Cuba Ransomware Nets Nearly $50m

Cuba Ransomware Nets Nearly $50m

The threat actors behind the Cuba ransomware variant have already amassed $44m through targeting of at least 49 victims, according to the FBI.

The bureau’s latest ‘flash’ alert revealed that the group had demanded at least $74m from its victims. These victims frequently come from critical infrastructure sectors like financial, government, healthcare, manufacturing, and IT.

“Cuba ransomware is distributed through Hancitor malware, a loader known for dropping or executing stealers, such as Remote Access Trojans (RATs) and other types of ransomware, onto victims’ networks,” the FBI explained.

“Hancitor malware actors use phishing emails, Microsoft Exchange vulnerabilities, compromised credentials, or legitimate Remote Desktop Protocol (RDP) tools to gain initial access to a victim’s network. Subsequently, Cuba ransomware actors use legitimate Windows services — such as PowerShell, PsExec, and other unspecified services — and then leverage Windows admin privileges to execute their ransomware and other processes remotely.”

Following a compromise, the ransomware will install and execute a CobaltStrike beacon as a service on the victim’s network via PowerShell. It also uses MimiKatz malware to steal RDP credentials and hijack user accounts, the report claimed.

The FBI took a notably softer line in the alert on organizations that go against its advice and pay their extorters. The bureau claimed it “understands” if corporate victims have to engage with their attackers in order to protect shareholders, customers and employees.

However, it urged firms to report any incidents to the FBI, even if they do pay-up, as this provides invaluable information to prevent future attacks and enable tracking of key groups.

“The FBI is seeking any information that can be shared, to include boundary logs showing communication to and from foreign IP addresses, Bitcoin wallet information, the decryptor file, and/or a benign sample of an encrypted file,” it said of the Cuba variant.

It’s believed that Cuba has been active since January 2020.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Nine State Department Phones Hijacked by Spyware

Nine State Department Phones Hijacked by Spyware

Nine US State Department officials had their iPhones remotely hacked by spyware from controversial firm NSO Group, according to reports.

Four people familiar with the matter told Reuters that the Israel developer’s Pegasus malware was used to snoop on the US government victims over the past few months. Although the identity of the hacker(s) is unknown, the targeted staffers were either based in Uganda or working on projects concerning the African country.

They were apparently notified by Apple as part of a wider effort to contact global customers whose devices had been compromised by the NSO-developed “ForcedEntry” exploit. It enabled attackers to remotely hijack smartphones and install Pegasus without any need for user interaction. Apple is also suing NSO Group in a bid to hold it accountable for the actions of some unscrupulous clients.

NSO Group said in a statement that it “shut down all the customers potentially relevant to this case,” while it investigates further.

It appears that the individuals were able to be compromised in this incident because they were using phones not registered in the US.

“We emphasize that the Pegasus software is installed based on phone numbers only, and the tools are incapable of being installed on US (+1) numbers. This case doesn’t involve US phone numbers, and the company had no way to know who the persons monitored by our customers were,” the NSO Group statement continued.

“If the allegations turn out to be true, they are a blunt violation of all commitments and agreements that company has with its customers, and the company will take legal action against these customers.”

Last month, the Treasury put NSO Group on its Entity List — an export blacklist that will make it harder for the firm to get hold of American components or work with US partners.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Romance Fraudster Targeted 670 Women Online

Romance Fraudster Targeted 670 Women Online

A romance fraudster who targeted hundreds of women online has pleaded guilty to charges of fraud and money laundering.

Osagie Aigbonohan, 40, from Lagos, Nigeria, is currently awaiting sentencing after appearing before Southwark Crown Court on Friday.

His scams are said to have tricked at least nine victims he befriended on dating sites into sending him money, including one woman who was conned out of nearly £10,000.

That victim made nine payments over the course of a 10-month online ‘relationship’ with Aigbonohan. The money was wired to fake accounts he had set up, before being forwarded to his own personal bank account, according to the National Crime Agency (NCA).

Using the alias ‘Tony Eden,’ Aigbonohan targeted 670 women on internet dating sites, including one who was terminally ill and whom he continued to pursue even after she passed away.

After his arrest in July this year, Aigbonohan was found to be carrying a fake driver’s license and had no legal right to be staying in the UK, having overstayed a student visa from two years previously.

A search of his flat in Abbey Wood, London, apparently revealed footwear he had purchased with store cards linked to one of his victims.

The NCA urged anyone using dating sites to limit the amount of personal information they share with other users until they meet in person, in case it is part of an identity scam. The agency also warned users never to send money to people they meet on such sites, irrespective of how long they’ve been messaging for.

The NCA that users should stick to the messaging services provided by dating sites themselves, rather than taking conversations to other platforms which may offer fewer online protections.

“Romance fraud is a particularly cruel crime that impacts victims both emotionally and financially, with victims often feeling like they’re the ones to blame. Aigbonohan showed total disregard for the victims in this case and was happy to commit further fraud by moving money between various fraudulently held accounts,” said NCA operations manager, Dominic Mugan.

“It’s possible that he contacted more people than we know about. If you think you may have been a victim, or may be a victim in a similar case, we would urge you to report the details to Action Fraud.”

Romance fraud was the second highest grossing cybercrime category last year, leading to total losses of over $600m, according to the FBI.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains