TrickBot Uses “Service Update” Windows Task in a Grab for Persistence

TrickBot malware is using a Windows Task named “service update” in an attempt to evade detection and maintain persistence on infected endpoints. The refinement is part of a new wave of phishing emails that distribute the botnet trojan, a threat which shares many characteristics with Dyre. These emails all come with PDF documents containing an […]… Read More

The post TrickBot Uses “Service Update” Windows Task in a Grab for Persistence appeared first on The State of Security.

Continue reading TrickBot Uses “Service Update” Windows Task in a Grab for Persistence

Industroyer Malware Capable of Causing ‘Significant Harm’ to Electric Power Systems

Part of Ukraine’s capital, Kiev, lost power on December 17-18, 2016, due to a digital attack. The operation, which occurred nearly one year after BlackEnergy targeted western Ukrainian power company Prykarpattyaoblenergo with KillDisk malware, pushed networks and Supervisory Control and Data Acquisition (SCADA) systems at utility Ukrenergo “outside normal parameters.” Security researchers believe bad actors hid […]… Read More

The post Industroyer Malware Capable of Causing ‘Significant Harm’ to Electric Power Systems appeared first on The State of Security.

Continue reading Industroyer Malware Capable of Causing ‘Significant Harm’ to Electric Power Systems

Latvian Computer Criminal Extradited to United States for Scareware Plot

Polish law enforcement has extradited a Latvian computer criminal who helped orchestrate an international scareware scheme to the United States. 28-year-old Peteris Sahurovs aka “Sagade” made his first appearance in a Minneapolis court on 12 June following a plot for which he targeted the Minneapolis Star Tribune website and stole millions of dollars from unsuspecting […]… Read More

The post Latvian Computer Criminal Extradited to United States for Scareware Plot appeared first on The State of Security.

Continue reading Latvian Computer Criminal Extradited to United States for Scareware Plot

Social Media Scam Uses Two Free Airline Tickets as Lure

A new scam claiming that major airlines are giving away two free tickets is making the rounds on social media platforms. The ploy begins when a user stumbles across a post published on social media by another member offering two free airline tickets. In their posts, users around the world have mentioned Emirates, American Airlines, […]… Read More

The post Social Media Scam Uses Two Free Airline Tickets as Lure appeared first on The State of Security.

Continue reading Social Media Scam Uses Two Free Airline Tickets as Lure

Malicious Downloader Uses Mouse-Hovering to Deliver Banking Trojan

A malicious downloader waits for users to hover over modified text or an image file as a means of delivering a banking trojan. Like most attack campaigns, this operation begins when a user receives a spam email. Bad actors appear to be abusing compromised websites, which they’re using as their command and control (C&C) servers, […]… Read More

The post Malicious Downloader Uses Mouse-Hovering to Deliver Banking Trojan appeared first on The State of Security.

Continue reading Malicious Downloader Uses Mouse-Hovering to Deliver Banking Trojan

Encryption: The GDPR Standard That’s Got Web Privacy Services Hopeful

Businesses now have less than a year to achieve compliance with the General Data Protection Regulation (GDPR). As part of their efforts, organizations must look to Article 32 of the Regulation. This section affirms the data controller’s and processor’s responsibility to leverage “the pseudonymisation and encryption of personal data” to protect against digital risk. Encryption […]… Read More

The post Encryption: The GDPR Standard That’s Got Web Privacy Services Hopeful appeared first on The State of Security.

Continue reading Encryption: The GDPR Standard That’s Got Web Privacy Services Hopeful