<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PandaLabs Blog</title>
	<atom:link href="http://pandalabs.pandasecurity.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://pandalabs.pandasecurity.com</link>
	<description>Everything you need to know about Internet threats</description>
	<lastBuildDate>Tue, 06 Mar 2012 16:23:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
		<item>
		<title>Where is the lulz now?</title>
		<link>http://pandalabs.pandasecurity.com/where-is-the-lulz-now/</link>
		<comments>http://pandalabs.pandasecurity.com/where-is-the-lulz-now/#comments</comments>
		<pubDate>Tue, 06 Mar 2012 16:23:20 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[Hacktivists]]></category>
		<category><![CDATA[LulzSec]]></category>
		<category><![CDATA[sabu]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3469</guid>
		<description><![CDATA[Really good news. I have just read that LulzSec members have been arrested and that their main head Sabu has been working as an informant for the FBI. It turns out he was arrested last year, and since then he has been working with Law Enforcement. As I said, really good news Will this mean [...]]]></description>
			<content:encoded><![CDATA[<p>Really good news. I have just <a href="http://www.foxnews.com/scitech/2012/03/06/hacking-group-lulzsec-swept-up-by-law-enforcement/" target="_blank">read</a> that LulzSec members have been arrested and that their main head Sabu has been <img class="alignright size-full wp-image-3471" title="lulzsec" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/03/lulzsec.jpg" alt="" width="284" height="177" />working as an informant for the FBI. It turns out he was arrested last year, and since then he has been working with Law Enforcement.</p>
<p>As I said, really good news <img src='http://pandalabs.pandasecurity.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Will this mean the end of Anonymous? No. It will mean the end of LulzSec, but Anonymous existed before LulzSec and will continue existing. However we probably won&#8217;t see any more hacks as the ones LulzSec had been perpetrating, and Anonymous will only use their known childish tactic of DDoS using their LOIC tool.</p>
<p>Enjoy the story <a href="http://www.foxnews.com/scitech/2012/03/06/hacking-group-lulzsec-swept-up-by-law-enforcement/">here</a></p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Where+is+the+lulz+now%3F+http://pandalabs.pandasecurity.com/?p=3469" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/where-is-the-lulz-now/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Michael Jackson catalogue stole from Sony. More to come?</title>
		<link>http://pandalabs.pandasecurity.com/michael-jackson-catalogue-stole-from-sony-more-to-come/</link>
		<comments>http://pandalabs.pandasecurity.com/michael-jackson-catalogue-stole-from-sony-more-to-come/#comments</comments>
		<pubDate>Tue, 06 Mar 2012 15:36:35 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Michael Jackson]]></category>
		<category><![CDATA[Sony]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3457</guid>
		<description><![CDATA[Yesterday it was made public that Sony Music had a security incident in May 2011 and the entire back catalogue of Michael Jackson, including unreleased material, was stolen. This happened after Sony was also hacked last year, when personal information from more than a 100 million customers was stolen in 2 different incidents affecting PlayStation [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday it was made public that Sony Music had a security incident in May 2011 and the entire back catalogue of <img class="alignright size-medium wp-image-3460" style="margin: 10px 20px;" title="michaeljackson" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/03/michaeljackson-300x263.jpg" alt="" width="264" height="232" />Michael Jackson, including unreleased material, was stolen.</p>
<p>This happened after Sony was also hacked last year, when personal information from more than a 100 million customers was stolen in 2 different incidents affecting PlayStation Network and Sony Online Entertainment.</p>
<p>Looks like the cybercriminals involved in this Sony Music hack thought it should be easy to break into the company, and sadly they were right, even though this time they have been arrested and will face trial in January 2013.</p>
<p>It is likely that files from more music stars could have been stolen, unless Sony had it in an isolated server, so we could expect more news coming soon.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Michael+Jackson+catalogue+stole+from+Sony.+More+to+come%3F+http://pandalabs.pandasecurity.com/?p=3457" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/michael-jackson-catalogue-stole-from-sony-more-to-come/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bot shopping with my wife</title>
