Mostrando postagens com marcador Uber. Mostrar todas as postagens
Mostrando postagens com marcador Uber. Mostrar todas as postagens

sexta-feira, 5 de janeiro de 2018

New Android Malware Disguised as Uber App

By Waqas on 

t is just another day with just another Android malware targeting unsuspecting users.
Last time Uber was in news for hiding massive data breach of 75 million accounts from its users and paying $100,000 to the culprits. Now, the IT security researchers at Symantec have discovered malware that secretly spies upon Uber’s Android app and extracts private, sensitive data such as users’ passwords. This allows attackers to hijack the accounts owned by Uber users and has been dubbed as Android.Fakeapp.
The Android malware is capable of mimicking Uber’s interface; it was identified after various Trojan pop-ups were observed by the researchers on the screen at regular intervals. The purpose was to fool the users into giving away their phone numbers and passwords. When the user presses Enter, the malware sends login credentials to a remote server. The attackers would receive the information and use it to compromise accounts and sell them off to other hackers on the black market.
“In order to steal a user’s login information, the malware pops up on-screen regularly and prompts the user to enter their Uber username and password. Once a user falls for the attack and enters their information, it gets swept up by the attacker.”
This Fakeapp variant also gives a false sense of security to the user apart from showing a fake log-in screen of Uber. This is done to prevent users from suspecting any foul play and changing their password before the malware is able to obtain the required information.
New Android Malware Disguised as Uber App
Fake Uber app screens for users to enter their registered mobile number and password while screen of the legitimate app showing the user’s current location (Screenshot: Symantec)
According to Symantec’s findings, the case shows that malware creators are always eagerly looking to find new social engineering tricks to trap users.
They recommended that users must keep their software updated and install a reliable anti-malware app to prevent malware from infecting the device. Furthermore, it is suggested that apps from unfamiliar websites are not downloaded at all.
“We recommend only downloading apps from trusted sources. However, we want to protect our users even if they make an honest mistake and that’s why we put a collection of security controls and systems in place to help detect and block unauthorized logins even if you accidentally give away your password.”
To cover up the stealing of credentials, the malware accesses Uber app’s deep links to show the current location of the user, which gives away the feeling that user is using legitimate Uber app. Dinesh Venkatesan, the threat analysis engineer at Symantec, stated:
“To avoid alarming the user, the malware displays a screen of the legitimate app that shows the user’s current location, which would not normally arouse suspicion because that’s what’s expected of the actual app.”
The malware is not as widespread as we might believe it to be and a majority of Uber users are protected from it. However, it malware affects users in Russian-speaking countries at the moment and widescale distribution of the campaign is currently not expected by researchers.

quarta-feira, 22 de novembro de 2017

After Getting Hacked, Uber Paid Hackers $100,000 to Keep Data Breach Secret

Mohit Kumar em 21/11/2017 no site The Hacker News

uber-data-breach

Uber is in headlines once again—this time for concealing last year's data breach that exposed personal data of 57 million customers and drivers.

On Tuesday, Uber announced that the company suffered a massive data breach in October 2016 that exposed names, e-mail addresses and phone numbers of 57 million Uber riders and drivers along with driver license numbers of around 600,000 drivers.

However, instead of disclosing the breach, the company paid $100,000 in ransom to the two hackers who had access to the data in exchange for keeping the incident secret and deleting the information, according to a report published by Bloomberg.

Uber said none of its own systems were breached, rather two individuals outside the company inappropriately accessed and downloaded 57 million Uber riders' and drivers' data that was stored on a third-party cloud-based service.

The cyberattack exposed the names and driver license numbers of some 600,000 drivers in the United States, and the names, emails, and mobile phone numbers of around 57 million Uber users worldwide, which included drivers as well.

However, the company said other personal details, such as trip location history, credit card numbers, bank account numbers, Social Security numbers or dates of birth, were not accessed in the attack.


Uber Hid 57 Million User Data Breach For Over a Year


According to Bloomberg report, former Uber CEO Travis Kalanick learned of the cyber attack in November 2016, when the company was negotiating with the Federal Trade Commission (FTC) on a privacy settlement.

So, the company chose to pay the two hackers $100,000 to delete the stolen information and keep quiet about the incident and finally agreed to the FTC settlement three months ago, without admitting any wrongdoing.

Uber Technologies Inc. only told the FTC about the October 2016 data incident on Tuesday, when the breach was made public by Bloomberg.

However, this secret payment eventually cost Uber security executives their jobs for handling the incident.

Now Uber CEO Dara Khosrowshahi has reportedly asked for the resignation of Uber Chief Security Officer Joe Sullivan, and one of his deputies, Craig Clark, who worked to keep the attack quiet.
"None of this should have happened, and I will not make excuses for it. While I cannot erase the past, I can commit on behalf of every Uber employee that we will learn from our mistakes," Khosrowshahi said.
"We are changing the way we do business, putting integrity at the core of every decision we make and working hard to earn the trust of our customers."

Uber is notifying regulatory authorities and offering affected drivers free credit monitoring and identity theft protection.

The company also says that it is monitoring the affected accounts for fraudulent activity and that riders do not need to take any action against this incident. It's likely that Uber will be forcing its customers to reset their passwords for its app.