<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PandaLabs Blog</title>
	<atom:link href="http://pandalabs.pandasecurity.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://pandalabs.pandasecurity.com</link>
	<description>Everything you need to know about Internet threats</description>
	<lastBuildDate>Tue, 31 Jan 2012 09:04:16 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
		<item>
		<title>PandaLabs Annual Report &#8211; 2011</title>
		<link>http://pandalabs.pandasecurity.com/pandalabs-annual-report-2011/</link>
		<comments>http://pandalabs.pandasecurity.com/pandalabs-annual-report-2011/#comments</comments>
		<pubDate>Tue, 31 Jan 2012 09:04:16 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[Cyber Protest]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[PandaLabs]]></category>
		<category><![CDATA[Security Reports]]></category>
		<category><![CDATA[annual report]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3442</guid>
		<description><![CDATA[Today we are publishing the PandaLabs report, where you can enjoy an overview of the main figures and security news that have happened in the last 12 months, as well as some figures. You will see how malware creation hit a new record high in 2011 with 26 million samples, that Trojans continue to be [...]]]></description>
			<content:encoded><![CDATA[<p>Today we are publishing the PandaLabs report, where you can enjoy an overview of the main figures and security news that have happened in the last 12 months, as well as some figures. You will see how malware creation hit a new record high in 2011 with 26 million samples, that Trojans continue to be the most pervasive malware threat, and some nice stories about cybercrime and cyberwar, as well as some other information about social networks.</p>
<p>I really hope you enjoy it, you can download the report <a href="http://press.pandasecurity.com/press-room/reports/">here</a>.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=PandaLabs+Annual+Report+%E2%80%93+2011+http://tinyurl.com/72flb5f" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/pandalabs-annual-report-2011/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Katy Perry and Russell Brand baits to spread a new Facebook worm</title>
		<link>http://pandalabs.pandasecurity.com/katy-perry-and-russell-brand-baits-to-spread-a-new-facebook-worm/</link>
		<comments>http://pandalabs.pandasecurity.com/katy-perry-and-russell-brand-baits-to-spread-a-new-facebook-worm/#comments</comments>
		<pubDate>Thu, 26 Jan 2012 15:39:03 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3435</guid>
		<description><![CDATA[Once again, user curiosity becomes cyber-criminals’ best ally. Scammers exploit people’s interest in celebrities to infect users. We have recently detected a new Facebook scam that uses a fake video of singer Katy Perry and ex-husband actor Russell Brand to trick users. If the user clicks the link, they are taken to a fake Facebook [...]]]></description>
			<content:encoded><![CDATA[<p>Once again, user curiosity becomes cyber-criminals’ best ally. Scammers exploit people’s interest in celebrities to infect users. We have recently detected a new Facebook scam that uses a fake video of singer Katy Perry and ex-husband actor Russell Brand to trick users.</p>
<p><img class="aligncenter size-full wp-image-1515" title="kate1" src="http://pandalabs.pandasecurity.com/es/wp-content/uploads/2012/01/kate1.jpg" alt="" width="405" height="168" /></p>
<p>If the user clicks the link, they are taken to a fake Facebook page where they are invited to download a plug-in to watch the video.</p>
<p><img class="aligncenter size-full wp-image-1516" title="kate perry" src="http://pandalabs.pandasecurity.com/es/wp-content/uploads/2012/01/kate-perry.png" alt="" width="636" height="525" /></p>
<p>The page indicates that over 4,000 people have already clicked the “Like” button, which is used by the scammers to trick victims into believing that the video is legitimate.</p>
<p>If the user tries to play the video, the worm will act differently depending on the browser used. If you use Firefox or Chrome, the worm installs a browser plug-in and uses it to post the scam to the victims’ friends’ pages. On Internet Explorer, the worm displays an age verification page to access an application called “X-Ray Scanner”.</p>
<p><img class="aligncenter size-full wp-image-1517" title="kate3" src="http://pandalabs.pandasecurity.com/es/wp-content/uploads/2012/01/kate3.jpg" alt="" width="506" height="229" /></p>
<p>Then, before the user can take any other action, the browser takes them to a typical scam site where they are asked to enter their phone number. However, if they do so, they will start receiving unwanted premium rate text messages.</p>
<p><img class="aligncenter size-full wp-image-1518" title="kate4" src="http://pandalabs.pandasecurity.com/es/wp-content/uploads/2012/01/kate4.jpg" alt="" width="698" height="384" /></p>
<p>Here you have some tips on how to avoid falling victim to this type of scam:</p>
<p>-	Be wary of websites offering sensational videos or unusual stories.<br />
-	Before you click on a link sent by one of your contacts, make sure it has been intentionally sent by your friend and it is not the result of a massive scam like this one.<br />
-	Don’t accept friend requests from people you don’t know. This will help keep your privacy safe.<br />
-	Always keep your computer’s operating system and Web browsers up to date, and make sure you have an up-to-date antivirus solution installed.</p>
<p>If, however, you suspect you have fallen into the trap:</p>
<p>-	Check your browser plug-ins and remove any suspicious ones.<br />
-	Check the applications that have permission to access your Facebook account, and delete those you don’t know.<br />
-	Change your Facebook account password. If you use the same credentials to sign in to other services as well, change them too. It is always better to take all necessary precautions.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Katy+Perry+and+Russell+Brand+baits+to+spread+a+new+Facebook+worm+http://tinyurl.com/6r483co" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/katy-perry-and-russell-brand-baits-to-spread-a-new-facebook-worm/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Sex, lies and Twitter</title>
		<link>http://pandalabs.pandasecurity.com/sex-lies-and-twitter/</link>
		<comments>http://pandalabs.pandasecurity.com/sex-lies-and-twitter/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 12:20:42 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[lies]]></category>
		<category><![CDATA[Sex]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3418</guid>
		<description><![CDATA[Last week we got a new follower in Twitter, Alena Edwards: No tweets so far, the only information about &#8220;her&#8221; is the message in her profile, where she&#8217;s looking for funny guys and gives us a link. Probably it is a spammer, but instead of tweeting links just put the spam link in the profile [...]]]></description>
			<content:encoded><![CDATA[<p>Last week we got a new follower in Twitter, Alena Edwards:</p>
<p><img class="aligncenter size-full wp-image-3419" title="spamtwitter" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/spamtwitter.png" alt="" width="704" height="181" /></p>
<p>No tweets so far, the only information about &#8220;her&#8221; is the message in her profile, where she&#8217;s looking for funny guys and gives us a link. Probably it is a spammer, but instead of tweeting links just put the spam link in the profile description. So let&#8217;s see what happens when we go there:</p>
<p><img class="aligncenter size-full wp-image-3421" title="postspamtwitter1" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/postspamtwitter1.png" alt="" width="709" height="433" /></p>
<p>It looks like the typical dating site, maybe not for regular relationships but for more spicy moments&#8230; It is awesome the number of hot girls that are alone looking for some friends <img src='http://pandalabs.pandasecurity.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  take a look at some of the pictures I could see there:</p>
<p><img class="aligncenter size-full wp-image-3423" title="spamtwitter2" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/spamtwitter2.png" alt="" width="711" height="449" /></p>
<p>After checking there were no exploits, etc. I tried to get some more info about that domain, and this is what I got:</p>
<p><img class="aligncenter size-full wp-image-3422" title="registrar" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/registrar.png" alt="" width="364" height="311" /></p>
<p>So the site was created the day before Alena started following us. Then I created a email address to register in the site,  filling all the fields. Once I did it I was registered, but not for that domain I was in, but for a new one, called XXXBlackBook. I was told I was going to receive an email from them to activate my account, so I went to check my inbox and I had the message:</p>
<p><img class="aligncenter size-full wp-image-3424" title="mail" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/mail.png" alt="" width="694" height="206" /></p>
<p>Once I did it I could access as a regular member to the site. In the same website you have an inbox where other members can send you messages, and in a few minutes I got a new one:</p>
<p><img class="aligncenter size-full wp-image-3426" title="spamtwittermessage" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/spamtwittermessage.png" alt="" width="648" height="195" /></p>
