Law enforcement reels in phishing-as-a-service whopper

0
[ad_1]

A major international law enforcement effort involving agencies from 19 countries has disrupted the notorious LabHost phishing-as-a-service platform.

Europol reports that the organization’s infrastructure has been compromised, its website shut down, and 37 suspects arrested, including four people in the UK linked to the running of the site, which also allegedly included the original developer of the service.

Europol’s announcement also hints that this isn’t the end of the story, and users of the platform should ready themselves for some uncomfortable encounters with law enforcement in the future. As Europol said in its release:

A vast amount of data gathered throughout the investigation is now in the possession of law enforcement. This data will be used to support ongoing international operational activities focused on targeting the malicious users of this phishing platform.

The UK’s Metropolitan Police (“The Met”), which spearheaded the operation, says it has already contacted the criminals who used the site:

Shortly after the platform was disrupted, 800 users received a message telling them we know who they are and what they’ve been doing. We’ve shown them we know how much they’ve paid to LabHost, how many different sites they’ve accessed and how many lines of data they’ve received. Many of these individuals will remain the focus of investigation over the coming weeks and months.

In a phishing attack, criminals use emails to trick users into entering details like passwords or credit card numbers into fake websites. The emails and websites typically mimic popular brands like UPS, Amazon, or Microsoft, and copy the format of emails sent by those companies, luring victims with things like fake security alerts.

Phishing-as-a-Service (PaaS) provides the tools and infrastructure criminals need to carry out phishing attacks on a subscription basis, so they don’t have to create and run it themselves. This lowers the barrier to entry for these kinds of crimes and puts sophisticated tools in the hands of people who wouldn’t otherwise have access to them.

LabHost was set up in 2021 and grew to become one of the largest PaaS vendors. Europol says that “with a monthly fee averaging $249, LabHost would offer a range of illicit services which were customizable and could be deployed with a few clicks.” Those services reportedly included a menu of over 170 fake websites for users to choose from, and a campaign management tool called “LabRat” that could capture two-factor (2FA) authentication codes.

The phishing platform is reported to have had 2,000 registered users and was used to create “more than 40,000 fraudulent sites.” The Met says that around 70,000 individual UK victims have been phished using the service, and that globally, it swallowed up 480,000 card numbers, 64,000 PIN numbers, and more than one million passwords.

Victims in the UK have been contacted by the Met to inform them that some of their data has been compromised. Ironically, thousands of victims being contacted in this way creates an opportunity for copycat phishing emails with Met branding. For that reason, the Met has been careful not to include any links in its communications and warns potential victims that:

…if you receive any contact from the Met with links in, this will be fraudulent so please do not engage with this.

If you’ve been contacted by the Metropolitan Police about the LabHost breach you can find some useful guidance and support on its LabHost Disruption page.


[ad_2]
Source link

Adobe launches the Adobe Express mobile app

0
[ad_1]

Over the years, Adobe has been an extremely developmental company for creators, but the company has made a hard pivot and started integrating generative AI into many of its products. Last year, the company revamped its Adobe Express desktop application. Now, the new Adobe Express mobile app is available, and it brings some generative AI capabilities.

Nowadays, it should be no surprise that so many companies are going hard on AI. It’s a tool that allows people to either streamline their workflow or skip it altogether. Well, Adobe is no different. The company has its Firefly suite of AI tools, and it uses it to power its AI experience.

Recently, we got the news that Adobe Premiere is getting some generative AI tools. One tool will allow you to insert artificially generated frames to extend your shots. Another will be able to artificially generate B-roll footage for you. This shows the company’s commitment to the fast-growing technology.

The Adobe Express mobile app has landed

Android users may be surprised to know that Adobe is launching this app on both iOS and Android at the same time. The app officially launched on Wednesday, so you can download it now.

What can you do with the Adobe Express mobile app? Well, you have access to the classic Gen-AI tools that you would see with most services. There are tools for generating images and graphics. So, if you are a designer, you will be able to quickly generate images and use them in your projects.

There are also other AI tools for photo and video editing. You will be able to create all sorts of impressive media just by using these tools.

There’s no doubt that this will be a very popular app because Adobe’s products are usually industry standards. So, many people should expect to see works made using the Adobe Express mobile app in the future. You should expect to have to sign in to your Adobe account to use these tools.


[ad_2]
Source link

Sneaky Android Malware Evades Detection – Is Your Phone Safe?

0
[ad_1]

Another day, another trojan is on the loose, targeting Android users. This time, the ‘SoumniBot’ was found, and some pretty clever tricks were used to avoid detection. Currently, it’s mainly targeting users in South Korea by leveraging weaknesses in the manifest extraction and parsing procedure.

As you might or might not know, every Android app comes with a manifest XML file, which is located in the root directory and declares the various components of the app, as well as the permissions and hardware and software features it requires. Because this is so widely known, threat hunters typically commence their analysis by inspecting the app’s manifest file to determine its behavior.

It’s important to note that this method has been adopted by threat actors associated with several Android banking trojans since April 2023. Additionally, SoumniBot also misrepresents the archived manifest file size, providing a value that exceeds the actual figure because the “uncompressed” file is directly copied, with the manifest parser ignoring the rest of the “overlay” data.

Kaspersky researcher Dmitry Kalinin stated that this malware is notable for its unconventional approach to evading analysis and detection. Kalinin has also said, “Although any unpacker that correctly implements compression method validation would consider a manifest like that invalid, the Android APK parser recognizes it correctly and allows the application to be installed.”

SoumniBot will be invisible once your device is infected

Like many other trojans that affect Android devices, SoumniBot will hide its icon after installation, making it more difficult to remove. But it does remain active int he background, uploading data from the victim.

Kaspersky goes into more detail about this Android Trojan, as well as providing some indicators of compromise, so you can protect yourself and your device(s). The reason for Kaspersky to detail the techniques used by this Trojan is so that researchers around the world are aware of the tactic and can put together resolutions to keep SoumniBot from causing more havoc.


[ad_2]
Source link

TikTok wants a “For You” feed free of problematic topics

0
[ad_1]

TikTok is getting tougher on users who repeatedly post content on problematic topics. The company just updated its community guidelines with detailed information on the types of videos people should avoid posting to avoid restrictions.

TikTok is currently one of the most popular platforms among young people. However, the type of content it allows has led it to serious problems with the United States government. Currently, the TikTok team is trying to gain the favor of American officials to continue operating normally in the country. After all, losing such a large and lucrative market would be a serious economic blow.

TikTok will restrict accounts that repeatedly post about problematic topics

In a new effort to make the platform safer for young people, the company will begin restricting the accounts of users who continually post problematic content. The restrictions will cause videos from restricted accounts to not appear in the “For You” tab. This tab is a feed of recommended videos according to the user’s tastes. It is the main source of discovery for accounts to follow, so appearing there is important for growth.

To make things clear, the latest TikTok community guidelines detail what type of content qualifies as a “problematic topic.” They mention some obvious topics, such as dangerous activities that young people are encouraged to follow. For example, the risky “challenges” that have led some to even lose their lives.

Content that is sexually suggestive and potentially related to eating disorders will cause restrictions too. Additionally, content from users under 16 years of age will not be eligible to appear in the “For You” tab.

Content that promotes misinformation will also cause restrictions

The company also places special emphasis on avoiding posting misinformation and conspiratorial content. The community guidelines in this regard include conspiracy theories, repurposed media, harmful health misinformation, misrepresenting authoritative sources, and unverified claims.

The consequences that restricted accounts will face

The restrictions will occur on those TikTok accounts that repeatedly post problematic topics according to the latest guidelines. They will not be limited to not being eligible to appear in the “For You” tab. Restricted accounts will also be difficult to find using the search box. If your account receives a restriction, you will receive a notification that will give you the opportunity to appeal.

The changes will take effect on May 17. So, content creators have time to update their accounts. If they don’t, the platform will stop its growth.


[ad_2]
Source link

Russian APT44 The Most Notorious Cyber Sabotage Group

0
[ad_1]

As Russia’s invasion of Ukraine enters its third year, the formidable Sandworm (aka FROZENBARENTS, APT44) cyber threat group remains highly active and increasingly integrated with Russian conventional military operations in support of Moscow’s war aims. 

However, Sandworm’s disruptive operations now span globally across Russian political, military, and economic interests.

With 2024 seeing record participation in national elections, the group’s history of attempting to interfere in democratic processes elevates potential near-term threats. 

Recently, cybersecurity researchers at Google’s Threat Intelligence team unveiled that Russian APT44 is the most notorious cyber sabotage group globally.

Russian APT44 Most Notorious Gang

The operationally mature APT44 (Sandworm) which is sponsored by Russian military intelligence infrastructure, carries out the full range of spying, warfare, and influencing operations – something that is quite unique to state groups who often specialize.

APT44’s spectrum of operations (Source – Google Cloud)

Russia’s “information confrontation” cyber warfare doctrine necessitates these abilities.

In pursuit of this, APT44 has actively sought to create several initiatives that would end up giving Russia an upper hand during times of war, Mandiant said.

During the early stages of the invasion, it ran a fierce campaign with wiper malware against Ukrainian critical infrastructure, sometimes aligned with kinetic strikes.

As the war proceeded, APT44 switched its interest towards intelligence gathering and launched campaigns to extract data from captured devices that could be used as intelligence sources for Russian forces at the front line.

The group’s changing strategy illustrates flexibility in support of Moscow’s military goals.

APT44’s wartime disruptive activity (Source – Google Cloud)

As an arm of Russian military intelligence, APT44’s sabotage operations extend beyond military objectives to support the Kremlin’s broader national interests like political signaling, crisis response, and preserving perceived global reputation. 

This has resulted in historically consequential attacks like disrupting Ukraine’s power grid in 2015-2016, the global NotPetya strike on Ukraine’s Constitution Day 2017, and the disruption of the 2018 Pyeongchang Olympics opening ceremony over Russia’s doping ban. 

With high capabilities, risk tolerance, and a far-reaching mandate backing Russian foreign policy across governments, civil society, and critical infrastructure globally, APT44 presents a severe, persistent threat wherever Russian interests intersect. 

Its aggressive cyber offense increases new attack concepts, likely lowering barriers for other state and non-state actors, a risk Russia itself appears concerned about based on observed defensive exercises.

APT44 is a well-known Russian-based advanced persistent threat group constituting a critical and growing international cyber threat.

For ten years, this group has been at the forefront when it comes to conducting cyber-attacks that are aimed at promoting the nationalist agenda of Russia, which focuses mainly on elections, sports events, and geopolitics.

The Ukraine war still continues, but APT44 has not shifted its concentration from the region as it may further the Kremlin’s global strategic goals, consequently perhaps impacting political dynamics, elections, and matters surrounding Russian neighboring countries.

Looking to Safeguard Your Company from Advanced Cyber Threats? Deploy TrustNet to Your Radar ASAP.


[ad_2]
Source link

Google could bring a “Look and Sign” feature to the Pixel Tablet

0
[ad_1]

Google is reportedly working on a new “Look and Sign” feature for the Pixel Tablet. This new feature will likely offer users a new way to interact with Google Assistant on their device. It’s worth noting that the Pixel Tablet comes with an included charging speaker dock. It allows users to use their tablet just like they would a Nest Hub Max.

Thanks to the speaker dock, users can easily manage their smart home and get answers to their queries through Google Assistant. But, this is likely to change with the future update coming to the Pixel Tablet.

In a recent APK teardown of the Google Search app, 9to5Google found that a revamped feature like Nest Hub Max’s “Look and Talk” is in the works. For those who are uninitiated, the Look and Talk feature on Nest Hub Max uses the device’s built-in camera to recognize when a user is talking while looking at it.

This eventually eliminates the whole “Hey Google” process and streamlines it for a better user experience. Not to forget, rumors about the development of the Look and Talk feature for the Pixel Tablet already surfaced online a few months ago.

A new ‘Look and Sign’ feature might come soon to your Pixel Tablet

The teardown revealed the feature in the Google Search app beta version 15.15. There were some strings of code labeled as “LnS” that pointed out the Look and Talk feature. Although Google chooses to hide these labels, 9to5Google managed to forcibly enable it in the “Assistant on Hub Mode” settings.

While there’s no exact information on what this could mean, there are a few possibilities around how the Look and Sign feature would work. First, Google might allow users to make hand gestures to engage with Google Assistant rather than saying “Hey Google.” It could be a thumbs-up, pointing fingers at the camera, or hand-waving.

Secondly, Google could bring the “Look and Sign” feature to cater to Pixel Tablet users who use sign language. No doubt, the possibilities are immense. But, if Google chooses this route, it would require advanced machine learning capabilities to achieve it.

Although Google is gradually replacing Google Assistant with Gemini, the new finding hints that Google Assistant is here to stay. At least in smart home devices, if not all of Google’s products.

This feature is in a very early stage. So, the launch date for the Pixel Tablet’s “Look and Sign” feature is unknown as of now. However, we might hear some of it in the upcoming Google I/O 2024 event, scheduled for May.


[ad_2]
Source link

FIN7 Hackers Attacking IT Employees Of Automotive Industry

0
[ad_1]

IT employees in the automotive industry are often targeted by hackers because they have access to sensitive information such as customer data, intellectual property, and critical systems.

The connected technologies’ dependence on the automotive industry and the value of their data make them attractive targets for threat actors.

BlackBerry analysts recently discovered that the FIN7 hackers are actively attacking the IT employees of the automotive industry.

FIN7 Attacking IT Employees

According to some BlackBerry evaluations at the end of 2023, there was a spear-phishing campaign against a major United States-based car manufacturer by FIN7 hackers. 

FIN7 used a free IP scanning tool as bait to exploit IT staff with admin rights and then deployed their Anunak backdoor. 

It has been reported that these attacks were part of a broader campaign by FIN7, a financially motivated APT group from Russia known to be focused on sectors such as transportation and defense. 

However, before this happened, the Blackberry team interrupted before they could perform a ransomware attack.

This demonstrates the importance of detecting early intrusion to mitigate possible losses.

FIN7 then shifted to hunting big game that could pay bigger ransoms, with great detailed plans for maximizing the impacts of attacks.

They are scouts who select and study targets carefully, zooming in for employees with high access rights and delivering payloads such as “WsTaskLoad.exe” via spear-phishing emails containing malicious URLs.

These attacks take advantage of trust in legitimate sites, highlighting the necessity for strong cyber security measures to mitigate such advanced threats.

Attack chain (Source – BlackBerry)

WsTaskLoad.exe executes the final payload of Anunak/Carbanak in multiple stages. It is called jutil.dll, and it then executes the exported function “SizeSizeImage.”

jutil.dll now reads and decrypts infodb\audio.wav; its decrypted blob is shellcode that gets copied to mspdf.dll, and it runs as code there.

This shellcode also reads and decrypts infodb\audio.wav again; this decrypted blob is a loader that can be loaded and run later by the same shellcode.

The loader identifies files in the current directory with dmxl.bin and dfm\open.db matching a certain mark.

The decrypted dmxml.bin constitutes the Anunak payload, having “rabt4201_x86” as the campaign ID.

Besides this, the WsTaskLoad.exe performs scripting dissemination and persistence establishment. The first thing it does is run an obfuscated PowerShell script called powertrash.

This is established by the persistent installation of OpenSSH, scheduled as a job that opens up firewall ports.

The fake lure website “advanced-ip-sccanner[.]com” was pointed at “myipscanner[.]com”, and several other domains were registered too.

Post compromise, OpenSSH is utilized for external access with an SSH tunnel proxy server using a common fingerprint.

The target was a large multinational automobile manufacturer whose IT department had been deliberately pointed against.

The obfuscation and tool employed resemble FIN7 POWERTRASH tactics, confirming that the actor behind this incident was likely FIN7.

Recommendations

Here below we have mentioned all the recommendations:-

  • Conduct Regular Security Training
  • Social Engineering Awareness
  • Phishing Report System
  • Multi-Factor Authentication
  • Password hygiene
  • Security Updates and Patch Management
  • Endpoint Security Solutions
  • Monitor Suspicious Behavior
  • Data Protection and Encryption
  • Email Filtering and Authentication
  • Incident Response

Looking to Safeguard Your Company from Advanced Cyber Threats? Deploy TrustNet to Your Radar ASAP.


[ad_2]
Source link

Mental health company Cerebral failed to protect sensitive personal data, must pay $7 million

0
[ad_1]

The Federal Trade Commission (FTC) has reached a settlement with online mental health services company Cerebral after the company was charged with failing to secure and protect sensitive health data.

Cerebral has agreed to an order that will restrict how the company can use or disclose sensitive consumer data, as well as require it to provide consumers with a simple way to cancel services.

After a data breach in 2023 Cerebral disclosed that it had been using invisible pixel trackers from Google, Meta (Facebook), TikTok, and other third parties on its online services since October 2019.

A tracking pixel is a piece of code that website owners can place on their website. The pixel collects data that helps businesses track people and target adverts at them. That’s nice for the advertisers, but the combined information of all these pixels potentially provides a company with an almost complete picture of your browsing behavior and a lot of information about you.

The FTC statement claims that by using these tracking pixels, which are invisible to the website visitor unless they look at the underlying code, Cerebral provided the sensitive information of nearly 3.2 million consumers to these third parties.

The complaint points out that to get consumers to sign up for Cerebral’s services and to provide detailed personal data, the company claimed to offer “safe, secure, and discreet” services, saying that users’ data would be kept confidential.

Also, according to the complaint, the company specifically claimed in many instances that it would not share users’ data for marketing purposes without obtaining people’s consent.

Many organizations are unclear about how much information the social media companies behind the tracking pixels can gather. In the Notice of HIPAA Privacy Breach Cerebral disclosed that the following data were potentially exposed:

  • Full name
  • Phone number
  • Email address
  • Date of birth
  • IP address
  • Cerebral client ID number
  • Demographic information
  • Self-assessment responses and associated health information
  • Subscription plan type
  • Appointment dates
  • Treatment details and other clinical information
  • Health insurance/pharmacy benefit information

Among other penalties, Cerebral has to refund $5.1 million to customers who were impacted by deceptive cancellation practices and pay a $10 million civil penalty, limited to $2 million due to Cerebral’s inability to pay the full amount.

The number of breaches concerning health information is shocking. As required by section 13402(e)(4) of the HITECH Act, the Secretary of the US Department of Health and Human Services Office for Civil Rights publishes a list of breaches that reveal unsecured protected health information affecting 500 or more individuals.

We have reported about similar cases that involved tracking pixels. Research done by TheMarkup in June of 2022 showed that Meta’s pixel showed up on the websites of 33 of the top 100 hospitals in America.

Protecting yourself from a data breach

There are some actions you can take if you are, or suspect you may have been, the victim of a data breach.

  • Check the vendor’s advice. Every breach is different, so check with the vendor to find out what’s happened, and follow any specific advice they offer.
  • Change your password. You can make a stolen password useless to thieves by changing it. Choose a strong password that you don’t use for anything else. Better yet, let a password manager choose one for you.
  • Enable two-factor authentication (2FA). If you can, use a FIDO2-compliant hardware key, laptop or phone as your second factor. Some forms of two-factor authentication (2FA) can be phished just as easily as a password. 2FA that relies on a FIDO2 device can’t be phished.
  • Watch out for fake vendors. The thieves may contact you posing as the vendor. Check the vendor website to see if they are contacting victims, and verify any contacts using a different communication channel.
  • Take your time. Phishing attacks often impersonate people or brands you know, and use themes that require urgent attention, such as missed deliveries, account suspensions, and security alerts.
  • Set up identity monitoring. Identity monitoring alerts you if your personal information is found being traded illegally online, and helps you recover after.

Malwarebytes has a new free tool for you to check how much of your personal data has been exposed online. Submit your email address (it’s best to give the one you most frequently use) to our free Digital Footprint scan and we’ll give you a report and recommendations.


We don’t just report on threats – we help safeguard your entire digital identity

Cybersecurity risks should never spread beyond a headline. Protect your—and your family’s—personal information by using identity protection


[ad_2]
Source link

Galaxy Z Fold 6, Flip 6 to feature Corning and Schott UTG substrate

0
[ad_1]

Samsung may have finalized the Galaxy Z Fold 6 and Galaxy Z Flip 6’s component suppliers. According to the Korean media, the company will keep the same suppliers for the ultra-thin glass (UTG) substrate and its back-end processing orders for the new foldables. The devices are expected to arrive in July.

Samsung finalizes its UTG partners for the Galaxy Z Fold 6 and Flip 6

Galaxy foldables feature an extremely thin layer of glass in the display assembly. It adds some strength to the flexible display. Since the third-gen models in 2021, South Korean firms Econy and Dowoo Insys have been handling the back-end processing orders for the UTG panels for Samsung foldables. They remain Samsung’s partners for the Galaxy Z Fold 6 and Galaxy Z Flip 6.

Like last year, Dowoo Insys will work on the UTG panel for the Fold model, while Econy will handle the job for the Flip. Back-end processing for UTG involves thinning the UTG substrate supplied by the vendor and cutting plates according to the display size. Samsung will provide them with the dimensions and other info on the folding displays for the new foldables.

According to The Elec, the Galaxy Z Fold 6’s UTG panel will feature Schott’s substrate. The Galaxy Z Flip 6, on the other hand, will use Corning’s UTG substrate. All of these firms are part of Samsung’s supply chain. Corning and Econy are part of the smartphone division’s supply chain, while Schott and Dowoo Insys are part of the display division’s supply chain.

Samsung’s smartphone division also has another Korean firm UTI as its back-end processing partner. However, UTI’s etching technology reportedly isn’t up to the mark, so Samsung didn’t sign it up for the Galaxy Z Flip 6. UTI has several Chinese smartphone companies as its customers, though the report doesn’t specify whether it handles back-end processing for any foldable device.

Samsung may have more foldable smartphones in the pipeline

Samsung may launch more than two foldable smartphones this year. Alongside the Galaxy Z Fold 6 and Galaxy Z Flip 6, there are also strong rumors about the Galaxy Z Fold 6 Ultra. Additionally, the Korean firm may also be working on two low-cost foldables. They could be called Galaxy Z Fold FE and Galaxy Z Flip FE. The “FE” in Samsung’s product branding stands for Fan Edition. These devices usually offer a mix of flagship features and affordability. Time will tell how much truth is in these rumors.


[ad_2]
Source link

Snapchat’s AI-generated images get watermarks

0
[ad_1]
Snap announced early this week some improvements to its AI related tools. The most important change is Snap’s decision to add watermarks to all AI-generated images shared via Snapchat.

The watermark seen below (a small ghost logo with a sparkle icon beside it) will appear on image created with Snap’s generative AI tools when the image is exported or saved to camera roll.

Besides adding watermark to all AI-generated images, Snap announced it has developed more safeguards to ensure all AI-powered features adhere to its safety and privacy regulations.

For instance, Snap announced it has created a safety review process to detect and remove potentially problematic prompts in the earliest stages of development of AI Lens experiences. Going forward, all Snap’s AI Lenses that generate an image from a prompt will go through this process before they’re finalized and become available on Snapchat.

Finally, Snap revealed that it’s implementing additional testing to minimize potentially biased AI results but didn’t offer any other details.


[ad_2]
Source link