Monday, April 7, 2014

Zeus malware found with valid digital certificate

A recently discovered variant of the Zeus banking Trojan was found to use a legitimate digital signature to avoid detection from Web browsers and anti-virus systems.


Security vendor Comodo reported Thursday finding the variant 200 times while monitoring and analyzing data from users of its Internet security system. The variant includes the digital signature, a rootkit and a data-stealing malware component.

"Malware with a valid digital signature is an extremely dangerous situation," the company said in a blog post.

Zeus is typically distributed through a compromised Web page or through a phishing attack in which cybercriminals send email that appear to come from a major bank.

A sample of the latest Zeus variant tried to trick the recipient into executing it by posing as an Internet Explorer document that included an icon similar to the Windows browser.

Because the file is digitally signed with a valid certificate, it appears trustworthy at first glance, Comodo said. The certificate is issued to "isonet ag."


When executed, the malware downloads the rootkit and a program capable of stealing login credentials, credit card information and other data a person keys into a Web form. The rootkit prevents the malicious files from being deleted by either the computer user or AV software.

Zeus malware typically launches a man-in-the-browser attack when a person visits an online banking site. The malware lets hackers create a remote session where they can see what the victim is doing and secretly intercept all data flowing from the activity.

For example, if the victim transfers funds on a banking site, the payment information will display as usual, but behind the scenes the hackers will alter the transaction and send the money to another account.

Zeus is one of the oldest families of financial malware. Also called Zbot, the malware's source code was leaked on the Internet in 2011, resulting in a surge of customized versions. Among the more popular Zeus-based Trojans are Citadel and GameOver.

In December, Kaspersky Lab discovered a 64-bit version of Zeus, an indication that hackers were preparing for the software industry's move away from older 32-bit architectures.

Tuesday, January 14, 2014

Create strong passwords

 

 Create strong passwords

A strong password is an important protection to help you have safer online transactions. Here are some steps to create a strong password. Consider using some or all to help protect yourself online:
  • Length. Make your passwords at least eight (8) long.
  • Complexity. Include a combination of at least three (3) upper and/or lowercase letters, punctuation, symbols, and numerals. The more variety of characters in your password, the better.
  • Variation. Change your passwords often. Set an automatic reminder to update passwords on your email, banking, and credit card websites every three months.
  • Variety. Don't use the same password for everything. Cyber criminals can steal passwords from websites that have poor security, and then use those same passwords to target more secure environments, such as banking websites.
There are many ways to create a long, complex password. Here are some suggestions that might help you remember it easily:
What to doExample
Start with a sentence or two.Complex passwords are safer.
Remove the spaces between the words in the sentence.Complexpasswordsaresafer.
Turn words into shorthand or intentionally misspell a word.ComplekspasswordsRsafer.
Add length with numbers. Put numbers that are meaningful to you after the sentence.ComplekspasswordsRsafer2013.

More strategies for strong passwords

Test your password with a password checker

A password checker evaluates your password's strength automatically. Try Microsoft's password checker.

Avoid common password pitfalls

Cyber criminals use sophisticated tools that can rapidly decipher passwords.
Avoid creating passwords that use:
  • Dictionary words in any language.
  • Words spelled backwards, common misspellings, and abbreviations.
  • Common letter-to-symbol conversions, such as changing "and" to "&" or "to" to "2".
  • Sequences or repeated characters. Examples: 12345678, 222222, abcdefg, or adjacent letters on your keyboard (qwerty).
  • Personal information that could be guessed or easily discovered. Your name, birthday, driver's license number, passport number, or similar information.