Lucy malware for Android adds file-encryption for ransomware ops - BleepingComputer
Lucy malware for Android adds file-encryption for ransomware ops - BleepingComputer |
- Lucy malware for Android adds file-encryption for ransomware ops - BleepingComputer
- How to Keep Your Zoom Chats Private and Secure - WIRED
- Avast Secure Browser comes to Android - SecurityBrief Europe
| Lucy malware for Android adds file-encryption for ransomware ops - BleepingComputer Posted: 28 Apr 2020 04:24 AM PDT
A threat actor focusing on Android systems has expanded their malware-as-a-service (MaaS) business with file-encrypting capabilities for ransomware operations. Named Lucy Gang by researchers, the actor is a Russian-speaking team that made itself known two years ago with the Black Rose Lucy service, offering botnet and malware dropping capabilities for Android devices. No cryptocurrency demandThe new feature allows customers of the service to encrypt files on infected devices and show a ransom note in the browser window asking for $500. The message purports to be from the FBI and accuses the victim of storing adult content on the mobile device. The purpose of the fake FBI note is to scare the victim into obeying the cybercriminals' request. It is a clear extortion attempt preying on fear of legal consequences for visiting adult websites and storing lewd files. Adding to the scare, the criminals say that a picture of the victim's face had been taken and uploaded to FBI's cyber crime data center along with location details. Payment is expected in three days from the notification, otherwise the fine triples, the message warns.
Interestingly, the attacker does not take cryptocurrency. Instead, they demand credit card information. This is unusual as ransomware operators are typically cashing in by making victims pay the ransom in cryptocurrency. According to researchers from Check Point, who discovered the Black Rose Lucy malware family in September 2018, more than 80 samples of the new version have been distributed in the wild via instant messaging apps and social media. One of the new samples was spotted by Tatyana Shishkova, an Android malware researcher at Kaspersky, who in February tweeted a list of four IP addresses used for command and control (C2). Speaking to BleepingComputer, Check Point manager of mobile research Aviran Hazum said that the current campaign targets only victims in former Soviet states, for reasons unknown. This restriction is enforced upon malware initialization by checking the country code of the device. Using an alert dialog, Lucy then tries to trick the victim into enabling the Accessibility Service, which is intended for users with disabilities to assist them with various tasks on behalf of installed apps. The alert calls the user to turn on Streaming Video Optimization, which allegedly allows video to play on the phone. If the ruse works, the malware gets permission to use the accessibility service. "Inside the MainActivity module, the application triggers the malicious service, which then registers a BroadcastReceiver that is called by the command action.SCREEN_ON and then calls itself. This is used to acquire the 'WakeLock' service, which keeps the device's screen on, and 'WifiLock' service, which keeps the WIFI on" - Check Point Encrypt, decrypt, and self-deleteAs far as encryption goes, Lucy first tries to retrieve all the directories on the device. In case of failure, it looks for the "/storage" directory. If this also fails, the malware searches for the "/sdcard" folder. In the next stage, it starts encrypting the data in the selected storage location and verifies the success of the operation when it completes. The procedure does not discriminate between files, Hazum told us, as long as they can be encrypted/decrypted. "On this campaign, we have not observed a specific file-type targeting. All files were encrypted" - Aviran Hazum As an interesting note, there is a false lead during the encryption process. A false key is generated using the AES algorithm with a constant seed of 0x100. This may be a trick from the malware developer or a mistake in the code.
However, the real encryption key is made of data in the first segment of the 'SecretKeySpec' and the 'Key' string that is taken from SharedPreferences. The function responsible for processing the files uses these with the chosen file directory and a boolean variable that switches between the encryption and the decryption mode.
Lucy stores the decryption key on the device, in the SharedPreferences variable, Hazum says, adding that "in order to access other application's data, the device needs to be rooted, which we do not suggest doing." Check Point's analysis reveals that the malware sends logs following the decryption process, to inform that all files were processed and then runs a command to delete itself. A look into the commands sent from the C2 shows that Lucy can make calls, export a list of installed apps, delete the encryption keys, or run a remote shell on the device. A set of commands from the C2 that the malware recognizes is available below:
|
| How to Keep Your Zoom Chats Private and Secure - WIRED Posted: 05 Apr 2020 04:13 AM PDT ![]() Another step you can take is to lock a meeting once you're sure that everyone who needs to join has joined. From the desktop app, click Manage Participants, More, and then Lock Meeting. Just make doubly sure that you weren't expecting someone who hasn't yet arrived, as they won't be able to get in. Add all of these measures up together and you can be very confident that your next Zoom meeting isn't about to get rudely interrupted. Be careful not to get complacent though, particularly when it comes to limiting the exposure of the meeting IDs and the passwords that you're using for your video calls. Stay Private So you're safe and protected from outsiders; all that's left is an awareness of what your boss can peek at while you're using Zoom as a meeting participant. Meeting hosts have a lot of privileges and tools at their disposal, which you should know about going in. Zoom had an attention-tracking feature, for instance, that told hosts if participants clicked away from the Zoom app for more than 30 seconds. After a public backlash, Zoom deactivated the feature last week. Also remember that hosts can record audio and video from meetings in full, as well as keep a record of public chats. What's more, if you save the chat log for yourself, it will also include private chats you've been involved in, so be very careful about sharing that file with anyone else. Don't just post it in the group chat for everyone to read. If a host chooses to enable this setting, Zoom will notify you and give you a chance to opt out. There's not a lot you can do about these features, which are designed to make it easier to create logs for people to look back on later, but it's worth knowing about them. A simple rule of thumb: If there's a communication you don't want anyone else to know about, keep it off Zoom. Try an Alternative If you're not happy with Zoom, then you've got plenty of other options to turn to. For example, Google Duo: it recently updated the maximum video chat group size from 8 to 12, it's available on mobile devices and the web, and video and audio calls are end-to-end encrypted (not even Google can peek at the data). For those of you with colleagues, family, and friends who are all on Apple devices, FaceTime is an option. Group video chats of up to 32 people are supported, end-to-end encryption is turned on by default, and the apps are simple to use across iOS, iPadOS, and macOS. The downside is, of course, that no one on Windows or Android can join in. Webex from Cisco is another group video calling tool that supports end-to-end encryption: It's a little business-focused, but you do get support for video calls of up to 100 people, and a lot of the same features that Zoom brings to the table. The free tier is quite generous at the moment, though we'll have to wait and see if it remains so after the current global pandemic has passed. Like Webex, GoToMeeting has been in the virtual meeting business a long time, and includes end-to-end encryption as standard. Unlike Webex, there are no free plans, so you or your company will have to pay $12 a month and up for video calls with up to 150 different people. There's also a 14-day free trial. If you can live without full end-to-end encryption—so you're essentially putting your trust in the software developer not to gather any more data than it needs to—then programs such as Skype (up to 50 people on a video call), Slack (up to 15 people on a video call with a paid plan), and Facebook Messenger (up to 50 people on a video call) are all options as well. Correction 4/5/20 12 pm ET: This story previously stated that Zoom hosts could use an attention-tracking feature that the company had disabled last week. More Great WIRED Stories |
| Avast Secure Browser comes to Android - SecurityBrief Europe Posted: 28 Apr 2020 05:10 PM PDT ![]() Cybersecurity firm Avast has released a version of its Avast Secure Browser for those who want a little more security built into their internet experience. Avast Secure Browser has been a mainstay for the security platform in Windows and Mac, and this is the first time it has come to mobile. According to Avast, the Secure Browser for Android was built from the ground up, with total encryption protecting both cybersecurity and privacy. It uses AES-256, ChaCha 256-bit encryption, as well as the latest TLS/SSL cryptographic protocols for the data transport layer. "To ensure that user DNS requests are kept private and secure, Avast Secure Browser for Android supports multiple DNS options straight out of the box, such as DNS over TLS, DNSSEC and decentralised DNS support," Avast states. There is also a VPN that encrypts all inbound and outbound connection to the VPN's location; a user PIN code for device access; anti-tracking technologies that discourage websites, advertisers and other web services from tracking online activity; adblock integration, and an encrypted media vault. Avast Secure Browser vice president and general manager Scott Curtiss says that Avast takes a privacy by design stance because it just wants to make the world safer by protecting every user's security and privacy. "We know that our customers care deeply about security and privacy and want to be in control of their own personal data without compromising the quality of their online interactions." He says Avast wants to be the first all-in-one browser that secures privacy and the entire browsing experience. According to Avast Threat Lab reports, mobile device usage is creating plenty of opportunities for mobile-related malware. Between October and December 2019, adware (software that hijacks user devices to spam them with malicious ads) is responsible for 72% of mobile malware, with the remaining 28% of threats linked to banking trojans, fake apps, lockers and downloaders, according to researchers. To date, 131 COVID-19 related apps have been detected as malicious through Avast's apklab.io platform as cybercriminals look to exploit the pandemic using social engineering tactics," the company states. "There is still a perception among many consumers that on mobile, internet and browser-based threats do not exist", says Curtiss. "This is not the case. Mobile is a lucrative platform for cybercriminals because of its majority market share versus desktop and higher levels of internet traffic. In the past 12 months, we've seen adware rise by 38% on Android." Avast says its Secure Browser will come to iOS later this year. |
| You are subscribed to email updates from "location of encryption devices,mobile security encryption,what does it mean to encrypt my phone" - Google News. To stop receiving these emails, you may unsubscribe now. | Email delivery powered by Google |
| Google, 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States | |







Comments
Post a Comment