A zombie game with 50,000 Play Store downloads is pulling sensitive data from Gmail

An Android game with more than 50,000 downloads from the Google Play Store attempts to collect scores of data from users’ Google accounts — including Gmail usernames and passwords — alongside other dubious behaviors, according to forthcoming research provided exclusively to CyberScoop. Researchers from the mobile security company Wandera have identified the app, called “Scary Granny ZOMBY Mod: The Horror Game 2019,” as a malicious program that launches persistent full-screen advertisements on users’ phones, and asks some to enter their Google credentials. Upon receiving a victim’s username and password, the program automatically logs into users’ Google accounts and collects personal data for a purpose that researchers are still trying to determine, according to Michael Covington, vice president of product at Wandera. “There is no doubt in my mind that this app is malicious and puts private user data at risk,” he said. “It’s logging into the profile section of your Gmail and […]

The post A zombie game with 50,000 Play Store downloads is pulling sensitive data from Gmail appeared first on CyberScoop.

Continue reading A zombie game with 50,000 Play Store downloads is pulling sensitive data from Gmail

Lawyer for alleged LinkedIn hacker wants out, says client is ‘not sane’

The attorney for Yevgeniy Nikulin has had enough. Defense counsel Arkady Bukh has asked Judge William Alsup of the Northern District of California to allow him to withdraw as the lawyer for the Russian man accused of stealing more than 100 million usernames and passwords from LinkedIn, Dropbox, and other sites. The court filing in San Francisco on Tuesday marks the end of a chapter in Nikulin’s long and strange story. The alleged scammer arrived in the U.S. more than a year ago after he was arrested in Prague on charges related to stealing some 117 million usernames and passwords. Nikulin since then has refused to cooperate in his defense, and underwent a court-ordered psychiatric evaluation in which he ultimately was determined fit to stand trial. The defense team, led by Bukh, had embarked on novel legal strategy in which it would have asked the court to extradite Nikulin back […]

The post Lawyer for alleged LinkedIn hacker wants out, says client is ‘not sane’ appeared first on CyberScoop.

Continue reading Lawyer for alleged LinkedIn hacker wants out, says client is ‘not sane’

Spies targeting Saudi Arabia switched tactics after Symantec exposed them, report says

A cyber-espionage group widely believed to be carrying out attacks on behalf of the Iranian government resorted to new hacking tools after its malicious activity was unveiled earlier this year, according to research scheduled to be published Wednesday. The threat intelligence company Recorded Future determined the hacking group APT33 or “a closely aligned threat actor” has used more than 1,200 web domains to conduct cyberattacks since March 28. That’s the date researchers from Symantec released findings exposing an APT33 operation that targeted 50 organizations in Saudi Arabia and the United States. But Recorded Future also found that in the months since, APT33 apparently has resorted to new remote access trojans, which is yet another indication that suspected Iranian hackers are ramping up their activity amid ongoing international tension. “Our research found that APT33 or a closely aligned threat actor continues to conduct and prepare for widespread cyber-espionage activity … with a […]

The post Spies targeting Saudi Arabia switched tactics after Symantec exposed them, report says appeared first on CyberScoop.

Continue reading Spies targeting Saudi Arabia switched tactics after Symantec exposed them, report says

Another Florida city is making a ransomware payment, worth nearly $500,000 this time

It turns out that hackers are a lot like retirees. When they’re looking for an easier life, they go to Florida. Lake City, a city of about 12,000 people between Tallahassee and Jacksonville, on Tuesday agreed to pay ransomware hackers 42 bitcoins, the equivalent $490,421, to unlock phone and email systems following a cyberattack, according to the Gainesville Sun. An insurer is paying most of that, with the city kicking in $10,000, the newspaper reported. Lake City’s news follows similar actions by the government of Riviera Beach, on the state’s Atlantic coast, which agreed last week to pay roughly $600,000 to recover. City leaders throughout the U.S. undoubtedly took notice of that case as well as the aftermath of the May ransomware attack in Baltimore, which knocked digital services offline. It cost taxpayers roughly $18 million after lawmakers declined to pay a ransom once worth roughly $104,000. While many businesses hit with ransomware quietly pay the digital […]

The post Another Florida city is making a ransomware payment, worth nearly $500,000 this time appeared first on CyberScoop.

Continue reading Another Florida city is making a ransomware payment, worth nearly $500,000 this time

Former McAfee employees conspired to take ‘secret sauce’ to Tanium, lawsuit says

McAfee has filed a lawsuit against former employees, accusing them of conspiracy and stealing trade secrets before starting new positions at a competitor. In a suit filed Monday in the Eastern District Court of Texas, McAfee claims that three former sales staffers — Jennifer Kinney, Alan Coe and Percy Tejeda — conspired to breach their contracts and steal the “secret sauce” underlying McAfee’s sales tactics and customer strategies. The three left McAfee for Tanium, the lawsuit states, a rival endpoint-security firm, at various points throughout the past year. The case highlights the cutthroat nature of the security industry, a relatively small field where firms are in constant competition and employees frequently get offers to jump ship. Tejeda, McAfee’s former director of finance, was the first employee to accept a new position at Tanium, according to the complaint. He then recruited Kinney, who formerly reported to Tejeda at McAfee, and Coe […]

The post Former McAfee employees conspired to take ‘secret sauce’ to Tanium, lawsuit says appeared first on CyberScoop.

Continue reading Former McAfee employees conspired to take ‘secret sauce’ to Tanium, lawsuit says

Facebook fails to kill class-action lawsuit over data breach

A proposed class action lawsuit against Facebook will move forward after a judge disagreed with the company’s contention it should not be held liable for failing to protect users’ information. Facebook last year announced that a data breach allowed hackers to make off with information about some 30 million people. A vulnerability in Facebook’s code enabled outsiders to access to users’ digital access tokens, which make it possible to visit the site without logging in each time. The company had previously claimed that some of the plaintiffs’ information was not “sensitive” because it was accessible on a public Facebook profile and no real harm had been done because attackers had failed to steal users’ financial information and passwords. Additionally, the company said it should be absolved from responsibility due to the sophistication of the hack. U.S. District Judge William Alsup disagreed, ruling on June 21 that the evidence-gathering phase of the […]

The post Facebook fails to kill class-action lawsuit over data breach appeared first on CyberScoop.

Continue reading Facebook fails to kill class-action lawsuit over data breach

Dell quietly patched a security vulnerability that affected millions of users

Computing giant Dell released a security advisory Thursday encouraging customers to patch a software vulnerability the company says could have enabled hackers to access sensitive information on “several million” machines running Microsoft Windows. The unnamed issue in Dell’s SupportAssist application could have allowed outsiders to take over a machine and read the stored physical memory, according to SafeBreach Labs, a California network security company. Dell released its security patch to fix this issue on May 28, and a spokesperson says more than 90 percent of customers have recieved the update. Dell waited three weeks to go public with the advisory to allow time for PC Doctor, the third-party supplier behind the component responsible for the vulnerability, to release its own advisory. SafeBreach did not provide any evidence hackers exploited the vulnerability, but such a flaw would be a tempting target for hackers. The tool comes preinstalled on Dell computers and helps customers check the health of both hardware and software. Those tasks require a high level of permission, and abusing such […]

The post Dell quietly patched a security vulnerability that affected millions of users appeared first on CyberScoop.

Continue reading Dell quietly patched a security vulnerability that affected millions of users

AMCA parent company files for bankruptcy amid data breach fallout

The debt collection agency responsible for a data breach that compromised information on at least 20 million people has declared bankruptcy. U.S.-based Retrieval-Masters Creditors Bureau Inc., which collects medical bills under the name American Medical Collection Agency (AMCA), filed for bankruptcy protection in the Southern District of New York. The filing comes after the company learned of a data breach lasting from August 1, 2018 to March 30 affecting information on millions of patients at testing firms Quest Diagnostics and LabCorp. AMCA’s four largest clients soon ceased operations with the company. Affected companies included Quest, with information about some 11.9 million people involved, LabCorp with 7.7 million, Carecentrix with 500,000 patients hit, and Bio Reference Labs with 423,000 patients. Numerous class-action lawsuits also have been filed, with plaintiffs alleging an unreasonable breach notification delay, a lack of reasonable data security and possible violations of the Health Insurance Portability and Accountability […]

The post AMCA parent company files for bankruptcy amid data breach fallout appeared first on CyberScoop.

Continue reading AMCA parent company files for bankruptcy amid data breach fallout

Key witness in press-release hacking case is sentenced to time served

It look like the legal troubles are over for Alexander Garkusha, one of the key figures in a case involving Wall Street high-rollers and Ukrainian hackers. U.S. District Judge Raymond Dearie on Monday sentenced Garkusha, a Georgia real estate developer, to time served for his role in a $30 million scheme to trade stocks based on information gleaned from hacked press releases. The Russian-born U.S. citizen served as a cooperating witness against other defendants. Garkusha has, “in effect, been on probation” since his arrest in August 2015, his attorney said in a court filing. He was arrested in August 2015, along with four others, as part of a criminal securities fraud case that began after hackers breached PR Newswire, Marketwire and Business Wire and gathered unreleased financial news. Authorities said Garkusha traded on that inside information, and he pleaded guilty later that year to conspiracy to commit wire fraud. Dearie this week cited Garkusha’s “thorough” and “compelling” testimony in the case […]

The post Key witness in press-release hacking case is sentenced to time served appeared first on CyberScoop.

Continue reading Key witness in press-release hacking case is sentenced to time served