Showing posts with label malicious. Show all posts
Showing posts with label malicious. Show all posts

Tuesday, November 5, 2013

Hidden Administrator !

Android devices have been under attack more so than in previous years. Jay-Z’s Magna Carta Holy Grail Fake App, for example, hides within a pirated copy of the Jay-Z app. If you had this fake application installed on your Samsung device, you suddenly had your background wallpaper image changed to an image of President Barack Obama on July 4th. We also heard of another threat called Master Key that affects all Android users. Master Key allows an attacker to turn any legitimate application into a malicious Trojan horse. The hacker accomplishes this by modifying the APK code without modifying the application’s cryptographic signature.

Recently, another malware threat known as Hidden Administrator Apps has targeted Android users. Hidden Administrator Apps is not an actual name for the malware, but should be viewed more of a category of malware with characteristics that include stealth implementation and elevated user privileges.

A Hidden Device Admin app is an infected application that installs itself with administrator privileges. The app hides itself and you have no means of knowing if this was installed on your device. You can’t remove the app because you simply can’t see it on your screen and you don’t know that it’s there. With administrator privileges, the malware takes complete control of your device and can enable the attacker to utilize it.

How Are Hidden Administrator Apps Installed?

When the malware attempts to install on your device, it will ask you to grant it the elevated privileges. If you’re attentive and deny this request, the malware displays frequent pop-up messages once the device restarts. If you install the infected app, you can attempt to uninstall the app by deactivating its administrator privileges by going to Settings ->Security->Device Administrators. However, this technique may not work all the time because variants of the malware will hide this deactivation option.

How Can You Prevent or Remove Hidden Administrator Apps?

You should always be cautious about the apps you download and install on your device. The malware payload can cause damage to your mobile device, as well as intrude on your privacy and personal information. You can take the following preventive measures for installing Hidden Administrator Apps:

Only download from a reputable app store, such as Google Play or Amazon Appstore.

Glance at app reviews -- People will often rate an infected app poorly and will usually warn others through the app reviews.

Avoid downloading unofficial apps -- It's always safer to install official apps from an official app store.

Keep your mobile device up-to-date -- Ensure you have the latest updates installed on your device.

Don't download pirated software.

If your device is infected with a Hidden Administrator App, you can search Google Play for utilities that can detect the Hidden Administrator App and will remove its elevated privileges. You then can uninstall the app because it will no longer have the administrator rights. A solid solution is McAfee Mobile Security. One of the many features that McAfee Mobile Security provides is Hidden Administrator App detection

Friday, October 11, 2013

Facebook account has just been backed !, What to DO ?

You've just got a text from one of your friends saying that he is wiring some money to your hotel in Paris and that he hopes you are OK. The only problem is that you're not in Paris, you're in Michigan eating Cheetos and watching Judge Judy. Before your orange cheese covered fingers can text him back, you start getting more texts from other concerned friends who also say they are wiring you money ASAP. What the heck is going on?

It looks like your Facebook account has just been backed and the hackers who did it are impersonating you and hitting your friends up for cash. Before things get further out of hand, follow the steps below to bring things back to normal.

If you believe your Facebook account has been hacked:

1. Go to the Facebook Account Compromise Reporting Page

2. Click the "My Account Is Compromised" button

3. On the "Identify Your Account" page, enter either your e-mail address, phone number, Facebook user name, or your name and and the name of one of your friends.

4. Follow the instructions provided to report your account as compromised.

5. Once your account has been reinstated and is back under your control, reset your Facebook password from the Accountt Settings" page by clicking the "Change" link under the "My Account" Password section.

6. From the Facebook Privacy Settings page, click on "Apps and Websites". Under the "Apps You Use" section, click "Edit Settings" and then click on the "X" to delete any suspicious / malicious apps that may have been used to compromise your account.

7. Alert your friends that your account was hacked and warn them not to click on any links that the hackers who compromised your account may have posted on their walls, in chat sessions, or in facebook e-mails that the hackers sent to them.

Tuesday, September 10, 2013

What is Malware?

Protecting your computer from malicious software is perhaps the most important aspect of computer ownership.
A wide range of products are available that offer computer security. However, did you know that certain products only offer protection against a few malicious attacks? Are you concerned that your computer may not be fully secured? Before you take the necessary measures of securing your computer, you should understand the different types of attacks that could harm your machine.
What is Malware?
Malicious software (malware) is the wide range of software applications developed with a malicious intent. The methods used for malware installation is unlike any other software installation you are accustomed to because malware is installed through devious means. People often use the terms virus and malware interchangeably. However, a virus is a type of malware. Other major malware types include:
Virus

A virus contains malicious code that attaches itself to an application. When the infected application is executed, the virus is launched and will attempt to spread to other computers. A virus typically will not cause immediate damage as it needs time to replicate in order to infect other computers. Eventually, the virus will deliver its payload. The payload can cause significant damage such as deletion of critical system files, random reboots of your computer, and can corrupt hard drives and make them unbootable. Viruses are delivered to systems in a variety of ways. Email is the most common method for spreading viruses. For example, spammers will email viruses as attachments and will entice users to download and open the attachment, which in turn will execute the virus. Users can also transmit viruses by using infected USB flash drives. Most operating systems have Autorun enabled, which enable infected USB flash drives to execute the virus as soon as the device is plugged into the machine.


Trojan Horse

Trojan horses trick users by posing as legitimate applications. For example, a Trojan horse may appear to be a game or a screensaver. A deceived user will download the application and the Trojan horse is released once the user executes the program.
Worms

Unlike viruses and Trojan horses, worms do not need to be executed. Worms reside within memory and can travel throughout a network without depending on an infected computer application or interaction. Worms replicate themselves exponentially and can literally crash networks by consuming its bandwidth.

Spyware

Spyware is installed on a machine without the user’s awareness or consent. Spyware attempts to gather specific user information and send it to a third party. You can determine if your computer is infected with spyware if your Internet home page has suddenly changed, if your web browser redirects web searches, or if additional software has been installed on your machine. Another form of spyware is adware. Adware launches pop-up windows to display unwanted advertisements.

Logic Bombs

A logic bomb is malicious code embedded within an application that executes based on certain events. The logic bomb lies dormant until that event occurs. The event may be when a specific date is reached or if an employee’s record is removed from an organization’s payroll information system.
Rootkits

A rootkit is the combination of programs designed to infect your computer without being detected. Your antivirus application communicates with your operating system to identify threats. However, rootkits breaks down this communication process. Consequently, your antivirus software will think that everything is fine and will not report that your computer is infected.

You can find security tools that will protect your computer from the above threats. In most cases, one tool is not enough. You may need to use a combination of utilities to fully project your system. Understanding the major types of malware can help you make informed decisions about acquiring tools to project your computer.