I joined McAfee labs in Jan 2012. I am part of Mcafee - Facebook team and customer escalation team.
Be advised cybercriminals are at it again, leveraging the popularity of Facebook and YouTube to scam consumers.We have seen several scams in the past spreading through Facebook promising of some leaked video of celebrities, or free Facebook T-shirts etc. The malware authors are making money by pay-per-click with these techniques. Users are tricked into clicking Read more…
Tags: Celebrity video in Facebook, Facebook Scam, Facebook Threat, Fake YouTube plugin, Recent Facebook Scam, Recent Facebook threat, scam, Scam Video, Youtube Scam
Malicious worms are found infecting customers through-out the year. They keep evolving to evade the Anti Virus detections. They add junk codes or come up with new custom packer, yet achieve their full functionality and reward their developers. We have seen earlier how different types of malware use chat windows to download and spread across Read more…
Tags: Aishwarya Rai videos, Autorun, Indian Celebrity video, Nuquel, Video of Nayanthara and Simbu, video shot of infosys girl, Worm/Autorun, worm:Win32/Nuquel
We recently came across a Trojan that steals image files of .jpg, .jpeg extensions, and Windows memory dumps (.dmp) from victims’ machines and uploads them to an FTP address hardcoded in the malware. This Trojan silently opens a command line and copies those image files found on the C, D, and E drives to the Read more…
Tags: dmp stealing, Image stealing, image stealing trojan, image theft, images uploaded to FTP, JPEG, jpg, PixSteal Trojan, steganography
This blog was updated on October 15. See the end of this file. We recently received a sample of the malware NGRBot from a customer, who got a spam email with what appears to be a Skype link. Victims are lured into clicking a link that promises an image. Once victims click the link, the Read more…
Tags: Dorgbot Skype, image.exe, malware spread through chat link, malware stealing credentials, malware using skype as spreading vector, ngrbot, pic.exe, Pushbot, Skype malware, skype.exe, Social Engineering tricks by malware
Since the beginning of October we have seen a variant of fake antivirus malware that belongs to the FakeRean family of rogue security products. FakeRean is distributed by drive-by downloads or is dropped and executed by another malware. It blocks victims from accessing any other legitimate application on an infected machine. Like other fake AV Read more…
Tags: Defender 2013, fake-av, FakeRean, Multiplatform FakeAV, MultiRogue, rogue security software, Vista Defender 2013, Win7 Defender 2013, XPDefender 2013
System Progressive Protection, a new malware pretending to be antivirus software, first appeared a couple of days ago. It belongs to the Winwebsec family of rogue security products. The malware is distributed by drive-by downloads or is dropped and executed by another malware. It blocks its victims from accessing any other application on an infected Read more…
Tags: fake security software, fake-av, FAKEAV, Proactive Corporation, rogue antivirus, System Progressive Protection
NGRBot is a worm that propagates through chat messengers, the Internet Relay Chat channel, social networking sites etc. It steals FTP and browser passwords and can cause a denial of service by flooding. NGRBots use the IRC network for file transfer, sending and receiving commands between zombie network machines and the attacker’s IRC server, and Read more…
Tags: botnet, C&C command bot, IRC bot, malware spread through chat link, ngrbot
Update from Facebook: The Facebook security team been actively tracking this botnet and providing McAfee AV to the victims (via Scan and Repair) The sample covered is out of date, and the malware now works differently Any users infected with this malware should be pointed to the McAfee self-checkpoint on.fb.me/InfectedMcA [Original Post] Malware authors Read more…
Posts by Niranjan Jayanand