix in a future update for the game. In a statement to PC Gamer, the company said: "After a thorough investigation, we can confirm that player t0st did, in fact, reveal an aspect of the game code related to load times for the PC version of GTA Online that could be improved. "As a result of these investigations, we have made some changes that will be implemented in a forthcoming title update."
IT

Dropbox Passwords Rolls Out Free Version Just as LastPass Limits Free Users (gizmodo.com) 39

Just as LastPass nerfs the free tier of its popular password manager, Dropbox has swooped in with a free version of its own password app -- but there's a bit of a catch. From a report: Dropbox today announced that Passwords will soon be free to all of its users, whether they're on its free basic plan or one of its premium individual or business tiers. Beginning in early April, any Dropbox user will be able to access a limited version of Passwords that will securely store up to 50 credentials. The catch here, of course, is that most people likely have more than 50 passwords to various accounts, and a password manager should ideally be used for all of them.
Security

WeLeakInfo Leaked Customer Payment Info (krebsonsecurity.com) 14

A lapsed domain registration tied to WeLeakInfo, a wildly popular service that sold access to more than 12 billion usernames and passwords from thousands of hacked websites, "let someone plunder and publish account data on 24,000 customers who paid to access the service with a credit card," reports Krebs on Security. This comes after the service was seized a little over a year ago by the FBI and law enforcement partners overseas. From the report: In a post on the database leaking forum Raidforums, a regular contributor using the handle "pompompurin" said he stole the WeLeakInfo payment logs and other data after noticing the domain wli[.]design was no longer listed as registered. "Long story short: FBI let one of weleakinfo's domains expire that they used for the emails/payments," pompompurin wrote. "I registered that domain, & was able to [password] reset the stripe.com account & get all the Data. [It's] only from people that used stripe.com to checkout. If you used paypal or [bitcoin] ur all good."

Cyber threat intelligence firm Flashpoint obtained a copy of the data leaked by pompompurin, and said it includes partial credit card data, email addresses, full names, IP addresses, browser user agent string data, physical addresses, phone numbers, and amount paid. One forum member commented that they found their own payment data in the logs.

Microsoft

Microsoft Office 365 Down For Some Users (twitter.com) 36

Thelasko writes: Microsoft is reporting an outage of Office 365, including Microsoft Teams. On its status page, Microsoft adds: Users may be unable to access multiple Microsoft services. User impact: Users may be unable to access multiple Microsoft 365, Azure, and Dynamics 365 services, including the Service Health Dashboard. More info: Any service that leverages Azure Active Directory (AAD) may be affected. This includes but is not limited to Microsoft Teams, Forms, Exchange Online, Intune and Yammer. Current status: We've identified the underlying cause of the problem and are taking steps to mitigate impact. We'll provide an updated ETA on resolution as soon as one is available. Scope of impact: This issue could affect any user.
Privacy

'A Hacker Got All My Texts For $16' (vice.com) 40

An anonymous reader quotes a report from Motherboard, written by Joseph Cox: I didn't expect it to be that quick. While I was on a Google Hangouts call with a colleague, the hacker sent me screenshots of my Bumble and Postmates accounts, which he had broken into. Then he showed he had received texts that were meant for me that he had intercepted. Later he took over my WhatsApp account, too, and texted a friend pretending to be me. Looking down at my phone, there was no sign it had been hacked. I still had reception; the phone said I was still connected to the T-Mobile network. Nothing was unusual there. But the hacker had swiftly, stealthily, and largely effortlessly redirected my text messages to themselves. And all for just $16.

I hadn't been SIM swapped, where hackers trick or bribe telecom employees to port a target's phone number to their own SIM card. Instead, the hacker used a service by a company called Sakari, which helps businesses do SMS marketing and mass messaging, to reroute my messages to him. This overlooked attack vector shows not only how unregulated commercial SMS tools are but also how there are gaping holes in our telecommunications infrastructure, with a hacker sometimes just having to pinky swear they have the consent of the target.
"I used a prepaid card to buy their $16 per month plan and then after that was done it let me steal numbers just by filling out LOA info with fake info," said Lucky225, the pseudonymous hacker who carried out the attack, referring to a Letter of Authorization, a document saying that the signer has authority to switch telephone numbers.

In a statement to Motherboard, Senator Ron Wyden said: "It's not hard to see the enormous threat to safety and security this kind of attack poses. The FCC must use its authority to force phone companies to secure their networks from hackers. Former Chairman Pai's approach of industry self-regulation clearly failed."

Slashdot Top Deals