New Go loader pushes Rhadamanthys stealer

0
[ad_1]

Malware loaders (also known as droppers or downloaders) are a popular commodity in the criminal underground. Their primary function is to successfully compromise a machine and deploy one or multiple additional payloads.

A good loader avoids detection and identifies victims as legitimate (i.e. not sandboxes) before pushing other malware. This part is quite critical as the value of a loader is directly tied to the satisfaction of its “customers”.

In this blog post, we describe a malvertising campaign with a loader that was new to us. The program is written in the Go language and uses an interesting technique to deploy its follow-up payload, the Rhadamanthys stealer.

Malicious ad targets system administrators

PuTTY is a very popular SSH and Telnet client for Windows that has been used by IT admins for years. The threat actor bought an ad that claims to be the PuTTY homepage and appeared at the top of the Google search results page, right before the official website.

In this example, the ad looks suspicious simply because ad snippet shows a domain name (arnaudpairoto[.]com) that is completely unrelated. This is not always the case, and we continue to see many malicious ads that exactly match the impersonated brand.

Fake PuTTY site

The ad URL points to the attacker controlled domain where they can easily defeat security checks by showing a “legitimate” page to visitors that are not real victims. For example, a crawler, sandbox or scanner, will see this half finished blog:

Real victims coming from the US will be redirected to a fake site instead that looks and feels exactly like putty.org. One of the big differences though is the download link.

The malicious payload is downloaded via a 2 step redirection chain which is something we don’t always see.

puttyconnect[.]info/1.php
HTTP/1.1 302 Found
Location: astrosphere[.]world/onserver3.php
astrosphere[.]world/onserver3.php
HTTP/1.1 200 OK
Server: nginx/1.24.0
Content-Type: application/octet-stream
Content-Length: 13198274
Connection: keep-alive
Content-Description: File Transfer
Content-Disposition: attachment; filename="PuTTy.exe"

We believe the astrosphere[.]world server is performing some checks for proxies while also logging the victim’s IP address. This IP address will later be checked before downloading the secondary payload.

That PuTTy.exe is malware, a dropper written in the Go language (version 1.21.0).

Its author may have given it the name “Dropper 1.3“:

Follow-up payload

Upon executing the dropper, there is an IP check for the victim’s public IP address. This is likely done to only continue with users that have gone through the malicious ad and downloaded the malware from the fake site.

zodiacrealm[.]info/api.php?action=check_ip&ip=[IP Address]

If a match is found, the dropper proceeds to retrieve a follow-up payload from another server (192.121.16[.]228:22) as seen in the image below:

To get this data, we see it uses the SSHv2 (Secure Shell 2.0) protocol implemented via OpenSSH on a Ubuntu server. We can only think of using this protocol to make the malware download more covert.

That payload is Rhadamanthys which is executed by the parent process PuTTy.exe:

Malvertising / loader combo

We have seen different types of loaders via malvertising campaigns, including FakeBat which we profiled recently. Given how closely the loader is tied to the malvertising infrastructure it is quite likely that the same threat actor is controlling both. The service they offer to other criminals is one of malware delivery where they take care of the entire deployment process, from ad to loader to final payload.

We reported this campaign to Google. Malwarebytes and ThreatDown users are protected as we detect the fake PuTTY installer as Trojan.Script.GO.

ThreatDown users that have DNS Filtering can enable ad blocking in their console to prevent attacks that originate from malicious ads.

Indicators of Compromise

Decoy ad domain

arnaudpairoto[.]com

Fake site

puttyconnect[.]info

PuTTY

astrosphere[.]world
0caa772186814dbf84856293f102c7538980bcd31b70c1836be236e9fa05c48d

IP check

zodiacrealm[.]info

Rhadamanthys

192.121.16[.]228:22
bea1d58d168b267c27b1028b47bd6ad19e249630abb7c03cfffede8568749203

[ad_2]
Source link

Whatsapp could soon let you disable the link previews in chats

0
[ad_1]

We previously reported a new feature in WhatsApp, where users can protect their IP address in calls. Now WhatsApp is enhancing user privacy further with a new feature in development that gives users more control over their messages.

Reports indicate that WhatsApp is working on an update that will allow users to disable link previews within chats. This new feature named “Disable link previews” is currently being tested in the WhatsApp beta for Android 2.24.7.12 and is expected to roll out to users in the beta program with a future update soon. It will likely roll out to all users once the testing is complete.

Link previews fetch a preview of webpages shared in chats

Link previews are a convenient feature in WhatsApp, automatically fetching a preview of webpages shared in chats. WhatsApp typically relies on its servers to generate these previews. However, they can sometimes expose information before recipients click on the link, potentially leading to clickbait. To address this, WhatsApp is developing the option to disable link previews, giving users the choice to generate previews or not when sharing links. This empowers users to exercise greater caution and protect sensitive information contained within previews.

Previously, the platform introduced features like disappearing messages and call encryption to safeguard user communication. By offering this new option, WhatsApp aims to provide users with more control over their online interactions and the information they share.

Disable link previews in WhatsApp
Credit: WABetaInfo

However, users will still be able to click the link and access whatever there is

While disabling link previews can mitigate the risk of misleading links, it’s important to note that users can still see the actual URL when a link is shared. Additionally, malicious actors might use deceptive link shorteners to bypass this control. Nevertheless, this added layer of control enables users to be more cautious and make informed decisions about the links they click within WhatsApp chats.

The upcoming update is currently in the development stage in the WhatsApp beta, with no announced release date yet. Once implemented, users can expect to find the option to disable link previews in their WhatsApp settings. This feature is part of WhatsApp’s ongoing efforts to prioritize user privacy and security. Nonetheless, even with the link previews disabled, users will still continue to see link previews from their contacts unless they disable it on their end.

Aside from the privacy features, WhatsApp is also working on improving the functionality of the app. You will soon be able to share a 1-minute video on your status.


[ad_2]
Source link

Samsung boosts 3nm yield rate, closes gap with TSMC

0
[ad_1]

Samsung has reportedly significantly improved its 3nm yield rate in recent times. The yield rate initially hovered around 10-20% but has now increased by over threefold. The information came from noted X tipster @Tech_Reve. The source didn’t share a precise figure but said that Samsung’s 3nm yield is still lower than TSMC’s.

Samsung sees big improvement in 3nm yield

Yield rate is a measure of the usable chips manufactured at a facility. It is calculated as the percentage of the total number of chips produced to the maximum chip count on one wafer. If the yield rate is high, the number of defective chips is low. In other words, a high yield rate translates to a greater manufacturing capacity.

Samsung started making 3nm chips in 2022 but has been struggling with the yield rate. It switched from the FinFET transistor architecture to the more advanced GAA architecture and is seemingly unable to get things right. TSMC, the Korean firm’s arch-rival in the semiconductor foundry industry, is still using the FinFET architecture and is enjoying a better 3nm yield.

This has helped the Taiwanese company win big manufacturing contracts. Despite a headstart in 3nm mass production, Samsung is lagging behind its rival. There are some positive signs though, if the latest report is accurate. While TSMC still has a better 3nm yield, the technological gap between the two firm’s 3nm processes is narrowing.

According to the tipster, Samsung’s second-gen 3nm technology is now on par with TSMC’s N3P process node in terms of PPA (Power, Performance, and Area) metrics. Compared to 4nm chips, which employ the FinFET architecture, the power efficiency and logic area have increased by 20-30%. This should help Samsung gain some foothold in the 3nm semiconductor market.

Samsung’s 2nd-gen 3nm process is undergoing a confusing rebranding

The report about improved 3nm yield comes just weeks after Samsung informed its customers about a rebranding of its 2nd-gen 3nm process. The company will call the process 2nm instead of 2nd-gen 3nm. Yes, it is technically a 3 nanometer process but the Korean firm is renaming it to 2nm. Its “real” 2 nanometer chips are expected to arrive in the second half of 2025.

Samsung has already rewritten the manufacturing contracts it signed earlier for its 2nd-gen 3nm process. Japanese AI startup PFN (Preferred Networks) is its first customer of the rebranded 2nm chips. Qualcomm has also requested 2nm samples from Samsung, though it likely wants samples of the real 2nm chip and not the misleadingly rebranded one.


[ad_2]
Source link

Thousands of WordPress Websites Hacked with New Sign1 Malware

0
[ad_1]
Thousands of WordPress Websites Hacked with New Sign1 Malware

Sign1 malware targets WordPress websites, injecting malicious code that redirects visitors to scams or bombards them with ads – Sucuri researchers discovered this evasive malware, urging website owners to update software and implement security measures to protect their sites.

Cybersecurity researchers at Sucuri have uncovered a concerning new malware campaign targeting WordPress websites. Dubbed “Sign1,” the malware injects malicious code into vulnerable websites, ultimately redirecting visitors to scam sites or bombarding them with unwanted pop-up ads.

The new malware discovery emerged shortly after Check Point Software Technologies Ltd. disclosed a malicious campaign named FakeUpdates, which specifically targeted WordPress websites with malware.

Sign1 malware’s stealthy tactics make it a significant threat. The malware leverages time-based randomization to generate dynamic URLs, making it difficult for security software to identify and block them. Additionally, the code itself is obfuscated, further hindering detection.

Perhaps most concerning is Sign1’s ability to target visitors from specific websites, such as popular search engines and social media platforms. This suggests a level of sophistication, potentially allowing attackers to focus on users they deem more susceptible to scams.

Sucuri’s report estimates that over 39,000 WordPress websites have been infected with Sign1 thus far. Website owners are urged to take immediate action to protect their sites and visitors.

How to Protect Your WordPress Website from Sign1

If you are using WordPress as your website’s content management system (CMS), here are some simple yet vital steps to protect the website from Sign1 and other similar malware:

  • Update WordPress core, themes, and plugins regularly. Outdated software often contains vulnerabilities that attackers exploit.
  • Implement strong security practices. This includes using secure passwords, enabling two-factor authentication, and keeping backups of your website data.
  • Use a reputable website security scanner. Regularly scan your website for malware and vulnerabilities.
  • Be cautious when installing plugins. Only install plugins from trusted sources and with good reviews.

Website owners who suspect their site may be infected with Sign1 malware should:

  • Contact a security professional or your WordPress hosting company. They can help identify and remove the malware.
  • Change all website passwords. This includes the WordPress admin password, FTP password, and database password.

Nevertheless, the discovery of Sign1 malware goes on to show the vulnerable state of websites. With more than 835 million sites using WordPress even a small threat could end up compromising a staggering number of sites.

It’s crucial to stay informed about the latest security vulnerabilities and take proactive steps to protect your website. Security researchers like Sucuri play a vital role in identifying and mitigating these threats.

  1. Hackers Hit WordPress Sites with Balada Malware
  2. Tips for Using Uploader Widgets on WordPress Blogs
  3. Zero-Day Exploit Threatens 200,000 WordPress Sites
  4. Database Malware Strikes Vulnerable WordPress Sites
  5. 5 Signs your WordPress Site is Hacked (And How to Fix It)

[ad_2]
Source link

Galaxy M55 leak reveals 45W charging, 12GB RAM & more

0
[ad_1]

Earlier this month, Samsung launched the Galaxy A55 as its premium mid-range offering for 2024. The company is now readying an M-series equivalent of the device. Leaked renders have revealed that the Galaxy M55 will sport a slightly different design than the A-series model. A fresh leak has just revealed its detailed specs and those differ too.

The Galaxy M55 has its specs leaked ahead of launch

According to an MSPowerUser report, Samsung will equip the Galaxy M55 with a 6.7-inch Super AMOLED+ display with a Full HD+ resolution, a 120Hz refresh rate, and 1,000 nits of peak brightness. It is a slightly larger panel than the Galaxy A55 (6.6 inches), though the rest of the display specs are unchanged. Both phones have a punch-hole display design, so they look identical from the front.

However, Galaxy M55’s back panel appears slightly curved on the edges. It is also likely a plastic back instead of glass. The frame is also expected to be made of plastic rather than aluminum. Speaking of the frame, Samsung isn’t employing its Key Island frame design here. It’s a standard flat frame with power and volume buttons on the right side. The power button isn’t recessed, hinting at an under-display fingerprint scanner.

Samsung Galaxy M55 5G leaked renders

The camera design is similar to other Galaxy smartphones launched lately. Samsung will reportedly offer a 50MP main camera, an 8MP ultrawide lens, and a 2MP macro camera on the back. The Galaxy M55 has a 50MP selfie camera on the front. You should get some premium camera features such as OIS (Optical Image Stabilization), dual recording, 4K video recording, and Nightography.

45W charging and 12GB RAM may be on the cards

The Galaxy M55 will reportedly pack a 5,000mAh battery with 45W Super Fast Charging 2.0, a first for non-flagship Samsung phones. Qualcomm’s Snapdragon 7 Gen 1 chipset will power the phone, supported by 8GB and 12GB RAM options. Storage options will include 128GB and 256GB, with Samsung also offering microSD card support up to 1TB. The phone boasts Dolby Atmos sound, Bluetooth v5.2, NFC, and Samsung Knox Vault.

Samsung will ship the Galaxy M55 with Android 14-based One UI 6.1. The device should get four major Android OS updates (up to Android 18) and five years of security patches. The handset will be available in Black and Sky Blue colors and will be relatively lightweight at just 180 grams. A launch date and pricing details are missing but should be available soon. The Galaxy M54 arrived on the market in April 2023.


[ad_2]
Source link

Here’s a glimpse of Gemini in Google Messages

0
[ad_1]

It’s no little-known fact that Google is set to introduce Gemini into the entire Android ecosystem. One way it plans to do this is by implementing Gemini into core Google Apps, and Google Messages is one of the first apps up. Thanks to some sleuth work by AssembleDebug, we finally got a glimpse of Google’s vision for an AI-integrated messaging service.

Right now, this is still in the developmental stage, so there could be some major changes between now and the official launch. Also, we’re not sure if all of the features showcased will make it to the final product. So, you’re going to want to take this news cautiously.

Here is a glimpse at Gemini integrated into Google Messages

AssembleDebug was able to get a glimpse at several of the features that Gemini will bring to Google Messages. You will be able to access Gemini in a separate conversation. This is similar to Snapchat’s My AI. Using it will be just like using any other chatbot; you will type your query into the text field, press send, and wait for a text message-style response. However, this will differ from a regular chatbot because many of the responses will be tailored to text message conversations.

Maps integration

Looking at the screenshots below, we see Gemini generating several forms of responses. For example, in the first screenshot, we simply see the text “Find something nearby.” Under that, we see that Gemini was able to tap Google Maps to find nearby locations. It showed a list of nearby locations. What’s neat about this is the fact that each entry shows the name, a link to that location (we don’t know if it’s leading to that location’s website or if it’s leading to that location’s Google Maps profile), star rating, and hours of business.

Code generation

In the next screenshot, we see an example of the chatbot generating code. It generated a bash script to list files in Foldee. Under the code, we see an explanation. This shows Google’s commitment to helping AI users with their coding rather than just spitting out the code.

Emoji reactions

For the third screenshot, we see two things. Firstly, we see that it’s able to generate images within chat. So, you will be able to download these images from the conversation. Next, if you look at the top message in the same screenshot, we see Gemini reacting to an emoji with the text “Thanks for the thumbs-up”. That might not be the most useful feature, but it’s still a nice touch.

The last screenshot shows that Gemini in Google Messages will not be able to process uploaded images just yet. So, we are going to have to wait for that functionality.

Other things to note

One important thing to know about this feature is the fact that there’s a possible security risk. Using Gemini in Google Messages means that conversations will not be encrypted. So, there’s a slight chance that the messages you send to Gemini will be vulnerable.

In terms of availability, the news is a little bit disappointing. Currently, Google is testing this in the latest version of Google Messages (version messages.android_20240318_00_RC00.phone.openbeta_dynamic). So, if you’re not signed up for the Google Messages beta, then you will not be able to access the feature. Even if you currently have the beta, it still took tinkering and messing around with the software to activate Gemini in Google Messages.

Google said that it will start rolling out this feature to the beta version of the app, but the list of eligible devices is pretty limited. In order to use this feature, at least initially, you need to have a Pixel 6 or newer, Pixel Fold, Galaxy S22 or newer, or a Galaxy Z Flip/Fold or newer. We don’t know when Google plans on bringing this feature to more devices.


[ad_2]
Source link

Teachers fear that TikTok ban will hurt education in US

0
[ad_1]

Fearful TikTok creators are concerned about the potential ban of the popular short-content platform. One of the concerns expressed by people is the loss of learning opportunities for children. With the platform deemed a national security threat by the US government, TikTok’s parent company ByteDance, will soon face a ban, unless it chooses to sell the platform to an American entity.

Teachers say that children will lose countless learning opportunities if there’s no TikTok

Several TikTokers have voiced fears about a ban in a Reuters article headlined “Content creators worry about miseducation in a world without TikTok”. One public school teacher from a rural Southern town saw her TikTok following skyrocket as she used the platform to teach grammar lessons to her students. Like so many others, the ban might cripple all her educational endeavors now that they have over 5.8 million followers.

Dr. Youn, who has 8.4 million followers on TikTok, uses his page to educate people and share some insights with them. He underscores how important it is to have access to this social application for news purposes, especially for youngsters. A different user who has up to 1M followers targets issues like Transgenderism and Body Image through Tiktok, teaching kids during their formative years.

However, Karen North from the University of Southern California is worried about privacy hazards on TikTok. Although it is useful as an educational tool, she cautions against voluntarily providing personal information to a platform that may not abide by the United States’ privacy regulations.

The uncertainty about TikTok’s future in the US is making educators anxious

The potential prohibition of TikTok makes one wonder what the future holds for social media and freedom of expression in general. The creators are concerned about the effects of banning TikTok or selling it to a US-based company on educational content and information access. The uncertainty surrounding the future of TikTok raises broader questions about digital platforms and individual freedoms.

As TikTok nears its climax in the US, its worth as an education tool is under discussion by creators and teachers alike. These talks will not only determine what will happen to TikTok but also shape online learning and information flow for years to come.


[ad_2]
Source link

Samsung bags a massive $752 million AI chip order from Naver

0
[ad_1]

Samsung has dominated the AI chip market, securing an order valued at $752M for its Mach-1 AI accelerator chip production. This move shows how ambitious the Korean tech giant is to disrupt NVIDIA’s stronghold on the AI accelerator segment and be a key player in the industry.

Samsung steals $752M order from NVIDIA, producing AI accelerator chips for Naver

Mach-1 is an in-house AI accelerator chip that Samsung has released. It has attracted attention with its superior performance compared to those of NVIDIA. Naver Corp has contracted to buy about $752 million worth of Mach-1 chips from Samsung. In partnering with Samsung, Naver seeks a way to relieve itself of NVIDIA’s dependency as the demand for alternatives continues growing in the semiconductors market.

This decision reflects a wider trend within the industry towards dual sourcing as companies look to avoid risks associated with dependence on only one supplier. Competitive pricing and innovative technology have made Samsung an attractive option compared to NVIDIA for AI accelerator solutions.

According to DigiTimes Asia, the negotiations might finalize with Mach-1 priced at around $3,756 per unit while Naver plans on purchasing between 150,000 and 200,000 units. This partnership will not only solidify Samsung’s presence in the AI-chip market but also open up opportunities for collaborations with other tech giants.

Samsung might also partner with major players in the USA

Samsung is considering expansion into America by talking with major players like Microsoft and Meta. By leveraging the momentum gained from the Mach-1 deal, Samsung intends to secure more partnerships with leading tech organizations, cementing its position as a prominent participant within the AI accelerator space.

NVIDIA’s AI accelerator card suffers from data bottlenecks due to general-purpose processors and high-power DRAM chips. Meanwhile, Mach-1 comes with proprietary processors and low-powered DRAM chips that result in fewer data bottlenecks thus improving power efficiency. Moreover, this chip is much cheaper than NVIDIA’s solution, which makes it attractive for those companies looking for cost-effective AI.

Samsung is seeing more success within the AI chip market and therefore stiff competition between players in this space seems imminent. With its inventive know-how, advanced technology, and strategic partnerships, Samsung can challenge NVIDIA’s supremacy in the segment and reshape the AI accelerator industry.


[ad_2]
Source link

Google backports new Fitbit Workout UI to first-gen Pixel Watch

0
[ad_1]

Early adopters of the first-gen Google Pixel Watch are being treated with the March Feature Drop which includes the new Fitbit Workout UI. These new features make it easy for wearers to gain valuable insights about their vitals with just a glance.

The first-generation Pixel Watch will now get access to the same Fitbit Workout UI that Google introduced in the smartwatch’s second generation. The March Feature Drop, announced earlier this month for the Pixel smartphone and smartwatch series, is now being rolled out.

What new features does the March Feature Drop have for Pixel smartwatches?

The March Feature Drop revamps the original Google Pixel smartwatch and brings it in line with the newer models. Simply put, the first-gen Pixel Watch is getting the new Fitbit Workout UI.

The original User Interface (UI) had multiple stats cramped into two rows on the same face. The new UI offers a semi-circular ring for heart rate zones, which is way more visually appealing.

The new UI has key stats in a list that users can access by swiping up or down. Even though four stats appear on the first page and three on the second, this is way more informative at a glance compared to the old UI.

The Fitbit Workout UI now reveals other metrics when users swipe right and to the left like exercise controls. Additionally, Google has changed the shape of the Lock, End, and Pause buttons. While they were circular, the new UI has pill-shaped buttons. As the controls are effectively larger, it is now easier to tap them while working out.

The update includes the much-needed Auto Workout Mode, which promises to detect running, walking, elliptical, spinning, outdoor bike, treadmill, or rowing quickly and reliably. Curiously, the Fitbit Relax app for breathing exercises is missing in the update. Still, Google is offering Pace Training and Heart Zone Training.

Google had already unlocked the ability to obtain public transit directions in Maps on Pixel Watch via a recent Wear OS update.

How to install the latest Google Pixel Watch March Feature Drop update?

Google is rolling out the Fitbit Workout UI through the Fitbit app, which is now on version 3.19. First-gen Pixel Watch owners will have to first update their Fitbit app from the Play Store.

Just got new Fitbit Exercise UI on PW1
byu/Working-March inPixelWatch

There have been some complaints about the new features not working on the original Pixel Watch. Some users have indicated that the latest update demands a full reboot. It is possible that the smartwatch needs a complete power cycle to better synchronize its sensors with the new software.


[ad_2]
Source link

GPT-5 might launch this summer

0
[ad_1]

Individuals and businesses alike are enjoying using OpenAI’s GPT-4 Turbo model. However, as powerful as it is, we can’t help but look toward the future, and the future may be upon us sooner than we expected. According to a new report, GPT-5, if the company decides to call it that, may launch this summer.

In a recent interview with Lex Fridman, OpenAI CEO, Sam Altman, said that the company is going to release “an amazing new model” this year. Since GPT-4 is out and about, the logical next step will be GPT-5. However, neither Sam nor any other OpenAI employee officially stated that. So, this is still speculative.

GPT-5 may arrive this summer

Right now, information on GPT-5 is extremely scarce. So, we have no idea how much more powerful than GPT-4 it will be. In fact, we don’t even know if the company is planning on calling it GPT-5. We don’t have a solid idea of the company’s naming scheme for its models just yet. ChatGPT was introduced to the public with GPT-3.5, and that hints that the company could adopt a main and .5 naming scheme. However, with a GPT-4, the company introduced a Turbo version. So, this new model’s name will remain a mystery until the company launches it, most likely.

Since summer is only a few months away, we are certain to get some leaks or rumors as to what GPT-5 will bring to the table. Meanwhile, we can expect improvements in reasoning, contextual understanding, accuracy, speed, etc. That information has not been officially revealed, but those seem like the likely suspects. One source close to the matter said that GPT 5 will be “materially better” than GPT-4. Hopefully, that’s the case, as it’d be rather weird if it was worse.

With the launch of GPT-5, one can only wonder what sort of multimodal capabilities will come with it. GPT-4 is able to tap DALL-E to generate images. Well, with Sora set to hit the public at some point in the near future, we wonder if there’s a chance that GPT-5 will be able to generate videos through Sora integration.

In any case, we will all have to wait for that information to be revealed. If GPT-5 is going to come in the summer, then we’ll be waiting until late September at the very latest. So, those of us who are excited about this will just have to be patient.


[ad_2]
Source link