Security News

Cybercriminals timed attacks to spike during peak uncertainty about the coronavirus
2020-05-05 19:57

Bad actors matched their cyber attack strategy with the increasing uncertainty of the coronavirus epidemic, according to a new analysis from Mimecast. Over the 14 weeks that Mimecast analyzed, detections increased during seven weeks, decreased during five weeks, and showed no change during two weeks.

Microsoft catches cybercriminals adding malware to "John Wick 3," "Contagion" torrents
2020-05-01 19:45

Cybercriminals have taken notice as well, increasingly lacing popular movie torrents with dangerous malware that can damage your device. In a recent thread on Twitter, Microsoft Security Intelligence wrote at length that the team saw malware attached to torrents for popular "John Wick 3" and "Contagion" in Spain, Mexico, and a number of South American countries.

How Cybercriminals are Weathering COVID-19
2020-04-30 18:20

These restrictions have created a burgeoning underground market for reshipping scams, which rely on willing or unwitting residents in the United States and Europe - derisively referred to as "Reshipping mules" - to receive and relay high-dollar stolen goods to crooks living in the embargoed areas. Still, every dark cloud has a silver lining: Intel 471 noted many cybercriminals appear optimistic that the impending global economic recession "Will make it easier to recruit low-level accomplices such as money mules."

Dark web: Cybercriminals sell over 500,000 Zoom accounts
2020-04-14 19:54

A new report from BleepingComputer found that cybercriminals are selling and trading the credentials for more than 500,000 Zoom accounts associated with companies like Chase and Citibank as well as schools like Dartmouth College, the University of Florida, and the University of Vermont. Earlier this month, a report from cybersecurity firm IntSights by cyber threat analyst Charity Wright and chief security officer Etay Maor found that there has been increased chatter across the dark web about ways to take advantage of the increased usage of Zoom globally.

Cybercriminals capitalize on COVID-19 fears, push shady websites, pharmaceuticals
2020-04-10 03:30

NormShield researchers looked for websites using the names of 10 commonly discussed drugs over the last several months. While the number of phishing domains catapulted for chloroquine and azithromycin in particular, domain names containing the eight other drugs increased as well.

Know thy enemy: The evolving behaviors of today’s cybercriminals
2020-04-09 05:30

As these industries evolve and become more digitized, attackers have the opportunity to access more data than ever before. Wipers continue to trend upward as adversaries begin to realize the futility of purely destructive attacks.

Cybercriminals now using malware and adware to exploit virtual meeting apps
2020-04-08 17:46

As more people have been forced to work or stay at home due to the coronavirus , there's been a much greater reliance on virtual meeting software to communicate with co-workers, colleagues, friends, and family. As cybercriminals have been exploiting all aspects of COVID-19 for their own nefarious purposes, so too have they been taking advantage of virtual meeting apps to spread malware.

Cybercriminals, state-sponsored groups ramping up attacks exploiting COVID-19 pandemic
2020-04-08 14:48

Since January, the two longtime cybersecurity experts have looked at how cybercriminals, ransomware groups, and several nation state actors quickly became involved in coronavirus-themed attacks, leveraging fears about the virus to steal money and information from thousands of people. Cybercriminals have also expanded attacks to take advantage of the fact that most countries are under quarantine, forcing millions to now work from home.

Cybercriminals increasingly using SSL certificates to spread malware
2020-04-07 13:00

Recent studies have shown that cybercriminals building phishing sites now use SSL as well, complicating efforts by enterprises to keep their employees safe. The Menlo Security research revealed that while 96.7% of all user-initiated web visits are being served over https, only 57.7% of the URL links in emails turn out to be https, which means that web proxies or firewall will be oblivious to the threats unless enterprises turn on SSL inspection.

BlackBerry: Chinese cybercriminals target high-value Linux servers with weak defenses
2020-04-07 12:00

Linux malware is real and Advanced Persistent Threat groups have been infiltrating critical servers with these tools for at least eight years, according to a new report from BlackBerry. The RATs report describes how five APT groups are working with the Chinese government and the remote access trojans the cybercriminals are using to get and maintain access to Linux servers.