::Trend Micro Threat Resource Center::

26 August 2015

Malaysia takes the lead as the most cyber-savvy Asian nation while Indonesia is on the bottom rung

While 93% of online users in Asia worry about cyber security, 3 out of 5 consumers are unable to answer basic cyber security questions correctly, according to the ESET Asia Cyber Savviness Report 2015.


The survey also underlines that the region still has a long way to go in understanding online security and protecting themselves.

Polling 1,800 respondents from across Hong Kong, India, Indonesia, Malaysia, Singapore, and Thailand, the survey aimed to gain insights into the attitudes, knowledge and user behaviours across Asia when it comes to cyber security.

Despite the fact that Asia-Pacific region has the highest number of internet users in the world, the results of the study show that users in this region don’t know how to stay safe online. Moreover, a large  share of those  polled  commit basic mistakes like using passwords containing easy to access personal information, such as their date of birth or surname, storing passwords and credit card details online, and connecting to unsecured public wi-fi networks.

ESET’s study ranked Malaysia as the most ‘cyber-savvy‘nation in Asia-Pacific, ahead of Singapore, India, Thailand, Hong Kong, and Indonesia in that order. Cyber-savviness is based on factors such as the ability to understand activities likely to make them vulnerable online, risky behaviours while surfing the web, and the steps users take to protect themselves online.

Surprisingly, the results showed that consumers in countries with higher cyber savviness didn’t necessarily take all the right precautions, nor were they fully aware of the cyber security risks that common online activities pose. For example, users in India and Indonesia, take the highest number of precautions despite having the lowest levels of cyber security awareness. On the other hand, countries like Malaysia, Singapore and Thailand, which ranked amongst the top in ESET’s awareness survey came in near the bottom when it came to protecting themselves.

“We need to bust some myths about online security,” said Parvinder Walia, Sales Director APAC at ESET. “The ESET Asia Cyber Savviness Report 2015 found that users in Asia-Pacific tend to take unnecessary risks when they’re online, partly due to a lack of awareness. Users have the dangerous misconception that their personal accounts and activities are not likely to be a target for hackers or might be trading security for convenience. This has to change.”

“Information today is available at the touch of a button and the Internet is simplifying our day-to-day lives. Being aware and taking simple precautions will mean that users can stay protected online and feel confident as they take advantage of all that the Internet has to offer,” added Walia.

More education needed to boost cyber security awareness 
The study quizzed respondents about common safety risks online in order to find out how much they actually know about cyber security. Across the region, while 68 percent of online users said that they are aware of online security issues, they were unable to answer questions regarding cyber security practices.

In the Asia-Pacific region, the lack of formal education is a huge issue as 4 in 10 online users said they gained most of their information about online security through unofficial sources such as doing their own online research or from their families and acquaintances.

On an encouraging note, over 78 percent of the surveyed respondents that didn’t have any formal training about cyber security, said they were keen to learn more.

21 August 2015

Ashley Madison 2.0 - Hackers Leak 20GB Data Dump, Including CEO's Emails

The group of hackers behind the breach of Ashley Madison, the popular cheater's dating service, have released a second, even much bigger 'cheat sheet' exposing sensitive materials that include sensitive corporate information.


Two days ago, the hackers released nearly 10GB of its customers' personal data online, which included 36 million emails and hashed passwords, 9.6 Million Credit Card Transactions records and their associated usernames.

Nearly 20GB of Ashley Madison Internal Data LEAKED
This time, the Impact Team leaked nearly 20GB worth of what appears to be internal data – not customers' data – from the adultery website on the dark Web
.
The leaked data appears to include the source code for the site, as well as a massive amount of e-mail from Ashley Madison parent company's Avid Life Media CEO Noel Biderman.
According to the researcher, who analysed the leaked data, the TL;DR of the leak is:

  • The leak contains lots of Source Code
  • 73 different git repositories are present
  • Ashley Madison used gitlab internally
  • The 13GB compressed file appears to contain Ashley Madison CEO's emails seems corrupted
  • The leak contains plain text or poorly hashed (md5) db credentials

Personal Emails of Avid Life Media CEO Noel Biderman Exposed
The trove of information was dumped with a taunting message to the adultery website's founder posted on the same dark web hosting the earlier data dump. The message reads:

"Hey Noel, you can admit it's real now." – presumably directed at CEO Noel Biderman, who has refused to recognize the data is all legitimate.


Dave Kennedy, the founder of cyber security company TrustedSec LLC, has analysed the second data dump and confirmed that it contained nearly 1GB of Biderman's emails.

"The dump appears to contain all of the business/corporate e-mails, the source code for all of [Avid Life Media's] websites, mobile applications, and more," TrustedSec wrote in its official blog post published yesterday.

This is really interesting; having the complete source code to these websites means that hackers now are capable of finding new security holes in Avid Life's websites, and further compromise them more.

However, we have yet to wait for a response to this new release from Avid Life Media officials. If they do, this post will be updated accordingly.

11 August 2015

A New Company Called Alphabet Now Owns Google

Well, this was a very unexpected move by Google.


Google Co-Founder Larry Page announced a restructuring of the whole company, revealing the creation of the umbrella "Alphabet" corporation.

But, don’t worry… Google isn’t dead! Rather, Google will become part of Alphabet.

Why Google Rebrands As ‘Alphabet’
Over time, Google, the Mountain View company has become a lot more than just a Search Engine.

Google created and acquired a large number of other popular Internet services, including Android, YouTube and Gmail, that makes too much difficult for a single company to manage all of them effectively.

According to Google Founders, it’s time, when different projects require different leaders, different company cultures, and different types of resources.

"Our model is to have a strong CEO, who runs each business, with Sergey and me in service to them as needed," Page wrote.

So the founders decided to create an all new parental brand that will manage both Google as well as its other far-flung projects — called ‘Alphabet’, going to be the biggest tech company most people have never heard of.

As a part of the new structure, Alphabet will manage Google and all of its other products, including:

  • Google
  • Calico, an anti-aging biotech Research Division
  • Nest, Google's Smart-Home project
  • Sidewalk, a company, focused on Smart Cities
  • Fiber, Company for High-speed Internet services
  • Investment arms, such as Google Capital and Google Ventures
  • R&D unit, such as Google X, developing Self-driving cars and Drones.
  • Alphabet Inc. will replace Google Inc. as the publicly traded company on the Nasdaq Stock Exchange, and shareholders will get one Alphabet share for every Google share they previously owned.

G is for 'Google' and 'Sundar Pichai 'is New CEO
Google’s senior vice president Sundar Pichai (Pichai Sundararajan), currently senior vice president of products, will be the new CEO of the Search Engine.


Google is now a more coherent company than it was previous. Google will now include the company's core businesses, including:

  • Search Engine
  • Advertising, Adwords, and Adsense
  • Google Maps
  • YouTube, the Video Service
  • Android, Mobile operating system
  • Chrome operating system
  • related technical infrastructure.

And the current CEO Larry Page will become Alphabet’s CEO. Co-founder Sergey Brin will be its president, and Eric Schmidt will be the executive chairman of Alphabet.

"It is clear to us and our board that it is time for Sundar to be CEO of Google," Larry Page wrote in the open letter announcing the creation of Alphabet.

"Google itself is also making all sorts of new products and I know Sundar will always be focused on innovation—continuing to stretch boundaries. I know he deeply cares that we can continue to make 
big strides on our core mission to organize the world's information."

The 43-year-old Sundar Pichai rose quickly at Google, from working with the Chrome team to lead both the team as well as Android as senior vice president of Products.

The Launch of Alphabet Inc. will not affect you at all, but Good news… the company’s shares jumped 6 percent after hours, adding tens of billions of dollars to its value.

29 July 2015

IoT to generate 20 trillion gigabytes of data by 2025

Internet of Things (IoT) has been gaining quite a fair bit of attention in the headlines recently. SO what can we expect out of this emerging technology trend?


The Internet of Things is expected to generate more than 20 zettabytes, or 20 trillion gigabytes, of data by 2025, underlined by the increase in broadband penetration and access speeds, according to researched unveiled by Seagate Technology.

The research shows multiple device ownership and increased Internet speeds as being key drivers of cloud adoption and IoT.

Asia Pacific broadband speeds will be fastest in the world 
According to the research, broadband speeds in the region are expected to be the fastest in the world and quadruple to 87 Mbps in a decade, compared to a forecasted average of 72 Mbps globally. This means that a two hour high definition movie can be downloaded in 7 minutes as compared to approximately 28 minutes today.

While Asia Pacific leads in terms of speed, broadband penetration rates in 2025 are expected to remain disparate and varying between countries in the region. Developed markets like South Korea (99 percent), Singapore (95 percent) and Hong Kong (95 percent) can be seen as achieving ubiquity, while India, Indonesia and other Asia Pacific countries lag behind with penetration rates of 10 percent or less.

Majority of data will be generated by non-PC devices
The research shows that more than 40 billion devices will be connected to the Internet by 2025, and the majority of the IP traffic will be generated by non-PC devices. 64 percent of those connections will be used by machine-to-machine devices, 26 percent from smartphones, 5 percent from tablets, 4 percent from feature phones and only 1 percent from laptop PCs.

The automotive sector represents the fastest growing segment for IoT, growing from 200 million units in 2014 to more than 3.5 billion by 2025. Innovations that are already in today’s top range cars such as connected on-board diagnostics and automated safety systems will become more pervasive. At the same time, consumer IoT is projected to be the largest segment, reaching 13 billion devices by 2025, partly due to the growth of devices like smart watches and activity trackers.

According to the study, 11 million units of smart watches were sold in 2014, while its simpler sibling – activity trackers, shipped 32 million units. The total number of wearable devices in use is estimated to reach 170 million units by 2017, and that industry will be worth $10 billion in 2016.

Sales of fitness wearables in particular, will triple from 70 million devices in 2013, to 210 million in 2020.

In addition, the research identified smart garments often worn by athletes, like the smart shirts worn by Germany’s World Cup-winning soccer team, as having the greatest potential for growth, with an estimated compound annual growth rate (CAGR) of 48 percent predicted to take place between 2015 and 2020.

24 July 2015

Adult Dating Website Ashley Madison Hacked; 37 Million Accounts Affected

Life is short. Have an affair," but always remember "Cheaters never prosper."

AshleyMadison.com, an American most prominent dating website, that helps married people cheat on their spouses has been hacked, potentially putting very private details of Millions of its users at risk of being exposed.


The Stolen personal data may include information from users’ real names, addresses and their personal photographs to credit card details and sexually explicit chat logs.
With a Huge Database of over 37 Million users, AshleyMadison.com, owned by Avid Life Media (ALM) company, is a very popular dating website that helps married people have extramarital affairs.

Cougar Life and Established Men, two other dating sites also owned by Avid Life Media, have also had their data compromised.

The Hacker group responsible for the hacks called itself "The Impact Team," a company spokesperson confirmed.

The group apparently raises an objection to the website’s morally dubious business model and were threatening the company to release all its customer records if the Ashley Madison and Established Men are not completely shut down.

The Impact Team claims to have complete access to not only personal account information of the company’s customers, but also their secret sexual fantasies and matching credit card transactions, names, residential addresses, employee documents and emails.

Reason behind the Ashley Madison Hack
The Impact Team of hackers appears to be upset over a website's service called "Full Delete" that promises to erase a customer's profile and all associated data for a $19 fee completely.
However, according to the Impact Team, Ashley Madison made money from the paid "Full Delete" service that does not work.

"Full Delete netted [Avid Life Media] $1.7mm in revenue in 2014. It’s also a complete lie," the group wrote in a statement released Sunday. "Users almost always pay with the credit card; their purchase details are not removed as promised and include real name and address, which is, of course, the most important information the users want to be removed."

The company denied the claims, however, is now temporarily offering its customers the ability to delete their account completely from the website free of charge.

If you are Ashley Madison customer, You should Worry
Avid Life Media is working with law enforcement agencies to investigate this criminal act and also using Digital Millennium Copyright Act to get the personal data the hackers have disclosed so far removed from the Internet.

However, It’s unlikely to be a prevention measure, because once the personal data has been publicly exposed over the Internet, it becomes almost next to impossible to stop its spread.

13 July 2015

TeslaCrypt 2.0 conceals its identity to demand a US$500 ransom


Kaspersky Lab has detected curious behaviour in a new threat from the TeslaCrypt ransomware encryptor family. In version 2.0 of the Trojan notorious for infecting computer gamers, it displays an HTML page in the web browser which is an exact copy of CryptoWall 3.0, another notorious ransomware programme.

Perhaps the criminals are doing this as a statement of intent: so far, many files encrypted by CryptoWall could not be decrypted, which is not the case with many past cases of TeslaCrypt infection. After a successful infection, the malicious programme demands a $500 ransom for the decryption key; if the victim delays, the ransom doubles.

Early samples of TeslaCrypt were detected in February 2015 and the new ransomware Trojan gained immediate notoriety as a menace to computer gamers. Amongst other types of target files, it tries to infect typical gaming files: game saves, user profiles, recoded replays, etc. That said, TeslaCrypt does not encrypt files that are larger than 268 MB.

Mechanism of Infection 
When TeslaCrypt infects a new victim, it generates a new unique Bitcoin address to receive the victim’s ransom payment and a secret key to withdraw it. TeslaCrypt’s C&C servers are located in the Tor network. The Trojan’s version 2.0 uses two sets of keys: one set is unique within one infected system, the other is generated repeatedly each time the malicious programme is re-launched in the system. Moreover, the secret key with which user files get encrypted is not saved on the hard drive, which makes the process of decrypting the user files significantly more complicated.

Programmes from TeslaCrypt malware family were observed to propagate via the Angler, Sweet Orange and Nuclear exploit kits. Under this malware propagation mechanism, the victim visits an infected web site and the exploit’s malicious code uses browser vulnerabilities, most typically in plugins, to install the dedicated malware on the target computer.

“TeslaCrypt, a hunter of gamers, is designed to deceive and intimidate users. For example, its previous version displayed a message to the victim saying that his/her files were encrypted with the famous RSA-2048 encryption algorithm, and thus demonstrated there was no option to paying the ransom,” said Fedor Sinitsyn, Senior Malware Analyst at Kaspersky Lab.

“In reality, the cybercriminals did not use this algorithm. In its latest modification, TeslaCrypt convinces victims they are dealing with CryptoWall – once the latter encrypts user files, there is no way to have them decrypted. However, all links lead to a TeslaCrypt server – apparently, the malware authors have no intention of giving their victims’ money away to a competitor,”

 Recommendations to users

  • Create backup copies of all your important files on a regular basis. Copies should be kept on media that are physically disconnected immediately after the backup copying is completed.
  • It is crucially important to update your software in a timely fashion, especially the web browser and its plugins.
  • Should a malicious programme still land on your system, it will be best addressed by the latest version of a security product with updated databases and activated security modules.
  • Kaspersky Lab’s products detect this malicious programme as Trojan-Ransom.Win32.Bitman.tk and successfully protects users against this threat.

In addition, a Cryptomalware Countermeasure Subsystem is implemented in Kaspersky Lab’s solutions. This registers activity when suspicious applications attempt to open a user’s personal files and immediately makes local protected backup copies of them.

If the application is judged to be malicious, it automatically roll backs unsolicited changes by replacing those files with copies. In this way, users are protected from yet unknown cryptomalware.