North Korea’s plan to cultivate an army of cybercrime masterminds

In the shadow of nuclear weapons, bank robberies tend to be forgotten. In North Korea’s case, the two are closely connected. Conventional wisdom says North Korea is an arsenal-craving backwater under the rule of despots. The regime, however, is driving toward a modern version of authoritarianism, with cyberwar capabilities complementing hydrogen bombs. While the nukes purposefully grab the world’s attention, the regime is taking unprecedented steps in the cyber domain. And it’s targeting more than just its critics. It’s been just over one year since the collective known as Lazarus Group stole $81 million from the central bank of Bangladesh in a heist that ran through the Federal Reserve Bank of New York. The theft, one of the biggest bank robberies in modern history, initially targeted $1 billion but came up well short because of a simple typo during the online bank transfer process. It’s now the subject of a federal inquiry looking into […]

The post North Korea’s plan to cultivate an army of cybercrime masterminds appeared first on Cyberscoop.

Continue reading North Korea’s plan to cultivate an army of cybercrime masterminds

DOJ moves to topple Kelihos, one of the world’s largest botnets

The Department of Justice announced Monday an effort to take down a global network of over 100,000 enslaved computers under the control of Peter Yuryevich Levashov. Levashov, also known as Peter Severa, was known as one of the world’s most prolific and long-reigning kings of spam. A citizen of Russia, he was arrested in Spain earlier this week. The network, known as the Kelihos botnet, has been in operation since 2010, targeting Microsoft Windows machines for infection.  The results was millions of spam emails, pump-and-dump schemes to illegally profit illegally off stocks, mass password theft and the spreading of malware, according to the DOJ. Roughly five to ten percent of Kelihos victims reside in the United States, according to the Justice Department. “The ability of botnets like Kelihos to be weaponized quickly for vast and varied types of harms is a dangerous and deep threat to all Americans, driving at the core of how we communicate, […]

The post DOJ moves to topple Kelihos, one of the world’s largest botnets appeared first on Cyberscoop.

Continue reading DOJ moves to topple Kelihos, one of the world’s largest botnets

Rogue insider charged with writing malware to steal Wall Street firm’s crown jewel algorithms

After seven years on the job at a multibillion-dollar Wall Street financial services firm, a senior systems administrator stands accused by the FBI of creating malware to steal valuable source code and encryption keys that gave him direct access to the data files that make up the company’s crown jewels. Zhengquan Zhang, 31, was arrested on Friday morning at his Santa Clara, California, home by FBI agents who began investigating his actions last month. If convicted, he faces a maximum sentence of 10 years in prison. Zhang worked for KCG Holdings, a firm with offices around the world and the United States. Zhang, an employee at the company’s San Jose office, did not respond to a request for comment. The more than 3 million secret and proprietary files Zhang is accused of stealing make up the heart of KCG’s business, which earned more than $1.4 billion in revenue in 2016. A major portion of KCG’s business is […]

The post Rogue insider charged with writing malware to steal Wall Street firm’s crown jewel algorithms appeared first on Cyberscoop.

Continue reading Rogue insider charged with writing malware to steal Wall Street firm’s crown jewel algorithms

GameStop investigating possible credit card hack

The multibillion-dollar video game retailer GameStop.com is investigating a possible hack of credit card data. The data was then up for sale on a black market website. “GameStop recently received notification from a third party that it believed payment card data from cards used on the GameStop.com website was being offered for sale on a website,” the company said in a statement to CyberScoop. “That day a leading security firm was engaged to investigate these claims. GameStop has and will continue to work non-stop to address this report and take appropriate measures to eradicate any issue that may be identified.” Citing multiple anonymous sources in the financial industry, journalist Brian Krebs reported that the breach likely spanned five months from the middle of September 2016 to the first week of February 2017. The data being sold includes customer card number, expiration date, name, address and card verification value. GameStop did not respond to questions […]

The post GameStop investigating possible credit card hack appeared first on Cyberscoop.

Continue reading GameStop investigating possible credit card hack

Chinese surveillance giant Knowlesys pushes further into international market

After more than a decade of domestic success in China as a digital surveillance power, the internet and public opinion monitoring company Knowlesys now aims to push further into the international market. Competing against U.S., Russian and Western competition more broadly, Knowlesys is slated to attend several major surveillance industry trade shows in 2017, including ISS World and Milipol in Europe and the Middle East, to make its sales pitch to potential public and private sector customers across Asia and Europe. It’s a situation where “Made in China” carries a lot of weight among the purse-string set, given the company’s customer list, which includes the Chinese military. China is home to some of the most effective internet surveillance systems anywhere. Although “The Great Firewall of China” figures into the popular imagination as a looming monolith, it’s a complex and multi-tiered system. One key facet is the close and deep monitoring of public […]

The post Chinese surveillance giant Knowlesys pushes further into international market appeared first on Cyberscoop.

Continue reading Chinese surveillance giant Knowlesys pushes further into international market

How AlphaBay has quietly become the king of dark web marketplaces

In December 2016, The Rainmaker Labs was ready to debut its new product. The startup went through many of the same steps other businesses take on launch day. It advertised a long list of unique and powerful features that highlighted the product’s ease of use, peppered the targeted online marketplace with catchy slogans and filmed a slick YouTube commercial. Since the launch, The Rainmaker Labs is on pace to earn over $60,000 from the product, dubbed “Philadelphia.” The group’s full suite of offerings has it positioned for six-figure sales numbers for 2017. This is a big problem for security professionals and law enforcement alike. Why? The Rainmaker Labs creates malware, packages it with utter professionalism and sells it as a cutting-edge way for crooks to make mountains of money. It’s one of the scores of shady sellers that have turned cybercrime into a living thanks to AlphaBay, the highest-earning and most popular dark web market in the English-speaking world. Facilitating the sale of […]

The post How AlphaBay has quietly become the king of dark web marketplaces appeared first on Cyberscoop.

Continue reading How AlphaBay has quietly become the king of dark web marketplaces

After losing millions to hackers, SWIFT banks now enforce mandatory security controls

Hackers have stolen hundreds of millions of dollars from international banks in the last two years after compromising the networks of financial institutions and then using that access to send fraudulent transactions through SWIFT, the global network banks use to transfer money between one another. In response, SWIFT begins enforcing mandatory security controls on April 1 as part of an effort to strengthen defenses against an increasing host of hackers success in pulling off some of the biggest bank heists in history. One of the groups involved in attacks against South East Asia banks is largely thought to be controlled by North Korean intelligence. Cybercriminal groups have launched multiple distinct sustained and successful hacking campaigns against banks around the world with the ultimate targeting being fraudulent SWIFT transactions. One industry group said Eastern European banks had lost hundreds of millions of U.S. dollars to hackers. The first new rule is to restrict […]

The post After losing millions to hackers, SWIFT banks now enforce mandatory security controls appeared first on Cyberscoop.

Continue reading After losing millions to hackers, SWIFT banks now enforce mandatory security controls

After losing millions to hackers, SWIFT banks now enforce mandatory security controls

Hackers have stolen hundreds of millions of dollars from international banks in the last two years after compromising the networks of financial institutions and then using that access to send fraudulent transactions through SWIFT, the global network banks use to transfer money between one another. In response, SWIFT begins enforcing mandatory security controls on April 1 as part of an effort to strengthen defenses against an increasing host of hackers success in pulling off some of the biggest bank heists in history. One of the groups involved in attacks against South East Asia banks is largely thought to be controlled by North Korean intelligence. Cybercriminal groups have launched multiple distinct sustained and successful hacking campaigns against banks around the world with the ultimate targeting being fraudulent SWIFT transactions. One industry group said Eastern European banks had lost hundreds of millions of U.S. dollars to hackers. The first new rule is to restrict […]

The post After losing millions to hackers, SWIFT banks now enforce mandatory security controls appeared first on Cyberscoop.

Continue reading After losing millions to hackers, SWIFT banks now enforce mandatory security controls

EU Justice Commissioner: New ‘options’ on encrypted communications access are coming

Days after encryption climbed back into headlines following a deadly terror attack in London, European Union Justice Commissioner Vera Jourová said on Tuesday that she will soon propose “three or four” new “options” that will give police access to encrypted data on messaging apps like WhatsApp and Signal. Jourová, previously a member of the Czech parliament, left the options open to include everything from voluntary agreements to official legislation, the European news site Euractiv reported. She will make proposals in June. Following last week’s terror attack that killed four people, United Kingdom Home Secretary Amber Rudd said Sunday that encrypted apps like WhatsApp created a “secret place for terrorists to communicate.” She effectively called for the end of strong encryption as it now exists. “It is completely unacceptable,” she said. “There should be no place for terrorists to hide.” German Interior Minister Thomas de Maizière and French Interior Minister Matthias Fekl followed on […]

The post EU Justice Commissioner: New ‘options’ on encrypted communications access are coming appeared first on Cyberscoop.

Continue reading EU Justice Commissioner: New ‘options’ on encrypted communications access are coming

Health care industry is king of the malicious insider threat

The health care sector’s IT suffered from malicious insider attacks at a rate far higher than any other major industry in 2016, according to new research from IBM. The numbers further cement long held fears among health care technologists that highly valuable records, which sell on the black market for far-higher prices than stolen credit card information, are vulnerable in a sector that many professionals say does not do enough for security beyond minimum compliance requirements. About 25 percent of attacks on health care sector IT were malicious insider incidents, well above the rates in industries such as financial services (5 percent), manufacturing (4 percent) and retail (2 percent), the report said. The industry also had a high rate of incidents by “inadvertent actors,” meaning an attack came from inside the system but without the knowledge of the compromised machine’s user. A typical example would be a machine infected by malware that […]

The post Health care industry is king of the malicious insider threat appeared first on Cyberscoop.

Continue reading Health care industry is king of the malicious insider threat