Linux Admins Beware! Fake PuTTY Client Rhadamanthys stealer

0
[ad_1]

A malvertising campaign has been discovered deploying a fake PuTTY client to deliver the Rhadamanthys stealer, a dangerous malware.

This campaign cleverly exploits the trust in the widely used SSH and Telnet client, PuTTY, by presenting a counterfeit website through malicious ads at the top of Google search results.

This article delves into the mechanics of this attack, the role of malware loaders, and the subsequent deployment of the Rhadamanthys stealer, underscoring the need for heightened vigilance among Linux administrators.

Malware Loader

Malware loaders, also known as droppers or downloaders, play a pivotal role in the cybercriminal ecosystem.

Document

Free Webinar : Mitigating Vulnerability & 0-day Threats

Alert Fatigue that helps no one as security teams need to triage 100s of vulnerabilities.:

  • The problem of vulnerability fatigue today
  • Difference between CVSS-specific vulnerability vs risk-based vulnerability
  • Evaluating vulnerabilities based on the business impact/risk
  • Automation to reduce alert fatigue and enhance security posture significantly

AcuRisQ, which helps you to quantify risk accurately:

Their primary function is infiltrating a machine and deploying additional payloads while evading detection.

A sophisticated loader delivers malware and ensures that the victim is legitimate, thereby maximizing the attack’s impact.

The loader discussed in this campaign is particularly noteworthy for its use of the Go programming language and an innovative technique to deploy the Rhadamanthys stealer.

Malwarebytes has reported that the latest version of Go loader is being used to deliver the Rhadamanthys stealer malware.

This new variant is being actively distributed and poses a significant threat to organizations and individuals. 

The Malvertising Campaign

The campaign begins with a malicious ad that masquerades as the homepage for PuTTY.

malicious ads
malicious ads

This ad, cunningly placed above the official site in Google search results, directs unsuspecting users to a domain controlled by the attackers.

The domain, arnaudpairoto[.]com, is a red flag due to its irrelevance to PuTTY, highlighting the importance of scrutinizing domain names in ads.

Crawler, sandbox, or scanner, will see this half-finished blog
Crawler, sandbox, or scanner, will see this half-finished blog

Fake PuTTY AdVictims from the US are redirected to a counterfeit site that mirrors putty.org, with the critical difference being the download link.

Big difference though is the download link
A big difference though is the download link

This link initiates a two-step redirection process, ultimately leading to downloading a malicious PuTTY executable from the astrosphere[.]world.

puttyconnect[.]info/1.php
HTTP/1.1 302 Found
Location: astrosphere[.]world/onserver3.php
astrosphere[.]world/onserver3.php
HTTP/1.1 200 OK
Server: nginx/1.24.0
Content-Type: application/octet-stream
Content-Length: 13198274
Connection: keep-alive
Content-Description: File Transfer
Content-Disposition: attachment; filename="PuTTy.exe"

This server performs checks for proxies and logs the victim’s IP address, setting the stage for the delivery of the Rhadamanthys stealer.

Cybertron Technologies has recently tweeted about a malvertising campaign that leverages the Go Loader to deploy the Rhadamanthys Stealer.

The Rhadamanthys Stealer: The Final Payload

Upon execution, the fake PuTTY client, dubbed “Dropper 1.3” by its author, verifies the victim’s IP address to ensure the malware was downloaded through the deceptive ad.

The dropper proceeds to retrieve a follow-up payload from another server
The dropper proceeds to retrieve a follow-up payload from another server

Successful verification triggers the retrieval of the Rhadamanthys stealer from another server, utilizing the SSHv2 protocol for a covert download.

Rhadamanthys Stealer DeploymentThe Rhadamanthys stealer, once executed, poses a significant threat by stealing sensitive information from the compromised system.

This highlights the critical nature of the loader-malvertising combo, in which the threat actor meticulously manages the entire deployment process, from ad to loader to final payload.

The discovery of this malvertising campaign serves as a stark reminder of the constant vigilance required in the digital age.

System administrators, in particular, must be wary of seemingly legitimate tools and websites as cybercriminals continue to find innovative ways to breach defenses.

IOC

Decoy ad domain

arnaudpairoto[.]com

Fake site

puttyconnect[.]info

PuTTY

astrosphere[.]world0caa772186814dbf84856293f102c7538980bcd31b70c1836be236e9fa05c48d

IP check

zodiacrealm[.]info

Rhadamanthys

192.121.16[.]228:22
bea1d58d168b267c27b1028b47bd6ad19e249630abb7c03cfffede8568749203

With Perimeter81 malware protection, you can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits. All are incredibly harmful and can wreak havoc on your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

Step-by-Step Guide to Creating Your First Crypto Wallet

0
[ad_1]
Step-by-Step Guide to Creating Your First Crypto Wallet

Entering the dynamic world of cryptocurrencies is pretty exciting. But one can easily get overwhelmed with the amount of information that floods you once you dip your toes. 

Since you’re looking to create a crypto wallet, this guide was designed to help you as a newbie complete this process without a hassle. It will highlight the distinction between custodial and non-custodial wallets, emphasizing the benefits of each, and walk you through the setup process. 

Two Types of Crypto Wallets

There are two main types of wallets: custodial and non-custodial. Understanding the difference between these two is detrimental to making the right decision. 

Custodial Wallets

Custodial wallets are managed by a third-party entity, such as a cryptocurrency exchange or a specialized wallet service. When you use a custodial wallet, the private keys to your cryptocurrencies are held by the service provider.

Advantages:

  • Custodial wallets often offer a user-friendly interface, making them accessible to beginners. 
  • Users don’t need to worry about managing their private keys, as the service provider takes care of security.
  • If you forget your password or lose access to your account, you can recover your funds through the service provider’s customer support.

Disadvantages:

  • By entrusting your private keys to a third party, you’re exposed to the risk of the service being hacked. 
  • Since the service provider controls the wallet’s private keys, they have the ultimate authority over your funds. This control includes the ability to freeze accounts or delay transactions, which might be concerning for some users.

Non-Custodial Wallets: Security and Autonomy

Non-custodial wallets give you full control over your cryptocurrency by allowing you to manage your wallet’s private keys. This means that only you have access to your funds and the authority to make transactions.

Advantages:

  • Since you’re the sole holder of the private keys, the risk of external breaches is significantly reduced. 
  • You have complete autonomy over your funds, without any intermediary having the power to freeze or manage your assets. 

Disadvantages:

  • Managing your private keys means you must be vigilant in securing them. Losing your keys without a backup can result in the irreversible loss of your assets.
  • Non-custodial wallets can be more complex to use, especially for those new to cryptocurrency. 

Your choice between a custodial and non-custodial wallet will depend on what you value more: convenience or control. For those who prioritize ease of use and are just getting their feet wet in the crypto world, a custodial solution might be the way to go.

On the other hand, if you’re keen on having full control over your assets, a non-custodial wallet is your best bet. But then you must learn how to safely store and manage your keys, which might be tough for a beginner.

Setting Up Your Wallet

Regardless of the type of wallet you choose, the setup process is generally straightforward. Here’s how you can get started:

Research

Look for a reputable wallet provider. For non-custodial options, consider security features and compatibility with different cryptocurrencies. For custodial wallets, assess the platform’s reliability and customer service.

Download and Install

Once you’ve chosen your provider, download the wallet application on your smartphone or computer. Follow the installation instructions.

Create Your Wallet

Open the application and select the option to create a new wallet. You’ll likely be prompted to set up a password or PIN for additional security.

Backup Your Wallet

If you’re using a non-custodial wallet, you’ll be given a recovery phrase. It’s crucial to write this down and store it in a safe place. This phrase is your lifeline if you ever lose access to your device.

Deposit Cryptocurrency

You can now transfer crypto into your new wallet. You can do this by purchasing cryptocurrency through an exchange and sending it to your wallet’s address or receiving it from someone else.

Introducing Nonbank: The Best of Both Worlds

Now, let’s talk about Nonbank (PDF). It’s a new player but their concept is intriguing. Nonbank offers the convenience of a custodial wallet with the security and control of a non-custodial option. The upcoming Tron Wallet feature is especially noteworthy for those interested in managing both digital and traditional financial assets seamlessly. 

Setting up a wallet with Nonbank is a breeze. Their user interface is intuitive, making it easy for beginners to navigate. With Nonbank, you’re not just getting a wallet; you’re getting a comprehensive platform that supports your journey through the crypto space.

To Sum Up

Choosing the right wallet is a critical step for anyone venturing into the cryptocurrency world. Whether opting for a custodial or non-custodial wallet, the primary considerations should be convenience, security, and control. Nonbank can be a great tool to simplify the management of your digital and traditional assets, which makes it an excellent choice for you as a newcomer. 

  1. 5 Types of Crypto You Didn’t Know Existed
  2. The Future of MATIC and What to Expect in 2024
  3. Navigating the new frontier of cryptocurrency futures
  4. What the Bitcoin ETF Approval Mean for the Crypto Market
  5. Enhancing Blockchain Randomness To Eliminate Trust Issues
  6. Exploring the Phenomenal Rise of Ethereum as a Digital Asset

[ad_2]
Source link

Ulefone joins AliExpress Anniversary Sale with massive discounts

0
[ad_1]

AliExpress is currently hosting its Anniversary Sale with massive discounts, and Ulefone has decided to join the party. The company is now offering up to 65% off on its devices via AliExpress.

Ulefone has joined the AliExpress Anniversary Sale with some massive discounts

These discounts will be available until March 27, so keep that in mind, you only have a few days to grab something. Ulefone did throw in a bunch of devices in the mix here, so let’s highlight some of them.

The Ulefone Power Armor 16S and Note 17 Pro are the first that come to mind. These are both newer devices, and both are discounted by 60%. The former is a rugged device with a huge battery, while the latter is a more regular smartphone.

The Ulefone Power Armor 16S has a huge speaker on its back

The Ulefone Power Armor 16S has a 36mm smartphone speaker on the back with an 11.5cc sound cavity. It comes with a huge battery, expandable RAM thanks to virtual RAM, and more. It is now priced at $129.99.

Ulefone AliExpress Anniversary Sale 2024 image 2

The Ulefone Note 17 Pro, on the flip side, has a 6.78-inch AMOLED display with a 120Hz refresh rate. It is drop-proof too, and the display is protected by the Gorilla Glass 5. This handset is priced at $239.99.

Ulefone AliExpress Anniversary Sale 2024 image 4

The Ulefone Armor 23 Ultra has two-way satellite messaging built in

What else is on offer? Well, the Ulefone Armor 23 Ultra, for example. That rugged handset has two-way satellite messaging built in, and a 50% discount. It’s now priced at $369.99.

The Ulefone Armor 24 can now be purchased for $239.99, and it comes with a night vision lens. If you need a smartphone with a thermal camera, Ulefone has you covered. The Ulefone Power Armor 17T Ultra has the FLIR Lepton 3.5 sensor for thermal imaging. That device is priced at $429.99.

The Ulefone Armor 22’s 8GB RAM variant with 128GB of storage costs only $158.99 now, while more devices are available. If you follow the link below, you’ll be able to see everything that Ulefone is offering.

All Ulefone discounts

Buy the Ulefone Power Armor 16S (AliExpress)

Buy the Ulefone Note 17 Pro (AliExpress)


[ad_2]
Source link

Senators request that Congress declassifies TikTok briefing

0
[ad_1]

As the debate around potentially banning TikTok comes to a head, two members of the Senate have asked for the Congress TikTok briefing to be declassified. TikTok, the popular Chinese video-sharing platform, has been in hot water for a long time now. Rumors have been flying around for years that the app is Chinese spyware. For instance, some argue it is impossible for a Chinese platform to not hand over user data to the Chinese government. Senators Blumenthal and Blackburn now believe they have something concrete that the American public needs to be made aware of.

Senate bill and the Congress TikTok briefing

The House of Representatives has recently passed a bill that could see TikTok banned in the States. TikTok has been brought up as a national security concern before, but this bill is the closest anyone has come to banning it. The main concerns always raised center around TikTok being a tool to spy on users. Hence, ever since American users first picked up the popular app, it has faced scrutiny, like many other Chinese products and services.

Congress has just received a briefing by intelligence agencies on what they’ve learned about TikTok. This briefing apparently left some senators shocked, and others not convinced of any danger posed by the app. Senators Richard Blumenthal and Marsha Blackburn had this to say.

“We are deeply troubled by the information and concerns raised by the intelligence community in recent classified briefings to Congress. TikTok is a weapon in the hands of the Chinese government, and poses an active risk to our democratic institutions and national security.” The bill, if passed into law, will force TikTok’s parent company ByteDance to sell the platform within six months or face a ban in the States.

Is TikTok actually Chinese spyware?

The main question that comes to mind after all this drama is whether TikTok is actually spyware. The claim lacks concrete proof as of yet. Nonetheless, the public does not know what the classified briefing to Congress contained. Representative Sara Jacobs, speaking to the Associated Press, thinks the entire thing is blown out of proportion.

“Not a single thing that we heard in today’s classified briefing was unique to TikTok. It was things that happen on every single social media platform,” she said. What Representative Jacobs was talking about here was likely the app permissions each app requires. Less tech-savvy folk often mistake these requirements for something more sinister. Take, for example, an app that has a photo-taking feature. It would require access to the camera. The wording of this permission leads people to believe that the app is always using their camera to spy on them.

If the briefing is declassified, the public will get a look at what intelligence officials have found. Applying different perspectives to the data may lead to a more rational decision.


[ad_2]
Source link

Soon, you’ll be able to express your frustrations with Google’s Gboard quicker

0
[ad_1]

If you’re using Google’s Gboard and you’re facing issues with the way it behaves, you’ll be able to tell Google about your dissatisfaction even quicker in the near future.

9to5Google reports that Gboard now lets you quickly file a “Quality Bug Report”.

This is Gboard’s latest feature and this shortcut should open Google’s standard tool for submitting issues and feedback on Android.

This “Quality Bug Report” is found on the latest Gboard beta version (13.9.13.x) on Pixel devices.

If you don’t participate in the beta program, but you still want to let Google know about an issue (or a suggestion) on Gboard, you have to take the long road. The current bug filing process involves going to Gboard settings, then tapping Help & feedback (at the bottom), then it’s Send feedback.

When this beta feature rolls out to the public, the whole process would be quicker. It should take two taps or as fast as a single press if one drags and puts the “Quality Bug Reports” shortcut in the shortcuts’ toolbar.

The workflow appears to be otherwise identical, though “Quality bug report” is appended to the start of the “describe your issue” field. This should let the Gboard team filter and find feedback filed in this manner.

Prior to that, Gboard recently introduced a handy OCR feature called Scan Text to Gboard. When you use the feature, your camera will open, taking up a bit more than half of your display. A button will appear at the bottom center, along with a tagline that says, “Take a photo of words to scan.”

Afterward, Gboard highlights all the text it identifies on the page. You can then insert the content captured from the photo into messages, notes, and other places. The feature also provides a quick preview of what it copied beside the insert button.


[ad_2]
Source link

A week in security (March 18 – March 24)

0
[ad_1]

March 22, 2024 – Since the main reason for the ban was to prevent car thefts that didn’t happen, we’re happy to see the change of heart.

March 21, 2024 – Ivanti has issued patches for two new vulnerabilities with a high CVSS score. Neither is known to have been explioted in the wild. Yet.

March 21, 2024 – Researchers scanned the internet for incorrectly configured Firebase instances and what they found was frightening.

March 20, 2024 – We found a tax scammer that set up a fake website where targets could apply for an Employer Identification Number.

March 19, 2024 – Social media influencers are attractive targets for identity thefs. Not just for their bank accounts but also to influence their followers


[ad_2]
Source link

Reddit’s long-awaited IPO finds success as shares boom

0
[ad_1]

Following years of preparation and nearly two decades operating as a privately-held company, Reddit officially went public this week, searching for IPO success. The company had its initial public offering (IPO) on Thursday, March 21 and was subsequently listed on the New York Stock Exchange. As is tradition, Reddit’s IPO was marked by a company figure ringing the NYSE’s opening bell Thursday. It was Reddit’s affectionate mascot, Snoo, that got the honor of ringing the bell and signaling the start of Reddit’s time as RDDT on the NYSE. In the process, Reddit became the most recent social media site to go public, following Pinterest in 2019 and Snap in 2017.

