“King of Fraud” Gets Ten Years

“King of Fraud” Gets Ten Years

A Russian cyber-criminal has been sent to prison in the United States for defrauding American companies out of millions of dollars.

Aleksandr Zhukov ran a sophisticated digital advertising scam through purported advertising network Media Methane. In June, he was convicted of wire fraud conspiracy, wire fraud, money laundering conspiracy, and money laundering.

Zhukov, the self-styled “king of fraud,” worked with accomplices to trick victim companies into believing that they had purchased genuine digital advertising space. In reality, Media Methane was merely a smoke and mirrors operation, deploying a combination of coding and domain spoofing to give the false impression that victims’ ads were being viewed. 

“Rather than place advertisements on real publishers’ web pages where human internet users would see them, Zhukov rented more than 2,000 computer servers housed in commercial datacenters in Dallas, Texas, Amsterdam and the Netherlands, and programmed the datacenter computer servers (the “bots”) to simulate humans viewing ads on webpages,” stated the US Attorney’s Office for the Eastern District of New York in a statement released Wednesday.

The criminals programmed the bots to load genuine ads on blank web pages and then deceived their victims into believing that the ads were loading on authentic websites. 

Zhukov and his co-conspirators spoofed the domains of more than 6,000 publishers, including the New York Times, the New York Post, the New York Daily News, Newsday, and the Staten Island Advance

Victims of the scam include the Texas Scottish Rite Hospital for Children and household names Nestle Purina and Time Warner Cable.

Zhukov and his co-conspirators stole more than $7m through the scam, which they ran between September 2014 and December 2016.

On November 10, Zhukov was sentenced to ten years in prison and ordered to pay $3,827,493 in forfeiture.

Zhukov’s Methbot was initially discovered by HUMAN (formerly White Ops) in 2016. 

According to HUMAN Security: “We then took a leading role in engaging with law enforcement and many of our ad tech partners to create the largest private/public sector collaboration in history to orchestrate a major botnet takedown.”

It added, “After seeing how important cross-industry collaboration is to defeating cybercrime, we created The Human Collective – a program built for companies looking to be at the forefront of fighting fraud.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Hoax Email Blast Abused Poor Coding in FBI Website

The Federal Bureau of Investigation (FBI) confirmed today that its fbi.gov domain name and Internet address were used to blast out thousands of fake emails about a cybercrime investigation. According to an interview with the person who claimed responsibility for the hoax, the spam messages were sent by abusing insecure code in an FBI online portal designed to share information with state and local law enforcement authorities.

The phony message sent late Thursday evening via the FBI’s email system. Image: Spamhaus.org

Late in the evening on Nov. 12 ET, tens of thousands of emails began flooding out from the FBI address eims@ic.fbi.gov, warning about fake cyberattacks. Around that time, KrebsOnSecurity received a message from the same email address.

“Hi its pompompurin,” read the missive. “Check headers of this email it’s actually coming from FBI server. I am contacting you today because we located a botnet being hosted on your forehead, please take immediate action thanks.”

A review of the email’s message headers indicated it had indeed been sent by the FBI, and from the agency’s own Internet address. The domain in the “from:” portion of the email I received — eims@ic.fbi.gov — corresponds to the FBI’s Criminal Justice Information Services division (CJIS).

According to the Department of Justice, “CJIS manages and operates several national crime information systems used by the public safety community for both criminal and civil purposes. CJIS systems are available to the criminal justice community, including law enforcement, jails, prosecutors, courts, as well as probation and pretrial services.”

In response to a request for comment, the FBI confirmed the unauthorized messages, but declined to offer further information.

“The FBI and CISA [the Cybersecurity and Infrastructure Security Agency] are aware of the incident this morning involving fake emails from an @ic.fbi.gov email account,” reads the FBI statement. “This is an ongoing situation and we are not able to provide any additional information at this time. The impacted hardware was taken offline quickly upon discovery of the issue. We continue to encourage the public to be cautious of unknown senders and urge you to report suspicious activity to www.ic3.gov or www.cisa.gov.”

In an interview with KrebsOnSecurity, Pompompurin said the hack was done to point out a glaring vulnerability in the FBI’s system.

“I could’ve 1000% used this to send more legit looking emails, trick companies into handing over data etc.,” Pompompurin said. “And this would’ve never been found by anyone who would responsibly disclose, due to the notice the feds have on their website.”

Pompompurin says the illicit access to the FBI’s email system began with an exploration of its Law Enforcement Enterprise Portal (LEEP), which the bureau describes as “a gateway providing law enforcement agencies, intelligence groups, and criminal justice entities access to beneficial resources.”

The FBI’s Law Enforcement Enterprise Portal (LEEP).

“These resources will strengthen case development for investigators, enhance information sharing between agencies, and be accessible in one centralized location!,” the FBI’s site enthuses.

Until sometime this morning, the LEEP portal allowed anyone to apply for an account. Helpfully, step-by-step instructions for registering a new account on the LEEP portal also are available from the DOJ’s website. [It should be noted that “Step 1” in those instructions is to visit the site in Microsoft’s Internet Explorer, an outdated web browser that even Microsoft no longer encourages people to use for security reasons.]

Much of that process involves filling out forms with the applicant’s personal and contact information, and that of their organization. A critical step in that process says applicants will receive an email confirmation from eims@ic.fbi.gov with a one-time passcode — ostensibly to validate that the applicant can receive email at the domain in question.

But according to Pompompurin, the FBI’s own website leaked that one-time passcode in the HTML code of the web page.

A screenshot shared by Pompompurin. Image: KrebOnSecurity.com

Pompompurin said they were able to send themselves an email from eims@ic.fbi.gov by editing the request sent to their browser and changing the text in the message’s “Subject” field and “Text Content” fields.

A test email using the FBI’s communications system that Pompompurin said they sent to a disposable address.

“Basically, when you requested the confirmation code [it] was generated client-side, then sent to you via a POST Request,” Pompompurin said. “This post request includes the parameters for the email subject and body content.”

Pompompurin said a simple script replaced those parameters with his own message subject and body, and automated the sending of the hoax message to thousands of email addresses.

A screenshot shared by Pompompurin, who says it shows how he was able to abuse the FBI’s email system to send a hoax message.

“Needless to say, this is a horrible thing to be seeing on any website,” Pompompurin said. “I’ve seen it a few times before, but never on a government website, let alone one managed by the FBI.”

As we can see from the first screenshot at the top of this story, Pompompurin’s hoax message is an attempt to smear the name of Vinny Troia, the founder of the dark web intelligence companies NightLion and Shadowbyte.

“Members of the RaidForums hacking community have a long standing feud with Troia, and commonly deface websites and perform minor hacks where they blame it on the security researcher,” Ionut Illascu wrote for BleepingComputer. “Tweeting about this spam campaign, Vinny Troia hinted at someone known as ‘pompompurin,’ as the likely author of the attack. Troia says the individual has been associated in the past with incidents aimed at damaging the security researcher’s reputation.”

Troia’s work as a security researcher was the subject of a 2018 article here titled, “When Security Researchers Pose as Cybercrooks, Who Can Tell the Difference?” No doubt this hoax was another effort at blurring that distinction.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

UK Funds Project to Teach Autistic Children Cybersecurity Skills

UK Funds Project to Teach Autistic Children Cybersecurity Skills

A program set up to teach cybersecurity skills to autistic and neurodiverse young people in the United Kingdom has received a sizable injection of cash.

The UK chancellor of the exchequer, Rishi Sunak, has awarded £100,000 (approximately $135K) to the Cybersecurity Neurodiversity Skills Development Program, described by Native Newspost as “ground-breaking.”

The program, which is based in the central Scottish city of Perth, was created to give youngsters practical skills that will increase their self-confidence and employability.

The award will be made to the University of the Highlands and Islands and to the charity Perth Autism Support as part of the UK Government’s Community Renewal fund.

Perth Autism Support (PAS) was founded in November 2011 to support gaps identified in the support of autistic children and young people up to the age of 18 and their families in Perth and Kinross. 

The organization has more than 870 families registered for services across Perth and Kinross and supports on average 240 young people every week. 

Murdo Fraser, a politician who represents constituents in Mid-Scotland and Fife, hailed the cybersecurity project and the funding newly earmarked to support it.

Fraser said the award was “yet further evidence Rishi Sunak will step up to support rural and remote communities in Perth and Kinross.”

