Tag Archive for: Legit

Botnet Operators Abusing Legit GitHub, Pastebin Resources


Cryptocurrency Fraud
,
Cybercrime
,
Fraud Management & Cybercrime

Researchers: ‘Gitpaste-12’ Botnet Mainly Targets Linux And IoT Devices

Botnet Operators Abusing Legit GitHub, Pastebin Resources
GitHub Page Hosting ‘Gitpaste-12’ malware before being taken down (Source: Juniper Threat Labs)

The operators behind a recently uncovered botnet dubbed “Gitpaste-12” are abusing legitimate services such as GitHub and Pastebin to help hide the malware’s malicious infrastructure, according to report from Juniper Threat Labs.

See Also: Palo Alto Networks Ignite 20: Discover the Future of Cybersecurity, Today


The botnet, which was first uncovered in October but appears to have been activated in July, mainly targets vulnerable Linux applications as well as internet of things and other connected devices, according to Juniper. The researchers also note that the malware contains at least 12 separate attack modules to help it infect new endpoints and apps.


While the ultimate purpose of the botnet is not fully known, the Juniper analysis finds that Gitpaste-12 comes equipped with cryptomining capabilities and can specifically mine monero cryptocurrency, according to the report.


It is the use of legitimate services such as Pastebin and Github, however, that stood out when the researchers first came across the botnet last month, according to the report.


By using Pastebin and GitHub, the malware can remain hidden from firewalls and proxies. This allows the operators to act stealthily while building the botnet and sending instructions through the command-and-control server, according Juniper’s Alex Burt and Trevor Pott note in their report.


Juniper has contacted…

Source…

Social Media Promised To Block Covid-19 Misinformation; But They’re Also Blocking Legit Info Too

Sing it with me, folks: content moderation is impossible to do well at scale. Over the last few weeks, all of the big social media platforms have talked about their intense efforts to block misinformation about Covid-19. It appeared to be something of an all hands on deck situation for employees (mostly working from home) at these companies. Indeed, earlier this week, Facebook, Google, Linkedin, Microsoft, Reddit, Twitter, and YouTube all released a joint statement about how they’re working together to fight Covid-19 misinformation, and hoping other platforms would join in.

However, battling misinformation is not always so easy — as Facebook discovered yesterday. Yesterday afternoon a bunch of folks started noticing that Facebook was blocking all sorts of perfectly normal content, including NY Times stories about Covid-19. Now, we can joke all we want about some of the poor NY Times reporting, but to argue that its reporting on Covid-19 is misinformation would be, well, misinformation itself. There was some speculation, a la YouTube’s warning that this could be due to content moderators being sent home — and not being allowed to do their content moderation duties over privacy concerns, but the company said that it was “a bug in an anti-spam system” and was “unrelated to any changes in our content moderation workforce.” Whether you buy that or not is your choice.

Still, it’s a reminder that any effort to block misinformation is going to be fraught with problems and mistakes, and trying to adapt rapidly, especially on a big (the biggest) news story with rapidly changing factors and new information (and misinformation) all the time, is going to run into some problems sooner or later.

Permalink | Comments | Email This Story

Techdirt.

Windows 10 Flaw Lets Malware Disguise Itself as Legit Software – PCMag

  1. Windows 10 Flaw Lets Malware Disguise Itself as Legit Software  PCMag
  2. Microsoft, NSA confirm killer Windows 10 bug, but a patch is available  PCWorld
  3. Microsoft Patches Serious Crypto Flaw Found by NSA  Infosecurity Magazine
  4. An Alarming Windows Bug, a Triumph for Tesla, and More News  WIRED
  5. Your PC is in danger if you use Windows 7  Wink News
  6. View full coverage on read more

“malware news” – read more