Showing posts with label Technology. Show all posts
Showing posts with label Technology. Show all posts

Friday, 20 October 2017

Russian Hacker Exploits GTA 5 PC Mod to Install Cryptocurrency Miner


Gamers were delighted with the release of world’s second most popular video game Grand Theft Auto V (GTA 5) released by Rockstar North. It was in every way a modder’s dream as while playing the game it allowed gamers to change the base game to a great extent. However, with the high profile and extreme popularity of the game, cybercriminals were bound to identify ways of exploiting and benefitting from it. And, cryptocurrency mining being the latest fad among hackers is the primary mode of exploitation of GTA 5.
According to researchers, a mod maker going by the online handle of ‘Anton’ is reportedly distributing malware into the GTA 5 mods. The young, Russian speaking cybercriminal is apparently trying to hijack the computer power secretly to mine cryptocurrency. The mod maker of GTA 5 was discovered by researchers at Minerva Labs, a cybersecurity firm.
As per their findings, the Arbuz GTA 5 mod was utilized as the source of distribution of malware whereas Anton was found to be using malware WaterMiner for mining cryptocurrency. WaterMiner is a modified version of the authentic open-source XMRig miner. Through the malware, Anton successfully harvests Monero coins. All this is done without alarming the mod user.
Arbuz means watermelon in the Russian language that’s why researchers call have labeled the malware as WaterMiner. The malware is capable of evading all sorts of detection tools and also can hide from being identified by the Windows Task Manager tool or other monitoring services that are meant to keep tabs on computer resources. In case WaterMiner identifies that a computer monitoring tool is trying to detect it, the malware instantly aborts the process and shuts down mining after which it goes into hibernation.


A developer using the alias Martin 0pc0d3r is responsible for creating WaterMiner. Researchers were able to locate the developer because the developer has implemented poor track covering measures. It was due to the same careless attitude that researchers could trace Anton. The aim of Anton was to capitalize on the in-demand games in Russia and that’s why he hid the malware in the fiercely popular GTA 5 game. We suggest that you be cautious while installing mods and the platforms from where you download them in order to stay protected.
Anton, for your information, has become quite popular with his Twitter rants where he claims to have the immense hacking expertise and boasts about his experience as a hacker. The researchers noted that “It is clear that we are not dealing with an experienced cybercriminal.”
Minerva researchers are expecting more fireworks from Anton, and other hackers as the trend of employing malware based miners gain momentum. “It seems that Monero also attracts resourceful individuals who are not the classic attackers we might imagine as criminal masterminds, just like Alaska lured many unskilled miners during the gold rush,” stated the researchers at Minerva.
In a tweet, FiveM, a modification framework for GTA V said that they had issued a security update just to stop users from adding miners to their code. But it looks like things are already out of control.
A minor FiveM update has been released with some small fixes, and blocking of 'coinhive' mining services. Thanks for the reports!
The trend of using Cryptocurrency minors is at peak. It was The Pirate Bay that was caught secretly using Coin Hive’s script to mine Monero digital coins. After that, researchers discovered that there are more than 500 websites are currently mining cryptocurrency without user consent.

Canada’s Spy Agency Releases its Cyber-Defense Tool for Public



The Communications Security Establishment (CSE), Canada’s main signals intelligence agency, has made a malware scanning and analytics tool called AssemblyLine as open-source by releasing the code. AssemblyLine tool can analyze massive volumes of files and also rebalance workload automatically.
During the scanning process, every file is given a unique identifier, and user-defined analytics engines scan it to assess the maliciousness of the code. The file is then assigned a score accordingly, and if a file is identified to be malicious, then it has to go through other defensive mechanisms.
The CSE hopes that by making the code open-source and free, the information security or InfoSec community will be able to develop more tools and come up with innovative methods of detecting malicious files. Registered users can access the AssemblyLine source code at Atlassian’s Bitbucket repository. It is worth noting that the CSE made the software public without commercial or proprietary technology.
This isn’t the first time an agency has released the source code of software since the US NSA/National Security Agency has also publicly released a number of infosec tools such as Secure Extensions for Linux (SELinux) and GCHQ/Government Communications Headquarters of Britain also has a code repository on Github and has already made various tools open-source.
The primary objective of using AssemblyLine is to help analysts from preventing them to manually inspect the files and allowing them enough time and space so that they could focus upon incoming malware. Mainstream anti-virus programs like Kaspersky, McAfee, BitDefender, and F-Secure can also be used for scanning with AssemblyLine while the tool can connect with the VirusTotal anti-virus scanning service through an application programming key.
Assemblyline minimizes the number of non-malicious files that analysts have to manually inspect and allows users to focus their time and attention on the most harmful files.
CSE’s IT security head Scott Jones told CBS News that, AssemblyLine is “a tool that helps our analysts know what to look at because it’s overwhelming for the number of people we have to be able to protect things.”
The CSE has dubbed it an “unprecedented step” as it is the first electronic spy agency that has released its own developed cyber defense tool to the public. The agency hopes that organizations will be able to defend their data and sites from cyber threats better.
Independent researcher and member of University of Toronto’s Citizen Lab, Bill Robinson, has dubbed the step of CSE as “big change” and “a sea of change.” As for, AssemblyLine; the tool is available on BitBucket.

Sunday, 15 October 2017

DDoS attacks on Sweden’ Transport Agencies Delay Train Service









The official website of Transportstyrelsen, Sweden’s Transport Agency (STA) came under a series of DDoS (distributed denial-of-service) attacks on Thursday morning forcing it to go offline.

The attack on Transportstyrelsen came a day after the IT systems of Sweden’s Transport Administration (Trafikverket), which monitors railway traffic, was attacked by hackers leading to delays in trains schedule.

“I can confirm that in the morning we had something that was judging by a congestion attack,” Transport Agency Press Officer Mikael Andersson told Swedish public broadcaster SVT.

It is unclear who was behind the attacks or what were the motives of the attackers. However, this is the second time in the last four months that Sweden’s Transport Agency Transportstyrelsen is in the news for cyber attacks against its cyber infrastructure.

Patrik Gylesjö, deputy CEO of internet provider DGC told Computer Sweden “It could be a prank or someone trying to investigate what kind of protection Trafikverket has.”

In a successful DDoS attack, online service is forced to go down by overwhelming it with traffic from multiple sources.

In July this year, it was reported that a massive trove of data belonging to Transportstyrelsen was mistakenly uploaded to a cloud server. The data contained vehicle and personal information of almost every citizen in the country including the military and police officials.

Although the investigation is still in process, initial checks discovered that the exposed data includes names, addresses, and pictures of millions of citizens, details about people listed in police registers and government military vehicles, driver’s license records of fighter pilots of the Swedish air force, personal details of military members in secret units and data on critical infrastructure in Sweden including roads and bridges.

If you are running a business; calculate the cost and probability of a DDoS attack on your business with this DDoS Downtime Cost Calculator.

Hundreds Of websites mining cryptocurrency without user consent






Previously it was reported that torrent search platform The Pirate Bay and other popular siteshave been using visitor PCs to mine cryptocurrency and new reports have revealed that these are not the only websites that are exploiting our PCs but hundreds of websites are mining cryptocurrency without notifying the users.

Bitcoin or Monero are some types of cryptocurrencies that can be mined and received through computation. When a site that is mining cryptocurrency is visited, there is a surprising surge in the CPU usage, which can prove to be beneficial for website owners because when a large number of PCs donates their powers, the mining is successful in earning revenues.

The report published by Adguard states that within merely weeks since the revelation about The Pirate Bay, there is an astounding increment in sites that mine cryptocurrencies through PCs of their site’s visitors.

Reportedly, 0.22% of the top 100,000 sites on Alexa List are discovered to be mining cryptocurrency, which means about 220 sites are involved in mining while the average of visitors on these sites is nearly 500 million and this audience arrive from various parts of the world from the USA and Europe to Asia and South America. While JSEcoin and CoinHive are the two most common and popular scripts that are employed to acquire cryptocurrency.

Adguard explains that around $43,000 have been raked in by these domains without any expenditure and within only three weeks. Reports also reveal that The Pirate Bay made $12,000 per month through cryptocurrency as the traffic flow is quite heavy on its domain.

It is worth noting that most of the websites that are using miners are not as reliable and come from the blurry background. These include torrent search sites, pornographic sites, domains that host pirated content and similar other sites.

As per the analysis of Adguard, websites having “shady reputation” are involved in browser mining; these sites otherwise find it difficult to make money through standard advertising practices, therefore, they use such tactics. Sites offering video-based content are most likely to generate income through mining more than any other.

However, if handled appropriately, mining of cryptocurrency has immense potential as many users would agree to lend their CPUs so that they could get rid of annoying ads; but consent of users must be given importance. Domain operators need to respect end users and seek permission. Without user consent, domain operators are putting their reputation at risk, which might prove to be detrimental to their image in the long run.

CoinHive released the following statement after learning about the mining scheme used by websites:


“We’re a bit saddened to see that some of our customers integrate CoinHive into their pages without disclosing to their users what’s going on, let alone asking for their permission. We believe there’s so much more potential for our solution, but we have to be respectful to our end users.”

Remember that adblockers will block these scripts and it is on developers of cryptocurrency mining scripts and domain operators to transform this scheme into a reliable alternative to advertising.


“Providing a real alternative to ads and users who block them turned out to be a much harder problem. CoinHive, too, is now blocked by many ad-block browser extensions, which — we have to admit — is reasonable at this point,” stated CoinHive rep.

Popular Posts


Types of SQL Injection

SQL injection is a code injection method, used to attack data-driven applications. This vulnerability allows a hacker to submit crafte...

Blog Archive