		<link>http://pandalabs.pandasecurity.com/bot-shopping-with-my-wife/</link>
		<comments>http://pandalabs.pandasecurity.com/bot-shopping-with-my-wife/#comments</comments>
		<pubDate>Thu, 16 Feb 2012 09:02:28 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[bank of america]]></category>
		<category><![CDATA[bot]]></category>
		<category><![CDATA[darkcomet]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[online]]></category>
		<category><![CDATA[shopping]]></category>
		<category><![CDATA[steam]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3446</guid>
		<description><![CDATA[When my wife told me she had received an email with a purchase confirmation she hadn&#8217;t done, my first thought was: How can she even remember what she bought? She buys thousands of clothes online, probably she doesn&#8217;t remember it, this wouldn&#8217;t be the first time After she told me 1,000 times she had not [...]]]></description>
			<content:encoded><![CDATA[<p>When my wife told me she had received an email with a purchase confirmation she hadn&#8217;t done, my first thought was:</p>
<blockquote><p>How can she even remember what she bought? She buys thousands of clothes online, probably she doesn&#8217;t remember it, this wouldn&#8217;t be the first time <img src='http://pandalabs.pandasecurity.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p></blockquote>
<p>After she told me 1,000 times she had not bought anything in that  store, I decided to take a look at it, and it really looks like a legit  message, so I asked her again. She looked at me in a way that only your  better half can do, and at that moment I understood that my life was in  risk if I dare to ask again.</p>
<p>I looked at it again and it turned out it was not a legit email.  Usually cybercriminals use this kind of social engineering techniques  but the messages are usually less elaborated than this one:</p>
<p><img class="aligncenter size-full wp-image-3447" title="MailCult" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/02/MailCult.png" alt="" width="755" height="816" /></p>
<p>When you click in the URL to view the order, you go to a different place, as it is a html message and the real link cannot be seen in the text, so the user thinks he will see the actual order. Then you are asked to download the following file:</p>
<p style="text-align: left;"><img class="aligncenter size-full wp-image-3448" title="file" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/02/file.png" alt="" width="108" height="123" />As you can see the file name is the same as the subject of the message and the fake order number, and it uses the Acrobat icon to fool users into open the file as they will think it is a PDF, as most users have their systems configured to hide known file extensions and they couldn&#8217;t see the .exe that you can see in the picture.</p>
<p style="text-align: left;">Once you have done it&#8230; bad news, this is a nasty Trojan with bot capabilities. It is designed to steal all kind of personal information: from Bank of America customers to players using the game platform Steam. And it will log everything you do in your computer, so the next time you go to Facebook, Gmail, etc. your passwords will be sent to the cybercriminals.</p>
<p style="text-align: left;">Doing some reversing I found out it also looks for some other Trojans, mainly bot competitors, to remove them in case they are in the system, such as Zeus, DarkComet, etc. As Sean Connery (Ramirez) said in the film Highlanders: &#8220;In the end there can be only one.&#8221;</p>
<p style="text-align: left;">Once installed in creates a registry entry to ensure it will be executed every time the computer is started. It uses the name &#8220;Windows Defender&#8221; for that registry entry, so if the user sees that he will think it is some kind of legit application. It also modifies some values in the registry to bypass the firewall (very important when you pretend to send out the stolen data).</p>
<p>Lessons learnt:</p>
<p>1.- Your wife is always right, and in case she tells you something you don&#8217;t have to ask about it anymore</p>
<p>2.- Remember everything you buy online to avoid being fooled.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Bot+shopping+with+my+wife+http://tinyurl.com/7a8ubo2" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/bot-shopping-with-my-wife/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>PandaLabs Annual Report &#8211; 2011</title>
		<link>http://pandalabs.pandasecurity.com/pandalabs-annual-report-2011/</link>
		<comments>http://pandalabs.pandasecurity.com/pandalabs-annual-report-2011/#comments</comments>
