Cybercriminal offers email implant software that dodges traditional security platforms

Imagine if cybercriminals didn’t have to send a malicious email for their victims to get the message anyway. That’s a tool one hacker is advertising on a dark web forum, according to research Gemini Advisory released Wednesday. And because the email can be implanted rather than sent, it has the potential to bypass  security that inspects messages as they’re en route to their destination server, researchers said. “The software poses a significant threat as it raises the success rate of malware attacks, allows for more sophisticated phishing and business email compromise (BEC) campaigns, and opens the door for technically simple ransomware-like attacks,” according to a blog post from the Miami-based threat intelligence company. The trick to implanting the email via the “Email Appender” software goes like this, Gemini Advisory explained: First, attackers must obtain valid email addresses and associated passwords, often available on the dark web at a low cost. Then the attacker has to upload the compromised credentials into Email […]

The post Cybercriminal offers email implant software that dodges traditional security platforms appeared first on CyberScoop.

Continue reading Cybercriminal offers email implant software that dodges traditional security platforms

Biden transition efforts on cybersecurity uncertain as Trump administration throws up obstacles

Former Department of Homeland Security chiefs cautioned Tuesday that President Donald Trump is endangering national security by blocking the transition to Joe Biden’s presidency, as the standoff stretched days after news organizations declared Biden the victor. “At this period of heightened risk for our nation, we do not have a single day to spare to begin the transition,” said the four former DHS secretaries Tom Ridge, Michael Chertoff, Janet Napolitano and Jeh Johnson. “For the good of the nation, we must start now.” Biden nonetheless plowed ahead with his plans to take over the executive branch, announcing agency review teams sprinkled with former U.S. government cybersecurity officials. But the Trump administration is so far making it difficult, and the dispute potentially stands to hamper cybersecurity on multiple fronts. One of those fronts: The Office of the Director of National Intelligence (ODNI) indicated that it would not work with the Biden transition until after […]

The post Biden transition efforts on cybersecurity uncertain as Trump administration throws up obstacles appeared first on CyberScoop.

Continue reading Biden transition efforts on cybersecurity uncertain as Trump administration throws up obstacles

Not all cyberattacks are created equal: What researchers learned from 103 ‘extreme’ events

There’s a relatively small swath of cyberattacks mixed among the more common variety that are truly extreme, costing tens of million of dollars and beyond, or exposing millions of records. A report out Tuesday identified a little over 100 that fit that description over the past five years. The researchers learned that these massive events cost a median of $47 million and usually came via straightforward hacks or ransomware. They appear to be growing more frequent, and nation-state hackers are behind them to a surprising degree, the report says. But the report from the Cyentia Insitute, a data science firm, also found that these extreme attacks don’t affect all their targets in the same way. Some cost companies nearly 100 times their revenue, while others were still just a drop in the bucket, costing as little as 0.1 % of their revenue. And the financial, information and manufacturing sectors accounted for more than half of the 103 incidents. “What […]

The post Not all cyberattacks are created equal: What researchers learned from 103 ‘extreme’ events appeared first on CyberScoop.

Continue reading Not all cyberattacks are created equal: What researchers learned from 103 ‘extreme’ events

Suspected North Korean hackers who targeted job applicants prove more ambitious than first believed

A possible North Korean government-connected cyber-espionage campaign that targeted the defense industry stretched further than originally known when it was inititally uncovered this summer, researchers said. “Operation North Star” went beyond targeting South Korea to include Australia, India, Israel and Russia, McAfee said in a report out Friday. And its motives and methods seem to be clearer now, too, according to researchers. Israel’s Ministry of Defense had previously blamed Lazarus Group, which the U.S. government calls Hidden Cobra, for sending phony job offers in its defense sector — a tactic that lined up with McAfee’s earlier description of Operation North Star tactics. Additionally, the campaign used a previously undiscovered implant called Torisma that it deployed to burrow further into victims’ systems, McAfee said. The tactic represents the kind of digital spying technique that would have given hackers access to machines belonging to job applicants positioned near military organizations — just the kind of targets that a […]

The post Suspected North Korean hackers who targeted job applicants prove more ambitious than first believed appeared first on CyberScoop.

Continue reading Suspected North Korean hackers who targeted job applicants prove more ambitious than first believed

DOJ seizes $1 billion in cryptocurrency tied to Silk Road dark web market

The Department of Justice said Thursday that it seized approximately $1 billion worth of bitcoin, its biggest cryptocurrency seizure ever. The announcement solves a a years-old mystery about the shuttered Silk Road dark web market for illegal drugs and other unlawful goods, widely regarded as the largest and most extensive dark web marketplace of its time before its 2013 demise. The law enforcement action  solves another riddle about a bitcoin wallet that just saw a nearly identically valued amount of cryptocurrency withdrawn after sitting dormant for a long time. “The successful prosecution of Silk Road’s founder in 2015 left open a billion-dollar question. Where did the money go?” said U.S. Attorney David Anderson. “Today’s forfeiture complaint answers this open question at least in part. $1 billion of these criminal proceeds are now in the United States’ possession.” Motherboard reported Wednesday on the Election Day emptying of the wallet. Then the complaint, filed Thursday, detailed […]

The post DOJ seizes $1 billion in cryptocurrency tied to Silk Road dark web market appeared first on CyberScoop.

Continue reading DOJ seizes $1 billion in cryptocurrency tied to Silk Road dark web market

Nothing is sacred: Ransomware attack hit toy maker Mattel’s systems this summer

Count the company behind Barbie dolls and Fisher-Price toys among the ever-growing list of digital extortion victims. A ransomware attack struck toy manufacturer Mattel this summer, the company said in a financial disclosure to the U.S. Securities and Exchange Commission. In a year when ransomware has threatened elections, hospitals and schools, the attack on Mattel demonstrates once more that the attack method is leaving no kind of target untouched. In its Nov. 3 quarterly report, Mattel said it emerged from the attack largely unscathed, however. It discovered the intrusion on July 28, when a number of its IT systems became encrypted. “Promptly upon detection of the attack, Mattel began enacting its response protocols and taking a series of measures to stop the attack and restore impacted systems,” the company said. “Mattel contained the attack and, although some business functions were temporarily impacted, Mattel restored its operations.” The report continued: “A forensic investigation of the […]

The post Nothing is sacred: Ransomware attack hit toy maker Mattel’s systems this summer appeared first on CyberScoop.

Continue reading Nothing is sacred: Ransomware attack hit toy maker Mattel’s systems this summer

Robocalls urging voters to skip Election Day are subject of FBI investigation, DHS official says

The FBI is investigating apparent voter suppression robocalls across the nation, a senior Department of Homeland Security official said Tuesday. An estimated 10 million calls have gone out urging people to “stay safe and stay home.” There also were reports of robocalls in Michigan falsely telling voters they could vote on Wednesday, because lines on Election Day were long. The FBI is “tracking down this issue,” said the senior official in DHS’s Cybersecurity and Infrastructure Security Agency. The FBI did not immediately return a request for comment. In the call with reporters, conducted on the condition of anonymity, the CISA official said it was nothing out of the ordinary. “Robocalls of this nature happen in every election,” the official said. The FBI’s investigation into robocalls isn’t the only one this campaign season. Michigan Attorney General Dana Nessel recently filed felony charges against conservative operatives Jack Burkman and Jacob Wohl, alleging that they were responsible […]

The post Robocalls urging voters to skip Election Day are subject of FBI investigation, DHS official says appeared first on CyberScoop.

Continue reading Robocalls urging voters to skip Election Day are subject of FBI investigation, DHS official says

Last-minute court rulings on election go against GOP, voting restrictions

A federal judge on Monday rejected a Texas GOP bid to throw out approximately 127,000 ballots in largely Democratic Harris County, saying the Republicans failed to demonstrate that they were harmed by the votes cast at extra drive-through locations. It was one of two major election cases to see action on Monday. In both cases, courts sided against conservative challenges over voting in Democrat-friendly jurisdictions. But it might only foreshadow more legal challenges ahead, after the election. In Texas, GOP activist Steven Hotze brought the case alongside Harris County Republicans state Rep. Steve Toth, congressional candidate Wendell Champion and judicial candidate Sharon Hemphill. They contended the extra 10 drive-through stations violated state election law, in an argument that centered on the definition of curbside voting. The clerk for Harris County, Houston’s home, rebutted the conservatives’ argument on several fronts. but the issue of whether they had standing to sue apparently caught the attention of U.S. District Judge Hanen. […]

The post Last-minute court rulings on election go against GOP, voting restrictions appeared first on CyberScoop.

Continue reading Last-minute court rulings on election go against GOP, voting restrictions

$100 million botnet scheme earns Russian man 8 years in prison

A U.S. judge sentenced a Russian national to eight years in prison over his role in stealing personal and financial information via a botnet conspiracy that aimed to generate an estimated $100 million. Prosecutors announced the sentence Monday for Aleksandr Brovko, who pleaded guilty in February to conspiracy to commit bank and wire fraud. From 2007 to 2019, according to the Department of Justice, Brovko collaborated with other cybercriminals to turn data troves harvested by botnets — networks of infected computers — into cash. Brovko’s role was to write software scripts to go through botnet logs and conduct data searches to extract highly sensitive personal information and online banking credentials, as well as scout out the value of compromised accounts to determine whether they’d be worth using to conduct fraud. In all, prosecutors said, Brovko possessed and trafficked more than 200,000 “unauthorized access devices,” a term for credit cards, mobile identification […]

The post $100 million botnet scheme earns Russian man 8 years in prison appeared first on CyberScoop.

Continue reading $100 million botnet scheme earns Russian man 8 years in prison

Wisconsin Republicans say last minute hack cost party $2 million meant to reelect Trump

Less than a week before Election Day in a vital swing state, Wisconsin Republicans said on Thursday that hackers made off with $2.3 million devoted to reelecting President Donald Trump. The Republican Party of Wisconsin said it first detected the attack on Oct. 22, then notified the FBI the following day about doctored invoices in the names of its vendors. “Cybercriminals, using a sophisticated phishing attack, stole funds intended for the re-election of President Trump, altered invoices and committed wire fraud,” the party’s chairman, Andrew Hitt, said in a statement. “These criminals exhibited a level of familiarity with state party operations at the end of the campaign to commit this crime.” It’s common for hacking victims to claim they were the victims of “sophisticated” attacks, whether the attacks were rudimentary or not. Hitt and a party spokesperson did not immediately respond to questions seeking further details, including any evidence the […]

The post Wisconsin Republicans say last minute hack cost party $2 million meant to reelect Trump appeared first on CyberScoop.

Continue reading Wisconsin Republicans say last minute hack cost party $2 million meant to reelect Trump