::Trend Micro Threat Resource Center::

21 February 2016

Linux Mint Website Hacked and ISOs replaced with Backdoored Operating System


Are you also the one who downloaded Linux Mint on February 20th? You may have been Infected!
Linux Mint is one of the best and popular Linux distros available today, but if you have downloaded and installed the operating system recently you might have done so using a malicious ISO image.

Here's why:
Last night, Some unknown hacker or group of hackers had managed to hack into the Linux Mint website and replaced the download links on the site that pointed to one of their servers offering a malicious ISO images for the Linux Mint 17.3 Cinnamon Edition.

"Hackers made a modified Linux Mint ISO, with a backdoor in it, and managed to hack our website to point to it," the head of Linux Mint project Clement Lefebvre said in a surprising announcement dated February 21, 2016.

Who are affected?
As far as the Linux Mint team knows, the issue only affects the one edition, and that is Linux Mint 17.3 Cinnamon edition.

The situation happened last night, so the issue only impacts people who downloaded the above-mentioned version of Linux Mint on February 20th.

However, if you have downloaded the Cinnamon edition or release before Saturday 20th, February, the issue does not affect you. Even if you downloaded a different edition including Mint 17.3 Cinnamon via Torrent or direct HTTP link, this does not affect you either.

What had Happened?
Hackers believed to have accessed the underlying server via the team's WordPress blog and then got shell access to www-data.

From there, the hackers manipulated the Linux Mint download page and pointed it to a malicious FTP (File Transfer Protocol) server hosted in Bulgaria (IP: 5.104.175.212), the investigative team discovered.

The infected Linux ISO images installed the complete OS with the Internet Relay Chat (IRC) backdoor Tsunami, giving the attackers access to the system via IRC servers.
Tsunami is a well-known Linux ELF trojan that is a simple IRC bot used for launching Distributed
Denial of Service (DDoS) attacks.

Hackers vs. Linux Mint SysAdmins
However, the Linux Mint team managed to discover the hack, cleaned up the links from their website quickly, announced the data breach on their official blog, and then it appears that the hackers compromised its download page again.

Knowing that it has failed to eliminate the exact point of entry of hackers, the Linux Mint team took the entire linuxmint.com domain offline to prevent the ISO images from spreading to its users.

The Linux Mint official website is currently offline until the team investigates the issue entirely.
However, the hackers' motive behind the hack is not clear yet.

"What we don't know is the motivation behind this attack. If more efforts are made to attack our project and if the goal is to hurt us, we’ll get in touch with authorities and security firms to confront the people behind this," Lefebvre added.

Hackers Selling Linux Mint Website's Database
The hackers are selling the Linux Mint full website's database for a just $85, which shows a sign of their lack of knowledge.

The hack seems to be a work of some script kiddies or an inexperienced group as they opted to infect a top-shelf Linux distro with a silly IRC bot that is considered to be outdated in early 2010. Instead, they would have used more dangerous malware like Banking Trojans.
Also, even after the hack was initially discovered, the hackers re-compromised the site, which again shows the hackers' lack of experience.

Here's How to Protect your Linux Machine
Users with the ISO image can check its signature in an effort to make sure it is valid.
To check for an infected download, you can compare the MD5 signature with the official versions, included in Lefebvre's blog post.

If found infected, users are advised to follow these steps:

  • Take the computer offline.
  • Backup all your personal data.
  • Reinstall the operating system (with a clean ISO) or format the partition.
  • Change passwords for sensitive websites and emails.

You can read full detail about the hack here. The official website is not accessible at the time of writing. We’ll update the story when we hear more.

19 February 2016

Netflix has a black market for passwords, and they sell for just 25 cents

Attention Netflix users! Have you noticed odd activity in your ‘Recently Watched’ queue? There’s a possibility your account may have been compromised after a recent malware and phishing campaign targeting users has led to an influx of credentials for sale on the Dark Web for the low price of just 25 cents.


It’s long been known that hackers are nabbing and selling Netflix passwords, but a new report this week from security firm Symantec suggests the problem is growing following the streaming site’s recent international expansion to 130 new regions.

For hackers, the expanding membership base of Netflix, which is now available in a total of 190 regions globally, means there are more opportunities than ever to steal and sell passwords.

While the cost of a subscription for the streaming service already seems pretty reasonable when you look at the (legal) alternatives, the rise of the black market in Netflix passwords shows some people are willing to pay a lot less even if it means breaking the law.

According to Symantec, hackers grab passwords mainly through phishing attacks where a Netflix user is tricked into hitting a malicious link in an email or website that leads them unknowingly to a fake login page for the service. Malware is also being used to harvest account information, the California-based security firm said.

It also reveals that some cybercriminals are selling Netflix passwords on the dark Web for as little as 25 cents a pop. An ad lifted from the Web by Symantec shows a password vendor offering a minimum purchase of four accounts for a total of $1, adding that it has 300,000 passwords in stock. Its “terms of service” instructs customers not to change any account details as this would obviously alert the genuine subscriber to unauthorized activity.

Assuming the account details are indeed left untouched by the intruder, as a legitimate user you could still notice that your account’s been compromised if your “recently watched” list says you’ve already steamed through the entire season of Making a Murderer when you know darn well you haven’t (though why haven’t you?).

The video-streaming service now has 75 million users worldwide, a figure that indicates there’s plenty of potential for the black market in stolen Netflix passwords to expand and go on operating.

If you suspect that your Netflix account has been receiving an unwelcome visitor (or visitors), be sure to run a check:

  • Go to website haveibeenpwned.com. 
  • Check out the email address associated with your Netflix acount

Of course, if you’d rather be safe than sorry, you can skip that step and go straight to the fix: change your password. The important thing to remember is that you should change the password of any other account that uses the same one.


15 February 2016

Warning — Setting This Date On iPhone Or iPad Will Kill Your Device Permanently

Don’t Try this at Home! An interesting software bug has been discovered in Apple's iOS operating system that could kill your iPhone, iPad or iPod Dead Permanently.



Yes, you heard me right.

An issue with the date and time system in iOS had emerged recently when Reddit users started warning people that changing your iPhone's or any iOS device's date to January 1, 1970, will brick your iPhone forever.

You can watch the whole process in the video given below. Even regular recovery tricks do not work


So, you are recommended to Not Try This Trick with your iOS device really – unless you book a trip to your local Apple Store.

While I don’t have any intention or desire to try it out with my iPhone 6s to confirm the authenticity of the bug, it is pretty much clear based on reports that seem legitimate.

YouTuber Zach Straley first discovered the issue, which was later confirmed by iClarified, who tested the trick on an iOS device.

Affected iOS Devices
This bug affects any iOS device that uses 64-bit A7, A8, A8X, A9 and A9X processors and runs iOS 8 or newer, including iPhones, iPads, and iPod touches. However, for those running on 32-bit iOS versions are not affected by this issue.

How the Bug Kills the iPhone?
Basically, the whole process is due to this:

  • Set up the date to January 1, 1970, via settings on your iOS device
  • Reboot your device, and you are done.
Your iPhone or iPad will no longer boot and will be stuck to the Apple logo. Even recovery mode restore or DFU mode will not let you restore your device; it will remain stuck on the bootup screen.


Your device will reportedly not come back, and the only way to get it back to work once again is to take your iOS device to an Apple Store.

The Only Way to Get Your iPhone Back
The bug is believed to be related to UNIX timestamp epoch that causes the kernel to crash. The only way to get it back is to open the device's casing and physically disconnect the battery from the logic board. This could only be done with the help of Apple's Genius Bar.

This process will reset the iPhone's date and allow it to boot.

While there isn't any other fix at the moment, Apple is expected to come up with a software update to fix and unbrick the affected iOS devices.

Though some users are saying that letting the battery drain could make the iPhone work once again, or changing the SIM card could fix the issue, or waiting for the device to back after 5 hours, you are still advised to not try this on your device as there is no guarantee these tricks are going to work.

29 January 2016

'Critical' Israel power grid attack was just boring ransomware

Ransomware via a phishing attack hit Israel Electric Authority, not the power grid, but it still freaks out the world as the incident is dubbed a 'severe cyber attack;' that morphed in the media into an attack that took out the Israeli power grid.


Minister puts nation on alert, SANS Institute says move along, nothing to see here ...

The SANS Institute has moved to quell reports that Israel's energy grid has been hit by malware, revealing instead that the attacks were ransomware infecting the nation's utility regulatory authority.

Reports emerged after energy minister Dr Yuval Steinitz said a "severe" attack had hit the authority in what he reportedly called "one of the largest cyber attacks" the agency had experienced.

"We are handling the situation and I hope that soon, this very serious event will be over," Steinitz says.

Reports emerged suggesting the incident could impact the energy grid similarly to the targeted and sophisticated attacks against Ukraine, revealed earlier this year.

SANS security man Robert Lee says Israel-based analyst Eyal Sela of ClearSky Security says the reports are misleading.

"The Israel Electric Authority the Minister mentioned is in no way related to the networks of the Israeli electric companies, transmission, or distribution sites," Lee says.

"The Israeli Electric Authority is a regulatory body of roughly 30 individuals and this cyber attack is only referencing their networks.

"...new reporting shows that the cyber attack was simply ransomware delivered via phishing emails to the regulatory body's office network, and it appears it in no way endangered any infrastructure."

It is not known what ransomware infected the machines.

The latest versions of the most sophisticated malware – such as CryptoWall – cannot be removed without paying ransoms, while new and less-popular ransomware offerings contain encryption implementation flaws that allow the scumware to be removed without footing the extortion.


28 January 2016

Secret SSH backdoor in Fortinet hardware found in more products

A recently identified backdoor in hardware sold by security company Fortinet has been found in several new products, many that were running current software, the company warned this week.


Discovery comes a month after competitor Juniper disclosed unauthorized code.

The undocumented account with a hard-coded password came to light last week when attack code exploiting the backdoor was posted online. In response, Fortinet officials said it affected only older versions of Fortinet's FortiOS software. The company went on to say the undocumented method for logging into servers using the secure shell (SSH) protocol was a "remote management" feature that had been removed in July 2014.

In a blog post published this week, Fortinet revised the statement to say the backdoor was still active in several current company products, including some versions of its FortiSwitch, FortiAnalyzer, and FortiCache devices. The company said it made the discovery after conducting a review of its products. Company officials wrote:

As previously stated, this vulnerability is an unintentional consequence of a feature that was designed with the intent of providing seamless access from an authorized FortiManager to registered FortiGate devices. It is important to note, this is not a case of a malicious backdoor implemented to grant unauthorized user access.

 In accordance with responsible disclosure, today we have issued a security advisory that provides a software update that eliminates this vulnerability in these products. This update also covers the legacy and end-of-life products listed above. We are actively working with customers and strongly recommend that all customers using the following products update their systems with the highest priority:

  • FortiAnalyzer: 5.0.0 to 5.0.11 and 5.2.0 to 5.2.4 (branch 4.3 is not affected)
  • FortiSwitch: 3.3.0 to 3.3.2
  • FortiCache: 3.0.0 to 3.0.7 (branch 3.1 is not affected)
  • FortiOS 4.1.0 to 4.1.10
  • FortiOS 4.2.0 to 4.2.15
  • FortiOS 4.3.0 to 4.3.16
  • FortiOS 5.0.0 to 5.0.7

Undocumented backdoors have long been a security concern because they make it possible for outsiders to gain unauthorized access to sensitive devices. Backdoors have received increased scrutiny since network hardware maker Juniper dropped last month's bombshell that there was unauthorized code added to its Netscreen line of firewalls. Among other things, the unauthorized code in the Juniper product allowed attackers to surreptitiously decrypt encrypted traffic. While Fortinet officials say the backdoor in its products had no malicious intentions, there's little doubt it could be used for covert eavesdropping by people with knowledge of its presence.

27 January 2016

Is it time to move from Windows 7, 8 and 8.1 to Windows 10?

While standing in line at a burger joint recently, we spotted a sign in the manager's office that proclaimed, "Happy employees are productive." That pretty much sums up the Windows 10 experience from the user perspective. It's fast, feature-filled, easy to use and works across many types of devices. Although a unified experience across multiple devices (and using one account) was introduced in Windows 8, it remains a key factor in Windows OS usability. But because the mouse and keyboard still rule the desktop, it's equally important that the Start menu is back in Windows 10, in all its full glory.


Since its introduction in July 2015, Windows 10 has been well-received by consumers, partly because of the free upgrade and partly because it's a great OS for end users. These days, Windows 10 is also finally gaining traction with businesses. A Spiceworks survey of IT executives indicates that 73 percent expect to deploy the software by 2017. Let's take a look at the pros and cons involved in making that upgrade.

Why upgrade?
The unified experience is here to stay, offering a "one app platform, one security model, and one management approach" that should resonate with IT managers who must mind the budget and allocate staff time resourcefully. Microsoft has said that Windows 10 is its best and final full OS release. Going forward, the company will focus on its Windows as a Service (WaaS) model, in which updates and incremental upgrades will be rolled out as they are needed. WaaS should help organizations remain current on "upgrades," making for a more secure environment along with a less costly and time-consuming update-handling process.

Microsoft points to several good reasons to upgrade to Windows 10, such as the addition of new features and functionality, a more responsive system, easy provisioning and less overall burden on IT staff. In our opinion, a few key factors worth upgrading for include the following:


  • More control over deployments: Windows Update for Business provides feature upgrades and servicing updates from the cloud, which can target groups of endpoints for staggered and more controlled upgrade deployments. Essentially, IT staff can specify which groups of devices get updated and when such updates will occur. This is particularly important when mission-critical or line-of-business applications need to be tested in advance before deploying updates, so as not to "break" anything when updates are applied.
  • In-place upgrades: Microsoft has removed most of the complexity and effort involving in upgrading from Windows 7 or 8/8.1. Performing an in-place upgrade is easy and, for the most part, seamless. In our experience, in-place upgrades have taken about 30 minutes on average, with little to no user input needed during the process (and where automated answer files can easily handle such input for hands-off implementations). Clean installs are rarely necessary, and this applies to any device being upgraded, not just desktops and laptops.
  • Component independence: The OS treats system components as independent parts, which means they can be updated separately from the Windows core operating system. Likewise, Windows 10 provides excellent device handling, andWindows 10 is usually on-target in the drivers that it installs by default (and where issues may manifest, images can be customized easily to include such drivers for automated installations).
  • Security: The new OS includes trusted boot, which prevents malware from springing up before the boot process is complete. With UEFI Secure Boot, trusted boot allows only trusted software to run during start-up. And multi-factor authentication, which includes PINs, biometrics, a trusted PC and more, is highly streamlined and enables users to sign on to devices easily and with lightning speed.

Furthermore, Mobile Device Management (MDM) is also available across Windows 10 devices and supports laptops, tablets, smartphones and Internet of Things (IoT) devices. Enterprises can use Windows 10 IoT lockdown capabilities to prevent access to unauthorized USB devices, for example, and allow only trusted apps to run on devices.

Upgrade concerns
All of the rah-rah aside, there are indeed some downsides to upgrading, but they apply to nearly any major upgrade and not just Windows 10. For starters, an organization-wide OS upgrade is a major undertaking that requires thorough planning and testing before any production machine is affected. Legacy equipment and OSes generally cause the most issues, especially where automated deployments are concerned. Old hardware and supporting equipment may need to be upgraded or replaced outright. All of that takes time and money.

Organizations must also consider licensing costs, which can be substantial. Consumers and small businesses can upgrade from qualified OSes for free (at least for a while), but large organizations and enterprises must purchase enterprise licenses and software assurance contracts. One bright light for enterprise managers is that customers can license Windows on a per-user basis with a primary device running Windows Pro or other qualified OS. This eliminates the need to keep track of every device from the perspective of licensing.

Consider that an upgrade from Windows XP to Windows 7 costs an average of about $1,000. Although upgrading to Windows 10 should come in well under that figure, even $500 per user (as an example) in a large environment still produces an eye-popping number.