		<pubDate>Tue, 31 Jan 2012 09:04:16 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[Cyber Protest]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[PandaLabs]]></category>
		<category><![CDATA[Security Reports]]></category>
		<category><![CDATA[annual report]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3442</guid>
		<description><![CDATA[Today we are publishing the PandaLabs report, where you can enjoy an overview of the main figures and security news that have happened in the last 12 months, as well as some figures. You will see how malware creation hit a new record high in 2011 with 26 million samples, that Trojans continue to be [...]]]></description>
			<content:encoded><![CDATA[<p>Today we are publishing the PandaLabs report, where you can enjoy an overview of the main figures and security news that have happened in the last 12 months, as well as some figures. You will see how malware creation hit a new record high in 2011 with 26 million samples, that Trojans continue to be the most pervasive malware threat, and some nice stories about cybercrime and cyberwar, as well as some other information about social networks.</p>
<p>I really hope you enjoy it, you can download the report <a href="http://press.pandasecurity.com/press-room/reports/">here</a>.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=PandaLabs+Annual+Report+%E2%80%93+2011+http://tinyurl.com/72flb5f" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/pandalabs-annual-report-2011/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Katy Perry and Russell Brand baits to spread a new Facebook worm</title>
		<link>http://pandalabs.pandasecurity.com/katy-perry-and-russell-brand-baits-to-spread-a-new-facebook-worm/</link>
		<comments>http://pandalabs.pandasecurity.com/katy-perry-and-russell-brand-baits-to-spread-a-new-facebook-worm/#comments</comments>
		<pubDate>Thu, 26 Jan 2012 15:39:03 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3435</guid>
		<description><![CDATA[Once again, user curiosity becomes cyber-criminals’ best ally. Scammers exploit people’s interest in celebrities to infect users. We have recently detected a new Facebook scam that uses a fake video of singer Katy Perry and ex-husband actor Russell Brand to trick users. If the user clicks the link, they are taken to a fake Facebook [...]]]></description>
			<content:encoded><![CDATA[<p>Once again, user curiosity becomes cyber-criminals’ best ally. Scammers exploit people’s interest in celebrities to infect users. We have recently detected a new Facebook scam that uses a fake video of singer Katy Perry and ex-husband actor Russell Brand to trick users.</p>
<p><img class="aligncenter size-full wp-image-1515" title="kate1" src="http://pandalabs.pandasecurity.com/es/wp-content/uploads/2012/01/kate1.jpg" alt="" width="405" height="168" /></p>
<p>If the user clicks the link, they are taken to a fake Facebook page where they are invited to download a plug-in to watch the video.</p>
<p><img class="aligncenter size-full wp-image-1516" title="kate perry" src="http://pandalabs.pandasecurity.com/es/wp-content/uploads/2012/01/kate-perry.png" alt="" width="636" height="525" /></p>
<p>The page indicates that over 4,000 people have already clicked the “Like” button, which is used by the scammers to trick victims into believing that the video is legitimate.</p>
<p>If the user tries to play the video, the worm will act differently depending on the browser used. If you use Firefox or Chrome, the worm installs a browser plug-in and uses it to post the scam to the victims’ friends’ pages. On Internet Explorer, the worm displays an age verification page to access an application called “X-Ray Scanner”.</p>
<p><img class="aligncenter size-full wp-image-1517" title="kate3" src="http://pandalabs.pandasecurity.com/es/wp-content/uploads/2012/01/kate3.jpg" alt="" width="506" height="229" /></p>
<p>Then, before the user can take any other action, the browser takes them to a typical scam site where they are asked to enter their phone number. However, if they do so, they will start receiving unwanted premium rate text messages.</p>
<p><img class="aligncenter size-full wp-image-1518" title="kate4" src="http://pandalabs.pandasecurity.com/es/wp-content/uploads/2012/01/kate4.jpg" alt="" width="698" height="384" /></p>
<p>Here you have some tips on how to avoid falling victim to this type of scam:</p>
<p>-	Be wary of websites offering sensational videos or unusual stories.<br />
-	Before you click on a link sent by one of your contacts, make sure it has been intentionally sent by your friend and it is not the result of a massive scam like this one.<br />
-	Don’t accept friend requests from people you don’t know. This will help keep your privacy safe.<br />
-	Always keep your computer’s operating system and Web browsers up to date, and make sure you have an up-to-date antivirus solution installed.</p>
<p>If, however, you suspect you have fallen into the trap:</p>
<p>-	Check your browser plug-ins and remove any suspicious ones.<br />
-	Check the applications that have permission to access your Facebook account, and delete those you don’t know.<br />
-	Change your Facebook account password. If you use the same credentials to sign in to other services as well, change them too. It is always better to take all necessary precautions.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Katy+Perry+and+Russell+Brand+baits+to+spread+a+new+Facebook+worm+http://tinyurl.com/6r483co" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/katy-perry-and-russell-brand-baits-to-spread-a-new-facebook-worm/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Sex, lies and Twitter</title>
		<link>http://pandalabs.pandasecurity.com/sex-lies-and-twitter/</link>
		<comments>http://pandalabs.pandasecurity.com/sex-lies-and-twitter/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 12:20:42 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[lies]]></category>
		<category><![CDATA[Sex]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3418</guid>
		<description><![CDATA[Last week we got a new follower in Twitter, Alena Edwards: No tweets so far, the only information about &#8220;her&#8221; is the message in her profile, where she&#8217;s looking for funny guys and gives us a link. Probably it is a spammer, but instead of tweeting links just put the spam link in the profile [...]]]></description>
			<content:encoded><![CDATA[<p>Last week we got a new follower in Twitter, Alena Edwards:</p>
<p><img class="aligncenter size-full wp-image-3419" title="spamtwitter" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/spamtwitter.png" alt="" width="704" height="181" /></p>
<p>No tweets so far, the only information about &#8220;her&#8221; is the message in her profile, where she&#8217;s looking for funny guys and gives us a link. Probably it is a spammer, but instead of tweeting links just put the spam link in the profile description. So let&#8217;s see what happens when we go there:</p>
<p><img class="aligncenter size-full wp-image-3421" title="postspamtwitter1" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/postspamtwitter1.png" alt="" width="709" height="433" /></p>
<p>It looks like the typical dating site, maybe not for regular relationships but for more spicy moments&#8230; It is awesome the number of hot girls that are alone looking for some friends <img src='http://pandalabs.pandasecurity.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  take a look at some of the pictures I could see there:</p>
<p><img class="aligncenter size-full wp-image-3423" title="spamtwitter2" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/spamtwitter2.png" alt="" width="711" height="449" /></p>
<p>After checking there were no exploits, etc. I tried to get some more info about that domain, and this is what I got:</p>
<p><img class="aligncenter size-full wp-image-3422" title="registrar" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/registrar.png" alt="" width="364" height="311" /></p>
<p>So the site was created the day before Alena started following us. Then I created a email address to register in the site,  filling all the fields. Once I did it I was registered, but not for that domain I was in, but for a new one, called XXXBlackBook. I was told I was going to receive an email from them to activate my account, so I went to check my inbox and I had the message:</p>
<p><img class="aligncenter size-full wp-image-3424" title="mail" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/mail.png" alt="" width="694" height="206" /></p>
<p>Once I did it I could access as a regular member to the site. In the same website you have an inbox where other members can send you messages, and in a few minutes I got a new one:</p>
<p><img class="aligncenter size-full wp-image-3426" title="spamtwittermessage" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/spamtwittermessage.png" alt="" width="648" height="195" /></p>
<p>To follow my research, I clicked on the message to take a look at it, but sadly I got this:</p>
<p><a href="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/spamtwitter3.png"><img class="aligncenter size-full wp-image-3420" title="spamtwitter3" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/spamtwitter3.png" alt="" width="675" height="617" /></a></p>
<p>So you can get messages but to read them you have to upgrade to a silver or gold account&#8230; and it is not cheap:</p>
<p><img class="aligncenter size-full wp-image-3427" title="spamtwittermessage2" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/spamtwittermessage2.png" alt="" width="670" height="583" /></p>
<p>When I took my credit card my wife came to the room and I had to stop the research <img src='http://pandalabs.pandasecurity.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Sex%2C+lies+and+Twitter+http://tinyurl.com/72t4cff" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/sex-lies-and-twitter/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
		<item>
		<title>Megaupload and the cybercrime fight</title>
		<link>http://pandalabs.pandasecurity.com/megaupload-and-the-cybercrime-fight/</link>
		<comments>http://pandalabs.pandasecurity.com/megaupload-and-the-cybercrime-fight/#comments</comments>
		<pubDate>Fri, 20 Jan 2012 07:58:47 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[Cyber Protest]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[Hacktivists]]></category>
		<category><![CDATA[Anonymous]]></category>
		<category><![CDATA[Department of Justice]]></category>
		<category><![CDATA[FBI]]></category>
		<category><![CDATA[Megaupload]]></category>
		<category><![CDATA[RIAA]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3408</guid>
		<description><![CDATA[As most of you already now, yesterday Megaupload was closed by the FBI, accused of &#8220;copyright infringement&#8221;. You can read FBI&#8217;s press release here where the details of the case are explained, and you can see how each accused person in this case could face 50 years jail time. We should be concerned, as the [...]]]></description>
			<content:encoded><![CDATA[<p>As most of you already now, yesterday Megaupload was closed by the FBI, accused of &#8220;copyright infringement&#8221;. You can read FBI&#8217;s press release <a title="FBI Press Release" href="http://www.fbi.gov/news/pressrel/press-releases/justice-department-charges-leaders-of-megaupload-with-widespread-online-copyright-infringement" target="_blank">here</a> where the details of the case are explained, and you can see how each accused person in this case could face 50 years jail time.</p>
<p>We should be concerned, as the next step could be to close Google or Bing, at the end of the day we all use it to find the stuff we want, and I have seen many times results in those search engines with Megaupoad links. And what next? Will they close Internet?</p>
<p>Anonymous has of course reacted, and has started DDoS attacks against a number of different websites, among the targets we can find the Department of Justice, the RIAA, and Universal Music. Again, the best way Anonymous is able to come up with is to launch DDoS attacks. They could try to give information to the people, etc. but that is boring for them, it  is way funnier to break the law.</p>
<p>Going back to the press release, you can also read this:</p>
<blockquote><p>This case is part of efforts being undertaken by the  Department of  Justice Task Force on Intellectual Property (IP Task  Force) to stop the  theft of intellectual property.</p></blockquote>
<p>Meanwhile, in the real world, thousands of millions of dollars are  stolen every year by cybercriminals (real money, taken from users&#8217; credit cards and bank accounts). But as long as there is no theft of  intellectual property, that&#8217;s ok. Wait a moment,<span style="color: #000000;"> </span><span style="color: #ff0000;"><span style="color: #000000;">is that OK?</span><strong> </strong><span style="color: #000000;"><strong>Maybe some priorities should be adjusted</strong>. </span><strong><br />
</strong></span></p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Megaupload+and+the+cybercrime+fight+http://tinyurl.com/89dzf7e" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/megaupload-and-the-cybercrime-fight/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>The Rise of the Ransomware</title>
		<link>http://pandalabs.pandasecurity.com/the-rise-of-the-ransomware/</link>
		<comments>http://pandalabs.pandasecurity.com/the-rise-of-the-ransomware/#comments</comments>
		<pubDate>Thu, 19 Jan 2012 11:18:03 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Rogueware]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[police]]></category>
		<category><![CDATA[Ransomware]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3389</guid>
		<description><![CDATA[In the last months we have seen an increase of ransomware attacks. While the first ones we saw were posing as Microsoft to threaten the user because it had been detected a pirated version of Windows, and in case you didn&#8217;t pay the fine they would contact the local law enforcement agencies, the new ones [...]]]></description>
			<content:encoded><![CDATA[<p>In the last months we have seen an increase of ransomware attacks. While the first ones we saw were <a title="Ransomware Microsoft" href="http://pandalabs.pandasecurity.com/ransomware-posing-as-microsoft/" target="_self">posing as Microsoft </a>to threaten the user because it had been detected a pirated version of Windows, and in case you didn&#8217;t pay the fine they would contact the local law enforcement agencies, the new ones are posing as the very same law enforcement agencies.</p>
<p>While we are use to see this kind of fake messages in English, in this case the attacks are localized, we have seen English, German, Spanish or Dutch language (among others), depending on the targeted country. All of the attacks are targeting some European country, so it looks like that all of them are related and the same cibercriminal gang could be behind them.</p>
<p>The last one has appeared a couple of days ago, this time it is targeting Spain. The file is using as icon the following <em>Internet meme</em>:</p>
<p><img class="aligncenter size-full wp-image-3393" title="meme" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/meme.jpg" alt="" width="233" height="216" /></p>
<p>Once infected, this is what you will see in your desktop:</p>
<p><img class="aligncenter size-full wp-image-3397" title="malware_policia" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/malware_policia1.jpg" alt="" width="710" height="515" /></p>
<p>In the message it says that it has been detected access to illegal material (such as child pornography and spam about terrorism) from that computer, and that  the computer will be locked to prevent such a use. To solve that you have to pay a fine of €100:</p>
<p>The worst thing for the user is that it actually blocks the computer, so it is not easy to remove. To do it, restart the computer in safe mode and run a scan with an <a href="http://www.cloudantivirus.com" target="_blank">antivirus solution</a> that is able to detect it.</p>
<p>These are different examples we have seen in the last months:</p>
<div id="attachment_3398" class="wp-caption aligncenter" style="width: 520px"><a href="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/Poli-UK2.jpg"><img class="size-full wp-image-3398" title="UK" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/Poli-UK2.jpg" alt="" width="510" height="327" /></a><p class="wp-caption-text">English</p></div>
<div id="attachment_3399" class="wp-caption aligncenter" style="width: 510px"><a href="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/Poli-Italiana2.jpg"><img class="size-full wp-image-3399" title="Poli Italiana2" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/Poli-Italiana2.jpg" alt="" width="500" height="378" /></a><p class="wp-caption-text">Italian</p></div>
<div id="attachment_3400" class="wp-caption aligncenter" style="width: 529px"><img class="size-full wp-image-3400" title="Poli Dutch" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/Poli-Dutch.jpg" alt="" width="519" height="363" /><p class="wp-caption-text">Dutch</p></div>
<div id="attachment_3401" class="wp-caption aligncenter" style="width: 528px"><img class="size-full wp-image-3401" title="Poli alemana" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/Poli-alemana.png" alt="" width="518" height="415" /><p class="wp-caption-text">German</p></div>
<div id="attachment_3402" class="wp-caption aligncenter" style="width: 528px"><img class="size-full wp-image-3402" title="Poli Spa" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2012/01/Poli-Spa.jpg" alt="" width="518" height="348" /><p class="wp-caption-text">Spanish</p></div>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=The+Rise+of+the+Ransomware+http://tinyurl.com/6ulamut" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/the-rise-of-the-ransomware/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>2012 Security Trends</title>
		<link>http://pandalabs.pandasecurity.com/2012-security-trends/</link>
		<comments>http://pandalabs.pandasecurity.com/2012-security-trends/#comments</comments>
		<pubDate>Thu, 15 Dec 2011 12:26:02 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[PandaLabs]]></category>
		<category><![CDATA[Security Reports]]></category>
		<category><![CDATA[2012]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[trends]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3384</guid>
		<description><![CDATA[2011 is coming to an end, so now it&#8217;s time to try to see what we have to expect for the next 12 months: Social networks: Social engineering techniques exploiting users’ weaknesses have become the leading attack method in social networks. Trending topics such as the Olympics or the next US Presidential elections will be [...]]]></description>
			<content:encoded><![CDATA[<p>2011 is coming to an end, so now it&#8217;s time to try to see what we have to expect for the next 12 months:</p>