<p>To follow my research, I clicked on the message to take a look at it, but sadly I got this:</p>
<p><a href="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/spamtwitter3.png"><img class="aligncenter size-full wp-image-3420" title="spamtwitter3" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/spamtwitter3.png" alt="" width="675" height="617" /></a></p>
<p>So you can get messages but to read them you have to upgrade to a silver or gold account&#8230; and it is not cheap:</p>
<p><img class="aligncenter size-full wp-image-3427" title="spamtwittermessage2" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/spamtwittermessage2.png" alt="" width="670" height="583" /></p>
<p>When I took my credit card my wife came to the room and I had to stop the research <img src='http://pandalabs.pandasecurity.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Sex%2C+lies+and+Twitter+http://tinyurl.com/72t4cff" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/sex-lies-and-twitter/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Megaupload and the cybercrime fight</title>
		<link>http://pandalabs.pandasecurity.com/megaupload-and-the-cybercrime-fight/</link>
		<comments>http://pandalabs.pandasecurity.com/megaupload-and-the-cybercrime-fight/#comments</comments>
		<pubDate>Fri, 20 Jan 2012 07:58:47 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[Cyber Protest]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[Hacktivists]]></category>
		<category><![CDATA[Anonymous]]></category>
		<category><![CDATA[Department of Justice]]></category>
		<category><![CDATA[FBI]]></category>
		<category><![CDATA[Megaupload]]></category>
		<category><![CDATA[RIAA]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3408</guid>
		<description><![CDATA[As most of you already now, yesterday Megaupload was closed by the FBI, accused of &#8220;copyright infringement&#8221;. You can read FBI&#8217;s press release here where the details of the case are explained, and you can see how each accused person in this case could face 50 years jail time. We should be concerned, as the [...]]]></description>
			<content:encoded><![CDATA[<p>As most of you already now, yesterday Megaupload was closed by the FBI, accused of &#8220;copyright infringement&#8221;. You can read FBI&#8217;s press release <a title="FBI Press Release" href="http://www.fbi.gov/news/pressrel/press-releases/justice-department-charges-leaders-of-megaupload-with-widespread-online-copyright-infringement" target="_blank">here</a> where the details of the case are explained, and you can see how each accused person in this case could face 50 years jail time.</p>
<p>We should be concerned, as the next step could be to close Google or Bing, at the end of the day we all use it to find the stuff we want, and I have seen many times results in those search engines with Megaupoad links. And what next? Will they close Internet?</p>
<p>Anonymous has of course reacted, and has started DDoS attacks against a number of different websites, among the targets we can find the Department of Justice, the RIAA, and Universal Music. Again, the best way Anonymous is able to come up with is to launch DDoS attacks. They could try to give information to the people, etc. but that is boring for them, it  is way funnier to break the law.</p>
<p>Going back to the press release, you can also read this:</p>
<blockquote><p>This case is part of efforts being undertaken by the  Department of  Justice Task Force on Intellectual Property (IP Task  Force) to stop the  theft of intellectual property.</p></blockquote>
<p>Meanwhile, in the real world, thousands of millions of dollars are  stolen every year by cybercriminals (real money, taken from users&#8217; credit cards and bank accounts). But as long as there is no theft of  intellectual property, that&#8217;s ok. Wait a moment,<span style="color: #000000;"> </span><span style="color: #ff0000;"><span style="color: #000000;">is that OK?</span><strong> </strong><span style="color: #000000;"><strong>Maybe some priorities should be adjusted</strong>. </span><strong><br />
</strong></span></p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Megaupload+and+the+cybercrime+fight+http://tinyurl.com/89dzf7e" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/megaupload-and-the-cybercrime-fight/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>The Rise of the Ransomware</title>
		<link>http://pandalabs.pandasecurity.com/the-rise-of-the-ransomware/</link>
		<comments>http://pandalabs.pandasecurity.com/the-rise-of-the-ransomware/#comments</comments>
		<pubDate>Thu, 19 Jan 2012 11:18:03 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Rogueware]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[police]]></category>
		<category><![CDATA[Ransomware]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3389</guid>
		<description><![CDATA[In the last months we have seen an increase of ransomware attacks. While the first ones we saw were posing as Microsoft to threaten the user because it had been detected a pirated version of Windows, and in case you didn&#8217;t pay the fine they would contact the local law enforcement agencies, the new ones [...]]]></description>
			<content:encoded><![CDATA[<p>In the last months we have seen an increase of ransomware attacks. While the first ones we saw were <a title="Ransomware Microsoft" href="http://pandalabs.pandasecurity.com/ransomware-posing-as-microsoft/" target="_self">posing as Microsoft </a>to threaten the user because it had been detected a pirated version of Windows, and in case you didn&#8217;t pay the fine they would contact the local law enforcement agencies, the new ones are posing as the very same law enforcement agencies.</p>
<p>While we are use to see this kind of fake messages in English, in this case the attacks are localized, we have seen English, German, Spanish or Dutch language (among others), depending on the targeted country. All of the attacks are targeting some European country, so it looks like that all of them are related and the same cibercriminal gang could be behind them.</p>
<p>The last one has appeared a couple of days ago, this time it is targeting Spain. The file is using as icon the following <em>Internet meme</em>:</p>
<p><img class="aligncenter size-full wp-image-3393" title="meme" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/meme.jpg" alt="" width="233" height="216" /></p>
<p>Once infected, this is what you will see in your desktop:</p>
<p><img class="aligncenter size-full wp-image-3397" title="malware_policia" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/malware_policia1.jpg" alt="" width="710" height="515" /></p>
<p>In the message it says that it has been detected access to illegal material (such as child pornography and spam about terrorism) from that computer, and that  the computer will be locked to prevent such a use. To solve that you have to pay a fine of €100:</p>
<p>The worst thing for the user is that it actually blocks the computer, so it is not easy to remove. To do it, restart the computer in safe mode and run a scan with an <a href="http://www.cloudantivirus.com" target="_blank">antivirus solution</a> that is able to detect it.</p>
<p>These are different examples we have seen in the last months:</p>
<div id="attachment_3398" class="wp-caption aligncenter" style="width: 520px"><a href="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/Poli-UK2.jpg"><img class="size-full wp-image-3398" title="UK" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/Poli-UK2.jpg" alt="" width="510" height="327" /></a><p class="wp-caption-text">English</p></div>
<div id="attachment_3399" class="wp-caption aligncenter" style="width: 510px"><a href="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/Poli-Italiana2.jpg"><img class="size-full wp-image-3399" title="Poli Italiana2" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/Poli-Italiana2.jpg" alt="" width="500" height="378" /></a><p class="wp-caption-text">Italian</p></div>
<div id="attachment_3400" class="wp-caption aligncenter" style="width: 529px"><img class="size-full wp-image-3400" title="Poli Dutch" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/Poli-Dutch.jpg" alt="" width="519" height="363" /><p class="wp-caption-text">Dutch</p></div>
<div id="attachment_3401" class="wp-caption aligncenter" style="width: 528px"><img class="size-full wp-image-3401" title="Poli alemana" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/Poli-alemana.png" alt="" width="518" height="415" /><p class="wp-caption-text">German</p></div>
<div id="attachment_3402" class="wp-caption aligncenter" style="width: 528px"><img class="size-full wp-image-3402" title="Poli Spa" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/Poli-Spa.jpg" alt="" width="518" height="348" /><p class="wp-caption-text">Spanish</p></div>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=The+Rise+of+the+Ransomware+http://tinyurl.com/6ulamut" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/the-rise-of-the-ransomware/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>2012 Security Trends</title>
		<link>http://pandalabs.pandasecurity.com/2012-security-trends/</link>
		<comments>http://pandalabs.pandasecurity.com/2012-security-trends/#comments</comments>
		<pubDate>Thu, 15 Dec 2011 12:26:02 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[PandaLabs]]></category>
		<category><![CDATA[Security Reports]]></category>
		<category><![CDATA[2012]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[trends]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3384</guid>
		<description><![CDATA[2011 is coming to an end, so now it&#8217;s time to try to see what we have to expect for the next 12 months: Social networks: Social engineering techniques exploiting users’ weaknesses have become the leading attack method in social networks. Trending topics such as the Olympics or the next US Presidential elections will be [...]]]></description>
			<content:encoded><![CDATA[<p>2011 is coming to an end, so now it&#8217;s time to try to see what we have to expect for the next 12 months:</p>
<ul>
<li><strong>Social networks</strong>: Social engineering techniques exploiting users’ weaknesses have become the leading attack method in social networks. Trending topics such as the Olympics or the next US Presidential elections will be used as a bait. Cybercriminals will continue to target social media sites to steal personal data.</li>
</ul>
<ul>
<li><strong>Malware increase</strong>: In the past few years, the number of malware threats has grown exponentially, and everything seems to indicate that the trend will continue in 2012. In fact, malware is the weapon use by cybercriminals to carry on their attacks.</li>
</ul>
<ul>
<li><strong>Trojans</strong>: they are cyber-crooks’ weapon of choice for their attacks, as shown by the fact that three out of every four new malware strains created in 2011 were Trojans, designed to sit silently on users’ computers and steal their information.</li>
</ul>
<ul>
<li><strong>Cyberwar</strong>: or maybe it is more accurate to say cyberespionage. 2011 has been the year with most intrusions ever aimed at companies and government agencies. From New Zealand to Canada, from Japan to the European Parliament, there have been countless attacks aimed at stealing secret or classified information. We live in a world where all the information is in digital form, so modern-day spies no longer need to infiltrate a building to steal information. As long as they have the necessary computer skills, they can wreak havoc and access the best-kept secrets of organizations without ever leaving their living-rooms. In 2012 we will see these kind of attacks even more.</li>
</ul>
<ul>
<li><strong>Mac malware</strong>: As the market share of Mac users continues to grow, the number of threats will grow. Fortunately enough, it seems that Mac users are now more aware that Mac is not immune to malware attacks and they are increasingly using antivirus programs, hindering cyber-crooks. The number of malware specimens for Mac will continue to grow in 2012, although much less than for PCs</li>
</ul>
<ul>
<li><strong>Mobile malware</strong>: Over ten years ago, antivirus companies started making dire predictions of a mobile malware epidemic. Years later, as the situation was not as apocalyptic as predicted, they started claiming that the installation of antivirus software on mobile phones had prevented the catastrophe. Well, they were wrong again. If having an antivirus solution were enough to solve all types of malware problems, the world would be a happier place. Unfortunately though, both users and security vendors alike are in the hands of cyber-crooks, who are the ones who decide which platform to target. In this context, last year PandaLabs predicted a surge in cyber attacks on mobile phones, and the fact that Android has become the number one mobile target for cyber-crooks in 2011 confirms that prediction. In 2012 there will be new attacks on Android, but it will not be on a massive scale. New mobile payment methods –via NFC for example– could become the next big target for Trojans but, as always, this will largely depend on their popularity.</li>
</ul>
<ul>
<li><strong>Malware for tablets</strong>: The fact that tablets share the same operating system as smartphones means that they will be soon targeted by the same malware as those platforms. In addition, tablets might draw a special interest from cyber-crooks as people are using them for an increasing number of activities and they are more likely to store sensitive data than, say, a smartphone.</li>
</ul>
<ul>
<li><strong>Cybercriminals targeting small to medium-sized companies</strong>: Why do cybercriminals target online banking customers instead of directly attacking banking institutions to steal money? The answer to this question has to do with the cost-benefit ratio of the attack: Financial entities are usually very well protected, and the chance of launching a successful attack is remote and very costly. However, attacking their customers to steal their identity and impersonate them is much simpler. The security of small to medium-sized companies is not that strong, and this makes them very attractive for cyberthieves, who can steal data from hundreds or thousands of users in one go. On many occasions, small to medium-sized companies do not have dedicated security teams, which makes them much more vulnerable.</li>
</ul>
<ul>
<li><strong>Windows 8</strong>: The next version of Microsoft’s popular operating system is scheduled for November 2012, so even though it is not supposed to have much on an impact on the malware landscape in the coming year, it will surely offer cyber-crooks new opportunities to create malicious software. Windows 8 will allow users to develop applications for virtually any device (PCs, tablets and smartphones) running Windows 8, so it will be possible to develop malicious applications like those for Android. This, in any event, will probably not take place until 2013.</li>
</ul>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=2012+Security+Trends+http://tinyurl.com/cvwp9bo" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/2012-security-trends/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Could targeted attacks be avoided?</title>
		<link>http://pandalabs.pandasecurity.com/could-targeted-attacks-be-avoided/</link>
		<comments>http://pandalabs.pandasecurity.com/could-targeted-attacks-be-avoided/#comments</comments>
		<pubDate>Fri, 02 Dec 2011 11:37:47 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Vulnerabilities & Exploits]]></category>
		<category><![CDATA[Duqu]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[targeted attack]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3374</guid>
		<description><![CDATA[This could be a long blog post, but I&#8217;ll try to make it short. However, for those of you that are lazy, here you can read the answer to the question, and the ones interested on the whole story (I will make it short, I promise) just follow the * mark: NO (*) (*): One [...]]]></description>
			<content:encoded><![CDATA[<p>This could be a long blog post, but I&#8217;ll try to make it short. However, for those of you that are lazy, here you can read the answer to the question, and the ones interested on the whole story (I will make it short, I promise) just follow the * mark:</p>
<p><strong>NO</strong> <strong>(*)</strong></p>
<p><strong>(*)</strong>: One of the characteristics of a targeted attack is that the attacker has previously studied the victim (who is a specific person or organization). This attacker will study the victim: Which systems he is running, where the most valuable information is located, what defenses are built in place, etc. And not only that, also the person(s) will be investigated, in which fields are they working, what hobbies they have, etc. This is why it is almost impossible to avoid these kinds of attacks. However, this is not a reason to lower our defenses, and that&#8217;s something that really puzzles me: taking a look at some of the major attacks we have seen in the last years, many of them were possible because there were servers with no antivirus protection, with an outdated operating system, etc. In a single word: <strong>negligence</strong>.</p>
<p>However, this is not always the case. If we take a look at the 2 most important attacks that have happened during 2011 (the RSA incident and the Duqu case) we will see that both attacks were really sophisticated, and that the way to start the intrusion was a mix of social engineering mixed with some kind of software vulnerability. I would like to point out that in both cases users were receiving a document, and once it was opened the document dropped and run a file in the system, and from that moment on the system was compromised. Of course, these kind of attacks can be done using known or unkown vulnerabilities, and you could argue that a user has no way to detect that a document is malformed in that way, and that the antivirus won&#8217;t detect a single thing as it will be new and the attacker has previously checked that the malware pieces involved were not detected: fair enough, I do agree with that.</p>
<p>And what if I tell you that if they had used Panda the attack would have failed? In 2004 we released TruPrevent technologies, with the goal to detect a portion of the brand new malware, that one that was still not detected with signatures. Since then we have included those technologies in our products, and one of those basically prevents that opening a document a file is downloaded and executed. Smart, nice, clean&#8230; <img src='http://pandalabs.pandasecurity.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Conclusion: in case RSA, or any of the companies attacked by Duqu, had used even the free version of <a href="http://www.cloudantivirus.com" target="_blank">Panda Cloud Antivirus</a> those intrusions wouldn&#8217;t have happened&#8230; <strong>IN THAT WAY</strong>. Anyway, remember the answer to the question (<strong>&#8220;NO&#8221;</strong>). Attackers would have figured out a way to circumvent it, probably trying a different kind of attack, but the harder we make it, the more chances we&#8217;ll have to avoid it.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Could+targeted+attacks+be+avoided%3F+http://tinyurl.com/d4e2lec" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/could-targeted-attacks-be-avoided/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Fake Cloud AV 2012</title>
		<link>http://pandalabs.pandasecurity.com/fake-cloud-av-2012/</link>
		<comments>http://pandalabs.pandasecurity.com/fake-cloud-av-2012/#comments</comments>
		<pubDate>Wed, 30 Nov 2011 11:59:39 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[Rogueware]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3363</guid>
		<description><![CDATA[There is a new friend in the village. Many people thought that the fake antivirus (aka rogueware) business had decreased, and it was true that for a few months rogueware infections were not that prevalent, mainly due to the efforts made by law enforcement with the help of security companies, but it was a matter [...]]]></description>
			<content:encoded><![CDATA[<p>There is a new friend in the village. Many people thought that the fake antivirus (aka rogueware) business had decreased, and it was true that for a few months rogueware infections were not that prevalent, mainly due to the efforts made by law enforcement with the help of security companies, but it was a matter of time to have them back. In the last weeks we have seen an increase in the infections, and today I want to show you a new one that calls itself &#8220;Cloud AV 2012&#8243;.</p>
<p>Cybercriminals always try to confuse their victims, so they use names similar or equal to those used in real antivirus products. In this case they have taken advantage of the famous <a href="http://www.cloudantivirus.com" target="_blank">Panda Cloud AV</a> to do their trick. Once it is installed in your computer, it will create a link in your desktop to open the program, but you won&#8217;t need to do it as as soon as it is installed it will open itself and will launch a system scan, which will give you as a result loads of malware found in your system. Of course that won&#8217;t be true, but they don&#8217;t care:</p>
<p><img class="aligncenter size-full wp-image-3365" title="CloudAV" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2011/11/CloudAV.png" alt="" width="567" height="359" /></p>
<p>What any user would do here is to click on &#8220;Remove threats&#8221;, but once you click on it, a new window will pop up asking you to buy the product:</p>
<p><img class="aligncenter size-full wp-image-3366" title="CloudAV2" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2011/11/CloudAV2.png" alt="" width="523" height="276" /></p>
<p>Of course, if you want to buy it you will be redirected to a web form where you can make the payment:</p>
<p><img class="aligncenter size-full wp-image-3367" title="CloudAV4" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2011/11/CloudAV4.png" alt="" width="577" height="363" /></p>
<p>Of course if you give your credit card to pay the 52$, you&#8217;ll get the code to unlock the fake antivirus&#8230; if you don&#8217;t do it, you&#8217;ll get a message every now and then telling you are still infected. And what it&#8217;s worse, everytime you try to run any program in your computer it will tell you that it is infected, so your computer will be useless.</p>
<p>So&#8230; what to do if you are already infected? You should start your  computer in Safe Mode, go to <a title="Panda Cloud Antivirus" href="http://www.cloudantivirus.com" target="_self">www.cloudantivirus.com</a> and install the real  Panda Cloud Antivirus to remove all the malicious files. Easy, isn&#8217;t  it? <img src='http://pandalabs.pandasecurity.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Fake+Cloud+AV+2012+http://tinyurl.com/d2zq74a" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/fake-cloud-av-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hong Kong, AVAR 2011</title>
		<link>http://pandalabs.pandasecurity.com/hong-kong-avar-2011/</link>
		<comments>http://pandalabs.pandasecurity.com/hong-kong-avar-2011/#comments</comments>
		<pubDate>Fri, 11 Nov 2011 02:07:36 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[PandaLabs]]></category>
		<category><![CDATA[AVAR]]></category>
		<category><![CDATA[Conference]]></category>
		<category><![CDATA[Hong Kong]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3357</guid>
		<description><![CDATA[Greetings from Hong Kong! This week we are enjoying the security conference AVAR, which is taking place in Hong Kong. Some interesting topics are being covered, such as the talk &#8220;Malware in EFI&#8221;, where Intel&#8217;s Igor Muttik showed us how malware could take advantage of the the EFI (Extensible Firmware Interface)  and the challenges we [...]]]></description>
