Skip to main content

Windows 10 Warning: 250M Account Trojan Can Disable Windows Defender

Trickbot is not a new threat, but it is an evolving one. The latest twist of the banking Trojan knife as far as Windows 10 users are concerned is the addition of new methods to not only evade but actually disable Windows Defender security protection. As  reported  on July 14 in  Forbes , Trickbot is a particularly stealthy banking Trojan that has been around since 2016. Since then, it was thought to have compromised no less than 250 million email accounts in an effort to distribute the malware payload. That payload includes the stealing of online banking credentials and cryptocurrency wallets. Microsoft has always been front and center as far as Trickbot attack campaigns are concerned, with weaponized Word and Excel files being a favored approach. The  latest campaign  is targeting Windows 10 users and implementing a highly detailed and convincing, but fake nonetheless, Office 365 page to prompt for browser updates that install the Trojan itself. Disab...

Russian Hackers Stole NSA Tools From Contractor Who Used Kaspersky Software

WASHINGTON — Russian government hackers stole highly sensitive U.S. spying tools after a contractor brought classified material home and put it on a computer that used Kaspersky anti-virus software, a former senior intelligence official briefed on the matter told NBC News.
The details were first reported Thursday by The Wall Street Journal.
The contractor, whose name has not been made public, worked for the National Security Agency, which specializes in hacking computers and eavesdropping on communications.
The Journal said the stolen material included secret details about how the NSA penetrates foreign computer networks, the computer code it uses for such spying and how it defends networks inside the U.S.
The report also said it was unclear whether the contractor had lost his job or is facing prosecution. He is not believed to have wittingly cooperated with a foreign government.
The man took his work home in violation of NSA rules, and Russian hackers were able to identify the material and access his machine because he was using Kaspersky software, the former official said.
The case explains why the U.S. government has cracked down on Kaspersky in recent months, banning its use by government agencies, he added.
Image: Kaspersky Lab headquarters in Moscow
A view of the Kaspersky Lab headquarters in Moscow on Feb. 1, 2017. Kaspersky Lab is a Russian cybersecurity and anti-virus provider founded in 1997 by Eugene Kaspersky. Vyacheslav Prokofyev / TASS via Getty Images file
Kaspersky is an anti-virus company owned by Eugene Kaspersky, who has long been accused by U.S. officials of having ties with Russian intelligence officials. But until recently, the company's products were widely for sale in the U.S. and used by some federal agencies.
Kaspersky did not immediately respond to NBC News' request for comment.
The loss of secrets is "extremely damaging," the former official said, because it offers Russia great insights into how the NSA steals data. It will make the NSA's job harder.
"Not only is the work of the NSA and CIA increasingly visible, there is a certain aggression implied by this," he said. "It's a 'game-on' moment."
Kaspersky, he said, should be treated as a hostile actor.
Image: Eugene Kaspersky, founder and chief executive officer of Kaspersky Lab
Eugene Kaspersky, founder and chief executive officer of Kaspersky Lab, poses for a photograph at his office in Moscow on Dec. 9, 2014. Alexander Zemlianichenko Jr. / Bloomberg via Getty Images file
Another NSA contractor, Harold Martin, has been charged wi.th taking home classified material without permission. He had pleaded not guilty, and he is not the person implicated in this case, the former official said.
A third contractor, Edward Snowden, famously removed reams of classified information NSA facilities and leaked it to the news media. But Snowden for the most part did not reveal spying tools, so the current case could in some ways prove more damaging.
Sen. Ben Sasse, R-Neb., a member of the Armed Services Committee, said the NSA "needs to get its head out of the sand and solve its contractor problem. Russia is a clear adversary in cyberspace and we can’t afford these self-inflicted injuries."
An NSA spokesman declined to comment. An agency official who asked not to be named said the NSA is committed to improving its internal security. 

Comments

Popular posts from this blog

SmartBillions Challenges Hackers with 1,500 Ether Reward, Gets Hacked and Pulls Most of It Out

SmartBillions, a so-called fully decentralized and transparent lottery system, managed by an Ethereum smart contract, recently challenged hackers to get through its smart contract’s security, and added a 1,500  Ether  ($450,000) reward to be collected by anyone that managed to compromise it. The goal was to demonstrate “the SmartBillions lottery smart contract’s comprehensive security.” Initially, according to a  press release , the prize was to be collected by any hacker that managed to break into the smart contract and withdraw the funds, as a way to prove how serious the team took investor protection. The team stated: “The development team is so confident in their product and its security that they will risk their own funds (1500 ETH), to demonstrate its safety.” A few days later, the issued challenge seemingly backfired, as a hacker did manage to compromise the smart contract. The hacker, according to a  Reddit thread , essentially managed to game th...

Windows 10 Warning: 250M Account Trojan Can Disable Windows Defender

Trickbot is not a new threat, but it is an evolving one. The latest twist of the banking Trojan knife as far as Windows 10 users are concerned is the addition of new methods to not only evade but actually disable Windows Defender security protection. As  reported  on July 14 in  Forbes , Trickbot is a particularly stealthy banking Trojan that has been around since 2016. Since then, it was thought to have compromised no less than 250 million email accounts in an effort to distribute the malware payload. That payload includes the stealing of online banking credentials and cryptocurrency wallets. Microsoft has always been front and center as far as Trickbot attack campaigns are concerned, with weaponized Word and Excel files being a favored approach. The  latest campaign  is targeting Windows 10 users and implementing a highly detailed and convincing, but fake nonetheless, Office 365 page to prompt for browser updates that install the Trojan itself. Disab...

How To Convert DEB Packages Into Arch Linux Packages

We already learned how to  build packages for multiple platforms , and how to  build packages from source . Today, we are going to learn how to convert DEB packages into Arch Linux packages. You might ask,  AUR is the large software repository on the planet, and almost all software are available in it. Why would I need to convert a DEB package into Arch Linux package? True! However, some packages cannot be compiled (closed source packages) or cannot be built from AUR for various reasons like error during compiling or unavailable files. Or, the developer is too lazy to build a package in AUR or s/he doesn’t like to create an AUR package. In such cases, we can use this quick and dirty method to convert DEB packages into Arch Linux packages. Debtap – Convert DEB Packages Into Arch Linux Packages For this purpose, we are going to use an utility called  “Debtap” . It stands  DEB   T o  A rch (Linux)  P ackage. Debtap is available in AUR, so yo...