Sinclair Broadcast Group says ransomware incident not ‘fully resolved’ weeks after breach

The ransomware attack on conservative broadcasting giant Sinclair is still causing problems, the company reported in a U.S. Securities and Exchange Commission filing Wednesday. Noting that the investigation is ongoing, the notice reports that the Oct. 17 intrusion “has not yet been fully resolved, and certain disruptions to … business and operations remain.” The full extent of the impact on Sinclair’s “business, operations and financial results is not known at the present time.” Employees of the Maryland-based company — which is the second-largest broadcast company in the U.S., owning or operating 185 television stations in 85 markets, multiple national networks, and 21 regional sports network brands — reported at the time that the attack had caused “major technical problems” and made it difficult for some stations to get on the air. The company also reported that hackers had taken data in the attack. “Our employees’ quick response and creative workarounds […]

The post Sinclair Broadcast Group says ransomware incident not ‘fully resolved’ weeks after breach appeared first on CyberScoop.

Continue reading Sinclair Broadcast Group says ransomware incident not ‘fully resolved’ weeks after breach

Potent Brazilian banking trojan resurfaces in South America, despite arrests that averted $4M theft

Back in June, police in Spain arrested 16 people accused of being part of a gang laundering stolen money with the Mekotio and Grandoreiro banking trojans. The suspects in that arrest had already swiped more than $320,000, authorities said, but were on the verge of taking about $4 million before their arrests. But that arrest wasn’t the end for the malware. In the last three months, Mekotio malware has been used to actively target victims again, a report published Wednesday by Check Point Research suggests, with more than 100 attacks detected that show new stealth and evasion techniques in Brazil, Chile, Mexico, Spain and Peru. “Although the Spanish Civil Guard announced the arrest of 16 people involved with Mekotio distribution in July 2021, it appears the gang behind the malware is still active,” said Kobi Eisenkraft, the malware research and protection team leader at Check Point. The research, written by […]

The post Potent Brazilian banking trojan resurfaces in South America, despite arrests that averted $4M theft appeared first on CyberScoop.

Continue reading Potent Brazilian banking trojan resurfaces in South America, despite arrests that averted $4M theft

Michigan police execute warrant looking for missing election equipment

The Michigan State Police launched a criminal investigation this week after a piece of election equipment went missing. The inquiry comes after a local official—who has publicly questioned the validity and security of the 2020 election—had refused to allow a company vendor to run maintenance on the machine. Adams Township Clerk Stephanie Scott had been stripped of her election administration authority on Monday for failing to confirm that she would follow state law in certifying that public accuracy testing had been completed. A spokesperson for the Michigan State Police told CyberScoop Friday that the agency executed a search warrant in the rural community as part of an investigation requested by the Secretary of State, but declined to offer any additional information. Neither Scott nor a spokesperson for Secretary of State Jocelyn Benson responded to requests for comment. This is the second example in recent months of election officials taking extreme […]

The post Michigan police execute warrant looking for missing election equipment appeared first on CyberScoop.

Continue reading Michigan police execute warrant looking for missing election equipment

Russian national allegedly behind TrickBot malware extradited to US, makes court appearance

Vladimir Dunaev, a Russian national accused of being part of the group behind the notorious TrickBot malware, appeared in federal court in Ohio on Thursday after being extradited from South Korea. Dunaev is facing several charges related to computer fraud, bank fraud, wire fraud, money laundering and identity theft. He pleaded not guilty and could face up to 60 years in prison if convicted of all charges. The TrickBot malware, which dates back to at least 2016, was originally a Trojan that allowed attackers to steal financial data. But it evolved over time into a “highly modular, multi-stage malware that provides its operators a full suite of tools to conduct a myriad of illegal cyber activities,” the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency said in a notice earlier this in March. Three months after that CISA notice, U.S. prosecutors unsealed an indictment alleging that a Latvian woman, […]

The post Russian national allegedly behind TrickBot malware extradited to US, makes court appearance appeared first on CyberScoop.

Continue reading Russian national allegedly behind TrickBot malware extradited to US, makes court appearance

Election officials don’t need to report cyber incidents to the feds. That could soon change.

Security personnel charged with the challenging and high-stakes work of protecting election systems from digital threats might soon have another task on their to-do list: reporting any cyber incidents to the federal government. That’s if election technology, designated critical infrastructure in 2017, falls under proposed rules requiring critical infrastructure owners and operators to notify federal officials about cyber incidents, such as attempted hacks and ransomware attacks. The idea has surfaced again in a recent Stanford Internet Observatory paper authored by a former high ranking election security official who offered recommendations for election administration reform, ranging from increased funding to centralizing election IT infrastructure at the state level. The proposals are consistent with multiple bills under consideration in Congress, where momentum is building to require operators of critical infrastructure—pipeline owners, electrical grids, and other industries key to U.S. interests—to disclose yet-to-be defined cyber “incidents” to the Department of Homeland Security, FBI […]

The post Election officials don’t need to report cyber incidents to the feds. That could soon change. appeared first on CyberScoop.

Continue reading Election officials don’t need to report cyber incidents to the feds. That could soon change.

Scammers are emailing waves of unsolicited QR codes, aiming to steal Microsoft users’ passwords

Email fraudsters are seizing on the attention around the quick response codes that have become more common in restaurants and stories, leveraging QR codes try to steal users’ Microsoft credentials and other data. The latest campaign, uncovered Tuesday by the email security company Abnormal, leveraged compromised email accounts in order to bypass standard security screening, then target nearly 200 email accounts between Sept. 15 and Oct. 13, 2021. The operation is the latest example of QR code-enabled phishing, with warnings about “QRishing” or “quishing” dating back to at least 2012. The Better Business Bureau warned of such scams this summer, and the Army Criminal Investigation Command’s Major Cybercrime Unit warned of potential problems in March. An earlier version of the effort unveiled Tuesday embedded a malicious link behind what looked like a voicemail .WAV file. When that link was flagged by security screening services, attackers then switched to a QR […]

The post Scammers are emailing waves of unsolicited QR codes, aiming to steal Microsoft users’ passwords appeared first on CyberScoop.

Continue reading Scammers are emailing waves of unsolicited QR codes, aiming to steal Microsoft users’ passwords

US warns that Chinese government is using ‘wide variety’ of methods, some illegal, to steal trade secrets

The Chinese government’s aggressive push to dominate emerging technology such as artificial intelligence, quantum computing, and biotechnology make Beijing the “primary strategic competitor” to the U.S., the National Counterintelligence and Security Center said in a notice published Friday. The threat from the Chinese government with respect to these technologies is particularly threatening to U.S. national security because of its “well-resourced and comprehensive strategy,” which employs “a wide variety of legal, quasi-legal, and illegal methods” in pursuit of both technology transfers and intelligence gathering, the notice warned. This information transfer takes place in the shadows—through traditional intelligence activities, intellectual property theft, co-opted insiders, front companies—but also through less overtly nefarious activity such as science and technology investments, academic collaboration, mergers and acquisitions, and legal and regulatory actions, according to the NCSC. The notice urged companies take steps to protect their “crown jewels,” with such measures as scrutinizing suppliers, partners, and investors, […]

The post US warns that Chinese government is using ‘wide variety’ of methods, some illegal, to steal trade secrets appeared first on CyberScoop.

Continue reading US warns that Chinese government is using ‘wide variety’ of methods, some illegal, to steal trade secrets

Notorious Russian ransomware gang Evil Corp. reportedly hit Sinclair Broadcast Group

Evil Corp., one of the most notorious and prolific Russian cybercrime groups in recent years with a leader who has been accused of working with Russian intelligence, was reportedly behind last weekend’s cyberattack on Sinclair Broadcast Group. The revelation, first reported by Bloomberg Wednesday, is noteworthy because the U.S. Treasury department sanctioned the group in December, 2o19, making any U.S. company’s transactions with it illegal. The group used a new strain of malware called Macaw in the Sinclair attack, said Allan Liska, a senior threat analyst at Recorded Future. The Justice Department also announced a sealed indictment against Evil Corp. leader Maksim Yakubets in 2019 the same day as the Treasury sanctions. The U.S. government accused Yakubets and another Russian national, Igor Turashev, of being behind malware strains known as Bugat and Dridex, which authorities say hackers employed to target hundreds of banks in more than 40 countries and net the […]

The post Notorious Russian ransomware gang Evil Corp. reportedly hit Sinclair Broadcast Group appeared first on CyberScoop.

Continue reading Notorious Russian ransomware gang Evil Corp. reportedly hit Sinclair Broadcast Group

A China-aligned espionage group is targeting global telecoms, sweeping up call data dating back years

An advanced network of digital spies with a nexus to Chinese interests has successfully compromised parts of the global telecommunications network, in some cases allowing access to subscriber information, call metadata, text messages, and other data, according to research released Tuesday by CrowdStrike. The hacking group, dubbed “LightBasin” by the firm and known publicly as UNC1945, has targeted the telecommunications sector since at least 2016, investigators found. New research has identified 13 telecommunications companies as having been compromised by the network dating back to least 2019. The specific companies were not identified. “People leverage their cellphones like they’re magic,” said Adam Meyers, CrowdStrike’s senior vice president of intelligence. “They don’t think about the fact that there’s this whole infrastructure that makes it work … and that infrastructure is not something that you can take for granted.” The report lays out how this group has developed highly customized tools and a precise […]

The post A China-aligned espionage group is targeting global telecoms, sweeping up call data dating back years appeared first on CyberScoop.

Continue reading A China-aligned espionage group is targeting global telecoms, sweeping up call data dating back years

‘A lot’ of firms are developing offensive cyber techniques, hoping for investment

Aggressive cyber tools remain a topic of interest for “a lot of companies” pitching their technology to investors thanks to interest from government agencies and clients trying to test their defensive techniques, according to a former U.S. National Security Agency employee turned investor. Ron Gula, co-founder of the cyber investment firm Gula Tech Adventures and co-founder of Tenable Network Security, said Monday during CyberWeek, a summit presented by Scoop News Group, that an array of firms seeking investment are developing offensive software tools designed for intelligence agencies, along with federal and local police. Security personnel for years have crafted defensive tools out of known hacking techniques, using everything from phishing tests to leaked CIA hacking tools to hack clients in a way that’s designed to probe their defenses rather than steal data. Companies pitching this kind of software need to walk the fine line between intelligence gathering and law enforcement. There […]

The post ‘A lot’ of firms are developing offensive cyber techniques, hoping for investment appeared first on CyberScoop.

Continue reading ‘A lot’ of firms are developing offensive cyber techniques, hoping for investment