Costco Issues Scam Warning

Costco Issues Scam Warning

Costco Wholesale Corporation is warning American internet users to be wary of more than a dozen digital scams targeting its customer base. 

On its website, the American multinational corporation has published screenshots of 14 “prominent fraudulent emails, texts, and posts” in which cyber-criminals are impersonating Costco. 

The majority of the traps use financial benefits to lure victims, promising free products, financial reimbursements, exclusive offers, cash-back rewards, and gift cards worth $50. Many try to trick to victims into sharing their personal information by asking them to take a short survey in order to claim a prize. 

Cyber-criminals impersonating Costco are also exploiting the coronavirus pandemic to con customers. One scam tells shoppers that a Covid-19 stimulus package consisting of $130 of free merchandise will be given to “loyal Costco members” who fill in a customer survey.

Another survey-based scam tells customers that they will receive a free HDTV as a thank you for always paying their bills on time, if they answer questions about their Costco shopping experiences. 

Other social engineering tactics deployed by threat actors include the exploitation of Americans seeking employment. One scam email falsely told the recipient that Costco was “currently taking interviews for positions in your area that pay up to $21.00 per hour.” 

The target was told that after sharing their personal details, they would receive confirmation of a job interview with the company.  

A fraudulent phishing email flagged by Costco uses a limited-time offer and the promise of an exclusive giveaway to put pressure on victims to take the bait. 

It reads: “Congratulations! You have been specially selected to participate in our exclusive giveaway. Click here for a chance to win one of the exclusive prizes from our sponsors. Good luck!”

The scams have appeared in inboxes, mailboxes, on social media, and via text message. One scam tells victims that they have won a prize in the “supermarket customer sweepstakes raffle draw” and will receive their first payment of $6,994,92 after they pay a $3,860 processing fee. 

“These offers are not from Costco Wholesale,” said Costco. “You should not visit any links provided in messages such as these, and you should not provide the sender any personal information.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Google Ordered to Provide Info on Alleged Cyber-bullies

Google Ordered to Provide Info on Alleged Cyber-bullies

A Canadian court has ordered American tech giant Google to disclose who has been operating a YouTube channel and a blog that have allegedly been used for cyber-bullying. 

Wife and husband Sakura Saunders and Darius Mirshahi allege that whoever is behind the blog “Antifa: Exposed” and a YouTube channel they claim is linked to the blog, Undercoverkitty, has targeted them with insults and falsely accused both of them of being involved with a domestic terrorist organization. 

The couple made their allegation in affidavits filed in January 2021 before the Supreme Court of Nova Scotia. Now the court is using the relatively new and rarely used Intimate Images and Cyber-protection Act, Nova Scotia legislation that was introduced in 2017, to order Google to provide information that could identify the couple’s alleged online abuser(s).

Saunders said in her affidavit that content shared on the blog and YouTube channel has incorrectly suggested that she is violent. The writer and social justice activist described the blog as being written in “a hateful tone” and being full of conspiracy theories.

In their court filings, the couple wrote: “The blog alleges the applicant Sakura Saunders made trips to Australia to organize student riots. The blog alleges the applicant Sakura Saunders engages in criminal projects.”

The affidavits also state: “The blog alleges the applicants are a member and a leader of a domestic terrorist organization, which uses extreme violence against those they disagree with the intent of destroying civilization.”

Union organizer Mirshahi, who in a 2010 interview with the Guelph Mercury Tribune, said: “I’m very public about my beliefs. I don’t believe in the state,” is described as an anarchist hailing from Iran on the “Antifa: Exposed” blog.

Mirshahi, who said that he has never been to Iran but is of Iranian heritage, has authored articles themed around revolution and anarchy that were published on Canadian site Interrobang.

The order related to YouTube’s owner Google was issued March 25 by Nova Scotia Supreme Court Justice Richard Coughlan. Google has until the end of April 2021 to supply the requested information. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

INTERPOL to Work with The Coalition Against Stalkerware to Tackle Surge in Domestic Violence

INTERPOL to Work with The Coalition Against Stalkerware to Tackle Surge in Domestic Violence

INTERPOL is set to join The Coalition Against Stalkerware, and will help advance the group’s efforts by educating the global law enforcement community on how to proactively investigate the use of stalkerware, as well as provide support to victims.

The alliance was first set up in November 2019 to try and combat the use of stalkerware, a practice in which victims are monitored through their phone or computer. Initially compromised of 10 stakeholders, including Kaspersky, Norton, the National Network to End Domestic Violence, it has since grown to 35 members. Members are from a variety of different organizations across the world, ranging from vendors to non-governmental organizations and academia.

It undertakes a range of initiatives to combat this growing issue, including providing support to survivors of domestic violence, shutting down malicious surveillance apps and increasing public awareness around the issues.  

INTERPOL’s involvement in the coalition has come amid a surge in domestic violence and tech abuse incidents last year during the COVID-19 lockdown. For example, recent research by Kaspersky found that almost 54,000 of its mobile users were affected globally by stalkerware in 2020.

The international policing organization will now promote training sessions developed by The Coalition Against Stalkerware to its 194 member countries. This aims to better equip domestic police forces to investigate stalkerware, support victims who require assistance and bring the perpetrators to justice.

Craig Jones, INTERPOL’s director of cybercrime, commented: “INTERPOL is committed to supporting the Coalition Against Stalkerware in its fight against abuse, stalking, and harassment via the use of stalkerware. “To this end, we will continue to raise awareness within the global law enforcement community about intimate partner violence, unwanted surveillance and abuse.”

Tara Hairston, official representative of the Coalition Against Stalkerware, and head of public affairs, North America at Kaspersky said: “We understand that all key partners must join to fight against this pervasive tactic of abuse. Given that law enforcement should be able to identify and respond to the threats posed by stalkerware, it’s great to see that INTERPOL is devoted to working with their global community around the topic of intimate partner violence, unwanted surveillance and abuse.

“Alongside INTERPOL and our other partners, we will work to ensure nobody has to fall victim to stalkerware again.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

DoJ Launches Ransomware Taskforce as Apple Hit by Extortion Attempt

DoJ Launches Ransomware Taskforce as Apple Hit by Extortion Attempt

The US Department of Justice has reportedly launched a new ransomware task force, after an infamous threat group claimed to have stolen Apple trade secrets via a supplier.

The REvil (Sodinokibi) group is reported to have posted a blog to its dark web-hosted naming and shaming site in which it claims to have compromised the network of Taiwanese supplier Quanta Computer.

As the firm refused to pay the $50 million ransom, REvil is now putting the pressure on Apple, posting multiple screenshots of Macbook schematics with the promise of more to come. Other firms may also be affected.

“Our team is negotiating the sale of large quantities of confidential drawings and gigabytes of personal data with several major brands,” the REvil operators wrote, according to The Record. “We recommend that Apple buy back the available data by May 1.”

It’s unclear how much REvil is asking the tech giant to pay.

The attempt to extort a victim organization’s customers marks a new and concerning development in the ransomware story, although it’s unclear if the group genuinely has schematics for unreleased products.

It’s something a new US government taskforce will be looking at as it tries to tackle the threat.

The new DoJ taskforce will work to coordinated efforts across the federal government to disrupt C&C infrastructure, seize profits, coordinate training and intelligence sharing and more, according to CNN.

“Although the department has taken significant steps to address cybercrime, it is imperative that we bring the full authorities and resources of the department to bear to confront the many dimensions and root causes of this threat,” acting deputy attorney general John Carlin is reported to have written to DOJ department heads, US attorneys and the FBI on Tuesday.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Security Biz Launches RDP Breach Notification Site

Security Biz Launches RDP Breach Notification Site

A threat prevention firm is claiming to have access to 1.3 million breached RDP servers and their credentials, which were put up for sale on a popular dark web site.

New York-headquartered Advanced Intelligence is offering a new free service enabling concerned organizations to check if their RDP servers were part of the trove.

Ultimate Anonymity Services (UAS) has been running for around five years on the dark web, specializing in providing access to RDP servers. It’s known to be one of the largest and most reliable such marketplace around.

The market for these offerings has exploded over the course of the pandemic, as remote workers use the Microsoft solution to access their corporate Windows desktop from home.

Attacks targeting RDP increased by 768% between Q1 and Q4 last year, according to ESET’s Q4 2020 Threat Report.

“The [UAS] marketplace is tied to a number of high-profile breaches and ransomware cases across the globe. A number of ransomware groups are known to purchase initial access on UAS,” explained Advanced Intelligence. 

“This treasure trove of adversary-space data provides a lens into the cybercrime ecosystem, and confirms that low hanging fruit, such as poor passwords, and internet-exposed RDPs remain one of the leading causes of breaches.”

The threat prevention company’s new RDPwned site invites concerned organizations to submit a request via email, which will be manually verified by the team.

“We will be happy to search for you and your organization based on any reverse DNS, IP addresses, domains, or unique network attributes via the subsequent response email message to the provided contact email address,” it noted.

In the meantime, Advanced Intelligence recommended organizations to enable network-level authentication (NLA), and use two-factor authentication if possible, plus strong and complex passwords.

It also advised RDP-owners to ensure their environment is free from well-known administrative accounts with well-known passwords, and to ensure RDP servers only accept connections from trusted sources.

Organizations can also check Shadowserver’s free service to see if their RDP assets are exposed to the internet.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Prometei Botnet Exploits Exchange Server Bugs to Grow

Prometei Botnet Exploits Exchange Server Bugs to Grow

Security researchers have discovered that a persistent cryptocurrency mining botnet is exploiting still-unpatched Microsoft Exchange servers to grow globally.

Dubbed “Prometei,” the botnet was first reported on in July 2020 and is thought to have been around since 2016, according to Cybereason Nocturnus.

However, the research team found a new development in that the threat actors behind it have been exploiting Microsoft Exchange vulnerabilities CVE-2021-27065 and CVE-2021-26858 to penetrate victim networks, steal credentials and install malware.

These bugs are part of the four zero-days patched by Microsoft back in March after being exploited by Chinese APT group Hafnium.

“The victimology is quite random and opportunistic rather than highly targeted, which makes it even more dangerous and widespread. Prometei has been observed to be active in systems across a variety of industries, including: finance, insurance, retail, manufacturing, utilities, travel, and construction,” senior threat researcher Lior Rochberger of Cybereason noted in a blog post today.

“It has been observed infecting networks in the US, UK and many other European countries, as well as countries in South America and East Asia. It was also observed that the threat actors appear to be explicitly avoiding infecting targets in former Soviet bloc countries.”

After initial exploitation, the botnet is designed to spread across the network in order to install a Monero miner on as many endpoints as possible. To do this, it uses tried-and-tested exploits EternalBlue and BlueKeep, as well as harvesting credentials, and exploiting SMB and RDP alongside other components such as SSH client and SQL spreader, Rochberger said.

Four separate command-and-control (C&C) servers add resilience and make it harder to disrupt the botnet, he added. Prometei is also designed to use Windows or Linux payloads to compromise individual endpoints depending on their OS.

Assaf Dahan, Cybereason senior director and head of threat research, argued that the botnet poses a serious risk as it has been under-reported in the past.

“When the attackers take control of infected machines, they are not only capable of mining bitcoin by stealing processing power, but could exfiltrate sensitive information as well,” he added.

“If they desire to do so, the attackers could also infect the compromised endpoints with other malware and collaborate with ransomware gangs to sell access to the endpoints. To make matters worse, crypto-mining drains valuable network computing power, negatively impacting business operations and the performance and stability of critical servers.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Stallone Classic a Password Favorite

Stallone Classic a Password Favorite

New analysis of leaked login data has revealed which movie titles most frequently feature in passwords.

Specops trawled through more than 800 million breached passwords to determine which big-screen hits were favored by users. The selection was a subset of a list of 2 billion passwords that have appeared in breached lists.

Topping the list was the sports drama Rocky, written by and starring Sylvester Stallone as a kind-hearted working class Italian-American boxer who dreams of fighting his way out of Philadelphia’s slums. 

Rocky, which was released in 1976 and went on to spawn eight sequels, was used as a password nearly 96,000 times. 

Trailing close behind was 1991 American fantasy swashbuckler adventure movie Hook, which showed up in over 75,000 breached password lists. Directed by Steven Spielberg, the film stars Robin Williams as Peter Pan, Dustin Hoffman as Captain Hook, Julia Roberts as Tinker Bell, Bob Hoskins as Mr. Smee, and Maggie Smith as Granny Wendy.

Taking the number three spot with 50,000 uses was The Matrix. Released in 1999, the science fiction action movie starred Keanu Reeves as computer programmer and cybercriminal Neo. 

Superhero movies Batman, Superman, Spider-man, X-men, and Iron Man took the fourth, sixth, eleventh, thirteenth, and fourteenth spots, respectively, while Alfred Hitchcock’s 1960 American psychological horror thriller Psycho came in at number five. 

Children’s movies were also popular, with Frozen scooping the number 12 spot and Shrek taking number 16. While no romantic comedies made it onto the list, epically long romantic disaster movie Titanic beat Terminator to the number 19 spot. 

“While we present this breached password list in good humor, what shouldn’t be taken lightly is the negative impact that weak and compromised passwords can have on an organization’s cybersecurity risk,” said Specops.

“Passwords that show up on breached password lists can leave enterprise email, apps, servers and devices vulnerable to the unauthorized access needed to initiate a cyberattack.”

Password guidelines issued by the National Institute of Standards and Technology (NIST) call for a strict eight-character minimum length. NIST also recommends the use of multi-factor authentication to secure any personal information available online. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk