Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
Details Tied to Safari Browser-based ‘ScamClub’ Campaign Revealed
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Masslogger Swipes Microsoft Outlook, Google Chrome Credentials
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Browser Tracking Using Favicons
Interesting research on persistent web tracking using favicons. (For those who don’t know, favicons are those tiny icons that appear in browser tabs next to the page name.)
Abstract: The privacy threats of online tracking have garnered considerable attention in recent years from researchers and practitioners alike. This has resulted in users becoming more privacy-cautious and browser vendors gradually adopting countermeasures to mitigate certain forms of cookie-based and cookie-less tracking. Nonetheless, the complexity and feature-rich nature of modern browsers often lead to the deployment of seemingly innocuous functionality that can be readily abused by adversaries. In this paper we introduce a novel tracking mechanism that misuses a simple yet ubiquitous browser feature: favicons. In more detail, a website can track users across browsing sessions by storing a tracking identifier as a set of entries in the browser’s dedicated favicon cache, where each entry corresponds to a specific subdomain. In subsequent user visits the website can reconstruct the identifier by observing which favicons are requested by the browser while the user is automatically and rapidly redirected through a series of subdomains. More importantly, the caching of favicons in modern browsers exhibits several unique characteristics that render this tracking vector particularly powerful, as it is persistent (not affected by users clearing their browser data), non-destructive (reconstructing the identifier in subsequent visits does not alter the existing combination of cached entries), and even crosses the isolation of the incognito mode. We experimentally evaluate several aspects of our attack, and present a series of optimization techniques that render our attack practical. We find that combining our favicon-based tracking technique with immutable browser-fingerprinting attributes that do not change over time allows a website to reconstruct a 32-bit tracking identifier in 2 seconds. Furthermore,our attack works in all major browsers that use a favicon cache, including Chrome and Safari. Due to the severity of our attack we propose changes to browsers’ favicon caching behavior that can prevent this form of tracking, and have disclosed our findings to browser vendors who are currently exploring appropriate mitigation strategies.
Another researcher has implemented this proof of concept:
Strehle has set up a website that demonstrates how easy it is to track a user online using a favicon. He said it’s for research purposes, has released his source code online, and detailed a lengthy explanation of how supercookies work on his website.
The scariest part of the favicon vulnerability is how easily it bypasses traditional methods people use to keep themselves private online. According to Strehle, the supercookie bypasses the “private” mode of Chrome, Safari, Edge, and Firefox. Clearing your cache, surfing behind a VPN, or using an ad-blocker won’t stop a malicious favicon from tracking you.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
U.S. Indicts North Korean Hackers in Theft of $200 Million
The U.S. Justice Department today unsealed indictments against three men accused of working with the North Korean regime to carry out some of the most damaging cybercrime attacks over the past decade, including the 2014 hack of Sony Pictures, the global WannaCry ransomware contagion of 2017, and the theft of roughly $200 million and attempted theft of more than $1.2 billion from banks and other victims worldwide.

Investigators with the DOJ, U.S. Secret Service and Department of Homeland Security told reporters on Wednesday the trio’s activities involved extortion, phishing, direct attacks on financial institutions and ATM networks, as well as malicious applications that masqueraded as software tools to help people manage their cryptocurrency holdings.
Prosecutors say the hackers were part of an effort to circumvent ongoing international financial sanctions against the North Korean regime. The group is thought to be responsible for the attempted theft of approximately $1.2 billion, although it’s unclear how much of that was actually stolen.
Confirmed thefts attributed to the group include the 2016 hacking of the SWIFT payment system for Bangladesh Bank, which netted thieves $81 million; $6.1 million in a 2018 ATM cash out scheme targeting a Pakistani bank; and a total of $112 million in virtual currencies stolen between 2017 and 2020 from cryptocurrency companies in Slovenia, Indonesia and New York.
“The scope of the criminal conduct by the North Korean hackers was extensive and longrunning, and the range of crimes they have committed is staggering,” said Acting U.S. Attorney Tracy L. Wilkison for the Central District of California. “The conduct detailed in the indictment are the acts of a criminal nation-state that has stopped at nothing to extract revenge and obtain money to prop up its regime.”
The indictments name Jon Chang Hyok (a.k.a “Alex/Quan Jiang”), Kim Il (a.k.a. “Julien Kim”/”Tony Walker”), and Park Jin Hyok (a.k.a. Pak Jin Hek/Pak Kwang Jin). U.S. prosecutors say the men were members of the Reconnaissance General Bureau (RGB), an intelligence division of the Democratic People’s Republic of Korea (DPRK) that manages the state’s clandestine operations.
The Justice Department says those indicted were members of a DPRK-sponsored cybercrime group variously identified by the security community as the Lazarus Group and Advanced Persistent Threat 38 (APT 38). The government alleges the men reside in North Korea but were frequently stationed by the DPRK in other countries, including China and Russia.
Park was previously charged in 2018 in connection with the WannaCry and Sony Pictures attacks. But today’s indictments expanded the range of crimes attributed to Park and his alleged co-conspirators, including cryptocurrency thefts, phony cryptocurrency investment schemes and apps, and efforts to launder the proceeds of their crimes.
Prosecutors in California also today unsealed an indictment against Ghaleb Alaumary, a 37-year-old from Mississauga, Ontario who pleaded guilty in November 2020 to charges of laundering tens of millions of dollars stolen by the DPRK hackers.
The accused allegedly developed and marketed a series of cryptocurrency applications that were advertised as tools to help people manage their crypto holdings. In reality, prosecutors say, the programs were malware or downloaded malware after the applications were installed.
A joint cyber advisory from the FBI, the Treasury and DHS’s Cybersecurity and Infrastructure Agency (CISA) delves deeper into these backdoored cryptocurrency apps, a family of malware activity referred to as “AppleJeus. “Hidden Cobra” is the collective handle assigned to the hackers behind the AppleJeus malware.
“In most instances, the malicious application—seen on both Windows and Mac operating systems—appears to be from a legitimate cryptocurrency trading company, thus fooling individuals into downloading it as a third-party application from a website that seems legitimate,” the advisory reads. “In addition to infecting victims through legitimate-looking websites, HIDDEN COBRA actors also use phishing, social networking, and social engineering techniques to lure users into downloading the malware.”
The alert notes that these apps have been posing as cryptocurrency trading platforms since 2018, and have been tied to cryptocurrency thefts in more than 30 countries.
Image: CISA.
For example, the DOJ indictments say these apps were involved in stealing $11.8 million in August 2020 from a financial services company based in New York. Warrants obtained by the government allowed the FBI to seize roughly $1.9 million from two different cryptocurrency exchanges used by the hackers, money that investigators say will be returned to the New York financial services firm.
Other moneymaking and laundering schemes attributed to the North Korean hackers include the development and marketing of an initial coin offering (ICO) in 2017 called Marine Chain Token.
That blockchain-based cryptocurrency offering promised early investors the ability to purchase “fractional ownership in marine shipping vessels,” which the government says was just another way for the North Korean government to “secretly obtain funds from investors, control interests in marine shipping vessels, and evade U.S. sanctions.”
A copy of the indictments is available here (PDF).
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Neighbor Revealed as Cyber-Stalker
Neighbor Revealed as Cyber-Stalker

A South African man has admitted carrying out a cyber-harassment campaign against his neighbors in an attempt to extort money.
Residents of the same quiet street in a Durban suburb that Dharmesh Singh calls home were subjected to weeks of abuse with no idea that the person behind it was their immediate neighbor.
Twenty-three-year-old Singh used unregistered SIM cards to create fake social media profiles from which he sent threatening messages to residents of Battersea Road, Reservoir Hills. He also sent threatening text messages and WhatsApp messages under the alias Sashin Soobramoney.
Some Battersea Road residents, including Singh’s own parents, were inconvenienced by the almost constant arrival of e-hailing client pick-up services and food deliveries that they had not ordered in March and April last year.
However, it was Andy Hingdebi, the man living directly adjacent to Singh, who filed a complaint against the cyber-stalker. The married father of two young children said that along with hundreds of false food deliveries and unrequested pick-up orders, he received multiple threatening messages.
Singh threatened to rape Hingdebi’s wife and children, rob his home, and kill Hingdebi and the security guard he had hired unless Hingdebi left R50,000 in cash (approximately $3,400) in the mailbox at the front of his house to be collected.
No prior altercations had taken place between Hingdebi and Singh.
“My advice to parents is not to put your kids out there on social media,” said Hingdebi. “It was terrible when he sent me pictures of my children and threatened rape.”
Singh was arrested by Durban police in November and pleaded guilty to one charge of attempted extortion. Under a plea agreement, Singh accepted a two-year custodial sentence suspended for five years and a fine of R60,000 (just over $4K).
Verlie Oosthuizen, an attorney specializing in cybercrime matters at legal firm Shepstone and Wylie, said that the court outcome was precedent-setting in South Africa.
“It is one of the first times I’ve heard of a criminal conviction being followed through on,” said Oosthuizen. “It is a good precedent-setting case for people who are victims of this kind of harassment.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Europeans Unhappy with TikTok’s Child Safety Policy
Europeans Unhappy with TikTok’s Child Safety Policy

European consumer groups have accused video-sharing app TikTok of failing to protect minor users from inappropriate content and hidden advertising.
The Chinese-owned app was the target of multiple complaints from organizations in 15 different countries on Tuesday for allegedly violating European consumer rights. Along with its treatment of children and teens, the app was slammed for its allegedly unfair terms of service, misleading data-processing practices, and virtual gifts feature critics say modifies the exchange rate so transactions are financially in the app’s favor.
TikTok, which has over 800 million active users worldwide, is owned by ByteDance and has over two billion downloads on the Google Play and Apple app stores.
A complaint filed by BEUC urges authorities to investigate the conduct of the social media platform that it says is “failing to conduct due diligence when it comes to protecting children from inappropriate content such as videos showing suggestive content which are just a few scrolls away.”
BEUC said that companies who want to advertise on the app are encouraged to do so in a way that contributes to the proliferation of hidden marketing.
“Users are for instance triggered to participate in branded hashtag challenges where they are encouraged to create content of specific products. As popular influencers are often the starting point of such challenges the commercial intent is usually masked for users,” complained the BEUC.
Referencing findings included in the report “TikTok Without Filters,” the BEUC said that TikTok’s terms of service are “unclear, ambiguous and favor TikTok to the detriment of its users.”
“TikTok does not clearly inform its users, especially in a way comprehensible to children and teenagers, about what personal data is collected, for what purpose and for what legal reason. This information is, however, essential for consumers when using Tik Tok’s services,” stated the BEUC.
The app’s copyright terms are equally unfair, according to the BEUC, as they give TikTok an irrevocable right to use, distribute, and reproduce users’ published video content without remuneration.
“We’re always open to hearing how we can improve, and we have contacted BEUC as we would welcome a meeting to listen to their concerns,” a TikTok spokesman said.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Which? Flags Fake Amazon Reviews
Which? Flags Fake Amazon Reviews

Fraudulent product reviews for goods sold on Amazon’s Marketplace are available to purchase by the bundle, according to an investigation by consumer group Which?
The group identified 10 different websites including AMZTigers from which Amazon sellers could purchase positive reviews at prices starting from £5 each. In return for their services, reviewers accept free products, discounted products, or payment.
Sellers could also purchase “packages” of fake reviews ranging in price from £15 for one package up to £620 for 50 reviews and £8,000 for 1,000.
The number of reviewers working with the websites suggests that selling Amazon reviews is financially worthwhile. Which? found that five of the businesses in question had more than 702,000 reviewers for hire.
Some fake reviewers may have been lured into participating by the various loyalty schemes Which? found were on offer. Under these schemes, reviewers can earn premium goods including exercise equipment and toys.
Under the terms and conditions described on Amazon.com, “a review in exchange for monetary reward” is among the “types of reviews that we don’t allow and will remove.”
An Amazon spokesman said: “We remove fake reviews and take action against anyone involved in abuse.” But according to Which?, the fake reviews industry is so widespread that Amazon’s attempts to combat it are an “uphill struggle.”
To remove the fake reviews, Amazon first has to identify the false, paid-for reviews hiding among those left organically. According to Which? this task has been made harder by the fake-review-pedaling websites.
The group found that the websites offered advice on how to sing the praises of a product in such a way that the review comes across as authentic. Some websites even included criteria that reviewers had to meet in order to unlock rewards schemes.
Reviewers were encouraged to leave reviews that include photos and that are at least two sentences in length.
Natalie Hitchins, head of home products and services at Which?, said: “Amazon, and other online platforms, must do more to proactively prevent fake reviews infiltrating their sites so that consumers can trust the integrity of their reviews.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
#DTX Tech Predictions Mini Summit: Focus on Security When Expanding Digital Presence
#DTX Tech Predictions Mini Summit: Focus on Security When Expanding Digital Presence

The digital shift emanating from the COVID-19 crisis can serve to enhance workforce productivity, but organizations must be careful to ensure this does not threaten their security and make them more vulnerable to cyber-attacks, according to a panel speaking during the Tech Predictions Mini Summit.
The speakers firstly outlined how the shift to remote working and increased take up of digital technologies is having positive impacts for many organizations. James Maunder, CIO at The London Clinic, noted that “productivity equates to delivery of value and, in some senses, we’ve seen an increase.”
Similarly, at the UK’s Ministry of Defence (MOD), COVID-19 was viewed as an opportunity to accelerate a modernization program that was already in the making. “Part of that was the move to a mobile-first view of the world – mobile-first in the battlefield, mobile-first in our normal everyday working lives,” explained Charlie Forte, CIO at the MOD. “So we’ve used the COVID experience to really accelerate the delivery of a mobile-first workforce, and if we hadn’t done, we would have been quite challenged in terms of supporting defense outputs.”
However, as has been well-documented over the past year, the move to remote working, where staff are increasingly operating outside the secure perimeters of corporate buildings, has offered more opportunities for cyber-criminals to launch attacks. Forte acknowledged: “The threats substantially increase as you move to forming most of your daily engagement activities on a remote basis rather than being in a building somewhere and all together.”
In his view, awareness education and training is just as important to mitigating the increased threat levels as improving organizations’ technical infrastructure. “Your weakest link is always how people think about and approach their cyber-safety when they are working with anything digital. So we’ve been putting a lot of effort as part of a wider cyber-awareness program into equipping people to think responsibly and to have the education to act responsibly,” added Forte.
There has also been a major focus on enhancing digital skills in the NHS to ensure the growth in services such as online consultations are managed properly. David Farrell, head of digital readiness at Health Education England, highlighted a number of areas in which this is required, such as cybersecurity. This includes for senior leadership, ensuring they “fully understand the threats and opportunities of digital.” Going forward, Farrell highlighted plans to massively expand the number of digital roles in the NHS, up from around 45,000 to 80,000.
The panel went on to discuss the crucial role leaders within organizations have to look after the mental wellbeing of staff, ensuring they do not get too stressed or fatigued while working from home. One consequence of this is that staff are more likely to make errors that enable cyber-incidents to occur. Maunder commented: “There’s a real risk around jumping on the first video call at 8.00 am and staying staring at a screen until 6/7.00 pm. It is incredibly mentally draining and with that mental drain comes a reduction in our creativity, curiosity and emotional intelligence, and therefore our productivity drops.”
Another area organizations should be mindful of as they seek to expand their digital capabilities is the problems that can be caused by legacy IT systems. Remaining patient with IT teams as they balance removing so-called ‘tech debt’ while at the same time delivering advancements is vital in ensuring developments are undertaken safely. Maunder explained: “The challenge I think a lot of organizations have is that we need to deal with that technical debt and create a more sustainable, flexible, innovative future, while at the same time, delivering faster wins for the organization.”
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Industry Leaders Javvad Malik and Wendy Nather to Headline Infosecurity Magazine Online Summit
Industry Leaders Javvad Malik and Wendy Nather to Headline Infosecurity Magazine Online Summit

Infosecurity is delighted to announce that industry pioneers Javvad Malik, security awareness advocate at KnowBe4, and Wendy Nather, head of advisory CISOs at Duo Security (Cisco), will be headlining the upcoming Infosecurity Magazine Online Summit, taking place on March 23 and 24.
Malik will open Day One of the event (March 23, EMEA-focused) with a keynote address exploring the Defender’s Dilemma – sharing insight on the current cyber-risk landscape and outlining how security professionals and teams can effectively improve their defensive position.
Nather will open Day Two of the event (March 24, North America-focused) with an exploration into Analyzing the Chemistry of Data – describing the power of data (for good and bad), creating formulas for data’s security requirements and driving a data-centric security approach.

Speaking to Infosecurity, Nather said: “I’m looking forward to giving the keynote address because Infosecurity Magazine has a special place in my heart as an informative and entertaining source of security knowledge. I’m also delighted to be back in cahoots with Mr Javvad Malik, as you never know what will happen!
“What I hope people learn from my talk is that data isn’t a static string of ones and zeros. It’s our thoughts and our culture and our actions, made manifest in a unique form. Data has a life of its own, and we have to learn to secure it as it transforms and evolves.”
Along with the keynote addresses from Malik and Nather, the two-day Online Summit will also feature a range of sessions including panel discussions and presentations on topics such as:
- Home to Office: A CISO’s Guide to Securing Hybrid Working Environments
- Establishing a Cybersecurity Culture of Inclusion
- Ransomware Everywhere: Understanding Attack Evolution
- How To: Build and Maintain a DevSecOps Culture
- How Hackers Used and Abused the Pandemic to Profit
- Putting People First: Dealing with Team Burnout and Mental Health
- How To: Embark on a Bug Bounty Program
- The Scourge of Dis- and Misinformation in 2021
- And more!
Registration for Infosecurity’s Online Summit is open now.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk