Showing posts with label users. Show all posts
Showing posts with label users. Show all posts

Monday, April 24, 2017

Kaspersky Warns that WHATSAPP For PC Spam Email Campaign Striking Innocent Users

Kaspersky Warns that WHATSAPP For PC Spam Email Campaign Striking Innocent Users



Kaspersky Warns that ‘WHATSAPP for PC’ Spam Email Campaign Striking Innocent Users
WhatsApp is a renowned cross-platform messaging app. Security firm Kaspersky discovered a Brazilian spam email message targeting innocent users claiming WHATSAPP for PC is now available.

The Trojan downloading menace contains an embedded link. It makes attempts to fool users of PC to download the malware projecting on their screen. The spam email quotes that WhatsApp for the PC is now available and shows the recipient that they already have certain pending invitations from friends in his or her account.


According to Kaspersky, when the link is clicked, it wont offer WhatsApp messaging PC client software. The link leads the users to a hacked server in Turkey, after which it redirects them to a Hightail.com, which like Dropbox or YouSendIt, is a service which allows cloud file storage and downloads.

Theinquirer.net published a written statement by Dmitry Bestuzhev, Security Researcher of Kaspersky, on 21st January, 2014, as "the above downloader has some anti-debugging feature. Once it is activated, it downloads a new Trojan which appears to be a banker itself.

Threatpost.com published a report on 21st January, 2014, quoting Bestuzhev as saying "the malware reports itself to the cybercriminals infections statistics console and when open, a local port 1157 sends stolen information in the Oracle DB format."

Its unclear if the malware has made it to shores of U.S. but considering the popularity of WhatsApp abroad, especially in Europe and Latin America, it appears to be confined to those areas.

Bestuzhev even goes as far as to call it a "classic style of a Brazilian-created malware" as it appears to target users in Brazil, a country with an established userbase of WhatsApp. Moreover, the Trojan appears to be downloaded from a Brazilian server.

The security firm notes that the malware which steal information from infected devices was detected by only 9 of the 50 antivirus engines on VirusTotal.

In September 2013, fake emails appearing to be from WhatsApp claiming that the recipient has a new voicemail message even though WhatsApp does not provide a calling feature, it is was the text messaging service which were intercepted.

 SPAMfighter News - 30-01-2014


Go to link for download

Read more »

Tuesday, March 14, 2017

WhatsApp users targeted in cheating lover malware sting

WhatsApp users targeted in cheating lover malware sting



A new breed of malware is targeting WhatsApp users who are suspicious of potentially cheating partners, according to an exclusive report handed to ITProPortal by security firm Malwarebytes.
The potentially harmful cocktail of malware poses as a tool that claims to be able to "grab" the messages of any WhatsApp user, and promises to help you "find out if your spouse is cheating on you, etc."


The scurrilous hackers are also using widespread low confidence in WhatsApps security protocols in order to snare users. The site, registered at http://whatsapp-hack.in, claims in broken English that "Due to the low security WhatsApp applies to their servers, we can get it and extract easy any conversation."
It also reassures users that "While you are using you are 100% protected, your victims will not see any changes or suspect behaviour on their acount."
Sound tempting? Well hold on a minute – the site does mention one catch: "They are constantly patching our exploits so do not forget to update."

Thats where users get caught out. Once downloaded, the ostensible WhatsApp exploit shows the following message: "WhatApp patched this version. Click OK to start update."
Already two alarm bells should be ringing:

- WhatsApps is misspelled "WhatApp"
- There is no cancel button.

As youve probably guessed, hitting OK runs another executable, called update.exe.
If not connected to the Internet, the file will crash at that point. Otherwise, users see an installer that requires them to install Mobogenie, a potentially unwanted program (PUP) that various monetisation programs to bundle with third party installers, and an irritating browser extension called DefaultTab, along with  other PUPs that work together to clog up affected computers.
ITProPortal


Go to link for download

Read more »