Featured Stories
Google  Project Vs Facebook Safety Features This is how hacker steal your Facebook password
 
Facebook Security

Google+ Project Vs Facebook Safety Features

Today there are many social networks on the internet and everyday new ones are being introduced with new and better features. They have unique and useful features, which makes it easy for users to remain updated with friends. They also offer apps for different smartphones providing even easier access to friends and other useful information. [...]

This is how hacker steal your Facebook password

There’s many attackers out there who want to steal your credential information. And no doubt, Facebook as one of the largest Social Networking sites in the world, always been a target of attack from the bad guys. Let’s take an example from the following message: Your facebook account will be closed for security reasons, because [...]

Royal Wedding or Royal hunt

Instantly this news became? very fruitful? for all kinds of cybercriminals. Here is? some of the proof we found:1) SEO optimized Google image searches leading to a malicious site with the exploit for the “Help Center URL Validation Vulnerability“. The exploit drops into the system a malicious executable file which is a password stealer malware.?At [...]

Read the full story

29 April 2011

Be Careful If Searching For Images of Kate Middleton’s Dress

Real-world events occasionally generate a massive number of online searches. Japan’s recent earthquake and the subsequent tsunami that followed is a good example of a sudden event that turned the world’s attention to Google. And as topics trend in Google’s search results, Search Engine Optimization (SEO) attacks are attempted. Our March 11th post urged caution [...]

Read the full story

29 April 2011

Avira Antivir Premium

The Ultimate Profile Viewer is now being released! Shocking for real! See who visits your profile real time!

Scam Signature Message: The Ultimate Profile Viewer is now being released! Shocking for real! See who visits your profile real time! See who invisible you on their friend list chat! Check it now and you will be shocked who viewed your profile now ! See your results here ->Scam Type: Survey Scam - Profile Peeker – Rogue ApplicationTrending: April 2011Why [...]

Read the full story

29 April 2011

IME Injection Evolution

Recently,we found many malwares using a smarter way to inject the specified dll into system related to IME management. Comparing to the old IME injection tricks, it is much more difficult to be discovered by users or anti-virus companies.As we known, at the beginning of last year, many Chinese users found they could not use [...]

Read the full story

29 April 2011

The BLOODIEST Fight EVER – BANNED FROM TV!

Scam Signature Message: The BLOODIEST Fight EVER – BANNED FROM TV!Scam Type: Survey Scam Trending: April 2011Why it’s a Scam:Clicking the wall post link takes you to the  following page: If you do follow their directions and click to “Watch the Video” you are taken to the follow page:Here we see the end game of a typical Facebook Survey Scam. Each [...]

Read the full story

29 April 2011

The Royal Wedding and The Fake Antivirus

The Royal Wedding of Prince William and Catherine Middleton that will be held tomorrow, on April 29, will attract the attention of many people around the world, and has become a trending topic on various websites, especially the social networking sites.No doubt, it also became an easy target for the malware authors to spread their [...]

Read the full story

28 April 2011

Malicious E-Cards on the prowl

Emails disguised as electronic cards have been used as bait over and over again for malicious intent. The fact that they are overused is a clear indicator that this lure indeed works.  Websense Security LabsT and the Websense ThreatSeekerR Network recently came across an e-card themed email.  Our customers are protected from this threat by ACE, our Advanced [...]

Read the full story

28 April 2011

Cyber Crooks All Set to Crash the British Royal Wedding

As we have seen with many major events in the past, news of the British Royal Wedding is currently being used by cyber criminals to bolster their spam campaigns and push rogue antivirus software through black hat search engine optimization (SEO) techniques. Spam campaignsWe have blogged previously about “snowshoe” spammers targeting the upcoming British Royal Wedding [...]

Read the full story

28 April 2011

FBI takes on Coreflood botnet – but is this a step too far?

Two weeks ago, the Federal Bureau of Investigation (FBI) obtained a court order in Connecticut, USA. This court order allowed the FBI to undertake an anti-cybercrime operation of a sort which had never been authorised before in America.Not only did the cops seize various US-based Command and Control (C&C) servers belonging the Coreflood botnet, but [...]

Read the full story

28 April 2011

Free anti-virus for Mac named Best Anti-Malware solution at SC Awards

Who would have thought it? A free anti-virus program for Apple Macs being named best anti-malware solution ahead of those security products for boring old Windows.Well, that’s exactly what happened at the SC Magazine Awards Europe 2011, held last week at the London Hilton on Park Lane.Over 530 of the industry’s top companies saw Sophos [...]

Read the full story

28 April 2011

Sony says credit card details *were* encrypted, but questions still remain

Sony has published a new blog entry, confirming that credit card details which could have been stolen in the recent hack of the PlayStation Network were encrypted.Sony reassured users of the PlayStation Network that “all credit card information stored in our systems is encrypted”, but underlined that it cannot rule out the possibility that the [...]

Read the full story

28 April 2011

Malware spammed out as “FaceFacebook Support”.

