Here is the state of emoji report for 2023 from the Facemoji keyboard

0
[ad_1]

Just in, Facemoji has released its state of emoji report for the year. This report is coming in just before the world observes the global day set aside for emojis. With this insight, you can get to see the most popular emojis around the world and also in certain parts of the world.

The report also enlightens users on the new ways they can put stickers to good use. Have you ever wondered what was the most used emoji on various apps that you use? It’s quite easy to find out what your most used emoji is, but getting an idea of what others actively use is also fun.

This report shows little or no change in the top five most used emojis around the world. But it also points out a shocking change that might be of concern to a few people. Let’s now jump into the details and find out what insights the latest state of emoji report from Facemoji brings.

Insight from the Facemoji keyboard’s state of emoji reports for 2023

If you aren’t aware, Facemoji is a keyboard that comes with a ton of customization as well as other features. It is an alternative to the regular keyboard that comes with your smartphone. The app has over 1 million downloads on the Google Play Store, and it is free.

From its state of emoji report, it is clear that the top five emojis for 2023 remain the same as those from last year. These emojis are the crying, laughing (with tears), laughing rolling, heart, and the pleading face emoji. But the crying emoji has dethroned the laughing (with tears) emoji as the most used option for 2023.

Asides from these five emojis, Facemoji also compiled a list of the 20 most used options. Making the list are two heart emojis, the moai emoji, and the Argentinian flag. These entries join a host of regular face emojis that you use daily while chatting with friends.

A solid reason behind the Argentinian flag being on the list is as a result of their victory in the 2022 FIFA Men’s world cup. The flag also makes the list of the most used emojis in Argentina, Spain, and Italy. In most countries, the heart, crying, pleading face, and laughing (with tears) emojis are the most used options.

Across most social media apps, laughing (with tears) emojis are the most popular. To experience a new way to use emojis, Facemoji is now prompting users to try out emoji stickers. Also, with the keyboard, users can explore text art and use them to form impressive DIY emojis.

Now you have an idea of the most popular emojis among Facemoji users around the world. Possibly other keyboards might release information on the emojis their users frequent. What are your top five emojis, and why do you actively use them?


[ad_2]
Source link

A Hacking Tools To Launch Cyber Attack

0
[ad_1]

WormGPT, a black-hat-based tool has been recently launched by cybercriminals and has the potential to conduct various social engineering as well as Business Email Compromise (BEC) attacks. This tool has no limitations towards its use and has no boundaries.

The use of generative AI has seen a remarkable reach in recent times. With the release of ChatGPT in November 2022, there have been several AI tools created and refined for multiple purposes. However, here comes a time in which a new AI has been released specifically designed for Black Hats.

Business email compromise, commonly referred to as CEO fraud or whaling, attacks businesses by impersonating senior executives or reliable partners.

BEC Attacks Revolutionised by WormGPT

As per reports, threat actors have been using ChatGPT and other AI-based tools for generating malicious email that seems legitimate enough to convince an employee in giving sensitive information. 

In a forum of cybercriminal discussions, there has been evidence that threat actors rely on ChatGPT for composing BEC emails. Even hackers with low fluency in other languages can use these AI-generative emails for conducting such attacks.

Another discussion mentioned “Jailbreaks” for tools like ChatGPT. These are specially crafted prompts that can make ChatGPT give out sensitive information beyond the scope of its use. It can even provide inappropriate content or generate harmful code.

WormGPT
Jailbreak discussion (Source: Slashnext)

WormGPT

WormGPT was also found on a cybercriminal discussion forum, which was mentioned to be specially designed as a blackhat alternative to other GPTs. It is designed with GPTJ (Generative Pre-trained Transformer-J) language models with a range of features and code formatting capabilities.

WormGPT
WormGPT

In an experiment conducted with WormGPT where it was asked to generate a BEC email for pressurizing an account manager for paying a fraudulent invoice. The results were extremely harmful since they generated a convincing, grammatical error-free, and persuasive email which would convince any employee.

