<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PandaLabs Blog</title>
	<atom:link href="http://pandalabs.pandasecurity.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://pandalabs.pandasecurity.com</link>
	<description>Everything you need to know about Internet threats</description>
	<lastBuildDate>Fri, 26 Apr 2013 10:16:35 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>The Importance of Strong Passwords on Social Media</title>
		<link>http://pandalabs.pandasecurity.com/the-importance-of-strong-passwords-on-social-media/</link>
		<comments>http://pandalabs.pandasecurity.com/the-importance-of-strong-passwords-on-social-media/#comments</comments>
		<pubDate>Fri, 26 Apr 2013 10:16:35 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3685</guid>
		<description><![CDATA[Last Tuesday, April 23, the Twitter account of the Associated Press news agency was hacked and sent out a hoax tweet reporting that President Barack Obama had been injured by an explosion in the White House. Within seconds, Wall Street was in panic mode and US stock plunged. Situations like this illustrate once again the [...]]]></description>
				<content:encoded><![CDATA[<p>Last Tuesday, April 23, the Twitter account of the Associated Press news agency was hacked and sent out a hoax tweet reporting that President Barack Obama had been injured by an explosion in the White House. Within seconds, Wall Street was in panic mode and US stock plunged.</p>
<p>Situations like this illustrate once again the dangers of using weak passwords not only for home users but in corporate environments as well. Today, social networking sites are very often the first point of contact between users and companies, and special care should be taken to strengthen the security of social media accounts.</p>
<p>When a Twitter account is hacked, the public normally thinks it has been the result of some highly sophisticated attack perpetrated with complex programs and all sorts of stealth systems only accessible to some privileged minds… Well, in reality, things are usually much simpler. In most cases, the so-called “hacker” simply guess their victim‘s password. The most complex attacks are actually those where the attacker tricks the user into re-entering their credentials in some system unaware of the fact that, in reality, they are submitting their data to a cyber-criminal (which, by the way, was exactly what happened in the AP Twitter hack).</p>
<p>Two months ago, Burger King’s Twitter account was also hacked. Its background picture was changed to a McDonald’s image, and a message was posted announcing that the company had been sold to their rivals. It is not known what password Burger King used, but I would say “whopper” is one of the safest bets… The AP attack might look like an isolated incident, but unfortunately these attacks are far more common than it seems. In fact, the group behind the hack, the self-proclaimed “Syrian Electronic Army”, also hacked the Twitter accounts of watchdog organization Human Rights Watch, French news service France 24 and the BBC’s weather service.</p>
<p>But it is not only Twitter accounts that are at risk. Many of us still remember the theft of a series of compromising photos from Scarlett Johansson’s cell phone for example. Preliminary investigation seemed to indicate that a hacker had been able to launch a cyber-attack on the American actress’s cell phone, accessing her personal information. Later, however, it was found out that the ‘hacker’  was simply a man with a penchant for hacking into celebrities’ accounts who had been able to guess the star’s email address password.</p>
<p>Let me finish by offering you a series of simple tips about social media passwords that will help you protect yourselves from this type of attack:</p>
<ul>
<li>Size matters: The longer the password, the safer it will be.</li>
<li>Do not use personal information (your name, your phone number, etc.) to create passwords.</li>
<li>NEVER use the same password for multiple accounts.</li>
<li>Use passwords that are a combination of numbers, letters and special characters. The more complex the password, the safer it will be.</li>
<li>Change your passwords frequently.</li>
</ul>
<p>Do not reveal your passwords or send them via email.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=The+Importance+of+Strong+Passwords+on+Social+Media+http://tinyurl.com/bu2nufx" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/the-importance-of-strong-passwords-on-social-media/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Twitter, Facebook, Apple, Microsoft&#8230; who is left?</title>
		<link>http://pandalabs.pandasecurity.com/twitter-facebook-apple-microsoft-who-is-left/</link>
		<comments>http://pandalabs.pandasecurity.com/twitter-facebook-apple-microsoft-who-is-left/#comments</comments>
		<pubDate>Wed, 06 Mar 2013 08:44:44 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[Vulnerabilities & Exploits]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3678</guid>
		<description><![CDATA[If we had to elaborate a list with the top tech companies who have being hacked in the last weeks, we should include all the ones in the title of this blog post, and maybe a few more cases we are still not aware of. The first one was Twitter. On February 1st Twitter published [...]]]></description>
				<content:encoded><![CDATA[<p>If we had to elaborate a list with the top tech companies who have being hacked in the last weeks, we should include all the ones in the title of this blog post, and maybe a few more cases we are still not aware of.</p>
<p>The first one was Twitter. On February 1st Twitter published an article in their blog, &#8220;<a href="http://blog.twitter.com/2013/02/keeping-our-users-secure.html">Keeping our users secure</a>&#8220;. They explained they had been victims of an attack, and that information from 250,000 users had been accessed.</p>
<p>A couple of weeks later, Facebook published an article in their blog, titled &#8220;<a href="https://www.facebook.com/notes/facebook-security/protecting-people-on-facebook/10151249208250766">Protecting People On Facebook</a>&#8220;. It looks like no customer data was compromised in this attack.</p>
<p>The next victim was Apple, just a few days after Facebook announcement, they told <a href="http://www.reuters.com/article/2013/02/19/us-apple-hackers-idUSBRE91I10920130219">Reuters</a> they had also been targeted using the same attack.</p>
<p>And last, but not least, Microsoft <a href="https://blogs.technet.com/b/msrc/archive/2013/02/22/recent-cyberattacks.aspx?Redirected=true">recognized</a> they also had been victims of the same attack.</p>
<p>Not a bad list of companies, isnt&#8217;t it? Maybe we will see some more (Google is in the same target level, for example, or Amazon, or IBM&#8230;) but that&#8217;s not the point of this article. What can we learn? Of course there is a lot of information we don&#8217;t know yet, however we can see some positive outcome and 1very important task to do:</p>
<p>- Companies are not afraid of recognizing being targets of this kind of attacks.</p>
<p>- They have good security teams which have been able to identify the attacks as they were taking place.</p>
<p><strong>Task to do:  </strong>We all should stop using Java in the browser. All these attacks were successful thanks to yet another 0-day vulnerability in Java. Disable it now.</p>
<p>People involved in computer security know that there is not a 100% safe place. You can take a number of preventive measures, and they will work well most of the times. But there is always some weak point, some new vulnerability, some human error, and out of the thousands of attacks that such big companies receive on a daily basis, one could succeed.</p>
<p>And being able to identify a current attack is critical. And Twitter, Facebook, Apple and Microsoft were able. They all are gathering information about the attack. They all are working with law enforcement to find out who is behind this attack.</p>
<p>If you are responsible for a medium / small company, you may think you do not have to worry as much as those biggies as you are not such a sexy target. That is partially true, you probably will get a small number of targeted attacks (if any), however you will be hit constantly with the usual cybercrime attacks that infect millions of computers.</p>
<p>According to PandaLabs 2012 Anual Report, 1/3 of all computers were infected at some point last year. And cybercriminals love low-hanging fruit. If you have computers without protection, without updated software, without a serious security plan, you will be the next.</p>
<p>Most computer infections nowadays come from exploit kits, which will infect the user&#8217;s computer without his knowledge through some software vulnerability. More than a 90% of these cases are Java vulnerabilites through the browser, so the best way to avoid these infections is simple: DISABLE JAVA IN YOUR BROWSER. NOW. WHAT ARE YOU WAITING FOR?</p>
<p>If for any reason you need Java in the browser to run some application, then use it in a secondary browser.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Twitter%2C+Facebook%2C+Apple%2C+Microsoft%E2%80%A6+who+is+left%3F+http://tinyurl.com/a9zypbt" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/twitter-facebook-apple-microsoft-who-is-left/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A look back at cyber-security in 2012</title>
		<link>http://pandalabs.pandasecurity.com/a-look-back-at-cyber-security-in-2012/</link>
		<comments>http://pandalabs.pandasecurity.com/a-look-back-at-cyber-security-in-2012/#comments</comments>
		<pubDate>Fri, 22 Feb 2013 10:28:25 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3673</guid>
		<description><![CDATA[]]></description>
				<content:encoded><![CDATA[<p style="text-align: center;"><a href="http://pandalabs.pandasecurity.com/wp-content/uploads/2013/02/PandaLabs_Annual_Report_2012.jpg"><img class="aligncenter  wp-image-3674" alt="PandaLabs_Annual_Report_2012" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2013/02/PandaLabs_Annual_Report_2012-1024x894.jpg" width="614" height="536" /></a></p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=A+look+back+at+cyber-security+in+2012+http://tinyurl.com/bkqgltw" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/a-look-back-at-cyber-security-in-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Police Virus Infections On The Rise</title>
		<link>http://pandalabs.pandasecurity.com/police-virus-infections-on-the-rise/</link>
		<comments>http://pandalabs.pandasecurity.com/police-virus-infections-on-the-rise/#comments</comments>
		<pubDate>Thu, 21 Feb 2013 15:47:38 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3662</guid>
		<description><![CDATA[Last week I congratulated Spanish National Police for the fantastic job done that took down a cybercrime gang that was using the known &#8220;police virus&#8221;, but I already pointed out that this was not going to be the end of this threat, as most likely there were a number of different gangs using the same [...]]]></description>
				<content:encoded><![CDATA[<p>Last week I congratulated Spanish National Police for the fantastic job done that took down a cybercrime gang that was using the known &#8220;police virus&#8221;, but I already pointed out that this was not going to be the end of this threat, as most likely there were a number of different gangs using the same kind of attacks.</p>
<p>I talked about different evidences that indicated this fact: different techniques within the malware that were not used anymore suddenly appear again (encription of files in the infected computers, for example), how to perform the same actions (like showing the fake police warning screen) were performed in completely different ways, showing that they were different projects, or how we are still seeing new attacks performed on a daily basis.</p>
<p>Anyway I decided to pull the thread and look for some figures to see if they are coherent with the previously described evidences. In most of the cases, computers get infected via the infamous &#8220;exploit kits&#8221;, tools used by cybercriminals to install different malware just visiting a compromised web site without user intervention. To achieve this, exploit kits use different security holes in software installed in the computer, most of them based on Java or Adobe, as this is very popular software with hundreds of millions of users and with -sadly- many security holes. To make it worst, many users do not bother updating that software, which is like having an open door in your computer with a big sign saying &#8220;please infect me&#8221;. In short: infecting computers is child&#8217;s play in many cases.</p>
<p>This is why some months ago we deployed a new technology in Panda Cloud Antivirus that allows to stop infection attempts that try to use this kind of vulnerabilities (even when it is an unknown vulnerability) and furthermore it sends information to our cloud with data of the malware file that was trying to infect the system.</p>
<p>Out of all the data,  I have extracted a couple of different families that belong to the police virus to see how many infections have we stopped since December 2012 until mid February 2013. In other words, we are talking about Panda Cloud Antivirus users that while on the Internet were attacked with an exploit they had no protection for (his software wasn&#8217;t updated, most of them Java related) and which aim was to infect them with any of these particular 2 families of the police virus.</p>
<p>The Russian head of the cybercriminal gang was arrested in Dubai last December. If this was really the only gang behind these attacks, as we have seen in some media, the number should have dropped considerably. However, this is the result:</p>
<p><a href="http://pandalabs.pandasecurity.com/wp-content/uploads/2013/02/Infections.jpg"><img class="aligncenter size-full wp-image-3666" alt="Infections" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2013/02/Infections.jpg" width="640" height="449" /></a></p>
<p>As we can see, the number of blocked infections is not going down, it has increased by 2! This is a proof that shows how we will have to deal with this police virus for a long time, war is not over yet (as usual <img src='http://pandalabs.pandasecurity.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> )</p>
<p>These 2 families, as well as many others, are detected by Panda with the name Trj/Ransom.AB. If you have been already infected and need some help, our Technical Support team have the <a href="http://www.pandasecurity.com/usa/homeusers/support/card?id=1673">following instructions</a> that work really well to solve all your problems.</p>
<p>Finally, some advices to avoid becoming a victim of these cybercriminal gangs:</p>
<p>- Update. All installed software. From the operating system to any other software you have in your computer. Don&#8217;t be lazy, it is worth it <img src='http://pandalabs.pandasecurity.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>- Uninstall any Java plugin in the browser. You don&#8217;t need it and you get rid of a HUGE risk. Not only this, unless you need Java to run some local application in your computer, remove it completely. I did this long time ago. An ounce of prevention is worth a pound of cure.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Police+Virus+Infections+On+The+Rise+http://tinyurl.com/bd46oq7" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/police-virus-infections-on-the-rise/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Operation Ransom: Police Virus authors arrested</title>
		<link>http://pandalabs.pandasecurity.com/operation-ransom-police-virus-authors-arrested/</link>
		<comments>http://pandalabs.pandasecurity.com/operation-ransom-police-virus-authors-arrested/#comments</comments>
		<pubDate>Thu, 14 Feb 2013 12:31:06 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3655</guid>
		<description><![CDATA[Today, we have some important news to share with you. Our friends in the Technological Investigation Brigade of Spain’s National Police,  together with Europol and Interpol, have dismantled the cyber-crime ring responsible for the &#8220;Police Virus&#8221;. According to the news release published by Spain’s Ministry of Home Affairs, the police have arrested ten members of [...]]]></description>
				<content:encoded><![CDATA[<p>Today, we have some important news to share with you. Our friends in the Technological Investigation Brigade of Spain’s National Police,  together with Europol and Interpol, have dismantled the cyber-crime ring responsible for the &#8220;Police Virus&#8221;. According to the news release <a href="http://www.lamoncloa.gob.es/ServiciosdePrensa/NotasPrensa/MIR/2013/130213policiainformatica.htm">published by Spain’s Ministry of Home Affairs</a>, the police have arrested ten members of the computer hacking group, responsible for taking in around 1 million euros per year from victims of their scams. The arrested people include six Russians, two Ukranians and two Georgians, all of them living in Spain.</p>
<p>The head of the gang –a citizen of Russian origin &#8211; was also arrested in the operation. Oddly enough, and despite his origin, he was arrested in Dubai while on vacation, and awaits extradition to Spain. The operation remains open and more arrests could be forthcoming.</p>
<p>In any event, and before we all start celebrating, it must be said that in our opinion, based on our research of the Police Virus, there is more than one group behind the attacks. We’ve reached this conclusion after having studied multiple variants of this malware over time and having detected numerous striking differences among them.</p>
<p>Here on this blog we have posted <a href="http://pandalabs.pandasecurity.com/the-rise-of-the-ransomware/">several reports</a> on the Police Virus and its <a href="http://pandalabs.pandasecurity.com/the-rise-of-the-ransomware-police-virus-reloaded/">evolution</a> over time. This evolution is absolutely normal and it doesn’t necessarily mean that there are various teams behind the attacks, as it is quite normal for cyber-criminals to try different techniques to infect as many people as possible.</p>
<p>However, there is other evidence to the contrary: We saw how certain techniques that had apparently been abandoned (like the encryption of files on the victim’s computer) were suddenly put to use again; or how different variants used completely different techniques to achieve the same results (display a fake police warning on screen). All the evidence seems to indicate that we are dealing with different projects.</p>
<p>This wouldn’t be too surprising after all. If you analyze the situation from a purely commercial point of view, it would be something like this: someone comes up with a money-making idea, and others copy it quickly to get the same results. It happens all the time. In this particular case, it seems that there are different gangs ‘in the same line of business’.</p>
<p>Another clear evidence of this is the fact that the attacks keep repeating, even at this very minute: There are new Police Virus infections asking for their €100 fine. Here are a couple of screenshots of two new variants we have detected a couple of minutes ago as I was typing these lines:</p>
<p><a href="http://pandalabs.pandasecurity.com/wp-content/uploads/2013/02/Poli1.jpg"><img class="aligncenter size-full wp-image-3656" alt="Poli1" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2013/02/Poli1.jpg" width="711" height="557" /></a></p>
<p>&nbsp;</p>
<p><a href="http://pandalabs.pandasecurity.com/wp-content/uploads/2013/02/Poli2.jpg"><img class="aligncenter size-full wp-image-3657" alt="Poli2" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2013/02/Poli2.jpg" width="680" height="543" /></a></p>
<p>Anyway, this is still good news for everyone: another cyber-crime ring has been dismantled, and law enforcement agencies around the world keep making progress towards defeating the cyber threat.</p>
<p>&nbsp;</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Operation+Ransom%3A+Police+Virus+authors+arrested+http://tinyurl.com/cvo3ykx" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/operation-ransom-police-virus-authors-arrested/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Saint Valentine: tips to avoid falling victim to computer threats</title>
		<link>http://pandalabs.pandasecurity.com/saint-valentine-tips-to-avoid-falling-victim-to-computer-threats/</link>
		<comments>http://pandalabs.pandasecurity.com/saint-valentine-tips-to-avoid-falling-victim-to-computer-threats/#comments</comments>
		<pubDate>Tue, 12 Feb 2013 14:52:38 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[Valentine]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3652</guid>
		<description><![CDATA[I do not want to bore you to death, just a few tips on the topic -       Do not run attached files that come from unknown sources. Stay on alert for files that claim to be Valentine Day’s greeting cards, romantic videos, etc. -       Do not open emails or messages received on social networks from [...]]]></description>
				<content:encoded><![CDATA[<p>I do not want to bore you to death, just a few tips on the topic <img src='http://pandalabs.pandasecurity.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>-       Do not run attached files that come from unknown sources. Stay on alert for files that claim to be Valentine Day’s greeting cards, romantic videos, etc.</p>
<p>-       Do not open emails or messages received on social networks from unknown senders.</p>
<p>-       Do not click any links included in email messages, even though they may come from reliable sources. It is better to type the URL directly in the browser. This rule applies to messages received through any mail client, as well as those in Facebook, Twitter, or other social networks or messaging applications, etc. If you do click on any such links, take a close look at the page you arrive at and if you don’t recognize it, close your browser.</p>
<p>-       Even if the page seems legitimate, but asks you to download something, you should be suspicious and don’t accept the download. If you download and install any type of executable file and you begin to see unusual messages on your computer, you have likely been infected with malware.</p>
<p>-       If you are making any purchases online, type the address of the store in the browser, rather than going through any links that have been sent to you. Only buy online from sites that have a solid reputation and offer secure transactions, encrypting all information that is entered in the page.</p>
<p>-       Do not use shared or public computers, or an unsecured WiFi connection, for making transactions or operations that require you to enter passwords or other personal details.</p>
<p>-       Have an effective security solution installed, capable of detecting both known and new malware strains.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Saint+Valentine%3A+tips+to+avoid+falling+victim+to+computer+threats+http://tinyurl.com/cpdkovu" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/saint-valentine-tips-to-avoid-falling-victim-to-computer-threats/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>PandaLabs Annual Report &#8211; 2012</title>
		<link>http://pandalabs.pandasecurity.com/pandalabs-annual-report-2012/</link>
		<comments>http://pandalabs.pandasecurity.com/pandalabs-annual-report-2012/#comments</comments>
		<pubDate>Wed, 06 Feb 2013 09:36:08 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[PandaLabs]]></category>
		<category><![CDATA[Security Reports]]></category>
		<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[2012]]></category>
		<category><![CDATA[annual report]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trends]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3645</guid>
		<description><![CDATA[Today we are publishing the latest PandaLabs Annual Report, covering the major security news happened during 2012, from mobile malware to cyber-war, covering all major events in different areas such as social netwoks. &#160; We cover also the security trends for 2013, as well as some of the main figures related to malware: &#160; &#160; [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://pandalabs.pandasecurity.com/wp-content/uploads/2013/02/2012-annual-report.png"><img class="alignleft size-full wp-image-3646" style="border: 1px solid black; margin-left: 10px; margin-right: 10px;" alt="2012 annual report" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2013/02/2012-annual-report.png" width="376" height="265" /></a> Today we are publishing the latest PandaLabs Annual Report, covering the major security news happened during 2012, from mobile malware to cyber-war, covering all major events in different areas such as social netwoks.</p>
<p>&nbsp;</p>
<p>We cover also the security trends for 2013, as well as some of the main figures related to malware:</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>-       27 million new malware strains found in 2012, at an average of 74,000 new samples per day.</p>
<p>-       Three out of every four malware infections were caused by Trojans.</p>
<p>-       China, South Korea and Taiwan are the world’s most infected countries.</p>
<p>The full report is available <a href="http://press.pandasecurity.com/press-room/reports/">here</a>.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=PandaLabs+Annual+Report+%E2%80%93+2012+http://tinyurl.com/a72jowd" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/pandalabs-annual-report-2012/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Facebook spam leads to Exploit Kit</title>
		<link>http://pandalabs.pandasecurity.com/facebook-spam-leads-to-exploit-kit/</link>
		<comments>http://pandalabs.pandasecurity.com/facebook-spam-leads-to-exploit-kit/#comments</comments>
		<pubDate>Fri, 01 Feb 2013 10:55:39 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3637</guid>
		<description><![CDATA[To no wonders, the Blackhole Exploit Kit is still trying to infect users. One of the techniques commonly used is to send the victim an email from for example Facebook, Linkedin, Twitter, &#8230;. Asking to click on a link. We&#8217;ll take a small peek at those tactics. We received the following email: &#160; Hi , You [...]]]></description>
				<content:encoded><![CDATA[<p>To no wonders, the Blackhole Exploit Kit is still trying to infect users. One of the techniques commonly used is to send the victim an email from for example Facebook, Linkedin, Twitter, &#8230;. Asking to click on a link.</p>
<p>We&#8217;ll take a small peek at those tactics. We received the following email:</p>
<p><a href="http://pandalabs.pandasecurity.com/wp-content/uploads/2013/02/BP1.jpg"><img class="aligncenter size-full wp-image-3638" alt="BP1" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2013/02/BP1.jpg" width="320" height="171" /></a></p>
<p>&nbsp;</p>
<blockquote><p><i>Hi ,</i></p>
<p><i>You have disabled your Facebook account. You can restore your account at any moment by logging into Facebook using your old login email address and password. Subsequently you will be able to use the site in usual way.</i></p>
<p><i>Thanks,<br />
The Facebook Team</i></p></blockquote>
<p>Obviously, Facebook didn&#8217;t disable your account at all. There are some factors to easily determine this email is fake:</p>
<ul>
<li>The &#8216;From&#8217; field says it&#8217;s from &#8220;Facebook&#8221;, however, the sender is clearly &#8216;nondrinker@iztzg.hr&#8217;.</li>
<li>Have you disabled your account? If not, then there&#8217;s no reason to receive this mail.</li>
<li>The subject and the content of the email do not match.</li>
<li>Hovering over the links in the email reveals the real URL, which are not Facebook URLs.</li>
</ul>
<p>When clicking on any of the links, you are presented (after several redirects) with the Blackhole Exploit Kit (aka BH EK). It tries to load a Java exploit on the machine by firstly detecting which plugin and Java version you are using:</p>
<p><a href="http://pandalabs.pandasecurity.com/wp-content/uploads/2013/02/BP2.png"><img class="aligncenter size-full wp-image-3639" alt="BP2" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2013/02/BP2.png" width="314" height="106" /></a></p>
<p>&nbsp;</p>
<p>The payload? Probably ransomware or a Banker Trojan.</p>
<p><b>Prevention</b></p>
<p>Use the<a href="http://noscript.net/" target="_blank"> NoScript</a> add-on in Firefox or <a href="https://chrome.google.com/webstore/detail/notscripts/odjhifogjcknibkahlpidmdajjpkkcfn?hl=en" target="_blank">NotScripts</a> in Chrome to prevent this.</p>
<p>Use the <a href="https://www.mywot.com/" target="_blank">WOT </a>add-on to check on the status of a website.</p>
<p>Use your common sense and ask yourself the proper questions (see below).</p>
<p>Use a URL scanner if you&#8217;re unsure about a URL. Some examples are <a href="https://www.virustotal.com/#url" target="_blank">VirusTotal</a>, <a href="http://www.urlvoid.com/" target="_blank">URLvoid</a> and <a href="http://urlquery.net/" target="_blank">URLquery</a>.</p>
<p><b>Conclusion</b></p>
<p>As usual with this kind of emails, be alerted and always ask yourself the proper questions:</p>
<ul>
<li>Why did this get in my Unwanted Email or Spam folder if I normally get Facebook mails in my normal Inbox?</li>
<li>Why would Facebook send me this when my account isn&#8217;t disabled at all?</li>
<li>Why are those links not pointing to Facebook websites?</li>
<li>Why is the sender not from Facebook itself? What can I see in the headers?</li>
</ul>
<p>Use your common sense, update your 3d-party applications as well as Windows, and use a decent antimalware and antivirus product, like <a href="http://www.cloudantivirus.com">Panda Cloud Antivirus</a> free.</p>
<p><em>Author: Bart Parys</em></p>
<p><em>Source: <a href="http://bartblaze.blogspot.be/2013/01/facebook-spam-leads-to-exploit-kit.html">http://bartblaze.blogspot.be/2013/01/facebook-spam-leads-to-exploit-kit.html</a></em></p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=Facebook+spam+leads+to+Exploit+Kit+http://tinyurl.com/aoxdqx2" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/facebook-spam-leads-to-exploit-kit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to find out if you are receiving malware on Twitter</title>
		<link>http://pandalabs.pandasecurity.com/how-to-find-out-if-you-are-receiving-malware-on-twitter/</link>
		<comments>http://pandalabs.pandasecurity.com/how-to-find-out-if-you-are-receiving-malware-on-twitter/#comments</comments>
		<pubDate>Wed, 30 Jan 2013 09:23:17 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Social Networks]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[DM]]></category>
		<category><![CDATA[hacked]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3620</guid>
		<description><![CDATA[Social networks are actively used by cybercriminals to spread malware. The most common type of attacks in Twitter usually show the same behaviour: 1.- You get a Direct Message (DM) from one of your contacts, with a shortened link. 2.- You click on the link. 3.- Any (or even all) of the following options will [...]]]></description>
				<content:encoded><![CDATA[<p>Social networks are actively used by cybercriminals to spread malware. The most common type of attacks in Twitter usually show the same behaviour:</p>
<p>1.- You get a Direct Message (DM) from one of your contacts, with a shortened link.</p>
<p>2.- You click on the link.</p>
<p>3.- Any (or even all) of the following options will take place:</p>
<ul>
<li>A) You are taken to a Twitter like website and asked to enter your Twitter credentials.</li>
<li>B) You are taken to a spam website (which also could try to infect you through some drive-by-download trick)</li>
<li>C) You are asked to download a file which will be some kind of Trojan.</li>
</ul>
<p>Usually this is how it works, although some days ago it caught my attention a slightly different approach. This one, instead of sending you a DM it mentions you with some funny comment and a link.</p>
<p>These are some of the message that were being sent out from a compromised user account:</p>
<p><a href="http://pandalabs.pandasecurity.com/wp-content/uploads/2013/01/twitter_mention.png"><img class="aligncenter size-full wp-image-3625" alt="twitter_mention" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2013/01/twitter_mention.png" width="442" height="528" /></a></p>
<p>If the mentioned Twitter user clicks on the link, he will get to the following web:</p>
<p><a href="http://pandalabs.pandasecurity.com/wp-content/uploads/2013/01/facebook.png"><img class="aligncenter size-full wp-image-3626" alt="facebook" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2013/01/facebook.png" width="747" height="305" /></a></p>
<p>Of course if you download and run the file, your computer will be infected, a nice Trojan for the collection.</p>
<p>The reason for using mentions is that you can mention anyone, while you can only send DMs to your followers, so potentially it could spread faster. However, people tend to trust more on DMs as they come from a &#8220;trusted&#8221; source (at least it is someone you are actively following) so the infection ratio per tweet sent will be higher using DMs.</p>
<p>Another option (we haven&#8217;t seen it yet, but I guess it is just a matter of time) is a mix of both techniques, sending DMs to your followers and mentions to the rest of the Twitter users.</p>
<p>Remember, do not trust anyone you don&#8217;t know, and beware of your friends as their accounts could have been compromised <img src='http://pandalabs.pandasecurity.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>And finally, if even after following my advice your Twitter account is hacked, do the following:</p>
<p>A) If you can still log into your account, change your password IMMEDIATELY.</p>
<p>B) If your password has been changed and you cannot access your account anymore, follow <a href="https://support.twitter.com/articles/185703-my-account-is-compromised-hacked-and-i-can-t-log-in#" target="_blank">these instructions</a> from the Twitter team.</p>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=How+to+find+out+if+you+are+receiving+malware+on+Twitter+http://tinyurl.com/bcsdgm5" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/how-to-find-out-if-you-are-receiving-malware-on-twitter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>All that glitters is not gold</title>
		<link>http://pandalabs.pandasecurity.com/all-that-glitters-is-not-gold/</link>
		<comments>http://pandalabs.pandasecurity.com/all-that-glitters-is-not-gold/#comments</comments>
		<pubDate>Fri, 25 Jan 2013 12:55:40 +0000</pubDate>
		<dc:creator>Luis Corrons</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://pandalabs.pandasecurity.com/?p=3614</guid>
		<description><![CDATA[As the old saying goes, “All that glitters is not gold”. We live in a time of information abundance, overloaded with eye-catching news stories and links received via Twitter, Facebook, email, WhatsApp, LinkedIn and any other social networking site you may be on. The problem is that very often that information is nothing more than [...]]]></description>
				<content:encoded><![CDATA[<p>As the old saying goes, <em>“All that glitters is not gold”</em>. We live in a time of information abundance, overloaded with eye-catching news stories and links received via Twitter, Facebook, email, WhatsApp, LinkedIn and any other social networking site you may be on. The problem is that very often that information is nothing more than ‘noise’.</p>
<p>We’ve seen it before: Warnings claiming that Messenger is closing down (although this has turned out to be true <img src='http://pandalabs.pandasecurity.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> ), users can switch the blue color of their Facebook profiles by clicking a link, Twitter will become a paid-by-users service… Normally, these messages are nothing but harmless hoaxes, but sometimes they can have serious consequences.</p>
<p>One of the hottest topics lately has been the fragile health of Venezuelan President Hugo Chavez. In the rush to be first, the news media sometimes reports incorrect information or make blatant mistakes, as happened this week with Spain’s leading newspaper <a href="http://www.elpais.com/">El País</a>, which published a phony picture of President Hugo Chavez in his hospital bed. If such a prestigious newspaper as El País falls victim to a deception, just imagine what can happen to the rest of us, humble Internet users exposed to tons and tons of information and links we sometimes click without even thinking about it…</p>
<p>An email message purportedly containing a photo of Hugo Chavez. One link. One click. One Trojan. One infection. A massive infection of your company’s network. This is more common than you may think.</p>
<p><a href="http://pandalabs.pandasecurity.com/wp-content/uploads/2013/01/Stevejobs.jpg"><img class="aligncenter size-full wp-image-3615" alt="Stevejobs" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2013/01/Stevejobs.jpg" width="485" height="371" /></a></p>
<p>Remember when Steve Jobs passed away? Just a few hours after his death, a group of scammers had created a Facebook page called “R.I.P. Steve Jobs” which amassed more than 90,000 fans in just a few hours. The page contained a malicious URL and a text claiming that 50 free iPads were being given away ‘in memory of Steve Jobs’. However, to participate in the drawing, users were asked to enter personal details such as their name, phone number, email address, etc.</p>
<p>Another notorious scam, which affected a large number of Internet users, involved a supposed sex tape of Katy Perry and Russell Brand used to spread malware via Facebook at the beginning of the year 2012. Victims received the following message on their Facebook walls:</p>
<p><a href="http://pandalabs.pandasecurity.com/wp-content/uploads/2013/01/KatyPerry.jpg"><img class="aligncenter" alt="KatyPerry" src="http://pandalabs.pandasecurity.com/wp-content/uploads/2013/01/KatyPerry.jpg" width="414" height="168" /></a></p>
<p>If the user clicked the link, they were taken to a fake Facebook page where they were invited to download a plug-in to watch the video. The plug-in, however, was designed to post the scam to the victims’ friends’ pages and take them to a typical scam site where they were asked to enter their phone numbers in order to send them unwanted premium rate text messages.</p>
<p>These are just a couple of examples of Internet scams preying on users’ curiosity.  Actually, this is one of cyber-criminals’ favorite ways to spread infections. And I am pretty sure it won’t be long before President Chavez is used as bait to distribute malware.</p>
<p>PandaLabs offers users tips on how to avoid falling victim to this type of scam:</p>
<ul>
<li>Be wary of websites or messages offering sensational videos or unusual stories.</li>
<li>Before you click on a link sent by one of your contacts, make sure it has been intentionally sent by your friend and it is not the result of a massive scam.</li>
<li>Don’t accept friend requests from people you don’t know. This will help keep your privacy safe.</li>
<li>Always keep your computer’s operating system and Web browsers up to date, and make sure you have an up-to-date antivirus solution installed<b>.</b></li>
</ul>
<p align="left"><a class="tt" href="http://twitter.com/home/?status=All+that+glitters+is+not+gold+http://tinyurl.com/a2eup7j" title="Post to Twitter"><img class="nothumb" src="http://pandalabs.pandasecurity.com/wp-content/plugins/tweet-this/icons/tt-twitter-big3.png" alt="Post to Twitter" /></a></p>]]></content:encoded>
			<wfw:commentRss>http://pandalabs.pandasecurity.com/all-that-glitters-is-not-gold/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
