Free Tools For Detecting Hacking Team Malware In Your Systems
An anonymous reader writes: Worried that you might have been targeted with Hacking Team spyware, but don't know how to find out for sure? IT security firm Rook Security has released Milano, a free automated tool meant to detect the Hacking Team malware on a computer system. Facebook has also offered a way to discover if your Mac(s) have been compromised by Hacking Team malware: they have provided a specific query pack for its open source OS analysis tool osquery.
Well, following their own whois information:
Rook Security is apparently a front for the "Rook Group,"
Registrant Name: Rook Group ..of "Rook Consulting." So it's already sounding like a holding company...the interesting part is who's behind all -that- mess, on rooksecurity.com, they list their "PR" contact as twhitman@vocecomm.com...Tim Whitman, who apparently is also the PR contact for another no-name outfit, BeyondTrust:
Registrant Organization: Rook Consulting
Registrant Street: 560 S. Winchester Blvd
Registrant Street: Suite 500
Registrant City: San Jose
Registrant State/Province: California
Registrant Postal Code: 95128
Registrant Country: United States
Registrant Phone: +1.8887129531
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: info@rookconsulting.net
http://www.beyondtrust.com/New...
One of the few articles I can find advertising their "skills" is one of their own press releases and all the companies involved seem to be awfully vague about what services they're offering exactly...
2/54, could be false positives I've at least heard of Rook Security although I forget in what context ;)
Figured I'd take a look at the tools. Download what claims to be the software for windows (first link). Get presented with a Zip file, as expected. Open zip file and find.... OSX software. Thinking I clicked on the wrong link I went back to download a second time... Same file.
So... yeah.. ranking real high on the trust value right now.