US Indicts Money Launderers to Cyber-criminal Elite

US Indicts Money Launderers to Cyber-criminal Elite

The United States has indicted alleged members of a transnational gang that laundered millions of dollars for the cyber-criminal elite.

Fourteen alleged members of the criminal organization QQAAZZ were charged by a federal grand jury in the Western District of Pennsylvania in an indictment unsealed today. 

The QQAAZZ members are accused of conspiring with cyber-criminals all over the world to launder money stolen from victims of computer fraud in the United States and elsewhere. 

The indictment alleges that, since 2016, the gang has laundered, or attempted to launder, tens of millions of dollars’ worth of stolen funds. A related indictment unsealed in October 2019 charged five members of QQAAZZ.

Drawing from a network of members located in Latvia, Georgia, Bulgaria, Romania, and Belgium, among other countries, QQAAZZ opened and maintained hundreds of corporate and personal bank accounts at financial institutions in multiple countries to receive money stolen by cyber-criminals from bank accounts of victims.  

“The funds were then transferred to other QQAAZZ-controlled bank accounts and sometimes converted to cryptocurrency using ‘tumbling’ services designed to hide the original source of the funds,” stated the Department of Justice.

“After taking a fee of up to 40 to 50 percent, QQAAZZ returned the balance of the stolen funds to their cybercriminal clientele.”  

QQAAZZ advertised its services as a “global, complicit bank drops service” on Russian-speaking online cyber-criminal forums. Among the threat actors that used QQAAZZ’s services are the creators of Dridex, Trickbot, and GozNym.

In a closely coordinated international operation, more than 40 house searches were carried out in Latvia, Bulgaria, the United Kingdom, Spain, and Italy, with criminal prosecutions initiated in the United States, Portugal, Spain, and the United Kingdom.  

More searches and arrests were carried out in Latvia by the Latvian State Police than in any other country. Police in Bulgaria, conducting searches as part of the international operation, uncovered an extensive Bitcoin-mining operation associated with QQAAZZ.

American victims impacted by QQAAZZ include a Jewish Orthodox Synagogue in Brooklyn, New York, a technology company in Windsor, Connecticut, a medical device manufacturer in York, Pennsylvania, and an automotive parts manufacturer in Livonia, Michigan.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cyber-Attack on Major US Bookseller

Cyber-Attack on Major US Bookseller

American bookseller Barnes & Noble has been hit by cyber-criminals the day after resolving a connection issue with its Nook e-reader service.

The beleaguered bookstore has been emailing customers since Monday to notify them of the attack and warn them that their data may have been compromised.

“It is with the greatest regret we inform you that we were made aware on October 10, 2020, that Barnes & Noble had been the victim of a cybersecurity attack, which resulted in unauthorized and unlawful access to certain Barnes & Noble corporate systems,” states the notification email.

The company said that while some personal information belonging to customers may have been exposed, no evidence had been found so far to suggest that payment data had been impacted.

“Firstly, to reassure you, there has been no compromise of payment card or other such financial data,” wrote the bookseller. “These are encrypted and tokenized and not accessible.”

However, customers were warned that attackers may have accessed their email address, billing and shipping addresses, and telephone number and were advised that they may now receive unsolicited emails. Transaction details regarding what purchases customers had made may also have been compromised.

“We currently have no evidence of the exposure of any of this data, but we cannot at this stage rule out the possibility,” acknowledged the company. 

News of the cyber-attack on Barnes & Noble follows a “system failure” experienced by the bookseller that interrupted e-reader content access for some of the store’s users. According to PublishersLunch, difficulties were also experienced by some customers who were trying to access their online accounts.

Good E-Reader reported on Monday that some B&N branches struggled to process customer orders in-store as a result of the technical issue.

“We have a serious network issue and are in the process of restoring our server backups,” said Barnes & Noble in a statement to Fast Company on Wednesday.

“Our systems are back online in our stores and on BN.com, and we are investigating the cause. Please be assured that there is no compromise of customer payment details, which are encrypted and tokenized.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Government CIOs Praised for Pandemic Response, Better Collaboration Required

Government CIOs Praised for Pandemic Response, Better Collaboration Required

Collaboration with local governments and public higher education is critical to managing increasingly complex cyber-risk.

According to a new research document from Deloitte and the National Association of State Chief Information Officers (NASCIO), as US state and local governments are top targets for ransomware and other cyber-attacks, they can benefit by working together. The report claimed that they are often a target for ransomware and other attacks and that there is “a value to having states build a collaborative relationship with local governments and institutions of public higher education.”

This can enable all parties to benefit from sharing knowledge and resources, and coordinating approaches. “Such a collaborative approach may offer considerable advantages in terms of cost efficiencies, better cyber-hygiene and culture, and improved security of citizens’ data,” the report said.

Reflecting on 2020, the report claimed the pandemic forced state governments to “act quickly in response to public health and safety concerns” and this led CISOs and their staff to support the increased demands for technology, enabling remote work “despite being severely constrained by the lack of resources for cybersecurity.”

It claimed security teams “worked closely with IT departments to secure the government enterprise, the virtual work environment, technology infrastructure and the supply chain.” The top cybersecurity challenge barriers to overcome cited were the following:

  • Lack of sufficient cybersecurity budget
  • Inadequate cybersecurity staffing
  • Legacy infrastructure and solutions to support emerging threats
  • Lack of dedicated cybersecurity budget
  • Inadequate availability of cybersecurity professionals

“Reinventing statewide operations overnight, moving quickly at scale, relying on available resources amplified the importance of cybersecurity and highlighted shortcomings in the cybersecurity ecosystem,” the report said.

It also stated that some of the changes made in response to the COVID-19 pandemic are likely to remain, such as remote working, and “delivering citizen services without the need to visit government offices in person may become the norm as well.” This is because “states will need to adjust to this new reality, and CISOs will need to orient their strategies to meet the needs of this next normal.”

“The last six months have created new opportunities for cyber-threats and amplified existing cybersecurity challenges for state governments,” said Meredith Ward, director of policy and research at NASCIO. “The budget and talent challenges experienced in recent years have only grown, and CISOs are now also faced with an acceleration of strategic initiatives to address threats associated with the pandemic.”

Srini Subramanian, principal at Deloitte at Touche LLP, and state and local government advisory leader, said: “Continuing challenges with resources beset state CISOs/CIOs. This is evident when comparing the much higher levels of budget that federal agencies and other industries like financial services receive to fight cyber-threats.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Iranian APT Group Targets Global Universities Again

Iranian APT Group Targets Global Universities Again

An Iranian state-backed APT group known for targeting universities for research materials has been detected in a new campaign coinciding with the start of the new academic year.

Silent Librarian (aka TA407, Cobalt Dickens) is once again casting the net wide geographically. It has registered phishing sites for universities in: Australia (Victoria, Adelaide and Melbourne Victoria), the UK (Glasgow Caledonian, King’s College London, Bristol, Cambridge and others), the US (North Texas, McGill, Stony Brook), Singapore (Nanyang Technological), Canada (Western, Toronto) and in Sweden, Germany and the Netherlands.

Using a similar pattern to that spotted in previous campaigns, the group keeps most of the domain intact but simply swaps the TLD, which can happen if organizations don’t defensively register enough variants.

Although Silent Librarian is using Cloudflare to hide the true location of its servers, Malwarebytes said it was able to identify several based in Iran.

“It may seem odd for an attacker to use infrastructure in their own country, possibly pointing a finger at them,” the firm’s Threat Intelligence Team wrote in a blog post. “However, here it simply becomes another bulletproof hosting option based on the lack of cooperation between US or European law enforcement and local police in Iran.”

It warned that although sites are being taken down as quickly as possible, the group has amassed a sizeable number in order to continue its phishing campaign unabated.

“IT administrators working at universities have a particularly tough job considering that their customers, namely students and teachers, are among the most difficult to protect due to their behaviors. Despite that, they also contribute to and access research that could be worth millions or billions of dollars,” said Malwarebytes.

“Considering that Iran is dealing with constant sanctions, it strives to keep up with world developments in various fields, including that of technology. As such, these attacks represent a national interest and are well funded.”

Silent Librarian has been spotted in 2018 and 2019 performing similar attacks.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Zoom Finally Rolls out End-to-End Encryption

Zoom Finally Rolls out End-to-End Encryption

Zoom has finally announced its end-to-end encryption (E2EE) capabilities will be made available to users, significantly enhancing the security of video and voice calls.

The video conferencing giant’s head of security engineering, Max Krohn, said the first of a four-phase roll-out would begin next week. During this “technical preview,” users will be able to provide feedback to the firm for the first 30 days.

Zoom’s E2EE is based on the same AES 256-bit GCM encryption it currently uses but will add an extra layer of security to calls when conference hosts deem it important. As keys aren’t stored by the company itself, it could reassure those concerned about Zoom’s large China-based engineering team.

“In typical meetings, Zoom’s cloud generates encryption keys and distributes them to meeting participants using Zoom apps as they join,” explained Krohn.

“With Zoom’s E2EE, the meeting’s host generates encryption keys and uses public key cryptography to distribute these keys to the other meeting participants. Zoom’s servers become oblivious relays and never see the encryption keys required to decrypt the meeting contents.”

The functionality is available to free and paid users and can host up to 200 participants in a meeting. However, features including join before host, cloud recording, streaming, live transcription, Breakout Rooms, polling, 1:1 private chat and meeting reactions are not available with E2EE in this first phase.

Zoom came in for strong criticism early in the year when it said E2EE would only be available for paid users because, in the reported words of CEO Eric Yuan, “we also want to work together with FBI, with local law enforcement in case some people use Zoom for a bad purpose.”

It quickly backtracked on the issue after industry uproar. However, on another occassion, Zoom was called out for falsely claiming it provided E2EE when it did not.

The timing of Zoom’s announcement could be better, however: the Five Eyes nations plus India and Japan recently signed yet another statement calling on tech firms to build backdoors into end-to-end encryption in order to allow law enforcement to access data on suspects.

Zoom could now be dragged into this long-running tussle between Western governments and US tech firms.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Data Breach Volumes Plummet 30% in 2020

US Data Breach Volumes Plummet 30% in 2020

The volume of data breaches reported in the US is on track for its lowest number since 2015, although hundreds of millions have had their details compromised so far in 2020, according to official figures.

Non-profit the Identity Theft Resource Center (ITRC) records all publicly reported breaches in the country to compile an accurate running estimate across verticals.

It claimed in a Q3 update yesterday that the volume reported so far in 2020 is 30% lower than the same period last year. In terms of individual victims, the figure is 60% lower, at 292 million.

However, the major breach at IT service provider Blackbaud may have skewed results slightly, as the single incident actually caused data loss at hundreds of customers. If this was treated as a series of events, the number of breaches so far this year would only have fallen 10% since 2019, according to ITRC.

What’s more, only a small number of breached Blackbaud clients — 58 out of 247 — have notified how many customers were affected. Currently the number stands at nearly seven million individuals affected, but it could rise significantly.

“If anyone gets a breach notice connected to the Blackbaud data breach, they should act immediately because their information could still be available,” said ITRC president and CEO, Eva Velasquez.

“Whenever someone receives a breach notice, they need to act quickly and decisively because of the risks that come with personal information being exposed.”

The non-profit also reported that cyber-attacks were the primary cause of data compromise in Q3, with phishing and ransomware the most common types. However, if the Blackbaud breach was treated as a series of incidents then supply chain attacks would come top.

A report from Risk Based Security back in August also noted a decline in the volume of reported breaches. However, although the number of breaches fell 52% year-on-year in the first half of 2020, the number of exposed records was estimated to be four-times higher than at any previous time.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk