VB Blog

VB2019 paper: Fantastic Information and Where to Find it: A guidebook to open-source OT reconnaissance

Posted by   Martijn Grooten on   Nov 22, 2019

A VB2019 paper by FireEye researcher Daniel Kapellmann Zafra explained how open source intelligence (OSINT) can be used to learn crucial details of the inner workings of many a system. Today we publish Daniel's paper and the recording of his presentation.

Read more  

VB2019 paper: Different ways to cook a crab: GandCrab Ransomware-as-a-Service (RaaS) analysed in depth

Posted by   Martijn Grooten on   Nov 21, 2019

Though active for not much longer than a year, GandCrab had been one of the most successful ransomware operations. In a paper presented at VB2019 in London, McAfee researchers John Fokker and Alexandre Mundo looked at the malware code, its evolution and the affiliate scheme behind it. Today we publish both their paper and the recording of their presentation.

Read more  

VB2019 paper: Domestic Kitten: an Iranian surveillance program

Posted by   Martijn Grooten on   Nov 18, 2019

At VB2019 in London, Check Point researchers Aseel Kayal and Lotem Finkelstein presented a paper detailing an Iranian operation they named 'Domestic Kitten' that used Android apps for targeted surveillance. Today we publish their paper and the video of their presentation.

Read more  

VB2019 video: Discretion in APT: recent APT attack on crypto exchange employees

Posted by   Martijn Grooten on   Nov 18, 2019

At VB2019 in London, LINE's HeungSoo Kang explained how cryptocurrency exchanges had been attacked using Firefox zero-days. Today, we publish the video of his presentation.

Read more  

VB2019 paper: DNS on fire

Posted by   Martijn Grooten on   Nov 7, 2019

In a paper presented at VB2019, Cisco Talos researchers Warren Mercer and Paul Rascagneres looked at two recent attacks against DNS infrastructure: DNSpionage and Sea Turtle. Today we publish their paper and the recording of their presentation.

Read more  

German Dridex spam campaign is unfashionably large

Posted by   Martijn Grooten on   Nov 6, 2019

VB has analysed a malicious spam campaign targeting German-speaking users with obfuscated Excel malware that would likely download Dridex but that mostly stood out through its size.

Read more  

Paper: Dexofuzzy: Android malware similarity clustering method using opcode sequence

Posted by   Martijn Grooten on   Nov 5, 2019

We publish a paper by researchers from ESTsecurity in South Korea, who describe a fuzzy hashing algorithm for clustering Android malware datasets.

Read more  

Emotet continues to bypass many email security products

Posted by   Martijn Grooten on   Nov 4, 2019

Having returned from a summer hiatus, Emotet is back targeting inboxes and, as seen in the VBSpam test lab, doing a better job than most other malicious campaigns at bypassing email security products.

Read more  

VB2019 paper: We need to talk - opening a discussion about ethics in infosec

Posted by   Martijn Grooten on   Nov 1, 2019

Those working in the field of infosec are often faced with ethical dilemmas that are impossible to avoid. Today, we publish a VB2019 paper by Kaspersky researcher Ivan Kwiatkowski looking at ethics in infosec as well as the recording of Ivan's presentation.

Read more  

Stalkerware poses particular challenges to anti-virus products

Posted by   Martijn Grooten on   Oct 31, 2019

Malware used in domestic abuse situations is a growing threat, and the standard way for anti-virus products to handle such malware may not be good enough. But that doesn't mean there isn't an important role for anti-virus to play.

Read more  

Search blog

News by email

New twice-monthly email newsletter dedicated to news and technical information about the spam and anti-spam arena launched.
New twice-monthly email newsletter dedicated to news and technical information about the spam and anti-spam arena launched. Last month saw the inaugural issue of a twice-monthly… https://www.virusbulletin.com/blog/2004/12/news-email/

VB2005 call for papers

Virus Bulletin is seeking submissions from those wishing to present at VB2005 in Dublin - so set aside some time between the season's festive parties to get writing!
Virus Bulletin is seeking submissions from those wishing to present at VB2005 in Dublin - so set aside some time between the season's festive parties to get writing! Virus… https://www.virusbulletin.com/blog/2004/12/call-papers/

FBI's virus blunder

Virus infection nearly blew the cover on a secret FBI fraud investigation two years ago.
Virus infection nearly blew the cover on a secret FBI fraud investigation two years ago. It has come to light that a virus infection nearly blew the cover on a secret FBI fraud… https://www.virusbulletin.com/blog/2004/12/fbi-s-virus-blunder/

