Tuesday, November 6, 2012

Chain Letters: Insulting Your Intelligence

 
Electronic chain letters are emails that urge you to forward copies to other people. Chain letters, like virus hoaxes, depend on you, rather than on computer code, to propagate them.
A typical chain letter consists of a message that attempts to induce the recipient to make a number of copies of the letter and then pass them on to as many recipients as possible.

Common chain letters examples
  • Hotmail is going under maintenance and accounts that doesn’t pass this message are deleted within 24 hours, pass this message to your friends and people you care about, this is not a joke
  • Send this email to 5 friends and something good will happen to you, send it to 10 something even better will happen, send it to 20 friends and ..............., Ignore this message and you will die painfully.
  • Little Rosanna is 9 years old and is suffering from an acute and very rare case of the stupidontitus. This condition causes severe pain and terminal illness. The doctor has given her 6 month to live. But she can be saved using a very costly procedure. Nasa, Nato, UN, and Barcelona Football Club have decided to donate 3 cents for every new person that gets this email.........  
  • Beware of the new computer virus, JBm01.02 aka ComputerEater, don’t open the email with subject: “Contact me, I’m your Mother” for it will download an infected file that will erase all your email messages..... Send this message to your friends and family. Help them save their messages.
Even On Mobile Phones
  • Starting next month WhatsApp will start charging the amount of 5 usd / month for its service. Forward this message to your friends including me..........
  • RIM servers are getting overloaded and the blackberry service is delayed, therefore if you don’t forward this message to at least 7 of your contacts, there is a big chance that your BBM will stop working and you will lose your contact list.
 Chain letters don’t threaten your information security, but they can waste time, spread misinformation and distract users from genuine emails, they also create unnecessary email traffic and slow down mail servers.
Since hoaxes aren’t malware, your antivirus and endpoint security software can’t detect or disable them.

How to Spot Chain letters
  • Look for the phrase: 'Forward this to everyone you know”
  • The more urgent the request, the more you should suspect the message.
  • Usage of “forward this message to everyone even back to me”, to give the reader the false sense of trust.
  • Look for the statement: “this is not a spam” or “This is not an urban legend”
  • When in doubt Google the subject matter of your received message and you will get a better clue about the message.  
  • If the email writer is attributing the text to a 'legitimate' source or implying that powerful corporate is going to take certain action if you don’t forward the email.
  • Watch for emphatic language, the improper use of UPPERCASE letters, and the multiple uses of exclamation points.

Finally, Read carefully and think rationally about what the message is stating, looking for logical inconsistencies, violations of common sense and false claims.  

Monday, October 22, 2012

The Story Continues: MiniFlame



Early July 2012, a smaller Flame module was discovered. This module had many similarities with Flame, so at the beginning it was believed that it might simply be an earlier version or the Flame malware. Few months later, it was found that not only there exists a connection between this malware and Flame, but also came across examples of this module being used concurrently with Gauss and being controlled by the Gauss main module.
Unlike Flame, which is designed for "massive spy operations," miniFlame is "a high precision, surgical attack tool,"
Researchers found that MiniFlame was something of super stealth assassin compared to the other programs. Whereas Flame, Duqu and Gauss had large missions to infiltrate multiple computers in countries like Iran, Syria and Lebanon, MiniFlame targeted just a few select victims in what Kaspersky calls “highly targeted attacks.” Kaspersky reported that MiniFlame, while rare compared to the more well-known malware packages, was more likely to show up in a variety of countries, including a computer located at the Francois Rabelais University in Tours, France.
Kaspersky Lab data indicates the total number of infections worldwide is just 50 to 60, including computers in Lebanon, France, the United States, Iran and Lithuania. "Most likely it is a targeted cyber weapon used in what can be defined as the second wave of a cyber attack."

Kaspersky determined that one machine in Lebanon is the lucky recipient of every nasty cyber weapon in the family:
There is one machine in Lebanon – what senior Kaspersky researcher Roel Schouwenberg calls “the mother of all infections” – which has Flame, Gauss, and miniFlame/SPE on it. “It is like everybody wanted to infect that specific victim in Lebanon for some reason,” he says.
Th Russian antivirus company believes that there are two more malware packages still in the wild, currently code-named only SP and IP. They may function much like the previously known malicious programs, churning through the guts of target computers for sensitive data to send home to their controllers before they execute the final trick in their arsenal, deleting themselves and vanishing from the infected system as if they’d never been there at all.

MiniFlame operates "as a backdoor designed for data theft and direct access to infected systems," which said development of the malware might have started as early as 2007 and continued until the end of 2011, with several variations.

Finally:  to protect yourself
1- Make sure that your anti virus definitions are up to date. 
(I assume that you already use an antivirus.)
2- Continuously monitor all the PCs you use for the Trojan "win32.Gauss" 
3- Refrain from Using the Option "Save Password" that stores your credentials within web browsers.
4- Keep your Operating System Up to date. 
5- Change your Password using a trusted clean, in case you doubt that your PC is or was compromised by Gauss or any other Virus.
6- Exercise cautious when using external storage devices (CDs, USBs), in order to limit the propagation of the Gauss or any other infection.
           
More info on Securelist.com