Malicious Barcode Scanner App

Interesting story about a barcode scanner app that has been pushing malware on to Android phones. The app is called Barcode Scanner. It’s been around since 2017 and is owned by the Ukrainian company Lavabird Ldt. But a December 2020 update included some new features:

However, a rash of malicious activity was recently traced back to the app. Users began noticing something weird going on with their phones: their default browsers kept getting hijacked and redirected to random advertisements, seemingly out of nowhere.

Generally, when this sort of thing happens it’s because the app was recently sold. That’s not the case here.

It is frightening that with one update an app can turn malicious while going under the radar of Google Play Protect. It is baffling to me that an app developer with a popular app would turn it into malware. Was this the scheme all along, to have an app lie dormant, waiting to strike after it reaches popularity? I guess we will never know.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK’s Top Cyber Schools Revealed

UK’s Top Cyber Schools Revealed

Educational establishments offering the best cybersecurity instruction in the United Kingdom have been recognized by Britain’s National Cyber Security Centre (NCSC). 

Under the NCSC’s CyberFirst Schools initiative, fourteen schools and sixth-form colleges across the country have been issued with special awards for the quality of their teaching.

In Wales, gold, silver, and bronze awards were received by six different institutions, while five establishments in Northern Ireland received awards. In England, one school in Gloucestershire and two in the northeast were recognized for their efforts to educate a new generation in cybersecurity skills. 

All the schools went beyond offering standard classroom sessions to engage their students, drawing youngsters into cybersecurity by setting up coding clubs, projects linking computing to medical sciences, and internet of things (IoT) device pitching sessions.

“Congratulations to all the schools and colleges that have been awarded CyberFirst Schools status for their first-rate approaches to teaching cyber security skills,” said Chris Ensor, the NCSC’s deputy director for cyber growth.

“It is inspiring to see the wide range of opportunities being offered to pupils and I am delighted to welcome the schools to our growing community from around the UK.

“Through the CyberFirst Schools initiative, the NCSC continues to work with schools and local communities to inspire the next generation of cyber security experts.”

Cardiff High School, Cardiff and Vale College, Coleg Cambria near Flint, and Saint Ronan’s College in Lurgan all received gold awards from the NCSC. 

Silver awards were given to Corpus Christi Catholic High School in Cardiff, Denmark Road High School in Gloucester, North East Future UTC in Newcastle-upon-Tyne, Royal Grammar School Newcastle, Rougemont School in Newport, South Eastern Regional College in County Down, St. Joseph’s Roman Catholic High School in Newport, and St. Patrick’s College in Dungannon. 

Dalriada School in Ballymoney and Knockevin Special School in Downpatrick both earned a bronze award.

The CyberFirst Schools initiative was piloted in 2018 in Gloucestershire. Since then, the scheme has been rolled out to Wales, Northern Ireland, southwest England, and northeast England. 

Closing dates for the next round of award applications is June 18, 2021.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

IRS Warns of EFIN Scam

IRS Warns of EFIN Scam

The Internal Revenue Service has issued an urgent warning to tax professionals over a new scam in which cyber-criminals impersonate the IRS over email in an attempt to steal Electronic Filing Identification Numbers (EFINs).

Carrying the subject line “Verifying your EFIN before e-filing,” the scam email purports to be from “IRS Tax E-Filing.”

In the body of the bogus email, targets are asked to send an EFIN acceptance letter dated within the last 12 months and scans of the front and reverse of their driver’s license to a fake email address in order for their EFIN to be verified. 

Thieves who obtained the EFIN and driving license data of a tax professional could use it to impersonate that professional and file fraudulent returns.

“Phishing scams are the most common tool used by identity thieves to trick tax professionals into disclosing sensitive information, and we often see increased activity during filing season,” said IRS commissioner Chuck Rettig. 

“Tax professionals must remain vigilant. The scammers are very active and very creative.”

In an alert jointly issued February 10 by the IRS, state tax agencies, and the tax industry, tax professionals who receive this particular scam email are asked to save it as a file and send it as an attachment to phishing@irs.gov.

Tax professionals were also warned to be on the lookout for other common phishing scams that seek their EFINs, Preparer Tax Identification Numbers (PTINs), or e-Services usernames and passwords.

To Erich Kron, security awareness advocate at KnowBe4, the appearance of tax scams in the first quarter of the year is “as inevitable as paying taxes.”

“These tax-themed email phishing attacks are a powerful tool for cybercriminals to steal sensitive information such as social security numbers or bank account information, redirect payments or steal credentials that will allow them to file fake tax returns,” Kron told Infosecurity Magazine. 

“To defend against these scams, educating people about the types of scams occurring and the red flags, such as links that go to different websites when you hover over them, unexpected requests for sensitive information such as login information or social security numbers, is critical.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Mercedes Issues eCall Recall

Mercedes Issues eCall Recall

Luxury car manufacturer Mercedes-Benz AktienGesellschaft has recalled over a million vehicles following the discovery of an emergency call system fault. 

A glitch uncovered in the eCall feature means alerts sent from the car to emergency services in the event of an accident may contain incorrect information regarding the vehicle’s location. 

The software-related bug impacts 1,292,258 cars in the United States manufactured from 2016 through 2021. Among the vehicles affected are the A-, B-, C-, E-, GT-, S-, SL-, and SLC-class; CLA- and CLS-class; and G-, GLA-, GLB-, GLC-, GLE-, and GLS-class. 

According to the defect report issued by the National Highway Traffic Safety Administration (NHTSA), “either an authorized Mercedes-Benz dealer or an over-the-air (“OTA”) update will update the software of the communication module for the automatic emergency call system on the affected vehicles.

“All customers will be mailed recall notification letters as required under federal regulations. For vehicles with a ‘Mercedes Me’ subscription service, the software update will be performed OTA and so a dealer visit is not required.”

Mercedes in the UK told the BBC: “This software update will also be implemented in other countries and we are in close contact with the local authorities.”

An investigation into the fault was launched by Mercedes in October 2019 after the eCall center reported a single instance in Europe of the automatic eCall system relaying an inaccurate vehicle position.

Mercedes found that it had no record of the eCall system behaving in a similar way during any of its internal testing, including during vehicle crash tests in various scenarios.

“MBAG began to work closely with the supplier in different test environments and tried to replicate and understand the event,” wrote the NHTSA.

“In depth analysis of the potential behavior of the power supply and the communication module eventually found how the software design of the communication module affected the relay of location information for the single European case.”

No reported incidents of the eCall system’s sending incorrect location data have been recorded in the United States. Updated software in the production process from January 29, 2021, ensures that the fault can no longer occur.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Post Office Announces New Digital ID Solutions

Post Office Announces New Digital ID Solutions

The Post Office in the UK has announced it will expand the use of digital identity technology in partnership with software company Yoti.

The government-owned retail postal service will roll out a range of products both online and in-branch, providing consumers with a range of choices as to how they verify themselves via modern technology. The collaboration is designed to make Post Office transactions more simple and secure going forward.

Among the products to be introduced is a free-to-use Post Office digital identity app that will combine customers’ personal data and biometrics to create a secure, reusable ID on their device. This will launch in the Spring. There will also be a trial of in-branch digital ID services for those customers who do not have access to a smartphone or prefer face to face interactions, starting in July.

In addition, the solutions may make it easier to carry out vital tasks such as opening bank accounts, applying for jobs and accessing medical services, removing the need to carry around driving licenses or other physical documentation. Under the agreement, online businesses will able to use Post Office and Yoti identity verification services for fraud detection, e-signatures and customer authentication services, using secure biometric face matching and liveness detection.

Just last week, the UK government unveiled plans to govern the future use of digital identities in order to build trust in these technologies.

Nick Read, chief executive at the Post Office, commented: “Post Office is embracing new technologies and this partnership will enhance our reputation as the trusted go-to destination for identity solutions. Whether it’s proving your identity on a smartphone or face-to-face with a Postmaster, we will make transactions faster and simpler than ever before.”

“I am delighted that Post Office and Yoti are joining forces to expand our identity services. We have an ambitious strategy to deliver a unique offer to the market that integrates digital and physical identity verification at scale benefitting both individuals and businesses.”

Robin Tombs, CEO at Yoti, added: “I’m proud to announce Yoti’s partnership with the Post Office, together we’ll make it simpler and safer to prove who you are and know who you’re dealing with, anywhere in the UK.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

SBRC Adds Ransomware Scenario to Security Training Program

SBRC Adds Ransomware Scenario to Security Training Program

The Scottish Business Resilience Center (SBRC) has announced a ransomware-focused update to its facilitation of the National Cyber Security Center’s (NCSC) Exercise in a Box program, which it has been running with businesses across Scotland since late 2020.

The program – delivered with support from the Scottish Government, Police Scotland and other stakeholders – sees workshops provided to businesses via Zoom or Microsoft Teams. The workshops focus on cyber-resilience, exploring various scenarios to test organizations’ response capabilities in a safe and measured environment.

In recognition of the rise in ransomware infections impacting public and private sector organizations within the UK, the SBRC has launched the NCSC’s Phishing Attack that Leads to a Ransomware Infection scenario, in addition to its Working from Home scenario.

Available to Scottish businesses from later this month, the new workshops will explore how an organization would experience a phishing attack that leads to a ransomware infection, allowing them to test and measure their detection and response.

Jude McCorry, CEO of SBRC, said: “The extension of the scenarios explored within our workshops provide businesses with more opportunity than ever to extend their cyber-resilience.

“The specificity of the scenarios which are explored provides attendees with the opportunity not only to see how they might respond to such a situation but also hear how others might, which opens their mind to new approaches and processes. Given that businesses continue to face a bumpy road to recovery, I encourage all to attend this free program to ensure that cyber-resilience is one area of the business owners don’t need to be concerned about.”

The workshops specific to the ransomware scenario will run in late February and March.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Duo Charged with Multimillion-Dollar Dark Web Drugs Scheme

Duo Charged with Multimillion-Dollar Dark Web Drugs Scheme

Two men have been charged with a dark web drug distribution conspiracy said to be worth millions of dollars.

Kevin Ombisi, 31, and Eric Russell Jr, 35, both of Katy, Texas, were each charged in a complaint filed in the Western District of Tennessee after being arrested last Thursday. Ombisi is charged with one count of conspiracy and one count of unlawful distribution of controlled substances, and Russell is charged with one count of conspiracy.

Prosecutors have alleged that the duo used a dark web marketplace and encrypted messaging service Wickr to sell pills spoofed to look like Adderall, a prescription medication in the US commonly used to treat attention deficit hyperactivity disorder (ADHD).

In fact, the pills contained highly addictive synthetic stimulant methamphetamine, according to the Department of Justice (DoJ).

The government claimed to have seized $5m in unnamed assets connected to the conspiracy.

According to the affidavit, DEA agents made purchases from the duo which were mailed from Texas to addresses in Tennessee, Kansas and Missouri.

In November 2019, the vendor’s site on notorious dark web marketplace Empire boasted over 2000 five-star reviews and “3657 sold since April 2019,” the court document noted.

The officers are said to have traced the “Postage Reseller” account used by Ombisi to ship the items, plus GPS and CCTV data from post offices, to track him down.

They also analyzed multiple Bitcoin wallet addresses and managed to link them to accounts with a cryptocurrency exchange in the EU, registered in Ombisi’s name and accessed from an IP address registered to Russell.

A court order then provided the investigators with access to Ombisi’s iCloud account, where they were able to find more incriminating evidence.

Empire Market finally dissolved in August last year after a suspected exit scam, with experts claiming this may drive cyber-criminals away from dark web marketplaces altogether and to encrypted messaging apps and closed cybercrime forums.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Yandex Insider Breach Hits Nearly 5000 Inboxes

Yandex Insider Breach Hits Nearly 5000 Inboxes

Russian internet giant Yandex has revealed that thousands of its customers had their accounts accessed due to a malicious insider working at the firm.

The Moscow-headquartered multi-national provides search, email, e-commerce and even ride-hailing services, and claims to have tens of millions of unique monthly users.

However, on Friday it noted in a brief statement that an employee had been selling access to users’ email accounts for personal gain.

“The employee was one of three system administrators with the necessary access rights to provide technical support for the service. As a result of his actions, 4887 mailboxes were compromised. No payment details held by Yandex were compromised,” it continued.

“Yandex’s security team has already blocked unauthorized access to the compromised mailboxes. We have contacted the mailbox owners to alert them about the breach and they have been informed of the need to change their account passwords.”

Yandex said an investigation is underway into the incident and that it will be making changes to its back-end access procedures, in order to “minimize the potential for individuals to compromise the security of user data in future.”

Insider threats are less common than attacks by malicious third parties, but often the damage can be worse as they are harder to spot. According to Verizon’s 2020 Data Breach Investigations Report, 30% of breaches it analyzed last year featured internal actors, although many of these will be down to negligence rather than malice. 

In a separate study from Egress a year ago, 75% of IT leaders said they believed employees have put data at risk intentionally, up 14% from 2019.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Police Reportedly Arrest Egregor Ransomware Members

Police Reportedly Arrest Egregor Ransomware Members

French and Ukrainian police have been in action disrupting the Egregor ransomware group with several arrests last week, according to reports.

The suspects were traced via analysis of Blockchain records after victims of the ransomware paid their extorters in Bitcoin, according to public radio channel, France Inter.

Those arrested in Ukraine are thought to have been hackers as well as individuals providing logistical and financial support to the ransomware-a-service (RaaS) group.

The Paris Tribunal de Grande Instance, France’s busiest court, opened an investigation into Egregor last autumn after multiple French organizations fell victim to the group. These included video game developer Ubisoft, logistics giant Gefco, and newspaper Ouest France.

Just a few days ago, the Dax-Côte d ‘Argent Hospital Center in south-west France was taken offline by Egregor.

It’s not known how many have been arrested at this stage, or whether they were the original developers of the ransomware or one of the many groups that the former “lease” their malware out to for attacks in return for a cut of the profits.

The group itself appeared to rise out of the ashes of Maze. It’s not known if the original members were involved in the other group, but certainly many of the affiliates swapped over.

Revelations of law enforcement activity come after a relatively sharp decline in attacks using Egregor over the past month or so.

In fact, the site it uses to publish stolen data was out of action for a fortnight in January, leading some to speculate that investigators may have been able to disrupt the operation. When Infosecurity visited it a few days ago to confirm a Foxtons breach, none of the links to data downloads were working.

Researchers last week also claimed to have found ties between Egregor and Russia-based attacks in the past, as well as an unusual username also employed by the REvil group.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk