At MalCon security conference in Mumbai, Peter Kleissner demonstrated how to install bootkit on the next Microsoft operating system Windows 8. The exploit can bypass the new security measures implemented on Windows 8 to load directly in the memory to provide attacker root privilege to the system. “Windows 8 Bootkit and Art of Bootkit Development” [...]
Posts Tagged ‘Malware Research’
Reversing Malware with Android Reverse Engineering (A.R.E.)
January 16th, 2012
Mourad Ben Lakhoua Malwares on mobile system are increasing dramatically, especially on android smartphone system, this week Trendmicro security lab posted about new campaign targeting this system by infecting users over web applications (One-Click Billing Fraud Scheme Through Android App Found). After infecting the smartphone with ANDROIDOS_FAKETIMER some information will be sent to certain URL’s on the web, [...]
Fake Antivirus Attack Not Out
August 21st, 2011
Mourad Ben Lakhoua A new case have been observed by Armorize researchers that discovers a mass malicious code injection on different vulnerable website on internet, Security lab estimate at least 22,400 unique domains are spreading malwares by including a malicious iFrame-code. Attackers this time didn’t succeed at this operation as they made a mistake by missing to include [...]
Rootkit War Zeroaccess Kills TDL3
August 12th, 2011
Mourad Ben Lakhoua Cyber Gang have created a new way for getting income, the group is selling TDL3 malware on different underground forum with a modification of source code package that allow infected computer remove the TDL malware. Malware author have created two different versions one contains the original code and not for sale and another copy that [...]
MS Warns of Malware Requires System Reinstall
June 28th, 2011
Mourad Ben Lakhoua Microsoft informed of a new kind of rootkit that hides in the boot sector MBR. This new malware makes any windows user have to reinstall the whole system to remove it. The new Trojan that Microsoft calls Popureb displays advertisements, and modifies the affected user’s Internet Explorer start page. The Trojan works by: MBR decrypts [...]
YARA Adds Win32 Version
June 23rd, 2011
Mourad Ben Lakhoua I have previously posted on Infosec Institute an article about Classifying Malware with ClamAV and YARA, the article is focused on using open source tools under Linux system to create descriptions of malware families based on textual or binary patterns contained in samples from those families and to quickly identify known malware. Two days ago [...]



Posted in
Tags:



