Two Iranian hacking groups appear to be actively snooping on critics around the globe

Two suspected Iranian government-connected hacking groups are actively spying on dissidents around the world in renewed eavesdropping campaigns, researchers said in reports out Monday morning. One of the groups, known as Domestic Kitten or APT-C-50, notched victims in seven countries, Check Point Research found: Iran, the U.S., the U.K., Pakistan, Afghanistan, Turkey,and Uzbekistan. The other, known as Infy or Prince of Persia, snooped on dissidents in 12 countries, Check Point found in joint research with SafeBreach. Both companies were founded in Israel, which counts Iran as one of its chief nemeses. The U.S. also counts Iran among the handful of its biggest adversaries in cyberspace. Check Point has reported on both groups in the past, but the the company said its research uncovered new activity and fresh techniques. “The operators of these Iranian cyber espionage campaigns seem to be completely unaffected by any counter-activities done by others, even though they […]

The post Two Iranian hacking groups appear to be actively snooping on critics around the globe appeared first on CyberScoop.

Continue reading Two Iranian hacking groups appear to be actively snooping on critics around the globe

Serbian man extradited to US over cryptocurrency mining fraud scheme

Serbia extradited a man to the U.S. to face charges that he and his partners defrauded investors out of more than $70 million, in part by touting phony cryptocurrency mining companies, authorities announced Friday. The Serbian man, Antonije Stojilkovic, stands accused of conspiracy to commit fraud and money laundering, charges for which he could face 20 years in prison. “This $70 million scam spanned several continents, targeting American citizens and foreigners alike,” said Prerak Shah, acting U.S. Attorney for the Northern District of Texas. “The U.S. Department of Justice will not relent in our fight against cybercrime.” Stojilkovic and his co-conspirators advertised that their cryptocurrency mining platforms would allow investors to “purchase bitcoin at half market price!!” because of a “24-7 mining” operation at “facilities ‘worldwide,’” according to a Justice Department press release.  In propping up those companies and others devoted to binary options — more than 20 in all […]

The post Serbian man extradited to US over cryptocurrency mining fraud scheme appeared first on CyberScoop.

Continue reading Serbian man extradited to US over cryptocurrency mining fraud scheme

Facebook, TikTok, Twitter go after ‘OGUsers’ members who traffic hacked accounts

Facebook, TikTok and Twitter coordinated to banish hundreds of accounts on Thursday allegedly linked to OGUsers, a marketplace for hacked usernames that can fetch tens of thousands of dollars. Buyers use the simple, short usernames — such as @food — to obtain clout or make money. Facebook said it has cracked down on accounts affiliated with OGUsers before, but it is making its enforcement public in a bid to deter those who would harass or hack legitimate users to obtain those valuable accounts. “They harass, extort and cause harm to the Instagram community, and we will continue to do all we can to make it difficult for them to profit from Instagram usernames,” said a spokesperson for Facebook, which owns Instagram. In all, Facebook suspended around 400 accounts. Twitter said it suspended “a number” of them but didn’t elaborate upon request. TikTok did not immediately respond to a request for […]

The post Facebook, TikTok, Twitter go after ‘OGUsers’ members who traffic hacked accounts appeared first on CyberScoop.

Continue reading Facebook, TikTok, Twitter go after ‘OGUsers’ members who traffic hacked accounts

Congress is starting to move on more cyber bills, even if few become law

Congress dramatically ratcheted up the number of cybersecurity bills introduced in the last two years compared to the prior session of Congress, but that didn’t equate to much more of it becoming law, according to a think tank study out today. And while cybersecurity legislation remained a relative oasis of bipartisanship, that tendency sharply dropped off when it came to election security, found the tally from Third Way — which CyberScoop is first reporting. The findings offer potential insights into how the issue is evolving, and where it might go next, even if the trends don’t lend themselves to a simple explanation. In all, lawmakers introduced 316 cybersecurity bills in the 116th Congress that ran from 2019 to 2020, a 40% increase from the 115th Congress. That continues a trend that took off in that session of Congress: The 114th Congress saw just 22 cybersecurity measures offered, the center-left think […]

The post Congress is starting to move on more cyber bills, even if few become law appeared first on CyberScoop.

Continue reading Congress is starting to move on more cyber bills, even if few become law

House Dems pressure tech giants over spread of COVID-19 vaccine misinformation

With reports of COVID-19 vaccine misinformation and disinformation proliferating on tech platforms, Democratic leaders of the House Energy and Commerce Committee on Tuesday said they want answers from the industry’s titans about what they’re doing to stop it. “As the country enters this next phase in its fight against the virus — the success of which is dependent on hundreds of millions of Americans trusting the science behind these vaccines — the Committee is deeply troubled by news reports of coronavirus vaccine misinformation on your platform,” wrote Democratic leaders of the panel, including Chairman Frank Pallone, D-N.J., to the CEOs of Facebook, Google and Twitter. It’s the latest application of pressure on tech companies from government officials to halt fake news about COVID-19. Just last week, the European Union said it expects Facebook, Google, Microsoft and Twitter to continue delivering monthly reports on the subject for another six months. There’s […]

The post House Dems pressure tech giants over spread of COVID-19 vaccine misinformation appeared first on CyberScoop.

Continue reading House Dems pressure tech giants over spread of COVID-19 vaccine misinformation

Amid military coup, Myanmar’s internet is partially blacked out

Internet connectivity dropped precipitously in Myanmar on Monday as the military seized power, likely the result of the government shutting down access in a move that drew condemnation from President Joe Biden and digital freedom activists. The Myanmar military detained senior civilian politicians, including President U Win Myint and Nobel laureate Aung San Suu Kyi, whose party won a majority of parliamentary seats in the November elections. A military-owned television network said Commander-in-Chief Senior Gen. Min Aung Hlaing would assume control of the nation for one year following the military’s allegations that the elections were fraudulent. NetBlocks, which tracks digital freedom, said connectivity fell in Myanmar by 50% at one point before later recovering to 75% of ordinary levels. The disruption pattern pointed to a centrally issued blackout order to telecommunications providers, NetBlocks said. The outage accompanied a reported Army order to shutdown state media and the disabling of phone […]

The post Amid military coup, Myanmar’s internet is partially blacked out appeared first on CyberScoop.

Continue reading Amid military coup, Myanmar’s internet is partially blacked out

Emotet, NetWalker and TrickBot have taken big blows, but will it be enough?

A trio of operations meant to disrupt ransomware outfits in recent months — two of which came to light this week — could have lasting impacts even if they stop short of ending the threat, security experts say. Researchers are still sizing up the effects of recent busts of the Emotet and NetWalker gangs, but those operations have the potential to be more potent than last fall’s maneuvers against the TrickBot ransomware. In research out Friday, Menlo Security — echoing similar conclusions from other cyber firms — said it saw signs of TrickBot recovering, but the rebound has amounted to just a “trickle.” U.S. Cyber Command and Microsoft had led separate efforts to disrupt the hacking infrastructure of TrickBot, a massive army of zombified computers. The fear was that the botnet could be used to carry out ransomware attacks afflicting the November elections. This week’s two operations might be more promising […]

The post Emotet, NetWalker and TrickBot have taken big blows, but will it be enough? appeared first on CyberScoop.

Continue reading Emotet, NetWalker and TrickBot have taken big blows, but will it be enough?

Watchdog suggests State Department should have used ‘evidence’ to explain new cyber bureau

Government auditors concluded in a withering, deadpan report Thursday that the State Department should have used “data and evidence to justify its proposal” to establish a new cyber-focused bureau. Just before the Trump administration wound down, the State Department said it would create a Bureau of Cyberspace Security and Emerging Technologies, drawing fire from the chairman of the House Foreign Affairs Committee, Rep. Gregory Meeks, D-N.Y., who said he agreed that State needed a cyber bureau but that its last-minute proposal was “ill-suited” for the job. The Government Accountability Office reviewed the Jan. 7 proposal, and found that State “has not demonstrated that it used data and evidence to support its proposal, particularly for the bureau’s focus and organizational placement.” “Without developing evidence to support its proposal for the new bureau, State lacks needed assurance that the proposal will effectively set priorities and allocate appropriate resources for the bureau to […]

The post Watchdog suggests State Department should have used ‘evidence’ to explain new cyber bureau appeared first on CyberScoop.

Continue reading Watchdog suggests State Department should have used ‘evidence’ to explain new cyber bureau

For Microsoft, cybersecurity has become bigger than business

Since the cybersecurity firm FireEye hired Microsoft to help investigate a hack at the federal contractor SolarWinds, Microsoft has helped clean up the mess, alerted victims and distributed other details meant to fend off alleged Russian spies. Microsoft did all of that as it wrestled with its own probe of how hackers infiltrated its systems. Yet the company’s role in the SolarWinds investigation, while significant, represents a fraction of the cybersecurity-focused work Microsoft has done in recent years, including some behind the scenes and some in globe-spanning public relations campaigns. Once viewed as a traditional tech behemoth, Microsoft has evolved into a firm that fights cybersecurity battles in court, in election administration, in the international sphere, in the marketplace and elsewhere. The entirety of that perspective gives Microsoft a unique — if imperfect — place in the cybersecurity universe. The size of the company, and its level of visibility into […]

The post For Microsoft, cybersecurity has become bigger than business appeared first on CyberScoop.

Continue reading For Microsoft, cybersecurity has become bigger than business

NetWalker ransomware investigation yields arrest, big cryptocurrency seizure

In a coordinated, multi-part offensive against NetWalker ransomware attackers, law enforcement agencies announced Wednesday that they charged a Canadian national, seized nearly half a million dollars in cryptocurrency and disabled a dark web leak site. The NetWalker attackers have been part of a growing ransomware trend where the hackers hold stolen data hostage, leak a sample of it and threaten to release the rest in order to incentivize victims into paying. They’ve been gone after everyone from government agencies to hospitals to schools, and haven’t shied from exploiting the COVID-19 crisis. They’ve also sought to expand profits by offering their ransomware as a service to other cybercriminals, leading to reports of booming revenue in 2020. The number of overall ransomware attacks increased by 311% in 2020, according to recent research by Chainalysis, a cryptocurrency tracking firm. The charges against Sebastien Vachon-Desjardins, as well as the seizure of approximately $454,530.19 in […]

The post NetWalker ransomware investigation yields arrest, big cryptocurrency seizure appeared first on CyberScoop.

Continue reading NetWalker ransomware investigation yields arrest, big cryptocurrency seizure