Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66.1K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
hacking: security in practice
Learning Go vs Python

Obviously asking this in other pure programming subs will boil down to preference, but what about the hacking/exploit area?

I just picked up that humble bundle that contained a blackhat python book and the blackhat go book and want to give one a try.

I know python from a developer standpoint and only the very basics of go (I made it to loops before I stopped).

If I was to start on either, is there an advantage to one or the other? Python is more common and even comes preinstalled on a lot of stuff. But go has some interest since it’s new.

submitted by /u/space_wiener
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Android banking malware infects 300,000 Google Play users

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Android banking malware infects 300,000 Google Play usersPost Views: 113
https://www.blackhatethicalhacking.com/wp-content/uploads/2021/11/BF2.gif
Reading Time: 1 Minute
Malware campaigns distributing Android trojans that steals online bank credentials have infected almost 300,000 devices through malicious apps pushed via Google’s Play Store.
The Android banking trojans delivered onto compromised devices attempt to steal users’ credentials when they log in to an online banking or cryptocurrency apps. Credential theft is commonly done using fake bank login form overlays displayed on top of the legitimate apps’ login screens.
The stolen credentials are then sent back to the attacker’s servers, where they are collected to be sold to other threat actors or used to steal cryptocurrency and money from victims’ accounts. Evolving tactics to evade detectionIn a new report by ThreatFabric, researchers explain how they discovered four different malware dropper campaigns distributing banking trojans on the Google Play Store.

While threat actors infiltrating the Google Play Store with Android banking trojans are nothing new, recent changes to Google’s policies and increased policing have forced threat actors to evolve their tactics to evade detection.
This evolution includes creating small realistic-looking apps that focus on common themes such as fitness, cryptocurrency, QR codes, and PDF scanning to trick users into installing the app. Then, to add further legitimacy to the apps, the threat actors create websites that fit the theme of the app to help pass reviews by Google.
See Also: Complete Offensive Security and Ethical Hacking Course
Furthermore, ThreatFabric has seen these apps only being distributed to specific regions or at later dates to further evade detection by Google and antivirus vendors.

“This policing by Google has forced actors to find ways to significantly reduce the footprint of dropper apps. Besides improved malware code efforts, Google Play distribution campaigns are also more refined than previous campaigns,” ThreatFabric researchers explain in their new report.

“For example, by introducing carefully planned small malicious code updates over a longer period in Google Play, as well as sporting a dropper C2 backend to fully match the theme of the dropper app (for example a working Fitness website for a workout focused app).”

However, once these “dropper” apps are installed, they will silently communicate with the threat actor’s server to receive commands. When ready to distribute the banking trojan, the threat actor’s server will tell the installed app to perform a fake “update” that “drops” and launches the malware on the Android device.
https://www.bleepstatic.com/images/news/security/a/android/300k-banking-trojan/fake-banking-trojan-update.jpg
16 apps infect 300,000 devicesSince July 2021, ThreatFabric has these fake apps dropping four different banking trojans named ‘Alien’, ‘Hydra’, ‘Ermac’, and and ‘Anatsa’ through sixteen different apps.
https://www.bleepstatic.com/images/news/security/a/android/300k-banking-trojan/tf-timeline.jpg

Timeline of malware campaigns on Google Play
Source: ThreatFabric
The “dropper” apps known to be used during these malware distribution campaigns are:

* Two Factor Authenticator
* Protection Guard
* QR CreatorScanner
* Master Scanner
* QR Scanner 2021[...]

___________________________
@hacking_Attack
@Hacking_Video