Website disruptions were attempt to sow discord and cause panic, Ukraine officials say

Tuesday’s disruption of multiple Ukrainian government websites and web services for several state-owned banks — along with spam text messages falsely claiming ATMs didn’t work — were part of a coordinated operation designed to sow panic, Ukrainian government officials claimed Wednesday. The officials said it was “too early to talk about specific actors” associated with the distributed denial-of-service (DDoS) attacks, but that the targeting of multiple websites, along with the text messages, suggested an extensive effort beyond the range of an individual or even a group of hackers. The remarks, from some of Ukraine’s cybersecurity and law enforcement leaders, came at a joint briefing Wednesday that the government translated into English on Twitter. The cyber incidents came as the threat of Russian military assault on Ukraine looms large, even as the Russians and NATO governments continue talks in search of a diplomatic resolution. President Joe Biden said Tuesday that 150,000 […]

The post Website disruptions were attempt to sow discord and cause panic, Ukraine officials say appeared first on CyberScoop.

Continue reading Website disruptions were attempt to sow discord and cause panic, Ukraine officials say

Ukrainian government says websites for banks, defense ministry hit with DDoS attack

Websites for several banks and government agencies in Ukraine — including the Ministry of Defense, Ministry of Internal Affairs and the Armed Forces of Ukraine — were facing disruptions Tuesday, according to multiple sources. Ukraine’s Center for Strategic Communications and Information Security posted a message to Facebook late morning U.S. time saying the banks and the government were hit by a “massive” distributed denial-of-service (DDoS) cyberattack. A request for comment from the agency was not immediately returned. None of the reports attributed the DDoS attacks to a specific source. The attacks come as tensions in the region continue to ratchet up, with the Russian government potentially on the verge of military escalation against Ukraine. Local news reported that users were having problems with online banking earlier in the day. One of the banks in question, Privat, is one of the largest in Ukraine, and users were having issues with the […]

The post Ukrainian government says websites for banks, defense ministry hit with DDoS attack appeared first on CyberScoop.

Continue reading Ukrainian government says websites for banks, defense ministry hit with DDoS attack

Google Cloud offers good news and bad news on Log4Shell, other issues

Google Cloud is seeing 400,000 scans per day for systems vulnerable to the Log4Shell bug, the company said Tuesday. The findings — released as part of the company’s semi-regular Threat Horizons report — show that IT security professionals need to “keep paying attention to this, because the scans keep coming, and if you leave one vulnerable instance open, you’re going to be found,” Phil Venables, the chief information security officer at Google Cloud, told CyberScoop. That said, the companies interacting with Google Cloud have “been very much on top of this,” according to Venables. The warning comes as a reminder, however, to security professionals to keep doing the work of finding the devices and software vulnerable to the Log4Shell bug, which affects versions of the widely used Log4j logging software that haven’t been patched since early December. Shane Huntley, the head of Google’s Threat Analysis Group, said that the daily […]

The post Google Cloud offers good news and bad news on Log4Shell, other issues appeared first on CyberScoop.

Continue reading Google Cloud offers good news and bad news on Log4Shell, other issues

Years of hacks against aviation, transportation industries are tied to one group, researchers say

Analysts have noticed various attempts in recent years by hackers trying to breach entities in the aviation and aerospace industries, as well as related transportation fields. The operators typically use of off-the-shelf malware and deploy digital lures that refer to industry-specific topics like airline cargo conferences or machine parts. It now appears that most of those incidents were by the same group, according to cybersecurity firm Proofpoint. Dubbing the group “TA2541,” Proofpoint says the trail of evidence goes back to at least 2017, and the hackers remain a “consistent, active cybercrime threat.” Hundreds of different organizations have been targeted globally, with an emphasis on North America, Europe and the Middle East, the researchers say. Crime seems to be the main goal, says Sherrod DeGrippo, vice president of threat research and detection at Proofpoint, given TA2541’s targeting, its victims, its use of commodity malware and its high message volume. Campaigns ranging […]

The post Years of hacks against aviation, transportation industries are tied to one group, researchers say appeared first on CyberScoop.

Continue reading Years of hacks against aviation, transportation industries are tied to one group, researchers say

Project Zero researchers see promising trends in vulnerability fixes

Big tech vendors generally are remediating serious bugs faster than they were three years ago, according to a new report from Google’s Project Zero. The data — while limited to vulnerabilities the group itself reported between January 2019 and December 2021, and influenced by what the group’s researchers have chosen to pursue — offers “a number of promising trends,” according to Ryan Schoen of Project Zero. “Vendors are fixing almost all of the bugs that they receive, and they generally do it within the 90-day deadline plus the 14-day grace period when needed,” he wrote. In 2021 there was not “a single 90 day deadline exceeded,” which could be because responsible disclosure policies are becoming more standard across the industry, “and vendors are more equipped to react rapidly to reports with differing deadlines,” he wrote. Under the team’s vulnerability disclosure policy, it privately tells a vendor about a bug first, […]

The post Project Zero researchers see promising trends in vulnerability fixes appeared first on CyberScoop.

Continue reading Project Zero researchers see promising trends in vulnerability fixes

Russian government continues crackdown on cybercriminals

Russian authorities seized the websites of several Russian cybercrime forums Monday, the latest in a string of high-profile actions the government there has taken against cybercriminals. Visitors to the websites for Sky Fraud, a forum for stolen credit card data, were greeted with a message posted by the Russian Ministry of Internal Affairs announcing that the page was blocked. Other “carding” and cybercrime forums were also seized, including Ferum and Trump’s Dumps, as well as U-A-S Shop, which offered illicit remote access to various organizations through the remote desktop protocol (RDP) tool. “The SKYFRAUD resource was closed forever during a special law enforcement operation,” the message reads in Russian translated to English. “Management ‘K’ of the BSTM of the Ministry of Internal Affairs of Russia warns: theft of funds from bank cards is illegal!” Within the source code of the seized website, the Russian government left a message: “Which of […]

The post Russian government continues crackdown on cybercriminals appeared first on CyberScoop.

Continue reading Russian government continues crackdown on cybercriminals

Palestinian hacking group evolving with new malware, researchers say

A Palestinian-aligned hacking group has targeted Middle Eastern governments, foreign policy think tanks and a state-affiliated airline with a new malware implant as part of “highly targeted intelligence collection campaigns,” according to research published Tuesday. The findings, from researchers with cybersecurity firm Proofpoint, unpack the latest activities of an established and well-documented Arabic-speaking hacking group known as MoleRATs and its deployment of a new intelligence-gathering trojan they call “NimbleMamba.” The malware serves an intelligence-gathering trojan and, according to the researchers, is likely designed gain initial access to a target system. The group has gone after targets worldwide over the years, but Tuesday’s research examines campaigns against an unnamed Middle East government, foreign policy think tanks and a state-affiliated airline starting in August 2021 and continuing into January 2022. The operators behind MoleRATs — also known as TA402 — are “evolving their techniques and creating these very nicely done, specific and […]

The post Palestinian hacking group evolving with new malware, researchers say appeared first on CyberScoop.

Continue reading Palestinian hacking group evolving with new malware, researchers say

Russia-linked Gamaredon shows signs of possible recent activity in Ukraine, researchers say

A series of cyberattacks on Ukrainian institutions over the past few weeks — including website defacement, computer-wiping malware and phishing campaigns — have the hallmarks of hacking activity associated with the Russian government, but conclusive attribution remains elusive. Research published Thursday, however, shows how a known Russia-linked hacking group, Gamaredon, could be involved in active targeting of Ukrainian targets, including an attempt to compromise a Western government entity in Ukraine on Jan. 19. The findings, published by Palo Alto Networks’ Unit 42 threat intelligence unit, focus on the group as the Russian military amasses more than 100,000 troops along its border with Ukraine. The U.S. and other NATO governments say it’s preparation for a dramatic military escalation. Unit 42 makes clear that its research does not directly tie Gamaredon to the recent high-profile attacks. The team says it mapped out three “large clusters” of Gamaredon infrastructure that are used to support […]

The post Russia-linked Gamaredon shows signs of possible recent activity in Ukraine, researchers say appeared first on CyberScoop.

Continue reading Russia-linked Gamaredon shows signs of possible recent activity in Ukraine, researchers say

Researchers detect fresh wave of hacking attacks on Palestinian targets

A hacking group is targeting Palestinian people and organizations with a wave of years-old malware, according to research published Wednesday. The findings, from Cisco’s Talos threat intelligence division, unpack a surge of attacks starting around October 2021 targeting Palestinians using malware known as Micropsia. The attacks are part of a broader campaign dating back to 2017 connected to a group known as Arid Viper, an Arabic hacking group possibly associated with Hamas that first emerged in 2015. Also known as Desert Falcons or APT-C-23, — “APT” stands for “advanced persistent threat,” a kind of group often associated with nation-state hackers —Kaspersky researchers in 2015 named it the “first exclusively Arabic APT group.” Kaspersky estimated at the time that it numbered 30 or so attackers who employed homemade malware, social engineering and other techniques against targets all over the world. The group’s main motivation is espionage and information theft, Talos noted in […]

The post Researchers detect fresh wave of hacking attacks on Palestinian targets appeared first on CyberScoop.

Continue reading Researchers detect fresh wave of hacking attacks on Palestinian targets

Top White House cyber adviser Anne Neuberger makes the rounds in Europe

A top U.S. cyber official is in Europe this week to “elevate cybersecurity as a top-tier priority at NATO and with international partners,” a senior Biden administration official told reporters Tuesday morning. Anne Neuberger, the deputy national security adviser for cyber and emerging technology, starts her trip in Brussels to meet with counterparts at NATO and the European Union to discuss “deterring, disrupting, and responding to further Russian aggression against Ukraine, neighboring states, and in our respective countries,” the official said. Neuberger also will make a stop in Warsaw to meet with Polish and other Baltic region officials. The week also will include “virtual meetings” with German and French officials. The trip comes as Russian military buildup along its border with Ukraine continues, and cyberattacks against Ukrainian government and nongovernmental organizations continue unabated. The U.S. and other NATO governments say military escalation could happen at any time and that the […]

The post Top White House cyber adviser Anne Neuberger makes the rounds in Europe appeared first on CyberScoop.

Continue reading Top White House cyber adviser Anne Neuberger makes the rounds in Europe