Showing posts with label cybercrime. Show all posts
Showing posts with label cybercrime. Show all posts

Tuesday, November 14, 2023

Phishing Scam Viewer Worries Get Linden Lab's Attention

 
It's a sad fact that the Internet is full of scammers. And unfortunately some have come to Second Life.  There's been some news going around recently about one particular phishing scam: a viewer that will supposedly give you unlimited Lindens, and allow you to build anywhere.

Hello,

Are you tired of spending your hard-earned Linden Dollars? We've got an exciting solution just for you! Introducing our SecondLive Viewer, where everything is not only free but also open for endless possibilities.

  • Unlock unlimited Linden Dollars (L$) for all your virtual adventures.
  • Fly to unlimited heights.
  • Build on any land of your choice, all for free.

But that's just the beginning.

Link: <Some URL, typically a tinyurl link>

We're sincerely thankful to everyone who joins us in our mission to make SecondLife completely free. Don't miss this incredible opportunity.

Best Regards.

Most residents would recognize right away these claims are bogus. Viewers can't create Linden dollars, only Linden Lab's computers can do that. One would have to hack into them, and keep hacking to get the virtual money, which would not only be extremely difficult, but easily discovered and traced. Nor can your viewer determine which land you can build on - the permissions of who can and can't are stored in the servers.

Firestorm would express worries of copybot viewers last month before I personally started hearing about the forementioned scam. The scam itself I first heard about when a few people passed me a link to a post made by FelixWolf on GitHub, who would be identified by Inara Pey of Modem World as Chaser Zaks of Team Firestorm who "risked taking a look under the covers of the code that is supplied."

What the viewer actually does is run a program called builddata.bat on your computer, which installs a number of remote administrative toolkits (or RATs). Once your machine is infested with these RATs, the scammer can:

Steal your Linden dollars and go through your inventory

Steal your password and hijack your account, and whatever they do, people (and Linden Lab) will think it's you.

Go into your computer and steal/delete your files.
 
Steal your banking and credit card information, and steal your real-world money, and possibly ruin your credit.
 
Discover real-life information on you, such as your city and street address. 
 
Activate your camera and take pictures of you and the contents of your room. If they get your real-life location, they may know where to find valuable items to steal. 

Last Thursday, Linden Lab would feel the need to remind it's residents of the dangers of phishing scams in general, "Ensuring A Secure Second Life Experience." It brought up this particular viewer, "
It is important to remember that downloading software from unknown sources has a very real risk associated with it. You could unintentionally allow someone to monitor your keystrokes or even gain complete control over your computer. It has the potential to expose not just your Second Life password, but all other important information you have on your computer. ... Be wary of suspicious links or attachments sent by other users. These may be attempts to compromise your account or computer. ... Only download and install the official Second Life viewer, or an approved Third-Party viewer directly from the links provided by our site."
 
So once again, a reminder that one needs to be a little wary when going about Second Life (and the Internet in general), and don't let yourself get a RAT infestation. 
 
Bixyl Shuftan 

Saturday, May 13, 2017

"Unprecedented" Cyberattack Hits Thousands of Computers In 99 Countries



A massive cyberattack has hit at least 75,000 computers in 99 countries in the past few days. Described as "unprecedented" in scale, the attacks have been infecting both individuals and institutions from home computers to government agencies to businesses to hospitals. In Great Britian alone, at least 48 hospitals, clinics, and other health institutions were affected. Although some surgeries were postponed, there are no reports of deaths yet related to the hacking.

Reports of the malware, called "WannaCry" began coming in on Friday. What happens io infected computers is the files are locked and a picture appears on the screen demanding $300 US dollars worth of Bitcoin within three days for the key to unlock the computer. Unlike typical malware attacks that rely on tricking computer users into opening email attachments or clicking on links, WannaCry is a worm that attacks computers through active online connections through vulnerabilities in system software. WannaCry locks up files, looks for other vulnerable computers to infect, then deletes itself. Most computer experts recommend treating the files as lost, with only the backup files on external hard drives, if any, as recoverable. It is not recommended that people pay the criminals as in past cases of ransomware, the criminals almost never provided any key to recover lost files. It is believed that the reason Bitcoin is the method of payment demanded is because it's transactions can't be traced.

In an ironic twist, the worm may be based on a spyware tool created by the NSA to snoop on people's computers, designed to take advantages of vulnerabilities in Windows software that it had discovered. The program was leaked in April by computer hackers whom had discovered it. The agency will neither confirm or deny their program had anything to do with WannaCry. A lawyer for the American Civil Liberties Union called this "deeply troubling," saying the NSA should have notified Microsoft of the vulnerabilities instead of taking advantage of them, "These attacks underscore the fact that vulnerabilities will be exploited not just by our security agencies, but by hackers and criminals around the world. Patching security holes immediately, not stockpiling them, is the best way to make everyone's digital life safer." Others put the blame less on the NSA and more on institutions for being too slow to update systems, the attack happening two months after Microsoft had a patch available.

One British computer security blogger halted one strain of the malware by accident. Known as "Malware Tech," he decided to investigate the attack, and after an all-night session noticed the strain was trying to contact a specific web address every time it infected a new system. Seeing it was unregistered, he bought it for eight Pounds ($10.69 USD) to see where the attacks were happening. But in doing se, he accidentally triggered a "kill switch" for the strain. But there are still other strains of the worm out there.




A reminder that the computer world is full of dangers.

Sources: BBC, Arstechnica, Nerdgasm

Bixyl Shuftan

Friday, July 6, 2012

DNSChanger Malware Could Knock Thousands of Computers Offline July 9

Thousands of computers are at risk of being unable to use the Internet because of malware from online criminals in a scam last year. Despite an effort to get the word out, as many as 277,000 computers worldwide still cary the hostile software known as DNSChanger.

DNSChanger was discovered in 2007, and may have infected millions of computers over time. The malware worked by detecting what websites its victims browsed, then redirected them to sites under the control of a cybercrime enterprise working from the small Eastern European country of Estonia, where ads were pushed onto the viewers. The criminals were netting millions before the FBI worked with Estonian police to break up the crime ring and confiscated the servers. Six were arrested with a seventh in Russia still at large.

To avoid disrupting those with infected computers, the servers were kept online as word was spread about the malware infections. In January, it was estimated a half million computers had the malware. But on Midnight July 8, the servers will be turned off, and those computers still infected will be unable to get online, at least without taking certain steps. In January, it was estimated a half million computers had the malware. As many as 277,000 computers across the world may still be infected, including as many as 4500 in the United States. Messages, such as the one Google has been showing to users of computers it detected the malware on (shown below), have helped to get the word out.

For those computers still infected, there are a number of places one can go. Among them is a website that a group of security groups and experts set up: www.dcwg.org. Others include:

Hitman Pro (32bit and 64bit versions)

Kaspersky Labs TDSSKiller

McAfee Stinger

Microsoft Windows Defender Offline

Microsoft Safety Scanner

Norton Power Eraser

Trend Micro Housecall

MacScan

Avira


For computers knocked offline, they can still get to Google by typing "173.194.34.72" into their address bar, or to Microsoft with "64.4.11.37".

Internet security company Internet Identity reported at least 60 companies on the Fortune 500 still have infected computers. At the beginning of the year, they believed the number was 250. or 50 percent. For US Government agency computers, the amount infected went down from an estimated 49 percent to 4.

Sources: http://www.dcwg.org/, Forbes, Reuters, Internet News , Google


Bixyl Shuftan