Payment scammers hit 201 campus checkouts with Magecart-inspired tactics

A gang of payment-card scammers has targeted 201 college and university campus stores, trying to steal students’ financial data in a Magecart-style attack, according to new research. The new cybercrime group, labeled Mirrorthief, injected malicious code on payment checkout pages at hundreds of U.S. and Canadian stores, according to TrendMicro research published Friday. By compromising PrismWeb, an e-commerce platform designed for college stores, the attackers could collect payment card details, names, addresses and phone numbers, researchers said. PrismWeb is made by PrismRBS, a subsidiary of the Nebraska Book Company. TendMicro’s report comes as security researchers continue to grapple with an expansion of payment-card thievery along with an apparent surge in demand for stolen financial information. Success by one group inspires imitators in another. The most prominent, Magecart, is a collection of perhaps 12 hacking campaigns that steal payment information by secretly collecting data from online checkout pages. TrendMicro researchers noted that Mirrorthief is […]

The post Payment scammers hit 201 campus checkouts with Magecart-inspired tactics appeared first on CyberScoop.

Continue reading Payment scammers hit 201 campus checkouts with Magecart-inspired tactics

Ukrainian national accused of spreading millions of malicious ads by posing as a CEO

Another indictment unveiled by the U.S. Department of Justice this week provides more detail on how American authorities are trying to bring accused international advertising scammers to justice stateside. Prosecutors have charged Oleskii Ivanov, a 31-year-old Ukrainian, with computer fraud, wire fraud and conspiracy to commit wire fraud as part of an alleged scheme to launch advertising campaigns containing malicious software between 2013 and 2018. Ivanov and his unnamed co-conspirators caused unsuspecting web users to view more than 100 million of these advertisements, including in banners and other prominent website locations, according to the indictment filed by Craig Carpenito, U.S. attorney for the District of New Jersey. The indictment does not specify how much money members of the “malvertising” conspiracy made, though it says, “Ivanov and his co-conspirators attempted to cause millions of dollars of losses to victim internet users.” Security researchers have taken an increasing interest lately in the blurred line between […]

The post Ukrainian national accused of spreading millions of malicious ads by posing as a CEO appeared first on CyberScoop.

Continue reading Ukrainian national accused of spreading millions of malicious ads by posing as a CEO

International cops shutter two dark web sites, arrest three accused of running Wall Street Market

International law enforcement agencies have announced the shutdown of the Wall Street Market and the Valhalla Marketplace, two dark web marketplaces known for the sale of drugs, stolen data and other illicit materials. Europol announced Friday that Germany’s Federal Criminal Police shuttered the Wall Street Market, one of the most popular markets, and arrested three suspects accused of running the site. The forum was accessible only with the Tor browser, and featured more than 1.15 million customer accounts and 5,400 registered sellers who accepted payments in bitcoin and Monero, Europol said. The Valhalla Marketplace, also known as Silkkitie, was shut down earlier this year by French and Finnish authorities. “These two investigations show the importance of law enforcement cooperation at an international level and demonstrate that illegal activity on the dark web is not as anonymous as criminals may think,” Catherine De Bolle, Europol’s executive director, said in a statement. The […]

The post International cops shutter two dark web sites, arrest three accused of running Wall Street Market appeared first on CyberScoop.

Continue reading International cops shutter two dark web sites, arrest three accused of running Wall Street Market

No longer clicking: Online ad fraud has fallen in the past year

Online advertising fraud will cost digital marketers $5.8 billion this year, down from $6.5 billion the year before, according to new research. The forecast arrived in a report published Wednesday by White Ops and the Association of National Advertisers, providing a sliver of hope for ad companies who have lost money by paying for access to humans who don’t actually exist. This year’s decline can be attributed to the adoption of the ads.txt anti-spoofing protocol and incremental advances in more secure video advertising technology. But it’s also clear that ad-fraud rings also are updating their strategies, and looking for new ways to make a buck. “Less fraud means less revenue lost to cybercriminals,” the report states. “And increased implementation of cybersecurity defenses, raising the cost and risk of the crime, has helped to dissuade some would-be fraudsters from pursuing this line of cybercrime altogether.” Ad fraud works in a variety of […]

The post No longer clicking: Online ad fraud has fallen in the past year appeared first on CyberScoop.

Continue reading No longer clicking: Online ad fraud has fallen in the past year

Meet Sodinokibi, a ransomware strain that exploits a critical Oracle server flaw

Hackers are exploiting a critical vulnerability in a widely used Oracle service to distribute a new strain of ransomware that attempts to encrypt data in a user’s directory, then make recovery more difficult by deleting trustworthy backups, according to research published Tuesday. Attackers are trying to infect victims with a new variant of the Sodinokibi ransomware by leveraging a known security flaw in Oracle’s WebLogic Server, according to Cisco’s Talos threat research team. The digital extortionists are exploiting the flaw known as CVE-2019-2725, a bug with a severity score of 9.8 out of 10 that Oracle sought to squash with a patch issued April 26, outside the company’s normal patch cycle. “Historically, most varieties of ransomware have required some form of user interaction, such as a user opening an attachment to an email message, clicking on a malicious link, or running a piece of malware on the device,” Cisco’s Talos […]

The post Meet Sodinokibi, a ransomware strain that exploits a critical Oracle server flaw appeared first on CyberScoop.

Continue reading Meet Sodinokibi, a ransomware strain that exploits a critical Oracle server flaw

Russian charged with stealing $1.5 million in hacks on U.S. tax preparers

U.S. authorities have charged a Russian citizen in a scam that netted $1.5 million through bogus tax returns between June 2014 and November 2016, the Department of Justice announced Monday. Anton Bogdanov — who went by “Kusok,” according to court documents — is accused of computer intrusion, aggravated identity theft and other wrongdoing as part of his alleged role in a plot to combine hacking with traditional fraud techniques to steal money from the U.S. government. Bogdanov and others leveraged access to hacked computers at private U.S. tax preparation firms to steal individuals’ personal information, exploiting a vulnerability in an unnamed remote access program used by accountants to log in from home and while traveling, according to the indictment. They allegedly would use that access to change the information on victims’ tax returns, and redirect their refunds to debit cards under the thieves’ control, according to the Justice Department. Those debit cards […]

The post Russian charged with stealing $1.5 million in hacks on U.S. tax preparers appeared first on CyberScoop.

Continue reading Russian charged with stealing $1.5 million in hacks on U.S. tax preparers

Man who allegedly leaked CIA hacking tools says he’s been tortured and is owed $50 billion

A former CIA computer engineer compared himself to a victim of the Nazis and said the government has caused him to lose more than $50 billion in income in a new court filing accusing the U.S. Department of Justice of violating his civil rights. Joshua Schulte, a former software engineer, has filed a preliminary complaint seeking immediate release from federal detention, according to court documents filed earlier this month. Schulte was arrested in 2017, accused of crimes including sexual assault, possessing child pornography and, later, providing documents detailing CIA hacking capabilities to WikiLeaks. Schulte now argues that he has suffered “irreparable harm from torture imposed by the Federal Terrorists” and that he needs to be released in order to prepare a legal defense. The complaint was first noticed by independent journalist Marcy Wheeler. His argument asserts that there is no difference between pretrial detention and federal incarceration. It then goes on […]

The post Man who allegedly leaked CIA hacking tools says he’s been tortured and is owed $50 billion appeared first on CyberScoop.

Continue reading Man who allegedly leaked CIA hacking tools says he’s been tortured and is owed $50 billion

Anonymous offshoots rush to avenge Assange arrest with cyberattacks

Hackers have launched a series of uncoordinated cyberattacks against British and Ecuadorian targets over the past week in apparent retaliation for the arrest of WikiLeaks founder Julian Assange. A member of a group calling itself the Philippine Cyber Eagles, an Anonymous offshoot with fewer than 20 Twitter followers as of Friday morning, earlier this week released a 44 MB file containing documents purportedly stolen from police agencies throughout the United Kingdom. The file does not appear to contain personal information, though it does include spreadsheets, press releases, and Microsoft Excel files dated from February 2019. That data dump came on the same day another self-described Anonymous group claimed to knock offline Police.UK, a Home Office website, with a distributed denial-of-service attack — a blunt digital assault technique that overwhelms sites with falsified traffic. Other groups launched similar attacks against town councils in Barnsley, South Yorkshire, and Bedale, located north of Leeds. […]

The post Anonymous offshoots rush to avenge Assange arrest with cyberattacks appeared first on CyberScoop.

Continue reading Anonymous offshoots rush to avenge Assange arrest with cyberattacks

Facebook security notice announces millions of Instragram users had their passwords stored in plaintext

Facebook confirmed Thursday that password credentials belonging to millions of Instagram users were stored in an insecure format.  The company quietly updated a blog post first published March 21 to say millions of Instagram passwords, not tens of thousands as initially stated, were stored in a readable format accessible by company employees dating back to 2012. The social media company did not specify how many millions of users were affected. “We will be notifying these users as we did the others,” the company said in its update. “Our investigation has determined that these stored passwords were not internally abused or improperly accessed.” Facebook last month said an internal investigation had determined that hundreds of millions of users’ passwords were stored in a format that could have allowed employees to view them. More than 20,000 employees could have accessed information about between 200 million and 600 million users, KrebsOnSecurity reported at […]

The post Facebook security notice announces millions of Instragram users had their passwords stored in plaintext appeared first on CyberScoop.

Continue reading Facebook security notice announces millions of Instragram users had their passwords stored in plaintext

Millions of records about Middle Eastern drivers left in an insecure database

Records containing sensitive information on perhaps millions of Iranian drivers was left unsecured in a publicly available database for days, according to security research published Thursday. More than 6.7 million records from 2017 and 2018 were estimated to be exposed in a database discovered by researcher Bob Diachenko. Information included drivers’ first and last names, their Iranian ID numbers stored in plain text, their phone numbers, and other data such as invoice information. The data is now secured, Diachenko told CyberScoop. The actual number of people affected in the breach is likely less than 6.7 million, Diachenko explained, because the database contains multiple files referring to the same people. While the origin of the data remains unclear, Diachenko suggested it may have been stolen from the Iranian ride-hailing companies Snapp and/or TAP30. “[W]e can only guess if this data was part of their infrastructure,” he wrote in a post published Thursday. […]

The post Millions of records about Middle Eastern drivers left in an insecure database appeared first on CyberScoop.

Continue reading Millions of records about Middle Eastern drivers left in an insecure database