Visualização de leitura

Server prices to rise by up to 87% at OVHcloud

OVH is increasing the prices of its servers, some by as much as 87%, for both new and existing customers, blaming AI’s insatiable demand driving the rising cost of the RAM and storage it uses in its data centers.

The European cloud operator specializes in low-cost bare metal and public cloud offerings.

CIOs will be familiar with the balancing act OVH has had to perform over the last year. In a Monday post explaining the upcoming increases, OVH chairman Octave Klaba wrote on X,  “We have to place the right volume of orders, month by month, over 12 months, with no guarantee of the purchase price and without knowing what will be the real demand from our customers.”

Still, he added, “even though our prices are increasing, we remain the cheapest on the market for bare metal and public cloud; where before we could be 3x cheaper, we will be 2x cheaper (if our competitors don’t increase their prices).”

The increases will hurt hard-core gamers hardest, with the cost of the company’s most recent gaming servers rising 87%. (Older gaming instances are unaffected.)

High Grade, high price

But enterprises will also feel the pain from climbing component costs: OVH’s latest High Grade bare metal servers, with up to 2 x 96 cores of AMD Epyc 9005 series processors, 36 hard disks per server, and high-density cooling systems, will go up in price by 59%; older models built to the 2024 spec will go up 26%.

Lower-performance servers will also see increases of 40%-49% for the most recent models, and 26%-37% for older models.

The new prices take effect from Sept. 1 for new orders, and from Oct. 1 for renewals.

It’s not just baseline server prices that are increasing; optional additional memory and storage are going up in price too. OVH already increased the cost of these extras for new server orders as of July 1, with RAM prices rising 127% and disks 89%. From Oct. 1, renewals will be affected too, with the price of additional RAM in the latest servers rising by 40%, and that of larger disks by 15%. For servers built to 2024 specs, the increases will be 20% and 10% respectively.

Existing customers can lock in current prices for servers already in production for up to four years if they pay in advance by Oct. 1, Klaba wrote. Existing commitments will not be affected by the increases until they are due for renewal.

Small instances, big increases

The price rises are more nuanced when it comes to public cloud systems. In future, OVH will break out storage and IP address rental costs separately, and will allow customers to mix and match storage capacity and compute.

“In appearance, hourly compute cost won’t change,” Klaba wrote. “On the other hand, low-latency Block Storage and IPv4 addresses, previously included in our Gen3 instances (B3, C3, R3) will appear as two separately billed line items on Oct. 1.”

The result is price increases of as little as 1.4% for the most powerful instances, or as much as 21.9% for smaller instances, he said.

OVH will continue to offer a 15% discount for a commitment of one year, or 30% for three years, he said, but will no longer offer discounts for shorter terms.

This article originally appeared on NetworkWorld.

Black Friday chaos: The return of Gozi malware

On November 29th, 2024, Black Friday, shoppers flooded online stores to grab the best deals of the year. But while consumers were busy filling their carts, cyber criminals were also seizing the opportunity to exploit the shopping frenzy. Our system detected a significant surge in Gozi malware activity, targeting financial institutions across North America.

The Black Friday connection

Black Friday creates an ideal environment for cyber criminals to thrive. The combination of skyrocketing transaction volumes, a surge in online activity and often lax security awareness among users provides fertile ground for launching attacks. Gozi malware, a well-known banking Trojan, exploits this seasonal chaos to target unsuspecting users and financial institutions alike.

This year’s Black Friday activity was particularly concerning, with a notable increase in web-inject attacks. These sophisticated techniques compromised online banking sessions, enabling the theft of credentials, financial information and other sensitive data.

The campaign is not expected to stop there. With the subsequent year-end shopping rush, Gozi malware is poised to continue its onslaught. Cyber criminals are likely to capitalize on the desperation of last-minute shoppers seeking the best holiday deals, amplifying the malware’s reach and impact.

These ongoing attacks emphasize the need for vigilance and proactive security measures. Whether you’re a consumer enjoying the convenience of online shopping or a business managing increased transaction volumes, understanding the evolving tactics of cyber criminals is critical to staying ahead of the threat.

What is Gozi malware?

Gozi, also known as Ursnif and ISFB, is a modular banking Trojan that has been active since the mid-2000s. It is infamous for its ability to steal banking credentials, monitor user activity and execute advanced web-injects during online banking sessions. Over the years, it has evolved to include features like anti-debugging mechanisms and encrypted communication and is also used for targeted attacks on specific regions and financial institutions.

Observations from our system

During Black Friday, our telemetry revealed the following trends:

  • Targeted campaigns: Gozi operators appeared to focus on North American banks, aligning their campaigns with the peak shopping hours.
  • Increase in attack volume: The malware’s web-inject functionality was heavily used, indicating a rise in compromised banking sessions.

Why the surge?

The Black Friday spike in Gozi activity can be attributed to:

  • Volume of transactions: The sheer number of financial transactions increases the probability of successful attacks.
  • Weakened defenses: Many businesses prioritize frictionless user experience, uptime and sales during Black Friday, potentially delaying or weakening their security measures.
  • Human behavior: Consumers are more likely to overlook suspicious activity when rushing to grab deals.

What we found

The provided script demonstrates a sophisticated web injection attack used to compromise online banking sessions. It dynamically injects malicious code into the legitimate banking page, allowing attackers to manipulate the session without the victim’s knowledge. The malicious script operates in the background to steal sensitive data, such as credentials, and is designed to evade detection by immediately removing itself from the page after execution. By blending with the legitimate page and erasing evidence, the attack becomes nearly invisible to both users and traditional security measures. This highlights the growing sophistication of web-inject attacks and underscores the need for advanced monitoring systems and robust security measures to detect and prevent such threats.

Figure 1: Sample of Gozi injection

From the screenshot below, it appears that the attacker left minimal evidence, likely attempting to test the mechanism and ensure everything is functioning correctly:

Figure 2: Attacker preparation

We believe the web-inject is still a work in progress, with potential future updates and enhancements to the code likely.

If you’d like to learn more about Gozi malware, you can find additional information here.

Final thoughts

As cyber criminals continue to exploit global events like Black Friday, staying vigilant is more crucial than ever. The resurgence of Gozi malware activity highlights the importance of proactive security measures for both businesses and individuals. While the current attacks are predominantly targeting North America, we suspect this campaign will soon expand to Europe, leveraging the holiday shopping season to further its impact.

While we enjoy the convenience of online shopping, it’s vital to stay aware of the ever-present cyber threats lurking in the digital landscape. By adopting robust security practices and remaining cautious, we can reduce the risks and protect ourselves against these sophisticated attacks. Cybersecurity is not just a technical challenge—it’s a shared responsibility.

How to avoid Gozi malware

Here are some recommendations to avoid Gozi malware and protect yourself from similar threats:

  • Be wary of email links. Exercise caution when opening email attachments or clicking on links, especially if they come from unknown or suspicious sources. Be particularly vigilant for phishing emails that may attempt to trick you into downloading malware.
  • Increase your password security. Create strong and unique passwords for all your online accounts, including cryptocurrency exchanges and wallets. Avoid using easily guessable information and consider using a reliable password manager to securely store and manage your passwords.
  • Remain vigilant online. Pay attention to any unusual behavior or unexpected requests when accessing websites, especially financial or cryptocurrency-related platforms. If you encounter unexpected pop-ups, requests for additional personal information or changes in website appearance, it could be a sign of a web-inject attempting to deceive you.
  • Stay informed about the latest cybersecurity threats and best practices. Familiarize yourself with common techniques used by cyber criminals, such as phishing scams and social engineering, to avoid falling victim to their tactics.

One of the best tools to detect Gozi malware and protect your organization is IBM Security Trusteer Pinpoint Detect. The tool uses artificial intelligence and machine learning to protect digital channels against account takeover and fraudulent transactions and detect user devices infected with high-risk malware. Learn more here.

IOC

/usbank/inj[.]php

/in/sella/sella[.]php

/in/paypal/p[.]php

/in/ebay/ebay[.]php

/in/poste/po[.]php

/in/ubibanca/ub[.]php

/in/amazon/a[.]php

/in/clienti.chebanca/ch[.]php

/in/credem/cr[.]php

frcorporateonline/inj[.]php

hsbcnet/inj[.]php

/lancher/in

The post Black Friday chaos: The return of Gozi malware appeared first on Security Intelligence.

❌