Reddit hoped to sell its shares for $34 each, with the company making a total of 15.3 million shares available. If all shares sold at Reddit’s projected prices, it would generate $519.4 million for the company. Separately, private shareholders put up 6.7 million shares for purchase. Reddit’s projections and goals for the IPO would give it a market value at around $6.5 billion. But, after two whole days on the NYSE as a publicly-traded company, Reddit didn’t just meet its internal goals. It crushed them, finding success in Reddit’s IPO.

As reported by CBS News, Reddit stock prices grew 54% on Thursday after a full day of trading. The peak of Reddit’s share prices hit $52.29 in a result that greatly exceeded the company’s own goals. This meant that Reddit met its target of raising over $500 million for the company, and $748 million was generated through the IPO in total. However, some of that money went to private shareholders. Reddit’s successful IPO continued into Friday. The company traded at a stock price of $46 when the market closed on March 22.

Why Reddit found success through its IPO

Not every IPO turns out to be a success, so why did Reddit perform so well? It comes down to how the company strategically prepared for the IPO. Reddit made a couple of high-profile moves to increase revenue and make the company more valuable. Notably, it started charging for API access. More importantly, it struck an agreement with Google worth $60 million annually. Per the terms of the deal, Google can use Reddit content to help train artificial intelligence models.

In essence, Reddit’s success comes down to its user base. That’s why the company came up with the clever idea of letting users buy Reddit stock at its IPO pricing. With enough Reddit “karma,” users could have an early shot at owning a portion of the company. All of these things are just a few factors that led to a successful IPO for Reddit.


[ad_2]
Source link

Threads now shows live scores for NBA games

0
[ad_1]

Meta is testing a lot of new features for Threads, the app that has a long way to go before it could replace Twitter. Swipe gestures to “like” posts and “Trending now” are just some of the features that Threads has started testing in the last week or so.

Over the weekend, Meta’s Mark Zuckerberg announced that Threads will start showing live sports scores. The feature is now being tested, which is why NBA live sports scores are the only ones showing up on Threads.

Apparently, this isn’t just a simple implementation of a feature that allows users to see sports scores in real-time, but a more complex one that involves multiple functions.

According to TechCrunch, users can now tap a team’s logo to be redirected to the conversation about that specific team or connect with other sports fans who follow the same team.

Threads didn’t just pick NBA randomly, as basketball seems to be one of the most popular topics on the app. The social network also claims that NBA Threads is currently one of the most active sports communities.


[ad_2]
Source link

While the US seeks ways to subdue TikTok, Spain bans Telegram

0
[ad_1]

TikTok is feeling the heat – 170 million Americans’ favorite app might be facing a nation-wide ban, but Spain is a step ahead.

Spain’s High Court ordered the suspension of messaging app Telegram (via Reuters).

The popular chat’s services in the country are being put on a pause after media companies said it was allowing users to upload their content without permission – and they don’t like that.

That’s why from today, Monday, the use of Telegram in Spain will be temporarily suspended after a request by companies including Atresmedia, EGEDA, Mediaset and Telefonica.

The one to make that decision was Judge Santiago Pedraz who has issued an order to temporarily suspend Telegram’s services in Spain pending an investigation into the claims. Mobile phone operators will be tasked with implementing the service block, according to a court source.

In Spain, Telegram ranks as the fourth most popular messaging platform, as reported by the competition watchdog CNMC, with nearly 19% of the Spanish population (or more than 9 million people) saying they’re using the app.

Telegram has about 800 million monthly active users globally these days.

Spain’s EL PAIS reports on the matter and cites Fernando Suárez, the president of the General Council of Professional Colleges of Computer Engineering of Spain. According to him, “It’s like deciding to close a province of our country because a case of drug trafficking or a robbery occurred within the territory.”

The report notes that unlike Meta (think Facebook, Instagram), Telegram refuses to share information with the authorities.

According to cybersecurity expert Rafel López, Telegram is sought-after because of that: “In WhatsApp, there are back doors for the NSA and different intelligence agencies to enter. Not on Telegram. Nothing is shared there.”


[ad_2]
Source link

The implications of the EU AI Act for the European financial sector

0
[ad_1]

The European Union’s Artificial Intelligence (AI) Act is a groundbreaking piece of legislation that aims to regulate the use of AI across various sectors, with a significant focus on the financial sector. This legislation is poised to have a profound impact on how financial institutions operate, innovate, and manage risks associated with AI technologies. This article delves into the implications of the AI Act for the European financial sector.

Balancing Innovation and Risk

At its core, the AI Act seeks to balance the benefits of AI innovation with the need to mitigate risks and protect consumers, forming part of a wider package of policy measures designed to support the development of trustworthy AI, including the AI Innovation Package and the Coordinated Plan on AI. The financial sector, which has been at the forefront of adopting AI for everything from creditworthiness assessments to fraud detection, is now under the spotlight. The Act categorizes certain AI applications as high-risk, particularly those involved in critical decision-making processes such as credit scoring and insurance underwriting. These applications will be subject to stringent requirements to ensure they are transparent, secure, and do not discriminate against consumers.

High-Risk AI Applications

One of the AI Act’s central features is its classification of certain AI applications as high-risk, especially those integral to financial decision-making processes such as credit scoring, risk assessment, and fraud detection. For high-risk AI applications, the AI Act mandates comprehensive risk assessment and mitigation measures aimed at ensuring transparency, accuracy, and fairness. Financial institutions will need to ensure the quality of the datasets feeding AI systems to minimize risks and discriminatory outcomes. This includes maintaining detailed documentation and logs to ensure traceability of decisions made by AI systems.

Financial institutions will also be required to conduct thorough risk assessments and implement robust risk mitigation systems. This includes ensuring the quality of data feeding into AI systems to minimize biases and discriminatory outcomes, maintaining detailed documentation for transparency, and establishing mechanisms for human oversight. Moreover, these institutions must provide clear information to users and deploy appropriate human oversight mechanisms to minimize risks.

Innovation and Competitive Edge

While the AI Act introduces new regulatory requirements, it will also foster innovation and competition within the financial sector. By providing a clear legal framework for AI deployment, the Act seeks to encourage financial institutions to explore and integrate advanced AI technologies responsibly. This clarity is expected to boost confidence among stakeholders, including investors, regulators, and consumers, thereby promoting a more innovative and competitive financial services market.

The Act’s focus on general-purpose AI systems, including large language models and generative AI, opens up new avenues for financial institutions to enhance their services. These technologies can be leveraged for a range of applications, from personalized financial advice, which could be as pivotal as choosing the right investments to more efficient customer service, driving both innovation and competitive advantage.

The Role of Data and the European Data Strategy

The AI Act is part of a broader European data strategy that seeks to harness the potential of data for innovation while ensuring privacy and data protection. The Act facilitates the re-use of public sector databases and access to private datasets, enabling financial institutions to develop more personalized and efficient services. This is expected to broaden competition and improve consumer choice in the financial sector. Additionally, the proposed Financial Data Access (FiDA) regulation, which complements the AI Act, will further democratize data access by allowing consumers to share their financial data with third parties securely.

Supervision and Compliance

The implementation of the AI Act will require a concerted effort from national competent authorities (NCAs) to ensure compliance. Financial institutions will need to integrate the new AI governance and risk management requirements into their operational frameworks. This includes adapting to sector-specific guidance and leveraging new technologies for supervisory purposes (SupTech). The European Commission’s new AI Office will play a crucial role in enforcing the Act, ensuring that AI systems used in the financial sector are compliant and do not pose undue risks to consumers.

Global Implications and Leadership

The AI Act positions the European Union as a frontrunner in AI regulation, potentially setting a benchmark for other jurisdictions. For global financial institutions operating in Europe, this means navigating a complex regulatory landscape that may influence global standards for AI in finance. The Act’s emphasis on ethical, transparent, and responsible AI use could inspire similar regulatory efforts worldwide, affecting how financial institutions deploy AI on a global scale.

Financial institutions will need to navigate these new requirements carefully, ensuring that their AI systems are transparent, fair, and secure. As the Act is implemented, it will undoubtedly shape the future of AI in finance, not just in Europe but globally. The balance it seeks to strike between innovation and consumer protection could serve as a model for other regions grappling with the complexities of AI regulation.


[ad_2]
Source link