Hide it well or market it well: Two reports show how point-of-sale malware has users in mind

Sometimes the little things can help cybercriminals separate their wares from the pack. It could be an uncommon feature in the malware itself, or it could just be a new way to market a familiar strategy. In unrelated reports Wednesday, cybersecurity companies detailed DMSniff, which takes a new approach to remaining stealthy as it steals point-of-sale (POS) information from consumers, as well as GlitchPOS, which steals credit-card information in a familiar way but comes with an instructional video from its creators. Threat intelligence company Flashpoint reports that DMSniff has quietly been in active use since 2016 thanks in part to a domain generation algorithm, which allows hackers to continue siphoning data from a web page even after police or researchers have taken hackers’ domain pages offline. Flashpoint notes that the use of such an algorithm is “rarely seen” in the smash-and-grab world of POS malware, where thieves typically distribute malware to as many sites as possible and […]

The post Hide it well or market it well: Two reports show how point-of-sale malware has users in mind appeared first on CyberScoop.

Continue reading Hide it well or market it well: Two reports show how point-of-sale malware has users in mind

Microsoft patches two zero-days exploited by FruityArmor, SandCat hacking groups

Microsoft has released security updates for two vulnerabilities that researchers say have been exploited by suspected nation-state hacking groups dubbed FruityArmor and SandCat. The March edition of Microsoft’s Patch Tuesday — when the company introduces fixes for reported security problems — includes 64 updates, 17 of which were rated as “critical.” Attackers already have leveraged at least two of the bugs, CVE-2019-0808 and CVE-2019-0797, according to researchers from Google and Russian security vendor Kaspersky Lab. Both bugs are known as elevation of privilege vulnerabilities, and could allow outsiders to manipulate Windows machines into authorizing an action that should not be allowed. “An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode,” Microsoft wrote in a security bulletin about the vulnerabilities. “An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.” The warning is not just theoretical. Kaspersky […]

The post Microsoft patches two zero-days exploited by FruityArmor, SandCat hacking groups appeared first on CyberScoop.

Continue reading Microsoft patches two zero-days exploited by FruityArmor, SandCat hacking groups

Backdoor discovered in Swiss voting system would have allowed hackers to alter votes

A team of cybersecurity researchers on Tuesday revealed technical flaws in the Swiss government’s electronic voting system that could enable outsiders to replace legitimate votes with fraudulent ones. The issue is related to the way Switzerland’s voting system receives and counts votes. Anyone familiar with the sequence of “shuffle proofs” — the cryptographic protocol the system relies on to verify votes — could manipulate ballots that would pass the system’s authentication test, according to a paper published by Sarah Jamie Lewis, Olivier Pereira and Vanessa Teague. Swiss Post, the country’s national postal service, which developed the system along with Scytyl, a Spanish company, said Tuesday the issue had been resolved. But researchers say this flaw personifies the kind of worst-case scenario election security experts have warned about as more governments move toward paperless voting. “This system as apparently been audited multiple times, and both Scytl and Swiss Post have not been […]

The post Backdoor discovered in Swiss voting system would have allowed hackers to alter votes appeared first on CyberScoop.

Continue reading Backdoor discovered in Swiss voting system would have allowed hackers to alter votes

Nearly 6,000 Twitter accounts magnified recent far-right messaging on Brexit, F-Secure says

Far-right Twitter accounts apparently originating in the U.S. amplified pro-Brexit propaganda between December and February and December, according to research published Tuesday by F-Secure, a Finnish cybersecurity company. An analysis of 24 million tweets related to Brexit from 1.65 million users uncovered “inorganic” activity on both sides of the debate, though disinformation was “far more” frequent in among supporters of the United Kingdom’s scheduled withdrawal from the European Union. “At the very least, our research shows there’s a global effort amongst the far-right to amplify the ‘leave’ side of the debate,” Andy Patel, a senior researcher with F-Secure’s Artificial Intelligence Center of Excellence, said in a statement Tuesday. Researchers determined that several separate accounts retweeted messages from @Brexiteer30, @UnityNewsNet and @JackBMontgomery, an editor with the alt-right Breitbart News. Nearly 6,000 accounts magnified messages from those three far-right accounts, F-Secure found. Many of those pages also included some version of #MakeAmericaGreatAgain […]

The post Nearly 6,000 Twitter accounts magnified recent far-right messaging on Brexit, F-Secure says appeared first on CyberScoop.

Continue reading Nearly 6,000 Twitter accounts magnified recent far-right messaging on Brexit, F-Secure says

Lawyers for alleged LinkedIn hacker appear ready to fight results of psychiatric evaluation

The ongoing court case tied to an accused Russian hacker took another turn last week when the results of his psychiatric evaluation became a topic of contention. Now court deliberations in the case of Yevgeniy Nikulin, an alleged hacker accused of breaching LinkedIn, are scheduled to continue after a court-ordered psychiatric evaluation sought to determine whether he was fit to stand trial. Nikulin, a Russian national, is set to be tried in U.S. court for allegedly hacking into LinkedIn and other websites in 2012, when prosecutors say some 117 million usernames and passwords were stolen. Nikulin has not communicated about the case with the attorneys representing him, a defense lawyer told CyberScoop, since meeting with Russian consulate officials shortly after his arrival in the U.S. in March 2018. Judge William Alsup ordered Nikulin to undergo a psychiatric evaluation, as CyberScoop reported in November. The results of that evaluation now are in and, […]

The post Lawyers for alleged LinkedIn hacker appear ready to fight results of psychiatric evaluation appeared first on CyberScoop.

Continue reading Lawyers for alleged LinkedIn hacker appear ready to fight results of psychiatric evaluation

Facebook suit accuses two Ukrainians of distributing adware disguised as quizzes

Facebook has accused two Ukrainian men of using quiz apps on the social media platform to inject malicious software on people’s computers, according to a lawsuit first noticed by the Daily Beast. By installing software extensions that masqueraded as Facebook quizzes, users unwittingly allowed the two men to inject advertisements into their news feeds and access their lists of friends, according to the lawsuit. That information then was exfiltrated to servers outside the country. The two men, Andrey Gorbahov and Gleb Sluchevsky, are Kiev-based entrepreneurs affiliated with a company called the Web Sun Group. The company did not respond to a request for comment from the Daily Beast Friday, and its website appeared to be down by Monday. “In total, Defendants compromised approximately 63,000 browsers used by Facebook users and caused over $75,000 in damages to Facebook,” the company claims in the lawsuit. The activity lasted from 2016 until October 2018 and primarily […]

The post Facebook suit accuses two Ukrainians of distributing adware disguised as quizzes appeared first on CyberScoop.

Continue reading Facebook suit accuses two Ukrainians of distributing adware disguised as quizzes

Can Google’s security push overcome the public’s eroded trust?

Google in the coming months will embark on a marketing campaign to raise awareness about a service the company says will better protect people accessing new websites. They just need users to trust them first, a tall order when roughly half of Americans polled by the Pew Research Center said they were “not at all” or “not too confident” tech firms would protect their data. Tech executives now are beginning to publicly reflect on the ramifications – specifically an erosion of trust – that occurs after big time data breaches, or scandals such as Facebook’s sharing data about 87 million users with Cambridge Analytica. It’s still early, and conversations are awkward, but the topic was a big theme at the Davos World Economic Forum in January as corporate bigwigs consider what it might mean if users stop trusting them with their information, said Justin Harvey, global incident response leader at Accenture Security. “There’s no litmus test for trust. […]

The post Can Google’s security push overcome the public’s eroded trust? appeared first on CyberScoop.

Continue reading Can Google’s security push overcome the public’s eroded trust?

A bot doesn’t need to talk like a bot for Twitter to notice

Twitter is tracking accounts’ behavior — and not necessarily the content they disseminate — to determine whether a user is misrepresenting their identity, a possible indication the account is used to amplify information operations. The approach is an attempt to solve a problem that keeps changing as nation-states look for any edge in cyberspace. While hackers continue to breach international networks to steal trade secrets and conduct espionage, they also use trusted social media outlets to exploit users in a way that is re-defining cyberwar, according to a panel of experts at the RSA cybersecurity conference. “This practice … may be having a greater outcome than what we think of as traditional cybersecurity,” said political scientist Peter W. Singer. “Is [cybersecurity] about critical infrastructure, or the poisoning of democracies?” Twitter examines accounts by assessing whether they are part of a larger network of users pushing the same types of information, […]

The post A bot doesn’t need to talk like a bot for Twitter to notice appeared first on CyberScoop.

Continue reading A bot doesn’t need to talk like a bot for Twitter to notice

How China used Western social media for a late-2018 charm offensive

More than 40,000 English-language social media posts that originated with six state-run Chinese media agencies reached millions of users on Instagram and other services over a span of four months concluding in January, according to research published Wednesday by the threat intelligence company Recorded Future. Xinhua, People’s Daily and others sought to subtly manipulate public opinion in the U.S. by promoting flattering images of Chinese culture, including tourist destinations and panda bears, rather than copying the hard-line rhetoric typically found in the Chinese-language versions of the same outlets, according to Recorded Future. Verified Instagram accounts run by both of those services posted roughly 26 times a day, reaching more than 5 million users between October 2018 and January. The effect is to overwhelm social media users in the West with positive images about China, potentially eroding their ability to think critically about a government that has been accused of committing […]

The post How China used Western social media for a late-2018 charm offensive appeared first on CyberScoop.

Continue reading How China used Western social media for a late-2018 charm offensive

Think of satellites as big, vulnerable IoT devices, researcher says

Orbiting hunks of metal make it possible for billions of earthlings to benefit from marvels of the digital age, from GPS signals and weather monitoring systems to the communication protocols for credit card authorizations and other complex transactions. Humans take these satellite connections for granted, but new research suggests we’ll need to take important steps to keep it way. As of January there were at least 1,957 satellites in orbit, according to the Union of Concerned Scientists, some of which are vulnerable to various levels of snooping and disruption, including jammed communications, data interception, data hijacking and outright takeovers. The issue is especially urgent now because of the coming wave of connected devices and the evolution of 5G cellular networks, said Bill Malik, vice president of infrastructure technologies at the security vendor Trend Micro, who presented research on satellite security Wednesday at the RSA cybersecurity conference. “We didn’t think about this much until the popularization of […]

The post Think of satellites as big, vulnerable IoT devices, researcher says appeared first on CyberScoop.

Continue reading Think of satellites as big, vulnerable IoT devices, researcher says