Tag Archives: Trend Micro

Citadel malware active on 20,000 PCs in Japan, says Trend Micro

Citadel malware is installed on over 20,000 PCs in Japan and actively sending financial information it harvests to servers abroad, according to security software vendor Trend Micro.

Tokyo-based Trend Micro said it monitored remote servers in the U.S. and Europe that collect data gathered by Japanese versions of the malware for six days last week. On some days there were nearly 230,000 connections made from 20,000 infected computers.

The malware has been designed specifically to target domestic users, collecting financial details corresponding to six Japanese financial institutions as well as popular services such as e-mail from Google, Yahoo and Microsoft.

“Damage from this tool for online banking fraud is still continuing today,” Trend Micro said in a Japanese security blog.

To read this article in full or to leave a comment, please click here

…read more

Source: FULL ARTICLE at PCWorld

Malware campaign strikes Asian, European governments

Trend Micro says it detected a targeted attack that sent malware-laden emails to representatives of 16 European countries and some Asian governments.

The bogus emails purported to come from China’s defense ministry and contained a malicious attachment that exploited a now-patched vulnerability in Microsoft Office versions 2003 to 2010, wrote Jonathan Leopando, a technical communications specialist with Trend Micro. 

Microsoft patched the vulnerability in Office, CVE-2012-0158, more than a year ago although attackers are still frequently targeting it, including in the Safe and Taidoor campaigns, Leopando wrote.

If the email attachment is opened on an unpatched computer, a “backdoor” program is then installed that steals login credentials for websites and email credentials from Internet Explorer and Microsoft Outlook, Leopando wrote.

To read this article in full or to leave a comment, please click here

…read more

Source: FULL ARTICLE at PCWorld

Unusual file-infecting malware steals FTP credentials, researchers say

A new version of a file-infecting malware program that’s being distributed through drive-by download attacks is also capable of stealing FTP (File Transfer Protocol) credentials, according to security researchers from antivirus firm Trend Micro.

The newly discovered variant is part of the PE_EXPIRO family of file infectors that was identified in 2010, the Trend Micro researchers said Monday in a blog post. However, this version’s information theft routine is unusual for this type of malware.

The new threat is distributed by luring users to malicious websites that host Java and PDF exploits as part of an exploit toolkit. If visitors’ browser plug-ins are not up to date, the malware will be installed on their computers.

The Java exploits are for the CVE-2012-1723 and CVE-2013-1493 remote code execution vulnerabilities that were patched by Oracle in June 2012 and March 2013 respectively.

To read this article in full or to leave a comment, please click here

…read more

Source: FULL ARTICLE at PCWorld

Researcher: Security appliances are riddled with serious vulnerabilities

The majority of email and Web gateways, firewalls, remote access servers, UTM (united threat management) systems and other security appliances have serious vulnerabilities, according to a security researcher who analyzed products from multiple vendors.

Most security appliances are poorly maintained Linux systems with insecure Web applications installed on them, according to Ben Williams, a penetration tester at NCC Group, who presented his findings Thursday at the Black Hat Europe 2013 security conference in Amsterdam. His talk was entitled, “Ironic Exploitation of Security Products.”

Williams investigated products from some of the leading security vendors, including Symantec, Sophos, Trend Micro, Cisco, Barracuda, McAfee and Citrix. Some were analyzed as part of penetration tests, some as part of product evaluations for customers, and others in his spare time.

More than 80 percent of the tested products had serious vulnerabilities that were relatively easy to find, at least for an experienced researcher, Williams said. Many of these vulnerabilities were in the Web-based user interfaces of the products, he said.

To read this article in full or to leave a comment, please click here

…read more
Source: FULL ARTICLE at PCWorld

New Whitehole exploit toolkit emerges on the underground market

A new exploit kit called Whitehole has emerged on the underground market, providing cybercriminals with one more tool to infect computers with malware over the Web, security researchers from antivirus vendor Trend Micro reported Wednesday.

Exploit kits are malicious Web-based applications designed to install malware on computers by exploiting vulnerabilities in outdated browser plug-ins like Java, Adobe Reader or Flash Player.

Attacks that use such toolkits are called drive-by downloads and they don’t require any user interaction, making them one of the most efficient ways to distribute malware. Users generally get redirected to drive-by download attack pages when visiting compromised websites.

Whitehole uses similar code to Blackhole, one of the most popular exploit toolkits used today, but does have some particular differences, the Trend Micro security researchers said in a blog post.

To read this article in full or to leave a comment, please click here

…read more
Source: FULL ARTICLE at PCWorld

Security software showdown! 9 antivirus suites empirically tested

If you’re like a lot of people, when it comes time to renew your security software, you may ask yourself, “Do I really need to upgrade to the latest version?” The answer is yes. Keeping up-to-date is generally a good idea, as new threats surface constantly. And if you value mobile security or use a social network, this year’s crop of security suites is worth paying attention to.

An increasing number of security suites now feature special tools to help protect you on social networks—a growing target for spammers, scammers, and other parties who want to get at your personal information. For example, Trend Micro’s Titanium Internet Security suite comes with a handy tool that highlights any possible areas of concern involving your Facebook privacy settings. Various suites also include tools that will scan links on social networks so that you aren’t duped into clicking a malicious link hidden behind a URL shortener.

If you own a smartphone or tablet, or both, the security class of 2013 has some new tools for you. And some security packages come with a mobile app that provides protection against mobile malware or includes other features such as GPS tracking to help you find your phone should it go missing. These apps often also include remote-wipe capabilities that let you delete the contents of a missing phone or tablet so your private data doesn’t end up falling into the wrong hands.

In addition, Windows 8 has changed the way security software makers design their programs. Many of the suites we looked at this year sport redesigned interfaces that include larger buttons and controls made to be more touch-friendly.

To read this article in full or to leave a comment, please click here

Source: FULL ARTICLE at PCWorld

G Data InternetSecurity 2013 Review: Excellent protection, but a terrible user interface

G Data InternetSecurity 2013 ($35 for one year, as of 12/19/12) is a comprehensive security suite with an excellent protection record: It blocked, detected, and disabled all of the malicious files we threw at it, and cleaned up 80 percent of infections in our system cleanup test. However, it’s not the most user-friendly suite, with a tedious installation process and an advanced-users-only settings panel. As a result, it ended up toward the bottom of our rankings.

In our real-world attack test, G Data completely blocked 100 percent of attacks. This indicates how well the product will successfully block brand new malware attacks when it encounters them in the wild. Of the nine security suites we tested, five completely blocked all attacks: G Data, F-Secure, Bitdefender, Norton, and Trend Micro.

G Data also has an excellent malware detection rate. In our malware-zoo detection test, the program detected 99.7 percent of known malware samples. This detection rate puts G Data in fourth place for malware detection. G Data did have a higher false positive percentage than other security suites—it flagged three safe files (out of over 250,000) as malicious. Although this is a very low false positive rate, seven of the suites we tested flagged fewer than two safe files as malicious.

In our system cleanup test, G Data detected and disabled 100 percent of infections. It also managed to completely clean up 80 percent of infections, which puts it in third place (alongside Kaspersky and Trend Micro). This test shows how well a product can find, disable, and remove every last trace of an infection, so you can rest assured that G Data will do a respectable job.

To read this article in full or to leave a comment, please click here

Source: FULL ARTICLE at PCWorld

Review: Bitdefender Internet Security 2013: Excellent protection, user-friendly interface

Bitdefender Internet Security 2013 ($70 for one year and three PCs, as of 12/19/12) may just be everything that you’d want in a security suite. This program, which earned the highest rating in both our real-world attack test and our system cleanup test, has a user-friendly interface that will appeal to both regular and advanced users. It also comes with several extra services, such as antitheft protection for various mobile devices.

In our real-world attack test (which indicates how well a suite will be able to block new malware attacks as it encounters them), Bitdefender completely blocked 100 percent of attacks. (Four other tested security suites also put up perfect scores in this test: F-Secure, G Data, Norton, and Trend Micro.) Bitdefender was also able to detect 98.8 percent of known malware samples in our malware-zoo detection test. That’s not a bad detection rate, but five of the nine security suites in this year’s roundup had detection rates of 99.0 percent or higher.

Bitdefender managed to detect and disable 100 percent of the infections in our system cleanup test, and it successfully cleaned up all traces of infections 90 percent of the time. This result is the best full-cleanup rate of any of the suites we tested—only F-Secure Internet Security 2013 had a similar cleanup rate (90 percent). Bitdefender flagged just one file (out of over 250,000) as malicious, which gives it a very low false-positive percentage compared with its competition.

The program adds just a little extra weight to your system—in other words, its slowdowns are tolerable. It added 3.5 seconds to startup time (compared to a PC with no antivirus program installed), which puts it in the lower half of the suites we tested. It also added a second or so to shutdown time. Bitdefender has the longest on-demand scanning time (2 minutes, 1 second) of the programs we tested, and the fourth-longest on-access scanning time (5 minutes, 41 seconds).

To read this article in full or to leave a comment, please click here

Source: FULL ARTICLE at PCWorld

Review: F-Secure Internet Security 2013: First-rate protection and usability has a small performance price

F-Secure Internet Security 2013 (about $73 for one year and one computer, as of 12/19/12) came in first in several of our malware detection, blocking, and removal tests. It successfully blocked attacks, detected and disabled infections, and proved adept at cleaning up all traces of malware, landing at the top of this year’s security suite roundup.

In our real-world attack test, F-Secure completely blocked 100 percent of attacks. This test indicates how well the product will successfully block new malware attacks as it encounters them in the wild. But F-Secure wasn’t unique: Of the nine security suites we tested, four others also managed to completely block all attacks: Bitdefender, G Data, Norton, and Trend Micro.

F-Secure also put up great scores in our malware-zoo detection test: The suite detected 99 percent of known malware samples. This score puts it in the top five of the security suites we tested, though it’s at the bottom of that group (G Data, McAfee, Norton, and Trend Micro all posted detection rates of 99.7 percent or higher). F-Secure flagged just two safe files (out of over 250,000) as malicious, which is a good false-positive rate overall. However, since four of the suites achieved a perfect score in false-positive testing, and two suites flagged only one safe file as malicious, on this measure F-Secure still ends up in the bottom half of the list.

In our system cleanup test, F-Secure performed very well. In fact, it’s at the top of the list (alongside Bitdefender) after detecting and disabling all infections on our test PC and completely removing 90 percent of infections. So F-Secure should effectively dispatch any malware it finds on your machine.

To read this article in full or to leave a comment, please click here

Source: FULL ARTICLE at PCWorld

Review: Norton Internet Security 2013: Solid performer with a polished interface

Symantec’s 2013 edition of Norton Internet Security ($50 for one year and three PCs, as of 12/19/12) is a solid performer with a polished, touch-optimized user interface. This security suite didn’t totally dominate its competitors, but it did completely block, detect, and disable all malware in our real-world tests, and it performed well enough overall to snag second place in our roundup.

Norton’s excellent showing in our real-world attack test indicates that it should be effective at blocking brand-new malware attacks as it encounters them in the wild. As noted in the F-Secure review, of the security suites we tested, four others were also successful at completely blocking 100 percent of attacks: Bitdefender, F-Secure, G Data, and Trend Micro.

Norton produced stellar—though not absolutely perfect—results in detecting known malware. In our malware-zoo detection test, the program successfully detected 99.8 percent of known malware samples. Norton Internet Security also put up a perfect score in our false-positive test: It didn’t mistakenly identify any safe files, out of more than 250,000, as being malicious.

Norton does an acceptable job of cleaning up a system that has already been infected, but it missed some infections completely in our evaluation. In our system cleanup test, the program detected and disabled 90 percent of infections, and completely cleaned up 60 percent of infections. This is a decent but not fantastic showing—seven of our tested suites detected and disabled 100 percent of infections, and six cleaned up all traces of infection at least 70 percent of the time.

To read this article in full or to leave a comment, please click here

Source: FULL ARTICLE at PCWorld

Review: Trend Micro Titanium Internet Security 2013: An all-around winner

Trend Micro Titanium Internet Security 2013 ($50 for one year and three PCs, as of 12/19/12) certainly lives up to its name. This “titanium” security suite doesn’t let anything get through—in our tests, it earned excellent marks in just about every category. It also has a fairly user-friendly interface and a quick installation process, which makes it an all-around great pick.

In our real-world attack tests, which indicate how well an antivirus program will be able to block new malware attacks as it encounters them in the wild, Trend Micro’s suite completely blocked every threat that it faced. Needless to say, this means that the program will likely be able to keep you very secure, even when new malware programs are introduced in the future.

Trend Micro nabbed high marks in most of our other security tests. In our malware-zoo detection test, which exposes the program to a collection of malware that had been introduced in the preceding four months, Trend Micro’s package detected 100 percent of known malware samples. In our false-positive test, which checks to see whether a product mistakenly flags a known safe file as being dangerous, Trend Micro identified just one safe file (out of over 250,000) as malicious.

In addition, the suite did very well in our system cleanup test: It detected and disabled 100 percent of infections, and it managed to fully purge the system of 80 percent of those infections. This result puts it in second place, tied with G Data and Kaspersky, for total cleanup rate.

To read this article in full or to leave a comment, please click here

Source: FULL ARTICLE at PCWorld

Malware impersonates Java patch

Trend Micro has spotted a piece of malicious software that masquerades as the latest patch for Java, a typically opportunistic move by hackers.

Oracle released two emergency patches on Sunday for its Java programming language and application platform, which is installed on millions of computers worldwide.

The latest version of Java is Update 11. Trend Micro wrote on its blog that it was alerted to a fake “Java Update 11″ present on at least one website. If a user installs the bogus update, a malicious backdoor program is downloaded.

“Once executed, this backdoor connects to a remote server that enables a possible attacker to take control of the infected system,” wrote Paul Pajares, a fraud analyst with Trend.

To read this article in full or to leave a comment, please click here

Source: FULL ARTICLE at PCWorld

BlackBerry gets vote of confidence from monitoring-software maker

There’s good news for a change for BlackBerry maker Research in Motion, as monitoring-software vendor SpectorSoft today announced its first software support for BlackBerry in the enterprise.

“BlackBerry is very strong in certain places, like finance and government,” says Nick Cavalancia, vice president of marketing at SpectorSoft, which today announced Spector 360 7.5, an employee-monitoring package for centralized recording and alerting about what employees do on their Windows PCs, Apple Macs, and now company-issued BlackBerries. “The BlackBerry is still in 90% of the Fortune 500. And we do believe BlackBerry is a secure mobile-device platform.”

A recent study that Trend Micro did internally on mobile devices rated BlackBerry the most secure in comparison to Apple iOS or Google Android.

However, the latest SpectorSoft monitoring software for the enterprise, which costs $110 per computer and $57 per BlackBerry device, can’t do as much to track employee activity on the BlackBerry as on the PC or Mac due to constraints related to mobile-platform processing and bandwidth limit and costs.

To read this article in full or to leave a comment, please click here

Source: FULL ARTICLE at PCWorld