Through the Community Renewal Fund, the UK government will invest £220m in projects around the UK that seek to invest in local communities or offer skills or support to improve job opportunities.

On November 3, the UK’s levelling up secretary, Michael Gove, announced the 477 locally led projects whose applications for funding had met with success.

In the Northeast of England, £808,000 was awarded to a project to improve digital skills and digital employment opportunities and create 40 online training centers for people who don’t have access to the internet.

In Worcestershire, a 90-day Cleantech Bootcamp designed to teach businesses how to successfully enter the green sector was awarded £522,750.

A project in Argyll and Bute to create a Seaweed Academy that will provide education and training in seaweed farming received £400,000. 

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Spanish Brewery “Paralyzed” by Cyber-Attack

Spanish Brewery “Paralyzed” by Cyber-Attack

Spain’s second-biggest brewery says it expects to fully recover from a “highly complex” cyber-attack “in the coming days.” 

Sociedad Anónima Damm, which has been making the world-renowned Estrella Damm lager since 1876, was targeted by cyber-criminals on Tuesday. 

The attack on the company’s computer systems temporarily halted production at all of Damm’s breweries. However, the main brewery in El Prat de Llobregat, which is located near the capital city of Barcelona, was slowest to recover. 

Approximately 500 employees work at the El Prat de Llobregat plant, which typically produces 7 million hectolitres of beer a year. Damm’s head of communications, Olga Vidal, told Reuters on Friday that the digital assault had “entirely paralyzed” the plant for a two-hour period. 

Damm reportedly relies on computer-driven technology to complete its bottling processes. 

She said: “IT services made possible a partial resumption of production and we expect to operate at 100% in the coming hours.”

Fortunately, the attack had no impact on beer deliveries made by the brewery this week. Vidal said Damm’s existing stocks were sufficient to honor all its deliveries to bars, supermarkets, and restaurants. 

Damm also brews beer in smaller quantities at two other plants in Spain, one of which is in Murcia while the other is based in Alicante.

Vidal did not disclose the nature of the attack, nor did she say whether Damm made a ransom payment to its attackers. 

A Damm spokesperson told the Ara newspaper that the brewery had suffered a “computer incident in the operating system,” which was “under investigation.”

The same spokesperson said that the brewery had activated its emergency response plan and was now working to restore production to its normal level.

Sources close to the brewery told Ara that the attack would have been more catastrophic had it taken place in the summer months when more beer is consumed. At that time of year, stocks only last around three days. 

The incident at Damm brewery follows a ransomware attack at the nearby Autonomous University of Barcelona, which occurred last month. The perpetrators disabled computer services at the university, encrypting more than 650,000 files and demanding a €3m ransom.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Europol: Ransomware Gangs Focusing on High Profile Targets

Europol: Ransomware Gangs Focusing on High Profile Targets

Ransomware gangs have increasingly focused on high-profile targets like large corporations and government institutions in the past year, according to Europol’s Internet Organised Crime Threat Assessment (IOCTA) 2021.

The report, which offers insights into current cybercrime trends in Europe, revealed that ransomware actors have taken advantage of widespread homeworking to launch more sophisticated and targeted attacks.

The law enforcement agency also highlighted the growing use of multi-layered extortion methods to extort service providers, financial institutions and businesses, such as DDoS attacks.

Additionally, they observed that cyber-criminals have increasingly recognized the potential to attack a large number of organizations via supply chain attacks, often targeting the ‘weakest link.’ The Kaseya and SolarWinds incidents are prominent examples of this trend.  

Another concerning finding in the report was an “alarming” rise in self-produced explicit material of children online. This has been driven by increased unsupervised internet use by children in the pandemic. The authors said children were frequently lured into producing and sharing explicit material of themselves by offenders using fake identities on gaming platforms and social media sites. Additionally, some offenders recorded or captured victims performing live-streamed sexual acts for them without the victims’ knowledge.

Other notable trends in the past year included fraudsters continuing to leverage the COVID-19 crisis and increased online shopping to scam victims. There has also been an evolution in mobile malware, with cyber-criminals trying to find ways to circumvent additional security measures such as two-factor authentication, according to the report.

Catherine De Bolle, executive director at Europol, lauded recent law enforcement successes in disrupting cyber-criminal gangs and emphasized the importance of such operations in stemming the scourge of attacks. “Worldwide operations, such as the successful takedown of EMOTET botnet, have demonstrated the effectiveness of international cooperation. Ransomware groups have attempted to disrupt critical infrastructures, such as service providers and government institutions, to increase their profits with no concern for the possible damages such interceptions may cause to public safety and security. To this, the collective response of our international law enforcement community is clear: the authorities and the private sector worldwide stand strong and ready to mitigate together any threat that blackmails the stability of our societies,” she stated.

Commenting on the findings, Chris Waynforth, AVP Northern Europe at Imperva, said: “This is further evidence of how much of a threat ransom attacks pose to businesses, including those that go beyond ransomware. Our research has seen a surge in ransom-focused DDoS attacks, partly because they can be even easier to carry out than ransomware attacks. It’s no coincidence that the number of DDoS attacks has quadrupled in the last year. Using rapid-fire attacks, averaging just six minutes, cyber-criminals demonstrate their capabilities to businesses before sending an extortion demand, threatening much larger attacks if payments aren’t made.

“Hackers are carrying out ransom attacks because they are one of the fastest ways to big profits, and their tactics go beyond just using malware. Businesses need to have proper cyber-resiliency strategies in place so that no matter what sort of ransom attack comes their way, the impact is minimized and operations can continue.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Vulnerable Web Applications Prevalent in EU Pharma Companies

Vulnerable Web Applications Prevalent in EU Pharma Companies

Europe’s top 10 pharma companies all have vulnerable web applications, potentially putting sensitive medical and patient data at risk of being hacked, according to a new study by Outpost24.

The company used its external attack surface management tool to assess the security of Europe’s top pharma firms’ internet-facing web services. Worryingly, they gave 80% of these organizations a score of above 30 (out of 58.4), which indicates a high susceptibility to having security vulnerabilities presented externally for potential exploits.

However, the top 10 EU pharma firms had a significantly lower risk exposure score than their top 10 US counterparts (40.5).

Overall, the researchers noted that EU pharma companies run an exceptionally large number of web applications (20,394 web apps and 9,216 domains) compared to other industries. Nearly one in five (18%) use outdated components containing known vulnerabilities, while 3% were considered suspicious.

Additionally, over 200 EU pharmaceutical applications have unencrypted login forms, potentially putting clients’ and patients’ data at risk of exposure.

The authors also observed a number of other security and compliance issues in EU pharma companies, including basic SSL, cookie settings and privacy policy defects.

Encouragingly, the report noted many of the vulnerabilities are easily fixable.

Stephane Konarkowski, security consultant at Outpost24, commented: “This research highlights the complexity of modern-day pharmaceutical and healthcare applications and the vast volume exposed on the Internet.

“These results demonstrate how crucial it is for the industry to review their external footprint and vulnerability exposure to improve security hygiene in the face of the ransomware pandemic.”

Nicolas Renard, security researcher at Outpost24, added: “As the attack surface and trade secrets that pharmaceutical organizations process become more pertinent, it will give threat actors more reasons and motivations to step up malicious attacks for profit and put public health at risk.”

Attacks on pharma and other healthcare organizations have ramped up in the past year, with data on COVID-19 vaccine development viewed as highly valuable to threat actors. This includes accusations nations like Russia, China and North Korea have attempted to sabotage or steal information on R&D efforts in this area.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Major Water Supplier Suffers Nine-Month Long Breach

Major Water Supplier Suffers Nine-Month Long Breach

One of Australia’s largest regional water suppliers was breached for several months before detecting the unauthorized access, another worrying sign of weaknesses in critical infrastructure security.

A Queensland Audit Office annual report on the water industry did not mention the provider by name but said it continues to see “significant control weaknesses in the security of information systems” across the industry.

The breach in question occurred between August 2020 and May 2021, resulting in unauthorized access to a web server.

“Threat actors targeted an older and more vulnerable version of the system. The web server that stores customer information contained suspicious files that increased visitor traffic to an online video platform,” the report explained.

“As entities use more cloud-based services (which provide remote access to systems), cyber risk vulnerabilities and exposures must be continuously assessed. Entities need to make sure their users are aware of their responsibilities in managing cyber risks.”

A local report identified the provider as Sunwater, one of the state’s largest regional providers.

The auditor explained that it had taken corrective measures, including patching, more robust password practices, and network monitoring.

Although this breach appears to have been caused by financially motivated cyber-criminals, with no impact on customers, utility providers are increasingly being targeted by more concerning attacks designed to cause service disruption and even harm citizens.

In 2019 a former employee at a Kansas plant accessed and shut down some of the key processes used to disinfect water. Earlier this year, in the Florida city of Oldsmar, an actor tried to change the water supply’s chemical balance by remotely logging into a SCADA system.

Last month, the US authorities issued an alert warning of ongoing malicious cyber-activity targeting the country’s water and wastewater systems (WWS) sector.

Spear-phishing, compromise of Remote Desktop Protocol (RDP) systems, and exploitation of unpatched or outdated software were the key threat vectors highlighted in the report.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Interpol Closes in on Global BEC Gang

Interpol Closes in on Global BEC Gang

Irish police have joined forces with Interpol to track down an organized crime gang that has already stolen more than €14m ($16m) from local businesses and individuals through business email compromise (BEC).

The Garda has been investigating the gang for several years for multiple serious financial crime offenses. Its 18-month long Operation Skein has already led to the reported arrests of over 400 suspects, but the global nature of cybercrime meant international policing work was also needed.

To that end, Interpol’s Global Financial Crime Task Force (IGFCTF) provided on-the-ground support to the Garda National Economic Crime Bureau (GNECB) last month to help share intelligence with international forces.

Interpol also helped Irish police with digital forensic work, downloading data and call records from seized devices and analyzing the evidence “through a global lens.” This has already triggered cooperative investigations with police in the US and South Africa, Interpol said.

The investigation has also revealed links between the Ireland-based gang and notorious Nigerian crime syndicate Black Axe, which also focuses on BEC scams.

“Arrests and prosecutions outside of Ireland are foreseen as ongoing investigations unfold,” Interpol claimed.

BEC has been the highest-grossing cybercrime category over the past three years, according to the FBI.

Reported crimes led to losses of nearly $1.9bn last year, off the back of just 19,000 cases. That amounted to nearly half the total for cybercrime losses in 2020. In 2019 it was $1.8bn, and the year before that it was $1.3bn.

The investigation is not only targeting the BEC gang itself but also its international networks of money mules. They’ve already enabled the group to launder approximately €8m ($9m), according to Interpol.

COVID-19 dealt efforts by banks to track suspicious transactions of this sort of blow as key staff was sent to work from home, often without the right tools at their disposal, according to some reports.

According to a BAE Systems report in September, 60% of compliance officers from financial institutions believe that tracking money laundering has become harder over the past year.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Pentagon Set to Open Zero Trust Office in December

Pentagon Set to Open Zero Trust Office in December

The US Department of Defense is stepping up its cybersecurity efforts with a dedicated Zero Trust office set to open next month, according to a senior official.

Pentagon CISO, David McKeown, said at the CyberCon event this week that the office would report into the CIO, although the senior executive in charge has not yet been named.

Leadership buy-in to Zero Trust has helped to accelerate the opening, which can be seen in part as a response to the SolarWinds campaign in which nine federal government departments were compromised by Russian spies.

“We’ve redoubled our efforts, we’ve fought for dollars internally to get after this problem faster,” McKeown reportedly said.

“We’re standing up a portfolio management office that will … rationalize all network environments out there, prioritize and set each one of them on a path of Zero Trust over the coming five, six, seven years.”

President Biden’s Executive Order on cybersecurity back in May required the head of each agency to develop a plan to implement a Zero Trust architecture within 60 days. The plan should incorporate best practice migration steps as recommended by NIST, as well as “describe any such steps that have already been completed, identify activities that will have the most immediate security impact, and include a schedule to implement them.”

Felipe Duarte, senior researcher at Appgate, argued that Zero Trust is vital for preventing attackers from moving laterally through networks once an initial breach has occurred.

“Only by segmenting the networks and assuming all connections can be compromised you can detect an intruder in your network,” he added.

“Zero Trust needs to be implemented in the core infrastructure. You must profile any device trying to connect in your network, use multi-factor authentication to ensure credentials are not compromised, segment networks creating isolated perimeters, and, most important, only provide access to what a user or a system needs to.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains