Clever Billing Fraud Applications on Google Play: Etinu

A new wave of fraudulent apps has made its way to the Google Play store, targeting Android users in Southwest Asia and the Arabian Peninsula as well—to the tune of more than 700,000 downloads before detection by McAfee Mobile Research and co-operation with Google to remove the apps.

Figure 1. Infected Apps on Google Play

Posing as photo editors, wallpapers, puzzles, keyboard skins, and other camera-related apps, the malware embedded in these fraudulent apps hijack SMS message notifications and then make unauthorized purchases. While apps go through a review process to ensure that they are legitimate, these fraudulent apps made their way into the store by submitting a clean version of the app for review and then introducing the malicious code via updates to the app later.

Figure 2. Negative reviews on Google Play

McAfee Mobile Security detects this threat as Android/Etinu and alerts mobile users if they are present. The McAfee Mobile Research team continues to monitor this threat and is likewise continuing its co-operation with Google to remove these and other malicious applications on Google Play.

Technical analysis

In terms of details, the malware embedded in these apps takes advantage of dynamic code loading. Encrypted payloads of malware appear in the assets folder associated with the app, using names such as “cache.bin,” “settings.bin,” “data.droid,” or seemingly innocuous “.png” files, as illustrated below.

Figure 3. Encrypted resource sneaked into the assets folder

Figure 4. Decryption flow

The figure above shows the decryption flow. Firstly, the hidden malicious code in the main .apk opens “1.png” file in the assets folder, decrypts it to “loader.dex,” and then loads the dropped .dex. The “1.png” is encrypted using RC4 with the package name as the key. The first payload creates HTTP POST request to the C2 server.

Interestingly, this malware uses key management servers. It requests keys from the servers for the AES encrypted second payload, “2.png”. And the server returns the key as the “s” value of JSON. Also, this malware has self-update function. When the server responds “URL” value, the content in the URL is used instead of “2.png”. However, servers do not always respond to the request or return the secret key.

Figure 5. Updated payload response

As always, the most malicious functions reveal themselves in the final stage. The malware hijacks the Notification Listener to steal incoming SMS messages like Android Joker malware does, without the SMS read permission. Like a chain system, the malware then passes the notification object to the final stage. When the notification has arisen from the default SMS package, the message is finally sent out using WebView JavaScript Interface.

Figure 6. Notification delivery flow

As a result of our additional investigation on C2 servers, following information was found, including carrier, phone number, SMS message, IP address, country, network status, and so forth—along with auto-renewing subscriptions:

Figure 7. Leaked data

Further threats like these to come?

We expect that threats which take advantage of Notification Listener will continue to flourish. The McAfee Mobile Research team continues to monitor these threats and protect customers by analyzing potential malware and working with app stores to remove it. Further, using McAfee Mobile Security can detect such threats and protect you from them via its regular updates. However, it’s important to pay attention to apps that request SMS-related permissions and Notification Listener permissions. Simply put, legitimate photo and wallpaper apps simply won’t ask for those because they’re not necessary for such apps to run. If a request seems suspicious, don’t allow it.

Technical Data and IOCs

MITRE ATT&CK Matrix

IoCs

08C4F705D5A7C9DC7C05EDEE3FCAD12F345A6EE6832D54B758E57394292BA651 com.studio.keypaper2021
CC2DEFEF5A14F9B4B9F27CC9F5BBB0D2FC8A729A2F4EBA20010E81A362D5560C com.pip.editor.camera
007587C4A84D18592BF4EF7AD828D5AAA7D50CADBBF8B0892590DB48CCA7487E org.my.favorites.up.keypaper
08FA33BC138FE4835C15E45D1C1D5A81094E156EEF28D02EA8910D5F8E44D4B8 com.super.color.hairdryer
9E688A36F02DD1B1A9AE4A5C94C1335B14D1B0B1C8901EC8C986B4390E95E760 com.ce1ab3.app.photo.editor
018B705E8577F065AC6F0EDE5A8A1622820B6AEAC77D0284852CEAECF8D8460C com.hit.camera.pip
0E2ACCFA47B782B062CC324704C1F999796F5045D9753423CF7238FE4CABBFA8 com.daynight.keyboard.wallpaper
50D498755486D3739BE5D2292A51C7C3D0ADA6D1A37C89B669A601A324794B06 com.super.star.ringtones

URLs

d37i64jgpubcy4.cloudfront.net

d1ag96m0hzoks5.cloudfront.net

dospxvsfnk8s8.cloudfront.net

d45wejayb5ly8.cloudfront.net

d3u41fvcv6mjph.cloudfront.net

d3puvb2n8wcn2r.cloudfront.net

d8fkjd2z9mouq.cloudfront.net

d22g8hm4svq46j.cloudfront.net

d3i3wvt6f8lwyr.cloudfront.net

d1w5drh895wnkz.cloudfront.net

The post Clever Billing Fraud Applications on Google Play: Etinu appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

McAfee VP Shares His Four Pledges for a Healthier Lifestyle

After experiencing a health scare that changed his life, VP of Technology Services, Paul, vowed to make incremental changes by incorporating four important health pledges into his daily routine.

Hear Paul’s life-changing story, how his diagnosis impacted his outlook on prioritizing his physical and mental health, and how he describes McAfee’s role in empowering him and others to follow their own wellness goals.

“To the leadership team and colleagues around me, thank you for giving me the time, space and flexibility to recover. The fact that we can 100% check out and focus on our wellbeing is paramount. At McAfee, that’s in our culture and our spirit.”


Here are Paul’s recommendations of four daily practices that every person can incorporate daily into their busy schedules.

Get up and Walk
Plan for virtual 1:1 walking meetings with your team, it allows you to stay active even on the busiest days.

Hydrate
Keep a cannister of ice, cold water at your desk so that you can stay hydrated throughout the workday.

Takes Breaks
Take mental breaks and intentionally unplug. Spend time away from your electronic devices by avoiding emails or going on chat.

Stand Up
It can be easy to sit at your desk all day. This doesn’t benefit your health. Instead, stand up and find ways to move.

At McAfee, we believe that your mental and physical wellbeing is a top priority. That’s why we encourage team members to take the time they need to reset, recharge, and care for their health. Between our paid holidays, unlimited vacation policy in the U.S., and leave policy, we enable our team to balance work with life’s responsibilities. We know that the key to living our best lives at and away from the office starts with focusing on wellbeing.

Want to work for a company that encourages team members to prioritize their health and wellbeing? Check out McAfee’s Latest Career Opportunities. Subscribe to Job Alerts.

Stay Connected
For more stories like this, follow @LifeAtMcAfee on Instagram and  @McAfee on Twitter to see what working at McAfee is all about. 

Search Career Opportunities with McAfee
Interested in joining our team? We’re hiring!  Apply now.

 

 

The post McAfee VP Shares His Four Pledges for a Healthier Lifestyle appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

McAfee Awarded “Cybersecurity Excellent Awards”

In a year where people relied on their digital lives more than ever before and a dramatic uptick in attacks quickly followed, McAfee’s protection stood strong. 

We’re proud to announce several awards from independent third-party labs, which recognized our products, protection, and the people behind them over the course of last year. 

Recognized four times over for our people and products 

The Cybersecurity Excellence Awards is an annual competition honoring individuals and companies that demonstrate excellence, innovation, and leadership in information security. We were honored with four awards: 

  • As a company, we were recognized as the Gold Winner for the Best Cybersecurity Company in North America in a business with 5,000 to 9,999 employees. 
  • For security software, McAfee LiveSafe was presented with the Gold Winner for AntiVirus, which also includes further controls for privacy and identity protection, along with a renewed focus on making it easy for people to protect themselves while learning about security in the process.  
  • McAfee Secure Home Platform, our connected home security that provides built-in security for all the connected devices in your home, was the Gold Winner for Cybersecurity for Connected Homes in North America. 
  • Our leadership was recognized as well, with our SVP of Consumer Marketing, Judith Bitterli being named the Silver Winner for the Cybersecurity Marketer of the Year in North America. This award acknowledges her contributions to McAfee’s marketing strategy and growth, along with her “Safer Together” program that offered support to people as they shifted to schooling, telehealth, dating, and job hunting from home during the pandemic. 

Awards for McAfee product development and product performance 

Further recognition came by way of three independent labs known for their testing and evaluation of security products. Once more, this garnered several honors:  

  • McAfee was named a winner of SE Labs’ second annual Best Product Development award, which evaluates security solutions by “testing like hackers.” More formally, they base their awards on “a combination of continual public testing, private assessments and feedback from corporate clients who use SE Labs to help choose security products and services.” 
  • Germany-based AV-Test named McAfee Total Protection the winner for its Windows Best Performance for Home Users category. Likewise, it also scored a perfect 18 out of 18 in categories spanning, Protection, Performance, and Usability in its most recently published testing (for February 2021). 
  • AV-Comparatives named McAfee Total Protection the Silver Winner for Performance and gave McAfee three Advanced+ and two Advanced Awards in the year’s tests overallstating that, “Its user interface is clean, modern, and touch-friendly. The program’s status alerts are exemplary.” 

Continuous updates keep you protected with the latest advances 

As the threat landscape continues to evolve, our products do as well. We’re continually updating them with new features and enhancements, which our subscribers receive as part of automatic product updates. So, if you bought your product one or two years agoknow that you’re still getting the latest award-winning protection with your subscription. 

We’d like to acknowledge your part in these awards as well. None of this is possible without the trust you place in us and our products. With the changes in our work, lifestyles, and learning that beset millions of us this past year, your protection and your feeling of security remain our top priority. 

With that, as always, thank you for selecting us. 

Stay Updated  

To stay updated on all things McAfee and on top of the latest consumer and mobile security threats, follow @McAfee_Home  on Twitter, subscribe to our email, listen to our podcast Hackable?, and ‘Like’ us on Facebook. 

The post McAfee Awarded “Cybersecurity Excellent Awards” appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Indicts SecondEye Operators

US Indicts SecondEye Operators

The United States has indicted two Pakistani men on suspicion of operating an illegal online store that sold false identification documents on the dark web. 

Karachi residents 34-year-old Mohsin Raza and 33-year-old Mujtaba Raza were charged in a six-count federal indictment unsealed in the District of New Jersey on April 15. 

Each man is charged with conspiracy to produce and trade in false identification documents, three counts of transferring false identification documents, one count of false use of a passport, and one count of aggravated identity theft.

In 2011, the defendants allegedly set up a fraudulent e-commerce business in Karachi named at various times “SecondEye Solution” and “Forwarderz” through which they electronically produced, sold, and transferred digital versions of false documents, including government-issued ID.

According to the indictment, the business was highly lucrative, with the defendants making over $1.5m in Bitcoin transfers alone from more than 20,000 separate transactions.

The defendants allegedly advertised SecondEye’s services on at least one well-known dark net forum, claiming that customers could buy forged documents and use them to restore lost access to online accounts. 

According to the indictment, “SecondEye customers used the false SecondEye documents to defraud payment processing companies, e-commerce businesses, social media, and social networking platforms, and virtual currency exchanges, both foreign and domestic, by gaining unauthorized access to online platforms provided by such entities, often to gain access to customer accounts that previously had been revoked or suspended.”

It is further alleged that false documents created by SecondEye were used by a Russian organization accused of meddling in America’s 2016 presidential election.

“Between May 11, 2017, and September 16, 2017, a member of the Internet Research Agency LLC, a Russian organization that engaged in operations to interfere with elections and political processes, including the 2016 US presidential election, purchased multiple false identification documents from SecondEye in the names of real and fictitious US persons,” stated the Department of Justice.

“The false identification documents were later used as supporting documents for accounts previously operated by the Internet Research Agency at a social media company.”

Mohsin Raza, aka “Mohsin Raza Amiri,” and Mujtaba Raza, aka “Mujtaba Ali Lilani,” “Mujtaba Ali,” and “Mujtaba,” are currently at large. Their names have been added to the FBI’s White Collar Crimes Most Wanted website. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Issues Russian SVR Warning

US Issues Russian SVR Warning

America has issued a cybersecurity advisory that urges organizations to patch vulnerabilities it says are being exploited by Russian Foreign Intelligence Service (SVR) actors.

The warning was jointly issued on April 15 by the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the Federal Bureau of Investigation (FBI), as the US announced new sanctions against Russia.

Titled “Russian SVR Targets US and Allied Networks,” the advisory lists five publicly known vulnerabilities and calls for network defenders to act quickly to “prevent future loss of sensitive information.”

The vulnerabilities the United States says are being exploited by SVR are CVE-2018-13379 Fortinet FortiGate VPN, CVE-2019-9670 Synacor Zimbra Collaboration Suite, CVE-2019-11510 Pulse Secure Pulse Connect Secure VPN, CVE-2019-19781 Citrix Application Delivery Controller and Gateway, and CVE-2020-4006 VMware Workspace ONE Access.

“This advisory is being released alongside the US Government’s formal attribution of the SolarWinds supply chain compromise and related cyber espionage campaign,” stated the NSA.

“We are publishing this product to highlight additional tactics, techniques, and procedures being used by SVR so that network defenders can take action to mitigate against them.”

The agency said that the SVR actors, also known as APT29Cozy Bear, and The Dukes, are exploiting the vulnerabilities in an effort to gain access by obtaining authentication credentials.

“Mitigation against these vulnerabilities is critically important as US and allied networks are constantly scanned, targeted, and exploited by Russian state-sponsored cyber actors,” warned the NSA. 

“In addition to compromising the SolarWinds Orion software supply chain, recent SVR activities include targeting COVID-19 research facilities via WellMess malware and targeting networks through the VMware vulnerability disclosed by NSA.”

Commenting on the advisory, K2 Cyber Security co-founder and CTO Jayant Shukla said: “The easiest way to secure an organization is to keep software up to date and patched.”

He added: “Unfortunately, patching often takes organizations a significant amount of time due to testing and compliance requirements, so the sooner they can start the process the better off they will be. 

“For those applications that can be protected during runtime with newer technologies like virtual patching, organizations should implement solutions to keep these vulnerabilities from being exploited.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Keyfactor to Merge with PrimeKey

Keyfactor to Merge with PrimeKey

Ohio PKI-as-a-Service pioneer Keyfactor and Swedish PKI solutions provider PrimeKey have announced their intention to merge.

Plans for the companies to come together under the Keyfactor brand “while committing to increased investments across all product lines” were shared on April 15. 

PrimeKey was established 19 years ago by the company’s CTO, Tomas Gustavsson, who developed an interest in computer code as a child. Today the company works with partners and customers across six continents from its headquarters in Solna, Stockholm. 

Describing how the merger would benefit customers, PrimeKey CEO Magnus Svenningson said: “Our combined solutions now give customers unparalleled deployment choices including PKI-as-a-Service, SaaS PKI (Azure, AWS, GCP), software appliance or FIPS 140–certified hardware.

“These flexible deployment options give our customers the control to operate a single pane of glass across all their machine identities in hybrid and multi-cloud environments.”

Open source software developed by PrimeKey will not be closed following the deal, which is expected to be finalized after the Swedish government approves the merger from a national security perspective.

Svenningson said: “Our EJBCA, SignServer and Bouncy Castle solutions are widely adopted by the developer community to integrate security in DevSecOps workflows and will remain open source as we continue to bring cutting-edge innovations to our enterprise customers.”

Under the terms of the merger, Svenningson will assume the roles of executive vice president (EVP) of business development and chief strategy officer (CSO) while Keyfactor’s Jordan Rackie will remain at the helm as CEO.

“The merger with PrimeKey amplifies the performance of the combined businesses across product offerings, distribution channels, expertise for our customers and large open source communities,” said Rackie. 

The CEO attributed Keyfactor’s 50% year-over-year growth to industry’s need to prevent loss of brand reputation, business outages, and fines by proactively securing the identity of every machine before disaster strikes. 

Rackie said: “Now more than ever, enterprises must operate in a zero-trust world, and machine identity management can no longer be ignored as part of an identity and access management (IAM) strategy.” 

The transaction is expected to close within the next 90 days.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Mass Monitoring of Remote Workers Drives Shadow IT Risk

Mass Monitoring of Remote Workers Drives Shadow IT Risk

Nearly half (44%) of UK remote workers have had monitoring software installed by their employer, but the trend is pushing many into more insecure practices, Kaspersky has warned.

Around a year after the pandemic forced a majority of UK employees to work-from-home, the Russian AV vendor polled 2000 full-time staff to understand levels of trust among managers and employees.

Monitoring software can be an important bulwark against non-compliant and risky user behavior, especially given the large percentage of incidents that are caused by human error. Kaspersky cited monitoring of email, internet, app and phone usage as well as location tracking as increasingly common for employers to deploy on remote endpoints.

However, a third (32%) of workers polled for the study said that the use of monitoring tools would make them less trusting of their manager or team leader, and a similar number (30%) said they would be upset at the invasion of their privacy. Around a quarter (23%) said they would be concerned about potential access to their personal information via this software.

Yet even the perception that they are being watched may ironically force remote workers into more risky online behavior.

A quarter (24%) of employees polled said they use personal devices to avoid being spied on, while almost one-third (31%) said they would be likely to do so more often for work if they knew they were being monitored.

Some said they would raise a formal complaint with an independent body (26%), or even leave their current job (24%) if they found out they were being monitored.

Kaspersky principal security researcher warned that if organizations’ risk management of remote workers goes too far, there could be damaging consequences.

“Employees working on their own devices creates shadow IT, which presents an immense risk to businesses. With more than 90% of all cyber breaches caused by human error, companies must have complete oversight of how their IT systems and hardware are being used by remote workforces, and so must carefully balance their monitoring activities,” he argued.

“Without knowing what devices are potentially in contact with a business’s data systems, IT and cybersecurity teams have great difficulty anticipating how company data can be potentially compromised, sold on, or even held for ransom.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Google to Delay Publishing Bug Details for 30 Days

Google to Delay Publishing Bug Details for 30 Days

Google has added an extra 30-day period to its vulnerability disclosure cycle to allow customers more time to fix vulnerabilities before technical details are released.

The tech giant’s Project Zero team is a prolific researcher of industry vulnerabilities, and maintains a strict 90-day policy of public vulnerability disclosure after vendor notification, in order to pressure firms to issue patches quicker.

“In practice however, we didn’t observe a significant shift in patch development timelines,” explained manager Tim Willis yesterday. “And we continued to receive feedback from vendors that they were concerned about publicly releasing technical details about vulnerabilities and exploits before most users had installed the patch. In other words, the implied timeline for patch adoption wasn’t clearly understood.”

The extra 30-day grace period before details are released will apply only to bugs that are fixed within the initial 90-day period. If an issue remains unpatched after 90 days, technical details are published immediately.

Google also added the 30-day period to patches for bugs being actively exploited in-the-wild against users. If an issue remains unpatched after seven days, technical details are published immediately, but if it’s fixed within a week, those details will now be published 30 days after the patch.

Willis maintained that early release of the details surrounding each bug ultimately benefits the defensive community and helps protect users, but he acknowledged that it also risks inviting opportunistic attacks.

“Moving to a ‘90+30’ model allows us to decouple time to patch from patch adoption time, reduce the contentious debate around attacker/defender trade-offs and the sharing of technical details, while advocating to reduce the amount of time that end users are vulnerable to known attacks,” he concluded.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Trickbot Actors Target Slack and BaseCamp Users

Trickbot Actors Target Slack and BaseCamp Users

The threat actors behind the infamous Trickbot botnet have been at work again, firing highly customized phishing emails targeting Slack and BaseCamp users with loader malware, according to Sophos.

The British security vendor’s principal researcher, Andrew Brandt, explained that the campaign first appeared in January.

Malicious emails contained links to malware payloads hosted on the cloud storage services provided by popular collaboration tools like Slack.

“The emails also inserted the names of both the recipient and their employer into the messages, in an attempt to convince their enterprise recipients to download and execute the Trojan payloads temporarily hosted in those legitimate websites,” Brandt explained.

“When a target was convinced to open the documents tied to the spam email, their computer quickly became infected with BazarLoader, which itself acts primarily as a delivery mechanism for other malware. With a focus on targets in large enterprises, BazarLoader could potentially be used to mount a subsequent ransomware attack.”

Sophos also detected a second, more convoluted, campaign from the same actors, dubbed “BazarCall.” The spam message claims that the recipient’s free trial is ending and gives them a number to call in order to avoid paying for a renewal.

“In this later form of attack, only people who called the telephone number were given a URL, and instructed to visit the website where they could unsubscribe from these notifications,” said Brandt.

“The well-designed and professional looking websites bury an ‘unsubscribe’ button in a page of frequently asked questions. Clicking that button delivers a malicious Office document (either a Word doc or an Excel spreadsheet) that, when opened, infects the computer with the same BazarLoader malware.”

Sophos tied the campaigns to Trickbot via shared command and control (C2) infrastructure and the method of injecting malicious payloads into running processes, which it said it similar to Trickbot’s “injectDLL” module.

Although not as sophisticated as Trickbot, the BazarLoader malware appears to be in development and could be a new way for the gang to target high-value businesses going forward, Sophos said.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk