Skip to content

ESET發現了Linux版的SideWalk後門程式

駭客組織SparklingGoblin自2021年2月針對香港一所大學下手,並植入Linux後門程式,國際資安大廠ESET進一步調查後發現,此後門程式是名為SideWalk的Windows惡意軟體改造而成,且與騰訊旗下的360網路安全實驗室於2020年9月發現的Spectre RAT有關。而SparklingGoblin主要針對東亞和東南亞,且特別關注學術領域。

ESET研究人員表示,Linux版SideWalk與Windows版有許多共通的特性,例如,都使用ChaCha20演算法,具備5個同步執行的處理程序等。

原文出處:https://www.welivesecurity.com/2022/09/14/you-never-walk-alone-sidewalk-backdoor-linux-variant/

關於Version 2

Version 2 Digital 是立足亞洲的增值代理商及IT開發者。公司在網絡安全、雲端、數據保護、終端設備、基礎設施、系統監控、存儲、網絡管理、商業生產力和通信產品等各個領域代理發展各種 IT 產品。透過公司龐大的網絡、通路、銷售點、分銷商及合作夥伴,Version 2 提供廣被市場讚賞的產品及服務。Version 2 的銷售網絡包括台灣、香港、澳門、中國大陸、新加坡、馬來西亞等各亞太地區,客戶來自各行各業,包括全球 1000 大跨國企業、上市公司、公用事業、醫療、金融、教育機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟件提供商,其獲獎產品 — NOD32防病毒軟件系統,能夠針對各種已知或未知病毒、間諜軟件 (spyware)、rootkits和其他惡意軟件為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲得了更多的Virus Bulletin 100獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布裏斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事處,代理機構覆蓋全球超過100個國家。

ESET Threat Report T2 2022: RDP attacks see further drop; ransomware loses war-related messaging

  • Following a sharp decline observed in T1 2022, the total number of RDP attack attempts declined by a further 89%; the likely reasons for the decline are post-COVID return to offices, improved security, and the Russia-Ukraine war.
  • Politically motivated ransomware declined; operators turned their attention from Russia back to their usual targets such as the United States, China, and Israel.
  • Emotet continued to be active, with detections seen mainly in Japan and Italy; according to ESET telemetry, its operators took time off in August.
  • ESET phishing feeds showed a sixfold increase in shipping-themed phishing URLs, with the most commonly impersonated brands being USPS and DHL.
  • Web skimmer known as Magecart constituted three-fourths of all banking malware detections, leaving far behind the rest of the malware strains in the category.
  • Cryptocurrency threats went down along with the price of bitcoin; however, the previously declining category of Cryptostealers grew by almost 50%.

BRATISLAVA — October 5, 2022 — ESET released today its T2 2022 Threat Report, summarizing key statistics from ESET detection systems, and highlighting notable examples of ESET’s cybersecurity research. The latest issue of the ESET Threat Report (covering May to August 2022) sheds light on the changes in ideologically motivated ransomware, Emotet activity, the most-used phishing lures, how the plummeting cryptocurrency exchange rates affected online threats, and the continuation of the sharp decline of Remote Desktop Protocol (RDP) attacks. ESET analysts think these attacks continued to lose their steam due to the Russia-Ukraine war, along with the post-COVID return to offices and overall improved security of corporate environments.

Even with declining numbers, Russian IP addresses continued to be responsible for the largest portion of RDP attacks. “In T1 2022, Russia was also the country that was most targeted by ransomware, with some of the attacks being politically or ideologically motivated by the war. However, ESET Threat Report T2 2022 shows that this hacktivism wave has declined in T2, and ransomware operators turned their attention towards the United States, China, and Israel,” explains Roman Kováč, Chief Research Officer at ESET.

According to ESET telemetry, August was a vacation month for the operators of Emotet, the most influential downloader strain. The gang behind it also adapted to Microsoft’s decision to disable VBA macros in documents originating from the internet and focused on campaigns based on weaponized Microsoft Office files and LNK files.

The report also examines threats mostly impacting home users. ESET phishing feeds showed a sixfold increase in shipping-themed phishing lures, most of the time presenting the victims with fake DHL and USPS requests to verify shipping addresses. “In terms of threats directly affecting virtual and physical currencies, a web skimmer known as Magecart remains the leading threat going after online shoppers’ credit card details. We also saw a twofold increase in cryptocurrency-themed phishing lures and a rising number of cryptostealers,” explains Kováč.

The ESET T2 2022 Threat Report also reviews the most important findings and achievements by ESET researchers. They uncovered a previously unknown macOS backdoor, and later attributed it to ScarCruft, discovered an updated version of the Sandworm APT group’s ArguePatch malware loader, uncovered Lazarus payloads in trojanized apps, and analyzed an instance of the Lazarus Operation In(ter)ception campaign targeting macOS devices while spearphishing in crypto-waters. ESET researchers also discovered buffer overflow vulnerabilities in Lenovo UEFI firmware and a new campaign using a fake Salesforce update as a lure.

Besides these findings, the report also summarizes the many talks given by ESET researchers in recent months, and introduces talks planned for AVAR, Ekoparty, and many other conferences. For more information, check out ESET Threat Report T2 2022 on WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

CyberLink’s FaceMe Security Bundled with ASUS Mini PCs: Partnership delivers a lightweight turnkey security control solution designed for at-home and small business use

ASUS Mini PCs with pre-installed FaceMe Security offers a lightweight yet capable smart security control solution. The collaboration gives at-home and small business owners facial recognition security access control.

TAIPEI, TAIWAN – October 04, 2022 – CyberLink, a leader in AI facial recognition technology, recently announced their partnership with ASUS to pre-install its FaceMe Security solution on the ASUS Mini PC PN63-S1 and ExpertCenter PN64 series Mini PCs for businesses. These users will have access to the world’s leading facial recognition engine on their ASUS Mini PCs, and have the option of using facial recognition access control systems ideal for everyday home and small business use.

In the past, facial recognition security controls were mostly designed for larger businesses or enterprises, relying on GPU computing and dedicated servers, with considerable space and power requirements. With the integration of FaceMe Security, the everyday home computer user and small business owner has access to the same level of security, but without the heavy equipment.

ASUS Mini PCs combine a lightweight, powerful computing performance with a low power consumption. These compact PCs can be hooked up to a monitor or desktop without taking up much space, making them suitable for deploying security control equipment in confined spaces on any screen size. ASUS Mini PC PN63-S1 and ExpertCenter PN64 series Mini PCs also use the latest Intel® Core™ processors, leveraging the excellent display performance of Intel® Iris® Xe iGPUs to accelerate facial recognition processing. Through its multiple-I/O connections, an ASUS Mini PC can monitor 3-4 cameras at the same time, and monitor through traffic of up to 1,530 people per hour.

CyberLink’s FaceMe Security leverages the world’s most accurate face recognition engine, which can quickly and accurately verify an individual’s identity to implement security control and access control management.

“We have seen a widespread demand for facial recognition driven access control in both office and residential environments,” said Dr. Jau Huang, Chairman and CEO of CyberLink, “The cooperation between CyberLink and ASUS satisfies users’ desire for accurate facial recognition-based security. Moreover, the combination of the processing power and compactness of ASUS Mini PCs means our collaborative solution is easy to deploy in a wide range of environments. Thanks to this partnership with ASUS and others, we see CyberLink’s facial recognition technology continuing to expand and innovate in the smart security market.”

For more FaceMe Security information, please visit: 
https://version-2.com/cyberlink-face-me/

For more ASUS Mini PC product information, please visit :

PN63-S1: https://www.asus.com/Displays-Desktops/Mini-PCs/PN-series/Mini-PC-PN63-S1/

PN64: https://www.asus.com/Displays-Desktops/Mini-PCs/PN-series/ASUS-ExpertCenter-PN64/

Why ASUS Mini PC : https://www.asus.com/content/why-ASUS-Mini-PC/

About ASUS
ASUS is a global technology leader that provides the world’s most innovative and intuitive devices, components and solutions to deliver incredible experiences that enhance the lives of people everywhere. With its team of 5,000 in-house R&D experts, ASUS is world-renowned for continuously reimagining today’s technologies for tomorrow, garners more than 11 awards every day for quality, innovation and design, and is ranked among Fortune’s World’s Most Admired Companies.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About CyberLink
Founded in 1996, CyberLink Corp. (5203.TW) is the world leader in multimedia software and AI facial recognition technology. CyberLink addresses the demands of consumer, commercial and education markets through a wide range of solutions, covering digital content creation, multimedia playback, video conferencing, live casting, mobile applications and AI facial recognition.  CyberLink has shipped several hundred million copies of its multimedia software and apps, including the award-winning PowerDirector, PhotoDirector, and PowerDVD.  With years of research in the fields of artificial intelligence and facial recognition, CyberLink has developed the FaceMe® Facial Recognition Engine. Powered by deep learning algorithms, FaceMe® delivers the reliable, high-precision, and real-time facial recognition that is critical to AIoT applications such as smart retail, smart security, and surveillance, smart city and smart home. For more information about CyberLink, please visit the official website at www.cyberlink.com

ESET launches dedicated XDR security solutions for Managed Service Providers to protect their customers’ digital journeys

Bratislava, September 29th, 2022 ESET, a global leader in digital security, has announced the launch of its award-winning B2B solutions for Managed Service Providers (MSPs). Based in the heart of the European Union, ESET has been protecting their MSP partners across the globe since 2014, offering a dedicated MSP program. This launch represents a step forward in expanding the offering with XDR solutions, ESET Inspect and ESET Inspect Cloud -currently available to ESET’s enterprise business customers– which will be accessible via ESET’s MSP Administrator platform as used by current MSP partners.

ESET has been researching the cyber threat landscape and innovating digital security technology for decades and the new offering has been designed with both its customers and partners in mind. A combination of ESET’s long-standing use of machine learning and AI based technologies, its cloud reputation system called ESET LiveGrid, and the human expertise offered by the company’s tightly knit global community, powers the world’s most formidable multi-layered cyber threat prevention, detection and response technology – the ESET PROTECT platform powered by ESET LiveSense.

The new offering will allow current and prospective MSP customers access to a simplified and unified digital security platform, with MSP-optimized solutions which are easy to use, help minimize their daily operations, and allow MSPs to provide top-rated security to help solidify their own customers’ trust. This is accomplished without compromising efficiency on behalf of quality, because the new platform integrates balanced breach prevention, detection and response capabilities, and comprehensive threat intelligence. It is modular, adaptable, and continuously innovated with each system upgrade.

ESET’s solution is flexible and scalable in design, future-proofing the MSPs’ business model and helping clear security engineers’ overflowing helpdesk. In terms of making life easier for MSPs, ESET offers a flexible, self-service, zero-commitment billing model which keeps the pressure off and allows their MSP partners to ‘pay as they go’ monthly and for the subscriptions they actually need.

“At the very heart of ESET’s award-winning technology, we feel its paramount to protect progress – but not only ours and more significantly, the progress of our MSP partners. ESET allows MSPs to focus on what really matters, their own business and customers. In our minds, ESET and MSPs simply go together: superior protection of customers, flexible and easy to use product, and a business model tailored to MSP needs,” said Michal Jankech, VP for the MSP and SMB segment at ESET.

To read more about the offering, click here.

To find out more about what is XDR and why we need it in our cyber security lives, click here.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

runZero release notes v3.0.5

A bug that could cause offline self-hosted platform updates to fail has been resolved.
The timeout for Qualys connection tasks has been increased from 60 seconds to 5 minutes.
Fingerprint updates.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.

×

Hello!

Click one of our contacts below to chat on WhatsApp

×