Scammers are masquerading as smart TV owners to fleece advertisers, researchers say

Scammers who have infiltrated the advertising ecosystem are using data centers to impersonate a range of connected devices in order to defraud marketers, according to new findings. New York-based security firm White Ops on Thursday disclosed a vast, ongoing scheme in which fraudsters are charging advertising companies for ad space on smart TVs, and then not delivering on their promise. To boost their credibility, the scammers are disguising bot activity which originates in global data centers as legitimate traffic in order to dupe anti-fraud services. The campaign, which White Ops has named Ice Bucket, is an updated version of the notorious Methbot/3ve scheme, in which scammers sold commercial advertising space in videos and websites that were never viewed by real humans. Methbot scammers earned roughly $29 million between 2014 and 2018, according to the Department of Justice, and also used data center traffic to seem legitimate. While White Ops declined […]

The post Scammers are masquerading as smart TV owners to fleece advertisers, researchers say appeared first on CyberScoop.

Continue reading Scammers are masquerading as smart TV owners to fleece advertisers, researchers say

Someone is passing around Valorant beta keys that are actually malware

Hackers are trying to exploit widespread interest in a buzzy, new video game in an attempt to steal gamers’ username and password credentials. Attackers are disguising malicious software that looks like a product licensing key that would grant a user access to the beta version of “Valorant,” a new title from the developer Riot Games. However, the game-key generator actually includes keylogger software that would allow hackers to track the words and phrases that users type. Albert Zsigovits, a threat researcher at the security firm Sophos, disclosed the issue in a tweet Wednesday that attracted attention from other malware specialists. Riot Games did not respond to a request for comment by press time. Fake #RiotGames #Valorant game-key generators being distributed.It’s actually a stealer, stub grabs a 2nd stage keylogger from pastebin. @malwrhunterteam @JayTHL @PlayVALORANT pic.twitter.com/nXKzRc8W7O — Albert Zsigovits (@albertzsigovits) April 15, 2020 It remains unclear when hackers first launched the […]

The post Someone is passing around Valorant beta keys that are actually malware appeared first on CyberScoop.

Continue reading Someone is passing around Valorant beta keys that are actually malware

Here’s the latest info operation to blame the U.S. for coronavirus

For the past six weeks, an Iranian influence operation has pushed cartoons and fabricated news articles suggesting the U.S government committed bioterrorism by using the coronavirus as a way of attacking China and Iran, according to a new analysis of social media activity. The Iranian propaganda group known as the International Union of Virtual Media, or IUVM, is behind a series of headlines and animated cartoons reporting, for instance, that COVID-19 is part of “a biological war led by Trump to strike at China’s economy,” according to a report published Wednesday by Graphika. Facebook and Twitter have removed IUVM-affiliated accounts dating back to 2018, though the latest effort again demonstrates how propagandists are using Western technology services to amplify disinformation. This disclosure comes just days after U.S. military officials publicly admonished governments in Iran, Russia and China for exploiting the global pandemic to fan anti-American sentiment. “With the advent of the coronavirus, […]

The post Here’s the latest info operation to blame the U.S. for coronavirus appeared first on CyberScoop.

Continue reading Here’s the latest info operation to blame the U.S. for coronavirus

Reality Winner seeks to complete sentence in home confinement amid coronavirus concerns

A former U.S. government contractor who pleaded guilty to leaking a classified intelligence report on Russian government interference is asking a federal judge to allow her to serve the remainder of her prison sentence at home over concerns about contracting COVID-19. Reality Leigh Winner told a Georgia court April 10 she suffers from a respiratory illness and bulimia nervosa, sicknesses that she said could make her especially vulnerable to contracting the coronavirus behind bars. In August 2018, a court sentenced Winner to five years and three months in prison, at the time the largest sentence ever for disclosing national security secrets to the media. Now, her attorney argues that COVID-19, which is spreading through U.S. prisons, presents an “extraordinary and compelling” reason to release Winner to home confinement. “A prison inmate like Reality cannot ‘shelter in place’ and avoid contact with others,” wrote defense attorney Joe Whitley in the new […]

The post Reality Winner seeks to complete sentence in home confinement amid coronavirus concerns appeared first on CyberScoop.

Continue reading Reality Winner seeks to complete sentence in home confinement amid coronavirus concerns

Pentagon bristles at anti-American rhetoric in foreign coronavirus reports

U.S. military officials are criticizing foreign governments for spreading disinformation related to the coronavirus pandemic. In the latest example of the Pentagon trying to mitigate foreign propaganda, U.S. officials admonished the governments of Russia, China and Iran for leveraging the international COVID-19 outbreak to summon anti-American sentiment. U.S. officials, in a statement Monday on a government website, accused state-funded media agencies, like Russia’s Sputnik News, of creating mistrust in credible information in order to create confusion. “These are the messages that are endangering global health because they’re undermining the efforts of governments, of health agencies and of organizations that are in charge of disseminating accurate information about the virus to the public,” said Laura Cooper, deputy assistant secretary of Defense for Russia, Ukraine and Eurasia in a piece published by DOD News, a U.S. government-funded media agency. It’s the latest example of U.S. officials responding to foreign propaganda since the State Department began tracking […]

The post Pentagon bristles at anti-American rhetoric in foreign coronavirus reports appeared first on CyberScoop.

Continue reading Pentagon bristles at anti-American rhetoric in foreign coronavirus reports

Two traders accused of profiting from SEC hack settle charges

Two financial traders accused of using nonpublic information to enrich themselves have settled with the U.S. Securities and Exchange Commission more than a year after the allegations were made public. The SEC announced Thursday its settled charges against David Kwon and Igor Sabodakha in connection with a wider scheme to hack an SEC database, then use stolen data to inform financial trades. The breach at the SEC, and the insider trades that followed, illuminated to much of the public how cybercrime had emerged a new way to boost traditional forms of global financial crime. Kwon and Sabodakha were charged last year alongside seven others for allegedly infiltrating the EDGAR database, where public companies upload financial disclosure forms and future announcements for shareholders. The SEC alleges the hack was carried out by two Ukrainians, Oleksandr Ieremenko and Artem Radchenko, who then passed tips to different groups of traders. With early access […]

The post Two traders accused of profiting from SEC hack settle charges appeared first on CyberScoop.

Continue reading Two traders accused of profiting from SEC hack settle charges

Lawyer for alleged Methbot boss Aleksandr Zhukov wants case dismissed amid coronavirus concerns

The attorney for the accused ringleader of a $29 million cybercrime scheme is asking a U.S. federal judge to dismiss the case because the defendant is at risk of contracting COVID-19 behind bars. Aleksandr Zhukov’s lawyer argued in a court filing that U.S. authorities should release his client, who is currently incarcerated at the Metropolitan Detention Center (MDC) in New York City, in part because he is accused of a nonviolent crime. Zhukov is scheduled to stand trial for allegedly directing an international advertising fraud ring in which scammers have admitted using a range of known hacking techniques to commandeer victims’ computers to view internet ads. Two members of the so-called Methbot/3ve conspiracy have pleaded guilty, while Zhukov has maintained his innocence in the effort to defraud victims out of $29 million. He has spent more than a year in the federal jail, where 14 inmates have tested positive for […]

The post Lawyer for alleged Methbot boss Aleksandr Zhukov wants case dismissed amid coronavirus concerns appeared first on CyberScoop.

Continue reading Lawyer for alleged Methbot boss Aleksandr Zhukov wants case dismissed amid coronavirus concerns

Box will now do its own malware scans on your files

Cloud computing provider Box has announced a new malicious-software detection tool, in what is the latest indication that technology companies are exploring how to protect customer data in ways that used to be the domain of standalone security firms. California-based Box on Wednesday said it will add anti-malware software to Box Shield, its existing security product. Box says it works with 68% of the Fortune 500, and is perhaps best known for offering file-sharing and collaboration software meant to increase corporate efficiency. By adding automated malware alerts to its existing security software, though, the company is aiming to serve the influx of people working remotely amid the coronavirus pandemic. “The future of information security is technology and platforms that reduce risk without slowing down the business,” Lakshmi Hanspal, Box’s chief information security officer, said in a statement. “People are collaborating from more devices and remote locations than ever before, so security teams […]

The post Box will now do its own malware scans on your files appeared first on CyberScoop.

Continue reading Box will now do its own malware scans on your files

Suspected Russian operatives tried using forged diplomatic documents, social media to create divisions

A Russian information operation relied on forged diplomatic emails and planted articles on a number of social media sites in an attempt to undermine multiple governments and impersonate U.S. lawmakers, according to a new analysis of recent social media activity. Massachusetts-based Recorded Future on Wednesday published findings detailing how Russian-language operatives spent months using popular internet services to try to interfere in Estonia, the Republic of Georgia and the U.S. The effort appears to be a continuation of a prior Russian campaign, dubbed Operation Secondary Infektion, that utilized Facebook and dozens of online platforms to sow division in the West and discredit political efforts. The ongoing covert influence effort revealed Wednesday, known as Operation Pinball, involved activity on discussion sites like Reddit, LiveJournal, an array of self-publishing sites, falsified social media profiles that prioritized strong operational security over reaching a large audience. In one instance, Recorded Future detected a Reddit […]

The post Suspected Russian operatives tried using forged diplomatic documents, social media to create divisions appeared first on CyberScoop.

Continue reading Suspected Russian operatives tried using forged diplomatic documents, social media to create divisions

Zoom shareholder accuses executives of fraud over security practices

A Zoom shareholder has filed a lawsuit against the video-conferencing company for allegedly covering up security vulnerabilities in its app. The suit, filed April 7 in a San Francisco federal court, accuses top Zoom executives of failing to disclose flaws in the company’s software, now used by some 200 million people daily. Zoom misrepresented problems with the software’s encryption protocol, failed to disclose that it was sharing user data with Facebook and concealed the extent to which user data was vulnerable to hackers, according to the suit. Zoom chief executive Eric Yuan apologized for security issues in a blog post Monday, saying the company intends to improve its practices. Investor Michael Drieu filed the lawsuit amid ongoing scrutiny of San Jose-based Zoom’s data protection practices. The number of daily users has skyrocketed, up from 10 million in early March, according to the company, as much of the world’s white-collar workforce has […]

The post Zoom shareholder accuses executives of fraud over security practices appeared first on CyberScoop.

Continue reading Zoom shareholder accuses executives of fraud over security practices