Showing posts with label Malware. Show all posts
Showing posts with label Malware. Show all posts

Cyber Attack Hit Japanese Nuclear Power Plant using Special Malware

Software update cause Malware attack on Japanese Nuclear Power Plant.

When japan was hit by Earth Quick last year then it was also discovered that japan was working on some secret nuclear power Plants. So this may be possible that world power want to get information about Japan Nuclear Power Plants and have an eye on them.



The most critical and worst target of a State-sponsored cyber-attacks could be Hospitals, Dams, Dykes and Nuclear power stations and this may cause military conflicts between countries.

According to Japan Today, The Monju nuclear power plant in Tsuruga, Japan was accidentally targeted by a malware on 2nd January, when a worker updated the system to the latest version of the video playback program. Monju Nuclear Plant is a sodium-cooled fast reactor, was launched in April 1994. It has not been operational for most of the past 20 years, after an accident in which a sodium leak caused a major fire. Employees over there are only left with a regular job of company's paperwork and maintenance. So the malware could have stolen only some sensitive documents, emails, training records and employees' data sheets. The Malware command-and-control server suspected to be from South Korea. The malware itself is not much sophisticated like Stuxnet or Duqu, but the unmanaged software update and patch management system can seriously lead to a critical cyber attack. Even being isolated from the Internet does not prevent you from being infected. One of the best examples of flawed Internal policies is Stuxnet, one of the most infamous pieces of malware ever created to destroy Iranian Nuclear plants and infected the systems through a USB stick only. Also in November, The Kaspersky revealed that Russian astronauts carried a removable device into space which infected systems on the space station.

New Skype malware spreading at 2,000 clicks per hour makes money by using victims machines.

New Skype Malware spreading at 2,000 clicks per hour makes money by using victims machines.
A new piece of malware propagating across Skype has been discovered that tries to convince the recipient to click on a link. What makes this particular threat different is that it drops a Bitcoin miner application to make the malware author money.



Security Lab Kaspersky discovered the threat, which it names Trojan.Win32.Jorik.IRCbot.xkt, on Thursday night. At the time, most of the potential victims were from Italy, Russia, Poland, Costa Rica, Spain, Germany, and Ukraine, with the average clicking rate hitting 2,000 clicks per hour.

The initial trojan is downloaded from a server located in India, and many anti-malware programs as measured by VirusTotal don’t detect it. Once the machine is infected, the trojan drops multiple other pieces of malware, using Hotfile to grab the bits and also connecting to a server located in Germany for further instructions. Its quit cleverly coded but there is one really huge bug in code that it slow down computer by using whole CUP.

To avoid this threat and others like it, don’t click on random links you receive on Skype. You’ll be doing yourself a favor, helping stop the spread of malware, and ensuring criminals get a smaller pay day.

Reference : Link

Google Acquires Malware-Scanning Site VirusTotal

Google Acquires Malware-Scanning Site VirusTotal

Google has acquired VirusTotal


Google has acquired VirusTotal, a malware-scanning company that offered its services for free. Users can submit a file or an URL to be scanned and the site warns them if it contains any malware. The site relies on over 40 antivirus engines and other tools to scan the files.

The site will continue to operate as is as part of Google, the company said on its blog. However, it will benefit from the expertise and, more importantly, infrastructure and resources of Google.

 "Our goal is simple: to help keep you safe on the web. And we’ve worked hard to ensure that the services we offer continually improve," VirusTotal wrote.

"But as a small, resource-constrained company, that can sometimes be challenging. So we’re delighted that Google, a long-time partner, has acquired VirusTotal. This is great news for you, and bad news for malware generators," it said.

"VirusTotal will continue to operate independently, maintaining our partnerships with other antivirus companies and security experts. This is an exciting step forward. Google has a long track record working to keep people safe online and we look forward to fighting the good fight together with them." 

It's not exactly clear what Google plans to do with VirusTotal, if anything. There's a number of places that could benefit from better malware scanning, the Play Store for one, not to mention the search engine. Chrome too could do with better built-in security tools.

But there don't seem to be any big plans for integration at this point, Google is happy leaving VirusTotal do its job. At the very least, it could benefit from an improved URL blocklist for the search engine.

"Security is incredibly important to our users and we’ve invested many millions of dollars to help keep them safe online. VirusTotal also has a strong track record in web security, and we’re delighted to be able to provide them with the infrastructure they need to ensure that their service continues to improve," Google commented on the acquisition.

Cyber attack takes Qatar's RasGas offline

RasGas, the second largest producer of Qatari LNG after Qatar Petroleum, has been hit with an "unknown virus" which has taken the company offline.

A RasGas spokesperson confirmed that “an unknown virus has affected its office systems" since Monday 27 August.

RasGas confirmed the situation by fax yesterday. “RasGas is presently experiencing technical issues with its office computer systems,” said the RasGas fax seen by Oil & Gas Middle East, dated 28 August. “We will inform you when our system is back up and running.”




Emails to verified addresses at RasGas bounced back with a permanent delivery failure error message. and the RasGas website (www.rasgas.com) is down.

The RasGas spokesman said the virus has “no impact whatsoever on operations in Ras Laffan Industrial City and there are no issues with cargo deliveries.”

“Everyone is reporting to work as normal,” the spokesman said. “We are working with ICT Qatar to resolve the situation as soon as possible.”

The news follows a malware attack against Saudi Aramco on 15 August which forced the world's largest oil company to take down its company-wide office systems for 12 days.

RasGas, a joint venture between QP and ExxonMobil, comprises seven giant LNG process trains in Ras Laffan, Qatar. The company exports 36.3m tonnes a year of LNG, most of which under long-term contracts with customers in Korea, India, Italy, Spain, Belgium, Taiwan, and the Americas. The company us also responsible for around 10% of global helium production.

Oil giant Saudi Aramco workstations hit by malware Restored

Oil giant Saudi Aramco back online after workstations hit by malware.

 Aramco, Saudi Arabia’s national oil company, said on Sunday that the company was back in operation ten days after a massive malware outbreak hobbled 30,000 workstations at the company.

 In a statement on the company’s Facebook page (content alert: Facebook page contains images of extremely phallic architecture), Aramco said that it had “restored all its main internal network services” that were affected by a malware outbreak on August 15.


 The attack was attributed to “external sources.” It is just the latest against a national oil company, following reports of malware attacks on Iran’s oil infrastructure linked to the “Flame” malware in May.

 The malicious Trojan horse, which Sophos named Troj/MDrop-ELD, attempts to overwrite the master boot record on infected systems, which would make it impossible to boot the machine.

 Responsibility for the attack from a previously unknown group calling itself the “Cutting Sword of Justice.”

 The group posted details of the hack on Pastebin, and said that Aramco was attacked in retaliation against the Al-Saud regime for the “crimes and atrocities taking place in various countries around the world, especially in the neighboring countries such as Syria, Bahrain, Yemen, Lebanon (and) Egypt.

 Pastie bin link:
http://pastebin.com/HqAgaQRj

 We, behalf of an anti-oppression hacker group that have been fed up of crimes and atrocities taking place in various countries around the world, especially in the neighboring countries such as Syria, Bahrain, Yemen, Lebanon, Egypt and ..., and also of dual approach of the world community to these nations, want to hit the main supporters of these disasters by this action.

 One of the main supporters of this disasters is Al-Saud corrupt regime that sponsors such oppressive measures by using Muslims oil resources. Al-Saud is a partner in committing these crimes. It's hands are infected with the blood of innocent children and people.

 In the first step, an action was performed against Aramco company, as the largest financial source for Al-Saud regime. In this step, we penetrated a system of Aramco company by using the hacked systems in several countries and then sended a malicious virus to destroy thirty thousand computers networked in this company. The destruction operations began on Wednesday, Aug 15, 2012 at 11:08 AM (Local time in Saudi Arabia) and will be completed within a few hours.

 This is a warning to the tyrants of this country and other countries that support such criminal disasters with injustice and oppression. We invite all anti-tyranny hacker groups all over the world to join this movement. We want them to support this movement by designing and performing such operations, if they are against tyranny and oppression.



 Cutting Sword of Justice

 Attacks against private and public energy-producing firms are nothing new. In addition to the “Flame” malware attacks against Iran’s oil refineries, the US Department of Homeland Security warned in May about ongoing cyber attacks aimed at firms operating natural gas pipelines within the United States.

 In its Pastebin manifesto, Cutting Sword of Justice said its attack on Aramco was “a warning to the tyrants of this country and other countries that support such criminal disasters with injustice and oppression.” The group invited other “anti-tyranny hacker groups” to join the movement.

Naughty Nurse Sakura Shiratori tries to Infect Defence Firm with Malware

We’ve seen a large number of files spammed out to various organisations, exploiting the CVE-2012-0158 vulnerability.

Victims have not be
en limited to defence companies, but have also included government departments, charities and recruitment agencies.

One of the latest attacks we have seen was sent to a defence contractor, using the subject line “if you want sex pictrue!”.
Attached to the email is a file called sexpicture.rar that contains a number of naked pictures of Japanese model Sakura Shiratori.

Harmless enough you might think. However, alongside the seedy snapshots are two files.

An apparent screensaver, short-SEXGPJ_1.SCR, is malicious – and detected by Sophos products as Mal/Behav-043.

Another file, short-SEX_ST_1.DOC, is detected by Sophos products as Troj/DocDrop-AF, and attempts to install further malicious code onto victims’ computers by exploiting the CVE-2012-0158 vulnerability.

Although the email appears to have come from the Taiwanese branch of Yahoo, the “from:” address has been forged by whoever sent out the attack. I’m also going to make the fairly safe assumption that Miss Shiratori is not aware of how her images are being abused.

Make sure that the staff at your firm are wary of opening unsolicited email attachments, and that computers are defended with up-to-date anti-virus software and the latest security patches.

Microsoft released its patch for the vulnerability back in April – if you haven’t already rolled it out across your Windows PCs, do so now.

Power failure Across India, Hit by Malware Attack

India’s Northern power grid crashed on Monday morning wreaking havoc at airports, railway and metro stations, hospitals and across traffic congested roads, its worst power outage in a decade.

Indian power infrastructure under attack: India losing out millions in just hours same snag developed within just 24 hours of recovery reports say the system is infected by sophisticated malware.
Malware is spreading; today more than 67 crore people are without power. Cyber analysts suspect "PAK"- CHINA nexus behind this attack.


 Hundreds of millions of people have been left without electricity in northern and eastern India after a massive power breakdown.

There are some analyst saying that it is cyber Attack by a Malware but no Indian Authorities confirmed it yet. Authorities are restoring the service suggest the whole thing is out of their skills, meanwhile mainstream media has been barred from reporting as this could bring disgrace to security services of India.

Since the first power trip up on Monday, there have been discussions within the security establishment about the possibility of entities trying to carry out a sophisticated cyber-attack to cripple the grids.

Officials who carried out an audit of critical information infrastructure admit it is "theoretically possible" to cripple India's power grids through a cyber-attack.


Despite such a possibility, the shutdown did not seem to have led to a crisis management procedure that aimed at ruling out or confirming a cyber-attack.

"Given the fact that our grids are vulnerable to a cyber-attack, those responsible for managing grids should have a proactive policy to rule out cyber-attack as part of their crisis management procedures," a senior official said. "But none of it was visible," he added.

Sources aware of contacts among power ministry, power grid authorities and those in both CERT-IN ( Computer Emergency Response Team-India) and NTRO (National Technical Research Organisation) say there was no proactive effort by those responsible for power grids.

However, both CERT-IN and NTRO are believed to have established their own procedures to ensure the shutdowns were not a cyber-attack, having been brought on by massive over-the-limit withdrawals by states to supply electricity for pumps tapping groundwater in the absence of rainfall during this monsoon.

Officials said the government is now discussing possible ways to speed up the setting up of National Critical Information Infrastructure Protection Centre (NCIPC), which would act as the command and control centre for monitoring the critical information infrastructure of the country. NCIPC was recently approved by the National Security Council headed by the Prime Minster.

Sources said the government is also planning to hold a national consultation of all stakeholders involved in critical information infrastructure.

The government is already setting up dedicated CERT-INs for various critical sectors such as power and civil aviation.

Officials point out to breaches reported from power grids in the US, cyber intrusion into the Iranian nuclear network and other such incidents around the world to warn that India needs to have a more robust crisis management procedure that includes proactive ruling out of cyber-attacks.

Microsoft Names Two Zeus Botnet Operators


Three months after initially disrupting the Zeus botnet, Microsoft officials have named two of the people who they think are behind the malware network, a pair of Ukrainians who already are sitting in jail in the UK.
From the beginning of the anti-Zeus operation, which became public in March, Microsoft officials and lawyers from other organizations, including NACHA, have been trying to identify the dozens of John Does named in the initial legal complaint. Those efforts hadn’t met with any success, until last week when Microsoft named Yevhen Kulibaba and Yuriy Konovalenko as two of the John Does behind the Zeus botnet. The company has told both the FBI and the authorities in the UK of their findings, and also included the men’s names in the amended legal complaint.


