Samsung seeks ways to enter the mobile banking game via a “super app” like WeChat

0
[ad_1]

Samsung doesn’t want to just make smartphones, TVs, and all the other electronic devices it’s famous for. Apparently, the giant seeks ways to launch a so-called “super app” for mobile banking in collaboration with a major South Korean bank.

SamMobile‘s report has it that this is a project of Samsung Financial Networks, a unit under Samsung Group’s financial affiliates.

The proposed super app could evolve from Monimo, a financial services app introduced by Samsung Financial Networks in April 2022. Monimo offers a range of services including money transfers, foreign currency exchange, and tools for comparing prices and searching for real estate and vehicles within South Korea.

While all of this sounds great, Monimo has struggled to build a large user base, only attracting a few million users in the face of stiff competition from bank and fintech-operated apps, which boast tens of millions of users.

Samsung has proposed collaboration with South Korea’s top five banks – KB Kookmin, Woori, Shinhan, Hana, and the digital-first K Bank – to create a mobile banking super app based on Monimo. The banks are expected to present their proposals to Samsung. As Samsung Group does not own a banking entity, this super app project offers a pathway into the mobile banking services market.

What’s a “super app”?


A “super app” is a mobile application that integrates multiple services and functions into a single platform, essentially serving as a one-stop solution for users. These services can include messaging, social media, payment and financial transactions, ordering food, booking transportation and travel, e-commerce shopping, and more.

The idea is to create a seamless, integrated user experience where various needs can be met without leaving the app. Super apps are particularly popular in Asia, with examples like WeChat in China and Gojek in Indonesia, where they have significantly influenced user behavior and digital economy ecosystems.

What’s WeChat?


WeChat is a multifaceted social media and messaging app developed by Tencent in China, first released in 2011. It has evolved into a “super app,” offering a vast array of services beyond its initial messaging function. Users can send text and voice messages, make voice and video calls, share images and videos, and post updates on their personal timelines.

WeChat’s platform extends to mobile payments and financial services through WeChat Pay, enabling users to conduct transactions smoothly, such as bill payments, money transfers, and purchases both online and offline.

Moreover, WeChat serves as a hub for various third-party services, including ride-hailing, food delivery, travel booking, and e-commerce. The app also offers mini-programs, which are smaller sub-applications within the WeChat ecosystem, allowing users to access a wide range of services without needing to install separate apps.

With its comprehensive features, WeChat has become an integral part of daily life for its users, primarily in China, effectively blending social, commercial, and financial functionalities into a single, cohesive platform.


[ad_2]
Source link

Microsoft OneNote Files to Orchestrate Cyber Attacks

0
[ad_1]

Hackers have been found leveraging Microsoft OneNote files as a vector to compromise systems across various industries.

The campaign, under the radar of cybersecurity experts, showcases a new trend in cyber threats, exploiting commonly used office applications to gain unauthorized access to corporate networks.

The Campaign Unveiled

The malicious campaign was first documented by pr0xylife on their GitHub repository. According to researchers from THE DFIR REPORT, it revealed a widespread email phishing operation targeting companies in manufacturing, technology, energy, retail, insurance, and several other sectors.

The emails contained OneNote attachments purporting to be “secure messages,” a guise to trick recipients into opening the files.

Document

Download Free CISO’s Guide to Avoiding the Next Breach

Are you from The Team of SOC, Network Security, or Security Manager or CSO? Download Perimeter’s Guide to how cloud-based, converged network security improves security and reduces TCO.

  • Understand the importance of a zero trust strategy
  • Complete Network security Checklist
  • See why relying on a legacy VPN is no longer a viable security strategy
  • Get suggestions on how to present the move to a cloud-based network security solution
  • Explore the advantages of converged network security over legacy approaches
  • Discover the tools and technologies that maximize network security

Adapt to the changing threat landscape effortlessly with Perimeter 81’s cloud-based, unified network security platform.

Proofpoint Threat Research highlighted the campaign’s relatively low volume, with researchers saying that fewer than a thousand messages were observed over two days.

However, the broad targeting across unrelated industries underscores the threat actors’ intent to cast a wide net, hoping to snag unsuspecting victims.

Execution and Initial Access

The attack begins with the victim receiving an email containing a OneNote file.

Upon opening, this file presents a large “Open” button behind which lies a Windows batch file named “O p e n.cmd.”

Once executed, this file leverages PowerShell to download an IcedID DLL disguised as a JPG file. This DLL then connects to command and control servers, signaling the system’s successful compromise.

OneNote Phishing Email
OneNote Phishing Email

The simplicity of the initial access vector, coupled with the use of a non-sophisticated OneNote file, highlights the attackers’ reliance on social engineering rather than technical sophistication to breach corporate defenses.

Cobalt Strike Beacon and Persistence

The intrusion doesn’t stop at the initial breach.

On the 33rd day of the intrusion, the IcedID malware facilitated the execution of Cobalt Strike beacons, a testament to the attackers’ patience and persistence.

The IcedID malware was observed dropping several files
The IcedID malware was observed dropping several files

Cobalt Strike, a legitimate tool used by cybersecurity professionals, has been co-opted by hackers for malicious purposes, allowing them to maintain a foothold within the compromised network.

The campaign also demonstrated a method for achieving persistence by creating scheduled tasks and installing AnyDesk, a remote desktop software.

During the deployment of AnyDesk, a service creation event was generated under the System channel
During the deployment of AnyDesk, a service creation event was generated under the System channel

This allowed the attackers to return to the compromised system at will, further entrenching their presence within the victim’s network.

Defense Evasion and Privilege Escalation

The attackers employed various techniques to evade detection, including masquerading the malware DLL as a standard image file type and using standard Windows process names for their malicious payloads.

The earliest indicators that something suspicious occurred were the Sysmon events
The earliest indicators that something suspicious occurred were the Sysmon events

Additionally, the initial compromise was facilitated through an account in the domain administrators’ security group, bypassing the need for privilege escalation.

Exfiltration and Impact

The campaign’s ultimate goal appears to have been data exfiltration and ransomware deployment.

Threat actors were so kind to use the sponsored version, to bring some additional PUPs as well
Threat actors were so kind to use the sponsored version, to bring some additional PUPs as well

The attackers prepared for exfiltration by installing FileZilla on the compromised server and later deployed Nokoyawa ransomware, encrypting files and demanding a ransom for their release.

Nokoyawa.

If you see this, your files have been successfully encrypted and stolen.

Don't try to search free decryption method.

It's impossible.

We are using symmetrical and asymmetric encryption.

ATTENTION:

        - Don't rename encrypted files.

        - Don't change encrypted files.

        - Don't use third-party software.

You are risking irreversibly damaging the file by doing this.

If you manage to keep things quiet on your end, this will never be known to the public.

To reach an agreement you have 48 hours to visit our Onion Website.

How to open Onion links:

        - Download the TOR Browser from the official website.

        - Open and enter this link:

               http://nokopay<REDACTED>

        - On the page, you will see a chat with the Support.

        - Send your first message.

Don't waste your time.

Otherwise, all your valuable and sensitive data will be leaked.

Our websites are full of companies that doubted the fact of the data breach or its extent.

        - http://nokoleakb76znymx443veg4n6fytx6spck6pc7nkr4dvfuygpub6jsid.onion/

        - http://hl66646wtlp2naoqnhattngigjp5palgqmbwixepcjyq5i534acgqyad.onion/

        - http://snatchteam.top

This campaign underscores the evolving landscape of cyber threats, where attackers exploit the trust in commonly used applications to bypass traditional security measures.

The use of Microsoft OneNote files to deliver malware represents a shift towards more creative attack vectors, necessitating a reevaluation of cybersecurity strategies to protect against such threats.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

A week in security (March 25 – March 31)

0
[ad_1]

March 29, 2024 – Cybercriminals have taken MFA bombing to the next level by calling victims of an attack from a spoofed Apple Support number.

March 29, 2024 – Backing up your Mac is a simple process that can save your most important files from cyberthreats.

March 29, 2024 – An easy-to-understand guide on how to back up your Windows PC to OneDrive.

March 29, 2024 – An easy-to-understand guide on how to back up your iPhone to a Windows computer

March 29, 2024 – An easy-to-understand guide on how to backup your iPhone or iPad to your Mac.


[ad_2]
Source link

YouTube Music gives the share sheet a new look

0
[ad_1]

Not too long ago, YouTube Music launched a new feature for recognizing songs. And now, the streaming platform is getting another tweak, adding a bit more convenience to the mix.

As reported by 9to5Google, YouTube Music is getting a makeover for the custom share sheet within the Android app. This redesign follows its recent rollout on iOS just a few days back.

Now, when you tap “Share,” you won’t see the grid-based sheet that used to take up more than half of the display. Instead, it is much smaller, featuring a carousel that displays about five targets per screen.

Below, you will find buttons for “Copy link,” which used to be the first option in the previous look, and “Share with other apps” to open the system Share sheet. The new size, about a third of the screen, is more convenient for one-handed usage.

This new design mirrors the layout of the YouTube app, but there are a few distinctions. For example, while the share sheet on YouTube Music spans edge-to-edge, the one on the main app has rounded edges.

YouTube Music launched in 2015 and has been on the rise since then. Stats indicate that its user base jumped by 60% between 2019 and 2020. When it comes to pricing, there is a free tier available for YouTube Music. However, it has several limitations, like no background playing and plenty of ads.

An individual subscription to YouTube Music costs $9.99 per month. Its main rivals, Apple Music and Spotify, also provide individual plans priced at $10.99.

Alternatively, you can access YouTube Music as part of your YouTube Premium subscription, priced at $13.99 per month. This premium package offers ad-free content on the main app, the option to download videos for offline viewing, background play, and additional features. Recently, YouTube Premium crossed the milestone of 100 million subscribers worldwide.


[ad_2]
Source link

DinodasRAT Linux Malware Attack on Linux Servers

0
[ad_1]

DinodasRAT, also known as XDealer, is a sophisticated C++ backdoor targeting multiple operating systems. It is designed to enable attackers to monitor and extract sensitive information from compromised systems covertly.

Notably, a Windows variant of this RAT was employed in attacks against government bodies in Guyana, an operation that was thoroughly analyzed by ESET researchers and named Operation Jacana.

Following ESET’s exposé in early October 2023, a previously unknown Linux variant of DinodasRAT was uncovered.

Indications suggest that this version, labeled V10 by the perpetrators, may have been active since 2022.

However, the first detected Linux variant, V7, dates back to 2021 and has not been publicly detailed. This report delves into the technical aspects of a Linux implant utilized by the attackers.

Are you from the SOC and DFIR Teams? – Analyse linux Malware Incidents & get live Access with ANY.RUN -> Start Now for Free.

Infection and Persistence Mechanisms

The DinodasRAT Linux implant predominantly affects Red Hat-based and Ubuntu distributions. Upon execution, it generates a hidden mutex file to prevent multiple instances from running.

The backdoor achieves persistence through direct execution, SystemV or SystemD startup scripts, and by executing itself with the parent process ID as an argument, complicating detection efforts.

DinodasRAT
Backdoor main code

Victim Identification and Persistence

The RAT gathers system information and infection timing to create a unique identifier (UID) for the victim’s machine, which does not include user-specific data.

This UID comprises the infection date, an MD5 hash of the system’s hardware report, a random number, and the backdoor version.

Document

Download Free CISO’s Guide to Avoiding the Next Breach

Are you from The Team of SOC, Network Security, or Security Manager or CSO? Download Perimeter’s Guide to how cloud-based, converged network security improves security and reduces TCO.

  • Understand the importance of a zero trust strategy
  • Complete Network security Checklist
  • See why relying on a legacy VPN is no longer a viable security strategy
  • Get suggestions on how to present the move to a cloud-based network security solution
  • Explore the advantages of converged network security over legacy approaches
  • Discover the tools and technologies that maximize network security

Adapt to the changing threat landscape effortlessly with Perimeter 81’s cloud-based, unified network security platform.

The UID and other relevant details are stored in a hidden file, “/etc/.netc.conf”, which the RAT uses to maintain a profile of the backdoor.

Stealth and Service Manager Utilization

DinodasRAT employs techniques to avoid updating file access times and leverages Systemd and SystemV service managers to ensure its persistence on infected systems.

It determines the Linux distribution type and installs appropriate init scripts to launch the backdoor after network setup.

Command and Control (C2) Communication

The Linux variant communicates with its C2 server using TCP or UDP, with the domain hard-coded into the binary.

The RAT has a variable timed interval for sending information back to the C2, and if the user is root, communication is immediate.

It follows a structured network packet format and recognizes various commands for managing the infected system.

The Linux variant shares encryption methods with its Windows counterpart, using Pidgin’s libqq qq_crypt library functions and the Tiny Encryption Algorithm (TEA) in CBC mode.

It also shares encryption keys with the Windows version for C2 and name encryption.

The infrastructure used by DinodasRAT’s Linux versions was active during the analysis, with one IP address serving both Windows and Linux C2 domains.

The most affected regions include China, Taiwan, Turkey, and Uzbekistan. Kaspersky products detect this Linux variant as HEUR:Backdoor.Linux.Dinodas.a.

The discovery of the Linux variant of DinodasRAT highlights the threat actors’ capability to infiltrate Linux infrastructure. Unlike the Windows-focused Operation Jacana, the Linux variant does not prioritize user information for infection management.

Instead, it relies on hardware-specific data to generate UIDs, emphasizing the goal of maintaining access to Linux servers.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

TikTok takes a page out of Instagram’s book by working on a new collaboration feature

0
[ad_1]

Social media platforms have a thing for, well, “borrowing” each other’s hottest features. Remember how Reels and Shorts were basically answers to TikTok’s mega-success? Now, it looks like TikTok’s eyeing Instagram’s territory.

The latest is that TikTok’s about to roll out a “Collaboration” feature. Think bigger Duets – creators could invite up to five others for team-up content. Instagram launched something similar a while back. If you’ve used it, you know the drill. One creator sends an invite, the other accepts, both their names show up on the post, and it reaches everyone’s followers.

All the above was spotted by AssembleDebug from TheSPAndroid, who dug into the latest TikTok app code in version 34.1.15, and found a bunch of hints on how the feature would work. Some of the strings he found included the below language:
  • You’re invited to collaborate
  • You’ll be listed as a collaborator on this post. It’ll appear in your profile, but you can’t edit the post, or withdraw any income it may receive.
  • You’ll have to be invited to collaborate again if you change your mind.
  • Decline invite?
  • Accept invite?
  • You’re now a collaborator on this post
  • You’ve declined this invite to collaborate
  • You’re no longer a collaborator on this post
  • Pending invites
  • Can’t invite or remove collaborators
  • Collaborated with
  • Who’s in this post?
  • Invite collaborators
  • You can only invite 5 collaborators
  • You’ll no longer be listed as collaborator on this post, and it’ll be removed from your profile.
  • Leave collaboration?
  • Creators who accept your invite will be listed as collaborators on your post. It will appear in their profile, but only you can edit the post, and withdraw any income it may receive.
  • A new way to create with others on TikTok
  • You can only invite others to collaborate at most 4 times a month
  • You can only invite collaborators if the privacy settings of this post is set to “Everyone”
  • You can only invite collaborators if your account is set to public

The language makes it pretty clear how it’ll likely work, just like on Instagram. Creators send invites, others accept, and everyone gets a visibility boost. And hey, there are even options for politely backing out if you change your mind.For creators and influencers, this could be a huge boost to the creative possibilities, not to mention the audience numbers. TikTok’s also throwing in some limits – only five collaborators and four invites per month – probably to keep things from getting too chaotic.

[ad_2]
Source link

Google Podcasts app closes Tuesday; Google recommends that users migrate to this app

0
[ad_1]
Back in September, and then in December, we told you to expect Google to shut its Podcast app in April 2024. Guess what. According to Forbes, this coming Tuesday, April 2nd, the earlier reports will come true as the next day Google Podcast will go to that place where other Google apps, hardware, and software end up disappearing. And just like the many other things that Google shuts down seemingly for no reason, the Podcast app was a success reaching 500 million downloads exactly one year ago.

The Google Podcast app in the U.S. is going away after April 2nd and many users who have subscriptions to certain podcasts will have to move to another podcast app. This is not a simple process and can leave some Google Podcast users open to having their credentials stolen. In-app notifications were disseminated to users of the Google Podcast app reminding them it would be shut down oafter April 2nd and reminding them to make contingency plans.

One place where Google Podcast users can go in order to continue listening to their favorite podcasts is the YouTube Music app. Google says that the YouTube Music app will be a “better overall destination for fans and podcasters alike with YouTube-only capabilities across community, discovery and audio/visual switching.” On a YouTube support page, Google explains how to move your Google Podcast subscriptions to YouTube Music:

  • Visit the Google Podcasts app
  • Select Export subscriptions at the top of the screen.
  • Select Export under ‘Export to YouTube Music’
  • Select Transfer on the YouTube Music app
  • Select Continue
  • Select Go to Library to view your subscriptions once the transfer is complete

Things to keep in mind:
  • It may take a few minutes for your subscriptions to transfer, so hang tight!
  • Not all podcasts will be available in YouTube Music and you may see a “Content is unavailable” message next to it if that’s the case
  • If a podcast is missing from YouTube Music, you can save it to your library using the show’s RSS feed link

Even though Google Podcast shuts down on April 2nd, users will have until July 2024 to migrate their subscriptions to YouTube Music.


[ad_2]
Source link

Instagram is working on a feature to get friends to share even more Reels with each other

0
[ad_1]

Instagram fans have something new to look forward to with a brand-new feature called “Blend” that is brewing behind the scenes. This feature is expected to mix all your favorite Reels with a friend’s — all curated just for the two of you.

This scoop comes straight from Mobile Developer and Reverse Engineer Alessandro Paluzzi, who took to X to share his discovery. From this, it appears that with “Blend” you’ll have a private place to share Reels recommendations that the Instagram algorithm thinks both you and your friend will identify with.

Spotify vibes, but with Reels

As noted by Techcrunch, this feature is a bit like Spotify’s “Blend” feature, where you can mash up your favorite tunes with a friend to make one shared playlist. Imagine a similar experience, but instead of songs, you’re mixing and matching your favorite short-form videos.

We’re still fuzzy on some key details. For example, right now it looks like “Blends” are totally private, and you can bounce from one anytime, but these details have not been made public. We’ll also have to wait and see if the Reels feed constantly updates, or if there’s a set refresh time.

The appearance of this new feature signals that there’s more at work here by Instagram. “Blend” could be a new initiative to boost Reels and get everyone watching even more. After all,  you and your friends already DM each other all those funny Reels anyway, right? Now, Instagram wants to be part of the action by suggesting what you might love.

Like any project in the works, there’s no guarantee that “Blend” will make it to your Instagram feed. But if it does, it’s got the potential to shake things up. I can definitely see myself using this as I’m doomscrolling through Reels.


[ad_2]
Source link

Patent application reveals possible new Apple Maps features

0
[ad_1]
In a bid to get iOS users to use Apple Maps instead of arch-rival Google Maps, Apple is planning some new features for its navigation and mapping app that might surface in a future version of the Apple Maps app. A new patent application with the title “User interfaces for customized navigation routes” (via autoevolution) gives us some examples of what Apple has in mind for Apple Maps.

One new feature suggested by the patent will allow Apple Maps to determine routes depending on your vehicle’s engine profile. This happens to be something already offered in cars that have Apple Maps embedded inside the infotainment system. With this feature, the app will suggest when the driver should stop to refuel or charge up an EV. The app will look at the range that the vehicle has based on current fuel supply or battery charge and suggest routes within that range.

If the vehicle can’t make it to the destination because there is not enough fuel or battery life remaining, Apple Maps will look for gas stations or charging stations. The app will also estimate how much fuel or battery life will remain after you reach your destination. Users will be able to decide whether to follow the suggestions when to stop to refuel or charge or whether to roll the dice and continue driving.

Another feature listed in the patent will allow Apple Maps to avoid areas where access is limited based on the vehicle’s license plate. Apple Maps will avoid navigating a driver into such a restricted area. The patent also mentions advanced navigation that would be possible by inputting the engine type, more info about the vehicle, and the license plate number. The result will be routes suggested by Apple Maps that suggest when to stop for refueling or charging, and will also bypass areas where there might be a license plate restriction.

Keep in mind that just because Apple files a patent application for new Apple Maps features, it does not mean that the company will receive the patent. Nor does it mean that Apple will definitely add these features to Apple Maps.


[ad_2]
Source link

Israeli LGBTQ App Atraf Faces Data Leak, 700,000 Users Affected

0
[ad_1]
Hacker Claims to Leak Full Atraf Database, Affecting Over 669,000 Users

Atraf, a popular Israeli LGBTQ dating app, has suffered a major data breach exposing personal information of over half a million users – Leaked data includes clear text password and payment card data – Atraf users are advised to change their passwords immediately!

In November 2021, Hackread.com reported a ransom failure leading to the data leak of some Israeli LGBTQ dating app Atraf users. The group responsible for the attack, Black Shadow, originated from Iran. They demanded a ransom of $1 million after acquiring the app’s data by compromising an Israeli hosting service named CyberServe.

Now, a user on Breach Forums, apparently of Russian origin, claims to have leaked the Atraf database, containing the personal data of over 1.5 million users. However, Hackread.com has analyzed the 2.63 GB worth of data, which appears legitimate. After removing duplicates, the total number of leaked accounts decreases to over half a million, precisely 669,672.

It’s worth noting that the Atraf database was leaked twice in 2023 on the same forum. However, neither of these leaks contained clear text passwords or sensitive personal information like the latest one.

Hacker Claims to Leak Full Atraf Database, Affecting Over 669,000 Users
What the Breach Forums user posted on the forum (Credit: Hackread.com)

It’s important to note that the data breach remains alleged until official confirmation from the company. Meanwhile, our analysis reveals a treasure trove of personal and sensitive information, primarily from Israeli users. This information includes:

  • Full names
  • Nicknames
  • County
  • City
  • Age
  • Height
  • Religion
  • Address
  • Phone numbers
  • IP addresses
  • Data of birth
  • Interests and hobbies
  • Sex and Gender
  • Sexual orientation
  • Email addresses
  • Plain text passwords for some
  • Location coordinates
  • Type of smartphone and operating system
  • Conversations in direct messages (DMs)
  • Family details including if they have children or not
  • Payment card data excluding card numbers but including CVV codes, expiry dates, and card types (Master/Visa).
  • And much more…

Hackread.com can confirm that the leaked records date back to 2021, with no recent records. The timeline aligns with the claims made by Black Shadow in November 2021, suggesting that the data might be legitimate.

Hacker Claims to Leak Full Atraf Database, Affecting Over 669,000 Users
Screenshot from the leaked data (Credit: Hackread.com)

Nevertheless, this data breach poses a significant threat to the privacy and physical security of affected users. It can result in online harassment and the hacking of email accounts, as the breach includes clear text passwords.

If you are an Atraf user, you must immediately change the passwords for both your email and Atraf account. Additionally, exercise caution with emails purportedly from Atraf and double-check before clicking any links, as they could be attempts by cybercriminals to compromise your data further or infect your device with malware.

Hackread.com has notified Atraf about the breach, seeking their official response. If you have any concerns about your data, you can also contact Hackread.com at [email protected].

  1. Anonymous Sudan’s DDoS Attacks at Israeli BAZAN Group
  2. Hackers Target Israeli Rocket Alert App Users with Spyware
  3. Israeli El Al Sys Hackers Hit Flights in Mid-Air Hijack Attempt
  4. Hackers Defaces Israeli-Made Equipment at US Water Agency
  5. Iran’s MuddyWater Group Hit Israelis with Fake Memo Phishing
  6. Hamas Hackers Hit Israelis with New BiBi-Linux Wiper Malware

[ad_2]
Source link