Postări

A conversation with America Geeks

Imagine
Thanks to NeeP for contributing significant research. You can check out NeeP’s YouTube channel here . Malwarebytes has written quite a bit about tech support scammers, typically focusing on new scam techniques as they arise with new threat actor groups. But sometimes our research discovers scammers who persist with the same techniques, the same pitches, and the same IP abuse, no matter how many times we catch them. We first published on America Geeks (then known as Geeks Technical Support) in 2015, noting their attempts to use Malwarebytes’ intellectual property to pose as us and defraud their customers. After a series of takedowns and abuse complaints, we revisited America Geeks in 2016—still using Malwarebytes image assets, still scamming. And lastly, in March, Malwarebytes Labs researchers found them again using Malwarebytes to sell their scam, this time targeting French users. We were content to continue publishing on America Geeks indefinitely, but then they decided to open ...

Instagram story spam claims free Apple Watch

Imagine
I have to admit, I’m not 100 percent sure who Elton Castee is. “Who’s that?” you ask? Digging around revealed that he’s big on YouTube, has done some films , and raises money for dogs , which is very cool. He’s also popular on Instagram, with 400k+ followers. With that in mind, we’ve seen a few reports of his account being compromised (and by “few”, I mean “absolutely loads”), and decided to check it out. Click to enlarge A phony phone giveaway Visiting on the web while not logged in reveals the most recent post looks a little different from the other selfies: Click to enlarge A single white text on black background, which reads as follows: Wassup guys! I am giving away 100 free iPhone X’s and Apple watches on my IG Story! Claim them before it’s too late. Love you guys (emoji heart thing) Visiting the Instagram app while logged in immediately takes you to an Instagram Story . If you’re not familiar with an Instagram story, it’s a rotating set of images/video that you swipe t...

What is XLSTOTEXT.EXE?

A week in security (May 21 – May 27)

Last week we told you about a Mac cryptominer using XMRig , an overview of Dreamcast related scams , part 1 of decoding Emotet , and what to do about bad coding habits that die hard . We also published the results of our second CrackMe contest . Other news How a pioneer of machine learning became one of its sharpest critics . (Source: The Atlantic) The man who cracked the lottery . Spoiler: it was an inside job. (Source: The New York Times Magazine) New Spectre (variant 4) CPU flaw discovered —Intel, ARM, AMD affected (Source: The Hacker News) Amazon urged not to sell facial recognition tool to police . (Source: ABC News) Does the Facebook app even spy on those who don’t have an account ? (Source: The Register) FBI stats: email fraud still #1 cybercrime . (Source: MailGuard Blog ) Brain Food spam botnet malware found on thousands of websites . (Source: SCMagazine) Amazon Alexa Security – How to stop hacks on voice assistants . (Source: Forbes) Necurs delivering flawed Ammy...

Microsoft SMB MS17-010 Disclosure Attempt

Researchers discover vulnerabilities in smart assistants’ voice commands

Imagine
Virtual personal assistants (VPA), also known as smart assistants like  Amazon’s Alexa and Google’s Assistant , are in the spotlight for vulnerabilities to attack. Take, for example, that incident about an Oregon couple’s Echo smart speaker inadvertently recording their conversation and sending it to a random contact. Or that time when the Alexa started laughing out of the blue . Indeed, something has to be done about these hacks , whether they’re by accident or not. Earlier this month, researchers from Indiana University, the Chinese Academy of Sciences, and the University of Virginia found exploitable weaknesses in the VPAs above. Researchers dubbed the techniques they used to reveal these weaknesses as voice squatting and voice masquerading . Both take advantage of the way smart assistants process voice commands. Unsurprisingly, these also exploit users’ misconceptions about how such devices work. How smart assistants work VPA services used in smart speakers can do what the...

GSMA Mobile 360 Series focuses on privacy & security | Avast

Imagine
If you’re in the area, come visit us at the Privacy & Security conference taking place this Wednesday and Thursday in The Hague. Avast is a proud sponsor of the GSMA Mobile 360 Series , showcasing relevant discussions for mobile network operators (MNOs), but actually important for any business in the wider digital ecosystem. The two-day gathering of industry leaders will focus on the latest evolving cyberthreats and their respective solutions. GSMA organizers deliberately scheduled the event to take place just as the new GDPR rules and regulations kick in and online privacy is a key concern for people around the world.