Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Author: admin
RubyGems Packages Laced with Bitcoin-Stealing Malware
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Cryptologists Crack Zodiac Killer’s 340 Cipher
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
3M Users Targeted by Malicious Facebook, Insta Browser Add-Ons
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Code42 Incydr Series: Bringing Shadow IT into the light with Code42 Incydr
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
More on the SolarWinds Breach
The New York Times has more details.
About 18,000 private and government users downloaded a Russian tainted software update – a Trojan horse of sorts – that gave its hackers a foothold into victims’ systems, according to SolarWinds, the company whose software was compromised.
Among those who use SolarWinds software are the Centers for Disease Control and Prevention, the State Department, the Justice Department, parts of the Pentagon and a number of utility companies. While the presence of the software is not by itself evidence that each network was compromised and information was stolen, investigators spent Monday trying to understand the extent of the damage in what could be a significant loss of American data to a foreign attacker.
It’s unlikely that the SVR (a successor to the KGB) penetrated all of those networks. But it is likely that they penetrated many of the important ones. And that they have buried themselves into those networks, giving them persistent access even if this vulnerability is patched. This is a massive intelligence coup for the Russians and failure for the Americans, even if no classified networks were touched.
Meanwhile, CISA has directed everyone to remove SolarWinds from their networks. This is (1) too late to matter, and (2) likely to take many months to complete. Probably the right answer, though.
This is almost too stupid to believe:
In one previously unreported issue, multiple criminals have offered to sell access to SolarWinds’ computers through underground forums, according to two researchers who separately had access to those forums.
One of those offering claimed access over the Exploit forum in 2017 was known as “fxmsp” and is wanted by the FBI “for involvement in several high-profile incidents,” said Mark Arena, chief executive of cybercrime intelligence firm Intel471. Arena informed his company’s clients, which include U.S. law enforcement agencies.
Security researcher Vinoth Kumar told Reuters that, last year, he alerted the company that anyone could access SolarWinds’ update server by using the password “solarwinds123”
“This could have been done by any attacker, easily,” Kumar said.
Neither the password nor the stolen access is considered the most likely source of the current intrusion, researchers said.
That last sentence is important, yes. But the sloppy security practice is likely not an isolated incident, and speaks to the overall lack of security culture at the company.
And I noticed that SolarWinds has removed its customer page, presumably as part of its damage control efforts. I quoted from it. Did anyone save a copy?
EDITED TO ADD: Both the Wayback Machine and Brian Krebs have saved the SolarWinds customer page.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Mexican Drug Cartels with High-Tech Spyware
Sophisticated spyware, sold by surveillance tech companies to Mexican government agencies, are ending up in the hands of drug cartels:
As many as 25 private companies — including the Israeli company NSO Group and the Italian firm Hacking Team — have sold surveillance software to Mexican federal and state police forces, but there is little or no regulation of the sector — and no way to control where the spyware ends up, said the officials.
Lots of details in the article. The cyberweapons arms business is immoral in many ways. This is just one of them.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Sextortionists Deploy New Spyware
Sextortionists Deploy New Spyware

New spyware has been detected that targets iOS and Android users who patronize illicit sites that typically offer escort services.
The malware, named Goontact by the Lookout researchers who discovered it, targets heterosexual users in China, Korea, Japan, Thailand, and Vietnam, stealing personal information from their mobile devices.
Researchers noted: “The types of sites used to distribute these malicious apps and the information exfiltrated suggests that the ultimate goal is extortion or blackmail.”
Goontact frequently disguises itself as secure messaging applications. The malware has been observed exfiltrating a wide range of data, including device identifiers and phone number, contacts, SMS messages, location information, and photos on external storage.
Describing how users fall victim to the spyware, researchers wrote: “The scam begins when a potential target is lured to one of the hosted sites where they are invited to connect with women.
“Account IDs for secure messaging apps such as KakaoTalk or Telegram are advertised on these sites as the best forms of communication and the individual initiates a conversation. In reality, the targets are communicating with Goontact operators.”
By pretending that they are experiencing audio or video problems, the operators persuade their targets to install or sideload a mobile application that has no real user functionality beyond stealing the victim’s address book.
Researchers believe that the threat campaign is being operated by “a crime affiliate” since sites associated with the spyware are similar in appearance, naming convention, and targeted geographic region.
The sites use logos associated with domains caught up in a previous sextortion campaign exposed in 2015 by Trend Micro.
Goontact appears to be a recent addition to a campaign that has been active since at least 2013.
“The earliest sample of Goontact observed by Lookout was in November 2018, with matching APK packaging and signing dates, leading us to believe malware development likely started in this time frame,” wrote researchers.
The enterprise mobile provisioning profiles used by Goontact all reference apparently legitimate companies, including Linkplay Tech Inc and Jinhua Changfeng Information Technology Co.
Researchers said that it was unclear whether these signing identities have been compromised, or if they were created by malware operators spoofing representatives of the companies.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Refinitiv Acquires GIACT
Refinitiv Acquires GIACT

Refinitiv has added to its cybercrime-fighting capabilities by acquiring an American digital identity, payments verification, and fraud prevention company.
The definitive agreement to acquire Giact Systems, LLC (“GIACT“) was announced on November 2. News that the planned deal had officially closed was shared by Refinitiv on December 9.
GIACT was founded in Texas in 2004 and now has over 100 employees supporting more than 1,000 leading blue-chip companies, payment merchants, and financial and insurance customers.
The company helps businesses verify customers by providing real-time data, ID verification, OFAC screening, account verification, and authentication. GIACT has processed transactions for more than 1,000 customers since it was founded.
Refinitiv will offer GIACT’s platform alongside World-Check and Qual-ID, giving customers a comprehensive fraud prevention, identity verification, and compliance platform that tackles money-laundering risks in addition to preventing financial loss through payments fraud.
“We’re pleased to complete this acquisition and now look forward to introducing our customers to GIACT and our expanded suite of product offerings,” said Phil Cotter, managing director of the risk business at Refinitiv.
“GIACT’s real-time payment analytics are a great addition to our existing strength in anti-money laundering and digital identity verification. We now have a more holistic platform to help customers tackle new and emerging fraud threats, accelerated by the economic downturn and the Covid-19 pandemic.”
Refinitiv, founded in 2018, provides financial markets data, insights, and infrastructure to over 40,000 institutions in approximately 190 countries.
“We’re excited about the opportunities as we bring our capabilities and expertise of our teams together,” said Melissa Townsley-Solis, co-founder and CEO at GIACT.
“Refinitiv has a clear strategic vision for GIACT and our customers can look forward to hearing more as we turn that vision into a reality.”
Joy Wilder Lybeer, United States Information Solutions (USIS) chief revenue officer and senior vice president of global partnerships at Equifax, said that the company looked forward to continuing the relationship it had begun with GIACT in 2019.
“With the acquisition of GIACT by Refinitiv now complete, we will be able to continue our work in helping customers confront the challenges of identity verification and fraud prevention on a global scale,” said Wilder Lybeer.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk
Lithuania Suffers “Most Complex” Cyber-attack in Years
Lithuania Suffers “Most Complex” Cyber-attack in Years

A carefully coordinated cyber-attack on Lithuania that occurred last week has been described by the republic’s defense minister as one of the “most complex” security incidents to target the Baltic state in recent history.
On the night of December 9, cyber-criminals breached multiple content management systems to gain access to 22 different websites operated by Lithuania’s public sector. The attackers then published articles containing misinformation on the sites.
Among the fake news posted by the threat actors was a story that alleged a Polish diplomat, carrying illegal drugs, weapons, and money, had been detained at the Lithuanian border. This fictitious story was shared on the website of the State Border Guard Service (VSAT).
Another article claimed that corruption had been uncovered in the Šiauliai airport, where NATO’s Baltic air-policing mission is housed.
A third piece of misinformation promulgated in the attack inflated figures to make it appear as though more Lithuanians had been drafted into the military than was the case.
An investigation into the attack by the Defense Ministry’s National Cyber Security Centre (NKSC) found that the websites targeted by the attackers were mostly run by regional municipalities.
In a statement published on Wednesday, Lithuania’s defense minister, Arvydas Anušauskas, described the digital assault as one of the “biggest and most complex” cyber-attacks to hit the republic in recent years.
Anušauskas added that the attack, which took place “on the eve of the government’s transition […] was prepared in advance and with a goal in mind.”
After hacking into the systems and posting the false articles, the attackers launched an email spoofing campaign to spread the misinformation as far as possible. The attackers impersonated the defense and foreign ministries as well as the Šiauliai Municipality Administration to send out emails containing links to the fallacious stories.
“This shows huge gaps in cybersecurity of the public sector,” said Anušauskas.
Following the attack, the NKSC has submitted a number of cybersecurity recommendations to municipalities. These include actively searching for vulnerabilities, limiting access to content management systems, installing a firewall, and avoiding the use of passwords that are easy to guess.
Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk