Year: 2019

APT32 Returns with New Techniques to Attack South East Asian Countries

Delaware, USA ā€“ March 22, 2019 ā€“ APT32, also known as the OceanLotus group, is notorious for the cyber espionage campaigns targeting Asian countries and large-scale watering hole attacks. Researchers of ESET analyzed recent group campaigns and found changes in the groupā€™s actions. The adversaries send carefully crafted emails for each target, disguised as current […]

Read More
Carabank is Alive and Well Up

Delaware, USA ā€“ March 21, 2019 ā€“ Carabank group returned to attacks on financial organizations using new tools. The Carabank group (also known as FIN7) has been active for 4 years already; last year U.S. Department of Justice announced the arrest of three group members, who hid their illegal activities under the flag of Combi […]

Read More
LockerGoga Ransomware Strikes Norsk Hydro

Delaware, USA ā€“ March 20, 2019 ā€“ The Norwegian company Norsk Hydro became a victim of a cyber attack and was forced to switch to manual operations. NorCERT warned the organization about attacks using LockerGoga ransomware and defined that Norsk Hydro was one of its victims. The attack began on Monday night, presumably in the […]

Read More
IMAP Protocol Helps Attackers to Bypass Multifactor Authentication

Delaware, USA ā€“ March 19, 2019 ā€“ More than half of the brute force attacks targeted at tenants of G Suite and Microsoft Office 365 are conducted using the IMAP protocol. According to the Proofpoint study, every fourth such attack ends with a successful compromise. Such a success rate is possible because targeted accounts are […]

Read More
WinRAR Exploits Massively Used in Recent Attacks

Delaware, USA ā€“ March 18, 2019 ā€“ Less than a month ago, cyber security community became aware of a severe vulnerability in the archiver, which allows throwing a malicious file into Autorun folder, and to date, researchers have discovered over one hundred of WinRAR exploits used in real attacks. McAfee Labs reported their findings on […]

Read More
GMO Sniffer Steals Card Data on US Websites

Delaware, USA ā€“ March 15, 2019 ā€“ Another group gets into the game using the notorious method of stealing payment card data using JavaScript code inserted to the site. The new family of skimmers, which experts from Group-IB called GMO (after the name of the site associated with the malicious campaign), was found on six […]

Read More
Ursnif and Bebloh Target Japan in Joint Campaign

Delaware, USA ā€“ March 14, 2019 ā€“ A new tsunami of spam struck Japan, infecting users with the latest versions of the Ursnif and Bebloh trojans. In the current campaign, adversaries use a version of Ursnif compiled just a few weeks ago that has a number of new features. Researchers at Cybereason recorded a massive […]

Read More
XSS Hole Gives an Easy Way into WordPress

Delaware, USA ā€“ March 13, 2019 ā€“ Extending WordPress capabilities with plugins doesnā€™t only widen the default functions but also brings a number of risks. Woocommerce Abandoned Cart Lite plugin provides a webadmin with the report of the products frequently bought from the site as well as the details about the shopping card list. However, […]

Read More
Game Dev Under Supply-Chain Attack by Winnti Group

Delaware, USA ā€“ March 12, 2019 ā€“ Game development business has recently become the target of the notorious Chinese Winnti Group, ESET informs in their research. A gaming platform and two headline games have fallen the victims to the recent attack that compromised the networks and darted in a malicious payload. All three victims of […]

Read More
Ryuk Strikes Governmental Systems in Jackson County

Delaware, USA ā€“ March 11, 2019 ā€“ Local governmental systems in Jackson County, Georgia, suffered an extensive attack that made the officials pay the ransom equal to $400,000 to restore the access to the systems after shutting down all the operations. The local services laid under the necessity of conducting the on-time performance on paper […]

Read More