A massive computer shutdown of two South Korean banks and media companies occurred Wednesday via an Internet malware attack. The malware wiped out the master boot records on the hard drives of the infected computers, overwriting the MBR with either one of these strings: PRINCPES PR!NCPES HASTATI. Figure 1: Snapshot of MBR after infection. The Read more…
Tags: banks, malware, MBR, media, South Korea, targeted attack, Unix
Microsoft has issued Security Advisory 2718704, in which the company disclosed that it recently became aware of the Flamer/Skywiper threat, which uses certificates derived from the Microsoft Certificate Authority. The actual certificate in question was used to sign at least one of the attack components associated with the module in the Skywiper framework. This is Read more…
Tags: CA, certificate authority, Flame, Flamer, SkyWiper, worm
There has been quite a bit of analysis and speculation about the Flamer/Skywiper threat. As we started to analyze this threat, we knew from the very beginning that this was going to be a giant undertaking and potentially very long term. Now we want to pause to help the people we protect visualize the kind Read more…
Tags: advanced persistent threats, antivirus, APT, critical infrastructure, Cybercrime, Data Protection, enterprise, Flamer, global threat intelligence, Identity thieves and cybercriminals, labs, malware, McAfee, McAfee Labs, Mobile, mobile security, Network Security, SkyWiper, social networking
A few weeks ago, Iran reported intensified cyberattacks on its energy sector that they observed as a direct continuation of the Stuxnet and Duqu attacks. Over the weekend, the IR Cert (Iran’s emergency response team) published a new report that describes this attack as Flame and/or Flamer. Some other news agencies also called the attack Read more…
Tags: Advanced Persistent Threat, antivirus, APT, Cybercrime, cyberespionage, cyberwarfare, espionage, global threat intelligence, malware, McAfee Labs, targeted attack
We discussed much of the unfolding Duqu attack in our previous post. Some new light has recently illuminated some missing pieces to this interesting attack. Researchers at CrySys Labs in Hungary have disclosed information about a Word document that is purported to be the installer file for the Duqu attacks. The document loads a kernel Read more…
Tags: Duqu, Kernel 0day vulnerability, Stuxnet, Zero-Day
Stuxnet was possibly the most complex attack of this decade, and we expected that similar attacks would appear in the near future. One thing for sure is that the Stuxnet team is still active–as recent evidence has revealed. McAfee Labs received a kit from an independent team of researchers that is closely related to the Read more…
Tags: Cybercrime, data breach, global threat intelligence, Identity thieves and cybercriminals, malware
Today we’re going to take a look at an interesting file-infector virus. W32/Ramnit infects EXE, DLL and HTML files. That last one is right; W32/Ramnit also infects HTML files to replicate itself. Let’s start with the components of this thread. W32/Ramnit has basically three components. The infector, the infected code in EXE/DLL files, and the Read more…
As McAfee Labs predicted in a previous blog post regarding the Microsoft Windows Shell .LNK vulnerability, it was just a matter of time before malware started using Exploit-CVE2010-2568 to take advantage of this new Microsoft zero-day flaw. The flaw is described in CVE-2010-2568. First, there was talk about PWS-Zbot (a.k.a. Zeus) using the vulnerability in Read more…
As we know, the recent Operation Aurora has been making waves due to a highly organized attack targeting companies such as Google, Adobe and other high profile companies. A security breach due to a vulnerability in Microsoft’s Internet Explorer, CVE-2010-0249, caused remote code execution leading to download of malware on compromised systems. At McAfee Labs, Read more…
Tags: malware
With the current news about the deaths of Farrah Fawcett and Michael Jackson, it’s a good idea to remind our readers to beware of blackhat attempts to distribute malware to anyone looking for news. Â Every time a disaster happens or news about some celebrity reaches the media, malware writers try to take advantage of Read more…
Posts by Guilherme Venere