VB Blog

VB2018 paper: Unpacking the packed unpacker: reversing an Android anti-analysis library

Posted by   Martijn Grooten on   Jan 14, 2019

Today, we publish a VB2018 paper by Google researcher Maddie Stone in which she looks at one of the most interesting anti-analysis native libraries in the Android ecosystem. We also release the recording of Maddie's presentation.

Read more  

VB2018 paper: Draw me like one of your French APTs – expanding our descriptive palette for cyber threat actors

Posted by   Martijn Grooten on   Jan 7, 2019

Today, we publish the VB2018 paper by Chronicle researcher Juan Andres Guerrero-Saade, who argues we should change the way we talk about APT actors.

Read more  

Book Review: Cyber Wars

Posted by   Martijn Grooten on   Dec 19, 2018

VB Editor Martijn Grooten reviews Charles Arthur's Cyber Wars, which looks at seven prominent hacks and attacks, and the lessons we can learn from them.

Read more  

VB2018 paper: Office bugs on the rise

Posted by   Martijn Grooten on   Dec 14, 2018

At VB2018 Sophos researcher Gábor Szappanos provided a detailed overview of Office exploit builders, and looked in particular at the widely exploited CVE-2017-0199. Today we publish his paper and release the video of his presentation.

Read more  

VB2018 video: The Big Bang Theory by APT-C-23

Posted by   Martijn Grooten on   Dec 12, 2018

Today, we release the video of the VB2018 presentation by Check Point researcher Aseel Kayal, who connected the various dots relating to campaigns by the APT-C-23 threat group.

Read more  

VB2019 London - join us for the most international threat intelligence conference!

Posted by   Martijn Grooten on   Dec 11, 2018

VB calls on organisations and individuals involved in threat intelligence from around the world to participate in next year's Virus Bulletin conference.

Read more  

VB2018 paper: Tracking Mirai variants

Posted by   Martijn Grooten on   Dec 7, 2018

Today, we publish the VB2018 paper by Qihoo 360 researchers Ya Liu and Hui Wang, on extracting data from variants of the Mirai botnet to classify and track variants.

Read more  

VB2018 paper: Hide'n'Seek: an adaptive peer-to-peer IoT botnet

Posted by   Martijn Grooten on   Dec 6, 2018

2018 has seen an increase in the variety of botnets living on the Internet of Things - such as Hide'N'Seek, which is notable for its use of peer-to-peer for command-and-control communication. Today, we publish the VB2018 paper by Bitdefender researchers Adrian Șendroiu and Vladimir Diaconescu, who studied the Hide'N'Seek IoT botnet. We also release the recording of their presentation.

Read more  

New paper: Botception: botnet distributes script with bot capabilities

Posted by   Martijn Grooten on   Dec 4, 2018

In a new paper, Avast researchers Jan Sirmer and Adolf Streda look at how a spam campaign sent via the Necurs botnet was delivering the Flawed Ammyy RAT. As well as publishing the paper, we have also released the video of the reseachers' VB2018 presentation on the same topic.

Read more  

VB2018 video: Behind the scenes of the SamSam investigation

Posted by   Martijn Grooten on   Nov 29, 2018

Today we have published the video of the VB2018 presentation by Andrew Brandt (Sophos) on the SamSam ransomware, which became hot news following the indictment of its two suspected authors yesterday.

Read more  

Search blog

Ransom attacks hit webmail

Accounts held hostage by data-stealing extortionists.
Accounts held hostage by data-stealing extortionists. Following the wave of 'ransomware' attacks first spotted in the summer of 2005, online extortionists have picked another… https://www.virusbulletin.com/blog/2006/12/ransom-attacks-hit-webmail/

Patch Tuesday leaves Word open to attack

Old and new zero-day vulnerabilities to remain unpatched.
Old and new zero-day vulnerabilities to remain unpatched.Microsoft's monthly Patch Tuesday update release sees seven security patches for Windows operating systems and products,… https://www.virusbulletin.com/blog/2006/12/patch-tuesday-leaves-word-open-attack/

Sophos vulnerabilities found, patched

Fixes issued for archive handling problems.
Fixes issued for archive handling problems. Researchers working with Tipping Point's Zero Day Initiative (ZDI) program have released details of two vulnerabilities in the Sophos… https://www.virusbulletin.com/blog/2006/12/sophos-vulnerabilities-found-patched/

Smartphone security sphere to reach $5 billion by 2011

Market analysts foresee boom in mobile threats and security market.
Market analysts foresee boom in mobile threats and security market. UK-based telecoms analyst Juniper Research has released a report predicting a steady rise in attacks on… https://www.virusbulletin.com/blog/2006/12/smartphone-security-sphere-reach-5-billion-2011/

MIME tricks beat email virus scanners

Simple encoding dodges slip malware past gateways.
Simple encoding dodges slip malware past gateways. A security researcher released a report last week claiming that some simple manipulation allowed him to get mails containing the… https://www.virusbulletin.com/blog/2006/12/mime-tricks-beat-email-virus-scanners/

Anti-spyware activists condemn rogue MP3 search firm

CDT and StopBadware unite in call for action against spyware pushers.
CDT and StopBadware unite in call for action against spyware pushers. The Center for Democracy and Technology (CDT) and StopBadware.org have issued a joint complaint to the Federal… https://www.virusbulletin.com/blog/2006/12/anti-spyware-activists-condemn-rogue-mp3-search-firm/

Adobe hit by second vulnerability

More document software security worries.
More document software security worries. PDF software giant Adobe has released details of its second vulnerability in little over a week. The first, which was discovered in the… https://www.virusbulletin.com/blog/2006/12/adobe-hit-second-vulnerability/

Free firewalls rated best in leak tests

Leakage review puts Comodo, Jetico way ahead of field.
Leakage review puts Comodo, Jetico way ahead of field. An in-depth study subjecting 23 different personal firewall products to a range of leak tests has granted two free products,… https://www.virusbulletin.com/blog/2006/12/free-firewalls-rated-best-leak-tests/

Mobile spam wave hits Europe

Multilingual SMS spams reported.
Multilingual SMS spams reported. Mobile security researchers at F-Secure have received numerous reports of SMS spams from across Europe, in a variety of languages. Links in the… https://www.virusbulletin.com/blog/2006/12/mobile-spam-wave-hits-europe/

Trojan spreading mobile spyware

Consumer phone-snooping tool dropped by Symbian malware.
Consumer phone-snooping tool dropped by Symbian malware. A new variant of the MultiDropper trojan targeting Symbian smartphones has included amongst its payload a 'legitimate'… https://www.virusbulletin.com/blog/2006/12/trojan-spreading-mobile-spyware/

MS Word zero-day exploit seen in wild

Microsoft warns of attacks using vulnerability.
Microsoft warns of attacks using vulnerability.Microsoft has issued a security bulletin warning of a serious vulnerability discovered in several versions of Microsoft Word and… https://www.virusbulletin.com/blog/2006/12/ms-word-zero-day-exploit-seen-wild/

Firm charged $1 million in rogue spyware case

Heavy fines and fees hit fake 'Spyware Cleaner' pushers.
Heavy fines and fees hit fake 'Spyware Cleaner' pushers. A Seattle court has announced a $1 million settlement in a case brought against a spyware firm, marking the first… https://www.virusbulletin.com/blog/2006/12/firm-charged-1-million-rogue-spyware-case/

EU to fund Symantec phishing studies

Security firm in consortium researching phishing prevention.
Security firm in consortium researching phishing prevention.Symantec announced yesterday an award of funding from the European Commission to pay for research into securing email… https://www.virusbulletin.com/blog/2006/12/eu-fund-symantec-phishing-studies/

MySpace hit by worm, adware and phishing

Exploit in QuickTime file infecting social site profile pages.
Exploit in QuickTime file infecting social site profile pages. A malicious QuickTime movie file is spreading across social networking site MySpace, embedding itself in the user… https://www.virusbulletin.com/blog/2006/12/myspace-hit-worm-adware-and-phishing/

Vista launched, malware still a danger

New Windows version on sale, but viruses remain a threat, says Sophos
New Windows version on sale, but viruses remain a threat, says Sophos The corporate version Microsoft's long-awaited update to its Windows operating system was finally released… https://www.virusbulletin.com/blog/2006/12/vista-launched-malware-still-danger/

China source of huge phishing surge

Spam watchers see major jump in scam spam sent from China
Spam watchers see major jump in scam spam sent from China Analysts at email and web security firm Marshal have reported a major spike in the numbers of phishing email originating… https://www.virusbulletin.com/blog/2006/12/china-source-huge-phishing-surge/

December

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2006/12/

December issue of VB published

The December issue of Virus Bulletin is now available for subscribers to download.
The December issue of Virus Bulletin is now available for subscribers to download. The December 2006 issue of Virus Bulletin is now available for subscribers to browse online or… https://www.virusbulletin.com/blog/2006/12/december-issue-vb-published/

Festive greetings

Yuletide wishes.
Yuletide wishes. The VB team wishes all Virus Bulletin readers a very happy Christmas and a prosperous and peaceful new year. This year, continuing the tradition of its Christmas… https://www.virusbulletin.com/blog/2006/12/festive-greetings/

Anti-spammer loses case

Anti-spam activist sued in case that brings enforceability of state anti-spam laws into question.
Anti-spam activist sued in case that brings enforceability of state anti-spam laws into question. An anti-spam activist has successfully been sued in a US federal court by the… https://www.virusbulletin.com/blog/2006/12/anti-spammer-loses-case/

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.