Ransomware outbreak hits hospitals in England, companies in Spain

A large number of companies in England and Spain were hit by major ransomware attacks on Friday. Hospitals across England were forced to divert emergency patients, according to the National Health Service. Other hospitals are asking patients to avoid coming in except for emergencies, news reports said. In Spain, victims including the telecommunications company Telefónica have been forced the company to tell employees to shut down machines and networks in an effort to stop the spread of the malware. Other victims include Gas Natural and Iberdrola, an electric utility firm. Spanish authorities confirmed the ransomware is a version of WannaCry (also known as WannaCrypt0r), according to the National Cryptology Center. In Spain, El Mundo is reporting that “early indications point to an attack originating in China.” Less is known about the English attacks. Trusts and Hospitals in London and across England have been hit. St Bart’s in London, which was hit with ransomware on […]

The post Ransomware outbreak hits hospitals in England, companies in Spain appeared first on Cyberscoop.

Continue reading Ransomware outbreak hits hospitals in England, companies in Spain

U.S. intel officials slam Kaspersky while CEO calls fears of Russian influence ‘unfounded conspiracy theories’

Eugene Kaspersky, the namesake and CEO of the famed cybersecurity company Kaspersky Lab, spent Thursday refuting accusations that his Moscow-based cybersecurity company could be used to spy on key U.S. systems, as the idea continued to circulate in Washington. At a Senate Intelligence Committee hearing Thursday morning, Ted Cruz, R-Texas, asked top American intelligence officials if any of them would use Kaspersky products, which are found on computers throughout the U.S., including those of major businesses. “A resounding no from me,” Director of National Intelligence Daniel Coats testified. Every one of the witnesses, including acting FBI Director Andrew McCabe and Adm. Mike Rogers, who runs the NSA and U.S. Cyber Command, agreed. Earlier this week, several outlets had reported increasing concerns about American officials that Russian spies could use Kaspersky Lab’s software or personnel against American interests. Kaspersky himself hosted a question-and-answer session on Reddit’s /r/IAmA forum Thursday, and all of the top questions addressed the […]

The post U.S. intel officials slam Kaspersky while CEO calls fears of Russian influence ‘unfounded conspiracy theories’ appeared first on Cyberscoop.

Continue reading U.S. intel officials slam Kaspersky while CEO calls fears of Russian influence ‘unfounded conspiracy theories’

Macron leaks contained phishing links to domains associated with APT28, researchers say

The hacked emails leaked last week from the campaign of French President-elect Emmanuel Macron contain phishing links pointing to domains associated with Fancy Bear, the hacking group also known as APT28 that has been linked to Russian intelligence agencies, according to the cybersecurity firm Flashpoint. “Flashpoint’s hypothesis [is] that the Macron leak was undertaken by Fancy Bear based on the contents of the dump itself, as well as the current and historic political environment in which this attack took place,” said Vitali Kremez, research director for Flashpoint. The same group was blamed for hacking Hillary Clinton’s campaign and the Democratic National Committee in 2016, and researchers have recently linked other high-profile phishing attempts to the group. “These domains were likely registered and deployed in the phishing emails in order to harvest the login credentials of Macron campaign personnel,” Kremez said. “These credentials could have provided hackers with the information needed to obtain the documents in the […]

The post Macron leaks contained phishing links to domains associated with APT28, researchers say appeared first on Cyberscoop.

Continue reading Macron leaks contained phishing links to domains associated with APT28, researchers say

Staples hires first-ever CISO

Office-supply chain Staples, having recovered from a point-of-sale hack affecting 1.16 million credit and debit cards two years ago, has hired its first-ever chief information security officer. The new CISO, Brett Wahlin, had held the same position at Hewlett-Packard Enterprise since 2013. His resume includes other high-profile positions in and out of government. He started his career as a counterintelligence agent in the U.S. Army and at one point was CISO at Los Alamos National Laboratory. He also served as chief security office at McAfee from 2009-11 and then CSO at Sony Network Entertainment until 2013. He joined Sony right after a headline-grabbing intrusion against the PlayStation network that led to the theft of personal information from 77 million accounts. HPE was part of a data breach in October 2016 when when an employee’s laptop was compromised. The machine contained the names and Social Security numbers of 134,386 current and former U.S. Navy personnel and was accessed by “unknown […]

The post Staples hires first-ever CISO appeared first on Cyberscoop.

Continue reading Staples hires first-ever CISO

NSA alerted France to ‘Russian activity’ against presidential campaign targets, Rogers says

The U.S. National Security Agency tracked Russian hackers working against French political targets and then alerted French authorities prior to the “massive and coordinated hack” against the campaign of President-elect Emmanuel Macron, the NSA’s chief said Tuesday. Macron won convincingly even though the hack resulted in a massive email dump about a day before French voters headed to the polls, but upcoming crucial elections across Europe have raised alert levels for Western intelligence agencies tasked with fighting Russian interference. Adm. Michael Rogers, who leads both the U.S. Cyber Command and the NSA, testified before the Senate Armed Services Committee on Tuesday. He was asked about the United States’ role in protecting elections inside and outside of U.S. borders. “We had become aware of Russian activity,” Rogers said. “We had talked to our French counterparts prior to the public announcements of the events that were publicly attributed this past weekend. We said, ‘Look we are watching […]

The post NSA alerted France to ‘Russian activity’ against presidential campaign targets, Rogers says appeared first on Cyberscoop.

Continue reading NSA alerted France to ‘Russian activity’ against presidential campaign targets, Rogers says

Hacking against France’s Macron previews dangers for other major European elections

Last week’s “massive and coordinated hack” against the campaign of French President-elect Emmanuel Macron was the opening act in a year slated with critical European elections that will help decide the fate of the EU. The incident was, for about 24 hours, a hold-your-breath moment for Macron’s campaign. By Sunday night, the centrist candidate handily won, taking more than 66 percent of the vote over far-right-wing rival Marine Le Pen. Le Pen’s global array of opponents exhaled. But any reprieve for election systems’ cyber-defenders is destined to be brief. The United Kingdom, Germany and France are readying themselves for further elections and similar potential attacks. Experts have noted close similarities between this week’s leaked emails and hacks against American political targets in 2016 that were blamed widely on Russian intelligence agencies. While most experts say it’s too early yet to definitively attribute these latest attacks to any specific group, many expect the coming year to be […]

The post Hacking against France’s Macron previews dangers for other major European elections appeared first on Cyberscoop.

Continue reading Hacking against France’s Macron previews dangers for other major European elections

French presidential candidate Macron suffers ‘massive and coordinated hack’

The campaign of French presidential candidate Emmanuel Macron was targeted by a “massive and coordinated hack,” according to a statement from the campaign late Friday. A large collection totaling nine gigabytes of emails purportedly from the campaign was posted online less than two days before the country’s election in which Macron faces off against Marine Le Pen. Macron, who has accused Russia of cyberattacks against his campaign in the past, was targeted this year by the hacking group Fancy Bear, according to the cybersecurity firm Trend Micro. Fancy Bear has widely been linked to Russian intelligence operations and is one of the groups that hacked into U.S. political institutions including the Democratic National Committee and the Hillary Clinton campaign in 2016. Macron’s political movement En Marche! (Onwards!) confirmed that it had been hacked, according to Reuters. “The En Marche! Movement has been the victim of a massive and coordinated hack this evening which has given rise to the […]

The post French presidential candidate Macron suffers ‘massive and coordinated hack’ appeared first on Cyberscoop.

Continue reading French presidential candidate Macron suffers ‘massive and coordinated hack’

Monero mining botnet earns suspected Chinese hacker $25,000 per month

Mining cryptocurrencies can be a costly investment, but creative cybercriminals have found a money-making solution. Researchers say a newly discovered botnet consisting of 15,000 machines is stealing computing power to mine increasingly valuable cryptocurrencies like Monero to enrich a hacker named “Bond007.01.” The entire “BondNet botnet” operation is netting around $25,000 per month, according to researchers at the Israeli security firm GuardiCore Labs. The victims include high-profile global companies, universities, city councils and other public institutions. They’re not losing money, just resources: Hackers have long known that when you don’t have to pay for the electricity powering the processors, cryptocurrency mining is pure profit. As bitcoin and its variants continue to rise to unprecedented value, the reward for such a scheme will increasingly outweigh the risk. The price of Monero, a privacy-focused cryptocurrency that hides transactions, has risen 2,109 percent in the last year. The last month alone has seen a 44 percent rise in […]

The post Monero mining botnet earns suspected Chinese hacker $25,000 per month appeared first on Cyberscoop.

Continue reading Monero mining botnet earns suspected Chinese hacker $25,000 per month

OAuth-based phishing campaign gives Gmail users a scare

An immense phishing campaign targeting Google accounts hit a wide array of journalists, government employees, academics and private company email accounts. This is what the attack looks like: The email has been landed in newsrooms from BuzzFeed to ABC, at universities and reportedly from addresses within the Chicago city government. The “Open in Docs” link redirects to the OAUTH2 service on accounts.google.com, according to researcher Bojan Zdrnja, where it asks for full access to the GMail account and all contacts from an application deceptively named “Google Docs.” Once access is granted, the attacker uses that account to send phishing emails to every contact in the victim’s contact list. OAuth is a mechanism companies like Google use that allows users to authorize apps and websites to access account information without giving away a password. For example, a third-party email app will want access to your GMail and will ask for permission through OAuth. […]

The post OAuth-based phishing campaign gives Gmail users a scare appeared first on Cyberscoop.

Continue reading OAuth-based phishing campaign gives Gmail users a scare

Under tough surveillance, China’s cybercriminals find creative ways to chat

Think of it as hiding in plain sight. Ninety-nine percent of Chinese cybercriminals communicate over instant messenger apps like QQ and WeChat, according to research from the cybersecurity firm Flashpoint. Both apps are wildly popular in China and almost nowhere else. The apps, which are both owned and operated by the multibillion-dollar Chinese tech giant Tencent, cooperate directly and extensively with expansive government censorship and surveillance. To the outside, it would seem to be a barren and dangerous environment for coordinating criminal enterprises. That doesn’t stop the hackers, though. “You would imagine that people who are engaging in illicit activities would at least make an effort to use a platform that’s not explicitly monitored by the regime, right?” says Jon Condra, Flashpoint’s Director of East Asian Research and Analysis. To beat government surveillance, China’s cybercriminal underground deploy technical, typographic and linguistic tricks that can make tracking them increasingly difficult. In Russia, by stark contrast, Jabber reigns as the messenger […]

The post Under tough surveillance, China’s cybercriminals find creative ways to chat appeared first on Cyberscoop.

Continue reading Under tough surveillance, China’s cybercriminals find creative ways to chat