Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
How one man silently infiltrated dozens of high-tech networks
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Cybercrooks Rake in $304M in Romance Scams
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
US Cyber Command Valentine’s Day Cryptography Puzzles
The US Cyber Command has released a series of ten Valentine’s Day “Cryptography Challenge Puzzles.”
Slashdot thread. Reddit thread. (And here’s the archived link, in case Cyber Command takes the page down.)
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
On Vulnerability-Adjacent Vulnerabilities
At the virtual Enigma Conference, Google’s Project Zero’s Maggie Stone gave a talk about zero-day exploits in the wild. In it, she talked about how often vendors fix vulnerabilities only to have the attackers tweak their exploits to work again. From a MIT Technology Review article:
Soon after they were spotted, the researchers saw one exploit being used in the wild. Microsoft issued a patch and fixed the flaw, sort of. In September 2019, another similar vulnerability was found being exploited by the same hacking group.
More discoveries in November 2019, January 2020, and April 2020 added up to at least five zero-day vulnerabilities being exploited from the same bug class in short order. Microsoft issued multiple security updates: some failed to actually fix the vulnerability being targeted, while others required only slight changes that required just a line or two to change in the hacker’s code to make the exploit work again.
[…]
“What we saw cuts across the industry: Incomplete patches are making it easier for attackers to exploit users with zero-days,” Stone said on Tuesday at the security conference Enigma. “We’re not requiring attackers to come up with all new bug classes, develop brand new exploitation, look at code that has never been researched before. We’re allowing the reuse of lots of different vulnerabilities that we previously knew about.”
[…]
Why aren’t they being fixed? Most of the security teams working at software companies have limited time and resources, she suggests — and if their priorities and incentives are flawed, they only check that they’ve fixed the very specific vulnerability in front of them instead of addressing the bigger problems at the root of many vulnerabilities.
Another article on the talk.
This is an important insight. It’s not enough to patch existing vulnerabilities. We need to make it harder for attackers to find new vulnerabilities to exploit. Closing entire families of vulnerabilities, rather than individual vulnerabilities one at a time, is a good way to do that.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Deliberately Playing Copyrighted Music to Avoid Being Live-Streamed
Vice is reporting on a new police hack: playing copyrighted music when being filmed by citizens, trying to provoke social media sites into taking the videos down and maybe even banning the filmers:
In a separate part of the video, which Devermont says was filmed later that same afternoon, Devermont approaches [BHPD Sgt. Billy] Fair outside. The interaction plays out almost exactly like it did in the department — when Devermont starts asking questions, Fair turns on the music.
Devermont backs away, and asks him to stop playing music. Fair says “I can’t hear you” — again, despite holding a phone that is blasting tunes.
Later, Fair starts berating Devermont’s livestreaming account, saying “I read the comments [on your account], they talk about how fake you are.” He then holds out his phone, which is still on full blast, and walks toward Devermont, saying “Listen to the music”.
In a statement emailed to VICE News, Beverly Hills PD said that “the playing of music while accepting a complaint or answering questions is not a procedure that has been recommended by Beverly Hills Police command staff,” and that the videos of Fair were “currently under review.”
However, this is not the first time that a Beverly Hills police officer has done this, nor is Fair the only one.
In an archived clip from a livestream shared privately to VICE Media that Devermont has not publicly reposted but he says was taken weeks ago, another officer can be seen quickly swiping through his phone as Devermont approaches. By the time Devermont is close enough to speak to him, the officer’s phone is already blasting “In My Life” by the Beatles — a group whose rightsholders have notoriously sued Apple numerous times. If you want to get someone in trouble for copyright infringement, the Beatles are quite possibly your best bet.
As Devermont asks about the music, the officer points the phone at him, asking, “Do you like it?”
Clever, really, and an illustration of the problem with context-free copyright enforcement.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Bluetooth Overlay Skimmer That Blocks Chip
As a total sucker for anything skimming-related, I was interested to hear from a reader working security for a retail chain in the United States who recently found Bluetooth-enabled skimming devices placed over top of payment card terminals at several stores. Interestingly, these skimmers interfered with the terminal’s ability to read chip-based cards, forcing customers to swipe the stripe instead.
The payment card skimmer overlay transmitted stolen data via Bluetooth, physically blocked chip-based transactions, and included a PIN pad overlay.
Here’s a closer look at the electronic gear jammed into these overlay skimmers. It includes a hidden PIN pad overlay that captures, stores and transmits via Bluetooth data from cards swiped through the machine, as well as PINs entered on the device:
The hidden magnetic stripe reader is in the bottom left, just below the Bluetooth circuit board. A PIN pad overlay (center) intercepts any PINs entered by customers; the cell phone battery (right) powers all of the components.
My reader source shared these images on condition that the retailer in question not be named. But it’s worth pointing out these devices can be installed on virtually any customer-facing payment terminal in the blink of eye.
Newer, chip-based payment cards are more costly and difficult for thieves to clone, but virtually all cards still store card data on a magnetic stripe on the back of the cards — mainly for reasons of backwards compatibility. This overlay skimmer included a physical component designed to block the payment terminal from reading the chip, forcing the customer to swipe the stripe instead of dip the chip.
The magnetic stripe reader (top right) worked with a component designed to block the use of chip-based payment cards.
What’s remarkable is that these badboys went undetected for several weeks, particularly given that customers would have been forced to swipe.
“In this COVID19 world, with counter and terminal wipedowns frequent it was surprising that nobody noticed the overlay placements for a number of weeks,” the source said.
I realize a great many people use debit cards for everyday purchases, but I’ve never been interested in assuming the added risk and pay for everything with cash or a credit card. Armed with your PIN and debit card data, thieves can clone the card and pull money out of your account at an ATM. Having your checking account emptied of cash while your bank sorts out the situation can be a huge hassle and create secondary problems (bounced checks, for instance).
Want to learn more about overlay skimmers? Check out these other posts:
How to Spot Ingenico Self-Checkout Skimmers
Self-Checkout Skimmers Go Bluetooth
More on Bluetooth Ingenico Overlay Skimmers
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Chinese Supply-Chain Attack on Computer Systems
Bloomberg News has a major story about the Chinese hacking computer motherboards made by Supermicro, Levono, and others. It’s been going on since at least 2008. The US government has known about it for almost as long, and has tried to keep the attack secret:
China’s exploitation of products made by Supermicro, as the U.S. company is known, has been under federal scrutiny for much of the past decade, according to 14 former law enforcement and intelligence officials familiar with the matter. That included an FBI counterintelligence investigation that began around 2012, when agents started monitoring the communications of a small group of Supermicro workers, using warrants obtained under the Foreign Intelligence Surveillance Act, or FISA, according to five of the officials.
There’s lots of detail in the article, and I recommend that you read it through.
This is a follow on, with a lot more detail, to a story Bloomberg reported on in fall 2018. I didn’t believe the story back then, writing:
I don’t think it’s real. Yes, it’s plausible. But first of all, if someone actually surreptitiously put malicious chips onto motherboards en masse, we would have seen a photo of the alleged chip already. And second, there are easier, more effective, and less obvious ways of adding backdoors to networking equipment.
I seem to have been wrong. From the current Bloomberg story:
Mike Quinn, a cybersecurity executive who served in senior roles at Cisco Systems Inc. and Microsoft Corp., said he was briefed about added chips on Supermicro motherboards by officials from the U.S. Air Force. Quinn was working for a company that was a potential bidder for Air Force contracts, and the officials wanted to ensure that any work would not include Supermicro equipment, he said. Bloomberg agreed not to specify when Quinn received the briefing or identify the company he was working for at the time.
“This wasn’t a case of a guy stealing a board and soldering a chip on in his hotel room; it was architected onto the final device,” Quinn said, recalling details provided by Air Force officials. The chip “was blended into the trace on a multilayered board,” he said.
“The attackers knew how that board was designed so it would pass” quality assurance tests, Quinn said.
Supply-chain attacks are the flavor of the moment, it seems. But they’re serious, and very hard to defend against in our deeply international IT industry. (I have repeatedly called this an “insurmountable problem.”) Here’s me in 2018:
Supply-chain security is an incredibly complex problem. US-only design and manufacturing isn’t an option; the tech world is far too internationally interdependent for that. We can’t trust anyone, yet we have no choice but to trust everyone. Our phones, computers, software and cloud systems are touched by citizens of dozens of different countries, any one of whom could subvert them at the demand of their government.
We need some fundamental security research here. I wrote this in 2019:
The other solution is to build a secure system, even though any of its parts can be subverted. This is what the former Deputy Director of National Intelligence Sue Gordon meant in April when she said about 5G, “You have to presume a dirty network.” Or more precisely, can we solve this by building trustworthy systems out of untrustworthy parts?
It sounds ridiculous on its face, but the Internet itself was a solution to a similar problem: a reliable network built out of unreliable parts. This was the result of decades of research. That research continues today, and it’s how we can have highly resilient distributed systems like Google’s network even though none of the individual components are particularly good. It’s also the philosophy behind much of the cybersecurity industry today: systems watching one another, looking for vulnerabilities and signs of attack.
It seems that supply-chain attacks are constantly in the news right now. That’s good. They’ve been a serious problem for a long time, and we need to take the threat seriously. For further reading, I strongly recommend this Atlantic Council report from last summer: “Breaking trust: Shades of crisis across an insecure software supply chain.“
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Three Charged Over Fraudulent Vaccine Website
Three Charged Over Fraudulent Vaccine Website

Three men in Baltimore County have been accused of impersonating Massachusetts pharmaceutical and biotechnology company Moderna to sell fake COVID-19 vaccines.
Twenty-two-year-old Owings Mills resident Kelly Lamont Williams, together with cousins and Windsor Mill residents 22-year-old Olakitan Oluwalade and 25-year-old Odunayo Baba Oluwalade, also known as Olaki and Baba respectively, were arrested on February 11.
A criminal complaint unsealed yesterday accuses the trio of copying the source code of the genuine Moderna website (modernatx.com) and using it to create a similar-looking spoof website, modernatx.shop.
A vaccine (mRNA-1273) created by Moderna was authorized on December 19, 2020, by the FDA for emergency use in the United States to prevent COVID-19 in individuals 18 years of age and older. Via the fraudulent site, the three men allegedly sold hundreds of fake COVID-19 vaccines at $30 a dose.
According to an affidavit, the fake website dropped onto the radar of Homeland Security Investigations (HSI) Intellectual Property Rights Center and the HSI Cyber Crimes Center on January 11, 2021. An HSI special agent contacted a phone number listed on the fake domain, which investigators determined was linked to an account on an encrypted messaging application.
Two hours later, the agent received a reply requesting a contact email address, which the agent supplied. The agent then received an email from sales@modernatx.shop, welcoming them to Moderna, describing the company, and detailing the storage requirements of the vaccine.
Several emails later and the agent had agreed to pay $6,000 dollars for 200 doses of the vaccine into a Navy Federal Credit Union account in the name of Kelly Lamont Williams.
On January 15, 2021, the government seized the fake domain. Search warrants executed at the homes of all three defendants uncovered communications between Baba, Olaki, and Williams discussing the fraud scheme.
The communications also indicated that Olaki had applied for and received a fraudulent COVID-19 Economic Injury Disaster Loan funded by the federal government in the summer of 2020.
All three men are charged with conspiracy to commit wire fraud. If convicted, they could each face up to 20 years in federal prison.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
US Jails Money Mule Kingpin
US Jails Money Mule Kingpin

A Ukrainian man will spend the next seven years in prison in the United States for helping Eastern European computer hackers to obtain and launder millions of dollars in stolen funds.
Odessa resident Aleksandr Musienko partnered with the hackers to steal over $3m from online bank accounts and businesses in the United States, then launder the stolen money overseas.
Information hacked and stolen by the 38-year-old’s partners in the scheme allowed them to impersonate US victims in interactions with the victims’ banks.
“By deceiving the victims’ banks into believing that withdrawals from the victims’ accounts were requested by the victims, Musienko and others were able to steal large amounts of money from the victims’ accounts,” stated the Department of Justice.
Musienko’s role in the scheme included recruiting, supervising, and directing a network of individuals with American corporate and individual bank accounts who would agree to receive the stolen funds and transmit them overseas in exchange for a fee.
Using an alias, Musienko recruited these so-called money mules by advertising on job websites that he was seeking a financial assistant.
Those who answered his advertisement were falsely told that they were providing a service to a legitimate business by assisting its clients to make international money transfers.
In September 2011, the hackers working with Musienko broke into the online accounts of a company based in North Carolina and transferred a total of $296,278 to two bank accounts controlled by the money mules.
Musienko instructed his mules to wire the funds to multiple bank accounts in Europe. However, the company’s bank detected the fraud and deducted $197,526.36 in stolen funds from one of the mules before it could be wired overseas.
In the Western District of North Carolina in 2016, sealed charges were filed against Musienko. He was arrested two years later in South Korea and extradited to the United States in 2019.
A search of Musienko’s laptop conducted by the FBI in 2019 identified files containing around 120,000 payment card numbers and associated identifying information for individuals other than Musienko.
On February 11, Musienko was sentenced to 87 months in prison and ordered to pay $98,751.64 in restitution.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk