Showing posts with label Phishing Emails. Show all posts
Showing posts with label Phishing Emails. Show all posts

Monday, 12 March 2018

McAfee: Two Botnets Behind 97 Percent Of All Spam In Q4




Two botnets accounted for 97 percent of all spam sent in the fourth quarter of last year, according to McAfee in a new report. These are the Necurs and Gamut botnets, which are rented by spammers for sending spam, phishing emails and malware.

Necurs was the most used with a share of 60 percent, followed by Gamut with 37 percent ( pdf ). According to McAfee, Necurs is currently the largest spambot network in the world. The contaminated machines that are part of the botnet are controlled via a peer-to-peer model. In the fourth quarter of last year, the Locky ransomware and Dridex bank malware were sent via Necurs, among other things. Gamut focused more on e-mails during this period to recruit money mules and phishing e-mails.

Sunday, 11 March 2018

Leaked Source Code Ammyy Admin Uses For Malware



Source code of the remote desktop software Ammyy Admin has been used for malware that has been used for both targeted and large-scale attacks, according to security firm Proofpoint. Ammyy Admin is a program that allows remote access to computers.

Some time ago the source code of Ammyy Admin version 3 appeared on the Internet and cyber criminals have used it to develop malware called "FlawedAmmyy". This malicious version has been used in attacks since the beginning of 2016, but only recently discovered, Proofpoint says. Among other things, the automotive industry would be the target of the attacks.

To spread the malware, the attackers use e-mails that contain Word or ZIP files as an attachment. The Word files have a malicious macro that, when enabled by the user, downloads the malware on the system. Once active on a system, FlawedAmmyy can be used to steal trade secrets, customer data and other information from companies, according to the researchers.

Tuesday, 24 October 2017

Man Charged For Hacking 550 Gmail And iCloud Accounts


In the United States, a 32-year-old man is charged with hacking over 550 Gmail and iCloud accounts, including Hollywood star and other celebrity accounts. According to the charge, the man sent phishing emails from April 2013 until the end of August 2014 in which recipients were asked to return their username and password.

If the recipient responded and returned the credentials, the man used to log in to the victim's iCloud and Gmail account. As soon as the man logged in, he searched for sensitive personal information, including photos and videos. The case against the man arises from the search for 'Celebgate' or 'The Fappening', which loads all kinds of nude photos of celebrities. However, the FBI has not found evidence that the accused man is responsible for leakage of the naked photos or that he has shared or uploaded the information obtained.

The man has now signed a "plea" agreement with Justice and is expected to acknowledge debt, as soon as the US Department of Justice knows. Earlier this year, a 29-year-old American was sentenced to a nine-month imprisonment for hacking the iCloud and Gmail accounts of more than 300 people, including at least thirty Hollywood stars. According to the FBI, this man was not responsible for Celebgate.

Tuesday, 20 October 2015

US Defense Officials: Think Before You Click


US officials increasingly are targeted by so-called spear phishing attacks, reason for the US Department of Defense to issue a brochure with advice. The brochure follows two major break-ins at the Office of Personnel Management (OPM) earlier this year.

In addition, the data of millions of civil servants were stolen. The brochure explains how phishing attacks exactly and how phishing mails can be recognized. During an exercise of the army with a phishing test was a phishing email with a malicious Excel file sent to seven users. Two user opened the file, making the 'attackers' ultimate domain administrator on more than 6800 user and computer accounts were 5400. Officials are therefore given in the leaflet to stop the advice to first and think before they click on something.

Friday, 18 September 2015

F-Secure: Espionage Group Working For Russian Government



A group of cyber spies has been working since 2008 for the Russian government and is responsible for various espionage campaigns in which information in the field of foreign policy and security were captured, so claims the Finnish anti-virus firm F-Secure in a comprehensive report (pdf).

The group is called "Duke" and is assured seven years running. To infect targets are mainly used spear phishing emails.The messages contain infected attachments, such as a monkey movie, or links to a website that tries to install malware via a non patches vulnerability. After one vulnerability in Adobe Reader, all the vulnerabilities that the group attacked at the time of the attacks already patched.

Victims were then also can protect themselves by installing security updates timely. The only time there is no spear phishing was used was in the "Onion Duke 'malware. This malware was via a malicious Tor server and torrent files distributed. Once Tor users a program through the Tor network inside was pulled in real-time malware added to the file.

Russia

Attributing attacks to a specific country is very difficult, but in this case, F-Secure says that the espionage group is sponsored by the Russian government. Therefore the virus fighter relies on the motivation and goals of the group. "Based on what we now know about the targets that Duke chose the last seven years, it is consistent to entities with foreign policy and security issues associated," said the Finnish anti-virus company.

The main party that benefits from the work of the cyber spies is the Russian government, according to F-Secure. There are Russian words in the Duke-malware detected and the group is active during office hours in Russia. Further targets include the Eastern European Ministries of Foreign Affairs, Western think tanks and government agencies and even Russian-speaking drug dealers. "All available evidence suggests we believe that the group is working for Russia and we are not aware of evidence that shows otherwise see."

Thursday, 20 August 2015

Churchgoers Attacked Through New Explorer Leak



The zero-day vulnerability in Internet Explorer for which Microsoft Tuesday an emergency patch released is used to infect visitors of an evangelical church in Hong Kong with malware. Attackers had placed an iframe on the denomination's website, which visitors sent by unnoticed to a website with an exploit. This exploit took advantage of the vulnerability that was present in IE7 to IE11.

In the case the attack was successful Korplug the malware was installed, says Symantec. Korplug is a Trojan horse designed to steal information. Through the malware attackers full control over the computer. According to anti-virus company, there was a so-called "watering hole" attacks, where attackers hacking websites which potential targets already visit on its own. In this way, the attackers do not have phishing emails to be sent, so that the longer attack may go unnoticed. In giving the emergency patch Microsoft had already indicated that the leak was actively attacked.

Sunday, 26 July 2015

US Government Attacked Via Flash Player Flaw


Several agencies of the US government in June and July attacked via a Flash Player vulnerability that was discovered by the Italian Hacking Team and true at the time of the attacks had no patch yet, says the FBI. Details about the vulnerability were found in the data that were stolen from the Italian surveillance company. However, the break-in at Hacking Team was made ​​public on July 6.

Now, according to information from the FBI's Flash Player flaw had been since June 8 by assailants known and actively used to penetrate US government agencies. Previously had anti-virus company Trend Micro already know that the vulnerability before the disclosure in targeted attacks against targets in Korea and Japan had begun, namely July 1 . The FBI goes in the case for the attacks against US government agencies for two campaigns which probably gathering information aim.

Campaigns

The first phishing campaign took place on 8, 9 and 11 June, the second was observed on July 8, according to a warning that spread the FBI and by Public Intelligence online ( pdf is put). Both attacks emails were sent with a link. The link pointed to an exploit that took advantage of the vulnerability in Flash Player. The attack on July 8, the FBI more information mentioned in the warning. Thus, the government received a spear phishing e-mail with a link to a PDF document. When users opened a website loaded there the link containing JavaScript code. This code then loaded a malicious Flash file that vulnerability in Flash Player attacked to infect your computer with malware.

The spear phishing emails had different topics such as 'BBW Analysis report - 2015', 'Tomorrow Morning New Starts', "Perry Dale Club for Leadership: Financial Literacy 101", "FAS Analysis Report - 2015", "AEP Energy Program Update: 2015 Program Year Kick Off ',' Review Link "and" PLS Account A42660861. All spear phishing emails that were submitted in July had the same sender. The timing of the attack in July is remarkable, because on July 8 wrote poetry namely the vulnerability in Adobe Flash Player version 18.0.0.194 and earlier on an emergency patch . In the warning, the FBI also recorded several IP addresses and domains that were used by the attackers and can help detect a possible attack.

Friday, 10 July 2015

Flash Player Leak Of Hacking Team Previously Attacked


The critical vulnerability in Flash Player, which the Italian Hacking Team disposal and this week was discovered and published, has already been used to attack in Korea and Japan. These are limited attacks that took place on July 1, reports the Japanese anti-virus company Trend Micro.

Hacking Team had developed an exploit that made ​​abuse of the then unknown Flash Player flaw. However, operating would have been used on 1 July, before the hacker to Hacking Team did in breaking the corporate data put online, says Trend Micro . The exploit that discovered the virus fighter is very similar to that of Hacking Team. "We think this attack was carried out by someone who has access to the tools and code of Hacking Team," said analyst Wu Weimin. The only difference was that the leaked operates Hacking Team did not contain malware, whereas in the attack which it was held on July 1 the case.

Victims used by the leak to attack his likely spear phishing emails. These emails contain a Word document with a link. This link pointing back to a website with the Flash Player exploit. Further investigation revealed that the website from June 22 already had been visited by other users from Korea, as well as a user from Japan. Whether these users through the same or other exploits are attacked Trend Micro can not confirm, but according to this virus fighter is quite probable. Meanwhile, Adobe has released an update released to fix the leak.

Wednesday, 29 April 2015

Great Email Service SendGrid Hacked Account Via Employee



The major e-mail service SendGrid, which include e-mails sent to Pinterest, Uber, Foursquare, Hootsuite and Spotify, has warned customers that their data may be stolen. On 8 April, the SendGrid account of Coinbase hacked , a large Bitcoin exchange, and used to send phishing emails. At first thought SendGrid that it was an isolated incident.

Further investigation revealed that the account was hacked by a SenGrid employee and was used by a cyber criminal to approach various internal systems. These systems contained user names, email addresses and customize stretched and saved passwords. The cyber criminal could access servers with e-mail lists and addresses received from customers of the customers SendGrid. In theory, it could go to millions of users.

According SendGrid there is no evidence that this data is also captured. However, as a precaution decided to reset the passwords of all customers. In addition to resetting the passwords SendGrid customers will also generate their DKIM keys again. DKIM is a digital signature that verifies the domain where the emails were sent from. Because of the new DKIM keys will also be the DNS of the domain name must be modified. How not know the account of the employee could be hacked SendGrid late. However, the e-mail service will tighten security.

Sunday, 19 April 2015

Even Linux Users Targeted By Cyber Espionage



Appear regularly reports of attacks by cyber spies who have provided at Windows users, but the Japanese anti-virus company Trend Micro claims to have discovered an attack which also Linux users were targeted. The attacks come from a group that the defense companies, media organizations, Russian dissidents, members of NATO and even the White House has provided.

The attackers have been active for some time and use different tactics to infect their victims with malware. There Microsoft Office documents are used as containing spyware. In another attack were on a Polish government site posted several exploits that install malware on the same unpatched users. Finally phishing emails were also used those users to fake login pages for Microsoft Outlook Web Access (OWA) by sent.

Linux

In the first quarter of this year, the group was very active and used it several new attacks, including sending e-mails with malicious links, which supposedly to news reports seem to indicate. When a user opens the link, and certain conditions are met does the so-called news site with a message that there must be an HTML5 plugin installed to view the content of this website. In the case of Linux users who visit the website will be the X Agent or Fysbis spyware offered, while Windows users get the Sednit spyware.

Furthermore, the attackers use again the counterfeit OWA logon pages. These contain phishing pages JavaScript that when the user opens the link from the OWA preview pane, a tab opens with the intended site. In addition, the JavaScript causes the OWA session is forwarded in another tab to a phishing page that lets you know that the user is logged out and must log in again.

White House

Trend Micro also says to have proof that the group the White House has targeted. Four days after three YouTube bloggers President Barack Obama had interviewed these bloggers were the target of a Gmail phishing attack. According to the virus fighter they tried bloggers likely to use as a springboard for attacks against the White House. Who is behind the attacks is spying is not to say the anti-virus company.