HiatusRAT Malware Attack Routers to Gain Remote Access

0
[ad_1]

Lumen’s Black Lotus Labs recently witnessed that Hackers are currently targeting DrayTek Vigor router models 2960 and 3900 in a campaign known as ‘Hiatus’. 

The primary goal of hackers is to steal data from victims and establish a covert proxy network for cyberespionage purposes.

Vigor devices from DrayTek are business-class VPN routers used for remote access to corporate networks by small and medium-sized organizations.

It has been estimated that about 4,100 DrayTek routers are vulnerable on the internet as of mid-February 2023. It is estimated that this represents approximately 2% of the total number of DrayTek routers that are exposed.

There are three key components involved in this latest hacking campaign, which began in July 2022 and is still ongoing to this day:-

  • A malicious bash script
  • A malware named “HiatusRAT,”
  • The legitimate ‘tcpdump,’

The most interesting part of the campaign is its HiatusRAT component, which gives the campaign its name in the first place. There are several purposes for which this tool is used and here they are mentioned below:-

For additional payloads downloading

On the breached device running commands 

Converting the device into a SOCKS5 proxy

Technical Analysis

HiatusRAT has infected approximately a hundred businesses mainly in the following regions:-

  • America
  • Europe
  • North America

It is not yet known how DrayTek routers were initially compromised, and even scientists at this time are unable to determine how that occurred.

The threat actors download three components to the router by deploying a bash script, and they do so after they gain access to the device. 

As part of this script, the first step is to download the HiatusRAT to ‘/database/.updata’ and run it from there. Upon detecting that a process is already running on port 8816, the malware begins listening for it and kills it.

As part of HiatusRAT’s monitoring system, the threat actor can track the status of the compromised router by sending a heartbeat POST to the C2 every eight hours.

The following are some of the industries that have been negatively impacted:-

  • Pharmaceuticals
  • IT services
  • Consulting firms
  • Municipal government

Data Collected

From the breached device, the following information is collected:

  • MAC address
  • Kernel version
  • System architecture
  • Firmware version
  • Router IP address
  • Local IP address
  • MACs of devices on adjacent LAN
  • Mount points
  • Directory-level path locations
  • Filesystem type
  • Process names
  • IDs
  • UIDs
  • Arguments

Features

As a result of Black Lotus Labs’ reverse engineering analysis of the malware, the following features have been revealed:-

  • config: From the C2, load the new configuration.
  • shell: On the infected device, spawn a remote shell.
  • file: C2 files can be accessed, deleted, or exfiltrated.
  • executor: Retrieve a file from the C2 and execute it.
  • script: From the C2, run a script.
  • tcp_forward: Whenever TCP data is received on a host’s listening port, forward it to a forwarding address.
  • socks5: On the compromised router, set up a SOCKS v5 proxy server.
  • quit: Put an end to the execution of malware.

SOCKS is used to obfuscate network traffic and mimic legitimate behavior while forwarding data from other infected machines.

A packet-capturing tool will also be installed by the bash script when it is run. With the help of this tool, TCP ports connected to mail servers and FTP connections are monitored.

Here below we have mentioned the monitored ports:-

  • Port 21 for FTP
  • Port 25 for SMTP
  • Port 110 is used by POP3
  • Port 143 is associated with the IMAP protocol

Even though Hiatus is a small campaign in scale, the impact it has on the victims can be extremely serious. Research conducted by Lumen indicates that the threat actor has deliberately maintained a small volume of attacks in order to avoid detection.

Network Security Checklist – Download Free E-Book


[ad_2]
Source link

YouTube’s finally ditching these annoying ads

0
[ad_1]

Ads are a part of our modern internet world. We’ve gotten used to them, but they can still be a bother. YouTube shoves ads down our throats in several ways, but things are going to be slightly better thanks to a new announcement. According to the announcement, YouTube is getting rid of those annoying banner ads.

If you’re not a YouTube premium subscriber, then you’ll need to deal with ads before and during your videos. One of the more annoying ads is the banner that pops up during your video. If you’re watching a video that’s monetized, you’ll see a decently-sized banner appear on the bottom of the screen. It’ll give you the ability to “X out” of it.

YouTube will get rid of the banner ads

The company made a new post on the YouTube Help Forum (via Cord Cutters News) that explains its decision. On April 6th YouTube will be getting rid of the banner ads in order to help improve the viewer experience. The company referred to it as a “legacy ad format”. Basically, it’s an ad format that’s been around for a while and it overstayed its welcome.

Getting rid of these ads does eliminate one avenue of income for creators. However, judging by the wording in the post, it seems that the banner ads are low-performing compared to the other formats. It’s going to shift its focus to higher-performing formats on desktop and mobile.

What the company means by that, we have no idea. Hopefully, it doesn’t mean that we’ll see an uptick in other ads. People have already complained about getting an overdose of ads in the past. Some users would see as many as 10 ads before a video.

In any case, it’s good that the banner ads will be going away next month. If you’re tired of seeing ads altogether, you can always sign up for YouTube premium. You’ll get zero ads, downloads, background playing, and access to new experimental features.


[ad_2]
Source link

Paramount is interested in selling BET & VH1

0
[ad_1]

After being offered $3 billion to sell SHOWTIME and turning it down, Paramount is now looking to sell BET instead. It’s reportedly looking to sell the majority stake in BET Media Group, which includes BET, VH1 and the BET+ streaming service.

It’s a new strategy for Paramount to try and trim corporate losses, while also continuing to build up its subscription video-on-demand service, in Paramount+. As well as its ad-free ad-supported TV service Pluto TV. This will help Paramount compete with the other streamers in the market. Paramount has been prioritizing increased investments in Paramount+ as of late.

Paramount integrating BET and BET+ into Paramount+ would be pretty difficult, according to the report. This is because Paramount does not own 100% of the company. Instead it just has a majority stake in BET. With Tyler Perry having a small stake in the company. Paramount does plan to continue working with BET even if it does sell its stake.

Paramount declined an offer to sell SHOWTIME recently

The report also mentions that Paramount actually declined an offer to sell SHOWTIME recently. Apparently, they were offered more than $3 billion for the asset. And Paramount is interested in keeping it. This isn’t the first time that Paramount has gotten offers for SHOWTIME, however.

SHOWTIME is a very popular, premium streaming service. As it is one of the few services out there that hasn’t really raised its prices in quite some time. It does not have an ad-supported option, which is likely getting more attention for a buyout now. But Paramount’s CEO, Bob Bakich stated that “there is enormous value to unlock with the integration of SHOWTIME and Paramount+. If we were to divest the asset, it would have to create more value than our own operating plan…. but frankly, that bare is pretty high.”

So for the right price, someone could scoop up SHOWTIME, but that is pretty unlikely to happen.


[ad_2]
Source link

YouTube has new podcast features in the works, currently testing with select creators

0
[ad_1]

YouTube has quietly launched a new feature experiment, reports 9to5Google. The new experiment is centered on podcast creation and more tools for podcast makers.

YouTube tests new tools for podcasts


As you may probably know, YouTube has been eyeing the podcast scene for quite some time. Now, the platform is taking another step towards becoming a more podcast-friendly place for all those who would like to get into podcasting or work as podcasters. The new tools that are now in testing are, from what it seems, everything a content creator would need to start podcasts on the platform: from uploading a podcast episode to looking into analytical data about the podcast’s performance.

The users who are a part of the test will see a new option to upload a podcast under the “create” button, which usually gives you the option to upload a video, create a text post, or start a live stream.

But that’s not all! Creators would also see podcasts under a new “Podcasts tab” found in the content menu. Also, existing playlists will be able to be set as podcasts with a new option that’s found in the three-dots menu.

And last but not least, YouTube Studio will show podcast analytics on a desktop. Among the analytics, you will be able to view the performance of a specific podcast show, audience numbers, and revenue insights.

For now, a small number of creators are part of the experiment.

YouTube’s into podcasting, a little background


YouTube’s efforts to become a more prominent platform in the podcast scene have been showing ever since 2021. Back then, a report showed that YouTube was looking into hiring executives with experience on podcasts (via Bloomberg). This meant that YouTube was starting to take podcasts seriously.

Actually, even before that, YouTube was one of the places that people looked at when interested in podcasts in general. However, at the time, the platform wasn’t optimized for podcast listeners, so YouTube looked to make everything organized and manage the millions of podcasts on its platform.

In 2022, YouTube became even more serious about the endeavor as some leaked slideshows were detailed (via 9to5Google). These plans included new “search and discovery” tools, as well as a “podcast destination page” and “official podcast cards”. Later, the company also published a guide for creators that were looking into podcasting on YouTube.

All in all, YouTube is definitely becoming more popular for podcasters and podcast fans alike. We’ll have to wait and see what other features the platform may get for podcast fans.


[ad_2]
Source link

Idea Note is a readily accessible note-taking app

0
[ad_1]

If you’re on the lookout for a new note-taking app, you may want to consider Idea Note. This app is readily accessible no matter what you’re doing on your phone, and it also comes with a desktop client.

Idea Note app makes taking notes extremely easy, and readily accessible

How is this app more useful than others? Well, you can set it so that it’s one swipe away, on any screen. So if you get an idea of some sort, you can quickly jot it down (hence the name of the app).

If you give it some permissions, you’ll be able to access it from the top-right corner of the display. You’ll notice a semi-see-through line there, and all you need is to swipe inwards.

Once you do that, you will be presented with a nice interface. Your notes will be shown along the right side of the screen, while the field to enter a new note will be included at the bottom. You’ll still be able to see your current screen, though.

This app doesn’t force you to use it this way, though. You can use it as a regular note-taking app by launching it directly. The UI is very nice and quite frankly the app is a joy to use. It did remind me of Google Keep to an extent.

There is also a theming system built in

You can also change the theme, if you don’t like it. So you can change it to something entirely different, either light or dark, whichever you choose. The app adapts easily thanks to in-built theming.

Yes, you can take a quick voice message with the app, or create a checklist, if that’s what you want. It also comes with a labeling system built in, and it can sync all your changes online, if you want. You will need to log in if you’d like to do that, of course.

The app also has a web client which you can access via web.ideanote.cc. That way, your notes will be at your disposal regardless of whether you’re using your phone, or working on your PC.

The app works great, and it’s free to use, though in-app purchases are included. If you’d like to try it out, the Play Store link is included below. That’s also where you’ll find some official images to check out.

Idea Note (Google Play Store)


[ad_2]
Source link

The iPhone 14 in Yellow

0
[ad_1]

Spring is quickly approaching, and that means that there’s a new color of the iPhone coming. Today, Apple announced just that. Apple has a new yellow color for the iPhone 14 and iPhone 14 Plus. It is going to be available starting next week, on March 14.

Now, the iPhone 14 and 14 Plus are available in midnight starlight (PRODUCT)RED, blue, purple and yellow. It has the same starting price of $799 for the 128GB model. And it goes up from there.

Apple is also announcing new colors for the silicon cases for the iPhone 14 and 14 Plus. That includes canary yellow, olive, sky and iris. So there’s plenty of options for the silicon cases now.

It’s the same iPhone 14, now in yellow

There’s nothing new with this iPhone, other than the fact that it is now in yellow. So if you already have the iPhone 14 or 14 Plus in one of the other colors, there’s no real reason to run out and grab this yellow one. Unless, you really want the yellow color.

This yellow color is actually really nice. It’s a pretty bright color, almost highlighter like. Which is definitely an interesting color for the iPhone.

Apple typically does this around the Spring, typically in March. Where they will launch a new color for the iPhone, as well as a few more colors of its silicon cases, leather cases and Apple Watch cases. In the past, we’ve had green and purple. And now yellow, giving us some really cool spring colors.

Last year, Apple did launch the green iPhone in the Pro models. But this year, it appears to only be happening for the iPhone 14 and 14 Plus. There’s no new color for the Pro models, at least not yet. There’s a rumor that we are expecting more Apple releases this week, so we could see this come later this week, but it’s unlikely.

Apple iPhone 14 iPhone 14 Plus yellow 2up 230307 inline jpg large 2x


[ad_2]
Source link

Google starts rolling out an improved UI for the Android phone dialer

0
[ad_1]

Google has recently updated the Phone app to streamline the look of the Android dialer. As a beta tester for the Phone app, this writer has had these changes for some time, but they are now rolling out to those who choose not to beta test apps on their phones. Of course, the advantage of being a beta tester is that you get the first crack at new features or new UI designs and more.

The old UI for the dialer would show the name and number you are calling at the top of the screen with six options in the middle set up in two rows of three icons each. The top row contained Mute, Keypad, and Phone. Right underneath were icons for Add call, Video call, and Hold. At the bottom center of the display was a single button for placing a call or for hanging up on an active call. Pressing the Keypad icon would open the numerical pad on the bottom 40% of the display.

Google cleans up the UI of the Android dialer on the Phone app

After the update, there are only four icons when you make a call and they are all at the bottom third of the screen where they take up one row. In order, these icons are Keypad, Mute, Phone, and More. You see, Google brilliantly took away three of the icons and placed them inside a button called “More” to save some space. Oh, to have been a fly on the wall when they came up with that idea. Tap on More and icons for Hold call, Video call, and Add call appear.

And now, when you hit the Keypad button, the numerical pad opens higher up on the screen leaving the original four icons in full view. This should be available now as long as you’re using version 98.x of the Phone app. To find out which version your phone has, go to Settings > Apps > See all XXX apps and then scroll down to Phone. Tap on Phone and scroll to the bottom of the screen and you’ll see the version number of the app. For the record, my phone is running version 100.0 and is on the public beta.

The new and improved dialer gets rid of the floating box that would cover up content on the screen

And there is one more major change. If you’re on a call but need to open an app or go online, swiping up from the bottom of the call screen used to take you to your home screen and open a floating box that gave you options like Back to call, which returned you to the call screen; Mute, which is self-explanatory; Phone; and End call. But this floating box got in the way of whatever content you were looking at while on the call. So with the update, once you swipe up from the bottom of the screen during a call, a small pill with a phone icon appears next to the time in the upper left of the display.

Inside the pill is a timer that counts how long you’ve been on the call and if you need to end the call, mute the call, turn on or off the speaker, or add another caller, tap the pill and you will return to the call screen from where you can make the changes to the call that you want. And by placing this pill where it did, Google makes sure that the content you’re viewing while on a call is not covered up by a floating box. Sure it floats, but who wants to keep moving it out of the way?

It might not seem like these are earth-shattering changes, but they do save some space on the display, they do make the UI look better, and they might even save you some time.

[ad_2]
Source link

Get the Genuine Office 2021 and Windows 11 from $6 for a Limited Time on Godeal24 – GBHackers – Latest Cyber Security News

0
[ad_1]

Do you want to assemble a new computer and are tired of looking for the lowest-priced components in every online store? And there is a risk of buying a pirated version. Not only you personally will have some troubles with pirated versions, but also your computer will run with many problems, the system will not work, data of important files will be lost, file formats will be incompatible and there is a possibility that malware will infect your computer with virus and make it not work. With Godeal24, you completely avoid the risk of using pirated copies, because Godeal24 gets their permanent digital activation keys at a very low price, which allows them to offer them on their website at unbeatable prices. No stores, no middlemen, no physical media support, lower costs and regular legal software keys at the most affordable prices.Godeal24 is an online store that sells keys for computer operating systems, office software, and gaming software to the global market. We have been serving for several years now. We always put our customers first and bring them the best products and services.

The most popular operating systems and office software are currently available, all at special prices now! No practical discount code is required, just click on the links below to buy directly.

Genuine Windows 10 is as low as $6.12/PC!

At Godeal24 Software Sale, you can buy the latest Office 2021 Professional for just $24.25! And the most cost-effective 5PCs combination, each Office 2021 license is as low as $13.05! After the purchase is successful, the customer can use the license activation code provided by Godeal24 after downloading from the official website, without worrying about the security of the software, 100% genuine guarantee. Don’t miss out on this incredible deal, grab it now!

Hot Sale! Microsoft Office at the Best Price!

62% off on Bundles and more MS Office (coupon code “GG62”)

Up to 50% off on More Windows! (Coupon code “GG50”)

  • Windows 10 Enterprise 2019 LTSC -$9.13
  • Windows 10 Enterprise 2021 LTSC- $12.81
  • Windows Server 2022 Standard- $26.13
  • Windows Server 2022 Datacenter- $30.75

At Godeal24, you can save a lot of time and money with discounted Microsoft licenses, major IT security software and other computer tools like IOBIT, Ashampoo, Disk Drill and many more. Get Windows OS and MS Office at an unbeatable price. With Godeal24, you can rest easy knowing your software is 100% safe and genuine, backed by a lifetime support and update guarantee from Microsoft.

Experience hassle-free shopping with Godeal24’s digital delivery, which sends your software directly to your email within seconds of purchase. Plus, with a TrustPilot 98% Excellent rating and 24/7 expert technical support, you can be confident in the quality of the product you’re buying. Don’t miss this chance to save up to 90% on the software you need for work or play.

Godeal24 promises that they offer 24/7 professional technical support and lifetime after-sales service and that you can use the product without problems!

Contact Godeal24: [email protected]


[ad_2]
Source link

A week in security (Feb 27

0
[ad_1]

The most interesting security related news from the week of February 27 to March 5.

Last week on Malwarebytes Labs:

Stay safe!


Have a burning question or want to learn more about our cyberprotection? Get a free business trial below.

GET STARTED


[ad_2]
Source link

OnePlus Nord 3 design & specs confirmed by Ace 2V launch

0
[ad_1]

The OnePlus Nord 3 design and specs have just been confirmed, basically. OnePlus announced the OnePlus Ace 2V handset in China, and by doing that, it confirmed almost everything we need to know about the Nord 3.

The OnePlus Nord 3 design & specs confirmed thanks to Ace 2V launch

Multiple sources confirmed that the Nord 3 will be a rebranded Ace 2V, basically. So, there’s nothing left to hide, other than the Nord 3’s price tag and launch date.

If you take a look at the images provided below the article, you’ll see the OnePlus Ace 2V. It is exactly what we expected, as it leaked not long ago. The phone features flat sides, and a flat display too. It has a centered display camera hole, and two camera islands on the back.

The phone comes with a 4,129mm² VC cooling and a larger heat dissipation area. It includes a 6.74-inch 2772 x 1240 AMOLED display. That display offers a high refresh rate of up to 120Hz (40-120Hz).

The Dimensity 9000 SoC will fuel it, while up to 16GB of RAM will be on offer

The phone is fueled by the MediaTek Dimensity 9000 SoC. OnePlus also announced both 12GB and 16GB RAM (LPDDR5X) units, which come with 256GB and 512GB of storage (UFS 3.1), respectively.

A 5,000mAh battery sits on the inside of this phone, and the device supports 80W SuperVOOC wired charging. Wireless charging is not supported here. The phone does have an in-display fingerprint scanner, and stereo speakers too.

Android 13 comes pre-installed on the device, along with ColorOS 13. There are two SIM card slots (2x nano SIM) here. Bluetooth 5.3 is supported, and so is 5G connectivity.

Three cameras will sit on the back

A 64-megapixel main camera (OmniVision OV64M sensor, f/1.7 aperture, OIS) is backed by an 8-megapixel ultrawide camera (Sony’s IMX355 sensor, 120-degree FoV, f/2.2 aperture). A 2-megapixel macro camera (GalaxyCore GC02M sensor, f/2.4 aperture) also sits on the back. A single 16-megapixel selfie camera (S5K3P9SP04 sensor, f/2.4 aperture) is also a part of the package.

The OnePlus Ace 2V measures 162.6 x 75.1 x 8.15mm, while it weighs 191.5 grams. The phone’s pricing starts at CNY2,299 ($332) in China. The OnePlus Nord 3 will almost certainly have these exact same specs (maybe different RAM and storage flavors), and the same design.


[ad_2]
Source link