It is recommended for organizations train their employees about these kinds of phishing emails and have appropriate email filters in place for preventing such AI-generative email-based attacks.

Also Read:


[ad_2]
Source link

Fake Ads Manager Software and Malicious Extensions Target Facebook Accounts

0
[ad_1]

Currently, the campaign has affected approximately 800 individuals and businesses globally, including 310 in the United States, with an ad budget compromise of $180,000.

Facebook serves as a thriving platform for optimizing ad campaigns, making it a crucial tool for businesses worldwide to boost their revenues. However, it is not without its downsides, as the platform has been exploited by cybercriminals to spread malware and, even worse, ransomware.

A recent warning issued by Malwarebytes’ senior threat researcher, Jérôme Segura, highlights the need for businesses to be vigilant. He cautions against falling victim to malicious Meta ad manager downloaders and Chrome extensions, particularly when faced with offers that seem too good to be true and involve clicking on suspicious URLs. The primary targets of these attacks are often business account users who are willing to invest their ad dollars in Meta platforms.

Vietnamese Hackers Targeting Businesses’ Advertising Accounts

According to Malwarebyte’s latest blog post, a newly identified cybercrime gang originating from Vietnam has been engaging in targeted attacks on Facebook business users, with the aim of stealing advertising accounts. What makes this situation even more alarming is that victims are not limited to a specific geographic region; the attacks have been reported worldwide.

Jérôme Segura, in his analysis, reported a noticeable surge in sponsored posts and accounts that are attempting to impersonate Meta/Facebook Ad Manager in recent weeks. Delving deeper into the matter, investigators uncovered that the cybercriminals are distributing counterfeit software, falsely promoting it as a more effective tool for optimizing ads on Facebook. Businesses and advertisers need to be aware of this emerging threat to safeguard their accounts and assets.

The cybercrime gang employs malware-infected Chrome extensions as their method of choice to steal Facebook business account credentials. What is particularly intriguing is that Jérôme Segura was able to detect their campaign thanks to a mistake made by the threat actors themselves.

Apparently, the attackers accidentally placed one of the malware files in the wrong location, which ultimately led to the inadvertent exposure of stolen data. This fortunate error provided valuable insights to the researchers at Malwarebytes, aiding them in their investigation and analysis of the cybercrime operation.

What Happens When Meta Business Accounts Get Infected with Malware?

Once the malicious extension is downloaded, the attackers gain control over the business’s ad budget, allowing them to exploit it according to their own agenda. The campaign came to light in early June when the threat actors enticed businesses with deceptive Facebook Ads Manager program installers, distributed through URLs, promising to enhance ad revenues.

To make their scheme more convincing, the attackers utilized fraudulent accounts with thousands of followers. Consequently, the posts made through these accounts quickly went viral, further deceiving unsuspecting victims and expanding the impact of the attack.

The victims are redirected to phishing pages that imitate the appearance of Meta’s official logo and branding. Upon downloading the program file, several components of an MSI installer package are installed in the directory: C:\Program Files (x86)\Ads Manager\Ads Manager. Subsequently, a batch script is initiated, opening a new browser window displaying a custom extension.

In this window, the unsuspecting victim is prompted to enter their Facebook credentials on a deceptive login page. It is through this fraudulent login page that the cybercriminals aim to harvest the victims’ login credentials, granting them unauthorized access to the victims’ Facebook business accounts.

The custom extension cleverly masquerades as an unpacked Google Translate extension, making it appear innocuous and legitimate. However, upon reverse engineering, it becomes evident that the extension’s code is entirely unrelated to its purported function. Instead, the sole purpose of this deceptive extension is to illicitly gather Facebook login credentials and cookies from unsuspecting users.

Fake Ads Manager Software and Malicious Extensions Target Facebook Accounts
Image: Malwarebytes

To exfiltrate the stolen data, the cybercriminals employ a cunning technique of bypassing Content Security Policy (CSP) restrictions by leveraging Google Analytics. This allows them to transmit the stolen information undetected and without triggering any alarms. In effect, the attackers exploit the widely-used Google Analytics service as a conduit to sneak the stolen data out of the victim’s system and into their own malicious infrastructure.

This sophisticated method allows the cybercrime gang to continue their illicit activities discreetly, evading detection while compromising the security and privacy of Facebook business account users.

Just for your information, Facebook Ad Manager is a tool that enables users to run online ads on various social media platforms owned by Meta, including Instagram. Recently, cybersecurity researchers detected approximately 20 malicious ad manager archives, which were used to distribute Chrome extensions with the intention of hijacking Facebook business accounts.

During their investigation, researchers stumbled upon a newly discovered phishing site and found an unexpected mistake made by the cybercriminals. The attackers had failed to include the payload but inadvertently leaked the stolen data.

Recognizing their error, the criminals promptly removed the file from their Google Drive account and then updated the download link on the phishing site with a new file hosted on MediaFire. This move was likely an attempt to cover their tracks and maintain their malicious activities undetected.

Upon further analysis, researchers identified column titles in the Vietnamese language within the stolen data, which were directly related to ad budgets and currencies. This points to the origin of the cybercrime gang or indicates that they might be targeting victims from Vietnamese-speaking regions.

As of now, the campaign has victimized around 800 individuals and businesses, highlighting the severity of the threat and the importance of staying vigilant against such phishing attacks and malware distribution schemes. What’s worse, the threat actors managed to compromise over $180,000 in ad budget including from 300 victims within the United States.

Fake Ads Manager Software and Malicious Extensions Target Facebook Accounts
Targeted regions – Image: Malwarebytes

In previous research, Meta disclosed that threat actors like DuckTail, among others, have been targeting Facebook advertising accounts over an extended period. While Jérôme Segura acknowledges the uncertainty regarding the direct attribution of this threat actor to DuckTail, he highlights the undeniable similarities in motives and a shared preference for hacking Facebook business accounts, which raises the possibility of a connection.

In response to the campaign’s discovery, Facebook has been duly notified, and the company has taken prompt action. To protect themselves, users of Facebook business manager accounts are advised to immediately revoke access for any unidentified users and conduct a thorough scan of their computers to identify and remove any potential malware that might have been installed. Taking these precautionary measures will help safeguard their accounts and data from falling victim to these malicious attacks.

  1. Mandrake Android malware stealing Facebook data since 2016
  2. Facebook ads dropped malware posing as a Clubhouse PC app
  3. CopperStealer malware steals Facebook and Google passwords
  4. Facebook removes 100s of accounts for iOS and Android malware

[ad_2]
Source link

Check out this Google Pixel 8 Pro concept

0
[ad_1]

The Google Pixel 8 Pro (and Pixel 8) are due to be announced in October, as is typically the case for Google. But that has not stopped concept makers from making some really sweet renders on the Pixel 8 Pro. And this latest one from Twitter user @MichaelBTech looks fantastic. Especially the green one.

He’s also put out a concept video showing off all three colors. That’s the white, black and green colors. It’s not a long video, about 37 seconds, but it will definitely get you excited for the Pixel 8 Pro launch in October.

  • Editor’s Note: This is a concept, meaning that it is not the final or even an official design of the Pixel 8 Pro. This is just what a concept designer thinks it will look like, based on some leaks. So please keep that in mind here, that nothing here is official.

A much more curved Pixel

As you can see in this concept, the Pixel 8 Pro is a lot more curved here. Especially around the sides and the corners. It gives it a rather interesting look. And, Google is also not adopting the Pixel Fold’s camera bar here. It’s sticking with the same camera bar from the Pixel 6 and Pixel 7 series. The biggest difference here is that all three cameras are in the same cutout, instead of putting the telephoto in a separate cut out.

In the video, we can’t really see the front. And the few seconds we do see the front, it’s the top. Which doesn’t really show us much, other than the camera cutout is still front-and-center. And the bezels look pretty small.

The concept has Google going with a stainless steel frame and camera bar, which looks really nice, however, it will scratched up very easily. As we’ve seen with the Pixel 7 Pro’s camera bar. So hopefully that isn’t part of the final design when Google unveils it in a couple months.


[ad_2]
Source link

Twitter sues four unknown individuals over data scraping

0
[ad_1]

Ever since the start of the AI revolution, data scraping has become a pressing issue for platforms like Twitter, which hold vast amounts of valuable human conversation. Now, in a recent development, X Corp., the company owned by entrepreneur Elon Musk, has reportedly filed a lawsuit against four unidentified individuals for allegedly scraping user data from Twitter and is seeking over $1 million in damages.

What exactly is data scraping, and how does it affect Twitter?

Data scraping refers to the use of automated programs to gather data from publicly accessible websites, which can be utilized for various purposes, such as training artificial intelligence models or targeted online advertising.

According to the complaint, Twitter has accused four unknown identities of violating its terms of service by scraping user data from the platform. Additionally, the company argues that these unknown actors carried out the scraping through “automated requests” that flooded Twitter’s sign-up page, causing disruptions to the platform’s servers and affecting users’ experiences.

Although the report does mention the actors’ IP addresses, X Corp. claims that it has been unable to discover the identities of the four individuals responsible for the scraping activities. However, it is important to note that the legality of data scrapping is still a subject of debate in the US. This is because a ruling in 2022 by the U.S. Ninth Circuit of Appeals reaffirmed that scraping publicly accessible data does not violate the Computer Fraud and Abuse Act, making it generally permissible.

Twitter’s response

To address this, Twitter implemented several measures, including a rate limit that imposed restrictions on the number of posts a user can view in a single day and restricting access to tweets for users who do not have a registered Twitter account.

“By unlawfully scraping data, Defendants flagrantly ignore not only X Corp.’s Terms of Service but also the privacy preferences of Twitter users,” the filing stated.


[ad_2]
Source link

No, you can’t VPN your way into Threads if you are from the EU. Because Meta says so.

0
[ad_1]
Some of the best phones on the market come with all sorts of quirks. Did you know that Google provides its phones like the Pixel 7 Pro with a free VPN service in some regions? And it’s such a good thing that it does, because curiosity has led all of us to questionable destinations at a point.

But one of the cooler things about VPNs, beyond the extra layer of security and anonymity, is that you can also use it to get access to things that others don’t want you to see. Like region-exclusive Netflix shows or entirely new apps and games.

Such as the recently launched Twitter Threads, which has been blowing up in the last week or so. Well, outside of the EU at least, because these “law” things aren’t letting Europeans hop on the latest theands (no I’m not sorry for that one). Yes, even with a VPN on: it won’t work. 


Because, of course, a lot of online users already tried a VPN service to get over the barrier. Why would they do that? Well, simple really, it is because:

  • The platform is still fresh, so getting tons of new followers is very, very easy. And that is important, because those carry over to Instagram too, which ultimately means that you may get quick access to a boost in popularity.
  • Threads is doing something genius with its marketing: upon signing up to the platform, you get assigned a sequential number. And with this being an internet and all, people turned “having a cool number” it into a fashion statement.

And if that last statement doesn’t send dystopian chills down your spine, I don’t know what will.


Meta, however, is “dedicated to following EU regulations”. The app is smart enough to check more than your signal’s geolocation, so it can prevent you from logging in and taking part in the fun. Some users have managed to log in, but they were not allowed to do anything, so let’s hope that at least they got a cool number assigned for all of their troubles.

The situation really isn’t that complicated: your Meta account connects your Threads account with your Facebook and Instagram accounts. If you’ve had previous activity on there, Meta is probably aware of your estimated (or precise) location.

In other words, you suddenly popping up in LA after spending years in Italy probably isn’t legit.

Even if Meta says it’s dedicated to the idea of bringing Threads over to the EU, let’s not forget that the goal is to harvest more of that tasty user data. But as long as the EU keeps penalizing such nefarious plots through hefty fines, you might be wiser to not hold your breath for Threads. 


[ad_2]
Source link

QuickBlox Framework Vulnerabilities Could Expose User Data

0
[ad_1]

Researchers found the popular chat service QuickBlox exhibiting numerous security flaws. Exploiting the QuickBlox framework vulnerabilities could allow an adversary to access the users’ data from the apps’ databases. QuickBlox patched the flaw with the latest firmware release, urging users to update their systems at the earliest.

QuickBlox Framework Vulnerabilities Risked Users’ Data

According to a recent report from Check Point Research, their researchers and the Claroty Team82 team discovered numerous vulnerabilities in the QuickBlox framework.

QuickBlox is a dedicated chat and video communication service for IoT devices like telemedicine, finance, and other such mobile apps. The service boasts a considerable clientele, serving millions of customers. It also means that any vulnerabilities in the service may risk the security of millions of users.

That’s what the researchers highlighted in their post. Specifically, they noticed secret tokens and passwords stored within the app and insecure QuickBlox API design. Exploiting the vulnerabilities could let an adversary perform various malicious actions.

For instance, the researchers analyzed an Israeli-based intercom app Rozcom. They then exploited the QuickBlox framework vulnerabilities to take over the target intercom devices, access cameras and microphones, wiretap the devices’ feed, and manage door openings.

Likewise, they analyzed a popular telemedicine service, which already had some vulnerabilities. Consequently, combining the app’s issues with QuickBlox flaws allowed the researchers to access the app’s user database, including patients’ personal data, medical history, chat history with the doctors, and medical records. Besides, the flaws also allowed impersonating doctors and chatting with patients in real time without raising alarms.

In their post, the researchers have also shared the proof-of-concept exploits against the apps running QuickBlox API and SDK.

QuickBlox Patched The Flaws

Upon discovering the vulnerabilities, the researchers reported the matter to QuickBlox officials who promptly patched the flaws. Check Point Research confirmed in its post that the vendors have designed a new API and a new secure architecture for the service.

Hence now, all service providers using the QuickBlox framework must update their apps with the latest QuickBlox release immediately to receive the patches.

Let us know your thoughts in the comments.


[ad_2]
Source link

YouTube Music expands podcast support to more countries

0
[ad_1]

YouTube Music introduced podcasts to its platform in April, initially limited to US listeners. However, the company is now rolling out this feature to more countries, allowing a broader audience to enjoy their favorite podcasts through the platform.

According to 9to5Google, the popular streaming platform has extended its podcast feature to listeners in Brazil and Canada. While there has been no official announcement yet, YouTube Music had previously stated that it planned to expand the podcast support to other countries shortly after its introduction in the US.
With the podcast feature, YouTube Music allows users to easily find and listen to podcasts by searching for specific shows or exploring various categories. The platform also offers personalized recommendations based on individual listening history, making it simple to discover new podcast content.


The podcasts feature now comes with a redesigned user experience that includes podcasts as part of the mood filters on the Home page. Alongside the other five mood filters, such as Keep listening and Recommend episodes, the “Podcasts” option will appear. Upon selection, users will be presented with a dedicated feed featuring categories like Gaming, True Crime, Society & Culture, Comedy, etc.


In the Library tab, podcasts now join the filter for Playlists, Songs, Albums, and Artists. Users can create an Auto playlist for “New Episodes” from their subscribed shows and access a collection of previously saved episodes for later listening. Subscribed podcasts will be conveniently organized within the Library alongside other music content.


The Now Playing screen offers several useful features, including a 10-second rewind and 30-second forward option, playback speed adjustment, sleep timer, and access to show details.


Notably, offline and background playback is available to all users, regardless of whether they have a YouTube Premium subscription. However, it is important to note that only podcasts or channels that have uploaded video versions of episodes will be accessible within the YouTube Music platform.


[ad_2]
Source link

Black Box Penetration Testing – Complete Guide

0
[ad_1]
How To Perform External  Black-box Penetration Testing in Organization with “ZERO” Information

Black Box Penetration Testing to the organization is from an external point of view and tests an external network with zero information.

The objective was simple – see how susceptible the organization is from an external point of view and test the effectiveness of the security controls that are managed enterprise-wide.

As such, asides, from the company name, we were given “ZERO” information to perform external black-box penetration Testing.

This black-box external penetration Testing Performing with by a client called (Hackme

OSINT 101

We kicked off with some Open Source Intelligence (OSINT) 101 :).

There are quite a number of open-source intelligence tools – to assist in gathering emails, subdomains, hosts, employee names, etc from different public sources like search engines and Shodan. There is an exhaustive list of such awesome tools here.

Using quite a few open-source intelligence tools, we obtained publicly available documents relating to the organization using Black-box Penetration Testing methods.

With Google Dork to the rescue, we ran some basic search strings: “site:*.hackme.com ext:xls OR ext:docx OR ext:pptx”.

Also Read:  Network Penetration Testing Checklist

Of course, our aim was not to tirelessly search for documents.

Rather, our objective was to understand the organization’s naming schema by examining the metadata of the documents which is found in the “properties section” of the document (most especially Microsoft Word, PowerPoint, and Excel). One can also use FOCA for this.

How To Perform External

From this, I noticed that employees’ emails followed a particular naming convention – the first letter of the firstname + surname @ domain.com i.e. [email protected].

Armed with this knowledge, we forked out from LinkedIn the list of all current employees of Hackme using the following google dork syntax:

site:linkedin.com -inurl:dir “at Hackme” “Current”. A typical example is shown below using Google Inc as a reference company.

By hacking a script to automate the process, we copied out the first names, last names, and the roles of the current employees of Hackme.

A tiring approach is to manually crawl through the Google pages in search of these names and roles or one could also use GoogleScraper:

GoogleScraper -m http –keyword “site:linkedin.com -inurl:dir ‘at Hackme’ ‘Current’” –num-pages-for-keyword 3 –output-filename output.json

Black-box Penetration Testing

Result:  Black-box Penetration Testing

Again, I leave the possibilities to your imagination – but you can easily convert this to a .csv file using https://json-csv.com/ or any other converter that works for you.

Black-box Penetration Testing

then using your favorite word processor (word merge, notepad++, etc) or some good scriptural skills, merge the firstname + lastname – to form your email list.

Feed our Target list a Payload

Since we are simulating Black-box Penetration Testing, we decided (just like what an attacker would do) to gain code execution using malicious payloads.

As such, we thought of creating a payload and sending it via email to employees of Hackme.

We also know that it is a common practice for some file types/extensions to be blocked by the organization’s email filters – to limit exposure to risk.

This then brings us to using Koadic C3 COM Command & Control, a very decent framework just like your Meterpreter or Empire.

What made it really stand out asides from the beautiful interface is that it allows one to dump hashes, download/upload files, execute commands, bypass UAC, scan the local network for open SMB, pivot to another machine, load mimikatz, and a lot more.

So we ran Koadic and set the necessary variables – using the “stager/js/mshta “ module (serves payloads in memory using MSHTA.exe HTML Applications).

Black-box Penetration Testing

The result was a spawn of our HTA payload URL as evidenced in the screenshot above.

However, we need our targets to execute our payload as “mshta payload_url“.

In recent years, HTA payloads have been used as a web attack vector and also, to drop malware on a victim’s PC.

Now we need to get this payload past our victim’s numerous defenses.

Here comes the tricky part – we needed a way to have the victim run “mshta payload_url” without our payload being spawned as a child process of mshta.exe – as we suspect this organization’s blue team may flag this.

Black-box Penetration Testing

Thankfully, we saw the tip on the left from Matt Nelson and interestingly, the team at NCC group has this implemented in Demiguise.

So here is our final payload saved as a .hta file.

Black-box Penetration Testing

The next step typically is to send our .hta payload as an embedded OLE object.

The intended attack scenario was:

  1. Send a Microsoft Word document with our .hta payload embedded as an OLE object.
  2. Get the user to open the Word document and the embedded OLE object.
  3. This spawns a new process and we get shell access to our victim’s PC.

Now we get to the interesting part, we need our victim to open the Microsoft Word document and our payload.

To do this, we need a very compelling story – just because users are getting smarter. So we headed back to doing more recon.

…and more recon

We need to know more about Hackme – specifically the culture and employees’ behavior.

The question we kept asking ourselves was what would interest the employees?”

Where else to get this information than Glassdoor, a platform that gives you an inside scoop on companies with employee reviews about salaries, benefits, and pros and cons of working with the company?

After poring through reviews of Hackme on Glassdoor, we found some common themes:

…and more recon

We need to know more about the target organization’s environment – specifically employees.

The question we kept asking ourselves was – what would interest the employees?

Where else to get this information than Glassdoor, a platform that gives you an inside scoop on companies with employee reviews about salaries, benefits, and pros and cons of working with the company?

After poring through reviews of the target organization on Glassdoor, we found some common themes:

  1. Some employees felt mobility was a challenge as the office is quite a long distance from residential locations.
  2. Employees love the organization because they get free lunches.
Black-box Penetration Testing

But Wait!

As the old saying goes, the fastest way to a man’s heart is through his stomach.

So what better way to get the employees to open our payload-embedded Word document?

Send them an email – telling them there is a change in the FREE LUNCH menu starting tomorrow.

Rather than send a random phishing email to employees that could be spotted easily, we decided a seemingly genuine email would be ideal complete with a Hackme email signature while observing the organization’s email culture.

Now, how do we make our email more believable? By sending an email to the Customer Service/Help Desk with a service request and observing the email signature in the response.

… recon again???

We headed back to Linkedin, to look for the name of either the HR Manager, Logistic Manager, or Admin Manager (whichever is appropriate) of Hackme. We carefully crafted an email signature with the name we selected.

Black-box Penetration Testing

We are halfway through sending our payload now. Have some patience and read on…

It’s time to send our payload

From the metadata recon done earlier, we could tell what our target organization’s document headers and footers looked like.

I then created a new word document like the one shown below with a splitting image of Hackme document template with appropriate headers/footers.

Then we embedded our .hta as an OLE object. Microsoft Word Document >> Insert >> Object >> Package.
We changed the icon to a Microsoft Word icon and also the caption to reflect our message.
Black-box Penetration Testing

Change the icon to Microsoft Word’s icon and also, change the caption to reflect your message.

Don’t Forget the Anti-virus!!!

To check the AV detection rate of our payload – and to see if it will be flagged as malicious by Hackme antivirus solution (if any), we did a quick AV scan on nodistribute.com. Nodistribute.com was used because according to them, they don’t distribute payload samples to AV companies. We scanned both the maldoc and the .hta file as well.

Black-box Penetration Testing

AV Scan of our .hta payload (0 detections)

It’s Time to Send our Email

If the target org does not have SPF, DKIM, and DMARC configured, one can easily spoof the HR Manager, Logistic Manager, or Admin Manager’s email address.

In this case, I created a Gmail account (yes, Gmail works too) using the Logistic Manager’s first name and last name – and then spiced it up with his signature which was gotten earlier.

Black-box Penetration Testing

Let the shells in

Shortly after sending the email, within a period of about 3 minutes, we had at least 30 shell connections! W00t!!!

Black-box Penetration Testing

What next?

The rest they often say is history. From here on, using the mimikatz modules, we escalated privileges, dumped hashes, scanned the local network of Hackme, pivoted into other PCs, browsed the target’s file systems, and even became domain admins, etc.

In conclusion

All in all, this was a very fun engagement. Whilst it may take an attacker a month/2months/a year of dedication to break into an organization – through a loophole at the infrastructure level.

It can be fairly easy for one to gain access by exploiting the human factor.

“Once you understand your target environment, devising a creative means in gaining access to the environment becomes fairly easy”.

The moral of the exercise is: Recon, recon, and more recon – for a wise man once said

Give me six hours to chop down a tree and I will spend the first four sharpening the axe“.

Credits: 

Rotimi Akinyele – Rotimi is an experienced Cybersecurity, IT Governance, Risk, and Compliance (GRC) professional. He is an Assistant Manager, Cybersecurity at BDO UAE.


[ad_2]
Source link

Google Removes Swing VPN Android App Exposed as DDoS Botnet

0
[ad_1]

The app under discussion, Swing VPN – Fast VPN Proxy, was uncovered as a DDoS botnet by a cybersecurity researcher named “Lecromee” on June 4th, 2023.

On June 4th, 2023, cybersecurity researcher “Lecromee” uncovered alarming information about the popular VPN app, Swing VPN – Fast VPN Proxy. Developed by Limestone Software Solutions for Android and iOS platforms, Swing VPN’s Android version was found to be operating as a dangerous DDoS botnet, posing significant risks to its unsuspecting users.

Hackread.com, first reported on the issue on June 21, 2023, after Lecromee’s investigation raised serious concerns. The findings indicated that the app, which claimed to offer legitimate VPN services, was harbouring malicious intent and could carry out distributed denial of service (DDoS) attacks.

Shortly after the report was published, Hackread.com was contacted by Google on June 22, confirming the veracity of the claims. In response to the alarming discovery, Google took immediate action and swiftly removed Swing VPN’s Android app with over 5 million installs from the Google Play Store.

It is worth noting that another app from Limestone Software Solutions, called Hotspot for Swing VPN, has also been removed from the app store along with Swing VPN – Fast VPN Proxy.

Google Removes Swing VPN Android App Exposed as DDoS Botnet

A Google spokesperson emphasized the company’s commitment to user safety and security, stating,

“The app was removed from Google Play on June 22, and the developer has been banned. Users are also protected by Google Play Protect, which warns users of apps known to exhibit malicious behaviour on Android devices with Google Play Services, even when those apps come from other sources.”

Google

The removal of Swing VPN – Fast VPN Proxy app from the official app store highlights the ongoing challenges faced by platforms like Google Play in combating malicious apps. Unfortunately, such occurrences are not uncommon, and Google continuously works to enhance its security measures to protect users.

However, users themselves must remain vigilant and cautious about the apps they download and grant permission to. Cybersecurity experts recommend the following best practices to stay safe:

  • Research Before Download: Always research the app and its developer before downloading it. Check user reviews, ratings, and previous security incidents, if any.
  • Update Regularly: Keep all apps, including VPNs, up-to-date with the latest versions and security patches to minimize vulnerabilities.
  • Verify Permissions: Be cautious about granting excessive permissions to apps. Review and understand the permissions an app requests before installation.
  • Use Reputable Sources: Stick to trusted app stores like Google Play and Apple’s App Store to minimize the risk of downloading malicious apps.
  • Antivirus Software: Install reputable antivirus software on your device to detect and block potential threats.

As the digital landscape continues to evolve, staying informed and vigilant against cyber threats is crucial. The Swing VPN incident serves as a reminder that even seemingly legitimate apps can harbour dangerous intentions, making it essential for users to prioritize their online safety.

If you suspect any app or service is engaging in malicious behaviour, report it to the respective app store or platform immediately. By working together, users, researchers, and tech companies can create a safer digital environment for everyone.

If you are an Android user, you can follow this link to report an app or an app developer. For iOS users, this link can be helpful.

  1. Fake GitHub Repos Delivering Malware as PoCs
  2. Google kicks out 600 malicious apps from Play Store
  3. Apple removed all major VPN apps from Chinese App Store
  4. Google removes ClearURLs Chrome extension from its store
  5. Google Fails To Remove “App Developer” Behind Malware Scam

[ad_2]
Source link