Spam-reporting trial

Australia's latest anti-spam initiative
Australia's latest anti-spam initiative The Australian Communications Authority (ACA) is teaming up with Internet Service Provider Pacific Internet and software company… https://www.virusbulletin.com/blog/2004/12/spam-reporting-trial/

December

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2004/12/

Australia to protect critical computer systems

Vulnerability assessment for country's critical infrastructure systems
Vulnerability assessment for country's critical infrastructure systems The Australian government is to spend more than 8 million dollars on a project that will identify and fix… https://www.virusbulletin.com/blog/2004/11/australia-protect-critical-computer-systems/

Spam survey

Do women hate spam more than men? Are humans better at identifying spam than computers? Make your contribution to (anti-)spam research...
Do women hate spam more than men? Are humans better at identifying spam than computers? Make your contribution to (anti-)spam research... John Graham-Cumming, author of POPFile… https://www.virusbulletin.com/blog/2004/11/spam-survey/

Lycos turns hippy on spam

'Make love not spam'
'Make love not spam' Lycos Europe has come up with an interesting new way for its users to feel they are getting their own back on spammers. Lycos is encouraging its users to… https://www.virusbulletin.com/blog/2004/11/lycos-turns-hippy-spam/

Standardised malware naming for the new year

An end to the virus-naming problem?
An end to the virus-naming problem? A new initiative that aims to standardise malware naming may be in operation as early as January 2005. The US Department of Homeland… https://www.virusbulletin.com/blog/2004/11/standardised-malware-naming-new-year/

Most spammed

Think you've got it bad? Spare a thought for Bill.
Think you've got it bad? Spare a thought for Bill. Microsoft Chairman Bill Gates is the world's most spammed email recipient. The (let's face it, not entirely surprising) fact… https://www.virusbulletin.com/blog/2004/11/most-spammed/

29A virus writer sentenced

Member of notorious virus-writing group found guilty.
Member of notorious virus-writing group found guilty. A Russian virus writer has been found guilty of creating viruses and fined the somewhat paltry sum of 3,000 roubles. Eugene… https://www.virusbulletin.com/blog/2004/11/29a-virus-writer-sentenced/

Latest VGrep

The latest version of the virus name lookup tool - VGrep, is now available.
The latest version of the virus name lookup tool - VGrep, is now available. VGrep is a system produced in an attempt to clear up some of the confusion surrounding the naming of… https://www.virusbulletin.com/blog/2004/11/latest-vgrep/

November

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2004/11/

Phishy goings on

Fewer than five zombie network operators are responsible for all Internet phishing attacks worldwide according to CipherTrust...
Fewer than five zombie network operators are responsible for all Internet phishing attacks worldwide according to CipherTrust... According to Commtouch Software the US, UK,… https://www.virusbulletin.com/blog/2004/10/phishy-goings/

Storms put the wind up spammers

Significant decline in the volume of spam messages seen in the days immediately following the three recent hurricanes.
Significant decline in the volume of spam messages seen in the days immediately following the three recent hurricanes. Email security firm FrontBridge Technologies Inc. reported… https://www.virusbulletin.com/blog/2004/10/storms-put-wind-spammers/

Spam becomes a collectors' item

British man sets up his own Museum of Spam.
British man sets up his own Museum of Spam. Just in case you hadn't already seen enough spam in your inbox, or in case your spam filter is so efficient that you find yourself… https://www.virusbulletin.com/blog/2004/10/spam-becomes-collectors-item/

November issue released

The Virus Bulletin November issue is on its way.
The Virus Bulletin November issue is on its way. It's that time of the month again... If you are a subscriber to Virus Bulletin, you should be receiving your November issue… https://www.virusbulletin.com/blog/2004/10/november-issue-released/

Dial a detection

Guidance issued on how to deal with rogue Internet diallers ('porn diallers')
Guidance issued on how to deal with rogue Internet diallers ('porn diallers') UK telecoms watchdog the Independent Committee for the Supervision of Standards of Telephone… https://www.virusbulletin.com/blog/2004/10/dial-detection/

Spam gets the sniffles

Spammers seize the opportunity to cash in on the US flu vaccine problem.
Spammers seize the opportunity to cash in on the US flu vaccine problem. Not only has the shortage of flu vaccine been something of a political hot potato in the run up to the US… https://www.virusbulletin.com/blog/2004/10/spam-gets-sniffles/

Trial of virus writer postponed

Sasser author made to wait.
Sasser author made to wait. The trial of self-confessed virus writer Sven Jaschan has been postponed until next year. The 18-year-old, who confessed earlier this year to… https://www.virusbulletin.com/blog/2004/10/trial-virus-writer-postponed/

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.