“In an amended complaint, filed last week, Microsoft named Yevhen Kulibaba and Yuriy Konovalenko as defendants. Microsoft has learned that these particular defendants were already serving jail time in the United Kingdom for other Zeus malware related charges. Microsoft has advised the U.K. government of the criminal referral to the FBI. By referring this case to the FBI, as we did in September 2011 with our case against the operators of the Rustock botnet, we are affirming our commitment to coordinating our efforts with law enforcement. Our goal is always to work in ways that are complementary to law enforcement. Our hope is that the evidence we provided to the FBI in this case will lead to a criminal investigation that brings the perpetrators to justice,” Richard Boscovich, a senior attorney in Microsoft’s Digital Crimes Unit, said in an analysis of the operation.
The anti-Zeus operation is the latest in a line of botnet takedowns and anti-cybercrime actions undertaken by the Microsoft DCU, a relatively new gorup inside the company that’s devoted to investigating and helping stem cybercrime. The DCU also was involved in the takedown of the Rustock botnet, as well as operations against the Kelihos and Waledac botnets.The Zeus takedown hs been unique for a couple of reasons, chief among them the use of the civil section of the RICO anti-racketeering statute to aid in the investigation.
“In criminal court cases, the RICO Act is often associated with cases against organized crime; the same is true in applying the civil section of the law to this case against what we believe is an organization of people behind the Zeus family of botnets. By incorporating the use of the RICO Act, we were able to pursue a consolidated civil case against everyone associated with the Zeus criminal operation, even if those involved in the ‘organization’ were not necessarily part of the core enterprise,” Boscovich said at the time of the initial Zeus takedown.
Microsoft is working with ISPs to help them identify Zeus-infected machines and alert the users about the infection.

Hackers force Iranian nuclear facilities to blast AC/DC after Cyber Attack


A person inside the Atomic Energy Organization of Iran (AEOI) claimed this week in an email to a security researcher that a fresh hack is affecting two facilities, causing vital equipment to shut down and then playing AC/DC’s “Thunderstruck” on lab computers at maximum volume “during the middle of the night.”

Mikko H. Hypponen, chief research officer for the cybersecurity firm F-Secure, explained on the company’s website that he received an email from an unknown person within the AEOI who wanted to publicize details of the latest problems they’ve been running into.


“I am writing you to inform you that our nuclear program has once again been compromised and attacked by a new worm with exploits which have shut down our automation network at Natanz and another facility Fordo near Qom,” the tipster wrote.

“According to the email our cyber experts sent to our teams, they believe a hacker tool Metasploit was used,” he continued. “The hackers had access to our VPN. The automation network and Siemens hardware were attacked and shut down. I only know very little about these cyber issues as I am scientist not a computer expert. ”

The email concluded: “There was also some music playing randomly on several of the workstations during the middle of the night with the volume maxed out. I believe it was playing ‘Thunderstruck’ by AC/DC.”

While the identity of whomever sent the email has not been confirmed, reports in recent months have pointed to the U.S. and Israel as leading cyber-sabotage efforts against Iran’s nuclear program.

Reporters cited unnamed administration officials who claimed that the creation of the “Stuxnet” cyber weapon was authorized by President George W. Bush and sped up by President Barack Obama, who also allegedly initiated other lines of attack against the same facilities cited by Hyppone’s mystery tipster.


New malware hits Middle East computers


Security researchers say they have discovered another piece of espionage malware infecting computers and targeting sensitive organizations in the Middle East.

Kaspersky Lab in Russia and Seculert in Israel said the malware on more than 800 PCs operated by critical infrastructure companies, financial institutions and government agencies has been siphoning e-mails, passwords, computer files and nearby conversations, ArsTechnica.com reported Tuesday.



The researchers have dubbed the malware Madi or Mahdi, which in Islam is synonymous with Messiah, because of several code strings and handles used by the attackers.

The discovery evoked comparisons to the Flame malware used to disrupt Iran's nuclear program, but both Kaspersky and Seculert said the malware contained amateur coding practices and relied on the gullibility of its victims, whereas Flame contained world-class cryptographic breakthroughs and other techniques that suggested state-sponsored developers.

"While we couldn't find a direct connection between the campaigns, the targeted victims of Mahdi include critical infrastructure companies, financial services and government embassies, which are all located in Iran, Israel and several other Middle Eastern countries," Seculert said. "It is still unclear whether this is a state-sponsored attack or not."

Madi can log keystrokes, capture screenshots and steal any messages sent to or from a variety of widely used services, including Gmail, Hotmail, Yahoo! Mail, Skype or ICQ, the researchers said.

Reference: Link

Malware may Show its magic on July 9

1,000's off Internet Users On Risk!
The warnings about the Internet problem have been spread like fire across Facebook and Google plus. Internet service providers have sent notices, and the FBI set up a special website.

Tens of thousands of Americans may still lose their Internet service Monday unless they do a quick check of their computers for malware that could have taken over their machines more than a year ago.

Despite repeated alerts, the number of computers that are probably infected is more than 277,000 worldwide, down from about 360,000 in April. Of those still infected, the FBI believes that about 64,000 are in the United States.
Users whose computers are still infected Monday will lose their ability to go online, and they will have to call their Internet service providers for help.
And as my own experiences a huge amount of internet user in Pakistan & India are also effected by this Malware. 

Reference: Link1

Related Posts Plugin for WordPress, Blogger...