How alleged Iranian hackers are posing as an Israeli scientist to spy on US medical professionals

Suspected Iranian hackers have impersonated a well-known Israeli physicist as part of a broader campaign to break into the email accounts of some two-dozen medical researchers in Israel and the U.S., email security firm Proofpoint said Wednesday.   The intrusion attempts — carefully crafted efforts to spy on senior medical professionals in the genetic, neurology and oncology fields — are the handiwork of the Charming Kitten hacking group, Proofpoint said. A 2019 U.S Justice Department indictment linked the group to the Iranian military. The phishing campaign shows how, more than a decade after the Stuxnet worm’s infiltration of an Iranian nuclear facility, hacking is still central to the high-stakes spying game between Iran, Israel and the U.S. And it is but one of several recent examples, including the targeting of the 2020 U.S. election, of how Iranian hackers are capable of threatening U.S. interests.     In this case, the suspected Iranian […]

The post How alleged Iranian hackers are posing as an Israeli scientist to spy on US medical professionals appeared first on CyberScoop.

Continue reading How alleged Iranian hackers are posing as an Israeli scientist to spy on US medical professionals

State prosecutors push Facebook, Twitter to do more to slow virus misinformation

A group of 12 state attorneys general sent a letter on Wednesday to Facebook and Twitter urging them to do more to curtail vaccine misinformation on their platforms. “Misinformation disseminated via your platforms has increased vaccine hesitancy, which will slow economic recovery and, more importantly, ultimately cause even more unnecessary deaths,” the group of attorneys general state in the letter. The letter sent to Facebook CEO Mark Zuckerberg and Twitter CEO Jack Dorsey Wednesday is signed by the attorneys general of Connecticut, Delaware, Iowa, Massachusetts, Michigan, Minnesota, New York, North Carolina, Oregon, Pennsylvania, Rhode Island and Virginia. They note that purveyors of vaccine misinformation have often targeted Black Americans, “members of communities who have suffered the worst health impacts of the virus and whose vaccination rates are lagging.” Bad actors and grifters have been spreading misinformation about vaccines on social media, including on Facebook and Twitter, for years. Some of […]

The post State prosecutors push Facebook, Twitter to do more to slow virus misinformation appeared first on CyberScoop.

Continue reading State prosecutors push Facebook, Twitter to do more to slow virus misinformation

COVID-19 vaccine scammers are still lurking

Scams looking to take advantage of people attempting to get vaccinated against the coronavirus are alive and well. In the approximately two months since the first COVID-19 vaccines became available in the U.S., vaccine-related phishing campaigns aimed at stealing victims’ credentials increased by 530%, according to Palo Alto Networks’ Unit 42 research published Wednesday. In one campaign, hackers created a website that imitated a page for the Pfizer and BioNTech vaccine, requesting users’ Office 365 credentials to purportedly register for a vaccine. Phishing campaigns targeting employees of hospitals and pharmacies rose 189% during the same time period, the researchers found. In some attacks, the hackers attempted to steal credentials from employees at Walgreens, Canada-based Pharmascience, India-based Glenmark Pharmaceuticals and China-based Junshi Biosciences. Unit 42’s findings cover scams researchers tracked through the end of last month. The pandemic has spurred on a flurry of new cyberthreats over the course of the […]

The post COVID-19 vaccine scammers are still lurking appeared first on CyberScoop.

Continue reading COVID-19 vaccine scammers are still lurking

Is Congress finally ready to pass meaningful ransomware legislation?

During the entire last two-year session of Congress, lawmakers only signed one bill law that mentioned the word “ransomware.” With the epidemic of digital extortion showing no signs of abating, though, and as ransomware attacks claim ever more victims across all parts of the U.S., evidence is mounting that the next two years could bring a more concerted push for legitlation. “I think it will be a focus because essentially every congressional district has had some kind of ransomware incident, whether public or not,” said Michael Garcia, a senior policy adviser in the national security program at Third Way, a center-left think tank. “Just look at the number of hospitals getting hit, of schools being hit.” In one recent incident, a Mississippi public school system revealed it had paid $300,000 to ransomware attacks, while a U.S. medical company, Universal Health Services, said it lost $67 million as a result of […]

The post Is Congress finally ready to pass meaningful ransomware legislation? appeared first on CyberScoop.

Continue reading Is Congress finally ready to pass meaningful ransomware legislation?

Ryuk ransomware develops worm-like capabilities, France warns

A new sample of Ryuk ransomware appears to have worm-like capabilities, according to an analysis from the French National Agency for the Security of Information Systems (ANSSI), France’s national cybersecurity agency. With such worm-like self-replicating capabilities, Ryuk, one of the most prolific strains of ransomware in the world, can spread from machine to machine without any human interaction. The development presents only another challenge for security-minded researchers and law enforcement authorities already trying to grapple with the scourge of ransomware attacks pummeling international networks. Ryuk hackers have previously leveraged other methods to spread through the networks they target, and have not previously had the ability to move laterally in a network, according to previous research from the U.K.’s National Cyber Security Centre. ANSSI found the sample with the new capability earlier this year, the analysis states. The disclosure of the discovery comes weeks after law enforcement entities from multiple countries […]

The post Ryuk ransomware develops worm-like capabilities, France warns appeared first on CyberScoop.

Continue reading Ryuk ransomware develops worm-like capabilities, France warns

Universal Health Services reports $67 million in losses after apparent ransomware attack

An apparent ransomware attack last fall caused $67 million in pre-tax losses at Universal Health Services, the U.S. health care provider has revealed, illustrating the sharp financial toll that criminal hackers have caused the sector during the pandemic. The Sept. 27 breach at Universal Health Services (UHS) was widely reported to be a ransomware attack, with some analysts saying it involved the Ryuk strain of malicious code. It came amid a wave of suspected Ryuk incidents at the computer networks of various U.S. hospitals that federal authorities scrambled to address. UHS, which oversees 400 hospitals and calls itself one of the biggest health care providers in the country, now says the cost of the breach included lost revenue because ambulances were diverted to competitor facilities. The incident also delayed billing procedures for more than two months, and forced UHS to spend big on labor costs to restore connectivity, the company […]

The post Universal Health Services reports $67 million in losses after apparent ransomware attack appeared first on CyberScoop.

Continue reading Universal Health Services reports $67 million in losses after apparent ransomware attack

Flaw in popular video software Agora could have let eavesdroppers in on private calls

An error in a popular video calling software development kit could have allowed hackers to spy on private video and audio calls through services including eHarmony or Talkspace, according to McAfee research published Wednesday. The flaw, which stems from an encryption error, affected a video-calling software development kit (SDK) developed by Agora.io that is used by dating services such as eHarmony, Plenty of Fish, MeetMe and Skout and medical applications such as Talkspace, Practo and Dr. First’s Backline, according to McAfee. Agora is used by 1.7 billion devices for a whole host of applications used for educational, retail and gaming purposes as well as for other socializing reasons, the company says. The flaw, known as CVE-2020-25605, is accounted for in an update Agora issued in mid-December, according to McAfee. Agora did not immediately respond to a request for comment. McAfee’s Advanced Threat Research team does not have any evidence that the […]

The post Flaw in popular video software Agora could have let eavesdroppers in on private calls appeared first on CyberScoop.

Continue reading Flaw in popular video software Agora could have let eavesdroppers in on private calls

China could add new sets of genome data to espionage treasure trove, US officials warn

With coronavirus testing offering new avenues for collecting sensitive health data, U.S. intelligence officials have issued a fresh warning about Chinese government operatives’ alleged longstanding practice of using medical information for espionage. The public advisory released Monday by the U.S. National Counterintelligence and Security Center cautions that Beijing could pair DNA datasets with the millions of records thought to be in the hands of Chinese spies from the 2015 hacks of health insurer Anthem and the Office of Personnel Management, and the 2017 breach of credit-monitoring firm Equifax. (Beijing has repeatedly denied using hacking to steal sensitive data.) The concern is that Chinese authorities could use the data trove to extort or manipulate U.S. government officials or corporate executives. For example, the NCSC worries that Beijing could use knowledge of someone’s genetic vulnerability to addiction or past bouts with mental illness to coerce them into handing over U.S. government secrets. […]

The post China could add new sets of genome data to espionage treasure trove, US officials warn appeared first on CyberScoop.

Continue reading China could add new sets of genome data to espionage treasure trove, US officials warn

Health Care Remains a Prime Target for Ransomware Attacks

It’s easy to be distracted by the flood of other distressing news each day, but the FBI, CISA and HHS recently urged the health care industry to stay on high alert for malware; especially ransomware attacks. The FBI’s warning included the statement, “… Continue reading Health Care Remains a Prime Target for Ransomware Attacks

Hackers Calling Fair Game on Healthcare Institutions

The year 2019 saw big consumer brands get hacked: from Facebook to Capital One, every day people were urged to double-check their bank accounts and credit card statements to ensure their information had not been stolen. The prime target: all of your p… Continue reading Hackers Calling Fair Game on Healthcare Institutions