<?xml version="1.0"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>
   <channel>
   
   <atom:link href="http://www.secureworks.com/feeds/research.xml" rel="self" type="application/rss+xml" />

      <title>SecureWorks Research</title>
      <link>http://www.secureworks.com/research/</link>
      <description>Information security Threats and SecureWorks Research Blog.</description>
 
	     		 <item>
			   <title>New Banking Trojan Targeting ACH and Wire Payment Sites is Discovered </title>
			   <link>http://www.secureworks.com/research/blog/index.php/2010/2/8/new-banking-trojan-targeting-ach-and-wire-payment-sites-is-discovered</link>
			   <description>Over the past year, the SecureWorks Counter Threat Unit (CTU)(SM) has seen criminals continue to target Automated Clearing House (ACH) and wire transfer transactions for fraud activity, resulting in high-value losses. Small to midsized businesses (SMBs) and not-for-profits have been hit especially hard. Neustar has published an excellent overview (PDF) of this type of threat. </description>
			   <guid>http://www.secureworks.com/research/blog/index.php/2010/2/8/new-banking-trojan-targeting-ach-and-wire-payment-sites-is-discovered</guid>
			 </item>
 	   		 <item>
			   <title>Opachki Link Hijacker Trojan Analysis</title>
			   <link>http://www.secureworks.com/research/threats/opachki</link>
			   <description></description>
			   <guid>http://www.secureworks.com/research/threats/opachki</guid>
			 </item>
 	   		 <item>
			   <title>Operation Aurora: Clues in the Code</title>
			   <link>http://www.secureworks.com/research/blog/index.php/2010/1/20/operation-aurora-clues-in-the-code</link>
			   <description>With the recently disclosed hacking incident inside Google and other major    companies, much of the world has begun to wake up to what the infosec    community has known for some time - there is a persistent campaign of    &amp;quot;espionage-by-malware&amp;quot; emanating from the People's Republic of    China (PRC). Corporate and state secrets both have been shanghaied over a    period of five or more years, and the activity becomes bolder over time with    little public acknowledgement or response from the U.S. government.</description>
			   <guid>http://www.secureworks.com/research/blog/index.php/2010/1/20/operation-aurora-clues-in-the-code</guid>
			 </item>
 	   		 <item>
			   <title>Static Binary Analysis of Recent SMBv2 Vulnerability</title>
			   <link>http://www.secureworks.com/research/threats/windows-0day</link>
			   <description></description>
			   <guid>http://www.secureworks.com/research/threats/windows-0day</guid>
			 </item>
 	   		 <item>
			   <title>Publicly Disclosed GSM Attack Surface Expanding</title>
			   <link>http://www.secureworks.com/research/blog/index.php/2009/12/29/publicly-disclosed-gsm-attack-surface-expanding</link>
			   <description>During the course of 2009, the amount of publicly available information on the security of GSM cellular networks and devices has steadily increased. GSM stands for the &quot;Global System for Mobile communications&quot; and is the world's most popular standard for mobile handsets. </description>
			   <guid>http://www.secureworks.com/research/blog/index.php/2009/12/29/publicly-disclosed-gsm-attack-surface-expanding</guid>
			 </item>
 	   		 <item>
			   <title>The Underground Economy of the Pay-Per-Install (PPI) Business</title>
			   <link>http://www.secureworks.com/research/threats/ppi</link>
			   <description></description>
			   <guid>http://www.secureworks.com/research/threats/ppi</guid>
			 </item>
 	   		 <item>
			   <title>SecureWorks Reports Increase in Email Scams and Advises Extra Caution While Shopping Online this Holiday Season</title>
			   <link>http://www.secureworks.com/research/blog/index.php/2009/12/2/secureworks-reports-increase-in-email-scams-and-advises-extra-caution-while-shopping-online-this-holiday-season</link>
			   <description>In the last month, SecureWorks' Counter Threat Unit(SM) (CTU) has seen a general increase in malicious email campaigns  trying to infect online users with the Zeus Trojan (one of the most pervasive financial-credential stealing Trojan) on the market. In the last three weeks, the CTU has also monitored a large increase in the number of email lists being sold on the underground hacker forums, coinciding with the start of the holiday shopping season.</description>
			   <guid>http://www.secureworks.com/research/blog/index.php/2009/12/2/secureworks-reports-increase-in-email-scams-and-advises-extra-caution-while-shopping-online-this-holiday-season</guid>
			 </item>
 	   		 <item>
			   <title>Clampi/Ligats/Ilomo Trojan</title>
			   <link>http://www.secureworks.com/research/threats/clampi-trojan</link>
			   <description></description>
			   <guid>http://www.secureworks.com/research/threats/clampi-trojan</guid>
			 </item>
 	   		 <item>
			   <title>SANS Incident Detection Summit</title>
			   <link>http://www.secureworks.com/research/blog/index.php/2009/11/25/sans-incident-detection-summit</link>
			   <description>SecureWorks CTO Jon Ramsey will be participating on a panel at the SANS Incident Detection Summit December 9-10, 2009.</description>
			   <guid>http://www.secureworks.com/research/blog/index.php/2009/11/25/sans-incident-detection-summit</guid>
			 </item>
 	   		 <item>
			   <title>FFSearcher Click Fraud Trojan</title>
			   <link>http://www.secureworks.com/research/threats/ffsearcher</link>
			   <description></description>
			   <guid>http://www.secureworks.com/research/threats/ffsearcher</guid>
			 </item>
 	   		 <item>
			   <title>ToorCon 11 a Success!</title>
			   <link>http://www.secureworks.com/research/blog/index.php/2009/10/30/toorcon-11-a-success</link>
			   <description>There are two things one can count on every year at ToorCon: the amazing San Diego weather and excellent presentations about new and emerging security research. This year's ToorCon 11 did not disappoint, and delivered a lot of great content and new security research throughout the weekend.</description>
			   <guid>http://www.secureworks.com/research/blog/index.php/2009/10/30/toorcon-11-a-success</guid>
			 </item>
 	   		 <item>
			   <title>Virut Encryption Analysis</title>
			   <link>http://www.secureworks.com/research/threats/virut-encryption-analysis</link>
			   <description></description>
			   <guid>http://www.secureworks.com/research/threats/virut-encryption-analysis</guid>
			 </item>
 	   		 <item>
			   <title>Monkif/DlKhora Botnet Hiding Its Commands as JPEG Images</title>
			   <link>http://www.secureworks.com/research/blog/index.php/2009/9/29/monkifdlkhora-botnet-hiding-its-commands-as-jpeg-images</link>
			   <description>The SecureWorks Counter Threat Unit (CTU) has been carefully monitoring the activity of the Monkif/DlKhora botnet. This bot is an example of a Downloader trojan, in that its primary purpose is to receive instructions to download and execute other malware. The trojan also attempts to disable anti-virus and personal firewall software to maintain its foothold on the system. </description>
			   <guid>http://www.secureworks.com/research/blog/index.php/2009/9/29/monkifdlkhora-botnet-hiding-its-commands-as-jpeg-images</guid>
			 </item>
 	   		 <item>
			   <title>DNS Amplification Variation Used in Recent DDos Attacks</title>
			   <link>http://www.secureworks.com/research/threats/dns-amplification</link>
			   <description></description>
			   <guid>http://www.secureworks.com/research/threats/dns-amplification</guid>
			 </item>
 	   		 <item>
			   <title>Skype Eavesdropping Trojan</title>
			   <link>http://www.secureworks.com/research/blog/index.php/2009/9/25/skype-eavesdropping-trojan</link>
			   <description>Recently, programmer Ruben Unteregger released the source code for a Trojan that allows an attacker to listen in on a victim's Skype conversations. For approximately seven years, Unteregger has worked as a software engineer for ERA IT Solutions AG where he developed the trojan. Skype traffic is encrypted using a 256-bit AES block cipher, the kind approved by the US Government to protect &quot;TOP SECRET&quot; information.</description>
			   <guid>http://www.secureworks.com/research/blog/index.php/2009/9/25/skype-eavesdropping-trojan</guid>
			 </item>
 	   		 <item>
			   <title>Downadup/Conficker Worm Removal</title>
			   <link>http://www.secureworks.com/research/threats/downadup-removal</link>
			   <description></description>
			   <guid>http://www.secureworks.com/research/threats/downadup-removal</guid>
			 </item>
 	   		 <item>
			   <title>Twitter-Based Botnet Command and Control</title>
			   <link>http://www.secureworks.com/research/blog/index.php/2009/9/4/twitter-based-botnet-command-and-control</link>
			   <description>Twitter is a social networking and microblogging service launched in late 2006. Once logged in, users post small updates to the site frequently throughout the day. These short update messages, known as &quot;tweets,&quot; may not exceed 140 UTF-8 encoded characters. </description>
			   <guid>http://www.secureworks.com/research/blog/index.php/2009/9/4/twitter-based-botnet-command-and-control</guid>
			 </item>
 	   		 <item>
			   <title>Spam Botnets to Watch in 2009</title>
			   <link>http://www.secureworks.com/research/threats/botnets2009</link>
			   <description></description>
			   <guid>http://www.secureworks.com/research/threats/botnets2009</guid>
			 </item>
 	   		 <item>
			   <title>Crypto Attacks: It's the implementation stupid</title>
			   <link>http://www.secureworks.com/research/blog/index.php/2009/8/27/crypto-attacks</link>
			   <description>Black Hat USA 2009 brought us the latest release of Moxie Marlinspike's sslstrip tool. sslstrip is a tool for performing man-in-the-middle (MITM) attacks against TLS/SSL sessions. The previous version simply terminated the TLS connection at the MITM point and forwarded on an unencrypted connection to the client.</description>
			   <guid>http://www.secureworks.com/research/blog/index.php/2009/8/27/crypto-attacks</guid>
			 </item>
 	   		 <item>
			   <title>Rogue Antivirus Dissected - Part 2</title>
			   <link>http://www.secureworks.com/research/threats/rogue-antivirus-part-2</link>
			   <description></description>
			   <guid>http://www.secureworks.com/research/threats/rogue-antivirus-part-2</guid>
			 </item>
 	      </channel>
 </rss>