Meet Money Taker, the latest hacking group tied to Russian cybercrime

Hackers associated with a sophisticated Russian cybercrime ring attacked a series of banks in the U.S., U.K. and Russia, robbing at least one U.S. financial institution two separate times, according to Moscow-based cybersecurity company Group-IB. The researchers dubbed the group “Money Taker,” based on a custom, modular malware framework used to spy on banks and manipulate payment data. Security researchers say Money Taker has been active since at least 2016, targeting more than 20 organizations over the last two years. In addition to banks, victims include international law firms and financial software vendors. Money Taker is likely a criminal enterprise unaffiliated with any government, although they’ve proved to be highly-skilled, resourceful and well-equipped — similar to advanced persistent threat (APT) groups supported by a foreign government, Group-IB Director Nik Palmer told CyberScoop. “The [banking-focused] attacks ​were certainly conducted by a skillful targeted attack group,” explained Palmer. “The group is skillful enough to […]

The post Meet Money Taker, the latest hacking group tied to Russian cybercrime appeared first on Cyberscoop.

Continue reading Meet Money Taker, the latest hacking group tied to Russian cybercrime

MoneyTaker’s stealthy hacking spree spread from US to Russia

A stealthy group of Russian-speaking hackers has been targeting financial organizations (banks, credit unions, lenders) in the US and Russia, stealing money and documentation that could be used for new attacks. The targets The group’s operations … Continue reading MoneyTaker’s stealthy hacking spree spread from US to Russia

Who Was the NSA Contractor Arrested for Leaking the ‘Shadow Brokers’ Hacking Tools?

In August 2016, a mysterious entity calling itself “The Shadow Brokers” began releasing the first of several troves of classified documents and hacking tools purportedly stolen from “The Equation Group,” a highly advanced threat actor that is suspected of having ties to the U.S. National Security Agency. According to media reports, at least some of the information was stolen from the computer of an unidentified software developer and NSA contractor who was arrested in 2015 after taking the hacking tools home. In this post, we’ll examine clues left behind in the leaked Equation Group documents that may point to the identity of the mysterious software developer. Continue reading Who Was the NSA Contractor Arrested for Leaking the ‘Shadow Brokers’ Hacking Tools?

ShadowBrokers Expose NSA Access to SWIFT Service Bureaus

The latest ShadowBrokers dump includes exploits that allowed the NSA to target SWIFT data managed by outsourced service bureaus in the Middle East. Continue reading ShadowBrokers Expose NSA Access to SWIFT Service Bureaus

Shadow Brokers leak NSA documents that may reveal operation aimed at Middle Eastern banks

The Shadow Brokers published a cache Friday of supposed NSA documents, 23 executable hacking tools targeting Windows and perhaps most notably, evidence showing the secretive agency compromised offices connected to a global banking transaction system in order to spy on Middle Eastern banks. The cache holds authentic NSA documents and contains legitimate information, according to former intelligence officials who spoke on condition of anonymity. “TheShadowBrokers showing you cards theshadowbrokers wanting you to be seeing. Sometime peoples not being target audience. Follow the links for new dumps. Windows. Swift. Oddjob. Oh you thought that was it? Some of you peoples is needing reading comprehension,” a message written by the group reads. After publishing and promoting leaked documents for several months, Friday’s release by the mysterious group is the first to contain NSA Powerpoint presentation slides — prior to today, only files released by NSA whistleblower Edward Snowden offered such material. Security researchers […]

The post Shadow Brokers leak NSA documents that may reveal operation aimed at Middle Eastern banks appeared first on Cyberscoop.

Continue reading Shadow Brokers leak NSA documents that may reveal operation aimed at Middle Eastern banks

After losing millions to hackers, SWIFT banks now enforce mandatory security controls

Hackers have stolen hundreds of millions of dollars from international banks in the last two years after compromising the networks of financial institutions and then using that access to send fraudulent transactions through SWIFT, the global network banks use to transfer money between one another. In response, SWIFT begins enforcing mandatory security controls on April 1 as part of an effort to strengthen defenses against an increasing host of hackers success in pulling off some of the biggest bank heists in history. One of the groups involved in attacks against South East Asia banks is largely thought to be controlled by North Korean intelligence. Cybercriminal groups have launched multiple distinct sustained and successful hacking campaigns against banks around the world with the ultimate targeting being fraudulent SWIFT transactions. One industry group said Eastern European banks had lost hundreds of millions of U.S. dollars to hackers. The first new rule is to restrict […]

The post After losing millions to hackers, SWIFT banks now enforce mandatory security controls appeared first on Cyberscoop.

Continue reading After losing millions to hackers, SWIFT banks now enforce mandatory security controls

After losing millions to hackers, SWIFT banks now enforce mandatory security controls

Hackers have stolen hundreds of millions of dollars from international banks in the last two years after compromising the networks of financial institutions and then using that access to send fraudulent transactions through SWIFT, the global network banks use to transfer money between one another. In response, SWIFT begins enforcing mandatory security controls on April 1 as part of an effort to strengthen defenses against an increasing host of hackers success in pulling off some of the biggest bank heists in history. One of the groups involved in attacks against South East Asia banks is largely thought to be controlled by North Korean intelligence. Cybercriminal groups have launched multiple distinct sustained and successful hacking campaigns against banks around the world with the ultimate targeting being fraudulent SWIFT transactions. One industry group said Eastern European banks had lost hundreds of millions of U.S. dollars to hackers. The first new rule is to restrict […]

The post After losing millions to hackers, SWIFT banks now enforce mandatory security controls appeared first on Cyberscoop.

Continue reading After losing millions to hackers, SWIFT banks now enforce mandatory security controls