Tag Archive for: Hiding

Hackers are hiding malware in fake LinkedIn job offers


New Delhi: Cybercriminals are hiding malware in fake LinkedIn job offers, according to a new report by security firm eSentire. The company’s threat response unit (TRU) has discovered that hackers are hiding malicious zip files in fake job offers on the professional social media platform, in a new form of spearphishing attack.

“For example, if the LinkedIn member’s job is listed as Senior Account Executive—International Freight the malicious zip file would be titled Senior Account Executive—International Freight position (note the “position” added to the end). Upon opening the fake job offer, the victim unwittingly initiates the stealthy installation of the fileless backdoor, more_eggs,” the company said in a blog post.

Also Read | How India’s banking model has changed

According to eSentire’s TRU, the malware installs a “sophisticated backdoor” that can provide hackers access to the victim’s computer. They sell these backdoors as a malware-as-a-service (MaaS) to other cybercriminals, who can use it to steal user data. Once the malware is on a victim’s computer, it can allow cybercriminals to install ransomware, credential stealers, banking malware, or another backdoor on the affected computer.

The malware presents a decoy Word document to the victim, which looks like an employment application but serves “no functional purpose”. It does so while hijacking legitimate Windows processes that give the malware access to the victim’s computer. “It is merely used to distract the victim from the ongoing background tasks of more_eggs,” the firm said.

Robb McLeod, senior director at the TRU, said the malware poses a “formidable threat to businesses and business professionals”. It’s not picked up by regular anti-virus software and security solutions since it uses normal Windows processes. Users are also more likely to download the malware since it’s hidden inside a job posting that they are already interested in. “It is a perfect time to take advantage of job seekers who are desperate to find employment,” the firm said. “Thus, a customised job lure is even more enticing during these troubled times,” it…

Source…

Parler CEO goes into hiding blaming Amazon flak, death threats


By Joel Rosenblatt | Bloomberg

The chief executive officer of Parler says he’s gone into hiding after receiving death threats.

John Matze Jr.’s social media platform was briefly the new home to conservative supporters of Donald Trump who flocked to it after Twitter banned the president. But Parler went dark Sunday after Apple Inc. and Google removed it from their app stores and Amazon.com pulled the plug on its web-hosting service, citing violent content that the e-commerce giant says played into the Jan. 6 Capitol riot.

“Many Parler employees are suffering harassment and hostility, fear for their safety and that of their families, and in some cases have fled their home state to escape persecution,” Matze’s lawyer said in Parler’s lawsuit aimed at forcing Amazon Web Services to put the platform back online. Matze had to “go into hiding with his family after receiving death threats and invasive personal security breaches.”

The CEO didn’t specify the source of the threats, but his lawyer said in a filing that Matze’s covert action was required because he’s been spotlighted “as the CEO of the company AWS continues to vilify.”

Source…

New Android ‘Dangerous’ Download Warning: 61,669 Malicious Apps Hiding On App Store – Forbes

New Android ‘Dangerous’ Download Warning: 61,669 Malicious Apps Hiding On App Store  Forbes
“android security news” – read more

Google Confirms ‘Malicious’ Security Threats Hiding On Play Store: Delete These 12 Apps Now – Forbes

  1. Google Confirms ‘Malicious’ Security Threats Hiding On Play Store: Delete These 12 Apps Now  Forbes
  2. Google advises consumers to not sideload its Android apps on new, uncertified Huawei devices  9to5Google
  3. Google addresses Huawei ban and warns customers not to sideload apps like Gmail and YouTube  The Verge
  4. Google to put a muzzle on Android apps accessing location data in the background  ZDNet
  5. Android Malware: Joker Still Fools Google’s Defense, New Clicker Found  BleepingComputer
  6. View Full Coverage on read more

“android security news” – read more