Californian Charged with Cyberstalking Teenage Boys

Californian Charged with Cyberstalking Teenage Boys

A woman from California has been charged with waging a multi-year cyberstalking campaign against three teenage boys.

Brentwood resident Ramajana Hidic Demirovic was charged by a federal grand jury with cyberstalking and conspiracy to commit cyberstalking.

It is alleged that 46-year-old Demirovic harassed and intimidated victims who had entered into romantic relationships with an unnamed co-conspirator between February 2016 and March 2018. One of the relationships lasted just a few days.

According to the indictment, Demirovic and her co-conspirator sent hundreds of malicious, deceptive, and abusive messages to the victims with the aim of sabotaging their personal relationships, social reputation, academic life, and work prospects. 

Demirovic was living in San Francisco at the time the offenses were committed. Her first alleged victim was aged 14 when he dated her co-conspirator for a few days in February 2016. 

When the relationship ended, Demirovic allegedly sent intimidating messages to the victim’s mother and showed up at his school, where she asked other students where she could find him. It is alleged that Demirovic tracked the victim down, whereupon she threatened to “rip [his] f*cking heart out.” 

The defendant’s second alleged victim dated her co-conspirator in the spring of 2016 when he was 15 years old. For months after the relationship ended, Demirovic allegedly sent abusive messages to the victim and falsely informed his employer and school that the boy was physically abusive, used drugs, and abused alcohol.  

In 2018, Demirovic allegedly began a 17-month cyberstalking campaign against a victim who dated her co-conspirator for ten months from May 2017. 

Demirovic allegedly complained to Title IX officers at the third victim’s university that he “harassed and stalked” girls. She is further accused of sending vulgar text messages to his prom dates and spreading lies about his supposed drug use.

According to the indictment, the first two victims were so distressed by the abuse that their grades suffered significantly. The third victim sought therapeutic help after the abuse caused him to experience panic attacks. 

Victims 2 and 3 changed their phone numbers and abandoned social media, where some of the alleged abuse is said to have taken place. 

Demirovic was arrested April 16, and her arraignment is scheduled for April 27. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Cyber Games Launches Cyber Open and Combine

US Cyber Games Launches Cyber Open and Combine

The National Initiative for Cybersecurity Education (NICE) program at the National Institute of Standards and Technology (NIST) has teamed up with marketing and cybersecurity games company Katzcy to launch the first US Cyber Games

Consisting of the US Cyber Open and the US Cyber Combine Invitational, the program will run until October 2021. Included in the program is the selection of the first-ever US Cyber Team to represent the United States at the International Cyber Security Challenge (ICSC).

This year’s ICSC is scheduled to take place in Athens, Greece, in December, so those competing for a place on the team must have an active passport by September 2021 and be able to travel abroad (complying with any travel restrictions).

Other requirements to qualify for the US Cyber Combine and the US Cyber Team are that entrants must be citizens of the United States and aged 18–26 years old.

Athletes selected to compete will learn skills in areas including reconnaissance, cryptanalysis, operations security, forensics analysis, and malware analysis.

In the US Cyber Open, applicants from across the nation will compete in a two-week Capture the Flag (CTF) competition. Participants will be scored in multiple cybersecurity areas as they complete a series of virtual cybersecurity challenges.

The US Cyber Combine Invitational will see 60 cyber-athlete players invited to take part in a variety of virtual learning programs and games over an eight-week period. During this time, the athletes will be interviewed by multiple coaches and put through their paces in a series of aptitude tests before finally performing in an advanced CTF qualifier round.

The 20 best cybersecurity athletes will be selected to form the inaugural US Cyber Team that will go to Athens at the end of the year. 

A call for coaches began on Wednesday and will run until June 1, 2021. The Games’ organizers invite leaders from academia, corporations, and government to apply to be part of the all-volunteer 2021–22 US Cyber Coaching Team. 

“Cyber games are our passion,” said Katzcy CEO Jessica Gulick. 

“We view them not as just events, but as a fundamental element to competency development for the next generation of a diverse and well-qualified community of cybersecurity talent.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US: Ireland Is a Target for Cyber-Criminals

US: Ireland Is a Target for Cyber-Criminals

Ireland has been warned by the United States that storing large amounts of data makes it an attractive target for cyber-criminals.

The caution was uttered by John Demers, the assistant attorney general at the US National Security Division, while giving a keynote address at the IFPC2021 Cybersecurity and FinCrime conference. 

Delegates representing more than 90 countries logged on to view the event as it was live streamed from Dublin on April 21.

Demers shared a quote from nineteenth-century robber and gang leader Jesse James, who drily stated that he robbed banks “because that’s where the money is.” Framing James’ criminal activity in a modern setting, Demers said: “Why would you do a cyber-intrusion in Ireland? Because that’s where the data is.”

“Ireland has developed a wonderful ecosystem for US and European companies to thrive in, benefiting the companies, countries and Irish citizens,” added Demers.

“Having created that environment, it’s important to note that Ireland is now also a target for cybercriminals.”

Demers went on to say that Ireland needs to live up to the trust placed in it by American companies when it comes to data protection. He said that maintaining the security of data “can be achieved through good funding and drawing talent from the companies and all over the world.”

A January report by law firm DLA Piper found that Ireland had the sixth-highest data-breach rate in Europe and the third-highest rate when tallied per capita.

It isn’t just companies from the United States that have trusted the Emerald Isle with their data. Some of the world’s largest companies have chosen to site their European headquarters in Ireland. 

Ireland is home to more than 54 data centers, including sites operated by Amazon, Google, and Microsoft. The largest concentration of data centers in the country is in southwest Dublin.

In September 2020, Paul Budde Communication predicted that the data center market in Ireland would be worth $3bn by 2025. 

According to Ireland’s transmission system operator EirGrid, data centers and other large users will consume 29% of Ireland’s electricity by 2028. The Irish Times reported that worldwide, data center electricity consumption is expected to reach only 8% by 2030. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

GCHQ Director: The UK and Allies Must Counter “Existential Threat” to the Digital Environment

GCHQ Director: The UK and Allies Must Counter “Existential Threat” to the Digital Environment

The UK must work with other liberal democracies to ensure the internet and emerging digital technologies remain free and open. This is the view of Jeremy Fleming, director of GCHQ, who gave the 2021 Vincent Briscoe lecture for the Institute for Security Science and Technology at Imperial College London.

Fleming began by noting the increasingly prominent role of technology in all areas of society, which has been exacerbated by the COVID-19 pandemic in the past year. While technological advancements have had enormous benefits, improving interconnectivity and convenience, they have also provided more opportunities for malicious actors to cause harm. “We must acknowledge that our adversaries benefit too. They exploit the tools that were meant to bring society together to instead create discord,” he said. “They misuse that power to fuel division, exploit vulnerable people and peddle extreme views.”

Overall, Fleming believes the UK has already adapted very well to this transformation, which he compared to a seismic environmental event, such as an ice age. He outlined: “We are world leaders in cyber-defense through the NCSC, the National Cyber Force is transforming the UK’s cyber capabilities to disrupt adversaries through cyber-space, we have a strong tech sector and world class universities training the next generation in science and tech.”

Despite all this, the UK must not rest on its laurels and shouldn’t “assume we will be so in the future.”

This is the result of the rise of other nations whose values differ from our own, centered around authoritarianism and control—in particular Russia and China. These nations have become increasingly active in the cyber-space over recent years, as highlighted by the recent SolarWinds attacks, which were believed to be perpetrated by Russian state-backed actors.  

While Fleming described Russia as currently the “most acute threat” to the UK’s security, the long-term danger comes from China, which is taking steps to shape and control the digital environment, imposing its very different values in the process. “In the digital environment, we face an existential threat to our way of life as the old order is replaced by players who don’t share our values or follow the rules,” he outlined.

Fleming said that China is seeking to “control the global operating system” and is the implementer of emerging technologies that are “changing the digital environment.”

He added: “States that do not share our values will build their own illiberal values into the standards and technology upon which we may become reliant.” This could ultimately mean that “everyone is going to be facing a very difficult future.”

Urgent action is therefore required to counter this trend, and collaboration between like-minded liberal nations is a crucial element in developing systems outside of the control of countries such as China. Fleming said the UK should be at the heart of this and, along with its allies, needs to “use technology to deliver for open societies across the world and those who aspire to join them.”

This requires a multi-faceted approach, including continuing to enhance cybersecurity capabilities and growing the digital skills base in these societies.

Concluding, Fleming said that we need to create “a strategic advantage for the UK and our allies, based on the rule of law, shared ethics and common good.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Last Chance for Forensics Teams Ahead of Emotet Sunday Deadline

Last Chance for Forensics Teams Ahead of Emotet Sunday Deadline

IT security teams have until Sunday to hunt for evidence of Emotet infection, and potentially related malware, before the notorious botnet is removed from all global devices on Sunday, experts have warned.

Back in January, Europol announced that law enforcers had been able to seize the infrastructure used by Emotet in a coordinated international operation.

On Sunday April 25, they will deliver an update (EmotetLoader.dll) file designed to erase the malware from all infected machines globally.

While Emotet started life as a banking Trojan, in recent years it grew into a more complex, modular threat. Among other things, it was used to gain initial access into organizations — which could then be sold to ransomware groups and other gangs to deploy further malware.

Those who were infected with Emotet but don’t know it yet therefore have just days to carry out vital forensics, argued Redscan threat intelligence analyst, Mariya Grozdanova.

“The run key in the Windows registry of infected devices will be removed to ensure that Emotet modules are no longer started automatically and all servers running Emotet processes are terminated. However, it’s important to note that the switch-off does not remove other malware that has been installed on an infected computer via Emotet,” she explained.

“This leaves security teams with only a few more days to uncover Emotet artifacts and whether their organization has been compromised by Emotet, as well as to establish whether other related malware exists on their networks. Unless proper forensic analysis is conducted now, security teams will miss a unique opportunity to identify malware strains that may have the same MO as Emotet, leaving them in a weaker position to defend against future attacks.”

Security experts also warned that those members of the Emotet gang still at large would likely regroup, possibly with improved malware strains.

“While the takedown of Emotet is a big win for all but cyber-criminals, efforts made to replace it with malware such as BazarCall and IcedID demonstrate that cyber-criminal outfits are increasingly organized, ambitious and professionalized,” said Digital Shadows.

“This will almost certainly remain the same in the future; the problem does not end with Emotet, but don’t let this convince you that defenders and law enforcement alike won’t be hot on the tails of any group ambitious enough to replace it.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Lockdown Hotel Bookings at Risk Due to DMARC Fail

Lockdown Hotel Bookings at Risk Due to DMARC Fail

Some of the UK’s biggest hotel brands may be exposing themselves and their customers to the risk of phishing attacks due to a lack of adequate messaging security, according to Proofpoint.

The security vendor took a look at the primary corporate domains associated with the 60 most popular listed hospitality companies in the country, as ranked by YouGov.

It found that half (50%) have no published DMARC (Domain-based Message Authentication, Reporting & Conformance) record. The protocol is important in the fight against scam emails as it is meant to ensure that only authorized senders can send messages from registered domains.

Only 12% of those hotel brands assessed by Proofpoint implemented the strictest level of the protocol (p=reject), which ensures spoofed messages never reach their intended destination.

The other levels are p=none, which means mail is treated the same as non-DMARC validated messages, and p=quarantine, where emails are delivered but into the users’ spam folder.

This means 88% of big-brand hotels in the UK could be exposing their customers to potential email fraud, Proofpoint claimed.

The news comes as cyber-criminals look to capitalize on the huge demand in “staycation” bookings, as the UK comes out of lockdown but foreign travel remains restricted.

Proofpoint cybersecurity strategist, international, Adenike Cosgrove, urged consumers to be vigilant when checking their emails.

“Organizations in all sectors should deploy authentication protocols, such as DMARC, to shore up their email fraud defences,” she added. “Cyber-criminals are paying attention to the increased demand to book last minute travel and will drive targeted attacks using social engineering techniques such as impersonation, and hotel brands are no exception to this.”

Proofpoint recommended consumers  avoid using unprotected Wi-Fi, use strong passwords and do not click on links in unsolicited emails.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

TLS-Encrypted Malware Volumes Double in Just Months

TLS-Encrypted Malware Volumes Double in Just Months

The volume of malware hidden in encrypted traffic has doubled over the past few months as threat actors look to circumvent security tools, according to Sophos.

The security vendor claimed that 23% of the malware it detected in 2020 was encrypted with the Transport Layer Security (TLS) protocol. However, in the first three months of 2021, the figure had grown to reach nearly 46%.

The rise can be linked to an overall increase in use of TLS by popular web services abused by threat actors, explained senior threat researcher, Sean Gallagher.

“A large portion of the growth in overall TLS use by malware can be linked in part to the increased use of legitimate web and cloud services protected by TLS — such as Discord, Pastebin, GitHub and Google’s cloud services — as repositories for malware components, as destinations for stolen data, and even to send commands to botnets and other malware,” he explained.

“It is also linked to the increased use of Tor and other TLS-based network proxies to encapsulate malicious communications between malware and the actors deploying them.”

The challenge with criminals using these services is that they not only hide their activity from security tools, but also benefit from the “safe” reputation of these well-known platforms, Gallagher claimed.

Nearly half of all encrypted malware went to servers in the US and India in Q1 2021, which can partly be explained by Google cloud services — the destination for 9% of TLS malware call-homes — and India’s BSNL (6%).

Gallagher said Sophos had also seen an increase in the use of TLS encryption in customized ransomware attacks, in the form of “modular offensive tools” that use HTTPS. However, the vast majority of malicious TLS traffic is from malware designed to deliver initial compromise of a victim — for example, loaders, droppers and document-based installers, he added.

TLS encryption is also being used to hide the exfiltration of data from compromised networks and C&C communications, said Gallagher.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk