Overview of Modern Computer Threats | Total Security Software
Modern viruses are not as scary as their predecessors. Improved protection mechanisms of operating systems often do not allow them to do the same chaos as before (for example, formatting the hard drive). Viruses and fraudulent attacks are now mainly aimed at obtaining financial gain or controlling the user's computer, but not at destroying data. At the same time, to perform the listed tasks, a virus is not always required, often a correctly composed letter or SMS is enough for its recipient to send credit card information or other confidential information to attackers.
Most anti-virus signatures contain several million records about various viruses, but no more than 10 different types of attacks constitute a serious threat.
Ways to get into the computer
First, let's dwell on the very mechanism of the attack.
When it comes to phishing or social engineering, messages usually come via chat on social networks, email, or forums. In some cases, cybercriminals can post them with a link to their resource directly in the comments of other people's sites. If the moderators did not manage to delete them in time, then some users will follow the link and fall for the bait of scammers.
When hackers try to install a virus on someone's computer, in most cases they need the user to personally launch the program. To convince the PC owner to do this, the virus is usually passed off as some kind of useful software. For example, a critical update for Windows, an antivirus, a codec required to view a video on a website, etc. Viruses are also distributed in crackers and key generators, but the danger of these files is somewhat exaggerated. The activation of antivirus protection when they are launched does not always mean that they are really infected, since antiviruses can react in this way to their main purpose - changing the code of other programs to hack them. On the other hand, with this behaviour of antiviruses, the user can never be completely sure of the harmlessness of utilities of this kind,
The most widespread virus for a long time is Conficker and its modifications, which occupy several places in the TOP 10 threats at once, including the first one. They are distributed using the Autorun function, which launches the executable file specified in the Autorun. inf file when an external drive is connected to the computer. Conficker copies itself to the system, and then to other flash drives and hard drives connected to the PC. Most often, the virus itself is used to organize botnet networks. It is likely due to its outbreak that Microsoft recently disabled Autorun in Windows XP / Vista with an update released in early February this year. In Windows 7, autorun is disabled by default.
Why cybercriminals need information about users and access to their computer
There are only two main goals. They are achieved in different ways, but scammers are interested in either receiving money from (the amounts can vary widely) or using the computer or its owner's accounts to send spam.
Control over someone else's PC allows you to create botnets, which sometimes include hundreds of thousands of computers. Such virtual armies are formed to send spam or DDOS attacks to websites. Users are often unaware that someone else is controlling their PC.
General recommendations for protection
Be sure to install an antivirus (free AVG, avast !, Avira, Comodo, protegent360, or Microsoft Security Essentials will suffice). Add firewall protection if desired.
Please update your browser to the latest version.
Do not run unfamiliar programs without antivirus or total security software with disabled protection.
Do not agree to install the accompanying software offered by the site if you are not 100% sure of its need.
Check the resource name before entering data on it.
To pay on the Internet, it is better to issue an additional card and transfer money to it from the main card before making purchases.
Most common attacks
Locking your computer
A very widespread and at the same time rather unpleasant attack is an attack in which cybercriminals block a computer, demanding to send an SMS to receive an unlock code. Moreover, the owner of the PC is not always told how much money will be withdrawn from the account. As we managed to find out, at least in some cases we are talking about tens of hryvnias.
Such viruses most often get on the PC of inexperienced users who install programs (for example, video codecs) on it, which are offered when visiting fraudulent sites.
How to fight
There are several different scenarios worth trying depending on how locked your computer is.
If the virus has not yet been added to the databases, the codes should be searched on the Internet by yourself using a phone number or message. The main thing, in this case, is not to fall for another trap of scammers and not to pick up another virus, which is presented as a utility for fighting blockers.
If you manage to start the Task Manager, you need to find the virus in the list of processes and terminate it. The program most likely has some common name, such as plugin.exe, which attackers choose to disguise their application as a system process. After that, you need to remove it from the startup. To do this, you can use the standard msconfig.exe utility (to start it, click the "Start" button and enter MSConfig in the search field). The Startup tab lists programs launched from the Startup folder, as well as through registry keys. You should uncheck the box next to the virus so that it no longer boots when you turn on the PC. After that, it is advisable to check the computer with an antivirus to completely remove the malicious program from the system and make sure that no other copies of it are left on the PC.
When Task Manager is not available, you need to restart your computer into Safe Mode (to do this, press the F8 key a few seconds before the Windows logo appears on a black screen), and then repeat the same procedures with MSConfig and antivirus. To download the latter, you need an active Internet connection, so you must select Safe Mode with Networking.
If for some reason you cannot use Safe Mode, boot your PC using the Live-CD with antivirus. In this case, you need another working computer where you can burn the disc. Some antiviruses are also written to a USB flash drive, so both a netbook and a laptop without an optical drive are suitable as a spare PC.
Unfortunately, if all the above steps did not help or are not available, you will have to reinstall the OS. It is important to perform a clean installation of the system, not update it - if you do this over an old copy, the virus will not go anywhere.
Account hijacking
The next common nuisance for users is account hijacking. In most cases, they are not even blocked, and a person can work on the site without noticing any changes, but at the same time, other people will receive advertising messages on his behalf. This threat is especially relevant for social networks, although the virus can send spam to instant messaging services (ICQ, Skype, etc.).
Fraudsters already benefit from the fact of using someone else's computer, therefore, in this case, they do not require monetary compensation from its owner.
How to fight
If you were informed that spam is being sent on your behalf, you should check your computer with an antivirus with fresh databases, and then change the password for your account.
Phishing
Scammers often try to get a bigger catch using phishing techniques. In many cases, the user is required to follow a link to a fake site and enter their credentials there, which are then used to send spam. However, sometimes it is not their account that they try to steal from the user, but their credit card information.
As a rule, a letter comes to the mailbox with a message about the hacking of the site's protection system. To secure your account, you supposedly need to change your password, for which you are invited to go to the link to a fake resource, which outwardly is a complete copy of the original. The domain name usually differs by just one letter, and this is not immediately apparent (for example, facedook.com instead of facebook.com). The user registers and receives a message about the successful password change, and sometimes an inscription stating that technical work is being carried out on the service and the attempt should be repeated later. In fact, the credentials have already been sent to the hackers' computer. In cases where the user is required to enter information about his credit card, accordingly, the fraudsters receive its number and the cvv2 code.
Sometimes accounts from popular online games are also stolen to sell the hero or the contents of the inventory.
How to fight
First of all, you need to check the domain name of the site to which you are prompted to go in the letter. It's important to pay attention to the second-level domain (the one to the left of .com). For example, the address checkpass.visa.com is directly related to the Visa website, but the address visa.checkpass.com already has a second-level domain name check pass, and this resource belongs to completely different people.
In some cases, the sender's email address will help you quickly figure it out. If the letter is allegedly sent on behalf of one company, and the specified address does not correspond to this at all (for example, a message from Facebook comes from the @ yahoo.com mailbox), then the message can be safely ignored.
Ransomware viruses can do other things besides blocking your computer.
Here are some common examples:
the program threatens to delete all files from the PC if the money is not transferred to a certain mobile account within a few hours;
the user is warned that Windows has not passed the license check, and to register it, it is necessary to receive a code via SMS;
a porn banner pops up on the computer, which can only be removed using SMS;
access to a specific site is blocked, for example, "VKontakte", and a requirement is made to send an SMS to unblock;
the user is warned that the online antivirus has detected a dangerous threat on the PC. The virus is temporarily blocked (along with the computer), but to permanently remove it, a licensed version of the antivirus is required, which can be obtained by sending an SMS;
the virus encrypts the user's files (most often office documents) and offers to return access to them only after entering the code received via SMS.
This is one of the most dangerous attacks since it is almost impossible to deal with its consequences. For example, the G-Code virus uses a 1024-bit RSA key for encryption, and it will not be possible to recover files without "financial assistance" provided to the attacker. Decryption would require several million computers working over the course of a year to find the right key. The only loophole that can solve the problem is that certain modifications of such viruses create a copy of the file before encrypting it, which is then deleted. Under certain conditions, there is a chance for its successful recovery.
You should also look not at the link in the text of the letter (anything can be written there), but at where it really leads. This information is displayed in the status bar of the browser when you hover over the link. If abbreviated links are used in the message, then this is an additional signal that they want to hide the real address.
This type of threat has become increasingly rare lately, since one has to use e-mail or social networks to distribute letters, and spam filters in these services do a good job with such correspondence. For example, Gmail, in addition to automatically posting such messages in spam, also adds red text to the body of the message, warning that it is most likely phishing or spam. Also, all links in the text are blocked.
When clicking on links to frequently visited sites, also pay attention to requests for authorization. If you are sure that you have recently entered your username and password here, and you are asked to do this again, check the address in the browser bar. There is a possibility that you went to a fake resource using an incorrect link. For example, a common phishing attack is a message like "Is that you in the photo?" with a link to a fake site (for example, vkontavkte.ru). Having opened an incorrect link to an album with photos, the user is taken to a copy of the site, where his name and password will be stolen from him after an authorization attempt.
Keyloggers
To obtain information about your credit card, attackers can use keyloggers that read the pressed keys and send this information to scammers. Keyloggers are practically impossible to detect without antivirus since they do not manifest themselves in any way.
How to fight
In order not to catch such a virus, it is advisable not to install programs offered by unknown sites. It is also recommended to have an antivirus and firewall if possible. Here the firewall will be able to help out even if the antivirus is not installed since the keylogger needs to send the collected data to the remote computer. At this moment, the firewall will block it, and you will be able to determine the presence of a virus.
To avoid intercepting the keys that are pressed, when entering credit card information, a virtual numeric keypad is often used, in which the numbers are located in different places each time. If possible, you should always use it instead of the physical one.
Viruses can also hijack accounts by reading keystrokes. LastPass will help prevent such cases (since recently this add-on is available for all popular browsers). It can automatically insert a username and password into the site, as well as fill out forms and even enter credit card information. Since the physical keyboard is not involved in this, keyloggers will not be able to recognize the keys pressed. LastPass can generate complex passwords and store them in its database, so you don't have to remember them. Finally, LastPass cannot be spoofed with a fake URL, and the plugin will never enter user information on a fake site.
Social engineering
A special type of attacks that do not require the use of technical means. Simply put, instead of searching for vulnerabilities and writing viruses, attackers by letters or conversations push users to take a certain action that will disable computer protection or in some other way open access to the necessary information.
Lying money from mobile phone users
In the arsenal of ill-wishers, there are the following tricks:
using social engineering, scammers ask to transfer money to a specific account. For this, the SMS is composed in such a way that it seems as if it was sent by one of the relatives. In some cases, attackers also push the victim to make a call to the mobile number, and then try to drag out the time longer, since a special fee is charged for the conversation at a higher rate;
the program "SMS-spy" is proposed, supposedly able to determine the location of a person by his mobile phone number. To use the service, subscribers are naturally advised to register via SMS. After that, the user receives a link to a site with publicly available information about the belonging of a particular code to a particular telecom operator or to interactive map services (Google Maps or Yandex. Maps). Formally, such actions are not even a crime, since somewhere on the site information is indicated about what services will be provided to the user;
for a small fee, a program is offered that supposedly can read SMS on any phone after entering the number you need;
an SMS comes with a description of a little-known way to replenish an account without financial costs, for which you need to send a message to the number.
Little known attacks
In addition to common types of attacks, there are also little-known ones that are also worth knowing about, since the lack of preparation of users is the key to the success of hackers.
Smishing (SMS phishing) is the mobile version of phishing. A message with a link to a fake site comes via SMS. By launching the resource in a mobile browser, the user opens the path for the virus to the device.
Bluebugging is a special technique for gaining access to a phone via Bluetooth. At the same time, its owner does not receive any notification that a wireless connection has been established with his device. An attacker can view received calls, address book, read messages, call and send SMS, and delete data.
If the user somehow guessed that he was a victim of blue bugging, then getting rid of the scammer is quite simple: just turn off the phone, turn off Bluetooth, or go to another place (the Bluetooth range is only 10 meters).
Sidejacking - getting access to accounts by session ID. Most often, a special link with a large number of characters is used as an ID, which allows you to open a site without authorization. In some cases, a long character set in cookies is also used instead. If the attacker finds out the session ID, he will be able to access the user's sites without authorization and, for example, read his mail.

Comments
Post a Comment