VB Blog

VB2019 paper: Defeating APT10 compiler-level obfuscations

Posted by   Virus Bulletin on   Mar 13, 2020

At VB2019 in London, Carbon Black researcher Takahiro Haruyama presented a paper on defeating compiler-level obfuscations used by the APT10 group. Today we publish both Takahiro's paper and the recording of his presentation.

Read more  

VB2019 paper: Attribution is in the object: using RTF object dimensions to track APT phishing weaponizers

Posted by   Virus Bulletin on   Mar 12, 2020

At VB2019 in London Michael Raggi (Proofpoint) and Ghareeb Saad (Anomali) presented a paper on the 'Royal Road' exploit builder (or weaponizer) and how the properties of RTF files can be used to track weaponizers and their users. Today we publish both their paper and the recording of their presentation.

Read more  

VB2019 presentation: Nexus between OT and IT threat intelligence

Posted by   Virus Bulletin on   Mar 11, 2020

Operational technology, the mission critical IT in ICS, shares many similarities with traditional IT systems, but also some crucial differences. During the Threat Intelligence Practitioners’ Summit at VB2019, Dragos cyber threat intelligence analyst Selena Larson gave a keynote on these similarities and differences. Today we release the recording of her presentation.

Read more  

VB2019 paper: Kimsuky group: tracking the king of the spear-phishing

Posted by   Virus Bulletin on   Mar 10, 2020

In a paper presented at VB2019 in London, researchers fron the Financial Security Institute detailed the tools and activities used by the APT group 'Kimsuky', some of which they were able to analyse through OpSec failures by the group. Today, we publish their paper.

Read more  

VB2019 paper: Play fuzzing machine - hunting iOS and macOS kernel vulnerabilities automatically and smartly

Posted by   Virus Bulletin on   Mar 9, 2020

In a paper presented at VB2019 in London, Trend Micro researchers Lilang Wu and Moony Li explained how the hunt for vulnerabilities in MacOS and iOS operating systems can be made both smarter and more automatic. Today we publish both their paper and the recording of their presentation.

Read more  

VB2019 paper: Finding drive-by rookies using an automated active observation platform

Posted by   Virus Bulletin on   Mar 6, 2020

In a last-minute paper presented at VB2019 in London, Rintaro Koike (NTT Security) and Yosuke Chubachi (Active Defense Institute, Ltd) discussed the platform they have built to automatically detect and analyse exploit kits. Today we publish the recording of their presentation.

Read more  

VB2019 paper: Pulling the PKPLUG: the adversary playbook for the long-standing espionage activity of a Chinese nation state adversary

Posted by   Virus Bulletin on   Feb 28, 2020

The activities of China-based threat actor PKPLUG were detailed in a VB2019 paper by Palo Alto Networks researcher Alex Hinchliffe, who described the playbook of this long-standing adversary. Today we publish both Alex's paper and the recording of his presentation.

Read more  

VB2019 paper: Static analysis methods for detection of Microsoft Office exploits

Posted by   Virus Bulletin on   Feb 25, 2020

Today we publish the VB2019 paper and presentation by McAfee researcher Chintan Shah in which he described static analysis methods for the detection of Microsoft Office exploits.

Read more  

New paper: LokiBot: dissecting the C&C panel deployments

Posted by   Helen Martin on   Feb 17, 2020

First advertised as an information stealer and keylogger when it appeared in underground forums in 2015, LokiBot has added various capabilities over the years and has affected many users worldwide. In a new paper researcher Aditya Sood analyses the URL structure of the LokiBot C&C panels and how they have evolved over time.

Read more  

VB2019 presentation: Building secure sharing systems that treat humans as features not bugs

Posted by   Helen Martin on   Feb 14, 2020

In a presentation at VB2019 in London, Virtru's Andrea Limbago described how, by exploring data sharing challenges through a socio-technical lens, it is possible to make significant gains toward the secure sharing systems and processes that are vital for innovation and collaboration. Today we release the recording of her presentation.

Read more  

Search blog

New exploits emerge in wake of Patch Tuesday

Security update release cycle leads to attack release cycle.
Security update release cycle leads to attack release cycle. With the monthly 'Patch Tuesday' issue of security updates over, the now customary revelations of further… https://www.virusbulletin.com/blog/2007/04/new-exploits-emerge-wake-patch-tuesday/

Major seeding of Storm trojans seen

Latest wave of variants followed up by further fake warnings.
Latest wave of variants followed up by further fake warnings. Yet another wave of malware has been widely spammed out, using similar tactics to previous attacks evolving from the… https://www.virusbulletin.com/blog/2007/04/major-seeding-storm-trojans-seen/

Spam-fighters coalition formed

ICSA announces cooperative forum of anti-spam developers.
ICSA announces cooperative forum of anti-spam developers.CyberTrust-owned ICSA Labs has announced the formation of the Anti-Spam Product Developers' Consortium, a grouping of… https://www.virusbulletin.com/blog/2007/04/spam-fighters-coalition-formed/

Microsoft reveals more issues on Patch Tuesday

Fix for earlier .ani patch and another Vista issue included in batch.
Fix for earlier .ani patch and another Vista issue included in batch. Five out of six vulnerabilities patched by Microsoft yesterday, in April's 'Patch Tuesday' monthly security… https://www.virusbulletin.com/blog/2007/04/microsoft-reveals-more-issues-patch-tuesday/

Linux/iPod proof-of-concept sighted

New minority platform joins infectable list.
New minority platform joins infectable list. Virus analysts have reported receiving samples of a proof-of-concept virus for the iPodLinux operating system, a port of the… https://www.virusbulletin.com/blog/2007/04/linux-ipod-proof-concept-sighted/

UK ISP association issues spam guidelines

ISPA best practices document advises providers on spam control.
ISPA best practices document advises providers on spam control. The UK Internet Services Providers' Association (ISPA), a voluntary grouping of service providers and other Internet… https://www.virusbulletin.com/blog/2007/04/uk-isp-association-issues-spam-guidelines/

Kaspersky patches series of vulnerabilities

ActiveX and overflow issues allowed remote data theft, local system attacks.
ActiveX and overflow issues allowed remote data theft, local system attacks. Several vulnerabilities have been revealed in many Kaspersky security products, including ActiveX flaws… https://www.virusbulletin.com/blog/2007/04/kaspersky-patches-series-vulnerabilities/

Swiss spam law to enforce user security

New law may penalise careless zombie hosts.
New law may penalise careless zombie hosts. New anti-spam laws come into effect in Switzerland on Sunday, imposing strict curbs on spamming and strong punishment for perpetrators.… https://www.virusbulletin.com/blog/2007/04/swiss-spam-law-enforce-user-security/

Spam costing US companies over $70 billion per year

Survey finds junk email costs $713 per head in loss of productivity.
Survey finds junk email costs $713 per head in loss of productivity. A study into the impact of spam on US businesses has produced some startling figures for the financial impact… https://www.virusbulletin.com/blog/2007/04/spam-costing-us-companies-over-70-billion-year/

NASA hacker loses case against extradition

UK man should face trial in States despite threats, say judges.
UK man should face trial in States despite threats, say judges. Greg McKinnon, the British hacker accused of breaking into NASA and US military networks while apparently… https://www.virusbulletin.com/blog/2007/04/nasa-hacker-loses-case-against-extradition/

Animated cursor flaw patched out of cycle

Microsoft reacts fast to widespread zero-day exploitation.
Microsoft reacts fast to widespread zero-day exploitation.Microsoft have once again broken their monthly patching cycle to release a fix for a vulnerability which has been the… https://www.virusbulletin.com/blog/2007/04/animated-cursor-flaw-patched-out-cycle/

April issue of VB published

The April issue of Virus Bulletin is now available for subscribers to download.
The April issue of Virus Bulletin is now available for subscribers to download. The April 2007 issue of Virus Bulletin is now available for subscribers to browse online or… https://www.virusbulletin.com/blog/2007/04/april-issue-vb-published/

VB2007 conference programme revealed

VB has revealed the conference programme for VB2007, Vienna.
VB has revealed the conference programme for VB2007, Vienna. VB has revealed the conference programme for VB2007, Vienna. Once again, the three-day conference programme boasts… https://www.virusbulletin.com/blog/2007/04/conference-programme-revealed/

Scammers launch anti-terrorist hotline

Met Police website spoofed by 419 scammers.
Met Police website spoofed by 419 scammers. Last month saw the appearance of the latest 419 scamming trick: 'anti-terrorist certificates' sold via a fake version of the London… https://www.virusbulletin.com/blog/2007/04/scammers-launch-anti-terrorist-hotline/

Phishing attacks reach new high

APWG releases phishing figures for January.
APWG releases phishing figures for January. Phishing attacks and password-stealing applications both reached record levels in January 2007 according to the latest report from the… https://www.virusbulletin.com/blog/2007/04/phishing-attacks-reach-new-high/

Third round for US anti-spyware bill

Anti-spyware legislation presented in US House of Representatives for third time.
Anti-spyware legislation presented in US House of Representatives for third time. Anti-spyware legislation was presented for the third time in the US House of Representatives last… https://www.virusbulletin.com/blog/2007/04/third-round-us-anti-spyware-bill/

April

Anti-virus and security related news provided by independent anti-virus advisors, Virus Bulletin
https://www.virusbulletin.com/blog/2007/04/

MySpace latest to sue spammer Wallace

Social site takes on notorious junk mail merchant.
Social site takes on notorious junk mail merchant. Serial spammer Sanford 'Spamford' Wallace faces yet another lawsuit, this time from hugely popular social networking site… https://www.virusbulletin.com/blog/2007/03/myspace-latest-sue-spammer-wallace/

TJX hack thought biggest ever

Over 45 million card numbers gathered in massive breach.
Over 45 million card numbers gathered in massive breach. A report into a security breach at major US retailer TJX has revealed a lengthy and sophisticated attack which scooped vast… https://www.virusbulletin.com/blog/2007/03/tjx-hack-thought-biggest-ever/

Fujacks writer's removal tool slated

Virus creator's anti-virus not up to scratch, says Symantec.
Virus creator's anti-virus not up to scratch, says Symantec. A cleanup tool created by the writer of the Fujacks virus, also known as the 'Panda burning incense' virus in reference… https://www.virusbulletin.com/blog/2007/03/fujacks-writer-s-removal-tool-slated/

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.