—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Author: admin
Friday Squid Blogging: Squid Game Cryptocurrency Was a Scam
The Squid Game cryptocurrency was a complete scam:
The SQUID cryptocurrency peaked at a price of $2,861 before plummeting to $0 around 5:40 a.m. ET., according to the website CoinMarketCap. This kind of theft, commonly called a “rug pull” by crypto investors, happens when the creators of the crypto quickly cash out their coins for real money, draining the liquidity pool from the exchange.
I don’t know why anyone would trust an investment — any investment — that you could buy but not sell.
Wired story.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Read my blog posting guidelines here.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
US Indicts Brit Over SIM Swap Crypto Theft
US Indicts Brit Over SIM Swap Crypto Theft

A 22-year-old man from Britain has been indicted by the United States in connection with the 2019 theft of crypto-currency worth approximately $784,000.
It is alleged that Joseph James O’Connor, also known as “PlugwalkJoe,” conspired with others to carry out SIM swap attacks against at least three individuals, all of whom were executives employed by the same crypto-currency company based in Manhattan, New York.
“During a cyber intrusion known as a SIM swap attack, cyber threat actors gain control of a victim’s mobile phone number by linking that number to a subscriber identity module (SIM) card controlled by the threat actors, resulting in the victim’s calls and messages being routed to a malicious unauthorized device controlled by the threat actors,” explained the US Attorney’s Office for the Southern District of New York.
“The threat actors then typically use control of the victim’s mobile phone number to obtain unauthorized access to accounts held by the victim that are registered to the mobile phone number.”
An indictment unsealed on November 3 alleges that O’Connor and his co-conspirators, after successfully carrying out a SIM swap attack against one of the executives in April 2019, were able to gain unauthorized access to multiple accounts and computer systems belonging to the victim’s employer.
It is alleged that on or about May 1, 2019, the defendant and his criminal comrades used their unauthorized access to steal and fraudulently divert crypto-currency of various types including approximately 770.784869 Bitcoin cash, approximately 6,363.490509 Litecoin, approximately 407.396074 Ethereum, and approximately 7.456728 Bitcoin.
“After stealing and fraudulently diverting the Stolen Cryptocurrency, O’Connor and his co-conspirators laundered it through dozens of transfers and transactions and exchanged some of it for Bitcoin using cryptocurrency exchange services,” said the Department of Justice.
O’Connor is charged with conspiracy to commit computer hacking, conspiracy to commit wire fraud, aggravated identity theft, and conspiracy to commit money laundering.
On July 21, O’Connor was arrested on other US federal charges in Estepona, Spain, by Spanish National Police. The charges were in connection with the July 2020 hack of Twitter that resulted in the compromise of over 130 Twitter accounts, including those belonging to politicians, celebrities, and companies.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Amazon Spoofed in New Attack
Amazon Spoofed in New Attack

Researchers have unearthed a sneaky new cyber-attack that spoofs American multinational technology company Amazon to steal victims’ financial credentials.
The digital deception, which combines brand impersonation with social engineering, was discovered by software firm Avanan, a Check Point Company based in New York.
Today, Avanan shared details about the attack on its blog. The scam is a two-part affair that begins with an email. It was first observed in October 2021.
The perpetrators of the attack use legitimate Amazon links to force the end-user to make a phone call and give out their financial details.
“In this attack, hackers are spoofing an Amazon order notification page,” wrote researchers.
Victims receive what looks like a typical Amazon order confirmation email containing links that all direct the user to the legitimate Amazon site.
“When trying to call the number listed, which is not an Amazon number, the scam begins, with the end goal of obtaining credit card information,” noted researchers.
Though the number listed on the email has an area code from South Carolina, it is not an Amazon number. Victims who dial will not receive an answer. However, a few hours later, they will get a call back from attackers based in India.
To incite the victims to make the call to Amazon, the attackers include high-price items on the fictitious emailed invoice.
Details gathered under the scam could be used by the attackers to carry out other criminal activity.
Researchers noted that this method of stealing financial details “results not only in monetary gain for the hackers but serves as a form of phone number harvesting, enabling them to carry out further attacks by voicemail or text message.”
While the attackers “do a good job of spoofing an actual Amazon order,” eagle-eyed recipients of the malicious Amazon Service Alert email used in the attack will notice that it has been sent from a Gmail address.
Researchers said: “This attack bypasses traditional email security scanners in large part due to the existence of legit links. When doing a check against an Allow List, this email passes.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Consumers Warned About Rise in Call Center Threats
Consumers Warned About Rise in Call Center Threats

Consumers have been warned about a significant rise in call center threat activity, in which attackers use email alongside call center customer service agents to scam victims, sometimes out of tens of thousands of dollars.
Telephone-oriented attack delivery (TOAD) usually comes in two forms, according to cybersecurity firm Proofpoint. One uses free, legitimate remote assistance software to steal money, while the other uses malware, such as BazaLoder, disguised as a document to compromise a computer. These techniques begin with an email claiming to be from a legitimate source. The emails contain a phone number for customer assistance, and when the recipient calls the number, they are connected to a malicious call center attendant. The customer service representative will then verbally guide the victim through different types of user interaction, such as downloading a malicious file, allowing them to remotely access their machine or downloading a malicious application for remote access.
Proofpoint said that recent lures have included Justin Bieber ticket sellers, computer security services, COVID-19 relief funds, online retailers promising refunds for mistaken purchases, software updates and financial support.
These attacks can be “life-altering” for victims, with the vendor noting nearly $50,000 was lost in a single case in which the threat actor masqueraded as NortonLifeLock.
The researchers were able to pinpoint many of the attacks as coming from India, with multiple activity clusters occurring in Kolkata, Mumbai and New Delhi. Interestingly, they found many of these malicious call centers are architected like legitimate businesses, with leases being signed on buildings purporting to be telemarketers or other phone-based companies. Additionally, local jobseekers are often recruited to support the operation.
The report indicated that these attacks are not targeted, and contact lists are most likely procured from legitimate data brokerages or other telemarketer resources.
Commenting on the research, Sherrod DeGrippo, VP, threat research and detection at Proofpoint, said: “Threat actors are getting very creative with their lures, and a fake receipt for Justin Bieber tickets or a firearm purchase are attention-grabbing enough to trick even the most vigilant email recipient. Should you respond in an attempt to dispute the charges, what follows is an elaborate infection chain that requires significant human interaction and takes victims down the rabbit hole of the worst possible fake customer service experience imaginable – one that ultimately steals your money or leaves behind a malware infection.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Threat Actor Claims ‘Groove’ Ransomware Gang Was Hoax
Threat Actor Claims ‘Groove’ Ransomware Gang Was Hoax

A Russian-speaking ransomware ‘group’ which called on rival entities to join forces in targeting the US government may have been a social engineering experiment designed to toy with Western media, it has emerged.
The so-called “Groove” collective published a post on October 22, exhorting its “business brothers” to “stop competing, unite and begin to destroy the US public sector,” according to threat intelligence firm, Flashpoint.
“In its October 22 post, Groove called for a fight against Russian and FSU infosec companies who are ‘being sold to the Americans’ and warned against attacking China and Chinese-affiliated entities with whom Russian-speaking threat actors should maintain friendly relations,” it said.
“Earlier on the same day, Groove posted a list of logins and passwords that were supposedly the VPN credentials of the Hagerstown, Maryland Police Department, although it is unclear if these credentials are viable. Additionally, the Groove mastermind claimed to have access to several other undisclosed police departments.”
A single actor, dubbed “Boriselcin,” soon after claimed that Groove was just an experiment they alone dreamt up to “check whether it was possible to manipulate the Western media through a ransomware blog.”
However, other researchers argued that Boriselcin may have thought up the hoax narrative because their original plan didn’t work out.
“This individual is a well-known member of the Russian-language cybercrime community with ties to a number of ransomware gangs and in August offered $1000 for someone to design a ransomware victim-shaming blog for Groove,” Intel 471 said in a statement send to Infosecurity.
“We are skeptical of the claims raised by the actor that Groove was an elaborate hoax from the beginning, although we wouldn’t be surprised to see further claims by the actor claiming this in future.”
If nothing else, the incident highlights the fluid and at times disorienting nature of the cybercrime underground.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
NSO Group Blacklisted by US for Trade in Spyware
NSO Group Blacklisted by US for Trade in Spyware

A notorious Israeli spyware company has been added to a US export blacklist designed to prevent it from buying components from American companies.
NSO Group develops malware which it insists is used only for legitimate purposes by law enforcement agencies and governments.
However, it was taken to court by WhatsApp in 2019 after the Facebook company claimed it was responsible for attacks on 1400 of its users which involved the company’s Pegasus spyware.
There have also been reports that the zero-click malware was used to hack Amazon boss Jeff Bezos’s phone.
In its ruling, the US Commerce Department said NSO Group and fellow Israeli spyware-maker Candiru were added to the Entity List because the governments it sold to used the tools to “maliciously target government officials, journalists, businesspeople, activists, academics, and embassy workers.”
Earlier this year, investigative journalists revealed that reporters and activists worldwide had been targeted with Pegasus by repressive governments. Even French President Emmanuel Macron and his cabinet were reportedly selected as targets.
“These tools have enabled foreign governments to conduct transnational repression, which is the practice of authoritarian governments targeting dissidents, journalists and activists outside of their sovereign borders to silence dissent,” the Commerce Department notice continued.
“Such practices threaten the rules-based international order.”
Today, two other companies were also added to the Entity List: Russian firm Positive Technologies and Singapore-based Computer Security Initiative Consultancy PTE. Both were judged to trade in hacking tools that threaten the privacy and security of individuals and organizations worldwide.
The announcements can be seen as part of the Biden administration’s efforts to put human rights at the center of US foreign policy.
“The United States is committed to aggressively using export controls to hold companies accountable that develop, traffic, or use technologies to conduct malicious activities that threaten the cybersecurity of members of civil society, dissidents, government officials, and organizations here and abroad,” said commerce secretary, Gina Raimondo.
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
Iranian Hacking Group Leaks Patient and LGBTQ Info
Iranian Hacking Group Leaks Patient and LGBTQ Info

An Iranian hacking group has released highly sensitive personal information on hundreds of thousands of Israeli medical patients and members of an LGBTQ site, in a purported ransom attack.
The Black Shadow group appears to have obtained the data after targeting Israeli hoster CyberServe, which reportedly refused to pay a $1m ransom.
Tuesday saw the release of medical records on 290,000 patients at Israel’s Machon Mor institute – including info on blood tests, treatments, CT scans, ultrasounds, colonoscopies and vaccinations. The group also published the full database from LGBTQ dating service Atraf, including members’ names, locations, and in some cases, their HIV status.
According to the Times of Israel, multiple other customers of CyberServe were targeted in a similar way, including museums, transportation companies, and tourism firms.
The details were reportedly uploaded to a Telegram channel.
Although it’s unclear how the hosting firm was compromised, Israel’s National Cyber Directorate reportedly warned it “several times” that its IT systems were vulnerable.
While the Black Shadow group demanded ransom payments to prevent full disclosure of the information, it’s unclear whether complying with its request would have worked.
Atraf members, in particular, will be fearing reprisals from ultra-conservative groups and online extortionists.
Gurucul CEO, Saryu Nayyar, described the attacks as “troubling” and said that healthcare organizations (HCOs) must do more to protect patient records.
“If we can’t provide that level, at a minimum we have to monitor medical systems and databases to be able to retain people’s confidence in their data,” she added.
“Losing confidence means losing the battle to keep our health information private. Medical facilities simply aren’t protecting and managing their data to the extent that should be required.”
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
S3 Ep57: Europol v. Ransomware, Shrootless bug, and Linux browser flamewars [Podcast]
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains
US Blacklists Pegasus Spyware Maker
—————
Boost Internet Speed–
Free Business Hosting–
Free Email Account–
Dropcatch–
Free Secure Email–
Secure Email–
Cheap VOIP Calls–
Free Hosting–
Boost Inflight Wifi–
Premium Domains–
Free Domains