Category: Virus & Malware

  • intel new processor embedded anti malware feature – 15th june 2020

    Preface: Starting with Oracle 11g release 1 (11.1), there is a just-in-time (JIT) compiler for Oracle JVM environment. A JIT compiler for Oracle JVM enables much faster execution because, it manages the invalidation, recompilation, and storage of code without an external mechanism. Background: A way to prevent attack code execution by stack and heap. It…

  • data breach spread to banking enterprise. no exception to bank of America – 28th may 2020.

    Background: The PPP provides small businesses with forgivable loans of up to $10 million per company (8 weeks of payroll). This program was launched on April 3, 2020; it is a forgivable loan program offered primarily to help businesses deal with the adverse consequences COVID- 19. Point of view: Cybercrooks have been leveraging malicious macros…

  • Hacker target EU supercomputer – 19th May 2020

    Preface: What if your computer is slow? Perhaps it is a sign of malware infection. This scenario also apply to modern supercomputer. Perhaps it is powerful. So no one aware. This is only a assumption. However modern supercomputer will be infected by malware. Why? Because part of the modern supercomputer has deployed a Linux OS…

  • Little-Known Linux Exploits is being weaponize – 15th May 2020

    Preface: The following information will continue the theme released yesterday. For review the details by yesterday, please follow this link – www.antihackingonline.com/cyber-war/high-level-state-backed-apt-groups-entrenched-in-plenty-of-servers-for-nearly-a-decade-using-little-known-linux-exploits-14th-may-2020/ About the theme: Sound can tell, according to statistic provided by Microsoft. Cyber security attack is rapidly growth especially in education area within past 30 days. Perhaps Healthcare and pharmaceuticals area cyber attack…

  • For Malicious Cyber Activity, US Homeland Security provides visibility to the world – 13th May 2020

    Preface: It is impossible to rely on small group of expert to track malicious activities on the Internet. In fact, it needs strong financial support. This is reality, maybe this is a long-running game. Background: US Homeland Security issue an evaluation article on hostile country malware and phishing attacks motion. Perhaps you may ask? Can…

  • A retrospective album of BlackEnergy – Feb 2020

    Somewhere in time. This is 2015 – BlackEnergy2 exists in the form of a kernel-mode driver, which makes it harder for network administrators to discover the compromise. Black energy Group will mimics their custom tool(driver) thus made to look like a normal Windows component. They are interested in infecting Windows servers especially OPC server. But…

  • Hacker exploit Coronavirus Crisis, send scam email to different industries – 18th Feb 2020

    Synopsis: a. Attackers disguise their scam email as an official (WHO) alert issued by the Centers for Disease Control Health Alert Network. (Targeting individuals from the United States and the United Kingdom) b. Attackers disguise their scam email as an alert of Coronavirus status, they are target to shipping industry. Description: About the attack to…

  • HKMA alerting public of the hsbc phishing email – 6th Feb 2020

    Preface: Not the first time heard that cyber criminals mimics email from bank to hunting the victims. Historical record: HSBC’s “Payment Notification” malware email was discovered in 2018.These emails are designed to confuse people’s vigilance and use the HSBC brand name to reduce the defensive awareness of email recipients. An “auto-generated” email suggests that you…

  • looking back the malware evolutionary at 2019

    Preface: Unlike C, C++ is an object-oriented programming language, following a programming model that uses objects that contain data as well as functions to manipulate the data. Word is an object-oriented program. Security focus: The malware author usually exploit some kind of arbitrary code execution or zero day. And therefore it have chances to evade…

  • Analysis Reports by US Homeland Security – Legitimate open source remote administration tool re-engineer by threat actor as APT way of attack – Dec 2018

    Preface: Quasar, a legitimate open-source remote administration tool. It is a fast and light-weight remote administration tool coded in C#. Background: APT actors have adapted Quasar and created modified minor (1.3.4.0) and major (2.0.0.0 and 2.0.0.1) versions. Since the re-engineering Quasar client will be mimics a Mozilla Firefox 48 browser running on Windows 8.1 or…