VB Blog

VB2018 paper: Fake News, Inc.

Posted by   Helen Martin on   Apr 25, 2019

A former reporter by profession, Andrew Brandt's curiosity was piqued when he came across what appeared at first glance to be the website of a small-town newspaper based in Illinois, but under scrutiny, things didn’t add up. At VB2018 he presented a paper in which he shared the results of his investigation of the site. Today, we publish his paper and the recording of his presentation.

Read more  

Paper: Alternative communication channel over NTP

Posted by   Martijn Grooten on   Apr 24, 2019

In a new paper published today, independent researcher Nikolaos Tsapakis writes about the possibilities of malware using NTP as a covert communication channel and how to stop this.

Read more  

VB2019 conference programme announced

Posted by   Martijn Grooten on   Apr 5, 2019

VB is excited to reveal the details of an interesting and diverse programme for VB2019, the 29th Virus Bulletin International Conference, which takes place 2-4 October in London, UK.

Read more  

VB2018 paper: Under the hood - the automotive challenge

Posted by   Martijn Grooten on   Mar 27, 2019

Car hacking has become a hot subject in recent years, and at VB2018 in Montreal, Argus Cyber Security's Inbar Raz presented a paper that provides an introduction to the subject, looking at the complex problem, examples of car hacks, and the challenges ahead. Today, we publish both Inbar's paper and the recording of his presentation.

Read more  

VB2018 paper and video: Android app deobfuscation using static-dynamic cooperation

Posted by   Martijn Grooten on   Mar 20, 2019

Static analysis and dynamic analysis each have their shortcomings as methods for analysing potentially malicious files. Today, we publish a VB2018 paper by Check Point researchers Yoni Moses and Yaniv Mordekhay, in which they describe a method that combines static and dynamic analysis to defeat app obfuscation in Android binaries. We also publish the video of their presentation.

Read more  

VB2019 call for papers closes this weekend

Posted by   Martijn Grooten on   Mar 15, 2019

The call for papers for VB2019 closes on 17 March, and while we've already received many great submissions, we still want more!

Read more  

Registration open for VB2019 ─ book your ticket now!

Posted by   Martijn Grooten on   Mar 13, 2019

Registration for VB2019, the 29th Virus Bulletin International Conference, is now open, with an early bird rate available until 1 July.

Read more  

The VB2019 call for papers is about ... papers

Posted by   Martijn Grooten on   Mar 8, 2019

When we are calling for papers for the Virus Bulletin conference as we are doing now, we really mean a written paper. But don't worry if you've never written a paper - we can help!

Read more  

VB2018 video: Adware is just malware with a legal department - how we reverse engineered OSX/Pirrit, received legal threats, and survived

Posted by   Martijn Grooten on   Mar 8, 2019

Amit Serper first analysed the OSX/Pirrit adware in 2016, highlighting some of its malware-like techniques, and soon afterwards started receiving legal threats from the company behind it. At VB2018 Amit gave a presentation in which he discussed both the adware and the legal threats he received for calling it malware. Today, we publish the video of Amit's presentation.

Read more  

VB2018 paper: Anatomy of an attack: detecting and defeating CRASHOVERRIDE

Posted by   Martijn Grooten on   Mar 5, 2019

In December 2016, the CRASHOVERRIDE malware framework was used to cause a blackout in Ukraine. At VB2018 in Montreal, Dragos researcher Joe Slowik presented a detailed paper on the framework, explaining how the malware works and how it targets various protocols used to operate the electric grid. Today we publish both Joe's paper and the recording of his presentation.

Read more  

Search blog

Throwback Thursday: KAOS on the Superhighway?

This Throwback Thursday, we turn the clock back to 1994, when KAOS4 was discovered on the Internet.
This Throwback Thursday, we turn the clock back to 1994, when KAOS4 was discovered on the Internet. A new virus has been found on the Internet — today, this is an unfortunate fact… https://www.virusbulletin.com/blog/2015/06/throwback-thursday-kaos-superhighway/

Paper: Using .NET GUIDs to help hunt for malware

Tool to extract identifiers incorporated into VirusTotal.
Tool to extract identifiers incorporated into VirusTotal. The large number of new malware samples found each day hasn't made malware analysis an easier task, and researchers could… https://www.virusbulletin.com/blog/2015/06/paper-using-net-guids-help-hunt-malware/

Steganoprague: a VB2015 competition & puzzle

Use your obfuscation and deobfuscation skills to win a prize during the VB2015 conference!
Use your obfuscation and deobfuscation skills to win a prize during the VB2015 conference! "It is time for defenders to go on the offence," wrote Andreas Lindh in Virus Bulletin… https://www.virusbulletin.com/blog/2015/06/steganoprague-competition-amp-puzzle/

NSA, GCHQ found to target anti-virus products

Agencies looked for vulnerabilities to exploit and for submitted malware samples.
Agencies looked for vulnerabilities to exploit and for submitted malware samples. New documents from NSA whistle-blower Edward Snowden have revealed the agency and its British… https://www.virusbulletin.com/blog/2015/06/nsa-gchq-found-target-anti-virus-products/

Paper: Beta exploit pack: one more piece of crimeware for the infection road!

Exploit kit currently being tested focuses primarily on Flash Player exploits.
Exploit kit currently being tested focuses primarily on Flash Player exploits. Nuclear, Angler, Magnitude and Rig. Security researchers know we're talking about exploit kits (or… https://www.virusbulletin.com/blog/2015/06/paper-beta-exploit-pack-one-more-piece-crimeware-infection-road/

Throwback Thursday: Macro Viruses & The Little Virus That Could...

This Throwback Thursday, we turn the clock back to 1999, when Melissa was causing havoc across the globe and VB presented a series of articles detailing all you ever wanted to know about macro viruses but were afraid to ask.
This Throwback Thursday, we turn the clock back to 1999, when Melissa was causing havoc across the globe and VB presented a series of articles detailing all you ever wanted to know… https://www.virusbulletin.com/blog/2015/06/throwback-thursday-macro-viruses-amp-little-virus-could/

Virus Bulletin announces 'Small Talks' for VB2015

Smaller, more informal format ideal for discussion and debate.
Smaller, more informal format ideal for discussion and debate. When, a few months ago, we announced the programme for VB2015, we promised 'a number of added extras'. We have… https://www.virusbulletin.com/blog/2015/06/announces-small-talks/

Throwback Thursday: Virus Writers

This Throwback Thursday, we bring you a series of articles from the archives that looked at virus writers, asking 'who are they?', 'why do they do it?', and other pertinent questions.
This Throwback Thursday, we bring you a series of articles from the archives that looked at virus writers, asking 'who are they?', 'why do they do it?', and other pertinent… https://www.virusbulletin.com/blog/2015/06/throwback-thursday-virus-writers/

Vawtrak uses Tor2Web to connect to Tor hidden C&C servers

Option hides the servers, without having to include a Tor client in the malware.
Option hides the servers, without having to include a Tor client in the malware. The authors of the Vawtrak trojan (also known as Neverquest) have moved some of its C&C servers to… https://www.virusbulletin.com/blog/2015/06/vawtrak-uses-tor2web-connect-tor-hidden-c-amp-c-servers/

Duqu 2.0 found to target security company

Advanced malware also targeted venues linked to Iranian nuclear negotiations.
Advanced malware also targeted venues linked to Iranian nuclear negotiations. There are some security stories you couldn't make up. The authors of an advanced malware tool have… https://www.virusbulletin.com/blog/2015/06/duqu-2-0-found-target-security-company/

June

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2015/06/

London calling!

Infosecurity Europe, BSides London and the Security Bloggers Meetup.
Infosecurity Europe, BSides London and the Security Bloggers Meetup. June is the new April, at least for the security industry, as its traditional get-together in London… https://www.virusbulletin.com/blog/2015/05/london-calling/

Paper: On the beat

Kevin Williams looks back at UK law enforcement successes at combating cybercrime.
Kevin Williams looks back at UK law enforcement successes at combating cybercrime. In a recent Throwback Thursday article, we looked back at the sentencing of self-confessed virus… https://www.virusbulletin.com/blog/2015/05/paper-beat/

Throwback Thursday: Research and Other Hobbies

This Throwback Thursday we reflect on the life of one of industry's greats, who sadly passed away this week: Prof. Klaus Brunnstein.
This Throwback Thursday we reflect on the life of one of industry's greats, who sadly passed away this week: Prof. Klaus Brunnstein. Professor Klaus Brunnstein was one of the… https://www.virusbulletin.com/blog/2015/05/throwback-thursday-research-and-other-hobbies/

Weak keys and prime reuse make Diffie-Hellman implementations vulnerable

'Logjam' attack possibly used by the NSA to decrypt VPN traffic.
'Logjam' attack possibly used by the NSA to decrypt VPN traffic. A group of researchers have discovered a number of vulnerabilities in the way the Diffie-Hellman key exchange… https://www.virusbulletin.com/blog/2015/05/weak-keys-and-prime-reuse-make-diffie-hellman-implementations-vulnerable/

Virus Bulletin announces student tickets for VB2015

87% discount for students and the option to give a lightning talk.
87% discount for students and the option to give a lightning talk. A few weeks ago, we opened registration for VB2015, which will take place in Prague from 30 September to 2… https://www.virusbulletin.com/blog/2015/05/announces-student-tickets/

Throwback Thursday: Double Trouble / The Perfect Couple

Once again this Throwback Thursday, we bring you not one but two (related) pieces from the archives as VB heads back to the mid-90s when a new era of viruses was believed to be dawning.
Once again this Throwback Thursday, we bring you not one but two (related) pieces from the archives as VB heads back to the mid-90s when a new era of viruses was believed to be… https://www.virusbulletin.com/blog/2015/05/throwback-thursday-double-trouble-perfect-couple/

Book review: The Florentine Deception, by Carey Nachenberg

John Hawes reviews Carey Nachenberg's debut novel.
John Hawes reviews Carey Nachenberg's debut novel. There's a rather serious problem with fiction involving computers, and computer security in particular. It seems like any time a… https://www.virusbulletin.com/blog/2015/05/book-review-florentine-deception-carey-nachenberg/

Book review: Data and Goliath, by Bruce Schneier

Paul Baccas reviews Data and Goliath 'The Hidden Battles to Collect You Data and Control Your World', by Bruce Schneier.
Paul Baccas reviews Data and Goliath 'The Hidden Battles to Collect You Data and Control Your World', by Bruce Schneier. This book has been difficult to review. It has proved… https://www.virusbulletin.com/blog/2015/05/book-review-data-and-goliath-bruce-schneier/

Throwback Thursday: When Love came to Town

Once again this Throwback Thursday, we bring you not one but two (related) pieces from the archives as VB heads back to 2000 in the week of the 15th anniversary of the LoveLetter virus.
Once again this Throwback Thursday, we bring you not one but two (related) pieces from the archives as VB heads back to 2000 in the week of the 15th anniversary of the LoveLetter… https://www.virusbulletin.com/blog/2015/05/throwback-thursday-when-love-came-town/

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.