Security News

Top 5 myths businesses believe about bots
2022-03-18 05:30

Netacea announced the results from a new report showing that most businesses do not fully understand the threat bots pose, leaving those organizations vulnerable to threats. The report surveyed 440 businesses across the travel, entertainment, eCommerce, financial services, and telecoms sectors in the US and the UK. The report found that while most businesses were aware that bots were an issue, many were confused about where attacks originate and what technologies and techniques were effective against bots.

Microsoft App Store Sizzling with New ‘Electron Bot’ Malware
2022-02-24 18:42

As for its endgame, CPR researchers described the newly discovered and analyzed Electron Bot backdoor as "a modular SEO-poisoning malware" used "For social-media promotion and click fraud." Electron Bot can also promote online products: another way to generate PPC revenue or increase a store's rating for higher sales.

Massive LinkedIn Phishing, Bot Attacks Feed on the Job-Hungry
2022-02-16 21:15

Just since Feb. 1, analysts have watched phishing email attacks impersonating LinkedIn surge 232 percent, attempting to trick job seekers into giving up their credentials. The phishing emails themselves were convincing dupes, built in HTML templates with the LinkedIn logo, colors and icons, the report added.

DDoS IRC Bot Malware Spreading Through Korean WebHard Platforms
2022-01-19 20:23

An IRC bot strain programmed in GoLang is being used to launch distributed denial-of-service attacks targeting users in Korea. "Additionally, the DDoS malware was installed via downloader and UDP RAT was used."

Threat Advisory: E-commerce Bots Use Domain Registration Services for Mass Account Fraud
2021-12-29 19:13

While researching a recent large-scale bot campaign with CQ Prime Threat Research team lead, Dean Lendrum, we found attackers using domain parking and monetization services to register multiple domains, creating a large number of fake eCommerce accounts per domain. Patterns observed include irregular domain names, domain resolving to an untrusted web app, SSL not enabled.

Bots are stealing Christmas!
2021-12-24 05:30

Kasada released new data on the latest fraud and malicious automation trends, revealing increased threats during the holidays; rising attacks by bots; and the discovery of a new amped up All in One Grinch Bot that is being used extensively during hype drop sales. Majority of Black Friday bad bots come from the USA, followed by Australia and the UK. "As we approach 2022, the frequency and severity of bad bots continue to threaten online businesses," said Sam Crowther, CEO, Kasada.

Grinch bots hijack all kinds of holiday shopping, from gift cards to hype drop sales
2021-12-23 18:35

All-in-one Grinch bots are working over time this holiday season and using automation to steal gift cards and scoop up limited quantities of in-demand products. The Kasada Threat Intelligence Team identified these bad bot trends during the online holiday shopping season, based on data from the company's e-commerce customers.

From DDoS to bots and everything in between: Preparing for the new and improved attacker toolbox
2021-12-08 07:00

Much like sappers getting behind enemy lines to attack and destroy critical infrastructure, threat actors know how to avoid tripwires and stay below the threshold of detection while initiating an attack. To counter those efforts, organizations need to gain a better understanding of the new attacker toolbox and employ solutions that take a more holistic view of defense.

Skewed analytics caused by bots damage businesses as much as ad fraud
2021-12-08 06:00

Netacea announced results from a report that shows skewed analytics caused by bots cost businesses just as much as click fraud, despite click fraud's much bigger profile. Ad fraud and skewed analytics caused by bots cost businesses 4% of their revenue.

Twitter bots pose as support staff to steal your cryptocurrency
2021-12-07 09:04

If those phrases are present, these same programs will direct Twitter bots under the scammer's control to automatically reply to the tweets as fake support agents with links to scams that steal cryptocurrency wallets. In tests conducted by BleepingComputer, tweets containing the words 'support,' 'help,' or 'assistance' along with the keywords like 'MetaMask,' 'Phantom,' 'Yoroi,' and 'Trust Wallet' will result in almost instantaneous replies from Twitter bots with fake support forms or accounts.