• IT Support Provider letting you down?

    There is a better way...

    Request a Quote
  • Head in the Cloud? Let us clear the path to a brighter IT future for your business.

    Call us on 01268 575300 for more information

    Request a Quote
  • Due for an IT systems upgrade or rethink? We can offer solutions for every budget.

    Call us on 01268 575300 to find out more

    Request a Quote
Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

What is X-bash? A look at the all-in-one malware threat

nearly half of all global login attempts are made by hackersFollowing on from headline claiming malware like Petya, NotPetya and WannaCry, a new threat to computer users has emerged in the form of an all-in-one malware called X-bash.

What is X-Bash?

Researchers at Palo Alto Networks have named this new form of malware X-bash. They claim it combines bot net, cryptocurrency mining software and ransomware in one singular worm that specifically targets users of Linux and Windows.

Who created it?

The researchers, named ‘Unit 42’, have claimed that the malware can be tied to a collective known as the Iron Group (aka Rocke), who are known to be behind numerous other ransomware attacks.

British businesses warned to stay vigilant in the face of Ransomware attacks

british businesses warned to stay vigilant in the face of ransomware attacksA new report from security watchdog SonicWall has confirmed that the threat of Ransomware is greater than ever in the UK and that British businesses in particular should sit up and take note, with over 38 attacks every day on UK based companies and organisations.

What is Ransomware?

Ransomware is a form of malware which locks away a victim’s files and then requests payment to have them returned. Ransoms are paid through a digital currency such as Bitcoin, which allows for highly encrypted and anonymous transactions. While a ransomware attack can be a nuisance for individual computer users, for businesses the repercussions can be far greater. A loss of sensitive data, particularly that of clients and customers can lead to serious damage to reputation and financial losses. In order to protect themselves from Ransomware, businesses should work closely with IT security specialists to ensure that systems are updated with the latest software, patches and firewalls and that they have access to offline backups of their data should the worst happen, and they fall victim to a ransomware attack.

This hidden programme could be capturing everything you type

ECL blog 38You might not realise it, but your computer could be infected with a form of malware which collects everything you type into your keyboard. Throughout the day it could harvest passwords for your banking, social media accounts and other personal information –which could lead to identity fraud, blackmail and more.

What is a key logger?

The programme in question is called a keystroke logger – or a key logger for short. While these programmes can sometimes be used for honest purposes, they are often also used by cyber criminals as a way of mining important personal information from individuals or businesses. This information could then be used to hijack your accounts, steal customer or client information, exploit your bank account or blackmail your business.

Ransomware here to stay says Google

binary damage codeBusinesses are being warned to protect themselves after tech giant Google released research claiming that cyber thieves have extorted a total of £19m from ransomware since 2015.

At a talk at the Black Hat security conference in Las Vegas, Elie Bursztein from Google revealed the results of research conducted with Chainalysis, the University of California and New York University which looked at bitcoin transactions over the period. It concluded that ransomware has become a “very profitable market and is here to stay”.

Interestingly, Google highlighted the fact that less than 40% of computer users currently back up their data – a move which could protect you in the event of a ransomware attack. It also predicted that more varied strains of ransomware are being developed to compete with the already popular Locky and Cerber strains, which according to the report generated £5.9m and £5.2m from victims respectively.

Windows 10 update to make Ransomware attacks more difficult

code-1839406_640Controlled Folder Access – that’s the name of a new feature coming to Windows which could add extra protection against dangerous Ransomware like WannaCry and Petya.

News coming from technology website The Verge says that Microsoft will include a special tool in their next major update expected in September.

The ‘Controlled Folder Access’ option which will be found in the Windows Defender Security Centre will offer users an option to ‘protect their files and folders from unauthorized changes by unfriendly applications’ thereby preventing a user being ‘locked out’ of their files by a Ransomware attack.

1bn Yahoo users’ information stolen in biggest breach ever

clip_image002Internet giant Yahoo announced this week that it had discovered over 1bn of its users’ accounts had been compromised following a historical hack three years ago.

Yahoo has announced that they have discovered a historical hack from August 2013 which surpasses their own previously set record of 500 million accounts, set only months earlier in September. This is an act that they claimed had been conducted by an ‘unnamed’ government.

Warning: your Google Chrome browser might be an imposter!

clip_image002A report by security researchers MalwareBytes has identified a dangerous new form of Adware which masquerades as the Google Chrome Browser.

The Google Chrome copycat named ‘eFast Browser’ is a form of Adware which replicates the look and feel of Chrome to trick users into thinking they are using the official thing.

Upon installation, eFast attempts to delete Chrome, removing desktop and taskbar shortcuts and replacing them with its own, which look similar.

Weebly users’ data leaked: how can you protect your own passwords?

clip_image002Weebly, a popular ‘drag and drop’ build your own website company, has become the latest target for hackers as the company announced a huge data leak of customer data.

Weebly, which is based in San Francisco, has begun notifying customers of a serious data breach which occurred earlier this year. According to LeakedSource, over 43,000,000 customers had their details stolen with usernames, email addresses, passwords and IP addresses all obtained.

Ransomware is ‘biggest immediate cyber threat’

clip_image002A recent report from the security firm Kaspersky Lab has claimed that so called ‘Ransomware’ is now the biggest and most persistent threat to internet security.

Their report, which you can read here, acknowledges that there were as many as 2,900 incidents of Ransomware attacks during the first three months of 2016, a 14% increase on the previous quarter.

Whaling – a dangerous new cyber threat

clip_image002One of the most recent cyber security threats to come to our attention is the ‘whaling’ scam. This is a highly personalised form of phishing used to trick victims into giving away sensitive information and access to networks.

What is it?

Most phishing scams target a wide range of people and hackers will send their scam emails to a large number of recipients. However ‘whaling’ is different in that cyber criminals approach one ‘high value’ target with a highly personalised message instead.

Ubiquiti Networks, a provider of high-end wireless networking products, recently fell victim to a whaling attack which resulted in losses of $47m (£30m) for the company.

Ransomware: could you be blackmailed by hackers?

clip_image002[87]Ransomware is one of the most recent threats to your online security. We look at what it is, how it works and how you can protect your business effectively.

What is it?
Ransomware, as the name suggests, is a form of malware which locks away a victim’s files and then requests payment from them to have them returned.

In 2013, Cryptolocker attacked around 250,000 computers worldwide stealing personal files and refusing to return them unless a ransom was paid immediately, which a high amount of victims went ahead and did.

Ransoms are paid through a digital currency such as Bit coin, which allows transactions to be made anonymously.

Hackers are taking over LinkedIn profiles – what can you do?

clip_image002A recent investigation by the security firm Symnatec has uncovered that hackers are creating fake profiles on the social networking site LinkedIn in an effort to scam users.

LinkedIn was established in 2003 and is a social networking site used by over 400 million professionals worldwide as an online form of business networking.

As well as allowing businesses to connect with each other, it is also provides a reliable way for recruiters to headhunt potential employees by sending them ‘connection requests’ which allow them to be able to send each other messages – a feature which hackers are now believed to be exploiting.

What can we learn from the TalkTalk hack?

clip_image002TalkTalk is the latest major company to fall victim to a significant cyber attack during which some of their customers banking details may have been accessed.

While TalkTalk has gone on to say that the details accessed may have only been partly exposed, users are being warned that they could be targeted by opportunistic cyber criminals.

It is relatively common that in the aftermath of a high profile attack hackers and other cyber criminals seize on the confusion and concern of customers by attempting to trick them into handing over sensitive information.

Beware of Facebook dislike button scam

clip_image002Facebook users are being targeted by scammers’ just weeks after Facebook announced they are close to developing a long awaited ‘dislike’ button.

On the 15th September, Mark Zuckerberg, CEO of Facebook, announced that the social networking giant was “very close” to developing a ‘dislike’ button which will allow users to show empathy toward fellow users at times when a ‘like’ would not be suitable, such as when a loved one passes away.

Rombertik: Malware that destroys your computer when detected

clip_image002It has been announced in the last few days that a new computer virus has been discovered which has been named Rombertik. The malware is designed to capture any plain text entered into a browser. Nicknamed by Cisco Systems, Rombertik’s primary purpose is a big worry but this new type of malware has an additional destructive threat.

Once setup on a Windows computer, Rombertik will check to see if it has been detected. The malware performs several regular internal checks to establish when it is under analysis. If undetected the malware will continuously steal data entered into any website browser.

Most security threats are “well-known” says HP

laptop-computers-1446068-mAn annual cyber-security report by technology firm HP has found that despite advancements in cyber attacks, the majority of cyber-security incidents in 2014 took advantage of well-known vulnerabilities that have existed for years.

The report, which looked at a range of business that had their security compromised in the least year, found that many of the issues which led to their security breaches are not new developments and that they exploited code written years or even decades earlier.

“Most sophisticated spyware” discovered by Symantec

776464_87968784One of the most sophisticated pieces of computer spyware ever seen has been discovered by the leading computer security company, Symantec.

The bug goes by the name Regin and has been dubbed “super-spyware”. It was probably created by a government according to Symantec, due to how sophisticated it is. They believe it would have taken years to create and that it has probably been used for about six years, since at least 2008, against a range of targets around the world. The fact that it has remained hidden for so long is an illustration of the great lengths its creators have gone to in order to keep it hidden.