Four EU telco giants will start asking users if they want personalized targeted ads

0
[ad_1]

The EU Commission has greenlit the merge of four EU telco giants to offer millions of subscribers a different kind of targeted ads.

They say you can’t have too much of a good thing. Unfortunately, this applies to ads, too, whether you think they’re a good thing or not. Soon, Europe’s four biggest telecommunication companies—Germany’s Deutsche Telekom (DK), France’s Orange, Spain’s Telefónica, and the UK’s Vodafone Group—will deliver targeted ads to their millions of subscribers while also observing European privacy laws.

Back in January, the quartet of telcos filed a proposal to offer a “privacy-led, digital identification solution to support the digital marketing and advertising activities of brands and publishers.”

Now, the joint venture has been approved “unconditionally” by the European Commission under the EU Merger Regulation. With the four giants merging, the commission concluded competition concerns wouldn’t be raised in the European Economic Area (EEA), meaning this merger can only compete with non-EU telcos.

“The joint venture will offer a platform to support brands and publishers’ digital marketing and advertising activities in France, Germany, Italy, Spain and the UK,” the press release noted. “Subject to the user’s consent, the joint venture will generate a unique digital code derived from the user’s mobile or fixed network subscription. Such code will allow brands and publishers to recognize users on their websites or applications on a pseudonymous basis, group them under different categories and tailor their content to specific users’ groups.”

Although the commission cleared the joint venture, this doesn’t mean the EU’s data protection regulators will give this a sign-off, too, as the press release further stated: “During its investigation, the Commission has been in contact with data protection authorities. Data protection rules are fully applicable, irrespective of the merger clearance.”

The still-unnamed adtech merger is set to operate in Belgium, with each of the four holding a 25 percent stake. It isn’t clear when this venture will begin operation.

Subscribers must opt-in

The hundreds of millions of subscribers of the four telcos will not automatically be subjected to the ads; they have to agree to this explicitly. Because this new ad platform, which they dubbed as a “counter-design to third-party cookies”, according to TechCrunch, was designed with the GDPR and ePrivacy directive in mind, the JV would have to create an opt-in mechanism for willing subscribers to submit their phone numbers to start receiving “communication from brands via publishers”. 

“The trial platform requires affirmative opt-in consent by the consumer to activate communications from brands via publishers,” said Vodafone about the venture’s platform. “The only data that is shared is a pseudo-anonymous digital token that cannot be reverse-engineered. Consumers are free to opt in or deny consent with a single click, as well as revoke any other consents given either on the brand’s or publisher’s website, or via a dedicated, easily accessible privacy portal.”

“The platform is specifically designed to offer consumers a step change in the control, transparency and protection of their data, which is currently collected, distributed and stored at scale by major, non-European players,” the company added.

Vodafone has already conducted a platform trial on its network and DK in Germany. In France and Spain, other trials are being considered “to further develop the platform”. Eventually, it is to be made available to every operator within Europe.

The JV will be outlining its vision and strategy, including plans for adopting the trial technology commercially in the future. The name of the trial platform is TrustPid.


Vodafone’s Privacy Portal, TrustPid, is where users can opt out of receiving targeted ads when they decide to. (Source: Trustpid)

Privacy concerns and dark patterns

When the name TrustPid started appearing in headlines in May last year, it quickly became synonymous with “supercookie”, an ad targeting technology (tracker) famously associated with American telco Verizon. What a supercookie does is track websites visited by users on a smartphone or other mobile device on its network, allowing sites to better target them with ads. The Electronic Frontier Foundation (EFF) put it this way: “It allows third-party advertisers and websites to assemble a deep, permanent profile of visitors’ web browsing habits without their consent.”

Only in this case, explicit consent is required. However, it is not true consent—and this is a problem.

When the German Federal Commissioner for Data Protection and Freedom of Information (BfDI) began receiving inquiries about TrustPid in June 2022, they revealed [source] [translated from the German] they flagged several “data protection problem areas” with the project, including relying on user consent for its legal basis to gather user information. As revealed in a recent study, to have true consent, the party must have (1) an understanding of corporate practices, policies, and legal protection regarding their data—something a lot of us would blindly agree to because no one reads the terms—and (2) autonomy to decide. Satisfying only one of these would make consent “illegitimate.”

When TechCrunch quizzed Simon Poulter, a senior spokesperson for Vodafone, about consent, he claimed participating partners must explicitly collect consent before processing any data. However, the media outfit noted quickly that participating mobile carriers themselves never proactively asked for user consent at any point, making the source of tracking look “obfuscated by design”.

“By outsourcing the gathering of consents to third party ad ‘partners,’ TrustPid’s approach looks intended to dodge denials — but by doing that it risks running counter to key principles baked into EU law,” TechCrunch added.

Poulter eventually confirmed the carriers had no intention to gather consent themselves.

A number of privacy advocates weighed in on the matter of TrustPid months ago. One of them was Aram Zucker-Scharff, the privacy engineering lead for the Washington Post:

Participant users who don’t want to be tracked anymore would have to opt out every three months since TrustPid tokens are designed to respawn every 90 days.

Mobile traffic data is generally untouched, and EU telcos have seen it as a significant fund source. Can they really allow advertising partners to collect this data even with consent?

“Companies that operate communication networks should neither track their customers nor should they help others to track them,” digital rights activist Wolfie Christl was quoted saying. “I consider the project an irresponsible abuse of their very specific trusted position as communication network operators. It is a dangerous attack on the rights of millions. It appears they want to legally justify it with the misleading and meaningless pseudo-consent banners we have to deal with on websites every day, which is irresponsible and outrageous.”

“The project undermines trust into communication technology and should be stopped immediately,” Christl further added. “I hope that European data protection authorities quickly team up and stop the project.”


We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.


[ad_2]
Source link

How to buy the Samsung Galaxy S23

0
[ad_1]

Now that the Galaxy S23 is official, you might be wondering, when can you pre-order it? And even better yet, when can you get it in your hands? Well, the good news is that you won’t have to wait long.

Pre-orders for the Galaxy S23 start today, in fact they are open right now. Samsung says that they will arrive by February 17. Now this will be the same, no matter where you buy the Galaxy S23.

So what about pre-order bonuses? And where can you get the best deal for the Galaxy S23? That’s what we’re here to help you with. Now the one deal that we do know is everywhere is, the storage upgrade. So you can get the 256GB model for the price of the 128GB model. Which is pretty sweet.

AT&T

AT&T is offering $1,000 off of the new Galaxy S23 series when you trade-in your phone. This means that customers can get a Galaxy S23 or S23+ for “free” with eligible trade-in. Or get the Galaxy S23 Ultra for just $199.

This was the pre-order special, minus the free storage upgrade, so still a good time to buy the Galaxy S23.

AT&T

Samsung.com

When you pre-order from Samsung.com, you can purchase a carrier-locked phone or an unlocked one. Which will work on all three US carriers. You also get to choose from the Samsung.com-exclusive colors. This year, those include Lime, Graphite, Sky Blue and Red.

Samsung is still offering some sweet deals for the Galaxy S23. Where you can get up to $1,000 off depending on your carrier and your trade-in. That’s a pretty sweet deal for any of the three Galaxy S23 models.

Samsung.com

T-Mobile

T-Mobile is offering the Galaxy S23 and S23+ for free or $1,000 off the S23 Ultra when you add a line, or switch to T-Mobile. As well as with a trade-in. So plenty of ways to get a Galaxy S23 at a decent price.

T-Mobile

Verizon

Verizon is selling the Galaxy S23 with up to $800 off via trade-in. Which is really sweet since it can be a broken or cracked device as well. So it doesn’t need to be in perfect condition. That’s definitely a good thing here. That means you can get the Galaxy S23 for “free”, the S23 Plus for $200, or the Galaxy S23 Ultra for $400.

Verizon


[ad_2]
Source link

Samsung to borrow $16 billion to fund its semiconductor investments

0
[ad_1]

Samsung Electronics is planning to borrow nearly $16 billion to fund its semiconductor investments. Another Samsung company — Samsung Display — will lend it the money. This comes after the Korean conglomerate suffered a massive decline in profit in the year-ending quarter of 2022.

According to a regulatory filing seen by the Korean media, Samsung Electronics will borrow KRW 20 trillion (roughly $16 billion) from Samsung Display at an interest rate of 4.6 percent. Since the former holds an 85 percent stake in the latter, it was likely an easy negotiation. The display manufacturing unit reportedly has about KRW 20 trillion of cash reserve, and Samsung Electronics is taking almost all of that money. It appears to be a 30-month loan maturing on August 17, 2025.

Samsung Electronics also reportedly has a cash reserve of about KRW 100 trillion. However, since it is a global company with affiliates all over the world, that fund is likely widely distributed. It seemingly found it better to borrow funds from its sister firm. “When it is said the company has 100 trillion won in reserve, it could consist of all different types of cashable assets,” an industry official told The Korea Herald. “The funds may not be in Korea or may be allocated to different business units. So the company would likely have calculated all the costs before making the decision.”

Samsung borrows money from sister firm after suffering a profit decline

The ongoing economic downturn has hit the tech industry hard and Samsung was no exception. The Korean behemoth saw its profits plunge a staggering 70 percent in the year-ending quarter of 2022 to reach an eight-year low. Its semiconductor business barely broke even during the period. But despite these economic difficulties, Samsung continues to invest big in semiconductors. It plans to invest $115 billion in advanced logic chip development by 2030.

In 2022, Samsung Electronics reportedly invested more than KRW 53 trillion (roughly $40 billion) in infrastructure development. About 90 percent of that amount went into the semiconductor business. It wants to maintain the same level of investment this year. The company expects its new chip factory in Taylor, Texas in the US to be ready this year. The factory will cost Samsung a whopping $17 billion. It also plans to start making 3nm processors for smartphones this year.

All of this will require a huge cash reserve. To ensure that it doesn’t run into a fund shortage, Samsung Electronics decided to borrow money from its sister firm. It remains to be seen when the market rebounds. The Korean behemoth isn’t expecting any better financial results this year. But it likely sees a healthy return on this investment in the long run.


[ad_2]
Source link

Netflix is the king of streaming and that’s just a fact, as data proves it

0
[ad_1]
Nielsen — a company that made audience stats its business — has come forward with new data, which proves that Netflix was the most popular streaming service in 2022. A whopping 10 of the 15 most watched shows from 2022 were exclusive to the platform.

52 billion minutes — which for the record is about 866 million hours, or over 5 million weeks, a.k.a. more than 96 thousand years — is about how much users spent on watching Stranger Things alone in 2022. Okay, slightly scary, but it’s not strange in any way.

Season four gave birth to some of the most iconic moments, characters and scenes from the ultra-successful series. But you probably already know that, considering that everybody and their grandmother owns a Hellfire Club T-shirt at this point.

I bet your grandma doesn’t really play D&D though, Robert! That was a bit out of character, I’m sorry.

Here’s a quick list of the top five pieces of Netflix content from 2022:
  1. Stranger Things
  2. Cocomelon
  3. Ozark
  4. Grey’s Anatomy
  5. Gilmore Girls

But Netflix is famed for their original content, so let’s see what the top five offerings that they’ve developed are:
  1. Stranger Things
  2. Ozark
  3. Wednesday
  4. Cobra Kai
  5. Bridgerton

Quite a lot of variety! You’ve got adventure, you’ve got drama, there’s all sorts of comedy and some hammy nostalgia on the side. Regardless of the person you are, you are likely to click with at least one of these shows.

But here comes the kicker: this data excludes viewing time that users spent on PC or Mobile, due to the way Nielsen’s tracking works. As such, the estimated 27% in watch time growth is likely loads bigger.

Well, what really matters is that Stranger Things Season 5 is coming this year. It’ll be interesting to see the impact of the series finale when next year’s data comes in, but until then, we’ve got tons of new content and announcements to look forward to.


[ad_2]
Source link

TikTok car theft challenge: Hyundai, Kia fix flaw

0
[ad_1]

Hyundai and Kia have released a software update to fix a car theft hack that went viral on TikTok, and resulted in at least eight fatalities.

Car manufacturer Hyundai, and its subsidiary Kia, began rolling out a free software update on February 14, 2023, to address a flaw in their anti-theft software, which was highlighted in a social media challenge. The release of the update came nine months after an uptick in car theft of the affected models in the US. Outside the US, victims in Australia also came forward.

“The software updates the theft alarm software logic to extend the length of the alarm sound from 30 seconds to one minute and requires the key to be in the ignition switch to turn the vehicle on,” said the US National Highway Traffic Safety Administration (NHTSA). “The effort is in response to a TikTok social media challenge that has spread nationwide and has resulted in at least 14 reported crashes and eight fatalities.”

The “Kia Challenge” went viral on TikTok in August 2022. Thieves, known as “Kia Boys” or “Kia Boyz”, showed how to bypass Kia’s security system using simple tools like a screwdriver and a USB cable. It is said this method of thieving is so easy because many 2015-2019 Kias and Hyundais lack electronic immobilizers, which use electronic signals to deter thieves from hot-wiring cars.

The teens instructed viewers to forcefully remove the covering of the steering column (located just below the steering wheel) to expose a slot where a USB-A plug then comes into play.

From what we have gathered, the viral TikTok video was a snippet from a Tommy G YouTube documentary entitled Kia Boys Documentary (A Story of Teenage Car Theft). The scene in question was found in the last bit of the video.

Only cars that use keys seem susceptible to this kind of theft. Push-to-start cars, which are vehicles that you start by pushing a button, are immune.

“The software upgrade modifies certain vehicle control modules on Hyundai vehicles equipped with standard ‘turn-key-to-start’ ignition systems,” Hyundai said in a press release. “As a result, locking the doors with the key fob will set the factory alarm and activate an ‘ignition kill’ feature so the vehicles cannot be started when subjected to the popularized theft mode. Customers must use the key fob to unlock their vehicles to deactivate the ‘ignition kill’ feature.”

A total of 8.3 million cars are eligible for the free update. Owners of affected Hyundai and Kia models are encouraged to visit their local dealership to have the software upgrade installed. Updated vehicles also get a windshield decal indicating they’ve been equipped with anti-theft software.

Hyundai will also be releasing the patch in phases, the schedule of which you can view on their web page. For the February 14 release (part of Phase 1), owners of Hyundai 2017-2020 Elantra can receive the update. The model to receive the patch next is 2018-2022 Accent in June 2023 (part of Phase 2). The schedule for the remaining models is yet to be announced.


We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.


[ad_2]
Source link

Best Samsung Galaxy S23 Ultra Cases

0
[ad_1]

The Galaxy S23 Ultra is likely going to get all of the attention this year, from buyers. And that’s because it is the best of the best from Samsung. It also has the S Pen, so it’s more of a hybrid between the Galaxy S and Galaxy Note line of phones. It starts at $1,199 so it’s not a cheap phone. That means that you’re going to want to keep it in good shape and protect it. Which you can do with a case. So we’ve rounded up the very best cases for the Galaxy S23 Ultra here.

Best Samsung Galaxy S23 Ultra cases

In this list, you’ll find cases from Samsung as well as third-party cases from companies like Caseology, Ringke and others. So here are the best cases for the Galaxy S23 Ultra.

Samsung Silicon Cover

1 1

Samsung’s Silicon Cover is the same case that they have been offering with its phones for years now. It’s a pretty simple case, made of silicon for the Galaxy S23 Ultra. It looks and feels great in the hand. The only thing is that, because it is a soft-touch material, it does collect dust like crazy. It is available in a ton of colors too.

Samsung Silicon Cover – Samsung.com

Ringke Fusion

71pNKw8bD4L AC SL1500

  • Price: $14
  • Where to buy: Amazon

This case from Ringke is another good one for the Galaxy S23 Ultra. This is a clear case. So you won’t need to worry about it adding a lot of heft to your smartphone. That’s definitely good to see in this day and age. It’s clear, but it also comes in a matte-clear model and a smokey black model. The matte-clear might be the best option here, as traditional clear cases can get pretty disgusting quickly, due to fingerprints and other grease.

Ringke Fusion – Amazon

LK Protective Case

81qGXUpim7L AC SL1500

  • Price: $17
  • Where to buy: Amazon

Here’s another good looking clear case for the Galaxy S23 Ultra. This is from LK, who is pretty popular over on Amazon. But this one is military grade drop protection and won’t yellow. That’s something important to think about with clear cases, as they do tend to yellow after some time. But this one, apparently won’t. It also comes in a matte color, if you don’t want a 100% clear case.

AICase Rugged Case – Amazon

Caseology Nano Pop

51GQY1gfL AC SL1080

  • Price: $17
  • Where to buy: Amazon

The Nano Pop from Caseology is a newer collection of cases from the company, and they really “pop”. As you might expect from the name. This time around, it’s available in three colors: Black Sesame, Blueberry Navy, Avo Green. It’s a dual-layer case, which is going to offer a ton of protection for your new smartphone. It uses one color for the majority of the case, with the second being an accent color around the camera bump.

Caseology Nano Pop – Amazon

Samsung S-View Wallet Case

1 1

The Samsung S-View Wallet Case is another case that’s been around for quite some time. It basically is a flip case that has a small window in the corner to show you the time, date, battery percentage and some notifications. It does come in a slew of colors as well. So you can choose which one you want on your device.

Samsung S-View Wallet Case – Samsung.com

Samsung Frame Case

1 2

The Samsung Frame Case is a new case for Samsung this year, and it’s a quite interesting case. It’s available for all the Galaxy S23 models and it also comes in a few different colors too.

Samsung Frame Case – Samsung.com

Ringke Onyx

81YlGZj74zL AC SL1500

  • Price: $15
  • Where to buy: Amazon

The Ringke Onyx is one of my favorite cases for the Galaxy S23 Ultra. You see, it’s pretty minimal, and not very thick at all. And it does also have a textured back. Which makes it easier to hold onto. Of course, it has all of the cutouts for the usual things like the USB-C port, S-Pen slot and the speaker. So it’s a really good option to pick up.

Ringke Onyx – Amazon

Poetic Revolution Series

61kKeaepk1L AC SL1371

  • Price: $25
  • Where to buy: Amazon

Poetic is another popular one around these parts. The Revolution series is a really rugged case for the Galaxy S23 Ultra, which also has a built-in screen protector. And yes, the fingerprint sensor does work with this screen protector. So it’s a good option for a lot of people. Not to mention the fact that it does also have a built-in kickstand here.

teloxy Crystal Clear Case – Amazon

Caseology Skyfall

61Cseyw45yL AC SL1080

  • Price: $16
  • Where to buy: Amazon

Those looking for a clear case, the Caseology Skyfall is a great option. It is mostly clear, with a colored accent around the camera bump, and the frame. Caseology is available in two colors: matte black, and lilac purple. Which makes it a really great looking case, and one that won’t yellow either.

Caseology Skyfall – Amazon


[ad_2]
Source link

thinner bezels, USB-C & curvier design

0
[ad_1]

The iPhone 15 Pro is coming later this year, and thanks to 9to5Mac, we just got our first look at the phone. The site shared CAD-based renders for us to check out. These renders have been made by Ian Zelbo.

The iPhone 15 Pro CAD renders give us the very first look at the device

For those of you who are wondering, these renders are based on CAD files given by Apple to factories in Asia. CAD-based renders are usually shared by @OnLeaks but now come from a different source.

Such renders usually end up being quite accurate, so it’s easily possible this is what the iPhone 15 Pro will look like. The most noticeable design change comes in the form of a Type-C USB port at the bottom. The Lightning port is gone.

iPhone 15 Pro CAD based design 3

Apple already implemented Type-C to some other devices, including iPads, so it was only a matter of time before it arrives to iPhones. The EU’s decision to streamline charging ports may have something to do with it, though.

It will feature more curves, and a thicker camera bump

Now, another difference you’ll notice is the phone’s curvature. To be more accurate, in the curvature of the phone’s edges. You’ll notice the change both on the metal frame, and the glass. Let’s hope this change will make the phone more comfortable to hold and use, when not in a case.

The source also notes that the camera bump is thicker than it was before, and that is easily visible in the provided images. It still looks similar to the one on the iPhone 14 Pro, but it’s thicker. This could mean that we’ll get larger sensors on the inside.

iPhone 15 Pro CAD based design 2

We may also get solid-state buttons here, and thinner bezels too

It also seems like the rumors regarding solid-state buttons were true. The volume rockers look set to be capacitive buttons, not physical ones. We, of course, cannot be sure, but it sure seems like it. The same will happen with the power/lock button, if it happens with the volume buttons, of course, The mute switch is still here, though.

Now, if you take a look at the image provided below this paragraph, you’ll see the difference in bezel thickness. The bezels on the iPhone 15 Pro seem to be considerably thinner. The phone will retain the same 6.1-inch display size, but will be physically a bit smaller because of the thinner bezels.

iPhone 15 Pro CAD based design 4

All in all, the iPhone 15 Pro will look very similar to its predecessor, but with noticeably thinner bezels, more curves, a thicker camera bump, USB-C, and different buttons, it seems. So, it may look similar at first, but it’ll surely feel different.


[ad_2]
Source link

Google accepts to give clearer info to EU customers on its services to comply with EU regulations

0
[ad_1]

Big tech giants such as Google, Apple, and Amazon, often find themselves scrutinized by lawmakers, especially in Europe. Now, the EU has managed to make Google agree to something the EU has been pushing for: some transparency. Engadget reports that Google has agreed to provide clearer information to users on the Google Store, Google Play Store, Google Hotels, and Google Flights in Europe.

Google to give clearer info to users in Europe


The news comes from a press release by the EU Commission. Google will have to show whether it is an intermediary or it is selling products directly, it will also have to better inform customers about deliveries, returns, repairs, and more.

These moves are set in place so Mountain View can comply with EU regulations. These regulations have come up after a dialogue with the Consumer Protection Cooperation Network (CPC). The dialogue started all the way back in 2021.

EU commissioner for justice Didier Reynders said that EU customers are entitled to clear, complete information and that Google’s commitments to doing the mentioned above changes are a step in the right direction.

Google Flights and Google Hotels will have to indicate to customers whether they’re selling directly, or only acting as an intermediary for other companies. But that’s not all. These two search services have to also state what was used as a reference price for discounts that they show, and clarify that the reviews on Google Hotels aren’t verified.

All in all, these two services will have to comply with the same transparency rules followed by other platforms like Expedia.com (which is an online travel agency).

As we already mentioned above, two more services of Google are affected by the new changes. The Google Store will have to provide clear information on delivery prices, right of withdrawal, and repair or replacement options, and all of that info has to be “pre-contractual”, meaning before a contract was made.

Also, Google should make it easier to find info on vendors, such as legal name and address, as well as methods of contact.

Google will have to make it clear to developers on the Google Play Store that they have obligations under the Geo-blocking Regulation to make their apps accessible EU-wide. Basically, apps should be available across Europe. Also, means of payment from any country in the European Union have to be accepted in apps.

This change is, as you might suppose, put in place so all users will get to have the same rights and access the same content from anywhere in the European Union.

For now, the official date of the implementation of these changes has not been announced: neither by the European Commission nor by Google. Actions from regulations like this one, as some of you may know, may take months if not years to be implemented.

However, given the fact these requirements don’t seem too complicated to put in place, we might be looking at a smaller time frame for their implementation – but as anything policy, we can’t be sure until an official deadline has been set.

The Consumer Protection Cooperation Network, or the CPC will start to monitor the implementation of the commitments taken by Google. The CPC is a network of authorities who are responsible for the enforcement of consumer protection laws put in place by the European Union.

The biggest change that Google will have to tackle is the geo-blocking part. At the moment Google lets you change your country or region in the Play Store once a year. However, in doing so you might lose the content you’ve actually acquired before, in your previous country of residence. This is marked by the press release as an area where Google is still not fully compliant with the Geo-blocking Regulation.


[ad_2]
Source link

Mortal Kombat ransomware forms tag team with crypto-stealing malware

0
[ad_1]

It’s like a choose your own adventure game gone horribly wrong.

An “unidentified actor” is making use of these two malicious files to cause combo-laden mayhem on desktops around the world, according to new research from Talos.

The tag-team campaign serves up ransomware known as Mortal Kombat, which borrows the name made famous by the video game, and Laplas Clipper malware, a clipboard stealer. Depending on the flow of infection, targets can expect to find a demand for payment to unlock encrypted files or sneaky malware looking to grab cryptocurrency details from system clipboard functions.

These attacks have been taking place since December 2022 and have no specific target, with small and large organisations affected, as well as individuals. The infection chain is kick-started by an email harbouring a malicious attachment.

The email is cryptocurrency themed, and claims that a payment of yours has “timed out” and will need resending. Given how long it can take some cryptocurrency payments to be processed, this is likely to raise the curiosity of recipients.

The email comes with a dubious zip attachment containing a BAT loader that begins the infection process when it’s executed. The BAT loader kicks off a chain of events that results in the download and execution of the ransomware or the clipper malware, from one of two URLs. (The analysis by Talos does not include how it decides which to deploy, so it could be targeting or just random chance.)

It’s like a choose your own adventure game gone horribly wrong.

Laplas Clipper

Laplas Clipper is a form of Trojan, and it takes a very smart approach to cryptocurrency theft. Regular clipboard-swiping malware waits for a user to copy a cryptocurrency address (which looks like a long password) and then switches it out for an address owned by the scammer. The end result is that the victim sends their payment to the attacker instead of the intended recipient.

Laplas switches out to wallet addresses which look similar to the correct, intended destination. Rather than carrying a stack of addresses with it, it phones home, contacting its Command and Control (C2) server via HTTP GET for a close match.

It’s also able to generate imitation addresses for a wide variety of cryptocurrencies including Monero, Bitcoin, Ethereum, Solana, and even Steam trading URLs. This is, of course, very bad news for people who do a lot of wallet address copying and pasting.

In this instance, it creates both persistence on the infected machine via the AppData\Roaming\ folder and a Windows scheduled task which means Clipper activates “every minute for 416 days”. This essentially grants non-stop monitoring of a system. It then acts as mentioned above, switching out genuine wallet addresses for bogus imitations.

Malwarebytes detects Laplas Clipper as Trojan.Clipper.

Mortal Kombat ransomware

Mortal Kombat Ransomware is based on Xorist Commodity ransomware. According to Talos, it has mainly been seen in the US, as well as the Philippines, the UK, and Turkey. This type of ransomware is created via a builder program. The builder allows for a reasonable amount of customisation, which includes warning messages, desired file extension, wallpaper addition, the file extension used on encrypted files, and so on.

Once installed on a system, Mortal Kombat targets a large selection of files for encryption, based on their file extensions. It also drops a ransom note and changes the wallpaper for the PC. According to The Record, the wallpaper features the character Scorpion from…you guessed it…Mortal Kombat.

There is nothing subtle about this particular ransomware threat. Talos notes that files in the recycle bin are not spared from attack.

Applications and folders are removed from Windows startup, and indicators of infection are discreetly tidied up and removed. The ransom note reads as follows, pushing those impacted towards communication with the attackers via instant messaging:

YOUR SYSTEM IS LOCKED AND ALL YOUR IMPORTANT DATA HAS BEEN ENCRYPTED. DON’T WORRY YOUR FILES ARE SAFE. TO RETURN ALL THE NORMALLY YOU MUST BUY THE CERBER DECRYPTOR PROGRAM. PAYMENTS ARE ACCEPTED ONLY THROUGH THE BITCOIN NETWORK. YOU CAN GET THEM VIA ATM MACHINE OR ONLINE.

Instructions are then provided to download the aforementioned chat program, add the attackers as a “friend”, and begin communication.

Malwarebytes detects Mortal Kombat ransomware as Malware.Ransom.Agent.Generic.

Mortal Kombat Ransomware detection

How to avoid ransomware

  • Block common forms of entry. Create a plan for patching vulnerabilities in internet-facing systems quickly; disable or harden remote access like RDP and VPNs; use endpoint security software that can detect exploits and malware used to deliver ransomware.
  • Detect intrusions. Make it harder for intruders to operate inside your organization by segmenting networks and assigning access rights prudently. Use EDR or MDR to detect unusual activity before an attack occurs.
  • Stop malicious encryption. Deploy Endpoint Detection and Response software like Malwarebytes EDR that uses multiple different detection techniques to identify ransomware.
  • Create offsite, offline backups. Keep backups offsite and offline, beyond the reach of attackers. Test them regularly to make sure you can restore essential business functions swiftly.
  • Write an incident response plan. The period after a ransomware attack can be chaotic. Make a plan that outlines how you’ll isolate an outbreak, communicate with stakeholders, and restore your systems.

We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.


[ad_2]
Source link

YouTube Kids is merging with the main YouTube app

0
[ad_1]

YouTube Kids has been a safe bet for parents who wanted to plop their children down in front of their iPad to entertain them. This app filters and funnels child-friendly content for children to watch. Now, the Youtube Kids app is merging with the main YouTube app.

So, the standalone YouTube Kids app will be going away, but parents shouldn’t worry. They’ll still have a place for their children to watch their favorite kid-friendly content.

YouTube Kids is merging with the main YouTube app

This news comes from The Streamable. Folks who use YouTube Kids on game consoles, smart TVs, or streaming devices will find a difference. The YouTube Kids app will be gone. Instead of being a standalone app of its own, it will live within the main YouTube app.

When you open the YouTube app, you’ll be able to enter the Kids app from within the main app. If you use the kid’s app, then you should know that you’re able to make a kid’s profile.

When you open the main YouTube app, you’ll be able to select the kid account from the account picker. Then, you’ll be taken to the safe space on YouTube. The only issue is that there is an extra step. That can be an issue for parents who let their kids access YouTube Kids on their own.

Now, their child needs to go through the main app. They run the risk of seeing content that their parents don’t want them to see.

However, as noted by The Streamable, this could make YouTube Kids more accessible. While the YouTube app is available across a ton of platforms, YouTube Kids isn’t supported on a lot of platforms. Well, now that YouTube Kids is merging with YouTube proper, this will put this app on more platforms.

This is rolling out, so there’s a chance that you won’t see it right away. If you don’t see it, then you’ll want to wait a few days.


[ad_2]
Source link