Russian hacker who allegedly exploited accounting software to steal $1.5 million to plead guilty

A Russian man accused of stealing $1.5 million as part of a scam that relied on using fraudulent tax returns to intercept cash meant for Americans is preparing to plead guilty. U.S. prosecutors charged Anton Bogdanov, known online as “Kusok,” with computer intrusion, aggravated identity theft and related charges for alleged activity between June 2014 and November 2016. Bogdanov and a team of associates used information purloined from hacked computers at American tax firms to change clients’ personal information, according to an indictment made public in April. By leveraging a security flaw in a remote access program used by accountants, Bogdanov and his crew allegedly changed client data so legitimate tax refunds would be delivered to the thieves in th form of debit cards. Bogdanov was arrested while on vacation in Thailand in November 2017 and extradited to the U.S. in March. Now, his attorney said in a Dec. 15 […]

The post Russian hacker who allegedly exploited accounting software to steal $1.5 million to plead guilty appeared first on CyberScoop.

Continue reading Russian hacker who allegedly exploited accounting software to steal $1.5 million to plead guilty

New Jersey hospital chain pays attackers to thwart ransomware incident

New Jersey’s largest hospital system said last week it paid an extortion fee to hackers who had disrupted medical facilities with a ransomware attack. Hackensack Meridian Health, based in Edison, New Jersey, said Dec. 13 it was working to restore its computer systems following a Dec. 2 ransomware attack that forced administrators to cancel roughly 100 elective medical procedures. The nonprofit, which operates 17 clinics and hospitals, cautioned that no patients were harmed as a result of the attack. It did not say how much it paid ransomware attackers to unlock medical systems. “We believe it’s our obligation to protect our communities’ access to health care,” the nonprofit said in a statement. Ransomware attacks typically begin with an email containing a malicious link or attached document that infects victims’ computers. Once inside, scammers seek to infiltrate more sensitive areas of the network, encrypting data or disabling services along the way. […]

The post New Jersey hospital chain pays attackers to thwart ransomware incident appeared first on CyberScoop.

Continue reading New Jersey hospital chain pays attackers to thwart ransomware incident

No more delays: Judge in Vault 7 case sets trial date

It looks like the judge presiding over the case of a former Central Intelligence Agency employee accused of providing U.S. secrets to WikiLeaks is out of patience. Judge Paul Crotty of the U.S. Southern District of New York declared in a court filing Monday that the trial of Joshua Schulte will begin on Feb. 3, 2020, nearly a month after the anticipated Jan. 12 trial start and three months after the previously scheduled date of Nov. 4, 2019. The decision comes after a long series of delays from Schulte’s defense attorneys, who have argued they needed the court to add another lawyer to the defense, and that they failed to understand some of the government’s allegations against Schulte despite repeated explanations from prosecutors. Schulte’s team also requested on Dec. 5 the court grant an extension to file a response to a motion related to the handling of classified material in the […]

The post No more delays: Judge in Vault 7 case sets trial date appeared first on CyberScoop.

Continue reading No more delays: Judge in Vault 7 case sets trial date

Google expands Chrome’s anti-phishing tools as hackers’ obsession with credentials continues

Google says it will now warn users when they are potentially visiting a phishing page in the Chrome browser, a plan that coincides with a wider company effort to alert people when they are being targeted by state-sponsored cyberattacks and other threats to their digital identity. In a blog post Tuesday Google said it would expand “predictive phishing protection” in the Chrome browser. The goal is to check in real-time if scammers are leveraging websites, advertisements, chat apps or other channels to try to steal Chrome users’ credentials. The effort marks an improvement from the previous option, in Google’s Safe Browsing mode, which relied on a block list that Google updated every 30 minutes. It’s also the latest example of a technology company trying to mitigate the risks associated with usernames and passwords as means of validating a user’s identity. While biometric authentication has become common on smartphones, Microsoft also has […]

The post Google expands Chrome’s anti-phishing tools as hackers’ obsession with credentials continues appeared first on CyberScoop.

Continue reading Google expands Chrome’s anti-phishing tools as hackers’ obsession with credentials continues

Possible APT attacks against Ukraine expand to target journalists, researchers say

A suspected Russian hacking campaign that’s resulted in attacks against Ukrainian military and government agencies also has affected journalists, law enforcement and nongovernmental organizations, according to new findings. Gamaredon, a hacking group that has been active since 2013 and mostly haunted Ukrainian government targets, has broadened its reach within that country, the threat intelligence company Anomali said in research published Dec. 5. Anomali did not identify any Gamaredon targets by name, other than the Ministry of Foreign Affairs, and said it remains unclear if attackers successfully have breached the targeted people and organizations. The attempted attacks were ongoing as of Dec. 6 after beginning in mid-September, Anomali said. If Gamaredon is behind the hacking attempts, as Anomali has assessed, the campaign represents an expansion of the group’s interests. The advanced persistent threat (APT) group, which Fortinet previously reported has “strong Russian ties,” based on a language analysis, has sought to breach Ukrainian public […]

The post Possible APT attacks against Ukraine expand to target journalists, researchers say appeared first on CyberScoop.

Continue reading Possible APT attacks against Ukraine expand to target journalists, researchers say

U.S. charges two Russians in connection with Dridex banking malware

U.S. prosecutors have charged two Russian nationals, including one member of the FBI’s “Most Wanted” list, in connection with two years-long hacking and fraud campaigns that resulted in the theft of millions of dollars from American organizations. The Department of Justice charged Maksim Yakubets and Igor Turashev with involvement in the development and distribution of the malicious software known as Bugat. Bugat is a predecessor to Dridex, a banking malware strain that has haunted international victims for more than eight years, while prosecutors said Yakubets also was involved with Zeus, another pernicious hacking tool. Both suspects remain at large in Russia. Prosecutors unsealed the indictment against Yakubets and Turashev in conjunction with U.S. sanctions against Evil Corp, which the Treasury Department says is the criminal organization, led by Yakubets, behind the Dridex malware. Yakubets also has provided direct assistance to the Russian government’s “malicious cyber efforts, highlighting the Russian government’s […]

The post U.S. charges two Russians in connection with Dridex banking malware appeared first on CyberScoop.

Continue reading U.S. charges two Russians in connection with Dridex banking malware

Scammers dupe Chinese venture capitalists out of $1 million with the ‘ultimate’ BEC heist

Scammers fleeced a Chinese venture capital firm out of a $1 million payment meant for a startup by using malicious emails to steal the cash, according to new findings from Check Point Technologies. As part of the scheme, thieves posed as employees from an Israeli company hoping to raise seed funding from Chinese venture capitalists. By using email addresses that appeared remarkably similar to the actual startup, thieves posed as real Israeli employees in communications with an account manager at the Chinese investment firm. It was only after the $1 million payment went through when the actual startup realized it hadn’t received its payment, and the Chinese VC firm began to understand it’s money was gone. Check Point did not identify either company by name in a blog post Thursday, saying only the incident occurred early in 2019. Unlike a traditional business email compromise, when hackers infiltrate a high-level corporate […]

The post Scammers dupe Chinese venture capitalists out of $1 million with the ‘ultimate’ BEC heist appeared first on CyberScoop.

Continue reading Scammers dupe Chinese venture capitalists out of $1 million with the ‘ultimate’ BEC heist

AIG subsidiary tells court it’s not responsible for Landry’s legal costs in $20 million lawsuit filed after breach

An insurance company is arguing in court it should not be responsible for covering a $20 million lawsuit filed in connection with a data breach at a national restaurant and hospitality chain. The Insurance Company of the State of Pennsylvania, an AIG subsidiary, argued in the U.S. Court of Appeals for the Fifth Circuit on Nov. 25 that it does not need to fund a legal defense for the Landry’s restaurant chain following a breach uncovered in 2015. JP Morgan Chase and its payment processing arm, Paymentech, filed suit in 2018 against Landry’s, alleging the company has failed to compensate the bank for breach-related costs. Chase accused Landry’s, which operates Bubba Gump Shrimp, Rainforest Café and Joe’s Crab Shack locations, among others, of failing to reimburse the bank for post-breach assessments conducted by Visa and Mastercard. Hackers spent months lurking inside Landry’s systems from 2014 to 2015, accessing customers’ payment […]

The post AIG subsidiary tells court it’s not responsible for Landry’s legal costs in $20 million lawsuit filed after breach appeared first on CyberScoop.

Continue reading AIG subsidiary tells court it’s not responsible for Landry’s legal costs in $20 million lawsuit filed after breach

Amid stock dip, Palo Alto Networks says it wants to acquire another vendor

Palo Alto Networks announced its intention to acquire Aporeto, a cloud and identity vendor, at a time when Wall Street seems to be unsure about how to value the cybersecurity giant’s stock. Palo Alto said Monday it plans to purchase Aporeto, which helps customers improve their cloud access controls, for $150 million in cash. News of the deal came on the same day shares of Palo Alto Networks fell 8.45% in extended trading to $229.14 per share. Prices fell again Tuesday, sitting at a price around $220 as of mid-afternoon. The deal is expected to close during Palo Alto’s second fiscal quarter, and marks only the latest acquisition for the $27 billion company. It announced in September it would announce the internet of things startup Zingbox, said in May that it would acquire Twistlock and PureSec and, in March, revealed its plan to spend $560 million on Demisto. Aporeto previously raised $20 million in […]

The post Amid stock dip, Palo Alto Networks says it wants to acquire another vendor appeared first on CyberScoop.

Continue reading Amid stock dip, Palo Alto Networks says it wants to acquire another vendor

European police remove 26,000 pieces of Islamic State content from social media

European police agencies in recent days have removed a number of servers that the Islamic State terrorist group relied on to communicate internally, and amplify propaganda. In a statement Monday, Europol said it worked with internet companies like Google and Twitter to remove messaging from the group. Authorities said they eliminated 26,000 pieces of content from several sites, such as videos, social media accounts, communication channels and posts. Police have described the takedown as a major blow to the extremist’s radicalization efforts. Police in Spain’s Canary Islands also arrested one suspect accused of being “part of the core disseminators” of the group’s recruitment and radicalization efforts. “Prevention is a crucial part of the fight against terrorism because, when we disrupt the propaganda machine of terrorist organizations, we also disrupt radicalization, the recruitment of potential terrorists and also further spreading of the message that could lead to terrorist attacks,” said Ladislav […]

The post European police remove 26,000 pieces of Islamic State content from social media appeared first on CyberScoop.

Continue reading European police remove 26,000 pieces of Islamic State content from social media