Another Facebook spam mail pretending that your password is not safe, currently circulating on Internet. The subject is: FaceFacebook Support. Personal data has been changed!ID55733. The email comes with an attachment called New_Password_IN33494.zip.The zip file (New_Password_IN33494.zip) contain New_Password.exe file, Quick Heal detects this file as a “Trojan.Menti.gen”.New_Password.exe tries to fool the victim as it seems [...]

Read the full story

28 April 2011

MegaVideo for MegaMoney

Any trick to get Pay Per Installs (PPI) money from Ad-supported companies is good these days.This site (www.megavideomovieshare.com/?title=) is usurping MegaVideo’s identity to get people to install adware programs. (The real site does not require you to install “plugins” other than the default Flash Player).The plugin you must download is in fact the well known “ClickPotato” adware.To make [...]

Read the full story

28 April 2011

Backdoor Trojan lives on RE/MAX’s website

RE/MAX is a well known international real estate company. Here is one of their Israeli’s websites:remaxplus.co.ilAlthough everything looks fine on the surface, the site has been hacked and is hosting malware:remaxplus.co.il/Include/zombie60.exeThe file is poorly detected on VirusTotal (5/41).Upon running zombie60.exe, a copy is placed under:The following TCP connections are made:The IP 67.205.124.38 points to a [...]

Read the full story

28 April 2011

New spamvertized campaign theme

The wave of  United Parcel Service, DHL Global and Post Express Office spam – which has been so prolific and leading to scareware infections – changed to Bobijou Inc. over the Easter weekend.However, the first batch sent out was flawed. As you can see below, the file attached has a “.dat” extension.The mistake was rectified [...]

Read the full story

28 April 2011

A case of malware starring Mario. or should it be Wario?

I always find it interesting to know what goes on in cyber criminals’ minds.Lately I’ve been observing a deluge of websites being hacked and serving drive-by downloads in the form of Java exploits under the name mario.jar.Below is a screen cap of some of those caught by our HoneyPots:On the left hand side are sites that have been hacked [...]

Read the full story

28 April 2011

Obama, birth certificates and Rogue AV

You probably saw that whole “Obama birth certificate” thing yesterday.You’re also aware this means hunting around for pictures of his birth certificate is going to result in Rogue AV files popping up.The first page of Google Image Search:Click to EnlargeThat one in the middle was (until a little while ago) using a java exploit to [...]

Read the full story

28 April 2011

Modern Phishing: The Art of Warfare

XBox Live currently has a warning issued in relation to “phishing attacks” in the Modern Warfare 2 game. However, information is frustratingly thin on the ground leading to much confusion as to what the attack is, how it takes place, what to avoid and so on.Things I have seen in the past:* Social engineering attempts [...]

Read the full story

28 April 2011

Sony PlayStationRNetwork under attack

After discovering an external intrusion, the persons in charge took the worldwide network and the Qriocity services offline on April 20th 2011. Since then, none of the games can be played online anymore, some offline games can’t even be played offline due to the lack of network functionality, not to talk about the possibility to [...]

Read the full story

28 April 2011

infernomag.com / gtracking.org nastiness

Some sort of .htaccess hack is going on, redirecting users to infernomag.com and then on to a malicious site that looks like it’s downloading a Zbot variant. It only seems to work with Internet Explorer, and only when the page is accessed from a search engine (like Google). infernomag.com is hosted on 85.17.132.194 (Leaseweb) which [...]

Read the full story

28 April 2011

Fake “Lapatasker” job domains 28/4/11

This particular scam has been around for a couple of years and is so common now that I’ve christened this group of scam domains “Lapatasker” after the email address used in some of the older WHOIS details.New domains for this scam (all registered on 26/4/11) are:1job-europ.comconsult-europ.commiddle-consult.comwestconsult-eu.comThe (probably fake) contact details on the domains are:    Vilechka [...]

Read the full story

28 April 2011

Spamvertised “Successfull Order 977132″ Leads to Scareware

A currently ongoing malware campaign is impersonating Bobijou Inc for malware-serving purposes.Sample subject: “Successfull Order 977132“Sample message: “Thank you for ordering from Bobijou Inc.This message is to inform you that your order has been received and is currently being processed.Your order reference is 901802. You will need this in all correspondence. This receipt is NOT [...]

Read the full story

28 April 2011

FedEx used for continued email malware – Zombies up 70%

It’s been almost one month since we reported about the huge increase of email-borne malware attachments.  The outbreaks have continued on an almost daily basis since then and we have noted a corresponding dramatic increase of over 70% in the number of zombies.The traffic graph below shows the continued outbreaks (orange line).  As noted previously [...]

Read the full story

28 April 2011

500 free credits from Facebook – malware

There’s no such thing as a free lunch – or free Facebook credits.  As proof consider the attack described below which has several stages:1)      Users get messages with offers of “free Facebook credits”2)      These trick users into running a malicious JavaScript3)      The infected user is lead to a website – which probably offers [...]

Read the full story

28 April 2011

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
1 month ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
1 month ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
1 month ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
1 month ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
1 month ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
1 month ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
1 month ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
1 month ago
Some free-based music we play at work http://t.co/xu5agZfc
1 month ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
1 month ago