Skip to content

針對 Android 和 iOS 加密貨幣錢包的惡意軟件

加密錢包木馬化 在寫這篇文章的時候,比特幣的價格(38,114.80 美元)已經從大約 4 個月前的歷史最高點下降了約 44%。對於加密貨幣投資者來說,這可能是一個時機,要麼驚慌失措,撤回資金;要麼抓住機會,以較低的價格購買。如果您屬於這些群組,請仔細挑選使用哪個流動應用程式來管理您的資金。 從 2021 年 5 月開始,我們的研究發現了幾十個「木馬化」的加密貨幣錢包應用程式。這些惡意應用程式能夠通過冒充 Coinbase、imToken、MetaMask、Trust Wallet、Bitpie、TokenPocket 或 OneKey 竊取受害者的資料。到目前為止,這種攻擊主要針對中國用戶,但隨著加密貨幣越來越受歡迎,我們預計這些攻擊將蔓延到其他地區。 iOS 和 Android 上的行為差異 在 Android 系統上,主要針對那些尚未在其裝置上安裝合法錢包應用程式的新用戶。木馬錢包的軟件名稱與合法應用程式相同,但是,它們使用不同的證書進行簽名,這意味著,如果官方錢包已經安裝到 Android 系統上,惡意應用程式無法覆蓋它,因為用於簽署假冒應用程式的密鑰與合法應用程式不同。這是 Android 應用的標準安全模式,非正版應用的版本不能取代正版。 而在 iOS 上,受害者則可以同時安裝兩個版本 —— 來自 App Store 的合法版本和來自網站的惡意版本 —— 因為它們不是共享同一個帳號。 預防和刪除方法 ESET 研究人員經常建議用戶只從官方來源下載和安裝應用程式,如 Google Play 或 App Store。一套可靠的防毒軟件應該能夠檢測到 Android 裝置上的這種威脅。至於 iOS ,基於操作系統的特性,在沒有越獄的情況下,用戶只允許從官方應用商店下載應用程式,因此避免越獄,是最可取的預防建議。 如果有問題的應用程式已安裝到您的裝置,可根據系統執行相關的刪除步驟。在 Android 系統上,無論您從哪個來源下載惡意應用程式,如果對來源的合法性存有疑問,我們建議刪除該應用程式。iOS 方面,刪除惡意應用程式後,也有必要通過進入設定 → 一般 → VPN 與裝置管理來刪除其配置文件。 ESET 協助輕鬆打造安全無虞的企業網絡安全 專為企業防護設計,與本地端解決方案不同,雲端版將主機放置在 ESET 維護的雲端環境中執行 ,用戶端可依照用戶需求靈活運用及搭配,節省大量資源及成本。版本内結合了端點、伺服器, 利用遠程集中管理方式,為企業資訊安全提供便利又多重的保障。 ESET PROTECT Complete 組合包括:
  • 端點防護 – ESET Endpoint Solutions
  • 檔案伺服器 – ESET File Security
  • 流動裝置防護 – ESET Mobile Solutions
  • 雲端中央控制台 – Cloud Console
  • 全硬碟加密 – Full Disk Encryption
  • 動態威脅防禦 – Dynamic Threat Defense
  • 雲端辦公室安全 – Cloud Office Security
  • 郵件安全 – Mail Security
了解更多 https://www.eset.com/hk/business/complete-protection-bundle/

About Version 2

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products. Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布裏斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。

Mac Patching Best Practices

As vulnerabilities and threats become more sophisticated, having a reliable and automated Mac patch management solution for your organization’s devices is essential. This is important if you are using a lot of custom applications that may be hard to update. 

Continue reading

Safetica NXT, next-gen SaaS DLP, brings extremely fast time-to-protection of data

Safetica, the data security company with more than ten years of experience in developing the easiest to implement enterprise Data Loss Prevention*, enhances its next-gen SaaS DLP with easy management and the fastest implementation. Now any company with a hybrid workplace can deploy Safetica NXT with a single click and begin to protect their data in a matter of hours.

Implementation of legacy DLP (Data Loss Prevention) solutions used to be highly costly and inefficient projects with unclear outcomes. Safetica directly addresses this by continuously improving its SaaS product to turn this situation around for good.

Safetica NXT the next-gen SaaS (Software as a Service) DLPnow provides truly easy-to-use data protection enhanced with automation and built-in templates. It’s continuing Safetica’s tradition of best practices in data security for SMB and small enterprises.

Developed to run and reside natively in the secured cloud, deploying Safetica NXT is possible in minutes. No in-house hardware infrastructure is needed.

Once Safetica Clients have been remotely installed on Windows or macOS devices, it takes as little as one day to complete setup and configuration (with the help of our new product guide). Then you can immediately audit data flow, classify sensitive data and begin protecting it.


According to our most recent experience with Safetica NXT deployment, it takes, on average, just ten days to collect all necessary information from a customer’s environment, evaluate it and produce the first report, including a sensitive data-flow audit and incident overview,  

says David Klíma, Product Manager, Safetica.  

When you have an overview of your data security posture, you can efficiently detect insider threats and risks, prevent data leaks, and audit incidents right away, adds David Klíma.

Effective data protection requires fast implementation, the least amount of time to administer, and the ability to respond to detected incidents rapidly. Safetica’s years of DLP experience and focus on easy implementation and use have been acknowledged by SoftwareReviews. In 2021/2022, Safetica was recognized as an industry Champion and Gold medalist in the DPL marketplace.

 

 

Safetica has been developing a risk-driven SaaS solution with a focus on simplicity and automation. Straightforward settings and a pre-configured environment help to free up admins’ hands. Smart auto-detection of risk, continuous auto-definition of the company’s safe digital workspace, and auto-generated security reports further support low-maintenance operations. So Safetica NXT only takes a couple of hours per week to manage.

Based on the constant analysis of sensitive data flow, Safetica NXT evaluates the risk level of each operation and every protected user. Holistic risk classification is presented in a simple format of low to high-risk indicators to help managers focus only on events that require fast response.



The admin can always decide which category of high-risk events should be automatically blocked or which situations warrant notifying users about a potential risk and letting them proceed with logging the event.

This is especially beneficial for hybrid workspaces with remote workers and employees working from home. Furthermore, smart scanning dynamically recognizes when an employee is used to working, regardless of normal business hours, to ensure more accurate risk evaluation and incident detection.


Implementation projects and administration of traditional DLP solutions have a terrible reputation. That’s why we decided to transform ours into a service that keeps sensitive data from falling into the wrong hands by detecting security risks and preventing incidents from day one, says Zbynek Sopuch, CTO of Safetica.


Availability  

Monthly and annual per-user subscriptions to Safetica NXT are available immediately through Safetica channel partners. The free web trial is open to any interested party via www.safetica.com.

Subscriptions include cloud-native management with easy-to-set sensitive data detection and protection rules and easy-to-read reports and logs for incidents investigation, plus Safetica Client installed on endpoint devices (Windows and macOS).

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Safetica
Safetica is to provide small and mid-sized companies with the same quality data protection that corporations have – affordably, and without any additional IT administration or disruptions in operation.

×

Hello!

Click one of our contacts below to chat on WhatsApp

×