::Trend Micro Threat Resource Center::

10 April 2010

Trojan disguised as Windows Mobile game

A "trojanized" pirated version of a 3D first-person shooter game for the Windows mobile platform found its way to some Windows Mobile freeware download sites and "infected" the phones of those who downloaded it and installed them on their devices.

3D Anti-terrorist action is the name of the game, and it's manufacturer is located in China. But, as F-Secure reports, the trojanized version is the work of a Russian malware author, and makes the phones automatically, repeatedly and silently dial premium-rate numbers.

Here is the part of the trojanized game's code that makes the phone execute the code:

What is the virus writer's payoff, you might ask? Usually, it is a percentage of the revenue that resulted from those calls. The rates for this numbers are higher than normal, and you get billed by the minute.

Having a malicious software like this on your cell phone and not noticing it can result in a heart attack-inducing phone bill. Users are advised not to download pirated copies of any software, since there in no guarantee you'll get what you think you will.

08 April 2010

iPad, iPhone "prizes" as lures for Twitter users

Not surprisingly, spam using the Apple iPad as a lure to get users to give up personal or credit card information has began to make rounds of Twitter users.

Sunbelt reveals that Twitter bots have been hard at work spamming users discussing (or just mentioning) the iPad with messages such as these:

The link takes the users to promotional sites that where - in order to get and iPad - they are asked to fill in forms with a large amount of personal information, and to fill in some more information and get "accepted for a financial product such as a credit card or consumer loan” or even purchase something to get an additional gift ("2 years of unlimited data service").

In another instance, Sophos spotted an advert within a Twitpic page that offers the iPhone as a prize if you enter a competition that provides a perfunctory "spot the difference in the two pictures" quiz (in which, by the way, you can make as many mistakes as you want because you will be offered another chance to answer correctly).

When you provide the right answer, you are asked to provide various personal information so that they can send you the prize:

Both promotions seem legitimate, but it is only a matter of time when these "competitions" take a more malicious turn. Users are advised to remember that even if it says "Free!", you are actually "paying" for it with your personal information.

In this last instance, you could also incur an immediate material cost if you are not careful - the checked (by default) checkbox at the bottom of the page will sign you up for an alert service that costs £1.50 per week.

07 April 2010

Check how secure, private and open an app is

Surfing through the Net in search of a objective review of an application can be a daunting task, and even when you find one, it usually barely touches the issues of security or privacy.

Enter WhatApp (https://whatapp.org), a wiki page where you can rate and read reviews of Web and social network applications, browsers, add-ons and mobile platforms - reviews that will not tell you if an app is cool or not, but will tell you how secure, private and open it is.

The WhatApp wiki is the brainchild of Stanford's Center for Internet and Society academics and is funded by the Rose Foundation, which supports different projects that - among other things - promote consumer protection and civic participation.

In the teams' own words: "We want WhatApp to be a useful tool for both savvy Internet experts and novices to pool resources and share insights about the privacy features of a wide variety of applications, including Facebook and iPhone Apps, office suites, online maps, toolbars, and media players. The project’s aim is to fill the current market gap between consumer demand for privacy friendly applications and anti-privacy practices employed by the developers and thereby to foster better privacy practices Net-wide."

The page is actually quite simple and easily navigable and usable - search for the app you want to check out or browse the list of already reviewed apps:

The main page also contains two boxes that feature "good" and "bad" apps (of the week? Month?).

Currently, the Featured App is BugMeNot, a service that allows you to bypass compulsory registration to various sites and services by offering bogus data. RockYou Live is in the Penalty Box, for getting hacked and revealing (unencrypted) user data.

03 April 2010

Beware fake eBay security alert

Red Condor issued a warning of a new blended email threat that appears to be a security alert from eBay. The email message with the subject line "eBay Procedural Warning - Security Alert," is addressed to "Dear eBay Member," and warns recipients that the sender has "detected security issues on behalf of your account."

The email warns that to correct the issue, users "have to download and install the eBay Security Shield." The embedded link in the email actually takes user to a likely compromised site on eBay's network.

On the site is a Download Now button that when executed installs a Trojan. After the victim installs the malware as prompted by the email, they are directed to log into their eBay accounts, which then sends their eBay log-in credentials to the scammers.

"While this is a relatively low volume campaign, the scammers have not only figured out how to circumvent the majority of anti-virus engines, they have also exploited an 'About Me' page of a compromised eBay account to host the Trojan," said Dr. Tom Steding, president and CEO of Red Condor.

"In past eBay phishing attacks, the call to action URL has been on some random compromised machine. This scam, however, is a malicious and very sophisticated attack, and unfortunately, is a good representation of the types of phishing attacks that we are likely to see going forward. This attack is likely to get by many email security systems, so users should delete the message immediately."

02 April 2010

Games on social networks increase spam and phishing by 50%

In order to reach high scores, social entertainment applications require users to gather a considerable number of friends and supporters to play the same game, leading to player-development of social gaming channels, groups and fan pages to facilitate player interaction.

Spammers and phishers exploit the increasing trend of social gaming with fake profiles and bots that send spam messages to groups, as a BitDefender case study shows.

Unlike the regular social networking spam, when the users are enticed to add the spammer in their circle of friends, the social gaming-related phony profiles are willingly added by the users as an immediate consequence of their interest in enlarging the supportive players’ community. This makes it almost impossible for the bogus accounts to be automatically suspended, since the spammers’ action does not constitute an abuse.

The study also demonstrates that the most successful fake accounts are those miming real profiles, which hold plenty of details and pictures of the “user.” In an acceptance experiment, BitDefender researchers created three honeypot profiles – one without any picture and holding few details, another with an image and limited information and a third with a large amount of data and photos. All three profiles where subscribed to general interest groups.

One hour after adding people to each profile, the circle of friends enlarged with 23 connections for the first profile, 47 for the second profile and 53 for the third profile.

After joining social games groups, the volume of users willing to add unknown people drastically increased. Within 24 hours, 85 users accepted a request from the first profile, 108 from the second and 111 from the third.

“Users are more likely to accept spammers in their friends list when they are in a social network than in any other online communication environment,” said George Petre, BitDefender threat intelligence team leader and author of the case study.

The security implications are numerous, ranging from the consolidation and increase of the spamming power, data and ID theft, accounts hijacking to malware dissemination. A shortened URL posted without any explanation on each honeypot profile was followed by 24 percent of the friends from the three accounts, even if they did not know who posted it and where was going.

01 April 2010

Hacked Yahoo email accounts in China and Taiwan

Yahoo email accounts of several journalists and human activists have been hacked and their contents likely downloaded in what seems like an organized attack concentrated on gaining as much intelligence as possible regarding activities that those people might be engaged in and that the Chinese government finds objectionable or threatening to social stability.

Among the owners of the hacked accounts are Kathleen McLaughlin, a freelance journalist; Andrew Jacobs, reporter for the New York Times in Beijing; and Dilxat Raxit, spokesmen of World Uyghur Congress, a group that supports the idea of separatism among the ethnic Uighurs.

The accounts were inaccessible for several days, and Raxit says that that he couldn't access his for a whole month. Jacobs says that he discovered that his account was set to forward his emails to an unknown account - without his knowledge, of course.

Reuters reports that Yahoo made a statement in which claims it is going to investigate the matter and that it "condemns all cyber attacks regardless of origin or purpose". It was speculated that the company was among the ones that were breached by the Aurora attacks in January, but it was never actually confirmed by Yahoo itself.