Newsletters
News & Information for Technology Purchasers NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
Home Enterprise I.T. Cloud & Virtualization Applications Unified Communications More Topics...
Commvault Simpana® 10
Protect, manage, access, and
realize the untapped value of data.

www.commvault.com
Mobile Tech
Introducing Simpana® 10 software
Average Rating:
Rate this article:  
Phony Java Patch Pushes Malware
Phony Java Patch Pushes Malware

By Jennifer LeClaire
January 18, 2013 10:46AM

    Bookmark and Share
"Updates, patches and hot-fixes should always come directly from the vendor," said analyst Richard S. Westmoreland of the fake Java patch. "Companies should remind their employees to wait for instructions from their management and IT administrators and not try to 'solve' their own computer problems in ways that have not already been authorized."
 



With all the Java security problems, it's hardly surprising that malware authors would move to take advantage of the whirlwind. Ironically, a new ransomware campaign is targeting consumers looking to download the latest Java patch to keep their systems safe.

Trend Micro has warned of malware that poses as Java Update 11, created by an unknown publisher. According to Trend Micro, the fake update in question is javaupdate21.jar and it downloads and executes malicious files.

"Once executed, this backdoor connects to a remote Relevant Products/Services server Relevant Products/Services that enables a possible attacker to take control of the infected system," Paul Pajares, a fraud analyst at Trend Micro, wrote in the company's Security Intelligence Blog.

"Though the dropped malware does not exploit CVE-2012-3174 or any Java-related vulnerability, the bad guys behind this threat are clearly piggybacking on the Java zero-day incident and users' fears. The use of fake software Relevant Products/Services updates is an old social engineering tactic."

Not a New Trick

Pajares noted that this is not the first time that cybercriminals took advantage of software updates. Last year, we reported about malware disguised as Yahoo Messenger, which Trend Micro found in time for Yahoo's announcement of its update for Messenger.

"During our analysis, this ransomware locks users' screen and attempts to access specific sites to display its notification to users," Pajares said. "However, the malware we analyzed failed to download the said notification, thus the user is possibly left with a blank page."

Richard S. Westmoreland, Level III security analyst and team leader at Perimeter E-Security, told us social engineering is still the most successful way of breaching systems.

"Updates, patches and hot-fixes should always come directly from the vendor," Westmoreland said. "Companies should remind their employees to wait for instructions from their management Relevant Products/Services and IT administrators and not try to 'solve' their own computer problems in ways that have not already been authorized."

Malware Is Big Business

Alex Horan of CORE Security said that if you ever wanted proof that malware is an active business, look how quickly the malware providers respond to events.

"They leverage trending events -- like Hurricane Sandy, relief drives, elections -- to increase the likelihood of a victim interacting with their malware and exposing themselves to risk," Horan told us.

"'Trust but verify' should be the maxim for dealing with any messages or requests you receive. Even if it makes perfect sense for the IT department to be warning you of the Java exploit and sending you a link to download the patch, you should still call and verify it is truly an e-mail from them and not from an attacker."
 

Tell Us What You Think
Comment:

Name:

Paul:

Posted: 2013-01-23 @ 8:01pm PT
Very informative. Thank you for letting people know Java has no update, info on a fix is a fraud.

Spade:

Posted: 2013-01-19 @ 3:38pm PT
This again?!
What does Malware even want with us?! I see no reason for them to attack us!
WHAT THE HECK DID WE- THE USERS- EVEN DO?

Here I am, a day after gettind Java Version 7 Update 11 and hear THIS.
YEA, WE'RE PRETTY DARN DOOMED FOR NO REASON.
STUPID MALWARE.



CommVault is a data and information management software company dedicated to providing organizations worldwide with a radically better way to manage data and information. Their unique Solving Forward philosophy allows them to deliver complete solutions with infinite scalability and unprecedented control over data and costs. Be among the first to experience Simpana 10 software. Click here now.


 Mobile Tech
1.   iPhone Takes a Hit in Satisfaction
2.   Qualcomm Eyes Smartphone Growth
3.   Recharge Your Phone in 20 Seconds?
4.   Samsung Dangles $800,000 App Carrot
5.   MeeGo-Based Sailfish OS Launches


advertisement
Mandatory BYOD Is Catching OnMandatory BYOD Is Catching On
Will be required by many within 4 years.
Average Rating:
Thorsten Heins Predicts Tablet DemiseThorsten Heins Predicts Tablet Demise
BlackBerry PlayBook may color his view?
Average Rating:
Google Glass Raises Privacy ConcernsGoogle Glass Raises Privacy Concerns
House privacy panel wants answers.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Enterprise Hardware Spotlight
Dell Kills Its Public Cloud Effort, Will Offer Partner Marketplace
Putting the kibosh on its efforts to build out a public cloud, Dell has announced a new program to offer a choice of cloud Infrastructure-as-a-Service through a central marketplace of partners.
 
Dell's Dismal Quarter Shows PC Maker's Challenges
Dell's financial decay worsened during its latest quarter as the company slashed its personal computer prices in response to the growing popularity of smartphones and tablets in the beleaguered industry.
 
U.S. Defense Department Gives iOS 6 Security OK
In a vote of confidence for Apple's iOS devices, the Defense Department has given the all-clear for employees to use iPads and iPhones for work. But only those running iOS 6, and only if issued by the government.
 

Mobile Enterprise Spotlight
Consumer Satisfaction for iPhone Drops as Rivals Gain
Apple's iPhone has taken a favorability hit in the latest American Consumer Satisfaction Index, an annual survey of 70,000 consumers, while Samsung and Motorola put in strong gains.
 
Qualcomm CEO Eyes Smartphone Growth
With more than 6 billion mobile phones on the planet and population growth jumping in many corners of the world, Qualcomm CEO Paul Jacobs is sharing his thoughts on the future of the devices we love.
 
Teen Shows Battery-Charge Breakthrough at Intel Fair
Imagine being able to recharge your phone's battery in just seconds. If an invention recognized in Intel's International Science and Engineering Fair reaches the mass market, it could soon be possible.
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Cloud & Virtualization | Applications | Unified Communications | Mobile Tech | Hardware | Business Intelligence
World Wide Web | Network Security | Data Storage | Small Business | Microsoft/Windows | Apple/Mac | Linux/Open Source | Personal Tech
Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2013 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.