Easy SMS Hijacking

Vice is reporting on a cell phone vulnerability caused by commercial SMS services. One of the things these services permit is text message forwarding. It turns out that with a little bit of anonymous money — in this case, $16 off an anonymous prepaid credit card — and a few lies, you can forward the text messages from any phone to any other phone.

For businesses, sending text messages to hundreds, thousands, or perhaps millions of customers can be a laborious task. Sakari streamlines that process by letting business customers import their own number. A wide ecosystem of these companies exist, each advertising their own ability to run text messaging for other businesses. Some firms say they only allow customers to reroute messages for business landlines or VoIP phones, while others allow mobile numbers too.

Sakari offers a free trial to anyone wishing to see what the company’s dashboard looks like. The cheapest plan, which allows customers to add a phone number they want to send and receive texts as, is where the $16 goes. Lucky225 provided Motherboard with screenshots of Sakari’s interface, which show a red “+” symbol where users can add a number.

While adding a number, Sakari provides the Letter of Authorization for the user to sign. Sakari’s LOA says that the user should not conduct any unlawful, harassing, or inappropriate behaviour with the text messaging service and phone number.

But as Lucky225 showed, a user can just sign up with someone else’s number and receive their text messages instead.

This is much easier than SMS hijacking, and causes the same security vulnerabilities. Too many networks use SMS as an authentication mechanism.

Once the hacker is able to reroute a target’s text messages, it can then be trivial to hack into other accounts associated with that phone number. In this case, the hacker sent login requests to Bumble, WhatsApp, and Postmates, and easily accessed the accounts.

Don’t focus too much on the particular company in this article.

But Sakari is only one company. And there are plenty of others available in this overlooked industry.

Tuketu said that after one provider cut-off their access, “it took us two minutes to find another.”

Slashdot thread. And Cory Doctorow’s comments.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Mom Charged in Deepfake Cheerleading Plot

Mom Charged in Deepfake Cheerleading Plot

A 50-year-old mom from Pennsylvania has been arrested after allegedly using deepfake technology to tarnish the reputations her daughter’s cheerleading rivals.

Raffaela Marie Spone, of Chalfont, Bucks County, is accused of using technological trickery to make videos that appear to show members of a cheerleading group naked, smoking, or drinking. 

The deepfake videos were sent to the cheerleaders’ coach in an alleged attempt to get the girls kicked off the squad. 

Hilltown Township Police Department launched an investigation in July last year after a minor reported that she was being harassed via text message. 

“During the course of the investigation, additional juvenile victims of harassment came forward. The victims were all found to be part of a cheerleading group based in the Doylestown area,” said the Hilltown Township Police Department.

“As part of the investigation, police executed multiple search warrants to determine the origin of the harassment. The investigation led police to an adult female who was affiliated with the cheerleading group.”

Spone allegedly doctored photos and videos of at least three members of the Victory Vipers, her daughter’s cheerleading team. The altered content was allegedly downloaded from the girls’ social media accounts. 

The Philadelphia Inquirer reports that Spone allegedly sent the deepfake photos and videos to the girls along with messages urging them to kill themselves. 

George Ratel, father of one of the girls Spone is accused of targeting, was bewildered by the mom’s alleged actions. 

“I don’t know what would push her to this point. As a dad I was pretty upset about it. It’s an image put out there of my daughter that is simply not true,” he said.

Police said they found evidence on Spone’s cell phone that linked her to harassing texts and images received by the cheerleaders. 

Spone was arrested on the afternoon of March 4th and has been charged with three misdemeanor counts of cyber-harassment of a child and three misdemeanor counts of harassment. 

No evidence has been found to suggest that Spone’s daughter was aware of her mother’s alleged attempts to redirect the limelight. 

A 2020 study funded by the Dawes Centre for Future Crime at University College London ranked fake audio or video content as the most worrying use of artificial intelligence in terms of its potential applications for crime or terrorism.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Acronis Acquires South African Partner

Acronis Acquires South African Partner

Global technology company Acronis has completed its fourth acquisition in the past 18 months by acquiring its long-time partner in South Africa.

The acquisition of Synapsys was announced as part of an accelerated growth plan being carried out by Acronis. Synapsys is a channel-centric group of companies that specializes in distributing Acronis Cyber Protection Solutions.

Synpasys has two arms: Synapsys Distribution (Proprietary) Limited, which services the managed service provider (MSP) market, and Synapsys Systems (Proprietary) Limited, a specialist software distributor.

“Synapsys has been a trusted and valuable partner in our efforts to extend our cyber protection solutions to organizations across the African continent,” said Acronis’ founder and CEO, Serguei Beloussov.

“This acquisition will give their users direct access to our technology and support.”

Beloussov added that the deal marked the start of a permanent presence in a new continent for Acronis, which has its international headquarters in Singapore and its corporate headquarters in Schaffhausen, Switzerland.

“Africa is becoming a strategic growth opportunity for Acronis and acquiring Synapsys provides us with a permanent presence on the continent,” said Beloussov.

“The move is beneficial for Acronis, the African MSP channel, and the organizations and users that need to safeguard their workloads and systems against the modern threat landscape.”

Following the acquisition, Synapsys’ managing director, Peter French, will take on a new role as Acronis’ general manager for the Middle East/Africa market. 

“No business school advice tells you to put all your eggs in one basket. But this is exactly what we did with Acronis, and we have never regretted it,” said French.

“Our laser-focus and partner-centric ethos is backed by our alignment with Acronis’ mission, especially the drive to the cloud and the cyber protect approach to data protection and digital security.”

Responsibility for all Africa-based sales of Acronis’ solutions will be placed in the hands of Synapsys after a planned transition period.

Recently, Acronis acquired CyberLynx, 5nine Software, and DeviceLock. The company said it will continue to weigh up potential acquisitions that will help to solve cybersecurity challenges around safety, accessibility, privacy, authenticity, and security (SAPAS).

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Security Consultant Indicted on Cyberstalking Charges

Security Consultant Indicted on Cyberstalking Charges

A cybersecurity consultant from Seattle has been indicted by a federal grand jury on multiple counts of cyberstalking.

Sumit Garg is accused of waging an extensive year-long cyberstalking campaign against a woman with whom he and his wife formerly shared a two-bedroom apartment in the Belltown neighborhood of Seattle.

The 31-year-old allegedly directed sexually explicit messages and social media posts at the woman and sent threats to her, her family members, and her boyfriend.

When the victim went to the police to report Garg’s alleged crimes, the cybersecurity specialist allegedly threatened the Seattle police detective tasked with investigating the case. 

He is further accused of threatening his alleged victim’s uncle who represented her in obtaining a civil protection order. 

Garg allegedly even went on to threaten the deputy prosecuting attorney who filed illegal stalking conduct charges against the consultant.

Court documents state that in 2019, while Garg and his spouse were living with the victim, Garg snuck into the victim’s room and accessed her diary without her consent, leaving fingerprints on multiple pages. 

The diary contained intimate details about the victim’s private life and prior relationships. After reading it, Garg gave her the nickname Spicy. 

The victim moved out of the apartment in July 2019 after allegedly receiving threatening messages from Garg and being frightened by his behavior during a verbal argument over plans for her friends to visit from out of state.  

Scared for her safety, the victim took out a protection order against Garg. The consultant signed a settlement agreement to resolve the civil action and agreed to have no further contact with the victim.

Garg is accused of sending to the victim photos of her new apartment and a video of himself in the building’s lobby.

Court documents alleged that from around November 2019 to March 2021, Garg and others cyber-harassed and intimidated over a dozen victims. 

Garg allegedly created threatening messages and made false reports to law enforcement to create the illusion that he was a victim of the cyberstalking scheme, rather than its perpetrator.

Garg is charged with conspiracy to engage in cyberstalking, three counts of cyberstalking in violation of a criminal order, and two counts of cyberstalking.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Internet Crime Complaints Surge in 2020, Fueled By Pandemic

Internet Crime Complaints Surge in 2020, Fueled By Pandemic

Suspected internet crime complaints increased by 69% in 2020 compared to 2019 in the US, according to figures released in the FBI’s 2020 Internet Crime Report.

Total complaints reached 791,790 last year, representing a rise of more than 300,000 compared to 2019. This resulted in total recorded losses of more than $4.1bn to victims, as cyber-criminals took advantage of the shift to online services as a result of COVID-19 lockdown restrictions.

The report from the Internet Crime Complaint Center (IC3) found that business email compromise was the costliest scam technique employed.

The three most prominent forms of internet crime reported were phishing, which surged from 114,702 complaints in 2019 to 241,342 in 2020. This resulted in adjusted losses for victims of over $54m. This was followed by non-payment/non-delivery scams, growing from 61,832 in 2019 to 108,869, resulting in losses of more than $265m. Extortion was the third most complained about internet crime last year, rising from 43,101 victims in 2019 to 76,741 in 2020. Total losses from extortion were recorded as close to $70m.

The IC3 also observed a sharp rise in ransomware incidents last year, with 2474 complaints resulting in adjusted losses of more than $29.1m. The most common means of infection were email phishing campaigns and remote desktop protocol (RDP) vulnerabilities.

Additionally, the study emphasized the extent to which fraudsters leveraged the COVID-19 crisis, with the IC3 receiving over 28,500 complaints related to pandemic. These included the targeting of a number of government financial relief schemes, such as the Coronavirus Aid, Relief and Economic Security Act (CARES Act).

Commenting on the findings, Ilia Kolochenko, CEO, founder and chief architect at ImmuniWeb, said: “The most popular incidents mentioned in the report involve human error, spanning from trivial consumer fraud and phishing to more sophisticated BEC hacking and ransomware campaigns. In 2020, attackers were aggressively exploiting pandemic-related topics,  a trend that will likely persist this year. Unsurprisingly, most of the self-reported victims are over 60 years old – they may lack cybersecurity training and are susceptible to manipulation.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Fraudsters Impersonating Tesco in New Phone Scam, Police Warn

Fraudsters Impersonating Tesco in New Phone Scam, Police Warn

Police in Wales have issued a warning to residents about a new phone scam, in which fraudsters are impersonating supermarket giant Tesco.

Victims have reported receiving an automated call telling them that an order with Tesco has been placed and that £350 will be debited from their account. The automated message goes on to say “if this is not the right amount, please press 1 to go through to our fraud team.”

When worried victims press 1, they are put through to a scammer, who attempts to gain as many personal details as possible from them, including their bank details. The police warned that the scammers are highly sophisticated and will sound genuine. They advised: “If you receive a call like this, it’s best to hang up and either check your Tesco online account yourself, or call Tesco directly from a number you have obtained.”

The scam comes amid ongoing COVID-19 lockdown restrictions, a period which has seen a huge rise in online grocery shopping and click and collect services. Overall, the shift to online services and the economic and health uncertainties of the past year has led to fraudsters ramping up attempted scams. According to data from Barclays, impersonation was the joint highest form of scam (29%).

Commenting on the story, Ray Walsh, digital privacy expert at ProPrivacy, said: “These scams rely on clever scripts to convince people that they are being defrauded, so that worried victims hand over sensitive personal data, including their bank details.

“We remind everyone never to provide their personal information or payment details to anybody who calls them out of the blue, even if they claim to be from a huge brand like Tesco. If you have an order placed with Tesco and you receive a call like this which concerns you, hang up and make an inquiry with Tesco directly to check on the status of your delivery.

“According to some reports, the scammers may even attempt to convince the victim to install remote access software onto their PC to allow them to help remove malware that permitted the fake fraud to occur. Anybody who falls for this will be allowing cyber-criminals direct access to their PC so that they can install software designed to steal their data.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Recorded Future Swoops for Gemini Advisory in $52m Deal

Recorded Future Swoops for Gemini Advisory in $52m Deal

Recorded Future has announced a $52m deal to enhance its threat intelligence capabilities with the acquisition of Gemini Advisory.

The self-proclaimed “world’s largest provider of intelligence for enterprise security” said the combination of both companies’ capabilities would give customers a critical edge in their efforts to rapidly mitigate cyber-threats.

“In a short time, Gemini Advisory has become a leader in the fraud space with unique offerings in both payment card intelligence and merchant fraud intelligence,” argued Recorded Future CEO and co-founder Christopher Ahlberg.

“As we continue to execute on our mission to deliver a modular intelligence platform, joining forces with Gemini Advisory expands the value we deliver for customers across enterprise security and fraud.”

Gemini Advisory is set to stay as a separate business unit within the new company, where it will support its existing client base with services built on deep insight into the cybercrime underground.

This visibility into payment card, merchant and transactional fraud helps businesses to prevent fraud, on average, up to 24 days before it occurs, according to Recorded Future.

Gemini Advisory’s fraud and threat intelligence data will be particularly useful to Recorded Future’s Fraud Intelligence offering, which sits alongside a broad service portfolio covering SecOps, brand intelligence, vulnerabilities, geopolitical intelligence and cyber-threat insight.

“Gemini Advisory was able to take the market leader position for fraud intelligence because of the unparalleled expertise of our team, having spent years in undercover operations, and our novel approach to fraud detection and prevention,” said Gemini Advisory CEO and co-founder Andrei Barysevich.

“Recorded Future mirrors this approach across other cybersecurity solution areas, with intelligence at the foundation of both of our businesses. This common core is what makes a partnership with Recorded Future the right next step in our evolution.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

FBI Alert: Pysa Ransomware Targeting Education Sector

FBI Alert: Pysa Ransomware Targeting Education Sector

The FBI has issued an alert to education sector organizations in the US and UK of an uptick in multi-stage double extortion attacks using the Pysa ransomware variant.

Also known as Mespinoza, Pysa has been detected targeting higher education institutions, K-12 schools and seminaries in 12 US states and the UK.

The variant has been tracked by the FBI since March 2020 in attacks on multiple sectors including US and foreign governments, healthcare and private sector firms.

The initial threat vector is either phishing emails or RDP endpoints hijacked via compromised credentials.

Open source Advanced Port Scanners and Advanced IP Scanners are then used for network reconnaissance, before the installation of more open source tools such as PowerShell Empire, Koadic and Mimikatz to upload additional malware, grab passwords and more.

The threat actors also seek to disable anti-virus capabilities on the victim’s network before deploying the ransomware, the FBI warned.

“The cyber-actors then exfiltrate files from the victim’s network, sometimes using the free opensource tool WinSCP, and proceed to encrypt all connected Windows and/or Linux devices and data, rendering critical files, databases, virtual machines, backups and applications inaccessible to users,” the alert continued.

“In previous incidents, cyber-actors exfiltrated employment records that contained personally identifiable information (PII), payroll tax information and other data that could be used to extort victims to pay a ransom.”

Any exfiltrated data is uploaded to cloud storage site Mega.nz.

The news comes as a college in the UK’s second city of Birmingham reported a major ransomware attack which forced the closure of its campus buildings to students.

South and City College said some students were expected to return today after a ransomware incident last weekend “had made certain computer systems on our network inaccessible.”

The average ransom payment last year increased 171%, according to Palo Alto Networks.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk