Microsoft Warns of Stealthy Password Attacks

0
[ad_1]
Microsoft Password Attacks

The threat actor “Midnight Blizzard” is engaging in increasing credential attack activity.

They conceal the origin of their assaults by employing residential proxy services.

These attacks target governments, IT service providers, NGOs, the defense sector, and vital manufacturing.

Numerous password spray, brute force, and token theft tactics are used in these credential assaults.

Employing Low-Reputation IP Addresses & Proxy Services

Midnight Blizzard (NOBELIUM) has also carried out session replay assaults using stolen sessions, most likely obtained through illegal selling to get initial access to cloud resources.

Threat actors’ connections made with compromised credentials can be obscured by utilizing low-reputation IP addresses, such as those provided by residential proxy providers.

Microsoft Threat Intelligence reported that “the threat actor likely used these IP addresses for very short periods, which could make scoping and remediation challenging.”

Details of Midnight Blizzard Threat Actor (Microsoft)

Microsoft noted in a series of tweets that, making issues even more difficult, the threat actor only uses these IP addresses occasionally, creating substantial obstacles for effective scoping and remediation operations.

It is important to note that the same organization, known as Midnight Blizzard or NOBELIUM, was responsible for the disastrous SolarWinds breach in late 2021.

Microsoft has strengthened its defenses to combat this growing danger. To defend against these attacks, Microsoft Defender Antivirus, Defender for Endpoint, Defender for Cloud Apps, and Azure Active Directory have all been given strong security features and improved detection capabilities.

Manage and secure Your Endpoints Efficiently – Free Download


[ad_2]
Source link

US Military Personnel Targeted by Unsolicited Smartwatches Linked to Data Breaches

0
[ad_1]

US military personnel have become unsuspecting recipients of unsolicited smartwatches delivered straight to their mailboxes. Recent reports indicate that these seemingly innocuous devices, once activated, automatically connect to Wi-Fi networks and establish unauthorized connections with users’ cell phones, potentially exposing sensitive personal data.

It has been discovered that these smartwatches are not only capable of accessing a vast array of user information but may also contain malicious software, including malware. This was revealed on June 15th, 2023, by the Department of the Army Criminal Investigation Division in a press release.

This malicious software grants the sender unrestricted access to saved data, including but not limited to banking information, contacts, and account details such as usernames and passwords. The consequences of such breaches could be far-reaching, compromising not only personal privacy but also financial security.

Moreover, security experts have warned that the embedded malware might enable unauthorized individuals to remotely exploit the smartwatches’ voice and camera functionalities.

This would grant malicious actors the ability to monitor private conversations and gain unauthorized access to online accounts tied to these devices, further exacerbating the potential risks faced by the affected military personnel.

This incident is somewhat similar to the one in March 2020, in which malware-infected USBs were sent with unsolicited Best Buy gift cards. According to researchers, the USB drives contained an Arduino microcontroller ATMEGA32U4 and were infected with GRIFFON malware.

The unsettling discovery has raised concerns among military officials, prompting investigations into the origins and intentions of these unsolicited smartwatches. While the exact motives remain unclear, experts suspect that these devices might be part of a larger scheme known as “Brushing.”

This deceptive practice involves sending counterfeit products to unsuspecting individuals in order to generate positive reviews under their names, enabling unscrupulous companies to compete with established products.

To combat this growing threat, military personnel who receive these unsolicited smartwatches are urged to exercise caution and follow specific protocols. First and foremost, recipients are strongly advised not to turn on the device under any circumstances. Instead, they should promptly report the incident to their local counterintelligence or security manager.

Additionally, individuals can utilize dedicated reporting channels such as the “Submit a Tip – Report a Crime” portal to ensure swift action is taken to mitigate the risks posed by these rogue smartwatches.

As investigations continue, it is crucial for military personnel and the wider public to remain vigilant against potential cybersecurity threats and promptly report any suspicious activities. By raising awareness about this issue, steps can be taken to safeguard personal privacy, financial well-being, and national security.

In the face of these emerging challenges, it is imperative for authorities, technology companies, and individuals alike to work together to stay one step ahead of those who seek to exploit our vulnerabilities in the digital realm.

  1. Smartwatch flaw allowed overdosing dementia patients
  2. This Smartwatch exposed real-time location data of kids
  3. Strava’s Global Heat Map Exposed Locations of Military Bases
  4. Germany bans kids smartwatches, asks parents to destroy them

[ad_2]
Source link

Signal adds text formatting to let you emphasize your messages

0
[ad_1]

Privacy-focused messaging app Signal is adding text formatting. You can italicize your message, make it bold, strike through a word or phrase to discard it, share code in monospace, or use a spoiler effect to hide your message from the recipient (more about it below). These formatting options are currently available to beta users. A stable release may follow in the coming weeks.

The latest beta update for Signal brings text formatting

Signal has made itself a name in the messaging space thanks to its extensive privacy features. The app regularly adds new features, such as camouflage icons, to further bolster its privacy-centric approach. However, it still lacks in some other areas. Text formatting has been one of the missing features, and it’s now on the way.

Version 6.24.1 of the Signal beta for Android lets you format your message in various ways before sending it. You can format a single word or the whole message by selecting it in the compose field (press and hold on to a word). This will bring a pop-up menu with multiple action buttons, including Cut and Copy. Next to those are formatting options, such as Bold, Italic, Strikethrough, Monospace, and Spoiler (tap the vertical three dots to see more).

Most of you may be already familiar with these options, or at least the former three. Bold will make the selected word/phrase bolder to emphasize it, while Italic will italicize the text. Strikethrough puts a line through the text to make it look like you have discarded it without erasing the text. Monospace, meanwhile, is usually used to separate codes or other technical information from the main text. In this format, all characters have the same breadth.

Finally, Signal has added a Spoiler effect that hides the message with an animation. The recipient can choose to see it by tapping on the message bubble, but the message will not show up until they manually opt to see it. This can be handy in group chats where you don’t want to reveal the plot of a new movie to a friend who hasn’t watched it yet but want to discuss it with others who have watched the movie.

As said earlier, these text formatting options are rolling out with version 6.24.1 of Signal beta for Android. If you are part of the beta program, check for an update for the app in the Google Play Store. If not, you can join the beta program here. Those who are not willing to use the beta build will have to wait until these features arrive in the stable channel. You can click the button below to install the latest version of the Signal app.

DOWNLOAD SIGNAL


[ad_2]
Source link

iPhone SE 4 launch gets delayed again, analysts claim

0
[ad_1]

The iPhone SE 4 info has been all over the place for over half a year at this point. The latest piece of information claims that the iPhone SE 4 is coming, but that its launch got delayed again.

The iPhone SE 4 launch gets delayed yet again, unsurprisingly

Barclays analysts said, to MacRumors, that the phone’s 2024 launch window is “unlikely”. They say that the reason for that is Apple’s in-house 5G modem. That modem was supposed to debut inside the iPhone SE 4, and it still is, hence the delay.

As some of you may know, Apple acquired Intel’s 5G modem division back in 2019. At some point since then, Apple has been trying to produce its own 5G modem, but things don’t seem to be proceeding as expected.

Apple most likely acquired Intel’s 5G modem division due to a public clash it had with Qualcomm back then. Qualcomm accused Apple of patent infringement. That has been settled a long time ago, but Apple is still working on its own 5G modems.

The rumors have been all over the place, to put it mildly

In any case, at the beginning of the article, I said that the iPhone SE 4 rumors have been all over the place. That could not be more true. Back in December last year, a report surfaced claiming that the iPhone SE 4 is not coming at all.

Then, in February, a follow-up came, saying that the device will launch, but in 2024. After that, 2025 was mentioned as the launch year, and the latest rumor before this one claimed that the iPhone SE 4 is just a prototype for 5G modem testing, and that it’s not coming.

Saying that the rumors are all over the place is an understatement. If you decide to put faith in the latest one, the one we’re talking about today, the iPhone SE 4 will become a reality, but not until 2025.

The iPhone SE 3 launched with a very affordable price tag, but it came with a number of compromises, ranging from its dated design, to very poor battery life, to camera performance.

With the iPhone SE 4, if it ever sees the light of day, Apple will update the design. It will no longer use the iPhone 8 chassis.


[ad_2]
Source link

Hackers Can Extract Cryptographic Keys Via Device Power LED Videos

0
[ad_1]

Researchers have devised a new attack strategy to exfiltrate sensitive information from target devices without physical access. The attack methodology presents video-based cryptanalysis, where an attacker may extract the cryptographic keys of target devices from the video footage of their power LED indicators.

Extracting Cryptographic Keys Via Power LED Videos

According to a recent study, it is possible for an adversary to extract the cryptographic keys of a target device merely by analyzing video footage of the device with its power LED visible in it.

Specifically, this video-based cryptanalysis technique relies on detecting the change in power LED light’s brightness. As the CPU performs cryptographic computations, the subsequent power consumption impacts the brightness of the LED lights.

While these brightness fluctuations seem harmless, a smart attacker can detect and analyze the changes to retrieve secret keys. An attacker may simply record the video of the target device, focusing on the power LED. Then, zooming in the video to fill the frame with the power LED allows exploiting the rolling shutter to increase the sampling rate of the LED color by three magnitudes. Next, analyzing the video frames in the RGB space empowers the adversary to decipher the RGB values and retrieve the secret keys.

In their study, the researchers demonstrated two side-channel cryptanalytic timing attacks. First, they extracted the 256-bit ECDSA key of the target smart card by recording and analyzing the video footage of the smart card reader power LED, obtained from a distant (16 meters away) security camera. (Dubbed as the “Minerva” attack.)

Next, they demonstrated a similar attack on a Samsung Galaxy S8 by exploiting the power LED of a Logitech Z120 USB speaker connected to the same USB Hub as that of the Galaxy S8. The researchers recorded the speaker’s power LED via an iPhone 13 Pro Max. (Dubbed as the “HertzBleed” attack.)

The researchers from the Ben-Gurion University of the Negev, Israel, have shared the following video to demonstrate the attack. Besides, they have described their study in detail in their research paper.

Suggested Countermeasures

The researchers explained that the vulnerabilities exploited in this attack don’t exist in the power LED or other device hardware. Instead, the flaws exist in the existing cryptographic libraries. They found at least six smartcard readers from five different vendors and Samsung Galaxy S8 vulnerable to the demonstrated attacks.

Although, the researchers advise using the most updated cryptographic libraries to prevent the vulnerabilities. However, they do not rule out the possible zero-day flaws in the latest libraries that may facilitate such attacks.

Therefore, the basic prevention against Hertzbleed and Minerva attacks is having no power LEDs in the device. Nonetheless, such attacks are still possible by detecting the power LED of connected peripherals (as demonstrated in the case of Samsung Galaxy S8).

Let us know your thoughts in the comments.


[ad_2]
Source link

Best Android Apps for Learning Guitar – updated June 2023

0
[ad_1]

The guitar is one of the most fascinating musical instruments. Many people around the world dream of learning the art of playing guitar. But it’s no easy task by any means. It is a very complicated instrument. There lies immense dedication and sincerity to learning this art. Thankfully, your Android smartphone can help you with that.

The Google Play Store is full of Android apps that can help you learn to play guitar. Whether you are a complete newbie or know the basics of playing guitar, there are apps for every type of user. We have tested several such apps and compiled a list of the best Android apps for learning guitar.

Go through the article below for detailed information on each app, including a description, Google Play rating and size, cost of in-app purchases, and screenshots or promo videos, as well as a Google Play Store download link.

Best Android apps for learning Guitar 2023

Below is a quick overview of the best Android apps for learning guitar for 2023, including any download and in-app purchase costs.

Download Cost In-app cost (per item)
Yousician $5.99 – $179.99
Guitar Tricks $14.99 – $179.99
Fender Play $4.99 – $149.99
Ultimate Guitar $0.99 – $69.99
Justin Guitar $2.49 – $299.99
Songsterr $4.99 – $35.00
BandLab $3.00 – $149.99
GuitarTuna $0.99 – $49.99
Guitar Tuner Pro $1.99 – $49.99
Chordify $6.99 – $41.99
The Metronome $4.99 – $59.99

Best Android apps for learning Guitar 2023 downloads

Below is a little more information on each app, including a direct link for easy downloading.

All download links go to the app’s Google Play Store listing. Users are always recommended to download apps from Google Play or an authorized app store.

Yousician

Yousician best Guitar app Android

 

  • Price: Free to download
  • In-app purchases: $5.99 – $179.99
  • Size: 89MB
  • Google Play rating: 4.1 out of 5 stars

Yousician is an award-winning music app and is one of the best Android apps for learning bass guitar as well as standard guitar. It offers a vast library of video lessons with step-by-step guides, making learning more fun. You get to choose between various learning paths. An instructor will explain the steps and you can practice them along with a song. The app listens to you play and gives instant feedback on your rhythmic accuracy and timing.

The app is easy to navigate and use. It is free to download and offers in-app purchases for several subscription plans that unlock unlimited and uninterrupted playtime across all platforms. In addition to guitar, Yousician also offers video tutorials and step-by-step guides on piano and ukelele.

DOWNLOAD YOUSICIAN

Guitar Tricks

Guitar Tricks Android app

  • Price: Free to download
  • In-app purchases: $14.99 – $179.99
  • Size: 64MB
  • Google Play rating: 4.0 out of 5 stars

Guitar Tricks is another award-winning Android app for learning guitar. It uses the Core Learning System which is said to be the best guitar-learning method for beginners. It guides you through a series of short videos that focus on you making music from day one. You get to play guitar by learning actual hit songs from the very start, rather than those “boring drills and exercises.”

Once you learn the basics, you can then choose between different styles of the guitar like Rock, Country, Blues, and more. Active since 1998, Guitar Tricks offers over 11,000 guitar lessons with hundreds of song tutorials that include some massive hits from The Beatles, Ed Sheeran, The Rolling Stones, Eagles, and more. This app also offers several high-quality tools like scale finder, chord finder, and others to speed up the learning process.

DOWNLOAD GUITAR TRICKS

Fender Play

  • Price: Free to download
  • In-app purchases: $4.99 – $149.99
  • Size: 74MB
  • Google Play rating: 4.4 out of 5 stars

The best thing about Fender Play is that you can choose your path from the very beginning. The app will ask you a variety of questions about your preferred genre and style to create a structured learning path that teaches guitar using popular songs. It offers bite-sized guitar lessons so the learning process doesn’t feel exhausting.

Fender Play offers a collection of thousands of popular song lessons in a variety of genres, including rock, pop, country, folk, and blues. New songs are added weekly so you always have something new to learn. Tips and tricks from experienced instructors will make the learning process more fun and enjoyable.

This app also offers a guitar tuner for acoustic, electric, bass, and ukulele. There are contextual chord diagrams, guitar tablature, music notes, and an extensive glossary library as well. A Tone Integration feature allows you to sound like your favorite artist using amp presets.

DOWNLOAD FENDER PLAY

Ultimate Guitar

Ultimate Guitar app

  • Price: Free to download
  • In-app purchases: $0.99 – $69.99
  • Size: 132MB
  • Google Play rating: 4.5 out of 5 stars

Ultimate Guitar has the world’s largest catalog of guitar, bass, and ukulele chords, tabs, and lyrics. You can play more than 15,000 popular songs in their original sound with Tonebridge Guitar Effects. Additionally, you get chords, tabs, and lyrics for more than 800,000 songs in this app. You can search for any song by type, difficulty, tuning, and rating. There’s also a collection of songs for particular moments from professional guitarists.

This app features a built-in guitar tuner to help you achieve the right sound. You can jam with over 7,000 HQ tabs that include backing tracks and synchronized lyrics. A “simplify” function further lets you simplify difficult songs so you learn the basics of the song easily. You can also transpose songs to the tone that suits you. Ultimate Guitar also offers a left-handed mode for those who need it.

DOWNLOAD ULTIMATE GUITAR

Justin Guitar

Justin Guitar Android app

  • Price: Free to download
  • In-app purchases: $2.49 – $299.99
  • Size: 84MB
  • Google Play rating: 4.6 out of 5 stars

A venture of reputed Australian guitarist Justin Sandercoe, Justin Guitar offers a huge collection of real guitar songs to practice. You get sequential step-by-step tutorials and interactive exercises for hand-picked guitar songs so you are on the right track from the very first day. This app boasts over 1000 hit guitar songs with real band backing tracks to learn guitar.

Over one million people use Justin’s guitar lessons to learn guitar chords, guitar tabs, guitar strumming, capo, fingerpicking, and playing real guitar songs. This app has over 100 sequential instructional guitar video lessons. There’s also a self-assessment system to track your guitar learning progress over time.

DOWNLOAD JUSTIN GUITAR

Songsterr

Songsterr app

 

  • Price: Free to download
  • In-app purchases: $4.99 – $35.00
  • Size: 6MB
  • Google Play rating: 4.6 out of 5 stars

Songsterr boasts a collection of more than 800,000 high-quality guitar, bass, and drum tabs and chords. This app has a very clean user interface and is very easy to use, whether you’re picking up a guitar for the first time or are an advanced learner.

All songs on this app are legally sourced and most songs have tabs for each individual instrument (guitar, bass, drums, and vocal). Songsterr has a multi-speed playback feature so you can slow down the track to learn difficult parts. There’s also a solo mode where you’ll only hear the instrument you’re playing, i.e. the guitar. Mute current track, Loop mode, Offline mode, Count in, History, and Favorites are some other notable features of this app.

DOWNLOAD SONGSTERR

BandLab

  • Price: Free to download
  • In-app purchases: $3.00 – $149.99
  • Size: 29MB
  • Google Play rating: 4.6 out of 5 stars

BandLab is a community of more than 60 million music and guitar lovers from around the world. It is a mobile digital audio workstation that lets you record, edit, and remix your tunes and share your creative effects, beats, loops, and vocals. You can collaborate with other like-minded people and learn new things every day.

This app also lets you discover and stream millions of tracks made by other emerging music lovers. It has over 180 vocal, guitar, and bass effect presets, a 16-track mix editor, and more than 330 virtual MIDI (Musical Instrument Digital Interface) instruments. BandLab is completely free to use and offers over 15,000 royalty-free sounds and beats for sampling.

DOWNLOAD BANDLAB

GuitarTuna

Guitar Tuna app

 

  • Price: Free to download
  • In-app purchases: $0.99 – $49.99
  • Size: 79MB
  • Google Play rating: 4.7 out of 5 stars

GuitarTuna is made by the same team behind Yousician (the first app on this list) and is one of the most popular guitar tuning apps for Android. This app uses the same algorithms for audio recognition as Yousician. It works with both electric and acoustic guitars, as well as other string instruments.

The app’s background noise cancellation technology allows you to achieve perfect tuning in loud areas as well. There are over 100 tunings available, including Standard, Drop-D, Other drop tunings, Open tunings, Half step down, 7-string tunings including drop-A, and 12-string. There are also some advanced tools such as Metronome and Chromatic Tuner.

DOWNLOAD GUITARTUNA

Guitar Tuner Pro

  • Price: Free to download
  • In-app purchases: $1.99 – $49.99
  • Size: 65MB
  • Google Play rating: 4.3 out of 5 stars

Guitar Tuner Pro is, as the name suggests, another popular guitar tuning app. It offers a chromatic tuner for all your instruments and you can use it anywhere and anytime, without needing any accessories. The app has some useful features such as an easy switch between automatic mode and manual mode, an audio input level indicator, and auto-lock frequency.

Guitar Tuner Pro promises an accuracy range of +/- 0.5 hundredths and a tuning range from Ab1 (51.91 Hz) to D5 (587.32 Hz). Additionally, you also get over 2,600 chords in this app. You can easily search for a chord, visualize it, and start practicing.

DOWNLOAD GUITAR TUNER PRO

Chordify

  • Price: Free to download
  • In-app purchases: $6.99 – $41.99
  • Size: 26MB
  • Google Play rating: 4.5 out of 5 stars

With a catalog of over 22 million songs, Chordify offers you chords for any song you want. Simply search for your favorite song, choose your instrument, and start playing. This app offers seamless integration with YouTube and cross-platform support.

You can download the chords from your favorite songs as a MIDI file for easy audio editing. There’s also a capo feature as well as slow-down and loop functions to keep up if you have difficulty with a specific chord. You can also take a printout of the chords if you prefer it that way.

DOWNLOAD CHORDIFY

The Metronome by Soundbrenner

  • Price: Free to download
  • In-app purchases: $4.99 – $59.99
  • Size: 55MB
  • Google Play rating: 4.4 out of 5 stars

The Metronome by Soundbrenner is an app that can go a long way in helping you master your tempo, be it for guitar or any other instrument such as piano and drums. It offers powerful customization for rock-solid precision. You get a wide range of speed settings, starting from as low as 20 bpm and going all the way up to 400 bpm. It also lets you select the time signature and subdivision of your choice.

Most of the features in this app are free to use. But you can unlock some advanced features such as USB MIDI, Bluetooth MIDI, and Ableton Link with a paid plan. You might not find a better metronome app than this.

DOWNLOAD THE METRONOME BY SOUNDBRENNER


[ad_2]
Source link

Qualcomm announces new job cuts amidst slow smartphone sales

0
[ad_1]

Amidst economic hurdles, 2023 has been the year where almost every company has laid off a significant portion of their workflow. Now, in a recent development, Qualcomm has announced significant job cuts as it aims to reduce expenses in light of a persistent slowdown in smartphone sales.

As per the Worker Adjustment and Retraining Notification Act (WARN) paperwork, the company has not only eliminated 415 positions at its San Diego headquarters but also let go of 84 employees at the Bay Area office. Amongst the layoffs, the engineering department was the most affected, with approximately 300 positions eliminated, as indicated by the WARN notice.

Reasoning for the layoffs

While smartphone and modem sales in the US have remained consistent, soft smartphone sales, particularly in China, have had a substantial impact on Qualcomm’s growth this year. During the latest earnings conference call in May, Qualcomm’s CEO, Cristiano Amon, acknowledged the challenges and stated, “We are actively managing operating expenses and will continue to evaluate additional opportunities to drive greater operating efficiencies without losing sight of the automotive and Internet of Things growth opportunities ahead.”

However, it is important to note that this new round of job cuts comes in addition to two smaller layoffs that Qualcomm announced in December and March, resulting in a total of 232 workers being removed from the San Diego workforce.

Venturing into new areas

Although Qualcomm’s revenue has been slowing amidst economic hurdles, the company has been working on expanding its business, particularly in the automotive industry, where they are focusing on in-vehicle connectivity, digital dashboard/infotainment systems, and autonomous driving technologies. Additionally, the company is also ramping up its efforts to supply technologies for various industries, including in-cabin cameras for trucks, drones, retail and warehouse scanners, and robotics.

“We are on track to meet our commitment of a 5% reduction in non-GAAP operating expenses relative to our fiscal ’22 exit rate. This includes a further reduction of spending in handsets to fund diversification investments,” said Akash Palkhiwala, chief financial officer, at a recent earnings call.


[ad_2]
Source link

Spotify may finally be introducing HiFi audio, but are you willing to pay the price?

0
[ad_1]
You’ve probably heard of this huge music streaming service called Spotify. It is an app that’s likely to be found on some of the best phones on the market and for good reason: it works.

In recent times, Spotify devs seem to be busy with adding extra features to their service, which the core audience of music and/or podcast lovers don’t really care for. But still though, with the company’s recent financial troubles — including owing millions to the EU — we can’t really blame them for trying out ways to come out on top.

But all of this talk about core-audience, music and extra features brings back to memory a feature, which has been sorely lacking on the service, namely: lossless audio. Audiophiles have already been tempted to join Apple Music precisely because of this option, which grants users higher quality music with a more vibrant soundscape.

So, did you notice how I said money? Well, that was because Bloomberg says that Spotify may be planning to charge for this.

So what, you say? Well, yes, but the elephant in the room is as follows: Apple Music is also offering lossless, but at no extra cost. So do you see how this may be a bit weird? After all, Apple’s streaming service isn’t even limited to iPhones and iPads.

And even if you dislike Apple that much, you can still go with Amazon’s service and enjoy the same benefit at no extra cost.

Backtracking even further, metroidvania style: Spotify promised HiFi audio options two years ago. There were rumors that it might end up costing more on top, but most subscribers hoped that those were just that: rumors.

The allegedly incoming tier and its kind of cringy name: “Supremium” will launch in non-US territories first, but will also make its way overseas by the end of 2023. So one obvious question remains: how much will the price bump cost?

Well, we don’t know. We also don’t know whether it’ll bring along with it new, bonus features for users, which may — possibly — make the jump worth it? But as a proud member of the “average lossless enjoyer community”, I can’t name such a theoretical feature off the top of my head.

So, we get it. Despite being the largest music-streaming platform in the world, Spotify is still operating at a loss. They also owe millions of dollars to huge institutions. But one must ask: is a slight price bump in exchange for a feature that already exists elsewhere for free the way out of this conundrum?


[ad_2]
Source link

Hackers Attack Linux SSH Servers with Tsunami DDoS Malware

0
[ad_1]

Hackers Attack Linux SSH Servers. An attack campaign has been recently uncovered by AhnLab ASEC, where poorly controlled Linux SSH servers are targeted and infiltrated with the Tsunami DDoS Bot.

In addition to Tsunami, the threat actor installed several other types of malware, including:-

  • ShellBot
  • XMRig CoinMiner
  • Log Cleaner

Most attacks on poorly managed Linux SSH servers involve DDoS bots or CoinMiners being installed.

Tsunami DDoS Malware

Tsunami is a variant of Kaiten (aka Ziggy), a DDoS bot, and it is often distributed alongside Mirai and Gafgyt to attack vulnerable IoT devices.

Although they are all DDoS bots, Tsunami is unique because it functions as an IRC bot and communicates with the threat actor through IRC.

Tsunami’s source code is openly accessible, leading to widespread use by many threat actors.

It is primarily utilized for targeting IoT devices in attacks. Furthermore, it is regularly employed to target Linux servers without fail.

Tsunami DDoS Malware

Attack Against Linux SSH Servers

SSH service is commonly installed in Linux servers, making them vulnerable to attacks due to poor management.

It also enables remote login and system control for administrators, requiring them to log in with their registered user account.

Using basic login information (username and password) in a Linux system can let a malicious person get into the system by forcefully guessing or using a pre-made list of common passwords.

When poorly managed Linux SSH servers are targeted, attackers search for exposed servers by scanning specific ports.

They then try known account credentials to perform dictionary attacks and gain unauthorized access.

Here below we have mentioned the addresses that were attacked along with their IDs and passwords:-

Attack Against Linux SSH Servers

Once logged in, the attacker runs a command to download and launch different types of malware. One of the installed malware is a Bash script called the “key” file, which acts as a downloader and installs more malware.

Apart from downloading malware, the “key” file also carries out several initial tasks to gain control over infected systems, such as setting up a secret SSH account as a backdoor.

Here below we have mentioned all the malware that is installed via the executed command and downloader Bash script:-

  • Downloader Bash (Download URL: ddoser[.]org/key)
  • ShellBot DDoS Bot (Download URL: ddoser[.]org/logo)
  • ShellBot DDoS Bot (Download URL: ddoser[.]org/siwen/bot)
  • Tsunami DDoS Bot (Download URL: ddoser[.]org/siwen/a)
  • MIG Logcleaner v2.0 (Download URL: ddoser[.]org/siwen/cls)
  • 0x333shadow Log Cleaner (Download URL: ddoser[.]org/siwen/clean)
  • Privilege escalation malware (Download URL: ddoser[.]org/siwen/ping6)
  • XMRig CoinMiner (compressed file) (Download URL: ddoser[.]org/top)

ShellBot is a DDoS bot that is Perl-based which utilizes the IRC protocol for communication, can set up a reverse shell, and supports:-

Tsunami stays active even after restarting by saving itself in “/etc/rc.local” and disguising itself with common system process names.

Here below we have mentioned all the remote control commands that Tsunami supports:-

  • Shell command execution
  • Reverse shells
  • Collecting system information
  • Updating itself
  • Downloading additional payloads from an external source

In order to remove any traces of unauthorized access on compromised computers, MIG Logcleaner v2.0 and Shadow Log Cleaner are utilized, thus delaying the prompt detection of the infection by victims

In these attacks, the malware used by the threat actors is an “ELF” file and gives the threat actor elevated privileges.

Mitigations

Here below we have mentioned all the mitigations offered by the security analysts:-

  • Linux users should use strong passwords or SSH keys to protect against attacks.
  • Make sure to disable root login via SSH.
  • Take the necessary steps to restrict access to the server by allowing only a specific range of IP addresses.
  • Ensure that you alter the default SSH port to a less common number to evade automated bots and infection scripts.

Looking For an All-in-One Multi-OS Patch Management Platform – Try Patch Manager Plus.


[ad_2]
Source link

Instagram now lets users download Reels posted by others

0
[ad_1]

Instagram is letting users download Reels posted by others. The company’s CEO Adam Mosseri announced this feature on his Instagram broadcast channel yesterday. This ability is currently only available on the mobile app for users in the US. A global rollout may follow soon.

Instagram launched Reels inspired by TikTok, which made short-form social videos popular a few years back. However, the latter has always enjoyed an advantage over the former. Not that it had a head start but it allowed users to download videos posted by others and share them on various social platforms. Since the video has its logo and the username of the creator, it drove people from other platforms to TikTok.

The Meta-owned platform is finally catching up to TikTok. According to a screenshot shared by Mosseri, Instagram users can download Reels from the Share menu. The app has added a new “Download” button to the bottom row of the Share menu where you also find buttons to add the Reel to your story or share it on other platforms as a link. The Download button appears between Copy link and Message/SMS buttons.

You can only download Reels posted from public Instagram accounts

Moserri noted that users can only download Reels posted from public accounts. You cannot download Reels shared by private accounts even if you follow them. This respects the privacy setting of those users. Reels they share are only for people who follow them. Allowing downloads defeats the purpose. Meanwhile, public accounts can also block downloads for other Instagram users from their account settings.

Like other platforms, Instagram will also put a watermark on downloaded Reels. Mosseri didn’t specify that in his broadcast but an accompanying screenshot suggests so. It features the company’s logo and the username of the Reel creator. Note that Instagram stopped recommending or promoting videos/Reels with a watermark of TikTok or other platforms in February 2021 to discourage cross-platform sharing of short videos.

It’s unclear when Instagram plans to bring this feature to other markets. As said earlier, its rivals already allow downloading. This includes YouTube as well, which launched Shorts after TikTok surged in popularity globally. Downloaded YouTube Shorts also feature a logo-based watermark. Keep a close eye on the Share menu for Instagram Reels in the coming months. Always make sure to keep the app updated as well, so you don’t miss out on the new features. You can click here to download the latest version of Instagram from the Google Play Store.

Instagram Download Reels


[ad_2]
Source link