<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/">

<channel>
	<title>BGR: The Three Biggest Letters In Tech &#187; trojan</title>
	<atom:link href="http://www.bgr.com/tag/trojan/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.bgr.com</link>
	<description></description>
	<lastBuildDate>Fri, 01 Jun 2012 21:39:21 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>New Flashback variant continues Java attack on Macs</title>
		<link>http://www.bgr.com/2012/04/25/new-flashback-variant-continues-java-attack-on-macs/</link>
		<comments>http://www.bgr.com/2012/04/25/new-flashback-variant-continues-java-attack-on-macs/#comments</comments>
		<pubDate>Thu, 26 Apr 2012 01:05:12 +0000</pubDate>
		<dc:creator>Dan Graziano</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Flashback]]></category>
		<category><![CDATA[Flashback.S]]></category>
		<category><![CDATA[iMac]]></category>
		<category><![CDATA[Intego]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[MacBook]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[os x]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.bgr.com/?p=136721</guid>
		<description><![CDATA[Security firm Intego on Monday announced that it had discovered a new variant of the Flashback malware called Flashback.S that continues to use a Java vulnerability Apple has already patched. This variant requires no password to install, and it places its files into the user’s home folder in &#8220;~/Library/LaunchAgents/com. java.update.plist&#8221; and &#8220;~/.jupdate.&#8221; Once Fashback.S is installed, it will then delete all files and folders in &#8220;~/Library/Caches/Java/cache&#8221; in order to delete the applet from the infected Mac, and avoid detection. The virus is actively being distributed, although it will not install if it finds Intego VirusBarrier X6, Xcode or Little Snitch installed on the Mac it tries to attack. Read]]></description>
			<content:encoded><![CDATA[<center><a href="http://www.bgr.com/2012/04/25/new-flashback-variant-continues-java-attack-on-macs"><img class="size-full wp-image-134578 aligncenter" title="apple-logo-sign-virus-mac" src="http://www-bgr-com.vimg.net/wp-content/uploads/2012/04/apple-logo-sign-virus-mac.jpg" alt="" width="652" height="419" /></a></center>
<p>Security firm Intego on Monday announced that it had discovered a new variant of <a href="http://www.bgr.com/2012/04/05/flashback-trojan-virus-found-to-affect-600000-macs/">the Flashback malware</a> called Flashback.S that continues to use a Java vulnerability <a href="http://www.bgr.com/2012/04/12/apple-releases-removal-tool-for-flashback-malware/">Apple has already patched</a>. This variant requires no password to install, and it places its files into the user’s home folder in &#8220;~/Library/LaunchAgents/com. java.update.plist&#8221; and &#8220;~/.jupdate.&#8221; Once Fashback.S is installed, it will then delete all files and folders in &#8220;~/Library/Caches/Java/cache&#8221; in order to delete the applet from the infected Mac, and avoid detection. The virus is actively being distributed, although it will not install if it finds Intego VirusBarrier X6, Xcode or Little Snitch installed on the Mac it tries to attack.</p>
<p><span id="more-136721"></span></p>
<p><a href="http://www.intego.com/mac-security-blog/new-flashback-variant-continues-java-attack-installs-without-password/#disqus">Read</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bgr.com/2012/04/25/new-flashback-variant-continues-java-attack-on-macs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	<media:thumbnail url="http://www-bgr-com.vimg.net/wp-content/uploads/2012/04/flashback-s-128x128.png">http://www-bgr-com.vimg.net/wp-content/uploads/2012/04/flashback-s-128x128.png</media:thumbnail>	</item>
		<item>
		<title>Security firm identifies origins of &#8216;Flashback&#8217; Mac virus</title>
		<link>http://www.bgr.com/2012/04/23/security-firm-identifies-origins-of-flashback-mac-virus/</link>
		<comments>http://www.bgr.com/2012/04/23/security-firm-identifies-origins-of-flashback-mac-virus/#comments</comments>
		<pubDate>Mon, 23 Apr 2012 23:05:44 +0000</pubDate>
		<dc:creator>Zach Epstein</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Flashback]]></category>
		<category><![CDATA[Kaspersky]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[MacBook]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.bgr.com/?p=136556</guid>
		<description><![CDATA[The &#8220;Flashback&#8221; virus discovered to have infected more than 600,000 Mac computers earlier this month originated on a series of WordPress blogs, security experts have determined. According to Alexander Gostev, head of the global research and analysis team at Kaspersky, the virus began as a trojan hidden within a fake Adobe software update. In March, however, the malware&#8217;s creators repackaged the virus in a &#8220;drive-by attack&#8221; that infected users&#8217; Apple computers when they visited one of thousands of compromised WordPress blogs. &#8221;Tens of thousands of sites powered by WordPress were compromised,&#8221; Gostev wrote on Kaspersky&#8217;s SecureList blog. &#8220;How this happened is unclear. The main theories are that bloggers were using a vulnerable version of WordPress or they had installed the ToolsPack]]></description>
			<content:encoded><![CDATA[<center><a href="http://www.bgr.com/2012/04/23/security-firm-identifies-origins-of-flashback-mac-virus"><img class="size-full wp-image-134578 aligncenter" title="apple-logo-sign-virus-mac" src="http://www-bgr-com.vimg.net/wp-content/uploads/2012/04/apple-logo-sign-virus-mac.jpg" alt="" width="652" height="419" /></a></center>
<p>The &#8220;Flashback&#8221; virus discovered to have <a href="http://www.bgr.com/2012/04/05/flashback-trojan-virus-found-to-affect-600000-macs/">infected more than 600,000 Mac computers</a> earlier this month originated on a series of WordPress blogs, security experts have determined. According to Alexander Gostev, head of the global research and analysis team at Kaspersky, the virus began as a trojan hidden within a fake Adobe software update. In March, however, the malware&#8217;s creators repackaged the virus in a &#8220;drive-by attack&#8221; that infected users&#8217; Apple computers when they visited one of thousands of compromised WordPress blogs. &#8221;Tens of thousands of sites powered by WordPress were compromised,&#8221; Gostev wrote on Kaspersky&#8217;s <em>SecureList</em> blog. &#8220;How this happened is unclear. The main theories are that bloggers were using a vulnerable version of WordPress or they had installed the ToolsPack plug-in.&#8221; Apple <a href="http://www.bgr.com/2012/04/12/apple-releases-removal-tool-for-flashback-malware/">released a system update</a> earlier this month that patched a Java vulnerability and removed most common iterations of the Flashback virus. As of the middle of last week, however, <a href="http://www.bgr.com/2012/04/18/140000-mac-computers-still-infected-by-flashback-trojan-firm-says/">more than 140,000 Mac computers were still infected with the virus</a>, which is capable of intercepting private data and transmitting it without a user&#8217;s knowledge.<span id="more-136556"></span></p>
<p><a href="https://www.securelist.com/en/analysis/204792227/The_anatomy_of_Flashfake_Part_1">Read</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bgr.com/2012/04/23/security-firm-identifies-origins-of-flashback-mac-virus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	<media:thumbnail url="http://www-bgr-com.vimg.net/wp-content/uploads/2012/04/apple-logo-sign-virus-mac-128x128.jpg">http://www-bgr-com.vimg.net/wp-content/uploads/2012/04/apple-logo-sign-virus-mac-128x128.jpg</media:thumbnail>	</item>
		<item>
		<title>Malware found to steal credit card data from hotel payment systems</title>
		<link>http://www.bgr.com/2012/04/20/malware-found-to-steal-credit-card-data-from-hotel-payment-systems/</link>
		<comments>http://www.bgr.com/2012/04/20/malware-found-to-steal-credit-card-data-from-hotel-payment-systems/#comments</comments>
		<pubDate>Sat, 21 Apr 2012 00:20:05 +0000</pubDate>
		<dc:creator>Dan Graziano</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Hotel]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[screenshot]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://www.bgr.com/?p=136468</guid>
		<description><![CDATA[Security firm Trusteer warned this week of a trojan that is capable of stealing an individual&#8217;s credit card information from hotels. The firm&#8217;s intelligence team discovered the remote access trojan being sold on underground forums for $280. The malware is designed to capture screenshots from point-of-sale applications that access credit card numbers and expiration dates. These systems are located on front-desk computers at hotels, and they are often unmanaged and do not contain anti-virus protections software that would stop a trojan of this type. The malware&#8217;s creators also include instructions on how to use VoIP-based social engineering to trick front-desk clerks into installing the trojan. [Via SC Magazine] Read]]></description>
			<content:encoded><![CDATA[<center><a href="http://www.bgr.com/2012/04/20/malware-found-to-steal-credit-card-data-from-hotel-payment-systems"><img class="size-full wp-image-102036 aligncenter" title="hackers" src="http://www-bgr-com.vimg.net/wp-content/uploads/2011/08/hackers110830150530.jpeg" alt="" width="652" height="370" /></a></center>
<p>Security firm Trusteer warned this week of a trojan that is capable of stealing an individual&#8217;s credit card information from hotels. The firm&#8217;s intelligence team discovered the remote access trojan being sold on underground forums for $280. The malware is designed to capture screenshots from point-of-sale applications that access credit card numbers and expiration dates. These systems are located on front-desk computers at hotels, and they are often unmanaged and do not contain anti-virus protections software that would stop a trojan of this type. The malware&#8217;s creators also include instructions on how to use VoIP-based social engineering to trick front-desk clerks into installing the trojan.<span id="more-136468"></span></p>
<p>[Via <a href="http://www.scmagazine.com/trojan-designed-to-take-screenshots-of-hotel-payment-apps/article/237341/">SC Magazine</a>]</p>
<p><a href="https://www.trusteer.com/blog/no-reservations-%E2%80%93-remote-access-trojan-pilfers-credit-cards-hotels">Read</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bgr.com/2012/04/20/malware-found-to-steal-credit-card-data-from-hotel-payment-systems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	<media:thumbnail url="http://www-bgr-com.vimg.net/wp-content/uploads/2011/08/hackers110830150530-128x128.jpg">http://www-bgr-com.vimg.net/wp-content/uploads/2011/08/hackers110830150530-128x128.jpg</media:thumbnail>	</item>
		<item>
		<title>140,000 Mac computers still infected by &#8216;Flashback&#8217; trojan, firm says</title>
		<link>http://www.bgr.com/2012/04/18/140000-mac-computers-still-infected-by-flashback-trojan-firm-says/</link>
		<comments>http://www.bgr.com/2012/04/18/140000-mac-computers-still-infected-by-flashback-trojan-firm-says/#comments</comments>
		<pubDate>Wed, 18 Apr 2012 12:45:00 +0000</pubDate>
		<dc:creator>Zach Epstein</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Flashback]]></category>
		<category><![CDATA[iMac]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[MacBook]]></category>
		<category><![CDATA[os x]]></category>
		<category><![CDATA[removal tool]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.bgr.com/?p=136065</guid>
		<description><![CDATA[Apple responded fairly quickly to news that more than 600,000 Mac computers were infected with a trojan virus called &#8220;Flashback.&#8221; One week after the massive botnet was discovered, Apple issued an update fixing the Java vulnerability that allowed Flashback to infect the machines, as well as a removal tool for affected machines. Despite the company&#8217;s efforts, Symantec stated on Tuesday evening that approximately 140,000 OS X PCs were still infected with the virus at that time. &#8220;The statistics from our sinkhole are showing declining numbers on a daily basis,&#8221; the company wrote on its blog. &#8220;However, we had originally believed that we would have seen a greater decline in infections at this point in time, but this has proven not]]></description>
			<content:encoded><![CDATA[<center><a href="http://www.bgr.com/2012/04/18/140000-mac-computers-still-infected-by-flashback-trojan-firm-says"><img class="size-full wp-image-134578 aligncenter" title="apple-logo-sign-virus-mac" src="http://www-bgr-com.vimg.net/wp-content/uploads/2012/04/apple-logo-sign-virus-mac.jpg" alt="" width="652" height="419" /></a></center>
<p>Apple responded fairly quickly to news that <a href="http://www.bgr.com/2012/04/05/flashback-trojan-virus-found-to-affect-600000-macs/">more than 600,000 Mac computers were infected with a trojan virus called &#8220;Flashback.&#8221;</a> One week after the massive botnet was discovered, <a href="http://www.bgr.com/2012/04/12/apple-releases-removal-tool-for-flashback-malware/">Apple issued an update</a> fixing the Java vulnerability that allowed Flashback to infect the machines, as well as a removal tool for affected machines. Despite the company&#8217;s efforts, Symantec stated on Tuesday evening that approximately 140,000 OS X PCs were still infected with the virus at that time. &#8220;The statistics from our sinkhole are showing declining numbers on a daily basis,&#8221; the company wrote on its blog. &#8220;However, we had originally believed that we would have seen a greater decline in infections at this point in time, but this has proven not to be the case. Currently, it appears that the number of infected computers has tapered off, but remains around the 140,000 mark.&#8221; Symantec offers its own Flashback removal tool separate from the one Apple made available in a system update on April 12th.<span id="more-136065"></span></p>
<p><a href="http://www.symantec.com/connect/blogs/flashback-cleanup-still-underway-approximately-140000-infections">Read</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bgr.com/2012/04/18/140000-mac-computers-still-infected-by-flashback-trojan-firm-says/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	<media:thumbnail url="http://www-bgr-com.vimg.net/wp-content/uploads/2012/04/apple-logo-sign-virus-mac-128x128.jpg">http://www-bgr-com.vimg.net/wp-content/uploads/2012/04/apple-logo-sign-virus-mac-128x128.jpg</media:thumbnail>	</item>
		<item>
		<title>Second Mac trojan discovered, also exploits Java vulnerability</title>
		<link>http://www.bgr.com/2012/04/16/second-mac-trojan-discovered-also-exploits-java-vulnerability/</link>
		<comments>http://www.bgr.com/2012/04/16/second-mac-trojan-discovered-also-exploits-java-vulnerability/#comments</comments>
		<pubDate>Mon, 16 Apr 2012 17:15:38 +0000</pubDate>
		<dc:creator>Dan Graziano</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[computers]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[os x]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.bgr.com/?p=135686</guid>
		<description><![CDATA[The &#8220;Flashback&#8221; trojan virus affecting at least 600,000 Macs was discovered last week that is capable of intercepting passwords and other private data. The discovery prompted Apple to release a Java update for OS X users that removed a number of common variants of the virus. Securelist on Saturday found another Mac trojan that is also spread through Java exploits, however. The malware, called Backdoor.OSX.SabPub, can take screenshots of a user’s current session, execute commands on an infected machine and connect to a remote website to transmit the data. It is not clear how users get infected with the trojan, but because of the low number of instances and the trojan&#8217;s backdoor functionality, Securelist speculates that it is most likely used in]]></description>
			<content:encoded><![CDATA[<center><a href="http://www.bgr.com/2012/04/16/second-mac-trojan-discovered-also-exploits-java-vulnerability"><img class="size-large wp-image-135694 aligncenter" title="virus" src="http://www-bgr-com.vimg.net/wp-content/uploads/2012/04/virus-645x483.jpg" alt="" width="645" height="483" /></a></center>
<p>The &#8220;Flashback&#8221; trojan virus <a href="http://www.bgr.com/2012/04/05/flashback-trojan-virus-found-to-affect-600000-macs/">affecting at least 600,000 Macs was discovered last week</a> that is capable of intercepting passwords and other private data. The discovery prompted Apple to <a href="http://www.bgr.com/2012/04/12/apple-releases-removal-tool-for-flashback-malware/">release a Java update for OS X users</a> that removed a number of common variants of the virus. Securelist on Saturday found another Mac trojan that is also spread through Java exploits, however. The malware, called Backdoor.OSX.SabPub, can take screenshots of a user’s current session, execute commands on an infected machine and connect to a remote website to transmit the data. It is not clear how users get infected with the trojan, but because of the low number of instances and the trojan&#8217;s backdoor functionality, Securelist speculates that it is most likely used in targeted attacks, possibly launched through emails containing a URL pointing to two one of websites hosting the exploit. <span id="more-135686"></span></p>
<p><a href="http://www.securelist.com/en/blog/208193467/SabPub_Mac_OS_X_Backdoor_Java_Exploits_Targeted_Attacks_and_Possible_APT_link">Read</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bgr.com/2012/04/16/second-mac-trojan-discovered-also-exploits-java-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	<media:thumbnail url="http://www-bgr-com.vimg.net/wp-content/uploads/2012/04/virus-128x128.jpg">http://www-bgr-com.vimg.net/wp-content/uploads/2012/04/virus-128x128.jpg</media:thumbnail>	</item>
		<item>
		<title>Apple releases removal tool for &#8216;Flashback&#8217; malware</title>
		<link>http://www.bgr.com/2012/04/12/apple-releases-removal-tool-for-flashback-malware/</link>
		<comments>http://www.bgr.com/2012/04/12/apple-releases-removal-tool-for-flashback-malware/#comments</comments>
		<pubDate>Thu, 12 Apr 2012 21:45:33 +0000</pubDate>
		<dc:creator>Zach Epstein</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Flashback]]></category>
		<category><![CDATA[Flashback removal tool]]></category>
		<category><![CDATA[Java update]]></category>
		<category><![CDATA[lion]]></category>
		<category><![CDATA[os x]]></category>
		<category><![CDATA[Snow Leopard]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.bgr.com/?p=135551</guid>
		<description><![CDATA[Apple on Thursday released Java update for OS X that removes a number of common variants of the Flashback trojan virus. Discovered last week to have infected more than 600,000 Mac computers, Flashback is a trojan that is capable of intercepting sensitive data and transmitting it back to an attacker. Security experts at F-Secure published instructions on how to manually detect and remove the malware, but Apple&#8217;s new Java update will handle the process automatically. The update, Java for OS X Lion 2012-003, is available for download immediately from within Apple&#8217;s integrated OS X software update utility.]]></description>
			<content:encoded><![CDATA[<center><a href="http://www.bgr.com/2012/04/12/apple-releases-removal-tool-for-falshback-malware"><img class="size-full wp-image-135552 aligncenter" title="os-x-flashback-removal" src="http://www-bgr-com.vimg.net/wp-content/uploads/2012/04/os-x-flashback-removal.jpg" alt="" width="400" height="484" /></a></center>
<p>Apple on Thursday released Java update for OS X that removes a number of common variants of <a href="http://www.bgr.com/2012/04/05/flashback-trojan-virus-found-to-affect-600000-macs/">the Flashback trojan virus</a>. Discovered last week to have infected more than 600,000 Mac computers, Flashback is a trojan that is capable of intercepting sensitive data and transmitting it back to an attacker. Security experts at F-Secure published instructions on how to manually detect and remove the malware, but Apple&#8217;s new Java update will handle the process automatically. The update, Java for OS X Lion 2012-003, is available for download immediately from within Apple&#8217;s integrated OS X software update utility.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bgr.com/2012/04/12/apple-releases-removal-tool-for-flashback-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	<media:thumbnail url="http://www-bgr-com.vimg.net/wp-content/uploads/2012/04/os-x-flashback-removal-128x128.jpg">http://www-bgr-com.vimg.net/wp-content/uploads/2012/04/os-x-flashback-removal-128x128.jpg</media:thumbnail>	</item>
		<item>
		<title>Apple issues new software update to address Mac virus outbreak</title>
		<link>http://www.bgr.com/2012/04/06/apple-issues-new-software-update-to-address-mac-virus-outbreak/</link>
		<comments>http://www.bgr.com/2012/04/06/apple-issues-new-software-update-to-address-mac-virus-outbreak/#comments</comments>
		<pubDate>Fri, 06 Apr 2012 16:10:55 +0000</pubDate>
		<dc:creator>Zach Epstein</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Flashback]]></category>
		<category><![CDATA[Java for OS X 2012-002]]></category>
		<category><![CDATA[Java update]]></category>
		<category><![CDATA[lion]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[os x]]></category>
		<category><![CDATA[OS X 10.7]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[update]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.bgr.com/?p=134768</guid>
		<description><![CDATA[Apple on Friday issued a second software update to address a security flaw on its OS X operating system that has allowed a massive botnet to form. The update, &#8220;Java for OS X 2012-002,&#8221; is only available for desktop and laptop PCs running OS X Lion 10.7; Apple issued a similar update last week for both Lion and Snow Leopard, and the exploit was seemingly addressed properly the first time on the Snow Leopard OS. Russian anti-virus experts revealed earlier this week that the &#8220;Flashback&#8221; trojan virus had utilized a Java vulnerability to infect more than 600,000 Mac computers worldwide. The trojan is capable of intercepting sensitive data such as passwords and other personal information, and transmitting the data back]]></description>
			<content:encoded><![CDATA[<center><a href="http://www.bgr.com/2012/04/06/apple-issues-new-software-update-to-address-mac-virus-outbreak"><img class="size-full wp-image-130746 aligncenter" title="apple-sign-ipad-event" src="http://www-bgr-com.vimg.net/wp-content/uploads/2012/03/apple-sign-ipad-event.jpg" alt="" width="652" height="489" /></a></center>
<p>Apple on Friday issued a second software update to address a security flaw on its OS X operating system that has allowed a massive botnet to form. The update, &#8220;Java for OS X 2012-002,&#8221; is only available for desktop and laptop PCs running OS X Lion 10.7; Apple issued a similar update last week for both Lion and Snow Leopard, and the exploit was seemingly addressed properly the first time on the Snow Leopard OS. Russian anti-virus experts revealed earlier this week that the &#8220;Flashback&#8221; trojan virus had utilized a Java vulnerability to infect more than 600,000 Mac computers worldwide. The trojan is capable of intercepting sensitive data such as passwords and other personal information, and transmitting the data back to a host. A separate firm later <a href="http://www.bgr.com/2012/04/05/flashback-trojan-virus-found-to-affect-600000-macs/">published instructions detailing how to detect and remove the virus</a>, and Apple&#8217;s new update should be the last step in protecting its systems from further attacks. Apple had not yet published details surrounding the new update on its website at the time of this writing.<span id="more-134768"></span></p>
<center><img class="size-full wp-image-134769 aligncenter" title="lion-java-update" src="http://www-bgr-com.vimg.net/wp-content/uploads/2012/04/lion-java-update.png" alt="" width="514" height="623" /></center>
]]></content:encoded>
			<wfw:commentRss>http://www.bgr.com/2012/04/06/apple-issues-new-software-update-to-address-mac-virus-outbreak/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	<media:thumbnail url="http://www-bgr-com.vimg.net/wp-content/uploads/2012/04/lion-java-update-128x128.png">http://www-bgr-com.vimg.net/wp-content/uploads/2012/04/lion-java-update-128x128.png</media:thumbnail>	</item>
		<item>
		<title>&#8216;Flashback&#8217; trojan virus found to affect 600,000 Macs</title>
		<link>http://www.bgr.com/2012/04/05/flashback-trojan-virus-found-to-affect-600000-macs/</link>
		<comments>http://www.bgr.com/2012/04/05/flashback-trojan-virus-found-to-affect-600000-macs/#comments</comments>
		<pubDate>Thu, 05 Apr 2012 11:50:13 +0000</pubDate>
		<dc:creator>Zach Epstein</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Flashback]]></category>
		<category><![CDATA[iMac]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[MacBook]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.bgr.com/?p=134577</guid>
		<description><![CDATA[The idea that Macs don&#8217;t get viruses is now officially a thing of the past. Of course Mac malware has been around for years, but now a massive botnet has been discovered that takes this relatively small issue and makes it a widespread problem. While hackers indeed target Windows PCs far more frequently, a trojan horse virus discovered earlier this year has reportedly now been found to affect more that half a million Mac computers worldwide. Russian anti-virus vendor Dr. Web has discovered that malware called &#8220;BackDoor.Flashback.39&#8243; is currently present on at least 600,000 Macs. The trojan has the capability to use a java vulnerability to intercept passwords and other private data, and then transmit the information back to the]]></description>
			<content:encoded><![CDATA[<center><a href="http://www.bgr.com/2012/04/05/flashback-trojan-virus-found-to-affect-600000-macs"><img class="size-full wp-image-134578 aligncenter" title="apple-logo-sign-virus-mac" src="http://www-bgr-com.vimg.net/wp-content/uploads/2012/04/apple-logo-sign-virus-mac.jpg" alt="" width="652" height="419" /></a></center>
<p>The idea that <em>Macs don&#8217;t get viruses</em> is now officially a thing of the past. Of course Mac malware has been around for years, but now a massive botnet has been discovered that takes this relatively small issue and makes it a widespread problem. While hackers indeed target Windows PCs far more frequently, a trojan horse virus discovered earlier this year has reportedly now been found to affect more that half a million Mac computers worldwide. Russian anti-virus vendor Dr. Web has discovered that malware called &#8220;BackDoor.Flashback.39&#8243; is currently present on at least 600,000 Macs. The trojan has the capability to use a java vulnerability to intercept passwords and other private data, and then transmit the information back to the person or group that deployed it. Apple has since patched the vulnerability, but security experts at F-Secure have published a simple guide to help Mac users determine whether or not they are infected, and then remove any malicious files from their computers that are tied to the Flashback trojan. A link to F-Secure&#8217;s guide can be found below.<span id="more-134577"></span></p>
<p>[Via <a href="http://arstechnica.com/apple/news/2012/04/flashback-trojan-reportedly-controls-half-a-million-macs-and-counting.ars">Ars Technica</a>]</p>
<p><a href="http://news.drweb.com/show/?i=2341">Read</a> [Dr. Web] <a href="http://www.f-secure.com/v-descs/trojan-downloader_osx_flashback_i.shtml">Read</a> [Removal guide]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bgr.com/2012/04/05/flashback-trojan-virus-found-to-affect-600000-macs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	<media:thumbnail url="http://www-bgr-com.vimg.net/wp-content/uploads/2012/04/apple-logo-sign-virus-mac-128x128.jpg">http://www-bgr-com.vimg.net/wp-content/uploads/2012/04/apple-logo-sign-virus-mac-128x128.jpg</media:thumbnail>	</item>
		<item>
		<title>&#8216;Anonymous-OS&#8217; is fake and packed with malware, Anonymous says</title>
		<link>http://www.bgr.com/2012/03/15/anonymous-os-is-fake-and-packed-with-malware-hacker-group-says/</link>
		<comments>http://www.bgr.com/2012/03/15/anonymous-os-is-fake-and-packed-with-malware-hacker-group-says/#comments</comments>
		<pubDate>Thu, 15 Mar 2012 13:10:01 +0000</pubDate>
		<dc:creator>Zach Epstein</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Anonymous]]></category>
		<category><![CDATA[Anonymous-OS]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://www.bgr.com/?p=131864</guid>
		<description><![CDATA[Hacker group &#8220;Anonymous Operations&#8221; has confirmed that the custom Linux-based operating system released under its name earlier this week is not a platform it developed. &#8220;The Anon OS is fake,&#8221; the group posted on Twitter Wednesday evening. &#8220;It is wrapped in trojans.&#8221; The desktop operating system was released earlier this week by individuals claiming ties with Anonymous. It is based on popular Linux distribution Ubuntu, and it ships with a number of hacking tools pre-installed. According to Anonymous, it also ships with a variety of malware. The team behind Anonymous-OS responded to the group&#8217;s claims, denying that its platform contains any malicious software. &#8220;The #anonops on their twitter account say &#8216;That Anonymous-OS is wrapped in trojans,&#8217; &#8221; the group wrote]]></description>
			<content:encoded><![CDATA[<center><a href="http://www.bgr.com/2012/03/15/anonymous-os-is-fake-and-packed-with-malware-hacker-group-says"><img class="size-full wp-image-126677 aligncenter" title="anonymous-ops" src="http://www-bgr-com.vimg.net/wp-content/uploads/2012/02/anonymous-ops.jpeg" alt="" width="652" height="477" /></a></center>
<p>Hacker group &#8220;Anonymous Operations&#8221; has confirmed that the custom Linux-based operating system released under its name earlier this week is not a platform it developed. &#8220;The Anon OS is fake,&#8221; the group <a href="https://twitter.com/#!/anonops/status/180092538395443201">posted on Twitter</a> Wednesday evening. &#8220;It is wrapped in trojans.&#8221; The desktop operating system was <a href="http://www.bgr.com/2012/03/14/anonymous-hacker-group-releases-its-own-desktop-os/">released earlier this week</a> by individuals claiming ties with Anonymous. It is based on popular Linux distribution Ubuntu, and it ships with a number of hacking tools pre-installed. According to Anonymous, it also ships with a variety of malware. The team behind Anonymous-OS responded to the group&#8217;s claims, denying that its platform contains any malicious software. &#8220;The #anonops on their twitter account say &#8216;That Anonymous-OS is wrapped in trojans,&#8217; &#8221; the group <a href="http://anonymous-os.tumblr.com/post/19338333112/anonymosus-os-is-wrapped-in-trojans">wrote on its Tumblr blog</a>. &#8220;Please people&#8230; in our world, in Linux and opensource world, there is not virus. If any user believe that Anonymous-OS &#8216;is wrapped in trojans&#8217; or &#8216;backdoored OS by any Law enforcement Company or Hacker&#8217; please don’t download it! But don’t mislead the world that Linux is dangerous and has trojans!&#8221; Anonymous-OS has been downloaded more than 25,000 times.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.bgr.com/2012/03/15/anonymous-os-is-fake-and-packed-with-malware-hacker-group-says/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	<media:thumbnail url="http://www-bgr-com.vimg.net/wp-content/uploads/2012/03/anonymous-mask-lulzsec-128x128.jpg">http://www-bgr-com.vimg.net/wp-content/uploads/2012/03/anonymous-mask-lulzsec-128x128.jpg</media:thumbnail>	</item>
		<item>
		<title>More than $1 million stolen from Android users in 2011, mobile threats to increase in 2012</title>
		<link>http://www.bgr.com/2011/12/14/more-than-1-million-stolen-from-android-users-in-2011-mobile-threats-to-increase-in-2012/</link>
		<comments>http://www.bgr.com/2011/12/14/more-than-1-million-stolen-from-android-users-in-2011-mobile-threats-to-increase-in-2012/#comments</comments>
		<pubDate>Wed, 14 Dec 2011 15:15:21 +0000</pubDate>
		<dc:creator>Zach Epstein</dc:creator>
				<category><![CDATA[Mobile]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[mobile security]]></category>
		<category><![CDATA[theft]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://www.bgr.com/?p=116399</guid>
		<description><![CDATA[The Carrier IQ scandal has shifted attention from malicious mobile threats to carrier-sourced spyware over the past month, but a new report suggests the threat of more serious mobile malware continues to intensify. More than $1 million was stolen from Android smartphones alone in 2011 according to Lookout Mobile Security, which pulled data from more than a million apps and 15 million handsets around the world to compile its 2012 Mobile Threat Predictions report. The likelihood of an Android user encountering malware grew from 1% to 4% in 2011, and Lookout expects the trend to continue in 2012. Read on for more. &#8220;2011 was a watershed year in terms of the types threats we saw emerging,&#8221; Lookout co-founder and CTO Kevin Mahaffey]]></description>
			<content:encoded><![CDATA[<center><a href="http://www.bgr.com/2011/12/14/more-than-1-million-stolen-from-android-users-in-2011-mobile-threats-to-increase-in-2012"><img class="size-full wp-image-109030 aligncenter" title="BGR-samsung-galaxy-s-ii-t-mobile-1" src="http://www-bgr-com.vimg.net/wp-content/uploads/2011/10/BGR-samsung-galaxy-s-ii-t-mobile-1.jpg" alt="" width="652" height="489" /></a></center>
<p><a href="http://www.bgr.com/2011/12/06/how-to-find-out-if-carrier-iq-is-installed-on-your-phone-in-one-tap/">The Carrier IQ scandal</a> has shifted attention from malicious mobile threats to carrier-sourced spyware over the past month, but a new report suggests the threat of more serious mobile malware continues to intensify. More than $1 million was stolen from Android smartphones alone in 2011 according to Lookout Mobile Security, which pulled data from more than a million apps and 15 million handsets around the world to compile its <em>2012 Mobile Threat Predictions</em> report. The likelihood of an Android user encountering malware grew from 1% to 4% in 2011, and Lookout expects the trend to continue in 2012. Read on for more.<span id="more-116399"></span></p>
<p>&#8220;2011 was a watershed year in terms of the types threats we saw emerging,&#8221; Lookout co-founder and CTO Kevin Mahaffey said in a statement. &#8220;Threats had greater sophistication and were deployed using more innovative and efficient distribution methods. In 2012, we expect to see the mobile malware business turn profitable. What took 15 years on the PC platform has only taken the mobile ecosystem two years.&#8221;</p>
<p>The firm highlights mobile pickpocketing — malware that steals money by making unauthorized use of carrier billing features — mobile botnets and browser attacks as specific threats that will intensify in 2012. Android users in particular now have a 36% chance globally of clicking an unsafe link, and those odds increase to 40% in the U.S. according to Lookout. The firm&#8217;s full press release follows below.</p>
<blockquote><p><strong>Lookout Unveils 2012 Mobile Threat Predictions: Mobile Pickpocketing, Botnets and Automated Repacking Will Be On the Rise</strong></p>
<p><em>More than $1 Million Stolen from Android Users in 2011; Likelihood of Annual Malware Infection Rises to 4%</em></p>
<p>San Francisco &#8211; December 14, 2011 &#8211; Lookout Mobile Security, the global leader in mobile security, today unveiled its 2012 Mobile Malware Predictions, based on data collected from its Mobile Threat Network, which includes more than one million apps and 15 million user devices worldwide. Mobile threats are on the rise &#8211; Lookout estimates that mobile threats successfully stole more than one million dollars from Android users in 2011. In 2012, Lookout predicts that the criminal business of malware will be more profitable than ever before as the possibility of monetizing mobile devices grows and the cost of infecting devices lessens.</p>
<p>In the report, Lookout reveals that the annual likelihood of an Android user encountering malware today has increased to 4% up from a 1% likelihood measured at the beginning of 2011. Web-based mobile threats are also an important component of Lookout&#8217;s research, and the company found Android users worldwide have a 36% chance of clicking on an unsafe link in 2011. In the United States, the likelihood of encountering an unsafe link is higher than the global average at 40%. Additionally in the report, Lookout anticipates the methods that would-be thieves will use to target mobile users directly and discusses tips for consumers to protect themselves.</p>
<p>&#8220;2011 was a watershed year in terms of the types threats we saw emerging. Threats had greater sophistication and were deployed using more innovative and efficient distribution methods,&#8221; said Kevin Mahaffey, co-founder and chief technology officer at Lookout. &#8220;In 2012, we expect to see the mobile malware business turn profitable. What took 15 years on the PC platform has only taken the mobile ecosystem two years.&#8221;</p>
<p>Mobile Malware Monetization Trends</p>
<p>Mobile Pickpocketing (SMS/call fraud). In 2012, Malware writers will continue to steal money directly from consumers by accessing their mobile devices&#8217; ability to charge phone bills via SMS billing and phone calls. Earlier this year, Lookout identified GGTracker, the first mobile malware that steals money from users in the U.S and earlier this week Lookout identified another Android Trojan, RuFraud, targeting Eastern European users.</p>
<p>Botnets. To date, Lookout notes botnet networks have yet to be used at scale. In 2012, Lookout anticipates malware writers could secretly integrate thousands of mobile devices into extensive botnet-like networks to distribute spam, steal private info, and install other malware. DroidDream and Geimini are examples of botnets.</p>
<p>Vulnerable Phones. Due to the difficulty of updating software and patching vulnerabilities on mobile phones, malware writers will continue to exploit iOS and Android OS at a pace greater than vulnerabilities can be resolved.</p>
<p>Mobile Malware Distribution Trends</p>
<p>Automated Repackaging. Malware writers will develop tools that enable the automatic repackaging of malicious applications. Lookout has seen instances where several infected apps were packaged by the same developer within a matter of seconds &#8211; quicker than someone could do manually &#8211; so the means for automated repackaging may already be in existence.</p>
<p>Browser Attacks. As with PC-based threats in the past, malware writers will attempt to profit via Web-based distribution like email, text messages and fraudulent websites. Even iOS devices have been targeted by websites designed to jailbreak them. In 2012, Lookout expects a continued increase in mobile phishing and messages linked to websites that automatically install malware.</p>
<p>Malvertising. Instances of malvertising (genuine-looking advertisements that link back to fraudulent sites) will continue to increase. Given this method has been successful with Trojans like GGTracker, we expect other malware writers to try similar distribution tactics.</p>
<p>For the in-depth predictions, data and accompanying graphics, please see Lookout&#8217;s Mobile Malware Predictions: http://blog.mylookout.com/blog/2011/12/12/2012-mobile-threat-predictions.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.bgr.com/2011/12/14/more-than-1-million-stolen-from-android-users-in-2011-mobile-threats-to-increase-in-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	<media:thumbnail url="http://www-bgr-com.vimg.net/wp-content/uploads/2011/12/samsung-galaxy-s-ii-flat-128x128.jpg">http://www-bgr-com.vimg.net/wp-content/uploads/2011/12/samsung-galaxy-s-ii-flat-128x128.jpg</media:thumbnail>	</item>
		<item>
		<title>Android-targeted malware jumps 76% in Q2, McAfee says</title>
		<link>http://www.bgr.com/2011/08/24/android-targeted-malware-jumps-76-in-q2-mcafee-says/</link>
		<comments>http://www.bgr.com/2011/08/24/android-targeted-malware-jumps-76-in-q2-mcafee-says/#comments</comments>
		<pubDate>Thu, 25 Aug 2011 02:55:10 +0000</pubDate>
		<dc:creator>Todd Haselton</dc:creator>
				<category><![CDATA[Mobile]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[increase]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.bgr.com/?p=101366</guid>
		<description><![CDATA[A new report recently issued by the security firm McAfee suggests that the number of malware applications targeting Android devices jumped 76% during the second quarter of this year, making Android the &#8220;most attacked&#8221; mobile operating system. “This year we’ve seen record-breaking numbers of malware, especially on mobile devices, where the uptick is in direct correlation to popularity,” senior vice president of McAfee labs Vincent Weafer said. Android users typically install the malware accidentally and assume the app is from a safe and legitimate developer. The most prevalent malware-infected modified applications were: Android/Jmsonez.A -  a calendar app that sends SMS texts to a premium rate number. Android/Smsmecap.A &#8211; a fake comedy app that sends SMS texts to everyone in the]]></description>
			<content:encoded><![CDATA[<center><a href="http://www.bgr.com/2011/08/24/android-targeted-malware-jumps-76-in-q2-mcafee-says"><img class="size-full wp-image-101368 aligncenter" title="Screen shot 2011-08-24 at 10.35.43 AM" src="http://www-bgr-com.vimg.net/wp-content/uploads/2011/08/Screen-shot-2011-08-24-at-10.35.43-AM110824144632.png" alt="" width="469" height="390" /></a></center>
<p>A new report recently issued by the security firm McAfee suggests that the number of malware applications targeting Android devices jumped 76% during the second quarter of this year, making Android the &#8220;most attacked&#8221; mobile operating system. “This year we’ve seen record-breaking numbers of malware, especially on        mobile devices, where the uptick is in direct correlation to        popularity,” senior vice president of McAfee labs Vincent Weafer said. Android users typically install the malware accidentally and assume the app is from a safe and legitimate developer. The most prevalent malware-infected modified applications were:</p>
<ul>
<li>Android/Jmsonez.A -  a calendar app that sends SMS texts to a premium rate number.</li>
<li>Android/Smsmecap.A &#8211; a fake comedy app that sends SMS texts to everyone in the user&#8217;s address book.</li>
<li>Android/DroidKungFu &#8211; malware that is capable of installing its own software and updates.</li>
<li>Android/DrdDreamLite &#8211; capable of sending data back to the attacker.</li>
</ul>
<p>McAfee also noted a number of popular Android Trojans that have been making their way through devices. In addition, the company released compelling figures for how much a hacker can sell stolen email addresses for. In the United States, for example, 10,000,000 addresses can be sold to spammers for roughly $300. Read on for McAffee&#8217;s full press release, which includes several data points for PCs, too. <span id="more-101366"></span><strong></strong></p>
<blockquote><p><strong>McAfee Q2 2011 Threats Report Shows Significant Growth for Malware on        Mobile Platforms</strong></p>
<p><em>Report Shows Record Growth for Malware and Rootkits; Major        Hacktivist Activity</em></p>
<p>SANTA CLARA, Calif.&#8211;(BUSINESS WIRE)&#8211;McAfee today released the <em>McAfee        Threats Report: Second Quarter 2011</em>,  showing that the amount of        malware targeted at Android devices  jumped 76 percent since last        quarter, to become the most attacked  mobile operating system. 2011 has        also resulted in the busiest  ever first half-year in malware history,        including a first-ever  appearance of Mac fake AV and a significant        uptick in rootkits,  suggesting that McAfee’s comprehensive malware “zoo”        collection  will reach a record 75 million samples by the year’s end.</p>
<p>“This  year we’ve seen record-breaking numbers of malware, especially on         mobile devices, where the uptick is in direct correlation to         popularity”</p>
<p>“This year we’ve seen record-breaking  numbers of malware, especially on        mobile devices, where the  uptick is in direct correlation to        popularity,” said Vincent  Weafer, senior vice president of McAfee Labs.        “Overall attacks  are becoming more stealth and more sophisticated,        suggesting that  we could see attacks that remain unnoticed for longer        periods of  time. High-profile hacktivist groups have also changed the         landscape by drawing a line between attacks for personal gain and         attacks meant to send a message.”</p>
<p>The report also details  specific activity shaping the way cybercriminals        operate, such as  cybercrime “pricebooks” that determine the going rate        for large  email address lists, and acts of hacktivism and cyberwar.</p>
<p><strong>2011 On Track to Reach Record “Malware Zoo”</strong></p>
<p>With  an approximate 12 million unique samples for the first half of         2011, a 22 percent increase over 2010, this has been the busiest first         half-year in malware history. With the addition of Q2’s numbers,  the        grand total of total malware samples in McAfee’s database has  reached        approximately 65 million, and McAfee researchers  estimate that this        “Malware Zoo” will reach at least 75 million  samples by the year’s end.</p>
<p><strong>Android Nabs Top Spot for Most Mobile Malware</strong></p>
<p>With  the vast amount of personal and business data now found on user’s         mobile phones, mobile malware is steadily increasing, often mimicking         the same code as PC-based threats.<strong> </strong>In the second quarter  of 2011,        Android OS-based malware surpassed Symbian OS for the  most popular        target for mobile malware developers. While Symbian  OS and Java ME        remain the most targeted to date, the rapid rise  in Android malware in        Q2 indicates that the platform could become  an increasing target for        cybercriminals – affecting everything  from calendar apps, to comedy apps        to SMS messages to a fake  Angry Birds updates.</p>
<p><strong>Fake Anti-Virus for Apple, Rootkits and Stealth Malware Reach New        Terrain</strong></p>
<p>There  are more Mac users than ever before, and as organizations         increasingly adopt Macs for business use, Apple now has become more a         target for malware authors. Though historically the Apple platform  has        been unaffected by fake anti-virus (fake AV) software,  activity in Q2        indicates that it is now being affected. Although  this type of fake AV        is the first of its kind, McAfee Labs does  expect fake AV in general        will drop off over time.</p>
<p>Another  malware category that is demonstrating recent steady growth is         stealth malware. The tactic of hiding malware in a rootkit is used by         cybercriminals to make malware stealthier and more persistent, and  has        seen this type of attack gain in prominence over the past  year, with        high-profile attacks such as Stuxnet. Stealth malware  has increased more        rapidly in the last six months than in any  previous period, up almost 38        percent over 2010.</p>
<p><strong>Acts of Hacktivism and Cyberwar Make Their Mark</strong></p>
<p>Acts  of hacktivism, primarily from the groups Anonymous and LulzSec,         were among some of the most prominent cyber news generators for Q2. The         report details hacktivist activity from Q2, with at least 20  global        attacks reported in Q2 alone, and with the majority  allegedly at the        hands of LulzSec. The report also outlines acts  of cyberwar that        occurred in Q2, including attacks on United  States’ Oak Ridge National        Laboratory, and an attack on South  Korea’s National Agricultural        Cooperative Federation.</p>
<p><strong>Email “Black Market” for Spammers</strong></p>
<p>Though  spam is still at historic low levels, due in part to the Rustock         takedown, McAfee Labs still expects to see a sharp rise in activity  over        the coming months. A common method for cybercriminals to  increase their        volume of spam activity is to purchase a bulk list  of emails in order to        flood as much spam as possible to a  widespread group of people. Whether        it’s a botnet or a rental  service, prices vary for such enterprises,        often by location. For  instance, in the United States, the going rate        for 1 million  emails is $25, whereas in England 1.5 million emails are        worth  $100.</p>
<p>For more information on trends related to hacktivism,  cyberwar, web        threats and malware, please download a full copy of  the <em>McAfee        Threats Report: Second Quarter 2011</em> at http://www.mcafee.com/us/resources/reports/rp-quarterly-threat-q2-2011.pdf</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.bgr.com/2011/08/24/android-targeted-malware-jumps-76-in-q2-mcafee-says/feed/</wfw:commentRss>
		<slash:comments>41</slash:comments>
	<media:thumbnail url="http://www-bgr-com.vimg.net/wp-content/uploads/2011/08/Screen-shot-2011-08-24-at-10.35.43-AM110824144632-128x128.png">http://www-bgr-com.vimg.net/wp-content/uploads/2011/08/Screen-shot-2011-08-24-at-10.35.43-AM110824144632-128x128.png</media:thumbnail>	</item>
		<item>
		<title>LulzSec&#8217;s last lulz: Malware for all those who downloaded hackers&#8217; final plunder</title>
		<link>http://www.bgr.com/2011/06/28/lulzsecs-last-lulz-malware-for-all-those-who-downloaded-hackers-final-plunder/</link>
		<comments>http://www.bgr.com/2011/06/28/lulzsecs-last-lulz-malware-for-all-those-who-downloaded-hackers-final-plunder/#comments</comments>
		<pubDate>Tue, 28 Jun 2011 16:30:26 +0000</pubDate>
		<dc:creator>Zach Epstein</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[AT&T]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[CIA]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Lulz Security]]></category>
		<category><![CDATA[LulzSec]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[senate]]></category>
		<category><![CDATA[sony]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.bgr.com/?p=94985</guid>
		<description><![CDATA[The small group of hackers known as Lulz Security, or simply &#8220;LulzSec,&#8221; would never disband without one final round of fun. BGR reported on Monday that the group&#8217;s reign of terror was coming to an end after 50 lul-filled days. During that period of time, LulzSec released data stolen in a series of online breaches with targets ranging from Sony to the U.S. Government. In its coup de grâce, LulzSec released a stash of stolen data from a variety of targets, including AT&#38;T, Disney and the U.S. Navy. But data obtained through online breaches wasn&#8217;t the only thing LulzSec stuffed into the file; a directory named &#8220;BootableUSB&#8221; also contained a variety of malware including trojans and worms. While &#8220;LulzSec&#8221; is]]></description>
			<content:encoded><![CDATA[<center><a href="http://www.bgr.com/2011/06/28/lulzsecs-last-lulz-malware-for-all-those-who-downloaded-hackers-final-plunder"><img class="size-full wp-image-94656 aligncenter" title="lulzsec-hackers" src="http://www-bgr-com.vimg.net/wp-content/uploads/2011/06/lulzsec-hackers110624115314.jpg" alt="" width="652" height="409" /></a></center>
<p>The small group of hackers known as Lulz Security, or simply &#8220;LulzSec,&#8221; would never disband without one final round of fun. BGR reported on Monday that the group&#8217;s reign of terror was <a href="http://www.bgr.com/2011/06/27/lulzsec-says-bon-voyage-after-50-day-hack-fest/">coming to an end after 50 lul-filled days</a>. During that period of time, LulzSec released data stolen in a series of online breaches with targets ranging from <a href="http://www.bgr.com/2011/06/02/sony-pictures-website-hacked-1-million-accounts-compromised/">Sony</a> to the <a href="http://www.bgr.com/2011/06/20/lulzsec-and-anonymous-unite-to-wage-war-on-u-s-government/">U.S. Government</a>. In its coup de grâce, LulzSec released a stash of stolen data from a variety of targets, <a href="http://www.bgr.com/2011/06/27/4g-lte-ipad-already-in-testing-according-to-leaked-att-document/">including AT&amp;T</a>, Disney and the U.S. Navy. But data obtained through online breaches wasn&#8217;t the only thing LulzSec stuffed into the file; a directory named &#8220;BootableUSB&#8221; also contained a variety of malware including trojans and worms. While &#8220;LulzSec&#8221; is no more and its notorious Twitter account now sits dormant, members of the well-known hacktivism group &#8220;Anonymous Operations&#8221; have confirmed that LulzSec is gone in name only — the six LulzSec members have been absorbed by Anonymous, according to the group&#8217;s official Twitter feed.<span id="more-94985"></span></p>
<p><a href="http://allthingsd.com/20110627/laughs-just-keep-on-coming-lulzsecs-final-release-contained-malware/">Read</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bgr.com/2011/06/28/lulzsecs-last-lulz-malware-for-all-those-who-downloaded-hackers-final-plunder/feed/</wfw:commentRss>
		<slash:comments>33</slash:comments>
	<media:thumbnail url="http://www-bgr-com.vimg.net/wp-content/uploads/2011/06/lulzsec-hackers110624115314-80x80.jpg">http://www-bgr-com.vimg.net/wp-content/uploads/2011/06/lulzsec-hackers110624115314-80x80.jpg</media:thumbnail>	</item>
		<item>
		<title>Sophisticated Android trojan discovered in China, warns security firm</title>
		<link>http://www.bgr.com/2010/12/29/sophisticated-android-trojan-discovered-in-china-warns-security-firm/</link>
		<comments>http://www.bgr.com/2010/12/29/sophisticated-android-trojan-discovered-in-china-warns-security-firm/#comments</comments>
		<pubDate>Thu, 30 Dec 2010 02:33:49 +0000</pubDate>
		<dc:creator>Andrew Munchbach</dc:creator>
				<category><![CDATA[Mobile]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[trojan]]></category>

		<guid isPermaLink="false">http://www.bgr.com/?p=70811</guid>
		<description><![CDATA[Firm Lookout Mobile Security is warning of a new, sophisticated, Android-focused piece of malware that has been found in China. The security company warns that the trojan, dubbed Geinimi, can &#8220;compromise a significant amount of personal data on a user’s phone and send it to remote servers.&#8221; The malicious code is, currently, only found in third-party application stores attached to republished versions of legitimate applications. &#8220;Geinimi is the first Android malware in the wild that displays botnet-like capabilities,&#8221; reads the post on the company&#8217;s blog. &#8220;Once the malware is installed on a user’s phone, it has the potential to receive commands from a remote server that allow the owner of that server to control the phone.&#8221; Upon installation, compromised applications containing Geinimi&#8217;s payload will prompt users to grant the]]></description>
			<content:encoded><![CDATA[<center><em><a href="http://blog.mylookout.com/2010/12/geinimi_trojan/"><img class="size-full wp-image-70814 aligncenter" title="school-Trojan-Horse 3" src="http://www-bgr-com.vimg.net/wp-content/uploads/2010/12/school-Trojan-Horse-3.jpg" alt="" width="652" height="455" /></a></em></center>
<p>Firm <em>Lookout Mobile Security</em> is warning of a new, sophisticated, Android-focused piece of malware that has been found in China. The security company warns that the trojan, dubbed <em>Geinimi</em>, can &#8220;compromise a significant amount of personal data on a user’s phone and send it to remote servers.&#8221; The malicious code is, currently, only found in third-party application stores attached to republished versions of legitimate applications.</p>
<p>&#8220;Geinimi is the first Android malware in the wild that displays botnet-like capabilities,&#8221; reads the post on the company&#8217;s blog. &#8220;Once the malware is installed on a user’s phone, it has the potential to receive commands from a remote server that allow the owner of that server to control the phone.&#8221;</p>
<p>Upon installation, compromised applications containing Geinimi&#8217;s payload will prompt users to grant the app far more permissions than the original application. The company notes that the trojan can relay IMEI, IMSI, and location information to remote servers as well as prompt users to install additional applications.</p>
<p>Again, Geinimi is only known to be found on third-party app stores in China, so there is no need to set your personal DEFCON level any lower than 4. All those here in good ol&#8217; North America are safe for the time being, but such is the brave new world of mobile devices.<span id="more-70811"></span></p>
<p>[Via <a href="http://mobilized.allthingsd.com/20101229/mobile-security-firm-warns-of-new-android-trojan/?mod=ATD_rss">Mobilized</a>]</p>
<p><a href="http://blog.mylookout.com/2010/12/geinimi_trojan/">Read</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bgr.com/2010/12/29/sophisticated-android-trojan-discovered-in-china-warns-security-firm/feed/</wfw:commentRss>
		<slash:comments>24</slash:comments>
	<media:thumbnail url="http://www-bgr-com.vimg.net/wp-content/uploads/2010/12/school-Trojan-Horse-3-80x80.jpg">http://www-bgr-com.vimg.net/wp-content/uploads/2010/12/school-Trojan-Horse-3-80x80.jpg</media:thumbnail>	</item>
		<item>
		<title>Energizer Duo USB charger software has trojan on board</title>
		<link>http://www.bgr.com/2010/03/08/energizer-duo-usb-charger-software-has-trojan-on-board/</link>
		<comments>http://www.bgr.com/2010/03/08/energizer-duo-usb-charger-software-has-trojan-on-board/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 16:34:01 +0000</pubDate>
		<dc:creator>Andrew Munchbach</dc:creator>
				<category><![CDATA[Accessories]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[batteries]]></category>
		<category><![CDATA[Energizer]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.bgr.com/?p=45270</guid>
		<description><![CDATA[The Duo seems to have been a failed experiment for battery maker Energizer in more ways than one. Sales of the USB nickle-metal battery charging station never really took off, and now, via a press release, the company has announced the monitoring software distributed with the Duo packs a fairly nasty Windows trojan. The rogue code, according to Computerworld: &#8220;listens for commands on TCP port 7777&#8230; can download and execute files, transmit files stolen from the PC, or tweak the Windows registry. The Trojan automatically executes each time the PC is turned on, and remains active, even if the Energizer charger is not connected to the machine.&#8221; Energizer released a statement saying: &#8220;Energizer is currently working with both CERT and]]></description>
			<content:encoded><![CDATA[<center><a href="http://www.computerworld.com/s/article/9166978/Energizer_Bunny_s_software_infects_PCs"><img class="size-full wp-image-45271 aligncenter" title="Energizer USB DUO" src="http://www-bgr-com.vimg.net/wp-content/uploads/2010/03/energizer-energizer-duo-usb-battery-charger.jpg" alt="Energizer USB DUO" width="400" height="243" /></a></center>
<p>The Duo seems to have been a failed experiment for battery maker Energizer in more ways than one. Sales of the USB nickle-metal battery charging station never really took off, and now, via a <a href="http://phx.corporate-ir.net/phoenix.zhtml?c=124138&amp;p=irol-newsArticle&amp;ID=1399675&amp;highlight=">press release</a>, the company has announced the monitoring software distributed with the Duo packs a fairly nasty Windows trojan. The rogue code, according to Computerworld: &#8220;listens for commands on TCP port 7777&#8230; can download and execute files, transmit files stolen from the PC, or tweak the Windows registry. The Trojan automatically executes each time the PC is turned on, and remains active, even if the Energizer charger is not connected to the machine.&#8221; Energizer released a statement saying: &#8220;Energizer is currently working with both CERT and U.S. government officials to understand how the code was inserted in the software.&#8221; <span id="more-45270"></span></p>
<p><a href="http://www.computerworld.com/s/article/9166978/Energizer_Bunny_s_software_infects_PCs">Read</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bgr.com/2010/03/08/energizer-duo-usb-charger-software-has-trojan-on-board/feed/</wfw:commentRss>
		<slash:comments>38</slash:comments>
	<media:thumbnail url="http://www-bgr-com.vimg.net/wp-content/uploads/2010/03/energizer-energizer-duo-usb-battery-charger-80x80.jpg">http://www-bgr-com.vimg.net/wp-content/uploads/2010/03/energizer-energizer-duo-usb-battery-charger-80x80.jpg</media:thumbnail>	</item>
		<item>
		<title>Apple pulls support page recommending Antivirus software</title>
		<link>http://www.bgr.com/2008/12/03/apple-pulls-support-page-recommending-antivirus-software/</link>
		<comments>http://www.bgr.com/2008/12/03/apple-pulls-support-page-recommending-antivirus-software/#comments</comments>
		<pubDate>Wed, 03 Dec 2008 15:54:38 +0000</pubDate>
		<dc:creator>Zach Epstein</dc:creator>
				<category><![CDATA[Software]]></category>
		<category><![CDATA[Anti-virus]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.bgr.com/?p=10577</guid>
		<description><![CDATA[After a wave of attention surrounding a post on Apple&#8217;s support pages over the past few days, Cupertino has decided to pull the page from its site. The post in question encouraged &#8220;the widespread use of multiple antivirus utilities so that virus programmers have more than one application to circumvent, thus making the whole virus writing process more difficult.&#8221; As Apple&#8217;s OS X has yet to have any significant threats posed against it, the blogosphere questioned both the necessity and integrity of the recommendation, noting that two of the three recommended antivirus applications were available for sale from the Apple Store. Here we are a day or so later and Apple has removed the page from its site, stating: We]]></description>
			<content:encoded><![CDATA[<center><a href="http://news.cnet.com/8301-1009_3-10111958-83.html"><img class="size-full wp-image-10578 aligncenter" style="margin: 4px;" title="appleav-w500" src="http://www-bgr-com.vimg.net/wp-content/uploads/appleav-w500.jpg" alt="" width="500" height="145" /></a></center>
<p>After a wave of attention surrounding <a href="http://www.bgr.com/2008/12/01/apple-begins-recommending-antivirus-utilities-to-users/">a post on Apple&#8217;s support pages</a> over the past few days, Cupertino has decided to pull the page from its site. The post in question encouraged &#8220;the widespread use of multiple antivirus utilities so that virus programmers have more than one application to circumvent, thus making the whole virus writing process more difficult.&#8221; As Apple&#8217;s OS X has yet to have any significant threats posed against it, the blogosphere questioned both the necessity and integrity of the recommendation, noting that two of the three recommended antivirus applications were available for sale from the Apple Store. Here we are a day or so later and Apple has removed the page from its site, stating:</p>
<blockquote><p>We have removed the KnowledgeBase article because it was old and inaccurate. The Mac is designed with built-in technologies that provide protection against malicious software and security threats right out of the box. However, since no system can be 100 percent immune from every threat, running antivirus software may offer additional protection.</p>
</blockquote>
<p>If that&#8217;s the case, then why pull the article? Is Apple now comfortable leaving its computer users vulnerable and open to an attack? Some speculate that Apple removed the note due to poor and confusing wording but if that were the case, surely the company would have merely clarified its position and recommendation rather than removing it completely. Right? Hopefully Apple will further clarify its position over the coming days as for the time being, some might say it looks like the company was looking to make a quick buck from less savvy users. After all, Apple doesn&#8217;t even require the use of antivirus software on its own in-store display units or the internal computers used by store employees.</p>
<p><a href="http://news.cnet.com/8301-1009_3-10111958-83.html">Read</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.bgr.com/2008/12/03/apple-pulls-support-page-recommending-antivirus-software/feed/</wfw:commentRss>
		<slash:comments>19</slash:comments>
	<media:thumbnail url="http://www-bgr-com.vimg.net/wp-content/uploads/appleav-w500-150x145.jpg">http://www-bgr-com.vimg.net/wp-content/uploads/appleav-w500-150x145.jpg</media:thumbnail>	</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Content Delivery Network via Amazon Web Services: CloudFront: www-bgr-com.vimg.net

Served from: www.bgr.com @ 2012-06-01 18:05:17 -->
