<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.itpro.com/uk/feeds/tag/adware"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from ITPro UK in Adware ]]></title>
                <link>https://www.itpro.com/uk/tag/adware</link>
        <description><![CDATA[ All the latest adware content from the ITPro  UK team ]]></description>
                                    <lastBuildDate>Sat, 15 Oct 2022 07:00:06 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Internet pollution is only getting worse ]]></title>
                                                                                                <dc:content><![CDATA[ <p>It seems that every day we read about pollution around the world. From whales caught up on nets to particulates in the air we breathe, from water infested with everything from toxic chemicals to raw sewage. Then, there is the growing horror of microplastics, which are small chunks of plastic officially defined as being smaller than 5mm in diameter. Now, I read microplastics are being found inside living creatures.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/data-insights/368714/what-is-adtech-and-why-is-it-at-the-heart-of-a-regulation" data-original-url="/business-strategy/data-insights/368714/what-is-adtech-and-why-is-it-at-the-heart-of-a-regulation">​​What is AdTech and why is it at the heart of a regulation storm?</a></p></div></div><p>The pollution problem is getting worse in the world of computing and the internet, too, except here it’s mostly related to a <a href="https://www.itpro.com/business-strategy/data-insights/368714/what-is-adtech-and-why-is-it-at-the-heart-of-a-regulation" target="_blank" data-original-url="https://www.itpro.com/business-strategy/data-insights/368714/what-is-adtech-and-why-is-it-at-the-heart-of-a-regulation">tidal wave of advertising material</a>. Some of it is obvious, with websites that are often more advert than content a particular bête noir of mine. Other adverts are more insidious, such as those injected into video streams on YouTube. I understand the need for advertising revenue, and that I can pay the monthly YouTube fee to get rid of the inserted adverts, but this doesn’t rid me of the almost endless product placements made within the video itself.</p><p>Then, there’s my hatred of the inline feed adverts on Facebook, which has reached the level of almost a nervous tick. I have a morbid fascination with hitting the “block advert” button on the <a href="https://www.itpro.com/security/369044/the-iphone-security-features-that-come-with-ios-16" target="_blank" data-original-url="https://www.itpro.com/security/369044/the-iphone-security-features-that-come-with-ios-16">iOS</a> app, then flagging the advert as “irrelevant” and then blocking the advertiser, which can eventually make the Facebook advertising <a href="https://www.itpro.com/data-insights/30212/what-is-an-algorithm" target="_blank" data-original-url="https://www.itpro.com/data-insights/30212/what-is-an-algorithm">algorithm</a> back off for a few weeks. On desktop browsers, Social Fixer strips the feed of much unwanted rubbish, but Social Fixer and Facebook appear locked in an endless game of cat and mouse as Facebook tries new methods of getting around the filtering.</p><p>It doesn’t stop there, of course – buy a new computer and you can rest assured there’s a wheelbarrow full of rubbish to be immediately uninstalled, starting with the ubiquitous antivirus trialware. I strip <a href="https://www.itpro.com/laptops/23742/best-laptops" data-original-url="https://www.itpro.com/laptops/23742/best-laptops">laptops</a> back to the bare minimum, keeping only necessary vendor-supplied tools for updating firmware and drivers.</p><p>So, you can imagine my horror at reading reports that a company, Glance, is about to launch its lockscreen tool for <a href="https://www.itpro.com/mobile/20522/best-android-smartphones" target="_blank" data-original-url="https://www.itpro.com/mobile/20522/best-android-smartphones">Android phones</a> in the USA. It replaces the standard lock screen with its own platform and, as you can probably expect, this means adverts can be delivered directly to this screen. Although the company insists that it isn’t an ads platform but a “smart surface”.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/software/367479/its-time-to-ditch-software-subscriptions" data-original-url="/software/367479/its-time-to-ditch-software-subscriptions">It’s time to ditch software subscriptions</a></p></div></div><p>“In the US, monetisation on the lock screen surface will be primarily driven by the Space that a consumer chooses to consume at any moment,” its blog says. “For example, consumers can pay a <a href="https://www.itpro.com/software/367479/its-time-to-ditch-software-subscriptions" target="_blank" data-original-url="https://www.itpro.com/software/367479/its-time-to-ditch-software-subscriptions">subscription fee</a> for premium news wraps by a major publisher arriving every morning on their lock screens; or, they could choose to buy products from merchants when the product drop of the day surfaces on the lock screen.”</p><p>Time will tell how Glance works in the US – and you can expect the UK won’t be far behind – but my suspicion is that Glance-enabled phones will be supplied by telcos for a slightly lower fee, much as Amazon offers a discount on some Kindles.</p><p>Adverts have their place, but only if there is a clear understanding that the costs to the end-user are reduced, often to zero, by accepting the adverts. That requires a clear understanding that you either get the adverts, or you can pay a small subscription and get the clean feed. However, no one wants to engage in that discussion, mostly because it requires them to put a value on the advertising feed, and thus onto the end user uptake.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="FaB2FMpWMfQo5Z9ruoKGdb" name="FaB2FMpWMfQo5Z9ruoKGdb.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/FaB2FMpWMfQo5Z9ruoKGdb.png" mos="https://cdn.mos.cms.futurecdn.net/FaB2FMpWMfQo5Z9ruoKGdb.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Just enough data governance</strong></p><p class="fancy-box__body-text">Building program momentum and scale with agility</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-governance/369172/just-enough-data-governance" data-original-url="/policy-legislation/data-governance/369172/just-enough-data-governance">FREE DOWNLOAD</a></p></div></div><p>If I find a site or platform that offers a paid-for subscription, I will usually try it for a period. If I find the feed still laden with adverts, of whatever sort, then I will back away and have few qualms about applying technology to get the feed in a form that I want.</p><p>It really is about time that there was clarity in this space. Buy a laptop with all the crapware installed and pay a price. Pay slightly more and get it without. Then I can choose, based on the cost of my time, to clean things up.</p><p>At the same time, we need to talk about online advertising and its place in our lives. And this is before we even get onto the enormous amount of user profiling that is happening in real-time of each and every internet user, and the question of where and <a href="https://www.itpro.com/strategy/28185/what-is-data-mining" target="_blank" data-original-url="https://www.itpro.com/strategy/28185/what-is-data-mining">how that data is being used</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/359571/the-future-of-ai-in-advertising-and-media" data-original-url="/technology/artificial-intelligence-ai/359571/the-future-of-ai-in-advertising-and-media">The future of AI in advertising and media</a></p></div></div><p>I absolutely would not buy a <a href="https://www.itpro.com/mobile/23617/the-best-smartphones-to-buy" target="_blank" data-original-url="https://www.itpro.com/mobile/23617/the-best-smartphones-to-buy">smartphone</a> that had built-in advertising of the form provided by Glance. Telcos have no right into my phone operation other than providing raw connectivity.</p><p>It is no longer acceptable to just sit back and assume that we’re going to get swamped, and that there is nothing we can do about it. All that will happen is the pollution will grow and mutate until, like microplastics, it’s so pervasive that we can’t even spot it anymore. It's just there, inside our devices. It’s time we put these companies back into their box.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/infrastructure/network-internet/369210/internet-pollution-is-only-getting-worse</link>
                                                                            <description>
                            <![CDATA[ With online advertising becoming more pervasive and insidious, it won’t be long until they’re as ever present as microplastics ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tVvjQ8WkSgJEjtjqnuGvpc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Dna2N7XFDcys4TxqmqDpVa-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 15 Oct 2022 07:00:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Wifi and Hotspots]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jon Honeyball ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Dna2N7XFDcys4TxqmqDpVa-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Pop art-style graphic of popup windows]]></media:description>                                                            <media:text><![CDATA[Pop art-style graphic of popup windows]]></media:text>
                                <media:title type="plain"><![CDATA[Pop art-style graphic of popup windows]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Dna2N7XFDcys4TxqmqDpVa-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>It seems that every day we read about pollution around the world. From whales caught up on nets to particulates in the air we breathe, from water infested with everything from toxic chemicals to raw sewage. Then, there is the growing horror of microplastics, which are small chunks of plastic officially defined as being smaller than 5mm in diameter. Now, I read microplastics are being found inside living creatures.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/data-insights/368714/what-is-adtech-and-why-is-it-at-the-heart-of-a-regulation" data-original-url="/business-strategy/data-insights/368714/what-is-adtech-and-why-is-it-at-the-heart-of-a-regulation">​​What is AdTech and why is it at the heart of a regulation storm?</a></p></div></div><p>The pollution problem is getting worse in the world of computing and the internet, too, except here it’s mostly related to a <a href="https://www.itpro.com/business-strategy/data-insights/368714/what-is-adtech-and-why-is-it-at-the-heart-of-a-regulation" target="_blank" data-original-url="https://www.itpro.com/business-strategy/data-insights/368714/what-is-adtech-and-why-is-it-at-the-heart-of-a-regulation">tidal wave of advertising material</a>. Some of it is obvious, with websites that are often more advert than content a particular bête noir of mine. Other adverts are more insidious, such as those injected into video streams on YouTube. I understand the need for advertising revenue, and that I can pay the monthly YouTube fee to get rid of the inserted adverts, but this doesn’t rid me of the almost endless product placements made within the video itself.</p><p>Then, there’s my hatred of the inline feed adverts on Facebook, which has reached the level of almost a nervous tick. I have a morbid fascination with hitting the “block advert” button on the <a href="https://www.itpro.com/security/369044/the-iphone-security-features-that-come-with-ios-16" target="_blank" data-original-url="https://www.itpro.com/security/369044/the-iphone-security-features-that-come-with-ios-16">iOS</a> app, then flagging the advert as “irrelevant” and then blocking the advertiser, which can eventually make the Facebook advertising <a href="https://www.itpro.com/data-insights/30212/what-is-an-algorithm" target="_blank" data-original-url="https://www.itpro.com/data-insights/30212/what-is-an-algorithm">algorithm</a> back off for a few weeks. On desktop browsers, Social Fixer strips the feed of much unwanted rubbish, but Social Fixer and Facebook appear locked in an endless game of cat and mouse as Facebook tries new methods of getting around the filtering.</p><p>It doesn’t stop there, of course – buy a new computer and you can rest assured there’s a wheelbarrow full of rubbish to be immediately uninstalled, starting with the ubiquitous antivirus trialware. I strip <a href="https://www.itpro.com/laptops/23742/best-laptops" data-original-url="https://www.itpro.com/laptops/23742/best-laptops">laptops</a> back to the bare minimum, keeping only necessary vendor-supplied tools for updating firmware and drivers.</p><p>So, you can imagine my horror at reading reports that a company, Glance, is about to launch its lockscreen tool for <a href="https://www.itpro.com/mobile/20522/best-android-smartphones" target="_blank" data-original-url="https://www.itpro.com/mobile/20522/best-android-smartphones">Android phones</a> in the USA. It replaces the standard lock screen with its own platform and, as you can probably expect, this means adverts can be delivered directly to this screen. Although the company insists that it isn’t an ads platform but a “smart surface”.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/software/367479/its-time-to-ditch-software-subscriptions" data-original-url="/software/367479/its-time-to-ditch-software-subscriptions">It’s time to ditch software subscriptions</a></p></div></div><p>“In the US, monetisation on the lock screen surface will be primarily driven by the Space that a consumer chooses to consume at any moment,” its blog says. “For example, consumers can pay a <a href="https://www.itpro.com/software/367479/its-time-to-ditch-software-subscriptions" target="_blank" data-original-url="https://www.itpro.com/software/367479/its-time-to-ditch-software-subscriptions">subscription fee</a> for premium news wraps by a major publisher arriving every morning on their lock screens; or, they could choose to buy products from merchants when the product drop of the day surfaces on the lock screen.”</p><p>Time will tell how Glance works in the US – and you can expect the UK won’t be far behind – but my suspicion is that Glance-enabled phones will be supplied by telcos for a slightly lower fee, much as Amazon offers a discount on some Kindles.</p><p>Adverts have their place, but only if there is a clear understanding that the costs to the end-user are reduced, often to zero, by accepting the adverts. That requires a clear understanding that you either get the adverts, or you can pay a small subscription and get the clean feed. However, no one wants to engage in that discussion, mostly because it requires them to put a value on the advertising feed, and thus onto the end user uptake.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="FaB2FMpWMfQo5Z9ruoKGdb" name="FaB2FMpWMfQo5Z9ruoKGdb.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/FaB2FMpWMfQo5Z9ruoKGdb.png" mos="https://cdn.mos.cms.futurecdn.net/FaB2FMpWMfQo5Z9ruoKGdb.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Just enough data governance</strong></p><p class="fancy-box__body-text">Building program momentum and scale with agility</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/data-governance/369172/just-enough-data-governance" data-original-url="/policy-legislation/data-governance/369172/just-enough-data-governance">FREE DOWNLOAD</a></p></div></div><p>If I find a site or platform that offers a paid-for subscription, I will usually try it for a period. If I find the feed still laden with adverts, of whatever sort, then I will back away and have few qualms about applying technology to get the feed in a form that I want.</p><p>It really is about time that there was clarity in this space. Buy a laptop with all the crapware installed and pay a price. Pay slightly more and get it without. Then I can choose, based on the cost of my time, to clean things up.</p><p>At the same time, we need to talk about online advertising and its place in our lives. And this is before we even get onto the enormous amount of user profiling that is happening in real-time of each and every internet user, and the question of where and <a href="https://www.itpro.com/strategy/28185/what-is-data-mining" target="_blank" data-original-url="https://www.itpro.com/strategy/28185/what-is-data-mining">how that data is being used</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/359571/the-future-of-ai-in-advertising-and-media" data-original-url="/technology/artificial-intelligence-ai/359571/the-future-of-ai-in-advertising-and-media">The future of AI in advertising and media</a></p></div></div><p>I absolutely would not buy a <a href="https://www.itpro.com/mobile/23617/the-best-smartphones-to-buy" target="_blank" data-original-url="https://www.itpro.com/mobile/23617/the-best-smartphones-to-buy">smartphone</a> that had built-in advertising of the form provided by Glance. Telcos have no right into my phone operation other than providing raw connectivity.</p><p>It is no longer acceptable to just sit back and assume that we’re going to get swamped, and that there is nothing we can do about it. All that will happen is the pollution will grow and mutate until, like microplastics, it’s so pervasive that we can’t even spot it anymore. It's just there, inside our devices. It’s time we put these companies back into their box.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New Adload malware bypasses Apple’s XProtect to infect macOS devices ]]></title>
                                                                                                <dc:content><![CDATA[ <p><a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">Security</a> researchers have found a new Adload malware variant targeting Apple devices.</p><p><a href="https://labs.sentinelone.com/massive-new-adload-campaign-goes-entirely-undetected-by-apples-xprotect">Researchers at Sentinel Labs observed</a> over 150 unique samples as part of a new campaign that remains undetected by Apple’s on-device malware scanner.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/adware/32497/researchers-blast-wakenet-ab-for-spreading-adware" data-original-url="/adware/32497/researchers-blast-wakenet-ab-for-spreading-adware">Researchers blast Swedish developer WakeNet AB for ‘deceptively’ spreading adware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/24081/lenovo-stops-shipping-superfish-adware-with-consumer-devices" data-original-url="/security/24081/lenovo-stops-shipping-superfish-adware-with-consumer-devices">Lenovo stops shipping Superfish adware with consumer devices</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/360521/new-malware-plants-backdoor-on-microsoft-web-server-software" data-original-url="/security/cyber-security/360521/new-malware-plants-backdoor-on-microsoft-web-server-software">New malware plants backdoor on Microsoft web server software</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/93049/browzar-responds-to-adware-slurs" data-original-url="/93049/browzar-responds-to-adware-slurs">Browzar responds to adware slurs</a></p></div></div><p>The AdLoad malware initially surfaced in 2017 but has evolved over the years to evade detection by Apple’s XProtect security system. In 2019, Apple had some partial protection against its earlier variants, but there were no updates to cover the then-new 2019 variant.</p><p>AdLoad is a type of adware that redirects a user’s web traffic through the attacker’s preferred servers. The aim is to hijack and redirect user’s <a href="https://www.itpro.com/network-internet/web-browser/357253/8-most-secure-web-browsers" data-original-url="https://www.itpro.com/network-internet/web-browser/357253/8-most-secure-web-browsers">web browsers</a> for monetary gain.</p><p>Researchers said the 2019 and 2021 AdLoad variants used persistence and executable names that followed a consistent pattern. In 2019, that pattern included some combination of the words “Search,” “Result,” and “Daemon,” such as “ElementarySignalSearchDaemon”.</p><p>The latest version uses a different pattern that primarily relies on a file extension that is either .system or .service. The file extension used depends on the location of the dropped persistence file and executable as described below. Still, typically .system and .service files will be found on the same infected device if the user gave privileges to the installer.</p><p>With or without privileges, AdLoad will install a persistence agent in the user’s Library LaunchAgents folder.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="gGRwbS6T2JYCbdQmJ8xJri" name="gGRwbS6T2JYCbdQmJ8xJri.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/gGRwbS6T2JYCbdQmJ8xJri.png" mos="https://cdn.mos.cms.futurecdn.net/gGRwbS6T2JYCbdQmJ8xJri.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>How to increase cyber resilience within your organisation</strong></p><p class="fancy-box__body-text">Cyber resilience for dummies</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/359468/how-to-increase-cyber-resilience-within-your-organisation" data-original-url="/security/cyber-security/359468/how-to-increase-cyber-resilience-within-your-organisation">FREE DOWNLOAD</a></p></div></div><p>Researchers said they have found around 50 unique label patterns, each having a .service and a .system version. “Based on our previous understanding of AdLoad, we expect there to be many more,” they added.</p><p>Further investigations have found more than 150 unique samples in this year’s campaigns. Researchers noted there appears to have been a sharp uptick throughout July and the early weeks of August 2021. Researchers said a single sample of this variant was documented by <a href="https://blog.confiant.com/osx-hydromac-a-new-macos-malware-leaked-from-a-flashcards-app-2af28f1caa9e">analysts at Confiant,</a> who described the malware’s string decryption routine.</p><p>“It certainly seems possible that the malware developers are taking advantage of the gap in XProtect, which itself has not been updated since a few weeks after Confiant’s research over two months ago. At the time of writing, XProtect was last updated to version 2149 around June 15th – 18th,” researchers said.</p><p>“The fact that hundreds of unique samples of a well-known adware variant have been circulating for at least 10 months and yet remain undetected by Apple’s built-in malware scanner demonstrates the necessity of adding further endpoint security controls to Mac devices,” researchers concluded.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/software/adware/360560/new-adload-malware-can-bypass-apples-xprotect-security-to-infect-macos</link>
                                                                            <description>
                            <![CDATA[ Old malware retooled to evade Apple defenses ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3344fkwqNLx5pQFMQAiCiA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4teYEe22uJmKnZoRCYmRyW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 12 Aug 2021 13:27:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4teYEe22uJmKnZoRCYmRyW-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[&amp;quot;Adware&amp;quot; within a series of binary coding]]></media:description>                                                            <media:text><![CDATA[&amp;quot;Adware&amp;quot; within a series of binary coding]]></media:text>
                                <media:title type="plain"><![CDATA[&amp;quot;Adware&amp;quot; within a series of binary coding]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4teYEe22uJmKnZoRCYmRyW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">Security</a> researchers have found a new Adload malware variant targeting Apple devices.</p><p><a href="https://labs.sentinelone.com/massive-new-adload-campaign-goes-entirely-undetected-by-apples-xprotect">Researchers at Sentinel Labs observed</a> over 150 unique samples as part of a new campaign that remains undetected by Apple’s on-device malware scanner.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/adware/32497/researchers-blast-wakenet-ab-for-spreading-adware" data-original-url="/adware/32497/researchers-blast-wakenet-ab-for-spreading-adware">Researchers blast Swedish developer WakeNet AB for ‘deceptively’ spreading adware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/24081/lenovo-stops-shipping-superfish-adware-with-consumer-devices" data-original-url="/security/24081/lenovo-stops-shipping-superfish-adware-with-consumer-devices">Lenovo stops shipping Superfish adware with consumer devices</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/360521/new-malware-plants-backdoor-on-microsoft-web-server-software" data-original-url="/security/cyber-security/360521/new-malware-plants-backdoor-on-microsoft-web-server-software">New malware plants backdoor on Microsoft web server software</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/93049/browzar-responds-to-adware-slurs" data-original-url="/93049/browzar-responds-to-adware-slurs">Browzar responds to adware slurs</a></p></div></div><p>The AdLoad malware initially surfaced in 2017 but has evolved over the years to evade detection by Apple’s XProtect security system. In 2019, Apple had some partial protection against its earlier variants, but there were no updates to cover the then-new 2019 variant.</p><p>AdLoad is a type of adware that redirects a user’s web traffic through the attacker’s preferred servers. The aim is to hijack and redirect user’s <a href="https://www.itpro.com/network-internet/web-browser/357253/8-most-secure-web-browsers" data-original-url="https://www.itpro.com/network-internet/web-browser/357253/8-most-secure-web-browsers">web browsers</a> for monetary gain.</p><p>Researchers said the 2019 and 2021 AdLoad variants used persistence and executable names that followed a consistent pattern. In 2019, that pattern included some combination of the words “Search,” “Result,” and “Daemon,” such as “ElementarySignalSearchDaemon”.</p><p>The latest version uses a different pattern that primarily relies on a file extension that is either .system or .service. The file extension used depends on the location of the dropped persistence file and executable as described below. Still, typically .system and .service files will be found on the same infected device if the user gave privileges to the installer.</p><p>With or without privileges, AdLoad will install a persistence agent in the user’s Library LaunchAgents folder.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="gGRwbS6T2JYCbdQmJ8xJri" name="gGRwbS6T2JYCbdQmJ8xJri.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/gGRwbS6T2JYCbdQmJ8xJri.png" mos="https://cdn.mos.cms.futurecdn.net/gGRwbS6T2JYCbdQmJ8xJri.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>How to increase cyber resilience within your organisation</strong></p><p class="fancy-box__body-text">Cyber resilience for dummies</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/359468/how-to-increase-cyber-resilience-within-your-organisation" data-original-url="/security/cyber-security/359468/how-to-increase-cyber-resilience-within-your-organisation">FREE DOWNLOAD</a></p></div></div><p>Researchers said they have found around 50 unique label patterns, each having a .service and a .system version. “Based on our previous understanding of AdLoad, we expect there to be many more,” they added.</p><p>Further investigations have found more than 150 unique samples in this year’s campaigns. Researchers noted there appears to have been a sharp uptick throughout July and the early weeks of August 2021. Researchers said a single sample of this variant was documented by <a href="https://blog.confiant.com/osx-hydromac-a-new-macos-malware-leaked-from-a-flashcards-app-2af28f1caa9e">analysts at Confiant,</a> who described the malware’s string decryption routine.</p><p>“It certainly seems possible that the malware developers are taking advantage of the gap in XProtect, which itself has not been updated since a few weeks after Confiant’s research over two months ago. At the time of writing, XProtect was last updated to version 2149 around June 15th – 18th,” researchers said.</p><p>“The fact that hundreds of unique samples of a well-known adware variant have been circulating for at least 10 months and yet remain undetected by Apple’s built-in malware scanner demonstrates the necessity of adding further endpoint security controls to Mac devices,” researchers concluded.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Common malware slipped past the macOS notarization process twice ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Apple launched a notarization process for all apps and software created for macOS in February to weed out malware. Recently, a college student discovered adware with a full macOS notarization, <a href="https://www.wired.com/story/apple-approved-malware-macos-notarization-shlayer">according to WIRED</a>. </p><p>Mac computers were once impenetrable vaults, which led to few hackers attempting to infiltrate them. Those who tried would generally hit roadblocks. Today, Macs are hacked nearly as often as PCs, which lead to the February launch of Apple’s notarization process. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/adware/32497/researchers-blast-wakenet-ab-for-spreading-adware" data-original-url="/adware/32497/researchers-blast-wakenet-ab-for-spreading-adware">Researchers blast Swedish developer WakeNet AB for ‘deceptively’ spreading adware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/93049/browzar-responds-to-adware-slurs" data-original-url="/93049/browzar-responds-to-adware-slurs">Browzar responds to adware slurs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/182034/behind-the-scenes-symantecs-malware-battle" data-original-url="/182034/behind-the-scenes-symantecs-malware-battle">Behind the scenes: Symantec's malware battle</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/99419/it-industry-failure-to-educate-users-over-malware" data-original-url="/99419/it-industry-failure-to-educate-users-over-malware">IT industry failure to educate users over malware</a></p></div></div><p>This notarization is required for all apps and software designed for macOS. And if the notarization doesn’t exist, a user can’t run the software without a workaround. However, college student Peter Dantini purposefully downloaded malware, fully expecting his Mac to reject the installation. To his surprise, the well-traveled Shlayer adware installed on his machine without issue. </p><p>Dantini alerted Apple of the notarized <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a> on Aug. 28, and Apple immediately revoked the notarization certificates. Unfortunately, two days later, the malware reappeared with a notarization from a different Apple Developer ID. Dantini again alerted Apple of the issue. </p><p>Apple addressed the issue, saying, "Malicious software constantly changes, and Apple’s notarization system helps us keep malware off the Mac and allow us to respond quickly when it’s discovered.” The company continued, "Upon learning of this adware, we revoked the identified variant, disabled the developer account, and revoked the associated certificates. We thank the researchers for their assistance in keeping our users safe."</p><p>The fact that Apple quickly addressed the situation is reassuring, but this is proof that relying on Apple’s notarization system alone isn’t enough. While it can help prevent most malware, having a strong <a href="https://www.itpro.com/security/antivirus" data-original-url="https://www.itpro.com/antivirus-0">antivirus</a> and a critical eye for iffy apps is key. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/malware/356924/apple-mistakenly-approved-malware-on-macos</link>
                                                                            <description>
                            <![CDATA[ Apple immediately revoked the notarization, but the adware slipped through again ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cuuZmeHqigESZnT4vdmk6e</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kdWQYRnebCeRMuWc86udma-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 31 Aug 2020 17:28:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Justin Cupler ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kdWQYRnebCeRMuWc86udma-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Apple logo on the side of a building]]></media:description>                                                            <media:text><![CDATA[Apple logo on the side of a building]]></media:text>
                                <media:title type="plain"><![CDATA[Apple logo on the side of a building]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kdWQYRnebCeRMuWc86udma-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Apple launched a notarization process for all apps and software created for macOS in February to weed out malware. Recently, a college student discovered adware with a full macOS notarization, <a href="https://www.wired.com/story/apple-approved-malware-macos-notarization-shlayer">according to WIRED</a>. </p><p>Mac computers were once impenetrable vaults, which led to few hackers attempting to infiltrate them. Those who tried would generally hit roadblocks. Today, Macs are hacked nearly as often as PCs, which lead to the February launch of Apple’s notarization process. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/adware/32497/researchers-blast-wakenet-ab-for-spreading-adware" data-original-url="/adware/32497/researchers-blast-wakenet-ab-for-spreading-adware">Researchers blast Swedish developer WakeNet AB for ‘deceptively’ spreading adware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/93049/browzar-responds-to-adware-slurs" data-original-url="/93049/browzar-responds-to-adware-slurs">Browzar responds to adware slurs</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/182034/behind-the-scenes-symantecs-malware-battle" data-original-url="/182034/behind-the-scenes-symantecs-malware-battle">Behind the scenes: Symantec's malware battle</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/99419/it-industry-failure-to-educate-users-over-malware" data-original-url="/99419/it-industry-failure-to-educate-users-over-malware">IT industry failure to educate users over malware</a></p></div></div><p>This notarization is required for all apps and software designed for macOS. And if the notarization doesn’t exist, a user can’t run the software without a workaround. However, college student Peter Dantini purposefully downloaded malware, fully expecting his Mac to reject the installation. To his surprise, the well-traveled Shlayer adware installed on his machine without issue. </p><p>Dantini alerted Apple of the notarized <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a> on Aug. 28, and Apple immediately revoked the notarization certificates. Unfortunately, two days later, the malware reappeared with a notarization from a different Apple Developer ID. Dantini again alerted Apple of the issue. </p><p>Apple addressed the issue, saying, "Malicious software constantly changes, and Apple’s notarization system helps us keep malware off the Mac and allow us to respond quickly when it’s discovered.” The company continued, "Upon learning of this adware, we revoked the identified variant, disabled the developer account, and revoked the associated certificates. We thank the researchers for their assistance in keeping our users safe."</p><p>The fact that Apple quickly addressed the situation is reassuring, but this is proof that relying on Apple’s notarization system alone isn’t enough. While it can help prevent most malware, having a strong <a href="https://www.itpro.com/security/antivirus" data-original-url="https://www.itpro.com/antivirus-0">antivirus</a> and a critical eye for iffy apps is key. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Researchers blast Swedish developer WakeNet AB for ‘deceptively’ spreading adware ]]></title>
                                                                                                <dc:content><![CDATA[ <p>A pay-per-install (PPI) software firm has been accused of using increasingly deceptive tactics to convince online users to install potentially harmful software - while generating large revenues in the process, it has been claimed by security researchers. </p><p>WakeNet AB, which develops e-marketing platform FileCapital, offers malicious actors the tools to spread infected files and adware. These potentially unwanted programmes (PUPs) have the semblance of software with useful functionality, but pose risks to users and can seriously hamper performance.</p><p>FileCapital, the software under fire, allows malicious actors to install several PUPs on users' machines, including Wajam, which replaces display advertising with its own, and OnlineApp, a proxy which routes traffic through its own servers.</p><p>According to security researchers from McAfee, more than 1.9 million detections were seen in the wild during a 10 month period from September 2017 and June 2018 - predominately targeting devices in Germany, but also the UK and US. Overall, there were infections present in 178 countries.</p><p>"WakeNet AB has remained active for 19 years with little outcry," according to McAfee's senior security scientist Oliver Devane and security researcher Charles Crofford, who warned that installing FileCapital leads to PUP infections.</p><p>"Meanwhile, PUPs, which are more numerous than malware, plague users around the world. PUP development is unlikely to slow because they earn their distributors considerable sums.</p><p>"The security industry needs to do more to investigate companies that create PUPs and raise awareness among customers of their bad practices."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools" data-original-url="/security/malware/28083/best-free-malware-removal-tools">6 of the best free malware removal tools in 2023</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/adware/31333/zacinlo-malware-threatens-windows-10-pcs-security" data-original-url="/adware/31333/zacinlo-malware-threatens-windows-10-pcs-security">Zacinlo malware threatens Windows 10 PCs' security</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/phishing/32493/uk-nigerian-london-blue-hacking-gang-target-cfos-in-phishing-campaign" data-original-url="/phishing/32493/uk-nigerian-london-blue-hacking-gang-target-cfos-in-phishing-campaign">UK-Nigerian ‘London Blue’ hacking gang target CFOs in phishing campaign</a></p></div></div><p>FileCapital offers its customers a variety of marketing tools such as embedded movies, landing pages, banners and buttons to coax victims into installing bundled apps that house different PUPs.</p><p>An online user, for instance, may believe they are installing a helpful performance cleaner onto their machine, only to find this is disguised as malicious software that could lead to reduced performance and the appearance of pop-up advertising.</p><p>The embed movie function, which is described as "by far the worst" function, can allow customers to create a fake video website to show a 'codec missing' message and entice users into downloading the bundled installer. This feature is normally prevalent on illegal football and film streaming websites.</p><p>Meanwhile, the revenue WakeNet AB generated in one year through misusing pay-per-install, according to McAfee, put it above some of the most prevalent ransomware strains - with its 2017 financial statements showing the company reaped $2 million.</p><p>"As of now, it seems unlikely that PUP development will slow since it helps their distributors earn a considerable amount of money," said McAfee's chief consumer security evangelist Gary Davis.</p><p>"With that said, it's important now more than ever for users to be aware of the security risks involved with PUPs like the ones spread by WakeNet's FileCapital."</p><p><em>IT Pro </em>contacted WakeNet AB for comment but it had not responded to our request at the time of publication. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/adware/32497/researchers-blast-wakenet-ab-for-spreading-adware</link>
                                                                            <description>
                            <![CDATA[ Bad actors are using tools like 'embed movie' to coax victims into installing software that house adware ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">36SC2V5W53GFVknAZaTEya</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kjwVVRhhwnEyLrFpWGk2j-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Dec 2018 14:39:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kjwVVRhhwnEyLrFpWGk2j-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Graphic of pop-up advertising appearing on-screen]]></media:description>                                                            <media:text><![CDATA[Graphic of pop-up advertising appearing on-screen]]></media:text>
                                <media:title type="plain"><![CDATA[Graphic of pop-up advertising appearing on-screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kjwVVRhhwnEyLrFpWGk2j-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A pay-per-install (PPI) software firm has been accused of using increasingly deceptive tactics to convince online users to install potentially harmful software - while generating large revenues in the process, it has been claimed by security researchers. </p><p>WakeNet AB, which develops e-marketing platform FileCapital, offers malicious actors the tools to spread infected files and adware. These potentially unwanted programmes (PUPs) have the semblance of software with useful functionality, but pose risks to users and can seriously hamper performance.</p><p>FileCapital, the software under fire, allows malicious actors to install several PUPs on users' machines, including Wajam, which replaces display advertising with its own, and OnlineApp, a proxy which routes traffic through its own servers.</p><p>According to security researchers from McAfee, more than 1.9 million detections were seen in the wild during a 10 month period from September 2017 and June 2018 - predominately targeting devices in Germany, but also the UK and US. Overall, there were infections present in 178 countries.</p><p>"WakeNet AB has remained active for 19 years with little outcry," according to McAfee's senior security scientist Oliver Devane and security researcher Charles Crofford, who warned that installing FileCapital leads to PUP infections.</p><p>"Meanwhile, PUPs, which are more numerous than malware, plague users around the world. PUP development is unlikely to slow because they earn their distributors considerable sums.</p><p>"The security industry needs to do more to investigate companies that create PUPs and raise awareness among customers of their bad practices."</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools" data-original-url="/security/malware/28083/best-free-malware-removal-tools">6 of the best free malware removal tools in 2023</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/adware/31333/zacinlo-malware-threatens-windows-10-pcs-security" data-original-url="/adware/31333/zacinlo-malware-threatens-windows-10-pcs-security">Zacinlo malware threatens Windows 10 PCs' security</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/phishing/32493/uk-nigerian-london-blue-hacking-gang-target-cfos-in-phishing-campaign" data-original-url="/phishing/32493/uk-nigerian-london-blue-hacking-gang-target-cfos-in-phishing-campaign">UK-Nigerian ‘London Blue’ hacking gang target CFOs in phishing campaign</a></p></div></div><p>FileCapital offers its customers a variety of marketing tools such as embedded movies, landing pages, banners and buttons to coax victims into installing bundled apps that house different PUPs.</p><p>An online user, for instance, may believe they are installing a helpful performance cleaner onto their machine, only to find this is disguised as malicious software that could lead to reduced performance and the appearance of pop-up advertising.</p><p>The embed movie function, which is described as "by far the worst" function, can allow customers to create a fake video website to show a 'codec missing' message and entice users into downloading the bundled installer. This feature is normally prevalent on illegal football and film streaming websites.</p><p>Meanwhile, the revenue WakeNet AB generated in one year through misusing pay-per-install, according to McAfee, put it above some of the most prevalent ransomware strains - with its 2017 financial statements showing the company reaped $2 million.</p><p>"As of now, it seems unlikely that PUP development will slow since it helps their distributors earn a considerable amount of money," said McAfee's chief consumer security evangelist Gary Davis.</p><p>"With that said, it's important now more than ever for users to be aware of the security risks involved with PUPs like the ones spread by WakeNet's FileCapital."</p><p><em>IT Pro </em>contacted WakeNet AB for comment but it had not responded to our request at the time of publication. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Zacinlo malware threatens Windows 10 PCs' security ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Researchers have uncovered a sophisticated rootkit-based adware, mainly prevalent on Windows 10 devices, that has been operating covertly for six years.</p><p>Dubbed Zacinlo, this rare strain of malware typically operates by silently rendering webpages in the background in hidden windows to simulate clicks and keyboard interactions, or can replace ads naturally loaded in an open web browser with its own ads to collect revenue.</p><p>The malware, subject to an extensive investigation by security company Bitdefender, is armed with a sophisticated array of features to ensure it remains undetected, and even quashes any 'competition', featuring an adware cleanup routine to remove any potential rivals in the adware space.</p><p>It can also uninstall or delete services based on instructions it receives from the command and control infrastructure, to which it routinely sends information about its environment, including what form of anti-malware services may be installed, and which applications are running on startup.</p><p>One of its most concerning features involves a significant invasion of privacy, with Zacinlo able to take screen captures of a user's desktop and send them to its command and control centre for analysis.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="/malware/28076/what-is-malware">What is malware?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/30525/flaw-in-telegram-app-could-spread-malware" data-original-url="/security/30525/flaw-in-telegram-app-could-spread-malware">Flaw in Telegram app could spread malware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools" data-original-url="/security/malware/28083/best-free-malware-removal-tools">6 of the best free malware removal tools in 2023</a></p></div></div><p>Bitdefender's security researchers were alerted to the rootkit-based adware last year, <a href="https://labs.bitdefender.com/2018/06/six-years-and-counting-inside-the-complex-zacinlo-ad-fraud-operation" target="_blank">publishing the results of its analysis in a whitepaper</a>.</p><p>"Since rootkits these days account for under 1% of the malware output we see worldwide, this immediately drew our attention and prompted us to carry out an extensive analysis of the payload, its origins and the spread," the report said.</p><p>"We discovered an ample operation whose central component is a very sophisticated piece of adware with multiple functionalities."</p><p>Over the course of its investigation, Bitdefender learned the adware had been running covertly since 2012/13 with at least 25 different components in almost 2,500 distinct samples. Although components date back to 2012, the adware was most active towards the end of 2017.</p><p>The researchers also learned the functionality of many of Zacinlo's components were in a state of flux throughout the time it was being tracked; with functionalities updated, dropped, or integrated with other components, indicating it is still being developed.</p><p>The vast majority of the samples tracked were spotted in the US, with a handful found in France, Germany, Brazil, China, Indonesia, the Philippines, and several infections in the UK. </p><p>Significantly, despite <a href="https://www.microsoft.com/en-us/wdsi/threats/rootkits" target="_blank">Windows 10 being fitted with in-built technology to protect users from rootkits</a>, the overwhelming majority of samples, 90%, were found on devices running Microsoft's latest operating system.</p><p>"While generating untold revenue for the companies that run these programs, adware has witnessed constant improvements over the years in both data collection and resilience to removal," said Bitdefender senior e-threat analyst Bogdan Botenzatu.</p><p>"The line between adware and spyware has become increasingly fuzzy during recent years as modern adware combines aggressive opt-outs with confusing legal and marketing terms as well as extremely sophisticated persistence mechanisms aimed at taking control away from the user."</p><p>Asked where it fits into the wider threat landscape of 2018, Botenzatu told <em>IT Pro</em>: "Zacinlo was an unexpected surprise in the wider cyber-security landscape, which is currently dominated by ransomware and crypto-jacking malware.</p><p>"The discovery of rootkit-based malware that mostly affects Windows 10 is enough evidence that "independent" malware operators find lucrative niches in a threat landscape dominated by crypto-ransomware and illegal mining of digital currency."</p><p>Zacinlo is the latest in a number of sophisticated malware strains that researchers have uncovered in recent months. Bitdefender similarly detected a remote access tool, named <a href="https://madebychameleon-dot-yamm-track.appspot.com/Redirect?ukey=1F0rWO2TeLM90RSKj5XhaGBMW_iR2w-20q2Bs88gPVkM-187237717&key=YAMMID-08218740&link=https%3A%2F%2Fdrive.google.com%2Ffile%2Fd%2F1FueDY-206W6Bj5LaEB9l1zwvKZ5DijBA%2Fview%3Fusp%3Dsharing" target="_blank">RadRAT</a>, previously operating undetected since 2015, which offers attackers full control over seized computers.</p><p><a href="https://www.itpro.com/malware/31161/roaming-mantis-malware-is-now-spreading-across-the-globe" target="_blank" data-original-url="https://www.itpro.com/malware/31161/roaming-mantis-malware-is-now-spreading-across-the-globe">Roaming Mantis</a>, meanwhile, which uses DNS-hijacking to redirect users to phishing sites running a Coin Hive cryptomining script, was found by Kaspersky Lab last month to be on spreading rapidly across the globe after emerging only a couple of months previously in a handful of countries including Japan and India.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/adware/31333/zacinlo-malware-threatens-windows-10-pcs-security</link>
                                                                            <description>
                            <![CDATA[ Malware takes screenshots of users' desktops, and has been operating silently for six years ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6ubXPa4g7kmcCCGEifzFSs</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wQ6WgpL5aWTp3p9aBhpHr5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 19 Jun 2018 10:58:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wQ6WgpL5aWTp3p9aBhpHr5-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware]]></media:description>                                                            <media:text><![CDATA[Malware]]></media:text>
                                <media:title type="plain"><![CDATA[Malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wQ6WgpL5aWTp3p9aBhpHr5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Researchers have uncovered a sophisticated rootkit-based adware, mainly prevalent on Windows 10 devices, that has been operating covertly for six years.</p><p>Dubbed Zacinlo, this rare strain of malware typically operates by silently rendering webpages in the background in hidden windows to simulate clicks and keyboard interactions, or can replace ads naturally loaded in an open web browser with its own ads to collect revenue.</p><p>The malware, subject to an extensive investigation by security company Bitdefender, is armed with a sophisticated array of features to ensure it remains undetected, and even quashes any 'competition', featuring an adware cleanup routine to remove any potential rivals in the adware space.</p><p>It can also uninstall or delete services based on instructions it receives from the command and control infrastructure, to which it routinely sends information about its environment, including what form of anti-malware services may be installed, and which applications are running on startup.</p><p>One of its most concerning features involves a significant invasion of privacy, with Zacinlo able to take screen captures of a user's desktop and send them to its command and control centre for analysis.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="/malware/28076/what-is-malware">What is malware?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/30525/flaw-in-telegram-app-could-spread-malware" data-original-url="/security/30525/flaw-in-telegram-app-could-spread-malware">Flaw in Telegram app could spread malware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools" data-original-url="/security/malware/28083/best-free-malware-removal-tools">6 of the best free malware removal tools in 2023</a></p></div></div><p>Bitdefender's security researchers were alerted to the rootkit-based adware last year, <a href="https://labs.bitdefender.com/2018/06/six-years-and-counting-inside-the-complex-zacinlo-ad-fraud-operation" target="_blank">publishing the results of its analysis in a whitepaper</a>.</p><p>"Since rootkits these days account for under 1% of the malware output we see worldwide, this immediately drew our attention and prompted us to carry out an extensive analysis of the payload, its origins and the spread," the report said.</p><p>"We discovered an ample operation whose central component is a very sophisticated piece of adware with multiple functionalities."</p><p>Over the course of its investigation, Bitdefender learned the adware had been running covertly since 2012/13 with at least 25 different components in almost 2,500 distinct samples. Although components date back to 2012, the adware was most active towards the end of 2017.</p><p>The researchers also learned the functionality of many of Zacinlo's components were in a state of flux throughout the time it was being tracked; with functionalities updated, dropped, or integrated with other components, indicating it is still being developed.</p><p>The vast majority of the samples tracked were spotted in the US, with a handful found in France, Germany, Brazil, China, Indonesia, the Philippines, and several infections in the UK. </p><p>Significantly, despite <a href="https://www.microsoft.com/en-us/wdsi/threats/rootkits" target="_blank">Windows 10 being fitted with in-built technology to protect users from rootkits</a>, the overwhelming majority of samples, 90%, were found on devices running Microsoft's latest operating system.</p><p>"While generating untold revenue for the companies that run these programs, adware has witnessed constant improvements over the years in both data collection and resilience to removal," said Bitdefender senior e-threat analyst Bogdan Botenzatu.</p><p>"The line between adware and spyware has become increasingly fuzzy during recent years as modern adware combines aggressive opt-outs with confusing legal and marketing terms as well as extremely sophisticated persistence mechanisms aimed at taking control away from the user."</p><p>Asked where it fits into the wider threat landscape of 2018, Botenzatu told <em>IT Pro</em>: "Zacinlo was an unexpected surprise in the wider cyber-security landscape, which is currently dominated by ransomware and crypto-jacking malware.</p><p>"The discovery of rootkit-based malware that mostly affects Windows 10 is enough evidence that "independent" malware operators find lucrative niches in a threat landscape dominated by crypto-ransomware and illegal mining of digital currency."</p><p>Zacinlo is the latest in a number of sophisticated malware strains that researchers have uncovered in recent months. Bitdefender similarly detected a remote access tool, named <a href="https://madebychameleon-dot-yamm-track.appspot.com/Redirect?ukey=1F0rWO2TeLM90RSKj5XhaGBMW_iR2w-20q2Bs88gPVkM-187237717&key=YAMMID-08218740&link=https%3A%2F%2Fdrive.google.com%2Ffile%2Fd%2F1FueDY-206W6Bj5LaEB9l1zwvKZ5DijBA%2Fview%3Fusp%3Dsharing" target="_blank">RadRAT</a>, previously operating undetected since 2015, which offers attackers full control over seized computers.</p><p><a href="https://www.itpro.com/malware/31161/roaming-mantis-malware-is-now-spreading-across-the-globe" target="_blank" data-original-url="https://www.itpro.com/malware/31161/roaming-mantis-malware-is-now-spreading-across-the-globe">Roaming Mantis</a>, meanwhile, which uses DNS-hijacking to redirect users to phishing sites running a Coin Hive cryptomining script, was found by Kaspersky Lab last month to be on spreading rapidly across the globe after emerging only a couple of months previously in a handful of countries including Japan and India.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Lenovo vows to cut bloatware after Superfish ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Lenovo is to cut bloatware on its PCs to prevent security concerns triggered by the Superfish adware that led to a compromised HTTPS protocol.</p><p>The <a href="https://www.itpro.com/security/24081/lenovo-stops-shipping-superfish-adware-with-consumer-devices" target="_blank" data-original-url="https://www.itpro.com/security/24081/lenovo-stops-shipping-superfish-adware-with-consumer-devices">Superfish adware preloaded on Lenovo consumer notebooks</a> from September 2014 caused great concern from privacy and security groups because it could potentially allow attackers to access encrypted data when it inserted visual search results into a browser.</p><p>This is because it used a self-signed security certificate, which, if compromised, <a href="https://www.itpro.com/malware/24107/lenovo-cto-to-create-concrete-superfish-attack-plan" target="_blank" data-original-url="https://www.itpro.com/malware/24107/lenovo-cto-to-create-concrete-superfish-attack-plan">could have provided hackers with access to all of a user's browser data</a> - regardless of whether it had been encrypted. </p><p>Now, Lenovo said it will remove all adware and bloatware from new devices, offering tools to customers that can remove Superfish, as well as a free six-month subscription to McAfee LiveSafe service or, for existing users of the security software, a six-month extension on their existing plan.</p><p>The company said in a statement: "The events of last week reinforce the principle that customer experience, security and privacy must be our top priorities. With this in mind, we will significantly reduce preloaded applications. Our goal is clear: To become the leader in providing cleaner, safer PCs."</p><p>It will, however, include software that is "customarily expected" in some countries, which could, for example be default search engines and browsers in countries outside Western Europe.</p><p>"We are starting [to roll this out] immediately, and by the time we launch our Windows 10 products, our standard image will only include the operating system and related software, software required to make hardware work well (for example, when we include unique hardware in our devices, like a 3D camera), security software and Lenovo applications," the company added.</p><p>It plans to list all the software preloaded on its PCs and explain what it's all for to prevent the surprise of unwanted preinstalled software.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/malware/24138/lenovo-vows-to-cut-bloatware-after-superfish</link>
                                                                            <description>
                            <![CDATA[ The company says it will drop adware after its Superfish debacle left customer data at risk ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">43Q7WYHZshD9XLU5V6ZXfR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/766X3iM4DppaitSkdCPd9C-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 02 Mar 2015 09:41:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Clare Hopping ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/766X3iM4DppaitSkdCPd9C-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/766X3iM4DppaitSkdCPd9C-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Lenovo is to cut bloatware on its PCs to prevent security concerns triggered by the Superfish adware that led to a compromised HTTPS protocol.</p><p>The <a href="https://www.itpro.com/security/24081/lenovo-stops-shipping-superfish-adware-with-consumer-devices" target="_blank" data-original-url="https://www.itpro.com/security/24081/lenovo-stops-shipping-superfish-adware-with-consumer-devices">Superfish adware preloaded on Lenovo consumer notebooks</a> from September 2014 caused great concern from privacy and security groups because it could potentially allow attackers to access encrypted data when it inserted visual search results into a browser.</p><p>This is because it used a self-signed security certificate, which, if compromised, <a href="https://www.itpro.com/malware/24107/lenovo-cto-to-create-concrete-superfish-attack-plan" target="_blank" data-original-url="https://www.itpro.com/malware/24107/lenovo-cto-to-create-concrete-superfish-attack-plan">could have provided hackers with access to all of a user's browser data</a> - regardless of whether it had been encrypted. </p><p>Now, Lenovo said it will remove all adware and bloatware from new devices, offering tools to customers that can remove Superfish, as well as a free six-month subscription to McAfee LiveSafe service or, for existing users of the security software, a six-month extension on their existing plan.</p><p>The company said in a statement: "The events of last week reinforce the principle that customer experience, security and privacy must be our top priorities. With this in mind, we will significantly reduce preloaded applications. Our goal is clear: To become the leader in providing cleaner, safer PCs."</p><p>It will, however, include software that is "customarily expected" in some countries, which could, for example be default search engines and browsers in countries outside Western Europe.</p><p>"We are starting [to roll this out] immediately, and by the time we launch our Windows 10 products, our standard image will only include the operating system and related software, software required to make hardware work well (for example, when we include unique hardware in our devices, like a 3D camera), security software and Lenovo applications," the company added.</p><p>It plans to list all the software preloaded on its PCs and explain what it's all for to prevent the surprise of unwanted preinstalled software.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Facebook warns of new Superfish threat ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Hackers are easily able to extract the fake security certificate used by Superfish to make their malware even more dangerous, Facebook has warned.</p><p><a href="https://www.itpro.com/security/24081/lenovo-stops-shipping-superfish-adware-with-consumer-devices" target="_blank" data-original-url="https://www.itpro.com/security/24081/lenovo-stops-shipping-superfish-adware-with-consumer-devices">Superfish, the adware program that came pre-installed on Lenovo machines</a>, used a self-signed security certificate, known as a Certificate Authority (CA), to impersonate any SSL-enabled website.</p><p>That means it could trick a user's computer into connecting with a website by offering up its own, insecure CA, rather than the website's own, which a computer must receive to confirm the website is what it claims to be.</p><p>Known as a man-in-the-middle attack, this undermines the security of web browsers and operating systems, because it can see all of a computer user's actions, including banking, email and Facebook activity.</p><p>Lenovo was quick to state it didn't profile or monitor user behaviour, or record user information, and has now stopped shipping devices with the adware pre-installed.</p><p>However, Facebook security researcher Matt Richard warned other threat actors could re-use the Superfish CA on their own applications.</p><p><a href="https://www.facebook.com/notes/protect-the-graph/windows-ssl-interception-gone-wild/1570074729899339" target="_blank">He wrote</a>: "By reusing the same certificate, a bad actor could potentially obtain that CA file and perform "man-in-the-middle" (MITM) attacks on untrusted networks like public Wi-Fi, set up authentic-looking phishing pages, or sign software that makes people vulnerable to other malicious code as they browse the internet.</p><p>"In this case, the certificate used by the Superfish software is relatively easy to extract. Although we are not aware of anyone abusing this certificate in the wild, it's a real risk and would be hard to detect."</p><p>He said the social network has found more than 12 other software applications using the same fake certificate program as Superfish.</p><p>While Facebook is yet to determine the purpose of these applications, some of which appear to be Superfish-esque adware, he said a number of them are suspicious.</p><p>"What all of these applications have in common is that they make people less secure through their use of an easily obtained root CA, they provide little information about the risks of the technology, and in some cases they are difficult to remove," Richard added.</p><p>These applications are also unlikely to keep up with updates to the secure browser HTTPS protocol, meaning there's a risk they could expose private data to network attackers.</p><p>Superfish's fake CA comes from a company called Komodia, and Facebook found a Trojan horse, <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2014-121000-1027-99" target="_blank">known as Trojan.Nurjax</a>, using the Komodia's libraries of software development kits.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/malware/24101/facebook-warns-of-new-superfish-threat</link>
                                                                            <description>
                            <![CDATA[ The fake security certificate used by the Lenovo-installed adware can be re-used by hackers, says social network ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sxy965Et8cSBfUrkvtTGD5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7GvRgVNDgexq7MZ4z2vfVh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 23 Feb 2015 11:09:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Joe Curtis ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7GvRgVNDgexq7MZ4z2vfVh-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hackers]]></media:description>                                                            <media:text><![CDATA[Hackers]]></media:text>
                                <media:title type="plain"><![CDATA[Hackers]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7GvRgVNDgexq7MZ4z2vfVh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers are easily able to extract the fake security certificate used by Superfish to make their malware even more dangerous, Facebook has warned.</p><p><a href="https://www.itpro.com/security/24081/lenovo-stops-shipping-superfish-adware-with-consumer-devices" target="_blank" data-original-url="https://www.itpro.com/security/24081/lenovo-stops-shipping-superfish-adware-with-consumer-devices">Superfish, the adware program that came pre-installed on Lenovo machines</a>, used a self-signed security certificate, known as a Certificate Authority (CA), to impersonate any SSL-enabled website.</p><p>That means it could trick a user's computer into connecting with a website by offering up its own, insecure CA, rather than the website's own, which a computer must receive to confirm the website is what it claims to be.</p><p>Known as a man-in-the-middle attack, this undermines the security of web browsers and operating systems, because it can see all of a computer user's actions, including banking, email and Facebook activity.</p><p>Lenovo was quick to state it didn't profile or monitor user behaviour, or record user information, and has now stopped shipping devices with the adware pre-installed.</p><p>However, Facebook security researcher Matt Richard warned other threat actors could re-use the Superfish CA on their own applications.</p><p><a href="https://www.facebook.com/notes/protect-the-graph/windows-ssl-interception-gone-wild/1570074729899339" target="_blank">He wrote</a>: "By reusing the same certificate, a bad actor could potentially obtain that CA file and perform "man-in-the-middle" (MITM) attacks on untrusted networks like public Wi-Fi, set up authentic-looking phishing pages, or sign software that makes people vulnerable to other malicious code as they browse the internet.</p><p>"In this case, the certificate used by the Superfish software is relatively easy to extract. Although we are not aware of anyone abusing this certificate in the wild, it's a real risk and would be hard to detect."</p><p>He said the social network has found more than 12 other software applications using the same fake certificate program as Superfish.</p><p>While Facebook is yet to determine the purpose of these applications, some of which appear to be Superfish-esque adware, he said a number of them are suspicious.