Latest news
In response to the recent discovery of the Flashfake botnet, Kaspersky Lab has announced the availability of its free Flashfake Removal Tool.

Visit the safe verification site to determine if you’re infected.
If your UUID is found in the database, you need to disinfect your Mac. You can use the Kaspersky Flashfake Removal Tool. It will automatically scan your system and remove Flashback if it is detected.
Details
Kaspersky Lab’s experts recently analyzed the Flashfake botnet and found a total of 670,000 infected computers worldwide, with more than 98% of the computers most likely running Mac OS X. It is anticipated that the other 2% of machines running the Flashfake bot are very likely to be Macs as well.
This is the largest Mac-based infection to date, with the largest number of victims targeting developed countries. The United States had the most infected computers (300,917) followed by Canada (94,625), the United Kingdom (47,109) and Australia (41,600). Other infected countries included France (7,891), Italy (6,585), Mexico (5,747), Spain (4,304), Germany (4,021) and Japan (3,864).
On 6 April Kaspersky Lab’s researchers reverse-engineered the Flashfake malware and registered several domain names which could be used by criminals as a Command & Control (C&C) server for managing the botnet. This method enabled them to analyse the communications between infected computers and the C&Cs. By connecting to Flashfake, Kaspersky Lab’s experts are able to continuously monitor the botnet’s communication with active bots and have published their findings here.
Throughout the Bank Holiday weekend Kaspersky Lab experts saw a decline in the number of active bots: on 6 April the total number was 650,748. At the end of 8 April, the number of active bots was 237,103. However, the rapid decrease in infected bots does not mean the botnet is shrinking at the same rate.
The statistics represent the number of active bots connected to Flashfake over the weekend - it is not the equivalent of the exact number of infected machines. Infected computers that were inactive over the weekend would not have communicated with Flashfake, thus they would not have appeared as an infected bot.
Flashfake is a family of OS X malware that first appeared in September 2011. Previous variants of the malware relied on cyber criminals using social engineering techniques to trick users into downloading the malicious program and installing it in their systems.
However, this latest version of Flashfake does not require any user-interaction and is installed via a “drive-by download,” which occurs when victims unwittingly visit infected websites, allowing the Trojan to be downloaded directly onto their computers through the Java vulnerabilities. Although Oracle issued a patch for this vulnerability three months ago, Apple delayed in sending a security update to its customer base until 2 April. Users who have not updated their systems with the latest security should install and update immediately to avoid infection.


Spotlight

Cyber espionage campaign uses professionally-made malware
Posted on 20 May 2013. | A massive cyber espionage campaign has been hitting government ministries, IT companies, academic research institutions, and more.

Ransomware adds password stealing to its arsenal
Posted on 17 May 2013. | Microsoft researchers are warning about a new variant of the well-known Reveton ransomware doing rounds.

Application vulnerabilities still a top security concern
Posted on 16 May 2013. | Respondents to a new (ISC)2 study identified application vulnerabilities as their top security concern. A significant gap persists between software developers’ priorities and security professionals’ concerns.

IT security jobs: What's in demand and how to meet it
Posted on 15 May 2013. | Let's say you want a career in information security, where do you start? What credentials do you need? What are employers looking for? Read on to find some answers.

Hacking charge stations for electric cars
Posted on 15 May 2013. | Ofer Shezaf talks about what charge stations really are, why they have to be ‘smart’ and the potential risks created to the grid, to the car and most importantly to its owner’s privacy and safety.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.






