The 56th variant of a family of worms that use Facebook has emerged. It downloads and installs a fake antivirus -Boface.BJ.worm- to defraud users
The worldwide infection ratio of this family of worms now stands at 1%, and the increase in the number of infections has reached 1,200% in recent months
May 13, 2009
Variant number 56 of the Boface family of worms has just appeared. Each of these variants has been designed especially to use Facebook to distribute and download malware. This is largely due to the enormous global popularity of this social network and the potential it offers for reaching numerous users. The BJ variant in particular uses Facebook to download and install rogue anti-malware and trick users into believing they are infected and consequently buy a fake antivirus.
According to data compiled through the free Panda ActiveScan online scanner, since August 2008, 1% of all computers scanned were infected by a variant of Boface. According to Luis Corrons, technical director of PandaLabs: “Extrapolating this data in line with the number of Facebook users, some 200 million, we arrive at a figure of 2 million users that could be infected. The increasing number of variants in circulation is due to the aim of cyber-crooks to infect as many users as possible and therefore boost their financial returns”. With respect to the geographic distribution of infections, almost 40% are in the United States, with the rest distributed across many different countries.
The number of infections observed for this type of malware since August, indicates an exponential growth rate as high as 1,200%, comparing April 2009 with August 2008.
The rogue anti-malware business is one of the most prolific cyber crime activities, with respect to the number of examples in circulation. PandaLabs forecast quarterly growth of more than 100% for the current year.
The new Boface.BJ worm reaches computers in several ways: email messages with attachments, Internet downloads, files transferred via FTP, IRC channels, P2P file-sharing networks, etc. Users are infected without realizing.
Once the computer has been infected, the worm takes four hours to kick into action. And it does this once infected users have entered their Facebook accounts. In that moment, it sends a message to the entire network of friends, including the infected user.
Anyone clicking on the link in the message will be taken to a fake YouTube page (called “YuoTube”): http://www.flickr.com/photos/panda_security/3527896167/ where they will supposedly be able to see a video. However, they will first be prompted to download a media player. If the user accepts, the fake antivirus will be immediately downloaded.
From the moment it is installed, this malware will launch messages claiming that the computer is infected and that the user must buy a solution. Specifically, one of the fake antivirus products displayed in this interface:
http://www.flickr.com/photos/panda_security/3528707634/
Given the viral nature of Facebook networks, it is fair to assume that this message will spread exponentially leading to very high infection rates.
According to Corrons: “Users of social networks like this normally trust the messages they receive, so the number of reads and clicks is often very high. Clearly, in addition to the security measures of the social network itself, users have to take on board certain security and personal privacy basics, to avoid falling victim to fraud and contributing to its propagation”.
To prevent this type of fraud, PandaLabs offers the following advice:
1) Don't click suspicious links from non-trusted sources. This should apply to messages received through Facebook, and through other social networks and even via email.
2) If you do click on any such link, check the target page carefully (in this example, it is clearly a fraud). If you don't recognize it, close your browser.
3) Even if you don't see anything strange in the target page, but you are asked to download something, don't accept.
4) If, however, you have still gone ahead and downloaded and installed some type of executable file, and your computer begins to launch messages saying that you are infected and that you should buy an antivirus, this is very probably a fraud. Never entered your credit card details, as you will be putting your money at direct risk. And above all, make sure you get a second opinion on the security of your system, with any reliable free online security solution such as Panda ActiveScan.
5) As a general rule, make sure your computer is well protected, to ensure that you are not exposed to the risk of infection from any malicious code. You can protect yourself with the new, free Panda Cloud Antivirus solution (www.cloudantivirus.com).
Thursday, May 14, 2009
Facebook used by cyber-crooks to help drive the rogue anti-malware business
发表者
SC Cyberworld
0
评论
Wednesday, May 13, 2009
Studying or hacking? Today's adolescents could be the hackers of the future
May 12, 2009 According to a survey carried out by Panda Security1, more than half of adolescents between 15 and 18 years old use the Internet daily, spending, on average, 18.5 hours a week connected. The survey revealed that some 32% of this online activity is dedicated to studying, while the remaining 68% involves leisure activities, such as playing games online, watching videos, listening to music, chatting, etc.
While 63% of parents declared concern for the online security of their children, in particular relating to the threats to which they are exposed (contact with strangers, access to inappropriate content, etc.), none of them expressed among their main concerns the risk that their children could be involved in illicit activities on the Internet.
However, some 67% of the young people surveyed admitted to having tried, on at least one occasion, to hack into friends’ instant messaging or social network accounts, etc. Similarly, 20% confirmed that they had sent compromising photos of friends over the Internet or published them on the Web without prior consent.
The survey also revealed a significant amount (17%) of adolescent users who claim to have advanced technical knowledge and are able to find hacking tools on the Internet. Of these, 30% claim to have used them on at least one occasion. When asked why, 86% said that curiosity had led them to investigate these public tools.
According to Luis Corrons, Technical Director of PandaLabs, “The advanced knowledge that many adolescents acquire through free tools and content available on the Web can often lead them into activities which are sometimes even illegal. We have found cases of teenagers using Trojans to spy on their partners, hacking school servers to see exam papers or even stealing the identity of friends or colleagues on social networks”.
While there are many initiatives aimed at educating and promoting awareness of threats on the Web, there are far less that focus on detecting and addressing illegal behavior.
“We should encourage young people to use the Internet as a channel for personal development, teaching them to use it in a healthy and responsible fashion. It is important to help them avoid participating in dubious activities which are made all the easier thanks to the anonymity afforded by the Web”, urges Corrons. “Even though the percentage is very low, we still come across too many cases of adolescent cyber-criminals, such as the recent high-profile case of the 16-year-old creator of worms for Twitter. We estimate that just 0.5% of these are detected by the corresponding authorities. Those who are drawn into hacking out of curiosity, may well end up discovering the financial potential of this activity, and becoming criminals themselves.”
发表者
SC Cyberworld
0
评论
Thursday, April 30, 2009
Panda Security Launches Panda Cloud Antivirus:
Panda Security, a leading provider of IT security solutions, today announced the global beta release of Panda Cloud Antivirus, the industry’s first and only free cloud-based antivirus thin-client with 50 percent less impact on PC performance compared to the industry average. Consumers can download the free product from http://www.cloudantivirus.com/.

发表者
SC Cyberworld
0
评论
Thursday, May 22, 2008
Panda Launches New Service to Remove Complex Security Burden for SMBs
Utilizing Security as a Service, Panda Managed Office Protection reduces risk and costs associated with Small and Medium Size Businesses (SMBs) malware management. Madrid, May 19, 2008. Panda Security, one of the world’s leading IT security providers today announced the worldwide launch of Panda Managed Office Protection, a web-based subscription service that removes the cost and management overheads of hardware, personnel and software resources dedicated to anti-malware for small and medium-sized businesses and remote offices.
Research from Panda “Infected or Not” initiative (http://www.infectedornot.com) shows that 72% of organizations with traditional security solutions in place are unaware of the risks that they are running with hidden malware on their systems. In addition to this SMBs are suffering from the cost management overhead of trying to stay protected against the latest threats.
With Panda Managed Office Protection, SMBs will be able to focus on their core business. Its simple web based administrator console allows IT protection to be securely managed and installed from any computer with Internet access enabling security management to be completely externalized. Subscription to an outsourced security service helps further reduce software costs.
According to Vic Wheatman, managing vice president for industry analysts Gartner, “Most enterprises will not have the resources to do an effective job at keeping the bad guys out and letting the good guys in. Outsourcing keeping-the-bad-guys-out effort is a driver for the managed-security market”.
As one of the first movers in the growing outsourced security services market and with over seven years expertise in hosted security solutions, Panda’s new Managed Office Protection ensures business continuity and offers higher availability with 24x7 support, providing the latest available product versions as well as signature file updates. It also protects laptop computers and remote connections through the installation of an ultra-light agent. Through it, users will be able to access all product upgrades and updates across the Internet. Its detection capacity benefits from Collective Intelligence developed by Panda Security which leverages collective knowledge in order to offer the latest malware signatures in real time.
“We needed a product like Panda Managed Office Protection; this tool will help us reduce travel expenses, which is very important for us as we move across the entire country. The centralized administration console allows us to monitor the status of all installed licenses, see warnings, customize installation, etc.” explains Gabriel Garrido from Informatica Notarial.
“Installing and maintaining security software requires a lot of time and effort from small-and-mid-sized businesses. Companies need to invest in servers, licenses and security specialists, which translates into significant costs” says Jorge Dinares, CEO Panda Security. “Panda Managed Office Protection is specially designed to protect organizations that don’t want to waste time and resources on these tasks”.
发表者
SC Cyberworld
0
评论
Wednesday, April 30, 2008
New Panda Security Managed Office Protection Offered for Free Download
Kuala Lumpur, April 29th 2008
Panda Security, a leading IT security provider has launched the Panda Security Managed Office Protection beta version, a new and comprehensive solution for small and medium size business (SMBs). To download this free beta, go to http://www.pandasecurity.com/enterprise/downloads/beta/
According to Gartner, a leading provider of research and analysis on the information technology industry: “95% of small and medium sized businesses nowadays have an antivirus installed on their network endpoints, but 72% are still infected”
“This solution is designed to solve this issue and offer organizations complete protection without the need to invest in dedicated equipment. It is also an excellent tool for value added resellers wanting to offer security services to clients”, says Josu Franco, Corporate Development Director at Panda Security.
Panda Security Managed Office Protection provides a remote Web management console, allowing secure configuration of IT resources from any computer on the Web. Profiles can also be assigned across the organization, to adapt security measures to individual or departmental requirements. This enables complete security management, with no need for user intervention. And as there is no need to invest in dedicated security severs, total cost of ownership is reduced to a minimum.
With this solution, security management can be completely externalized, reducing costs further as no specialist staff are required. Minimal impact on system performance and resource consumption means that valuable IT assets are freed up for other tasks.
Panda Security Managed Office Protection also includes protection against unknown threats and a managed personal firewall to ensure maximum protection for servers and workstations.
“Taking advantage of Panda’s unique Collective Intelligence platform this innovative solution gives SMBs the highest levels of security combined with simple management and low resource usage”, concludes Josu Franco.
To download this solution, just go to http://www.pandasecurity.com/enterprise/downloads/beta/
发表者
SC Cyberworld
0
评论
Wednesday, August 22, 2007
惡毒工具處理3萬用戶機密資料
A malicious tool is processing confidential data from more than 30,000 users
A version of Apophis, a tool used by cyber-crooks to handle information stolen from users infected by several variants of the Nuklus family of Trojans, stores data belonging to over 30,000 users from more than twenty countries. PandaLabs has been able to access a file with some of the stolen data. This file kept encrypted confidential data belonging to almost 1,500 people from the USA, Canada and the UK.
Surprisingly enough, this data contained, in addition to information about bank and email accounts, information such as the users’ postal address, phone number or their credit card expiry date. With this information, cyber-crooks not only can get the users’ money, but also impersonate them and use their identity to make purchases, bank transfers, etc., in their name.
“This is just an example of the dangers of current malware, and, above all, of the need for a good protection that prevents data entered by users in Web forms, banking sites, etc. from ending up in the hands of cyber-criminals”, explains Luis Corrons, Technical Director of PandaLabs.
Apophis offers criminals several options: they can know the geographical location of infected computers, how many of them are active at a certain time or search among stolen data.
“We are coming across more and more tools like this, which confirms there is a black market for developing and selling them”, concludes Corrons.
For more information about this story, go to the PandaLabs blog.
发表者
SC Cyberworld
0
评论
Thursday, July 12, 2007
PandaLabs發現欺騙iPhone買家網站
Botnet threatens iPhone buyers, reports PandaLabs
The launch of iPhone is being exploited by cyber-crooks for financial gain. PandaLabs has uncovered a tool that controls a botnet made up of over 7,500 zombie computers infected by the Aifone.A bot Trojan. If the user of an infected PC tries to buy an iPhone online, their confidential data might end up in the hands of cyber-criminals.
The tool allows cyber-criminals to specify the web pages that the bot must redirect and where they must be redirected to
The tool uncovered by PandaLabs has a series of features that allow cyber-crooks to take users of infected computers to a false page that appears to be the iPhone official page. As a result, if the user tries to buy the phone from the spoof page, they will actually be giving their bank details to cyber-criminals.
One of the tabs in the tool, called “REDIRECTS ADMIN”, allows criminals to specify the web pages that the bot must redirect and where they must be redirected to. In this case, the tool sends users that want to visit the iPhone official pages to a false web page.
Another tab, “SEARCH REDIR”, is used to specify the results that the Trojan must display when the infected user performs an Internet search and where they should be redirected to when they click any of the links. Obviously, this will be the false page.
In section “INJECTS ADMIN” it is possible to indicate the links that the Aifone.A Trojan must modify. As a consequence, if the user visits a web page that contains a link to a page dealing with iPhone, they will also be redirected to the false page.
Other tabs, “POPUPS ADMIN” and “BANNERS ADMIN”, allow cyber-crooks to display pop-ups and banners with advertising about iPhone on the infected computer. This aims at enticing users to visit the spoofed web page and buy the phone from it.
“This is one of the most sophisticated attacks we have seen targeting a user community, in this case iPhone users. It is a really complex, dangerous attack that combines elements of malware (the Trojan), phishing (the spoofed web page) and even adware (pop-ups, modification of search results, etc.)”, explains Luis Corrons, Technical Director of PandaLabs.
The real danger behind this attack is the fact that, in the same way that it is now being used to affect users that want to buy an iPhone, it could be slightly modified and used to affect users interested in any other product, or even several groups of users simultaneously, which would increase the cyber-criminals’ chances of success.
If you think your computer might have been infected by this malware, scan it for free at http://www.infectedornot.com/
For more information about this tool, go to the PandaLabs blog.
发表者
SC Cyberworld
0
评论
Thursday, June 28, 2007
PandaLabs籲公衆防超低價產品網頁
PandaLabs warns of the danger of some web pages that offer products at very low prices
June 27, 2007
PandaLabs warns of the danger of buying products at very low prices from suspicious web pages. These products could have been bought using stolen credit cards or bank details obtained through techniques like phishing or data theft through Trojans.
PandaLabs has found one of these pages selling stolen products. The page includes a “F.A.Q” section that contains the following question: “You ask where we get such good prices?”. The answer on the website is “All very simple. We buy goods in Western Internet magazines on stolen credit cards and deliver it in the Russian Federation. You don’t run any risk buying goods from us.”
As you can see, in some cases, cyber-criminals assure consumers that buy their products that they do not run any risk. However, this is not true, as the penal code in the majority of countries prosecutes offenders for knowingly buying stolen goods. Internet users should be careful, as buying these products makes them accomplices of these cyber-criminals.
Image of the website in which some cyber-criminals admit that the products they sell are stolen“Another risk users run is that their own banking details could be stolen, as it is not advisable to give account
numbers or credit cards numbers to those who openly declare that they steal banking details,” explains Luis Corrons, Technical Director of PandaLabs.
One of the ways cyber-criminals make these pages known to users and get them to visit them is by sending junk messages with tempting offers.
“The case of spam is particularly worrying, as it allows the offer to be sent to a very large number of people around the world. Furthermore, this technique continues to offer high profitability to cyber-criminals, as many people still buy products advertised in spam messages. What’s more, if the advertised product seems legal and has an attractive price, these cyber-criminals will be even more successful,” adds Corrons.
Panda recommends users not to reply to any offer received via junk mail.
However, cyber-criminals use other ways of making these pages known and getting users to visit them. PandaLabs has found that some cyber-criminals give their “sales partners” the option of advertising them on their website in exchange for 25 percent of the money spent by the users who access the page from their website.
发表者
SC Cyberworld
0
评论
Tuesday, June 19, 2007
Panda Software推介網上掃毒NanoScan
Panda Software launches the mini, customizable version of NanoScan, its instant online antivirus
June 18 2007. Panda Software has launched the mini, customizable version of NanoScan, the new instant virus scanner from Panda Software to detect active malware on a PC in less than one minute. NanoScan is available at: http://www.infectedornot.com/
With this launch, Panda Software is contributing to the rapidly expanding Web 2.0 user community. Portals such as iGoogle, Windows Live, NetVibes or Protopage, already have custom versions of NanoScan, where visitors can benefit from the exceptional speed and detection capacity of NanoScan.
If you have a Web portal and would like to include a mini, customized version of NanoScan, write to: partners@nanoscan.com.
Since NanoScan detects all the malware that could be running on the system (viruses, worms, Trojans, spyware, etc.), it provides a highly useful ‘second opinion’ that complements any antivirus installed on a system.
Currently, NanoScan detects more than 1,000,000 samples of known malware and is continually updated against new threats, with almost 2,500 new samples a day. It also detects unknown malware thanks to the Genetic Heuristic Technology.
NanoScan uses a new Collective Intelligence approach. This approach includes automated processing of large quantities of information about programs and files, in a new infrastructure managed by PandaLabs, and real-time communication with users’ computers. This way, the malware scan and detection is performed on Panda Software’s servers, not on the system itself. Thanks to this new approach, NanoScan is capable of detecting even malware samples that slipped past other antivirus solutions, and are active carrying out malicious actions on the computer.
Take a free trial of NanoScan’s beta version at: http://www.infectedornot.com/
发表者
SC Cyberworld
0
评论