The McAfee Threats Report for the first quarter of 2013 highlighted a noteworthy increase in the number of Koobface malware samples on record. This data point is based on the number of unique malicious files associated with the Koobface family, and is generally one indicator of active malware development. Besides the number of changes made Read more…
Darkmegi was in the news a couple of months back; it was the first known threat to be delivered through the Microsoft vulnerability CVE-2012-0003 (MIDI Remote Code Execution Vulnerability) exploitation. More recently Darkmegi has been seen in CVE-2011-3544 (Java Runtime Remote Code Execution) drive-by attacks as part of the Gong Da Pack exploit kit. Darkmegi uses Read more…
Tags: Deep Defender, DeepSAFE, rootkit, Stealth
It’s been more than a year since McAfee became an Intel company, and the team and I have been privileged to be a part of designing and developing our DeepSAFE technology, as well as Deep Defender, the first available product that leverages this advancement. Recent threats in the news validate what we’ve been working on, Read more…
Tags: Deep Defender, DeepSAFE
Here’s a quick update on the Mac OS X malware landscape, a rather hot topic this month. May started off with the announcement of the DIY malware kit Weyland-Yutani BOT. This news was shortly thereafter dwarfed by numerous reports of fake (a.k.a. rogue) security software for the Mac; names include Mac Defender, Mac Protector, Mac Security, Read more…
Tags: fake anti virus, Mac OS X, malware
Stuxnet has received a lot of attention since McAfee first blogged about it in July. This post will answer some of the frequently asked questions we’ve received. Q: What is Stuxnet? A: Stuxnet is a highly complex virus targeting Siemens’ SCADA software. The threat exploits a previously unpatched vulnerability in Siemens SIMATIC WinCC/STEP 7 (CVE-2010-2772) and four Read more…
Tags: critical infrastructure, Stuxnet
McAfee Labs has been monitoring a spam run that was launched earlier today. The message follows: Subject: A very warm invitation to you Body: Hello, Hope your week has been wonderfull well. I would like to extend a very warm invitation to you to the Verbum Dei Missionary Festival this Sunday, September 19. With a lot Read more…
– Latest updates moved to the bottom – McAfee Labs is currently investigating a new threat commonly referred to as the “Here you have” virus due to the email subject line the worm uses during propagation. It looks like multiple variants may be spreading and may take some time to work through them all to Read more…
The Koobface worm has been one of the top malicious threats to Facebook users since 2008. Like most threats, Koobface has morphed over time, adding and changing malicious payloads, while maintaining the ability to propagate, or spread, from one system to another. A common misconception is that viruses often delete files or cause irrevocable system damage. There Read more…
Years ago adware was distributed primarily in two forms. Adware vendors sought out mainstream software vendors to distribute their programs in bundling arrangements. The Adware makers often used a pay-per-install model, paying as much as $1 or more to those responsible for the installation of the ad-delivering components. Often users could opt out of the adware installation. Read more…
A friend of mine forwarded a suspicious email message recently. I’ve replaced the domain, order number, etc. below: —————————- From: Customer Support <support@droa.com> Subject: Order Confirmation for <domain>, Order ###### To <registered domain holder>, Thank you for registering/renewing the following domains with the Domain Registry of America, America’s fastest growing Domain Registrar. We take pride Read more…
Posts by Craig Schmugar