The malware can adapt to the new environment, disguise itself, and even operate autonomously when there is no connection to the C&C server.
Cybersecurity Specialists from BioBright reported about a cyberattack on a bio-product manufacturing facility that used unusual malware called Tardigrade.
As experts have found, Tardigrade has a lot of functionality and is not limited to simply blocking computers throughout the facility. The malware can adapt to the new environment, disguise itself, and even operate autonomously when disconnected from its C&C server. The complexity of the malware and other digital analysis data points to a well-funded and motivated APT group.
“This is by far the most sophisticated malware we’ve ever seen in this area. This is very similar to other attacks and campaigns by APT groups targeting other industries, ”the experts noted.
Tardigrade bears some similarities to the popular Smoke Loader (also known as Dofoil) malware downloader, which has been used to distribute malware since at least 2011. Despite the similarities to Smoke Loader, Tardigrade seems to be more advanced and offers an extended set of configurations. The malware has the functionality of a Trojan and, after being installed on the victim’s network, searches for stored passwords, deploys a keylogger, starts stealing data, and installs a backdoor.
As the researchers noted, malware behaves differently depending on the environment, so the signature is constantly changing and more difficult to detect. Experts have tested the malware almost 100 times, and each time it was built on the system in a different way and interacted in different ways.
Tardigrade can make decisions about how to act on the victim’s network, even if there is no connection with the operators. According to experts, Tardigrade is primarily intended to spread using phishing attacks, but it can also spread via infected USB drives or even autonomously move from one infected network to another.
Important Chrome Browser Security Services Update
Since the advent ofInternet, it was necessary to design interfaces to access it. This is how web browsers were born. Unfortunately, this giant network of communication is not without drawbacks. Indeed, ill-intentioned people called hackers use it to harm to everybody. It is surely with this in mind that the chrome browser has decided to make a major update to its security protocols.
In reality, this major overhaul will take place in two phase. New versions of said browser will be created in the coming months and will include security measures. security much safer than previous versions. It should be added that all browsers working with the chromium kernel (chromium) will have to be upgraded.
Many developers are at work in this large-scale project. These are, for example, Titouan Rigoudyn, engineer and software developers and Eiji Kitamura, expert engineer in web security.
Chrome 98 and 101: new security measures
The provisions embedded in the latest versions of this browser send a control request with the header ” Access-Control-Request-Private-Network “. Subsequently, this request must be validated and include the specification ” Access-Control-Allow-Private-Network : true.” »
“Chrome will start sending a preflight request CORS (Cross-Origin Resource Sharing) before any private network request for a sub-resource, which requests explicit permission from the target server” said Titouan Rigoudy and Eiji Kitamura . This means that from chrome 101, access to internal data by a site will be under control.
Basically, according to the engineers, all these provisions are intended to protect routers, as well as users against request forgeries leading to malicious domains
A general and mandatory evolution
In addition to Chrome, the browser edge Microsoft’s Chromium-based has added a new navigation mode to the beta channel (build 98.0.1108.23) to make it more secure. Furthermore, Microsoft declares: “This feature is a huge step forward as it allows us to mitigate unplanned zero active days (based on historical trends). »
The company continued in these terms: “When enabled, this feature brings hardware-enforced stack protection, arbitrary code protection (ACG), and content stream protection (CFG) as support for security mitigations. security to increase user safety on the web. »
Can Microsoft Defender antivirus be disabled in Windows 11?
microsoft defender has reached a spectacular level of maturing with windows 10. What started as a basic malware protection more serious, it has become one of the best antiviruses on the market, with the advantage that it is free, lightweight, and is already included and activated with the operating system. However, there are times that we may be interested in deactivating it, but is it possible to do it with Windows 11?
When we install a third-party antivirus, Microsoft Defender is disabled. However, there may be times when it is not deactivated properly, or there may be times when we simply want to temporarily disable the antivirus to install something that is detected as a false positive. It is also possible that, on a weak computer, Microsoft Defender consumes a lot of resources; especially when booting the system. There are lighter options, or if we don’t have the internet connected device, we may not even need the antivirus.
Windows 11 allows you to disable antivirus
In the Security section of Windows 11, luckily, we can disable many antivirus functions, including Real-time Protection, which is the one that usually causes problems when it comes to detecting false positives in files that we know are safe. This protection can only temporarily deactivate, but the rest of the protection modules can be permanently disabled.
So, effectively, we can temporarily disable the protection in Windows. To do this, we go to Settings in Windows 11, and there we enter the Privacy security tab. In there, let’s windows security. Once there, click on the option that says Antivirus and threat protection. In there, we just have to go to the part of managing the configuration of Real-time protection, and disable it.
It can also be permanently disabled
This deactivation is temporary, so if we want to deactivate it completely, we will have to go to the Local Group Policy Editor. To go to this section, it is necessary to disable the function of Tamper Protection within the same section where real-time protection is temporarily disabled.
To do this, we look for theLocal Group Policy Editor«, or gpedit.msc. In there, let’s Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus. Once we get there, we look for the option «Disable Microsoft Defender Antivirus«. We double click, and we give Enabled. Now we just have to restart, and we will have the Windows 10 antivirus permanently disabled.
These are the best options we have for disable Microsoft Defender in Windows 11. Another option is to use programs like Defender Control or Configure Defender. This type of program allows you to manage a multitude of settings directly from the program and with a couple of clicks without having to navigate through the system settings.
ALL LG Smart TVs can be hacked through the Internet and DTT
The SmartTV They have all kinds of protection mechanisms against vulnerabilities. Some even integrate antivirus to prevent malware from entering them, and all their apps are carefully analyzed. However, they always end up discovering vulnerabilities, so some people prefer not to connect tvs to the internet. The problem is that they got to hack some remotely without even having them connected to the Internet.
The vulnerability has been discovered by the hacker David Buchanan, also know as retr0id. This fault consists of remote code execution via DVB-T standard. In other words, the broadcast of the exploit is carried out through the signal that reaches DTT through the antenna socket. Needless nor that the TV is connected to the Internet in order to exploit the vulnerability.
It hacks through DVB-T and HbbTV
The error consists in executing scripts to generate a DVB-T transmission with metadata from HbbTV, the standard used LovesTV. With these scripts, a web page is loaded on top of the video feed, containing a V8 n-day exploit. Buchanan says that now all he needs to do is find another vulnerability that allows him to escalate privileges on the TV for even more absolute control.
The exploit works on a 2019 LG Smart TVs. Until now, this type of attack required the Smart TV to be connected to the Internet, but now all it takes is for it to be turned on. Buchanan says it may also be possible to hack a TV that’s turned off, but he needs to keep testing.
The bug is still unpatched on LG TVs, whose latest update was released last January 13th. The vulnerability has been published on January 14, so LG has not had time to fix it yet. Although the bug has been exploited on a 2019 TV, Buchanan says the bug can be exploited on 2020 and 2021 models. However, these models use newer versions of Chrome as their browser, so an n-day exploit will be needed. different.
In the video that Buchanan has uploaded to his Twitter account, you can see how you can get almost total control of the TV, showing notifications, messages, and even choosing the video you want to play on it.
RCE over DVB-T
This is a 2019 model LG TV pic.twitter.com/o724k3K3IE
— David Buchanan (@David3141593) January 14, 2022
The vulnerability demolishes all those comments that say that “if you are concerned about your privacy, do not connect the TV to the Internet”. Now, it is possible to hack LG TVs without them being connected to the Internet. However, the flaw can be mitigated by disabling HbbTV’s autostart feature, although Buchanan says that many other vulnerabilities remain in DVB.
I just got DSMCC Carousels working.
That means the exploit still fires even if the TV is not connected to the internet. The entire exploit is served over the airwaves.
Everyone who said “just don’t connect it to the internet” can shut up now 😛 https://t.co/KSYMsdVmqo
— David Buchanan (@David3141593) January 14, 2022
Any LG TV can now be rooted
With this exploit it is possible root lg tv. There is a tool called RootMyTV, which makes it easier to take advantage of the vulnerability to install the homebrew channel on a TV after rooting it. Thanks to this, it is possible to install unauthorized applications and created by the community, such as moonlit to remotely play your PC games (since webOS does not have the Steam Link app), YouTube with enhanced features, RetroArch to play emulators, and many more to come in the future.
After the vulnerability, they have updated RootMyTV to the version 2.0, where, just by entering the website of rootmy.tv from an LG television, it is already possible root it to install apps on it. All current LG models can be rooted with this method, including those updated to version 04.30.57 released this week. The automatic system updates are disabled after rooting in case there is any problem with the updates. In case you want unroot, you just have to do a factory-reset of the TV to return it to the factory settings, so the method is quite safe.
— David Buchanan (@David3141593) January 14, 2022
A device that helps you know if you need more sun protection
There will always be electronic devices that will never cease to amaze us. UVMagic is one of them, being intended...
This Harry Potter actor doesn’t want to ‘stab’ [J.K. Rowling] in the back” despite his disagreements
For several years, Jason Isaacs played Lucius Malfoy, Draco Malfoy’s father. A villain who does not hesitate to swear allegiance...
The front panel of the Cooler Master MasterBox TD300 Mesh case is made of embossed polygonal mesh
Cooler Master announced the release of the MasterBox TD300 Mesh computer case. An interesting detail of this mini-ITX or microATX...
When virtual reality benefits anesthesiologists during surgical procedures
The Board of the European Society of Anaesthesiology and Intensive Care (ESAIC) held an annual meeting at Euroanaesthsia. During this...