Tag Archive for: Version

New RedLine malware version spread as fake Omicron stat counter


redline

A new variant of the RedLine info-stealer is distributed via emails using a fake COVID-19 Omicron stat counter app as a lure.

RedLine is a widespread commodity malware sold to cyber-criminals for a couple of hundred USD. It supplies dark web markets with over half of the stolen user credentials sold to other threat actors.

The malware is actively developed and continually improved with widespread deployment using multiple distribution methods.

RedLine targets user account credentials stored on the browser, VPN passwords, credit card details, cookies, IM content, FTP credentials, cryptocurrency wallet data, and system information.

The most recent variant was spotted by analysts at Fortinet, who noticed several new features and improvements on top of an already information-stealing functionality.

Targeting additional data

The new variant has added some more information points to exfiltrate, such as:

  • Graphics card name
  • BIOS manufacturer, identification code, serial number, release date, and version
  • Disk drive manufacturer, model, total heads, and signature
  • Processor (CPU) information like unique ID, processor ID, manufacturer, name, max clock speed, and motherboard information

This data is fetched upon the first execution of the “Omicron Stats.exe” lure, which unpacks the malware and injects it into vbc.exe.

The additional apps targeted by the new RedLine variant are the Opera GX web browser, OpenVPN, and ProtonVPN.

Previous versions of RedLine targeted regular Opera, but the GX is a special “gamer-focused” edition growing in popularity. 

Moreover, the malware now searches Telegram folders to locate images and conversation histories and send them back to the threat actor’s servers.

Finally, local Discord resources are more vigorously inspected to discover and steal access tokens, logs, and database files.

New RedLine variant searching for Discord logs
New RedLine variant searching for Discord logs
Source: Fortinet

Campaign characteristics

While analyzing the new campaign, researchers found an IP address in Great Britain communicating with the command and control server via the Telegram messaging service.

The victims are spread across 12 countries, and the attack doesn’t focus on specific organizations or…

Source…

Avast-Mobile Security App (Antivirus for Mobile)



New version of the Advice to Travelers app (Dec. 16 2021)


A new version of the mobile Advice to Travelers app is now available. Created in 1999, the Advice to Travelers page has seen a massive increase in hits on the France Diplomatie site in recent years, with 32 million hits in 2020 compared with 9.4 million in 2019, and more than 58 million since the beginning of 2021.

In light of the rapidly evolving health situation, it is more necessary than ever to make proper preparations for travel abroad.

To meet the needs of French citizens who travel abroad, the Ministry for Europe and Foreign Affairs decided to update the mobile app launched in 2012. In this latest version, users will have access, as they do on the website, to the 191 files that provide information on the situation in destination country to facilitate smooth stays abroad.

That information includes security advisories (written references and maps), conditions for entry and stays, health information (vaccination requirements, restrictions on movement linked to the Covid-19 pandemic, etc.) and practical information (practices and customs, local laws, etc.).

It is updated regularly by the Ministry for Europe and Foreign Affairs’ Crisis and Support Center in partnership with our field-based posts using a system certified by the ISO 9001 standard. In 2020, 3,378 updates were made.

The latest version of the app can be downloaded onto Android and IOS devices.

Source…

GBT Roadmaps The Development of a Wearable Version for Its


SAN DIEGO, Oct. 20, 2021 (GLOBE NEWSWIRE) — GBT Technologies Inc. (OTC PINK: GTCH) (“GBT” or the “Company”) has on its roadmap, a wearable version of the qTerm device. The finger-touch version prototype of the device is now under manufacturing; and the company plans to start a wearable version next year. GBT’s qTerm, a human vitals device, is aimed to measure human vitals with the touch of a finger.

According to Gartner’s (Gartner Forecasts Global Spending on Wearable Devices to Total $81.5 Billion in 2021) forecast, the world will spend about $81.5 billion on wearable devices in 2021, a significant rise compared to 2020. This rise is directly correlated with the global pandemic and the importance of health monitoring in our lives.

The qTerm wearable device is planned to have all features of the finger-touch version plus additional features that can be utilized due to its shape characteristics. Upon a user’s permission, an automatic scheduled monitoring feature is planned for on-going health observation. The device’s AI system will learn about the user’s health concerns and conditions, and perform health checks as part of a daily routine, transparent to the user. Even if users forget to take vitals measurements, the device will do it automatically for them. Based on the device’s cognitive and reasoning capabilities, automatic vitals measurements will be taken continuously throughout the day. In case of abnormal results, the device will alert, and advice on further steps; the device can be integrated with clinics and hospital data systems to keep and monitor patient’s records. It will be able to directly alert physicians about any health-related concerns and could also be used during telemedicine sessions. The wearable device plans to use optical sensors technology with an advanced display. Additionally, a web portal synchronized with a mobile application is planned to support qTerm’s wearable version. And just like the finger-touch version, the data will be securely kept and transferred to a back-end AI program for further analysis and monitoring. Due to the device’s nature, GBT will continue evaluating the addition of more wearable-oriented features…

Source…