Lab Matters: The Dark Side of Jailbreaking iPhones

December 1st, 2010 Tim Posted in Industry News, Kaspersky No Comments »

Costin Raiu, director of Kaspersky Lab’s Global Research and Analysis Team, discusses the security risks involved with jailbreaking Apple’s iPhone. In this Q&A with Ryan Naraine, Raiu talks about the Jailbreakme.com vulnerability and exploit and the social engineering techniques used to take advantage of the popularity of jailbreaking utilities. The discussion also touches on Android devices and some of the security ramifications of unregulated smartphone apps.


And Now, an MBR Ransomware

November 29th, 2010 Denis Posted in Industry News, Kaspersky No Comments »

Today my colleague Vitaly Kamluk wrote about a new GpCode-like ransomware which encrypts user’s files with RSA-1024 and AES-256 crypto-algorithms. We’re continuing to investigate this malware and will notify you about our findings.

However, GpCode.ax is not the only piece of ransomware we found today. We’ve just discovered a malware which overwrites the master boot record (MBR) and demands a ransom to retrieve a password and restore the original MBR. This malware is detected as Trojan-Ransom.Win32.Seftad.a and Trojan-Ransom.Boot.Seftad.a.

This ransomware is downloaded by Trojan.Win32.Oficla.cw.

If Seftad.a was downloaded by Oficla.cw and run, the victim’s PC is rebooted and the following message appears on the screen:


GpCode-like Ransomware Is Back

November 29th, 2010 VitalyK Posted in Industry News, Kaspersky No Comments »

We have received several reports from people around the world asking for help with infections very similar to the GpCode trojan that we detected in 2008.

GpCode was initially detected in 2004 and it reappeared almost every year until 2008. Since then, the author has been silent. A few copycats created some imitations of GpCode that were mostly hot air and not real threats because they weren’t using strong cryptographic algorithms.

As we explained before, this type of malware is very dangerous because the chances of getting your data back are very low. It is almost the same as permanent removal of the data from your hard drive. Back in 2006 and 2008, we managed to offer a few ways of recovering and even decrypting your data with our decryption tools.

Now, GpCode is back and it is stronger than before. Unlike the previous variants, it doesn’t delete files after encryption. Instead it overwrites data in the files, which makes it impossible to use data-recovery software such as PhotoRec, which we suggested during the last attack.

Preliminary analysis showed that RSA-1024 and AES-256 are used as crypto-algorithms. The malware encrypts only part of the file, starting from the first byte.

The malware detection was added today as Trojan-Ransom.Win32.GpCode.ax. Kaspersky Lab experts are working on an in-depth analysis of the recent Trojan and will update you on every discovery that may assist with data recovery.

If you think you are infected, we recommend that you do not change anything on your system as it may prevent potential data recovery if we find a solution. It is safe to shutdown the computer or restart it despite claims by the malware writer that files are deleted after N days – we haven’t seen any evidence of time-based file deleting mechanism. But nevertheless, it is better to stay away from any changes that could be made to the file system which, for example, may be caused by computer restart.

People who are not should be aware of the problem and should recognize GpCode from the first second when the warnings appears on your screen. Pushing Reset/Power button on your desktop may save a significant amount of your valuable data! Please remember this and tell your friends that if you see a sudden popup of notepad with text like this:

Don’t hesitate and turn off your PC, pull out the power cable if this is fastest!

Another sign of infection is immediate change of the Desktop background to something like this:

Gpcode desktop message 1

We will keep posting more information and screenshots as we continue our investigation.


Greetings from AVAR 2010

November 20th, 2010 Denis Posted in Industry News, Kaspersky No Comments »

Apa kabar! AVAR 2010 has just finished. It took place on the beautiful Bali island of Indonesia.

AVAR is the biggest international anti-malware event in the Asia-Pacific region. It is one of the best opportunities for industry experts from around the world to get together in a relaxed environment and discuss the latest hot topics. The papers presented in the last two days cover subjects ranging from PDF exploits, targeted attacks and mobile malware, to AV testing and rogue software.

We are proud to announce that Kaspersky Lab was the most active presenter here, with exactly 4 speakers:

And that’s not all: our own Stefan Tanase managed to win the Best Speaker Award, for the second year in a row. Congratulations!

We’re spending our last day here in paradise enjoying the beautiful places this island has to offer. Until next year, selamat tinggal and have a wonderful weekend!