<ul>
<li><strong>Social networks</strong>: Social engineering techniques exploiting users’ weaknesses have become the leading attack method in social networks. Trending topics such as the Olympics or the next US Presidential elections will be used as a bait. Cybercriminals will continue to target social media sites to steal personal data.</li>
</ul>
<ul>
<li><strong>Malware increase</strong>: In the past few years, the number of malware threats has grown exponentially, and everything seems to indicate that the trend will continue in 2012. In fact, malware is the weapon use by cybercriminals to carry on their attacks.</li>
</ul>
<ul>
<li><strong>Trojans</strong>: they are cyber-crooks’ weapon of choice for their attacks, as shown by the fact that three out of every four new malware strains created in 2011 were Trojans, designed to sit silently on users’ computers and steal their information.</li>
</ul>
<ul>
<li><strong>Cyberwar</strong>: or maybe it is more accurate to say cyberespionage. 2011 has been the year with most intrusions ever aimed at companies and government agencies. From New Zealand to Canada, from Japan to the European Parliament, there have been countless attacks aimed at stealing secret or classified information. We live in a world where all the information is in digital form, so modern-day spies no longer need to infiltrate a building to steal information. As long as they have the necessary computer skills, they can wreak havoc and access the best-kept secrets of organizations without ever leaving their living-rooms. In 2012 we will see these kind of attacks even more.</li>
</ul>
<ul>
<li><strong>Mac malware</strong>: As the market share of Mac users continues to grow, the number of threats will grow. Fortunately enough, it seems that Mac users are now more aware that Mac is not immune to malware attacks and they are increasingly using antivirus programs, hindering cyber-crooks. The number of malware specimens for Mac will continue to grow in 2012, although much less than for PCs</li>
</ul>
<ul>
<li><strong>Mobile malware</strong>: Over ten years ago, antivirus companies started making dire predictions of a mobile malware epidemic. Years later, as the situation was not as apocalyptic as predicted, they started claiming that the installation of antivirus software on mobile phones had prevented the catastrophe. Well, they were wrong again. If having an antivirus solution were enough to solve all types of malware problems, the world would be a happier place. Unfortunately though, both users and security vendors alike are in the hands of cyber-crooks, who are the ones who decide which platform to target. In this context, last year PandaLabs predicted a surge in cyber attacks on mobile phones, and the fact that Android has become the number one mobile target for cyber-crooks in 2011 confirms that prediction. In 2012 there will be new attacks on Android, but it will not be on a massive scale. New mobile payment methods –via NFC for example– could become the next big target for Trojans but, as always, this will largely depend on their popularity.</li>
</ul>
<ul>
<li><strong>Malware for tablets</strong>: The fact that tablets share the same operating system as smartphones means that they will be soon targeted by the same malware as those platforms. In addition, tablets might draw a special interest from cyber-crooks as people are using them for an increasing number of activities and they are more likely to store sensitive data than, say, a smartphone.</li>
</ul>
<ul>
<li><strong>Cybercriminals targeting small to medium-sized companies</strong>: Why do cybercriminals target online banking customers instead of directly attacking banking institutions to steal money? The answer to this question has to do with the cost-benefit ratio of the attack: Financial entities are usually very well protected, and the chance of launching a successful attack is remote and very costly. However, attacking their customers to steal their identity and impersonate them is much simpler. The security of small to medium-sized companies is not that strong, and this makes them very attractive for cyberthieves, who can steal data from hundreds or thousands of users in one go. On many occasions, small to medium-sized companies do not have dedicated security teams, which makes them much more vulnerable.</li>
</ul>
<ul>
<li><strong>Windows 8</strong>: The next version of Microsoft’s popular operating system is scheduled for November 2012, so even though it is not supposed to have much on an impact on the malware landscape in the coming year, it will surely offer cyber-crooks new opportunities to create malicious software. Windows 8 will allow users to develop applications for virtually any device (PCs, tablets and smartphones) running Windows 8, so it will be possible to develop malicious applications like those for Android. This, in any event, will probably not take place until 2013.</li>
</ul>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=2012+Security+Trends+http://tinyurl.com/cvwp9bo" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/2012-security-trends/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Could targeted attacks be avoided?</title>
		<link>http://pandalabs.pandasecurity.com/could-targeted-attacks-be-avoided/</link>
		<comments>http://pandalabs.pandasecurity.com/could-targeted-attacks-be-avoided/#comments</comments>
		<pubDate>Fri, 02 Dec 2011 11:37:47 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Vulnerabilities & Exploits]]></category>
		<category><![CDATA[Duqu]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[targeted attack]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3374</guid>
		<description><![CDATA[This could be a long blog post, but I&#8217;ll try to make it short. However, for those of you that are lazy, here you can read the answer to the question, and the ones interested on the whole story (I will make it short, I promise) just follow the * mark: NO (*) (*): One [...]]]></description>
			<content:encoded><![CDATA[<p>This could be a long blog post, but I&#8217;ll try to make it short. However, for those of you that are lazy, here you can read the answer to the question, and the ones interested on the whole story (I will make it short, I promise) just follow the * mark:</p>
<p><strong>NO</strong> <strong>(*)</strong></p>
<p><strong>(*)</strong>: One of the characteristics of a targeted attack is that the attacker has previously studied the victim (who is a specific person or organization). This attacker will study the victim: Which systems he is running, where the most valuable information is located, what defenses are built in place, etc. And not only that, also the person(s) will be investigated, in which fields are they working, what hobbies they have, etc. This is why it is almost impossible to avoid these kinds of attacks. However, this is not a reason to lower our defenses, and that&#8217;s something that really puzzles me: taking a look at some of the major attacks we have seen in the last years, many of them were possible because there were servers with no antivirus protection, with an outdated operating system, etc. In a single word: <strong>negligence</strong>.</p>
<p>However, this is not always the case. If we take a look at the 2 most important attacks that have happened during 2011 (the RSA incident and the Duqu case) we will see that both attacks were really sophisticated, and that the way to start the intrusion was a mix of social engineering mixed with some kind of software vulnerability. I would like to point out that in both cases users were receiving a document, and once it was opened the document dropped and run a file in the system, and from that moment on the system was compromised. Of course, these kind of attacks can be done using known or unkown vulnerabilities, and you could argue that a user has no way to detect that a document is malformed in that way, and that the antivirus won&#8217;t detect a single thing as it will be new and the attacker has previously checked that the malware pieces involved were not detected: fair enough, I do agree with that.</p>
<p>And what if I tell you that if they had used Panda the attack would have failed? In 2004 we released TruPrevent technologies, with the goal to detect a portion of the brand new malware, that one that was still not detected with signatures. Since then we have included those technologies in our products, and one of those basically prevents that opening a document a file is downloaded and executed. Smart, nice, clean&#8230; <img src='http://pandalabs.pandasecurity.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Conclusion: in case RSA, or any of the companies attacked by Duqu, had used even the free version of <a href="http://www.cloudantivirus.com" target="_blank">Panda Cloud Antivirus</a> those intrusions wouldn&#8217;t have happened&#8230; <strong>IN THAT WAY</strong>. Anyway, remember the answer to the question (<strong>&#8220;NO&#8221;</strong>). Attackers would have figured out a way to circumvent it, probably trying a different kind of attack, but the harder we make it, the more chances we&#8217;ll have to avoid it.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Could+targeted+attacks+be+avoided%3F+http://tinyurl.com/d4e2lec" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/could-targeted-attacks-be-avoided/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

