Teaching Kids Smart Online Money Habits

It’s rare that money jingles in our pocket or gets hidden between the mattresses for a rainy day. The way you grew up—and the tangible presence of money—isn’t the same experience for your 21st century cyber kid. As digital natives, our kids have grown up with an entirely different view of money: Money is plastic, Read more…

Know Where They Go: YouTube Basics for Parents

If you can hear your kids hysterically laughing in another room, chances are they—and their friends—are watching videos on YouTube. The numbers are staggering: Over 4 billion YouTube videos are viewed a day, which is about “500 years of YouTube video” each day, according to YouTube. What’s the big deal? Well, everything if you are Read more…

Should Stickam Be Blocked From Your Child?

Webcams have always been an area of concern for parents with online kids. Webcams can affect the safety and privacy of your children, but a website called Stickam poses an even greater risk. There are plenty of webcam sharing websites such as TinyChat and Chatroulette, but Sitckam is a little different. Chatroulette and Tinychat offers Read more…

Waledac Reloaded: Trojan.Rloader.B

Recently, we blogged about systems compromised by W32.Virut that were observed downloading W32.Waledac.D (Kelihos). Symantec has followed the Waledac evolution for a number of years and have observed the botnet showing considerable resilience against t…

Bitcoins Still a Hot Security Topic

Interest in Bitcoin—the decentralized digital currency—is definitely growing. But as with anything established, it also sparks the interest of scammers. We have seen a few Trojans stealing Bitcoin wallets over the last few years. Also, Trojans installing Bitcoin miners are not that exotic anymore. A case from last week shows how far interest has grown on the criminal side. Reports have emerged about phishing websites impersonating Mt.Gox, the largest Bitcoin exchange site. Mt.Gox has already fought battles in the past—for example when it was on the receiving end of a distributed denial-of-service (DDoS) attack and also when US authorities temporarily seized part of their money.

Of course, as with the nature of phishing websites, the real site has nothing to do with the fake scam site. The scammers just used the same second-level domain (SLD) name, “mtgox”, but with a different top-level domain (TLD)—for example, using .org, .net, .de, or .co.uk domains. The scam site tried to trick users into downloading and installing malware with the convincing MTGOX_Wallet.exe file name, which Symantec detects as Downloader.Ponik.
 

z z.png

Figure 1. Phishing website uses alternate TLD
 

mtgox_phishing2.png

Figure 2. Phishing website
 

The phishing websites were even advertised using more than one major online advertising service, for example Microsoft’s advertisement network, in order to reach as many victims as possible. This resulted in the scam ad being displayed on many prominent websites.

The ad enticed users by stating “New Century Gold: BITCOIN Protect your money – Buy Bitcoin”—a clever turn-about since the ad links to a scam site that has everything else in mind except protecting your money.

The fact that the phishing site does not use the common Secure Sockets Layer (SSL) security protocol should have been a clear giveaway for any visitor. As with any financial service, regardless of the currency behind it, people should pay due diligence to ensure they are on a real website when entering information. In this case, the scammers left an additional clue inside the HTML of the phishing website for the curious type: they hide the original site’s guidance to change passwords.
 

mtgox_phishing_html-2.png

Figure 3. Phisher-altered HTML
 

Symantec recommends all Mt.Gox users change their passwords and verify accounts. Mt.Gox has started to intensify the verification process of its members, allowing deposits or withdrawals only from verified accounts. They appear to be doing as much as possible to comply with anti-money laundry laws in order avoid the same fate as Liberty Reserve, which was shut down by federal prosecutors in May. Despite Bitcoin being substantially different to Liberty Reserve due to its decentralized peer-to-peer structure, and hence much harder to shut down, it is still good business practice to do as much as possible to ensure secure service.

Symantec has recently launched cloud-based Symantec AdVantage to help prevent ads that lead to malware from ever reaching customers. Website owners that include advertising on their websites should also check out the anti-malvertisement guidelines recommended by the Online Trust Alliance (OTA). The OTA is a non-profit organization with the mission to enhance online trust while promoting innovation and the vitality of the Internet. Symantec is a founding member of the OTA.

For Your Satisfaction – Android:Satfi-A [Trj]

We all have our favorite apps for all the things we do. I use Shazam when I don’t know what song is playing, Maps when I’m lost, FlightRadar24 when I’m curious about the plane flying over my head. These apps are there for my satisfaction; they meet some need. Each of us have different needs […]

From Tween To Teens – When The Info Dries Up!

In a fantasy world, children (of all ages) would tell their parents everything. “I am not really sick today – I really just want to catch up on some TV!” “Erica isn’t just my study mate – she is my girlfriend and we have been together for 6 months!’ “I know I am only 12 Read more…

Do You Know What Your Kids Are Hiding?

Many of you as parents may think, “not much” when asked this question. But in reality, it’s probably a lot more than you think. So it should come as no surprise to anyone that McAfee’s 2013 study, Digital Deception: Exploring the Online Disconnect between Parents and Kids, which examines the online habits and interests of tweens, Read more…

Six Easy Steps to Help Keep Hackers at Bay

Cybercriminals are adopting complex and powerful techniques to “hack,” or take control of online accounts belonging to other people or organizations. Often, they do this by identifying the passwords belonging to an account user. This used to be a complicated task, but, as The Atlantic notes, discovering passwords today can be as simple as running Read more…

What is Your Teen Doing Online? New McAfee Study Reveals All

As a parent, one of your top priorities is to ensure the safety and well-being of your children. This includes teaching them to look both ways before crossing the street, eating plenty of vegetables and having a healthy dose of skepticism when approached by strangers on the street – but how well are you doing Read more…