			<content:encoded><![CDATA[<p>Greetings from Hong Kong! This week we are enjoying the security conference AVAR, which is taking place in Hong Kong. Some interesting topics are being covered, such as the talk &#8220;Malware in EFI&#8221;, where Intel&#8217;s Igor Muttik showed us how <a href="http://pandalabs.pandasecurity.com/wp-content/uploads/2011/11/DSC03429.jpg"><img class="alignleft size-full wp-image-3358" style="margin: 10px;" title="AVAR 2011" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2011/11/DSC03429.jpg" alt="" width="247" height="329" /></a>malware could take advantage of the the EFI (Extensible Firmware Interface)  and the challenges we could be facing, as well as the countermeasures that can be taken. Another topic that has been around a lot is malware in mobile devices. Even though it is not that prevalent, it is true that it is an emerging threat and it raises some interesting thoughts. Of course the cloud is another topic covered here, but one of the most interesting ones are those that are talking about targeted attacks in certain countries in Asia, as South Korea and Japan. The full program is <a title="AVAR 2011" href="http://www.aavar.org/avar2011/program/" target="_blank">here</a> in case you want to take a look at it.</p>
<p>As some of you may remember, in last year&#8217;s AVAR in Bali I was awarded the &#8220;Wildlist Reporter of the year&#8221; prize, so this year I was the one in charge of giving the prize to the next. On Thursday night, after the gala dinner, I went to the stage to announce the next &#8220;Wildlist Reporter of the year&#8221; winner, and that was my good friend Philipp Wolf, Director of Protection Labs in Avira. In the following picture, from left to right, you can see Luis Corrons, Philipp Wolf and Peter Chung (Wildlist Director):</p>
<div id="attachment_3360" class="wp-caption aligncenter" style="width: 558px"><img class="size-full wp-image-3360" title="Wildlist Reporter of the Year" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2011/11/DSC03496.jpg" alt="Wildlist Reporter of the Year" width="548" height="411" /><p class="wp-caption-text">Wildlist Reporter of the Year</p></div>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Hong+Kong%2C+AVAR+2011+http://tinyurl.com/6uhdetj" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/hong-kong-avar-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PandaLabs Report  &#8211; Q3 2011</title>
		<link>http://pandalabs.pandasecurity.com/pandalabs-report-q3-2011/</link>
		<comments>http://pandalabs.pandasecurity.com/pandalabs-report-q3-2011/#comments</comments>
		<pubDate>Thu, 03 Nov 2011 08:26:17 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3347</guid>
		<description><![CDATA[The new PandaLabs Report Q3 11 is out. Take a look at what has happened in the computer security field during the last 3 months. Just click on the picture. In this quarter 5 million new malware samples have been created and the record of new Trojans has been broken as it the preferred category by [...]]]></description>
			<content:encoded><![CDATA[<p>The new PandaLabs Report Q3 11 is out.  Take a look at what has happened in the computer security field during the last 3 months.  Just click on the picture.</p>
<p style="text-align: center;"><a href="http://press.pandasecurity.com/wp-content/uploads/2011/10/PandaLabs-Report-Q3-2011.pdf"><img class="aligncenter" src="http://prensa.pandasecurity.com/wp-content/uploads/2011/10/Cover-PandaLabs-Report-Q3.jpg" alt="" width="329" height="233" /></a></p>
<p>In this quarter 5 million new malware samples have been created and the record of new Trojans has been broken as it the preferred category by cybercriminals to carry out their theft of information.</p>
<p>The Anonymous Group, who starred in the second quarter, has continued making the headlines in this period, due to the arrest of some members, theft of data from different web sites and operation PayPal.</p>
<p>The PandaLabs report also includes information about cybercrime, cyberwar, social networks, Mac and cell phones, social networks and a wide section to explain about exploits.</p>
<p>The highlight of this third quarter is the record set in the creation of new Trojan samples. 3 out of 4 new malware samples created by cybercriminals are Trojans and this is just another proof that they are focused on stealing users information.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=PandaLabs+Report++%E2%80%93+Q3+2011+http://tinyurl.com/6g4u5jf" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/pandalabs-report-q3-2011/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>

