Ukrainian government websites hacked amid rising regional security anxiety

A series of Ukrainian government websites were temporarily unavailable Friday in what appeared to be a coordinated cyberattack against the backdrop of rising tensions between Russia and Ukraine. As a result of the massive hacking attack, the websites of the Ministry of Foreign Affairs and a number of other government agencies are temporarily down,” Foreign Ministry spokesperson Oleg Nikolenko tweeted. “Our specialists are already working on restoring the work of IT systems. We apologize for any inconvenience.” Nikolenko told The Associated Press that it was too early to say who was behind the attacks, “but there is a long record of Russian cyber assaults against Ukraine in the past.” The websites for Ukraine’s Cabinet, seven ministries, treasury, National Emergency Service and the states services website were temporarily unavailable, the AP reported. A message was posted to the sites in Ukrainian, Russian and Polish warning that personal data had been leaked—a […]

The post Ukrainian government websites hacked amid rising regional security anxiety appeared first on CyberScoop.

Continue reading Ukrainian government websites hacked amid rising regional security anxiety

Ukrainian authorities arrest suspected ransomware ringleader

Police in Ukraine on Thursday said they broke up a ransomware gang allegedly responsible for extorting more than 50 companies across Europe and the U.S. for more than $1 million. The Ukrainian Cyberpolice, a division of the country’s national police, announced the arrest of an unnamed 36-year-old man who they say partnered with his wife and three others to carry out ransomware attacks. The group is also accused of providing virtual private network (VPN) services to other criminals for a fee. VPNs are widely and legally used around the world to shield portions of internet traffic and obscure the end-user’s IP address. But police in Ukraine say this VPN service also allowed customers to download computer viruses, spyware and other malware. “It was a purely ‘gangster’ service created by criminals for criminals and not under the control of any government or law enforcement agencies,” the Security Service of Ukraine said in […]

The post Ukrainian authorities arrest suspected ransomware ringleader appeared first on CyberScoop.

Continue reading Ukrainian authorities arrest suspected ransomware ringleader

U.S. Cyber Command shares new samples of suspected Iranian hacking software

U.S. Cyber Command posted more than a dozen malware samples to a public repository Wednesday, saying that if network administrators see two or more of these samples on their systems, they may have been targeted by Iranian military hackers. The samples, posted to VirusTotal early Wednesday afternoon, represent various “open-source tools Iranian intelligence actors are using in networks around the world,” the military agency said in a statement. It’s Cyber Command’s first VirusTotal upload in nine months, according the the agency’s page on the site. Referring to the actors as “MuddyWater” — the moniker applied to some suspected Iranian government hacking activities dating back to at least 2015 — Cyber Command’s Cyber National Mission Force shared the samples “to better enable defense” against the attackers. Wednesday’s statement refers to MuddyWater as “a subordinate element” within the Iranian Ministry of Intelligence and Security (MOIS), an arm of the security apparatus focused on […]

The post U.S. Cyber Command shares new samples of suspected Iranian hacking software appeared first on CyberScoop.

Continue reading U.S. Cyber Command shares new samples of suspected Iranian hacking software

Suspected Chinese hackers use Log4j flaw to deploy Night Sky ransomware, Microsoft warns

A China-based ransomware operator has been exploiting a vulnerability in Log4j software to attack internet-facing systems running a popular virtualization service, Microsoft analysts reported Monday. The findings point toward attacks on VMWare Horizon, an application that allows remote users access to virtual computers and servers. Successful attacks have led to the deployment of ransomware via a hacking campaign that calls itself Night Sky. The group behind this effort has previously deployed other ransomware strains, including LockFile, AtomSilo, and Rook, the Microsoft researchers reported. This new campaign, which dates back to Jan. 4 — even though the VMWare Horizon exploitation at the hands of the Log4j vulnerability was spotted toward the end of December — relies in part on spoofed domains made to look as though they’re associated with known technology firms such as TrendMicro, Sophos, Nvidia, and Rogers. VMware issued guidance on remediation on Dec. 14, less than a week after […]

The post Suspected Chinese hackers use Log4j flaw to deploy Night Sky ransomware, Microsoft warns appeared first on CyberScoop.

Continue reading Suspected Chinese hackers use Log4j flaw to deploy Night Sky ransomware, Microsoft warns

More than 1.1 million online credentials found in NY AG credential stuffing investigation

A months-long investigation into credential stuffing attacks by the New York attorney general’s office found credentials for more than 1.1 million online accounts at 17 major retailers, restaurant chains and food delivery services in internet forums, the agency announced Wednesday. Each of the unnamed companies was notified and took steps to protect impacted customers, the AG’s office said in a statement accompanying a 15-page report on the investigation. All of the companies’ investigations into the matter revealed that most of the attacks had not previously been detected, and each company either implemented or made plans to implement additional safeguards, the agency said. None of the affected organizations were named in the report. “Businesses have the responsibility to take appropriate action to protect their customers’ online accounts,” New York Attorney General Letitia James said in the statement. Credential stuffing refers to instances when an attacker relies on username and password combinations […]

The post More than 1.1 million online credentials found in NY AG credential stuffing investigation appeared first on CyberScoop.

Continue reading More than 1.1 million online credentials found in NY AG credential stuffing investigation

Israeli newspaper Jerusalem Post is hacked, website defaced to include threats

Outsiders defaced the website of a prominent Israeli newspaper early Monday, posting a picture of an Israeli nuclear facility being destroyed by a missile along with a threat in both English and Hebrew. Hackers targeted the home page of the The Jerusalem Post, among the biggest newspapers in Israel, early Monday morning Israeli time, the paper reported. Above the image of the exploding facility was the message: “We are close to you where you do not think about it.” The defacement comes on the two-year anniversary of the U.S. government’s killing of Qassem Soleimani, the former commander of the the Quds Force of the Islamic Revolutionary Guard Corps, a branch of Iran’s armed forces. Israeli officials reportedly aided the U.S. operation, which targeted Soleimani with a drone strike shortly after he’d arrived in Baghdad. We are aware of the apparent hacking of our website, alongside a direct threat of Israel. […]

The post Israeli newspaper Jerusalem Post is hacked, website defaced to include threats appeared first on CyberScoop.

Continue reading Israeli newspaper Jerusalem Post is hacked, website defaced to include threats

Fake Christmas Eve termination notices used as phishing lures

A phishing campaign using a well-known malware families is employing a pair of particularly devious methods to trick targets into opening an infected file: fake employee termination notices and phony omicron-variant exposure warnings. A threat researcher going by the name of “TheAnalyst” posted a screenshot of the fake employment termination notice Dec. 22, attributing it to a Dridex affiliate. The suspicious email told the target that their employment would cease as of Dec. 24, and that the decision was not reversible. An attached password-protected Excel file promised additional details. Once a recipient opened a file, a blurred form appeared with a button to “Enable Content,” which enabled the file to run an automated script through its macros feature, a technique intended to help automation that simultaneously has been abused for years for malicious purposes. After the button was clicked, a pop-up window appeared: “Merry X-Mas Dear Employees!” Dridex is a […]

The post Fake Christmas Eve termination notices used as phishing lures appeared first on CyberScoop.

Continue reading Fake Christmas Eve termination notices used as phishing lures

The Log4j flaw is the latest reminder that quick security fixes are easier said than done

Cybersecurity professionals have spent weeks scrambling to address a bug in a widely used software library that could enable hackers to steal data, launch ransomware attacks or otherwise knock systems offline. The bug, known as Log4Shell, exists in Log4j, an open-source software tool that is used widely in the technology industry. The flaw could allow for attackers, in some cases, to take over vulnerable systems by duping a target into logging code capable of downloading malware hosted elsewhere. Given the ubiquity of the software and the sheer number of vulnerable systems, U.S. cybersecurity officials gave federal agencies until Dec. 23 to evaluate their exposure and take remediation steps, urging private sector entities to do the same. Jen Easterly, the director of the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency, had previously called the bug perhaps “the most serious” she’d seen in her career. The CISA directive cited “active […]

The post The Log4j flaw is the latest reminder that quick security fixes are easier said than done appeared first on CyberScoop.

Continue reading The Log4j flaw is the latest reminder that quick security fixes are easier said than done

Russian national accused of hacking, illegal trading is extradited to US

A Russian national accused of hacking into U.S. company networks, stealing non-public information, and then trading stocks based on that information was extradited to the U.S., federal prosecutors announced Monday. Vladislav Kliushin, 41, along with four co-conspirators, allegedly hacked into two firms that help publicly traded companies prepare filings for public release, and used non-public information, such as earnings projections, to trade stocks ahead of the public release. Between February 2018 and August 2020, the scheme netted the hackers at least $82.5 million, prosecutors allege. The four other suspects in the case are: Nikolai Rumiantcev, 33; Mikhail Irzak, 43; Igor Sladkov, 42; and Ivan Yermakov, 35. All five face charges of conspiring to obtain unauthorized access to computers, along with wire and securities fraud. Kliushin is the only suspect in custody after his extradition from Switzerland. Yermakov, a former officer in the Russian military intelligence directorate, was already under U.S. […]

The post Russian national accused of hacking, illegal trading is extradited to US appeared first on CyberScoop.

Continue reading Russian national accused of hacking, illegal trading is extradited to US

DHS issues emergency directive ordering to all federal civilian agencies to address Log4j flaw

U.S. cyber officials issued an emergency directive Friday giving all federal civilian agencies until Dec. 23 to assess their internet-facing networks for the Apache Log4j vulnerability and immediately patch the systems, or take other measures to mitigate the software flaw. The directive, issued by the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency, comes in response to “the active exploitation by multiple threat actors” of the Log4j bug, which has roiled the information security community since it emerged Dec. 10 as a vulnerability in widely used logging software. The directive also requires agencies to report to CISA by Dec. 28 all software applications affected by the bug by name and version, and what actions were taken. “The log4j vulnerabilities pose an unacceptable risk to federal network security,” CISA Director Jen Easterly said in a statement. “If you are using a vulnerable product on your network, you should consider your […]

The post DHS issues emergency directive ordering to all federal civilian agencies to address Log4j flaw appeared first on CyberScoop.

Continue reading DHS issues emergency directive ordering to all federal civilian agencies to address Log4j flaw