Microsoft strikes back at Necurs botnet by preemptively disabling hacking tools

Microsoft is trying to sink a vast network that cybercriminals have used for eight years to spread spam and hack computers throughout the globe. Microsoft announced on Tuesday that it has moved to disrupt the Necurs botnet, a network of more than 9 million computers that had been surreptitiously infected with malware and then used by hackers to carry out various schemes. Attackers, likely in Russia, according to Microsoft, used Necurs to distribute pharmaceutical spam, facilitate ransomware attacks and infect victims with numerous types of malicious software, such as the GameOver Zeus malware that is blamed for $100 million in losses.   “The Necurs is one of the largest networks in the spam email threat ecosystem, with victims in nearly every country in the world,” Tom Burt, Microsoft’s corporate vice president for customer security and trust, said in a statement. “During a 58-day period in our investigation, for example, we observed that […]

The post Microsoft strikes back at Necurs botnet by preemptively disabling hacking tools appeared first on CyberScoop.

Continue reading Microsoft strikes back at Necurs botnet by preemptively disabling hacking tools

FBI arrests alleged operator of a Russian hosting service meant for scammers

U.S. authorities have arrested a Russian man accused of running an illicit service where buyers allegedly have spent years purchasing stolen data and hacked web accounts. In a complaint unsealed March 9, the FBI accused Kirill Victorovich Frisov of operating Deer.io, a web hosting service where subscribers can host independent stores online for roughly $250. The site, which remains online, is based in Russia, outside the reach of U.S. law enforcement, and advertises itself as the home of more than 24,000 accounts with more than $17 million in sales. Unlike legitimate hosting services, Deer.io promises anonymity and markets strong defenses against the kind of distributed denial-of-service attacks that scammers often use to harass each other, the threat intelligence provider Digital Shadows found in 2016. FBI investigators probing the site determined it existed entirely for the purpose of cybercrime. Seamus Hughes, the deputy director of the Program on Extremism at George Washington […]

The post FBI arrests alleged operator of a Russian hosting service meant for scammers appeared first on CyberScoop.

Continue reading FBI arrests alleged operator of a Russian hosting service meant for scammers

Vault 7 court case ends in mistrial on most serious charges

A New York City jury was unable to reach a verdict Monday on a number of charges against a former CIA engineer accused of orchestrating the largest leak in agency history. A federal jury in New York found Joshua Schulte guilty on charges of contempt of court and lying to the FBI after a monthlong trial and four days of deliberation. Jurors could not reach a decision on more serious charges of illegally transferring national defense information; unauthorized access to classified information; and theft of government property. A hearing will be held on March 26 to determine the next steps in the case. U.S. prosecutors argued that Schulte leaked a trove CIA hacking tools to WikiLeaks in 2016 to retaliate against co-workers and agency management for what he perceived as unfair treatment during his employment. Defense attorneys worked to convince jurors that the CIA had failed to secure its most sensitive […]

The post Vault 7 court case ends in mistrial on most serious charges appeared first on CyberScoop.

Continue reading Vault 7 court case ends in mistrial on most serious charges

Indictment appears to name Group-IB executive in scheme to sell hacked data

The U.S. Department of Justice on Monday unsealed a 2014 indictment that appears to accuse a current cybersecurity executive in an alleged conspiracy to sell usernames and passwords belonging to American customers of the social media company Formspring in 2012. The man identified in the indictment, Nikita Kislitsin, allegedly received data stolen from Formspring, then tried to sell that information to others. A man with the same name is currently listed as head of network security at Group-IB, a cybersecurity vendor with offices in Moscow and Singapore. CyberScoop has reached out to Group-IB to determine if Kislitsin is still an employee. The company did not provide a response as of Thursday morning, Eastern U.S. time. U.S. prosecutors have not alleged any wrongdoing by Group-IB. The Department of Justice’s office in the Northern District of California did not respond to requests for comment seeking clarification. Kistlitsin did not return messages seeking comment. Ties to @Udalite U.S. prosecutors say Nikita Kislitsin […]

The post Indictment appears to name Group-IB executive in scheme to sell hacked data appeared first on CyberScoop.

Continue reading Indictment appears to name Group-IB executive in scheme to sell hacked data

Accused LinkedIn hacker worked with alleged SEC hacker, according to DOJ filing

Hackers accused of carrying out separate attacks on social network LinkedIn and public relations firms for financial gain worked together as part of a “a criminal clique” in which scammers from Ukraine and Russia pooled their resources, according to the U.S. Justice Department. Yevgeniy Nikulin, a Russian man who allegedly stole 117 million usernames and passwords from LinkedIn, Dropbox and Formspring in 2012, was in regular contact with Oleksandr Ieremenko, a Ukrainian national charged in New Jersey for allegedly hacking the U.S. Securities and Exchange Commission, prosecutors say in a new court filing. Nikulin is set to stand trial in San Francisco for allegedly stealing credentials from LinkedIn and Formspring, then trying to sell that database on a Russian-language internet forum. Ieremenko was previously charged, along with six other individuals, in connection with a scheme to steal nonpublic information from the SEC and PR firms for the purpose of illegal […]

The post Accused LinkedIn hacker worked with alleged SEC hacker, according to DOJ filing appeared first on CyberScoop.

Continue reading Accused LinkedIn hacker worked with alleged SEC hacker, according to DOJ filing

Justice Department clarifies how threat researchers should work with law enforcement

New guidance from the Department of Justice warns threat intelligence companies to avoid breaking the law when gathering data from dark web forums and suspected cybercriminals. The department’s cybersecurity unit last week published a 15-page memo meant to clarify prosecutors’ position on the collection of evidence from private companies. Firms like Recorded Future, Digital Shadows and others often monitor known cybercriminal hangouts to gather information about possible data breaches, malicious software trends and emerging fraud techniques. Researchers rely on pseudonyms to build their reputation on hacking forums, building their reputations up high enough to encourage other members to inadvertently reveal information about themselves or their activities. Often, threat intelligence providers will detail their findings to law enforcement, or clients trying to fend off an attack. “Information gleaned from those sources can be a rich source of cyber threat intelligence and network deference information about past, current, or future cyberattacks[,]” the […]

The post Justice Department clarifies how threat researchers should work with law enforcement appeared first on CyberScoop.

Continue reading Justice Department clarifies how threat researchers should work with law enforcement

TA505 hacking crew spent much of 2019 trying to breach South Korea’s financial sector

A gang of hackers with a long history of financially motivated attacks increased its targeting of businesses in South Korea last year, using a combination of malicious attachments and ransomware to haunt victims, according to new findings. Researchers from the Financial Security Institute, which is similar to an information sharing and analysis center (ISAC) for South Korea’s financial sector, said on Friday that the hacking group spent much of 2019 trying to phish enterprises in finance, manufacturing and medical services in South Korea. The group, known as TA505, has been active since at least 2014, and appears to share tools, techniques and procedures with FIN7, a Russian-speaking group blamed for more than a billion dollars in global losses, researchers say. Linking FIN7 and TA505 is a notoriously difficult task, and researchers have confused the groups before. TA505 is perhaps best known for its reported connection to the Dridex banking trojan, […]

The post TA505 hacking crew spent much of 2019 trying to breach South Korea’s financial sector appeared first on CyberScoop.

Continue reading TA505 hacking crew spent much of 2019 trying to breach South Korea’s financial sector

Accused Chinese hackers abandon techniques after U.S. indictments

U.S. indictments against individual Chinese soldiers accused of hacking various American targets have deterred those military personnel from conducting the same kinds of hacks again, according to the co-founder of a firm known for investigating nation-state activity. Digital infrastructure associated with alleged hackers charged in 2014, 2017 and 2018 essentially evaporated when charges in each case were made public, said Dmitri Alperovitch, who co-founded CrowdStrike, during a keynote speech Wednesday during the RSA security conference in San Francisco. Each of the groups — known as APT 1, APT 3, or Buyosec, and APT 10, respectively — has been associated with Chinese intelligence services or the People’s Liberation Army. “Everything associated with them disappeared,” Alperovitch said during a conversation with reporters after the presentation. He cautioned that, while other Chinese groups largely have remained active, the specific groups named in the indictments “vanished” in a way that was “remarkable.” Some of […]

The post Accused Chinese hackers abandon techniques after U.S. indictments appeared first on CyberScoop.

Continue reading Accused Chinese hackers abandon techniques after U.S. indictments

An FBI unit recovered $300 million of $3.5 billion in reported cybercrime losses last year

A special unit inside the FBI helped victims of cybercrime recover $300 million of the roughly $3.5 billion in reported losses in 2019, according to a top bureau official. Tonya Ugoretz, a deputy assistant director in the cyber division at the FBI, said Monday the Internet Crime Complaint Center (IC3) responded to more than 467,000 complaints in 2019, up from 351,937 complaints in 2018. Each one of the nearly 500,000 complaints submitted to the FBI was analyzed by an individual human who then determines whether to begin an investigation and, in some cases, try to recover stolen funds, Ugoretz said. The FBI first quantified the figures from last year in its annual IC3 report, published earlier this month. The same report included details about how reported losses from ransomware attacks doubled in the past year to $8.9 million, though the true figure likely is much higher, and that attacks increasingly […]

The post An FBI unit recovered $300 million of $3.5 billion in reported cybercrime losses last year appeared first on CyberScoop.

Continue reading An FBI unit recovered $300 million of $3.5 billion in reported cybercrime losses last year

Google gives the boot to more malware-laden apps posing as games for kids

Google has removed another eight apps from the Play Store after researchers determined hackers had been using the games and utility programs to spread malicious software. Users who downloaded the eight Android apps thought they were adding new features for their camera, or installing games meant for kids. In fact the apps, which had been downloaded some 50,000 times, either enrolled victims in expensive premium services without their consent, or installed the “Haken” malware, which siphons user data, researchers from Check Point Software Technologies said in a blog post Friday. The announcement came one day after BuzzFeed News reported that Google had scrubbed another 600 apps that had pushed out “disruptive” advertisements. It’s the latest in a long game of Whac-A-Mole between the security team overseeing the Play Store, and the scammers trying to exploit the app marketplace’s credibility to reach as many victims as possible. Yet the latest revelations […]

The post Google gives the boot to more malware-laden apps posing as games for kids appeared first on CyberScoop.

Continue reading Google gives the boot to more malware-laden apps posing as games for kids