</p><p>"What all of these applications have in common is that they make people less secure through their use of an easily obtained root CA, they provide little information about the risks of the technology, and in some cases they are difficult to remove," Richard added.</p><p>These applications are also unlikely to keep up with updates to the secure browser HTTPS protocol, meaning there's a risk they could expose private data to network attackers.</p><p>Superfish's fake CA comes from a company called Komodia, and Facebook found a Trojan horse, <a href="http://www.symantec.com/security_response/writeup.jsp?docid=2014-121000-1027-99" target="_blank">known as Trojan.Nurjax</a>, using the Komodia's libraries of software development kits.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Lenovo stops shipping Superfish adware with consumer devices ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Lenovo has confirmed it has stopped shipping adware with its consumer laptops, which could have led to encrypted user data being compromised by hackers.</p><p>Known as Superfish', the program injected visual search results into the browser without user permission, according to forums unearthed by <em><a href="http://thenextweb.com/insider/2015/02/19/lenovo-caught-installing-adware-new-computers" target="_blank">The Next Web</a>.</em></p><p>While OEMs routinely install bloatware on Windows machines, the Superfish adware appeared to be dangerous, not just inconvenient. This is because it used a self-signed certificate, which if compromised, could have provided hackers with access to all browser data - regardless of whether it had been encrypted. </p><p><strong>Lenovo's official statement</strong></p><p>"We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns," the firm said in a statement.</p><p>"But we know that users reacted to this issue with concern, and so we have taken direct action to stop shipping any products with this software.</p><p>"We will continue to review what we do and how we do it in order to ensure we put our user needs, experience and priorities first."</p><p>A <a href="https://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Lenovo-Pre-instaling-adware-spam-Superfish-powerd-by/td-p/1726839/page/4" target="_blank">Lenovo forum administrator</a> tried to allay fears by stating Superfish did not "profile nor monitor user behavior" or "record user information". The firm has now confirmed it has stopped shipping devices with the software.</p><p>Many Lenovo users have expressed their dismay at the inclusion of the software.</p><p>"I have been working in tech software and systems engineering since mice were not even available for personal computers. I have never seen a brand, of any sort, come OTB with malware," noted <a href="https://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Lenovo-Pre-instaling-adware-spam-Superfish-powerd-by/td-p/1726839/page/4" target="_blank">a perplexed Lenovo customer.</a></p><p>"This is just unreal...and altogether unacceptable. Lenovo is a brand I always have associated with top quality, best practices trustworthy security. The brand has been rock solid, but sliding for years, and lately I have been having some concerns about its Chinese home...increasingly concerning to me in light of technology security and attacks originating from China."</p><p>Below is a tutorial showing users how to uninstall the adware. Those affected are also encouraged to install a fresh copy of Windows to make sure the rogue security certificate is completely removed from their system.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/oMMOPg9DRDc" allowfullscreen></iframe></div></div><p><strong><em>The article was originally published on 19/2/15 and has been updated to reflect with the latest statements from Lenovo.</em></strong></p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/24081/lenovo-stops-shipping-superfish-adware-with-consumer-devices</link>
                                                                            <description>
                            <![CDATA[ Superfish adware had potential to make browser data available to hackers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4vQs7nnS6yV5Gu8En1He7n</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/766X3iM4DppaitSkdCPd9C-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 19 Feb 2015 15:27:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Laptops]]></category>
                                                    <category><![CDATA[Hardware]]></category>
                                                                                                                    <dc:creator><![CDATA[ Khidr Suleman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/766X3iM4DppaitSkdCPd9C-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/766X3iM4DppaitSkdCPd9C-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Lenovo has confirmed it has stopped shipping adware with its consumer laptops, which could have led to encrypted user data being compromised by hackers.</p><p>Known as Superfish', the program injected visual search results into the browser without user permission, according to forums unearthed by <em><a href="http://thenextweb.com/insider/2015/02/19/lenovo-caught-installing-adware-new-computers" target="_blank">The Next Web</a>.</em></p><p>While OEMs routinely install bloatware on Windows machines, the Superfish adware appeared to be dangerous, not just inconvenient. This is because it used a self-signed certificate, which if compromised, could have provided hackers with access to all browser data - regardless of whether it had been encrypted. </p><p><strong>Lenovo's official statement</strong></p><p>"We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns," the firm said in a statement.</p><p>"But we know that users reacted to this issue with concern, and so we have taken direct action to stop shipping any products with this software.</p><p>"We will continue to review what we do and how we do it in order to ensure we put our user needs, experience and priorities first."</p><p>A <a href="https://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Lenovo-Pre-instaling-adware-spam-Superfish-powerd-by/td-p/1726839/page/4" target="_blank">Lenovo forum administrator</a> tried to allay fears by stating Superfish did not "profile nor monitor user behavior" or "record user information". The firm has now confirmed it has stopped shipping devices with the software.</p><p>Many Lenovo users have expressed their dismay at the inclusion of the software.</p><p>"I have been working in tech software and systems engineering since mice were not even available for personal computers. I have never seen a brand, of any sort, come OTB with malware," noted <a href="https://forums.lenovo.com/t5/Lenovo-P-Y-and-Z-series/Lenovo-Pre-instaling-adware-spam-Superfish-powerd-by/td-p/1726839/page/4" target="_blank">a perplexed Lenovo customer.</a></p><p>"This is just unreal...and altogether unacceptable. Lenovo is a brand I always have associated with top quality, best practices trustworthy security. The brand has been rock solid, but sliding for years, and lately I have been having some concerns about its Chinese home...increasingly concerning to me in light of technology security and attacks originating from China."</p><p>Below is a tutorial showing users how to uninstall the adware. Those affected are also encouraged to install a fresh copy of Windows to make sure the rogue security certificate is completely removed from their system.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/oMMOPg9DRDc" allowfullscreen></iframe></div></div><p><strong><em>The article was originally published on 19/2/15 and has been updated to reflect with the latest statements from Lenovo.</em></strong></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Yahoo serves up New Year malware to European customers ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Yahoo has confirmed a number of ads on its European sites were serving malware to visitors for three days over the New Year period.</p><p>The issue was first noted by Dutch IT security company Fox-IT, which <a href="http://blog.fox-it.com/2014/01/03/malicious-advertisements-served-via-yahoo">said in a blog post</a> it had detected and investigated infections suffered by clients who had visited yahoo.com.</p><p>According to the organisation, those who clicked on the ads were redirected to a Magnitude exploit kit, which can install various different malware including ZeuS, Andromeda and Necurs.</p><p>The malicious ads first appeared on 31 December until 3 January, after Yahoo removed them.</p><p>A Yahoo spokesperson told <em>IT Pro</em>: "At Yahoo, we take the safety and privacy of our users seriously. From December 31 to January 3 on our European sites we served some advertisements that...spread malware. Users in North America, Asia Pacific and Latin America...were not affected. Additionally, users using Macs and mobile devices were not affected."</p><p>The company said it is continuing to monitor the adverts appearing on its sites for any other suspicious activity.</p><p>Further information for users will also be posted shortly, the spokesperson said.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/malware/21325/yahoo-serves-up-new-year-malware-to-european-customers</link>
                                                                            <description>
                            <![CDATA[ Malicious adverts infect users’ computers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4FrkpHmhVHpb7gsgsWNWTm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/CxyfVF9HH4eD33zA5otzxD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 06 Jan 2014 16:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/CxyfVF9HH4eD33zA5otzxD-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware on binary]]></media:description>                                                            <media:text><![CDATA[Malware on binary]]></media:text>
                                <media:title type="plain"><![CDATA[Malware on binary]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/CxyfVF9HH4eD33zA5otzxD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Yahoo has confirmed a number of ads on its European sites were serving malware to visitors for three days over the New Year period.</p><p>The issue was first noted by Dutch IT security company Fox-IT, which <a href="http://blog.fox-it.com/2014/01/03/malicious-advertisements-served-via-yahoo">said in a blog post</a> it had detected and investigated infections suffered by clients who had visited yahoo.com.</p><p>According to the organisation, those who clicked on the ads were redirected to a Magnitude exploit kit, which can install various different malware including ZeuS, Andromeda and Necurs.</p><p>The malicious ads first appeared on 31 December until 3 January, after Yahoo removed them.</p><p>A Yahoo spokesperson told <em>IT Pro</em>: "At Yahoo, we take the safety and privacy of our users seriously. From December 31 to January 3 on our European sites we served some advertisements that...spread malware. Users in North America, Asia Pacific and Latin America...were not affected. Additionally, users using Macs and mobile devices were not affected."</p><p>The company said it is continuing to monitor the adverts appearing on its sites for any other suspicious activity.</p><p>Further information for users will also be posted shortly, the spokesperson said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Malwarebytes flags fake Flash update ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Security firm Malwarebytes has sounded the alarm on a new bogus Flash Player update which causes legitimate advertisements to be replaced with spam and inappropriate banners.</p><p>FlashPlayer11.safariextz is a convincing fake browser extension, Malwarebytes claims. It uses the correct Flash Player logo and even includes a hyperlink to the official Adobe website.</p><div><blockquote><p>The bad guys are banking on the fact people are aware how important it is to apply software updates</p></blockquote></div><p>However, once installed, the application either introduces its own intrusive adverts or overlays the official ads on legitimate websites with its own.</p><p>According to Malwarebytes security analyst Jerome Segura, the authors of this rogue application are hoping to tap into the lucrative business of web advertising by generating revenue from users clicking on the fake adverts.</p><p>"Online advertising is a billion dollar industry and everybody wants to have a piece of it. With such invasive adverts, cyber-crooks are likely to generate a lot of views' and even pay per clicks," he said.</p><p>As pointed out in Segura's <a href="http://blog.malwarebytes.org/?p=1643&preview=true">blog post</a>, these adverts are not only intrusive, but also indiscriminate in what they display.</p><p>"Shortly after being installed, [FlashPlayer11.safariextz] will begin to inject very rough advertisements on any website you visit," said Segura.</p><p>"For example, I visited <em>pbskids.org,</em> a site for children to play games and watch their favourite characters, when all of the sudden a pornographic advertisement was displayed," he added.</p><p>According to Segura, the malicious extension is being pushed from various websites, but most commonly comes from adult websites.</p><p>He also said he found it "interesting that the bad guys are banking on the fact people are now quite aware of how important it is to apply software updates".</p><p>"This is why you should always install updates from the vendor's official website to avoid nasty surprises," he advised.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/malware/20411/malwarebytes-flags-fake-flash-update</link>
                                                                            <description>
                            <![CDATA[ Unusual and inappropriate ads injected into websites. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gDpbi8V3agXucYmu3CYy1d</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nP5sLiizhgjJeDES4mAjDi-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 16 Aug 2013 09:49:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nP5sLiizhgjJeDES4mAjDi-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[spam]]></media:description>                                                            <media:text><![CDATA[spam]]></media:text>
                                <media:title type="plain"><![CDATA[spam]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nP5sLiizhgjJeDES4mAjDi-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security firm Malwarebytes has sounded the alarm on a new bogus Flash Player update which causes legitimate advertisements to be replaced with spam and inappropriate banners.</p><p>FlashPlayer11.safariextz is a convincing fake browser extension, Malwarebytes claims. It uses the correct Flash Player logo and even includes a hyperlink to the official Adobe website.</p><div><blockquote><p>The bad guys are banking on the fact people are aware how important it is to apply software updates</p></blockquote></div><p>However, once installed, the application either introduces its own intrusive adverts or overlays the official ads on legitimate websites with its own.</p><p>According to Malwarebytes security analyst Jerome Segura, the authors of this rogue application are hoping to tap into the lucrative business of web advertising by generating revenue from users clicking on the fake adverts.</p><p>"Online advertising is a billion dollar industry and everybody wants to have a piece of it. With such invasive adverts, cyber-crooks are likely to generate a lot of views' and even pay per clicks," he said.</p><p>As pointed out in Segura's <a href="http://blog.malwarebytes.org/?p=1643&preview=true">blog post</a>, these adverts are not only intrusive, but also indiscriminate in what they display.</p><p>"Shortly after being installed, [FlashPlayer11.safariextz] will begin to inject very rough advertisements on any website you visit," said Segura.</p><p>"For example, I visited <em>pbskids.org,</em> a site for children to play games and watch their favourite characters, when all of the sudden a pornographic advertisement was displayed," he added.</p><p>According to Segura, the malicious extension is being pushed from various websites, but most commonly comes from adult websites.</p><p>He also said he found it "interesting that the bad guys are banking on the fact people are now quite aware of how important it is to apply software updates".</p><p>"This is why you should always install updates from the vendor's official website to avoid nasty surprises," he advised.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ File sharing infects 500,000 computers ]]></title>
                                                                                                <dc:content><![CDATA[ <p><a href="http://www.mcafee.com" target="_blank">McAfee</a> has reported what it claims is the most significant malware outbreak in three years, with more than 500,000 detections of a Trojan horse which <a href="http://www.avertlabs.com/research/blog/index.php/2008/05/06/fake-mp3s-running-rampant" target="_blank">masquerades as a media file</a>.</p><p>A number of fake video and music files have been deliberately spread over peer-to-peer file sharing services like <a href="http://www.limewire.com" target="_blank">Limewire</a> and <a href="http://www.zeropaid.com/edonkey" target="_blank">eDonkey</a>. These were malicious MP3 and MPEG files triggering the download of an application which served ads to the infected computer.</p><p>"People were downloading these files hoping it was music, but it was a media file format that allowed you to link to another site where you downloaded additional files," said Toralv Dirro, security strategist at McAfee Avert Labs.</p><p>"Those files downloaded turned out to adware that in some cases even asked the user to accept an end user licence agreement prior to installing."</p><p>McAfee saw this as 'medium' risk, with no other malware receiving that risk rating since 2005 as all others were rated less severe.</p><p>The security vendor claimed that it was the most prevalent piece of malware in the last three years, and that it had never seen a threat this significant come as a media file.</p><p>The huge figure came from retail users that had the option to submit data on what viruses and adware was detected on their computer to McAfee and made publicly available.</p><p>Dirro said: "We are currently seeing that the distribution is still going on. It is now at about 580,000 where files have been detected, so people are continuing to download and share these files."</p><p>The strategist said that these only reported the incidents that were actually detected, and the real number of users and computers affected would be much higher.</p><p>He said that although the damage in this case was not too serious as it was only adware, it could have been much worse and what McAfee were now afraid of in the future was attackers with a more sinister agenda.</p><p>"They could try and copycat this attempt as they have seen it is a very successful way to distribute malware," Dirro said. "In the future we are pretty much expecting this distribution method a lot more."</p><p>Dirro said that instead of pointing to adware, it could lead users to spyware which would instead try to steal people's data. Instead of being a multimedia file it could take the form of a directly executable one.</p><p>"It has happened in the past, but not anywhere close to this scale," Dirro said of the peer-to-peer nature of the attack.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/195672/file-sharing-infects-500000-computers</link>
                                                                            <description>
                            <![CDATA[ McAfee reveal details on what it calls the most significant malware outbreak since 2005, as peer-to-peer networks look under threat. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">69QZrksB8khssDk64ErfGC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2H5jntiXwxW3JruFTR5hjZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 09 May 2008 12:18:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Asavin Wattanajantra ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2H5jntiXwxW3JruFTR5hjZ-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2H5jntiXwxW3JruFTR5hjZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="http://www.mcafee.com" target="_blank">McAfee</a> has reported what it claims is the most significant malware outbreak in three years, with more than 500,000 detections of a Trojan horse which <a href="http://www.avertlabs.com/research/blog/index.php/2008/05/06/fake-mp3s-running-rampant" target="_blank">masquerades as a media file</a>.</p><p>A number of fake video and music files have been deliberately spread over peer-to-peer file sharing services like <a href="http://www.limewire.com" target="_blank">Limewire</a> and <a href="http://www.zeropaid.com/edonkey" target="_blank">eDonkey</a>. These were malicious MP3 and MPEG files triggering the download of an application which served ads to the infected computer.</p><p>"People were downloading these files hoping it was music, but it was a media file format that allowed you to link to another site where you downloaded additional files," said Toralv Dirro, security strategist at McAfee Avert Labs.</p><p>"Those files downloaded turned out to adware that in some cases even asked the user to accept an end user licence agreement prior to installing."</p><p>McAfee saw this as 'medium' risk, with no other malware receiving that risk rating since 2005 as all others were rated less severe.</p><p>The security vendor claimed that it was the most prevalent piece of malware in the last three years, and that it had never seen a threat this significant come as a media file.</p><p>The huge figure came from retail users that had the option to submit data on what viruses and adware was detected on their computer to McAfee and made publicly available.</p><p>Dirro said: "We are currently seeing that the distribution is still going on. It is now at about 580,000 where files have been detected, so people are continuing to download and share these files."</p><p>The strategist said that these only reported the incidents that were actually detected, and the real number of users and computers affected would be much higher.</p><p>He said that although the damage in this case was not too serious as it was only adware, it could have been much worse and what McAfee were now afraid of in the future was attackers with a more sinister agenda.</p><p>"They could try and copycat this attempt as they have seen it is a very successful way to distribute malware," Dirro said. "In the future we are pretty much expecting this distribution method a lot more."</p><p>Dirro said that instead of pointing to adware, it could lead users to spyware which would instead try to steal people's data. Instead of being a multimedia file it could take the form of a directly executable one.</p><p>"It has happened in the past, but not anywhere close to this scale," Dirro said of the peer-to-peer nature of the attack.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>