Tag Archive for: bombarded

Mac users are getting bombarded by laughably unsophisticated malware

Mac users are getting bombarded by laughably unsophisticated malware

Enlarge (credit: Kaspersky Lab)

Almost two years have passed since the appearance of Shlayer, a piece of Mac malware that gets installed by tricking targets into installing fake Adobe Flash updates. It usually does so after promising pirated videos, which are also fake. The lure may be trite and easy to spot, but Shlayer continues to be common—so much so that it’s the number one threat encountered by users of Kaspersky Labs’ antivirus programs for macOS.

Since Shlayer first came to light in February 2018, Kaspersky Lab researchers have collected almost 32,000 different variants and identified 143 separate domains operators have used to control infected machines. The malware accounts for 30 percent of all malicious detections generated by the Kaspersky Lab’s Mac AV products. Attacks are most common against US users, who account for 31 percent of attacks Kaspersky Lab sees. Germany, with 14 percent, and France and the UK (both with 10 percent) followed. For malware using such a crude and outdated infection method, Shlayer remains surprisingly prolific.

An analysis Kaspersky Lab published on Thursday says that Shlayer is “a rather ordinary piece of malware” that, except for a recent variant based on a Python script, was built on Bash commands. Under the hood, the workflow for all versions is similar: they collect IDs and system versions and, based on that information, download and execute a file. The download is then deleted to remote traces of an infection. Shlayer also uses curl with the combination of options -f0L, which Thursday’s post said “is basically the calling card of the entire family.”

Read 7 remaining paragraphs | Comments

Biz & IT – Ars Technica

Online poker site bombarded by DDoS attacks, pauses tournaments

Online poker site bombarded by DDoS attacks, pauses tournaments

One of the world’s oldest online poker websites has been forced to pause its online tournaments after suffering a series of distributed denial-of-service attacks.

Read more in my article on the Hot for Security blog.

Graham Cluley

MalwareTech’s legal defense fund bombarded with fraudulent donations

Enlarge / Marcus Hutchins. (credit: Bloomberg via Getty Images)

Marcus Hutchins, the popular British security researcher, has a new legal headache beyond the criminal charges against him.

Hutchins, AKA “MalwareTech,” pleaded not guilty two weeks ago to criminal charges in Wisconsin that accuse him of creating and distributing the Kronos malware that steals banking credentials. Now comes word that his legal defense fund was riddled with illicit donations.

At least $ 150,000 in donations originated from stolen credit cards or fake credit card numbers, according to Tor Ekeland, a  criminal defense attorney who is not on Hutchins’ defense team. Ekeland, who became popular in hacking circles for successfully defending Andrew “weev” Auernheimer, had started a legal fund on Hutchins’ behalf.

Read 7 remaining paragraphs | Comments

Biz & IT – Ars Technica