::Trend Micro Threat Resource Center::

26 May 2010

New type of phishing attack using tabs

Aza Raskin from the Mozilla Firefox team found a pretty interesting new type of phishing attack that uses automatic change of favicon icon to make one of your tabs look like another web site.

The attack goes like this:

1. A user navigates to your normal looking site.
2. You detect when the page has lost its focus and hasn’t been interacted with for a while.
3. Replace the favicon with the Gmail favicon, the title with “Gmail: Email from Google”, and the page with a Gmail login look-a-like. This can all be done with just a little bit of Javascript that takes place instantly.
4. As the user scans their many open tabs, the favicon and title act as a strong visual cue—memory is malleable and moldable and the user will most likely simply think they left a Gmail tab open. When they click back to the fake Gmail tab, they’ll see the standard Gmail login page, assume they’ve been logged out, and provide their credentials to log in. The attack preys on the perceived immutability of tabs.
5. After the user has enter they have entered their login information and sent it back your your server, you redirect them to Gmail. Because they were never logged out in the first place, it will appear as if the login was successful.

Video showcasing the attack:

A New Type of Phishing Attack from Aza Raskin on Vimeo.

Proof of concept is available over here. Note that this is the blog post about the issue, but the page changes into fake Gmail.

BitDefender impersonated by rogue antivirus

BitDefender has detected a new rogue antivirus utility that attempts to trick users into installing it by posing as a BitDefender product. Suggestively named ByteDefender, the malicious application acts like a fully-fledged rogue antivirus with a twist.

Unlike average rogue AV products, the ByteDefender sibling does not rely on the classic drive-by method used by most products of its kind, but rather piggybacks on the popularity of the BitDefender products and their distinct visual identity to lure users into voluntarily downloading it.

The website distributing it is located at hxxp://www.bytedefender.in (URL specifically invalidated to avoid accidental infection) and abusively built using the BitDefender layout. The domain name has been registered in Ukraine. Even the boxshots have been crafted in such a manner to trick the user into thinking that they are installing the genuine security product.

The infection scenario is simple, yet efficient: the user looking for a BitDefender product may typo-squat the genuine address and gets redirected to the malicious webpage. Because of the similar webpage structure, the user may download and install the rogue AV.

Read here for a more detailed report with screenshots.

24 May 2010

IBM accidentally includes on USB drive at AusCERT 2010

IBM accidentally distributed some infected USB sticks that contained a Keylogger agent (which can infect via USB flash drives). IBM may have contracted these drives with their logo to another manufacturer and may not be even be responsible. The key point is that even with media from highly reputable companies, there is a need for AV protection at all times and also users who were up-to-date on Microsoft Security patches would also be well protected. Accidents can always happen in addition to direct attacks.

Conficker Worm - IBM accidentally includes on USB drive at AusCERT2010
http://www.itnews.com.au/News/175451,ibm-unleashes-virus-on-auscert-delegates.aspx
http://www.zdnet.com/blog/security/malware-infected-usb-drives-distributed-at-security-conference/1173

QUOTE: "At the AusCERT conference this week, you may have collected a complimentary USB key from the IBM booth," IBM Australia chief technologist Glenn Wightwick wrote in an email to delegates this afternoon. "Unfortunately we have discovered that some of these USB keys contained malware and we suspect that all USB keys may be affected."

IBM said in a statement that a "small number of IBM-branded USB sticks distributed to delegates at the recent AusCERT2010 conference were found to contain malware". "IBM has immediately contacted delegates with remedial advice, and regrets any inconvenience that may have been caused," an IBM spokesman said.

22 May 2010

Social networking sites passing on user data to ad agencies

Several social networking sites - including Facebook and MySpace - have apparently been sending users' data to advertising agencies - in spite of all the assurances and promises that this information is not shared with anyone without having previously asked the users for consent and receiving a thumbs-up.

The Wall Street Journal maintains that it has discovered the concealed practice of the social networks of sending users' ID numbers and/or names to the agencies every time the users click on the ads, but that Facebook and MySpace have reacted expeditiously to the questions about it and have already changed much of the code that allowed this practice.

The problem with the advertising agencies being given this information is that they could use it to mine other personal data from the profiles of those users, if they shared it with the network and if the privacy settings are set to minimum. The advertising agencies in question - including Yahoo's Right Media and Google's DoubleClick - claim that they haven't used the data because they didn't know the data was being sent in the first place.

It seems that the sending of this data could have occurred by mistake or simply by disregarding the fact that the address of the page from which someone clicked on an ad - if that page is of a social network - could contain user names or ID numbers. In an ideal world, this information should be obscured.

The question now raised is this one: "Haven't the social-networking sites been violating their own privacy policies and industry standards?"

Digg, LiveJournal, Hi5, Xanga and Twitter have also been caught sending the information. The Wall Street Journal asked Ben Edelman, an assistant professor at Harvard Business School and a connoisseur of Internet advertising, to have a look at the code of all the 7 sites in question. He confirmed their suspicions and even alerted the FTC to the offending practice, petitioning for a deeper investigation.

Incidentally, this is not the first time this issue has arisen. Researchers from AT&T Labs and Worcester Polytechnic Institute discovered the practice and published a paper about it last year in August. They even notified the sites in question of their discovery, but nine months later, the issue still exists. It's obvious, then, that the we-didn't-know-about-it excuse can't work.

When contacted about it, they offered the following explanations.

Facebook - "We fixed this case as soon as we heard about it." They are also experimenting on changing the formatting for the text of the address so that no identifiable information is passed on.

MySpace, Hi5, Digg, Xanga and Live Journal say that since their users aren't required to use their real names, they don't regard IDs and user names as relevant or personally identifiable. But still, MySpace is working on a method to obfuscate this information, and Digg scrambles the data before sending it on.

So, time to consider reviewing the REAL information that you have put up in your social networking profile?

21 May 2010

New Twitter Worm Abuses iPhone App News

Twitter's new iPhone app is being used as a lure for a new worm attack that ultimately steals a victim's financial credentials.

The attack abuses Twitter trending topics -- a popular source of abuse -- but with a twist: Rather than installing fake antivirus software like most similar attacks, it installs a new banking Trojan that steals online banking accounts, credit card PIN numbers, and online payment system passwords, according to Kaspersky Lab.

Dmitry Bestuzhev, senior antivirus researcher at Kaspersky Lab, says the attack injects malicious tweets from the attackers' own malicious Twitter profiles. Tweets include the words "Official Twitter App," which was No. 7 of the Top 10 trending topics on Twitter. In one case, the tweet includes a link to a "video" purportedly of the Olympic mascot. "I saw a lot of people retweeting this news several times without even checking the source," Bestuzhev says. "The victims who clicked on the links were forced to open a Web page with a malicious Java archive file on it. This one downloaded and installed the Trojan banker to the victim machine."

The aggressive Trojan also disables Windows Task Manager, regedit, and notifications from Windows Security Center as a way to avoid detection. "From the moment the malicious code was active and running, if the victims opened their online bank account, made an online payment with a credit card, or by PayPal, eBay, or any other online payment system, all sensitive information was stolen and sent as encrypted information to the criminals," Bestuzhev says. The Trojan can also spread via USB devices.

Kaspersky Lab discovered the Trojan worm copies itself onto the infected system with the name "Live Messenger," and it can check whether the hard drive is virtualized. If it is, the malware won't run. The anti-malware firm calls the Trojan "Worm.Win32.VBNA.b."

Researchers at PandaLabs also have spotted the Trojan attack and blogged about it here.

Interestingly, while the attackers have the ability to take over an infected Twitter account and send malicious tweets to the victim's followers, so far they don't appear to be doing so. "They just used several recently created Twitter accounts with few followers," Bestuzhev says. But they have the capability to steal the victims' Twitter account credentials, as well, with this attack, he says.

So who's behind the attack? Bestuzhev says it appears to be coming out of Latin America -- namely, Brazil -- unlike many of the rogue AV campaigns, which typically originate in Russian-speaking countries. He posted a blog on the attack here yesterday.

20 May 2010

Critical Facebook bug exposes sensitive information

Yet another Facebook privacy bug has been discovered - this time by M.J. Keith, a senior security analyst with AlertLogic.

The bug in question makes it possible for an attacker to access the account of a user and modify its content - if the user is duped into clicking on a link that leads to malicious Web site containing the Javascript code that exploits the cross-site request forgery flaw.

According to the security advisory released on Wednesday by AlertLogic, the bug was spotted last week, and Facebook has been notified of it immediately. Three days later the social network confirms it has fixed it, but additional testing executed yesterday by Keith show that the bug is still present.

IDG News reports that Keith had created a simple Web page containing an invisible iFrame, and when they clicked on the page while being logged into Facebook, they have automatically "liked" several pages.

When you think about it - "liking" pages you normally wouldn't could be a big deal if your account is public and the pages in question are embarrassing enough to make your boss think about firing you or friends wondering if they really know you. The attacker reading and misusing you personal information and making that information public (if it isn't) could also lead to a heap of trouble.

So think twice again, before you "Like" that page.