Pages

Showing posts with label Malware. Show all posts
Showing posts with label Malware. Show all posts

Friday, 24 April 2015

Report: One in Five Android Apps Is Malware

Report: One in Five Android Apps Is Malware
(Thinkstock)
Bad news, phandroids. Android malware is on the rise.
According to Symantec’s latest Internet Security Threat Report, “17 percent of all Android apps (nearly one million total) were actually malware in disguise.” In 2013, Symantec uncovered roughly 700,000 virus-laden apps.
More than one third of all apps were what Symatec calls “madware,” or mobile software whose primary purpose is to bombard you with ads. The company also discovered the first example of mobile crypto-ransomware – software that encrypts your data and holds it hostage until you pay ransom for it – for Android devices.
symantec norton internet threat security report
(Norton Mobile Insights)

How to stay safe

The good news is that it’s pretty easy to avoid infection if you obtain your apps from a trusted source, like the Google Play Store. The company doesn’t break out how many of the 1 million+ malware apps were found in the Play Store, but Symantec’s Director of Security Response Kevin Haley admits the number is probably quite low.
“Google does a good job of keeping malware out of the Store,” Haley says. “And if a malicious app does make it in there, they do a good job of finding it and getting rid of it.”
On the other hand, if you visit alternate Android app markets, download apps from app maker’s Websites, get them via email links, or find them on Bit Torrent sites, you run a much greater risk of infecting your phone, he adds.

Other App Stores

Symantec used its Norton Mobile Insight software to crawl more than 200 Android app stores, downloading and analyzing more than 50,000 apps and app updates each day in 2014.
Most of the malware found by Symantec tries to steal personal data like phone numbers and contact lists, which are then sold on the Internet’s black market, says Haley. Some may cause your phone to send text messages to premium SMS services, automatically adding charges to your monthly bill. Other apps may pelt you with ads that pop up randomly over other applications. Some apps even change your default ringtone to an advertisement, Haley says.
The Android malware problem is greater overseas, especially in regions where users can’t access Google Play and must rely on third-party app marketplaces.
image
Mobango is one of hundreds of alternate Android app marketplaces in the wild. Be careful out there. (Mobango.com)
If you see unusual charges on your bill for premium texting services or ads start popping up where you don’t expect them, those are good signs you’ve got an infection, he adds. Your best recourse is to use a mobile security app to scan and protect your phone.
As for iOS? Symantec found a grand total of 3 infected apps in the iTunes store in 2014. Last year it found zero.
“One of the benefits of Android versus iOS is that it gives you a lot more freedom as to where you can download apps,” Haley says. “But that freedom comes with a cost.”

Thursday, 12 June 2014

Malwarebytes: With Anti-Exploit, we'll stop the worst attacks on PCs

20140610-malwarebytes-marcin-pedro.jpg
Malwarebytes's director of special projects, Pedro Bustamante (left), and CEO Marcin Kleczynski, think they've got a way to stop exploits on Windows.Seth Rosenblatt/CNET
Imagine a world of Windows computer security where the latest zero-day exploits that seek to gain access to your computer are rendered ineffective before they can be used against you.
That world doesn't exist yet, but it took a giant step closer to reality with Malwarebytes Anti-Exploit, a new Windows security program released Thursday. It's powered by exploit-blocking technology that Malwarebytes acquired last year when it bought ZeroVulnerabilityLabs.
The free version of Anti-Exploit will protect against exploits in browsers, their add-ons, and Java, while the $24.95 premium version will also work in Microsoft Office, PDF readers, media players, and software selected by the owner. Anti-Exploit for Business works in conjunction with the Malwarebytes Management Console for enterprise deployment.
Anti-Exploit is "not about the product. It's about the problem," Kleczynski said during an interview at Malwarebyte's office in San Jose, Calif. "Sometimes it catches the exploit so early we can't show the alert" that it has stopped an exploit.Malwarebytes CEO and founder Marcin Kleczynski said that businesses will want to invest in Anti-Exploit as an extra layer of protection against the kinds of exploits that have been part of the major hacks of late.
If it works as advertised, Malwarebytes Anti-Exploit would be remarkable for preventing zero-day vulnerabilities -- previously unknown, unpatched software flaws -- from being exploited to steal data or gain control of your computer. Exploits that launch malicious code on your computer, known as remote code execution, combined with zero-days have been successfully used to target massive multinational corporations, financial institutions, and critical infrastructure, as well as private individuals.
Pedro Bustamante, director of special projects at Malwarebytes, said that even the beta version of Anti-Exploit that's been available for the past year has had a nearly-flawless record.
"Not a single zero-day has gotten through since the first beta, which let three vulnerabilities through. Even year-old versions" have protected against exploits attempting to use new zero-days, he said.
The beta has been running with "tens of thousands" of users, Kleczynski said.
He explained the difference between Anti-Exploit and his company's flagship product, Malwarebytes Anti-Malware, as one where Anti-Malware stops the final payload at the end of the attack, but Anti-Exploit stops how that payload gets delivered.
malwarebytes-anti-exploit-test.png
A screenshot from exploit expert Kafeine's report on his tests of Malwarebytes Anti-Exploit.Kafeine/malware.dontneedcoffee.com
"It detects exploits because it looks at exploit-like behavior," Bustamante said. It blocks attempts to bypass the operating-system level security, protects against exploits executing from the computer's memory, and halts payloads that can install malware. Worried about giving away the keys to kingdom, Bustamante wouldn't go into further detail on how Anti-Exploit works.
ZeroVulnerabilityLabs introduced the technology in Anti-Exploit as ExploitShield two years ago. At the time, Bustamante -- who co-founded ZeroVulnerabilityLabs -- said, "It is not blacklisting, not whitelisting, and not sandboxing. We call it 'application shielding.'"
This sounds similar to Microsoft's exploit-blocking Enhanced Mitigation Experience Toolkit, or EMET.
"EMET is still in technical preview, and it's complicated as hell" to run, said Kleczynski said. As anyone running Windows with a third-party security suite knows, it wouldn't be the first time that Windows security was better handled by outside sources. Kleczynski asserted that EMET is "allowing through a lot of junk."
To support claims about his own product, Kleczynski hired the independent exploit analysis expert known as Kafeine to try to break the software. Instead, Anti-Exploit was able to stop Kafeine in every test he ran, more than 30 times over two months.
"Malwarebytes Anti-Exploit is working as expected against all widely used exploit kits. It works on Java exploit where EMET wouldn't," Kafeine concluded in his report. He added that Anti-Exploit defeated all 11 of the most commonly-used exploit kits, which are complete software packages to exploit a computer, and all 14 of the most commonly-seen exploits. It also protected five of the commonly-attacked software programs.
In 2012, Bustamante predicted to CNET that the technology behind Anti-Exploit would be at the vanguard of a new breed of security software. That claim has yet to bear fruit. But as remote code exploits continue to be successfully used in attacks and as Microsoft attempts to walk away from the notoriously hole-riddled Windows XP, businesses and individuals could end up turning to Anti-Exploit to reinforce their armor.