Cisco Learning Network Store Promotions Page
Showing posts with label Symantec. Show all posts
Showing posts with label Symantec. Show all posts

1.14.2016

Updated Android.Bankosy malware steals passwords sent through voice calls

Around a year and a half ago, Symantec warned about the personal data stealing malware Android.Bankosy. Now the Trojan has been updated so it can steal passwords delivered via voice call-based two-factor authorization systems.
  
Such 2FA systems are is often used by banks to communicate one-time passcodes to people. While these have usually been delivered via SMS, voice call delivery is becoming increasingly common. Malware makers are keen not to miss out on data stealing opportunities, and the Android.Bankosy introduces a call-forwarding feature that sends 2FA calls to a C&C server so the code can be intercepted and exploited.
  
The malware enables call-forwarding on an infected phone, and is also able to enable silent mode to avoid alerting a victim about incoming calls. A successful attack is dependent on a victim's basic login credentials having already been stolen, but the malware represents a worrying new development in breaking through banking security.
Detailing how Android.Bankosy works, Symantec's Dinesh Venkatesan says:
Once the malware is installed on the victim's device, it opens a back door, collects a list of system-specific information, and sends it to the command and control (C&C) server to register the device and then get a unique identifier for the infected device. If the registration is successful, it uses the received unique identifier to further communicate with the C&C server and receive commands.
Most of the commands supported by the malware are common and trivial for typical back door or financial Trojans, such as intercepting incoming SMS, deleting SMS messages, wiping the data, etc. Out of these multiple commands, the most relevant for Android.Bankosy is call_forwarding; when this command is received by the malware from the C&C server, it executes a payload to enable call forwarding.
 
Full details of the malware is available from Symantec.
 
Photo credit: Mmaxer / Shutterstock

~ Mark Wilson

7.10.2015

Hackers of Apple, Facebook seen as independent group seeking money

A man types on a computer keyboard in Warsaw in this February 28, 2013 illustration file photo.        





























7.01.2013

Facebook Android App Found Collecting Phone Numbers Without User Consent

Next update to fix the issue

Faced with allegations of complicity in the furtive Prism surveillance program earlier this month, Facebook strongly denied being part of any such program and vowed to keep “fighting aggressively to keep your information safe and secure.” Well, its Android app tells a different story.
 
The latest version of Symantec’s Norton Mobile Security tool came out on Wednesday and got down to work straight away, flagging the Facebook app as being a privacy risk. According to the security company, the new Mobile Insight technology contained in the security app caught the Facebook Android app calling home to send the user’s phone number. What’s more alarming is the fact that this is something the app does right off the bat, without even waiting for the user to log in.
 
“The first time you launch the Facebook application, even before logging in, your phone number will be sent over the Internet to Facebook servers,” Symantec said in a blog post. “You do not need to provide your phone number, log in, initiate a specific action, or even need a Facebook account for this to happen.”
 
On being confronted on the issue by Symantec, Facebook promised to fix the issue in the next update (already in beta, thankfully). Further, it denied using or processing the phone numbers in anyway, adding that they have now been deleted from its servers.
 
~ Pulkit Chandna