Security News

Bluebottle Cybercrime Group Preys on Financial Sector in French-Speaking African Nations
2023-01-05 12:34

A cybercrime group dubbed Bluebottle has been linked to a set of targeted attacks against the financial sector in Francophone countries located in Africa from at least July 2022 to September 2022. "The group makes extensive use of living-off-the-land, dual use tools, and commodity malware, with no custom malware deployed in this campaign," Symantec, a division of Broadcom Software, said in a report shared with The Hacker News.

SpyNote Strikes Again: Android Spyware Targeting Financial Institutions
2023-01-05 11:05

Financial institutions are being targeted by a new version of Android malware called SpyNote at least since October 2022. "This has helped other actors [in] developing and distributing the spyware, often also targeting banking institutions."

Raspberry Robin Worm Evolves to Attack Financial and Insurance Sectors in Europe
2023-01-03 10:13

Financial and insurance sectors in Europe have been targeted by the Raspberry Robin worm, as the malware continues to evolve its post-exploitation capabilities while remaining under the radar. "What is unique about the malware is that it is heavily obfuscated and highly complex to statically disassemble," Security Joes said in a new report published Monday.

Hack-for-Hire Group Targets Travel and Financial Entities with New Janicab Malware Variant
2022-12-10 11:46

Travel agencies have emerged as the target of a hack-for-hire group dubbed Evilnum as part of a broader campaign aimed at legal and financial investment institutions in the Middle East and Europe. The attacks targeting law firms throughout 2020 and 2021 involved a revamped variant of a malware called Janicab that leverages a number of public services like YouTube as dead drop resolvers, Kaspersky said in a technical report published this week.

Financial organizations more prone to accidental data leakage
2022-12-02 04:00

Compared to other industries surveyed, financial institutions are much more concerned about users who have legitimate access to their cloud infrastructure. 44 percent of respondents in this sector say their own IT staff poses the biggest risk to data security in the cloud and 47 percent worry about contractors and partners, compared to 30 percent and 36 percent respectively in other verticals surveyed.

OPERA1ER APT Hackers Targeted Dozens of Financial Organizations in Africa
2022-11-03 10:21

A French-speaking threat actor dubbed OPERA1ER has been linked to a series of more than 30 successful cyber attacks aimed at banks, financial services, and telecom companies across Africa, Asia, and Latin America between 2018 and 2022. According to Singapore-headquartered cybersecurity company Group-IB, the attacks have led to thefts totaling $11 million, with actual damages estimated to be as high as $30 million.

Cyberattacks in healthcare sector more likely to carry financial consequences
2022-10-31 04:00

Netwrix announced additional findings for the healthcare sector from its global 2022 Cloud Security Report, revealing that 61% of respondents in the healthcare industry suffered a cyberattack on their cloud infrastructure within the last 12 months, compared to 53% for other verticals. "The healthcare sector is a lucrative target for attackers because the chances of success are higher. The first two years of the pandemic exhausted the industry. With patient health being the main priority for these organizations, IT security resources are often too stretched and are focused on maintaining only the most necessary functions," comments Dirk Schrader, VP of Security Research at Netwrix.

Financial watchdogs want to know what traders are talking about on WhatsApp
2022-10-13 08:30

Authorities in the US and the UK are taking a keen interest in the contents of WhatsApp messages among bank employees and their associates in the financial services industry. The UK's Financial Conduct Authority is set to probe sector workers' use of private messaging services as the watchdog increases scrutiny in line with the US. According to Bloomberg, the FCA has requested information from Citigroup, Deutsche Bank, JPMorgan Chase, and Nomura Holdings, among others, inquiring about the frequency and content of staff exchanges through texting and messaging apps.

How Wi-Fi spy drones snooped on financial firm
2022-10-12 07:22

Modified off-the-shelf drones have been found carrying wireless network-intrusion kit in a very unlikely place. The idea of using consumer-oriented drones for hacking has been explored over the past decade at security conferences like Black Hat 2016, in both the US and in Europe.

Financial organizations fail to act on firmware breaches
2022-09-12 04:30

In this Help Net Security video, Michael Thelander, Director Product Marketing at Eclypsium, discusses how financial organizations are failing to act despite the majority experiencing a firmware-related breach. 92% of CISOs in finance believe adversaries are better equipped at weaponizing firmware than their teams are at securing it, according to Eclypsium and Vanson Bourne.