malware
4 articles with this tag
'Your PC is infected' warnings are almost always fake — how to close them, and what to do if you already called
A browser page shouting 'your computer is infected' with a phone number is a tech support scam. Japan's IPA says that if the screen merely appeared, the PC is not infected and closing it is enough, and that most victims get hurt because they couldn't close it and called. This site's view: the goal of the fake warning is not infection — it is getting you to call. Genuine security features never show a phone number. If you can close it, you're done; if it went further, act on the stage you reached.
What is a backdoor — how attackers keep their way in, and how to spot it
A backdoor is a hidden entry point planted so an attacker can return while bypassing normal authentication. It usually follows an initial breach and turns one intrusion into ongoing access; it can also arrive inside a poisoned dependency. What separates it from legitimate remote maintenance is whether someone authorised it, knows about it, and can see it in the logs. Defense: least privilege, integrity monitoring, egress monitoring, dependency review.
Coincheck NEM Heist (2018) — How ~$530M Was Stolen, and the Key-Management Defense
The entry point was reported to be spear-phishing / malware aimed at employees, which stole the private key of an internet-connected hot wallet; ~523 million XEM (~$530M at the time) was then moved out in one sweep. The core failure was keeping a huge, instantly-spendable balance 'hot' and with no multisig — a single stolen key moved almost everything. Defend by keeping important keys cold / in a dedicated vault, minimizing the hot balance, removing single points of failure (multi-approval), and detecting and stopping abnormal bulk operations.
What is malware? Types, infection routes, and the basic defenses
Malware (malicious software) is the umbrella term for software built to harm your devices or data. Viruses, worms, trojans, ransomware, spyware, and bots are all types under it. However different they look, the defense is the same three layers: close the entry (updates, don't open suspicious attachments/macros, MFA), detect (EDR, antivirus), and be able to recover (backups). Mastering the principle matters far more than memorizing the type names.