The post NSA SHALL RELEASE A FORMIDABLE REVERSE ENGINEERING TOOL FOR FREE appeared first on Manny Cuevas.
]]>GHIDRA has been previously mentioned in the CIA Vault 7 documents released by WikiLeaks last 2017. They referred to a “pretty cool” tool called Ghidra, which was developed by NSA.
NSA claimed that GHIDRA is currently compatible for Windows, macOS and Linux. NSA plans to make a full demonstration of the tool at the next RSAC, and shall be released at their repository page at the following link address: https://code.nsa.gov/

The forthcoming tool shall have an interactive GUI capability for easy use. It shall also contain features similar in high-end commercial tools with further functionality.
Some developers expect much more from the GHIDRA tool compared to existing free reverse engineering tools. The global cyber-community expects highly of the said tool from the renowned NSA of the US.
The post NSA SHALL RELEASE A FORMIDABLE REVERSE ENGINEERING TOOL FOR FREE appeared first on Manny Cuevas.
]]>The post GRANDCRAB 5.04 STEALS IMPORTANT FILES BEFORE ENCRYPTION appeared first on Manny Cuevas.
]]>Vidar is a new payload equipped in GrandCrab which lets the authors to steal passwords and forms on web browsers. Additionally, it can be configured to search for particular strings such as payment card numbers and other credentials. The stolen data are compiled into a ZIP archive and sent to the attackers’ C&C server.
Furthermore, Vidar is equipped with a GUI for easy monitoring of victims and stolen data.

After credentials were stolen, GrandCrab now proceeds with the following process:

It should be noted that files encrypted by GrandCrab 5.0.4 are appended with a randomly-generated extension.
This way, by using Vidar, GrandCrab authors can earn by selling the stolen credentials in dark web forums, even if a victim refused to pay the demanded ransom.
As of now, there is no third-party decryption tool yet for victims of GrandCrab 5.0.4 and 5.0.3. However, all earlier versions can be decrypted by the tool developed by Romanian antivirus, Bitdefender. The said decryption tool can be downloaded for free under the following link address:
http://download.bitdefender.com/am/malware_removal/BDGandCrabDecryptTool.exe
The post GRANDCRAB 5.04 STEALS IMPORTANT FILES BEFORE ENCRYPTION appeared first on Manny Cuevas.
]]>The post WINDOWS DEFENDER CAN NOW BE RUN IN SANDBOX MODE appeared first on Manny Cuevas.
]]>This process highly improves the security of Windows, since their built-in antivirus and anti-malware can now be run in its own isolated environment. Running in a sandbox means that a particular application uses a custom-made environment, exclusive only for the application, instead of using the system of Windows. This means that attackers need to penetrate first the sandbox before they can compromise the application. Moreover, the compromised application cannot affect system entities outside the sandbox.
Since the antivirus is one of the primary protection of Windows, and it has the highest levels of privileges to function effectively, it means that it should be protected the most. In the past, several vulnerabilities were reported against Windows Defender, and that it can compromise the entire Windows system. Windows took the challenge and announced earlier that they would make efforts to increase the security of their system through the antivirus.
Trying to run Windows Defender in Sandbox mode is not an easy task for Microsoft Security researchers. Additionally, since it creates an exclusive environment for Windows Defender, it is also resource intensive.
The feature has been launched on Windows 10 with version 1703 or later. However, since the said functionality is still in testing mode, users will have to manually enable the same by doing the following steps:
setx /M MP_FORCE_USE_SANDBOX 1
Users will have to check if the process takes a toll on the system upon enabling the same.
The post WINDOWS DEFENDER CAN NOW BE RUN IN SANDBOX MODE appeared first on Manny Cuevas.
]]>The post VULNERABILITY FOUND IN SIGNAL MESSAGING APP appeared first on Manny Cuevas.
]]>Only in April 2018, a screen lock bypass in Signal app for iOS was discovered which could let anyone bypass the app screen lock within seconds and in a few taps

Signal is an encrypted messaging application for Android and iOS, as well as a desktop version for multiple platforms. It uses the Internet to send one-to-one and group messages, which can include files, voice notes, images and videos, and make one-to-one voice and video calls.
The said vulnerability is a remote code execution vulnerability which is capable of executing JavaScript codes sent through a message.
However, details of the vulnerability are yet to be disclosed publicly. Security researchers worry that the vulnerability might be based from the Electron framework, a framework which Signal and many other apps such as Skype and Wordpress utilize. Hence, a flaw in the Electron framework might also compromise other apps apart from Signal.
Fortunately, the vulnerability has already been fixed in the latest Signal updates.
Despite the vulnerability being fixed immediately by Signal, the details of the vulnerability should be closely monitored to check whether there are other platforms affected by the same.
Signal has been found to contain numerous bugs since the start of 2018, and it is advisable for users to refrain from communicating sensitive information through the said messaging app to prevent unwanted security issues.
The post VULNERABILITY FOUND IN SIGNAL MESSAGING APP appeared first on Manny Cuevas.
]]>The post GRANDCRAB RANSOMWARE V2 IS IMPENETRABLE COMPARED TO ITS FIRST VERSION appeared first on Manny Cuevas.
]]>GrandCrab ransomware is a new ransomware-as-a-service which emerged in the Dark web during early 2018. The GandCrab was advertised in Russian hacking community. Security researchers noticed that the developers leveraged the RIG and GrandSoft exploit kits to distribute the malware.
Some of the advertising points of the GrandCrab ransomware-as-a-service include high percentage of proceeds, technical support, updates, and prohibition to use it against countries in the Commonwealth of Independent States.
This February 2018, security firm Bitdefender, the Romanian Police, and Europol allegedly gained access to the GandCrab Ransomware’s Command & Control servers, which allowed them to recover some of the victim’s decryption keys.
In GrandCrab V2, the hostnames for the ransomware C&C servers are changed to politiaromana.bit, malwarehunterteam.bit, and gdcb.bit, in mockery of the team that led to the breaching of the threat actors’ initial C&C servers.
Apart from the change of hostnames, the GrandCrab ransomware now appends a .CRAB extension to the file name of encrypted files. A ransom note is also included in a notepad file CRAB-Decrypt.txt along with payment instructions.
The following image shows a screenshot of the ransom note:

The payment site at TOR for GrandCrab V2 also had a considerable change in layout and payment procedure.

The security researches who took down the first version of GrandCrab ransomware must not stop at their initial success. They should not let the GrandCrab V2 team be successful with the redesign of the ransomware for it will greatly affect their reputation in terms of global cyber security. The security researchers should again take down the V2 to prove their global competence, and to demonstrate that the malicious attackers cannot prosper against a team of white-hat hackers.
The post GRANDCRAB RANSOMWARE V2 IS IMPENETRABLE COMPARED TO ITS FIRST VERSION appeared first on Manny Cuevas.
]]>The post CRYPTO-MINERS ARE NOW EQUIPPED WITH PROCESS KILLER appeared first on Manny Cuevas.
]]>Since majority of cyber-attackers are now focused on cryptocurrency, every device that has computing power is now a target of malware propagation. Different kinds and methods of cryptocurrency-mining emerged such as smartphone miners, NSA tool-powered miners, and even nuclear facility miners. All these schemes are effective in their own ways, and are gradually making innovations through time.
Recently, it was discovered that newly-engineered crypto-mining malware have the capability to kill processes that consume the computing power of the target system. Included in the code of the crypto-mining malware is a kill list consisting of processes that might hinder the mining process consumption. The list includes some Operating system processes, as well as known processes from other cryptocurrency-miners to ace the competition.
The following is the list of some of the processes included in the kill list:
Although the process-killing capability of the crypto-mining malware will make the miner more effective, the function is quite advantageous to the infected system. Primarily, the malware is easily detectable since it is noticeable that some windows processes are terminated without the user interaction. Second, security researches can utilize the same code used in the malware to develop defensive applications which can auto-kill processes coming from crypto-mining malware.
The post CRYPTO-MINERS ARE NOW EQUIPPED WITH PROCESS KILLER appeared first on Manny Cuevas.
]]>The post $70 MILLION WORTH OF BITCOIN STOLEN IN NICEHASH HACKING INCIDENT appeared first on Manny Cuevas.
]]>Most of the major hacking and breaches concerning Bitcoin happened early this year including CoinDash, Veritaseum and Etherparty. Considering the skyrocketing price of Bitcoin, attackers are now focusing their skills and resources towards such cryptocurrency. Since a successful cryptocurrency hack generates bountiful outcome, services that offer exchange and trade of cryptocurrency became the primary target of cyber-attacks.
NiceHash is a crypto-mining marketplace that connects sellers of hashing power (miners) with buyers of hashing power.
On December 6 2017, NiceHash users have reported that their BTC wallets were emptied. The extent of the attack was not verified by then, but users shared and circulated among affected users a BTC wallet which shows a balance of 4,736 BTC. The following is the screenshot of the Bitcoin address:

CEO Marko Kobal and co-founder Sasa Coh officially announced over a video stream that NiceHash has been hacked. The said cyber-attack resulted in the loss of over 4,700 BTC or an amount equivalent to more than $70 million dollars from Bitcoin wallets of thousands NiceHash user accounts.
NiceHash website has been shut down since the said attack, and displayed the following announcement to its users:

Since the extent and damage of the attack executed was considerably large, and that the BTC amounts were siphoned in a very short span of time, it proves that the attack was properly laid upon and has extensive resources. There might also be an inside job which purposely let the attackers into the NiceHash systems.
NiceHash is recommending its customers to change their passwords—both on NiceHash and other services, if they are using the same credentials.
The post $70 MILLION WORTH OF BITCOIN STOLEN IN NICEHASH HACKING INCIDENT appeared first on Manny Cuevas.
]]>The post A TEAMVIEWER VULNERABILITY LETS THE VIEWER BE VIEWED HIMSELF, OR VICE VERSA appeared first on Manny Cuevas.
]]>TeamViewer is a registered computer software package for remote control, desktop sharing, online meetings, web conferencing and file transfer between computers. TeamViewer is used to let the client share his desktop to another computer, or to a team of computers, as the application name suggests. TeamViewer, however, must be installed in all participating systems in order to function.
Prior to sharing, the client shares a pass-key which must be entered by the viewers to authenticate the connection. After which, by exploiting the TeamViewer vulnerability, the client can, while sharing his desktop to the viewers, in return view the desktop of the viewers themselves without them noticing. Simply, the vulnerability works by “switching sides.”
Otherwise, if such vulnerability is exploited by the viewer after authenticating the connection, the viewer can take control of the keyboard and mouse of the client disregarding current control settings and permissions.
This vulnerability affects versions running on Windows, macOS as well as Linux machines.
In unpatched systems or untrusted clients and servers, participants in TeamViewer sessions should first create a standard local user account which shall be used exclusively to connect to the session and safeguard the computer’s files irrelevant to the session.
As for systems which are under the user’s supervision, it is advised to apply the necessary patches and updates provided by TeamViewer to remedy such vulnerability.
The post A TEAMVIEWER VULNERABILITY LETS THE VIEWER BE VIEWED HIMSELF, OR VICE VERSA appeared first on Manny Cuevas.
]]>The post UBER CONCEALED A MAJOR DATA BREACH appeared first on Manny Cuevas.
]]>Uber Technologies Inc. is a global transportation technology company headquartered in San Francisco, California, United States, operating in 633 cities worldwide. It develops, markets and operates the Uber car transportation and food delivery mobile apps. Uber drivers use their own cars although drivers can rent a car to drive with Uber.
The year 2017 gave a series of setbacks to Uber. Last January 2017. Uber taxi drivers held a protest against the company to lift surge pricing. By March, it was exposed that Uber uses a tool to systematically deceive authorities in cities where Uber was violating local laws. Furthermore, CEO Travis Kalanick resigned by June 2017. This September 2017, Uber lost its London license to operate.
Uber concedes hiding a 2016 major data breach that uncovered the information of 57 million Uber clients and drivers, neglecting to unveil the hack to controllers or influenced people. The organization paid a one hundred thousand USD $100,000 payment to the attackers to devastate the data and keep the rupture calm.
The attackers stole individual information of around 57 million Uber passengers and drivers worldwide including names, email locations and telephone numbers, and also the names and driver’s license of around 600,000 drivers in the United States. The organization said more delicate data, for example, area information, credit card numbers, financial accounts, and birth dates, had not been traded off.
Now Uber CEO Dara Khosrowshahi has reportedly asked for the resignation of Uber Chief Security Officer Joe Sullivan, and one of his deputies, Craig Clark, who collaborated to conceal the attack.
The Uber company shall surely face numerous lawsuits and claims for damages. While this is undeniably true, the affected individuals, who are drivers and passengers must find ways to remedy the breach of their credentials by changing account passwords, Uber app password, and discard of personal accounts if possible.
In addition, the Uber company also says that it is monitoring the affected accounts for fraudulent activity and that riders do not need to take any action against this incident. Despite the company’s assurance, affected individuals must not be complacent and shall secure their exposed credentials themselves.
The post UBER CONCEALED A MAJOR DATA BREACH appeared first on Manny Cuevas.
]]>The post MAILSPLOIT, AN UNDETECTABLE EMAIL SPOOFING IN MAJOR EMAIL CLIENTS appeared first on Manny Cuevas.
]]>Email spoofing is the forgery or imitation of an email header so that the email appears to have originated from someone or somewhere other than the actual source. Email spoofing is a method used in phishing and spam campaigns because people are more likely to open an email when they think it has been sent by a legitimate source. The goal of email spoofing is to get recipients to open, and possibly even respond and provide information to, a solicitation.
A successful variety of a spoofed email can cause serious problems and pose security risks. A spoofed email may disguise to be from a well-known shopping website, asking the recipient to provide sensitive data such as a password or credit card number. Or the spoofed email may ask the recipient to click on a link that installs malware on the recipient’s computing device, similar to how Mailsploit can be utilized.
Security researcher and programmer Sabri Haddouche revealed Mailsploit, a series of methods for spoofing email the have the capacity to exploit more than a dozen common email clients, including Apple Mail, Thunderbird, Microsoft Mail, Outlook 2016, Opera Mail, Airmail, Spark, Guerrilla Mail and Aol Mail. By integrating the bugs in those email clients with twists in how operating systems handle certain kinds of text, Mailsploit may craft email headers that, to the recipient, give every indication of having been sent from whatever address the attacker wishes.
Due to progression in cyber-security, email providers have devised a way to prevent email spoofing by exploiting DMARC. DMARC or Domain-based Message Authentication, Reporting and Conformance blocks spoofed emails by carefully filtering out those whose headers pretend to come from a different source than the server that sent them. Mailsploit made a workaround by modifying email headers to take advantage of flawed implementation of a 25-year-old system for coding ASCII characters in email headers known as RFC-1342.
The trick is encoding non-ASCII characters inside the email headers which could stealthily hide the domain part of the original email.
The following example shows how email headers are crafted:
The payload:
From: =?utf-8?b?${base64_encode(‘[email protected]’)}?==?utf-8?Q?=00?==?utf-8?b?${base64_encode(‘([email protected])’)}[email protected]
Which becomes:
From: =?utf-8?b?cG90dXNAd2hpdGVob3VzZS5nb3Y=?==?utf-8?Q?=00?==?utf-8?b?cG90dXNAd2hpdGVob3VzZS5nb3Y=?=@mailsploit.com
Which, once decoded by Mail.app, becomes:
From: [email protected]\0([email protected])@mailsploit.com
Flaw in client turns it into:
From: [email protected]
Furthermore, these are some of the clients affected by email spoofing:

Besides spoofing, email clients, including Hushmail, Open Mailbox, Spark, and Airmail, are also vulnerable to cross-site scripting (XSS) vulnerabilities.
In using Mailspolit, the potential for phishing schemes is enormous. Taking into account that major email clients and providers are affected, they should create the necessary patches as soon as possible before this effective phishing scheme is utilized by attackers. As for emails, recipients are advised to apply utmost discretion in opening and responding to emails by verifying from the source the legitimacy of the email sent, especially when there are attachments sent and when particular sensitive information are being requested upon.
The post MAILSPLOIT, AN UNDETECTABLE EMAIL SPOOFING IN MAJOR EMAIL CLIENTS appeared first on Manny Cuevas.
]]>