Home Blog Page 210

3 Hacking Forums Hacked! Database Leaked Online

zero-day vulnerabilities

This might be a case of tasting one’s own medicine. Hackers turned against their own when they leaked databases from hacking forums. Researchers from security firm Cyble discovered database leaks of three hacking forums – Sinful Site, SUXX.TO, and Nulled. According to the researchers, the databases have been exposing hackers’ personal information from the beginning of May 2020. Hacking forums are the places of aggregation for cybercriminals to participate in general discussion with other hackers to share and sell data leaks, hacking tools, malware, and tutorials, etc. Threat actors can easily buy and own malware and ransomware via hacking forums and dark web market networks.

“All these hacking forums are based on general discussion and sharing of related resources. It is a place where users can find lots of great data leaks, hacking and cracking tools, software, tutorials, and much more,” Cyble said in a statement.

The researchers stated that the databases of hacking forums SUXX.TO and Nulled contained detailed information of their users, which appears to be dumped on May 20, 2020. And the database of Sinful Site includes private messages of hackers in the forum, which appear to be dumped on May 15, 2020. While the members behind the database leak are unknown, Cyble stated the websites of the three hacking forums were taken down temporarily.

 Cyberattacks on Hacking Forums

Recently, a database of an infamous darknet forum “WeLeakData.com” was breached, exposing private messages of malicious actors who used the site. Cybercriminals used WeLeakData.com for discussing, trading, and selling databases that are stolen during breaches and combo lists used in credential stuffing attacks. Researchers from Cyble stated that WeLeakData.com site was suddenly brought offline for unknown reasons in January 2020. It was rumored that the operator of this platform got arrested and that the forum database had been stolen or sold to another hacking group. A month after WeLeakData.com was closed, the content of its database, including hackers’ private messages were kept for sale on the dark web.

 

APAC Public Cloud Spending Increasing, but Businesses May Be Vulnerable: BCG Study

public cloud

A new eight-nation APAC study conducted by Boston Consulting Group (BCG) shows that spending on the public cloud and related services is growing, yet organizations aren’t confident about the security of cloud infrastructure and are holding back. The study titled “Businesses in Asia-Pacific Can Find Resilience and Growth in the Cloud,” showed that APAC cloud spending is growing at a compound annual rate of 25%. This is much faster than similar growth across the U.S. and Western Europe and points to the region’s readiness to invest in cloud initiatives that are accelerating the pace of innovation, growth, and customer engagement. The study notes that capturing the full potential of the cloud may help companies successfully navigate through the current and post-COVID-19 environment. Remote working is accelerating cloud adoption, but companies need to evaluate their security posture for remote environments.

The April 2020 BCG study was developed in collaboration with Amazon Web Services (AWS) and covers Australia, India, Indonesia, Malaysia, the Philippines, Singapore, Thailand, and Vietnam. It shows that companies in these countries are dedicating an average of roughly 5% of their IT budgets to cloud expenditures, a figure that is expected to double by 2023. The study finds that growth in the public cloud could have a positive economic impact of more than $450 billion across the region. It highlights the case of Australian Airways, which saved $40 million per year in fuel costs by using cloud-based analytics to improve thousands of flight routes.

Luc Grimond, a Managing Director at BCG, said, “We’re seeing in the current COVID-19 crisis that more companies are shifting workers to virtual environments and employing end-user computing, using the cloud to quickly roll out essential collaboration tools. Cloud investments will have longer-term benefits as well, such as risk reduction, the ability to provide new and better services to business stakeholders, and improved personalization of product and service offerings.”

Cybersecurity Concerns

Despite the growth in cloud spending, several organizations are slow to move to cloud or are holding back due to security concerns.

Security awareness has also created uncertainty. In some countries, organizations are still awaiting the completion of regulatory assessments governing data privacy and security protection. Companies may also be unaware of the security capabilities offered by their cloud providers. As a result of cybersecurity concerns, approximately 45% of respondents said that they do not host specific data on the public cloud.

Rethink cybersecurity for the cloud. Many nascent businesses still rely on conventional security controls to manage their cloud environments, but these do not provide the necessary safeguards. Mapping out rules and requirements ahead of time is crucial. One executive at a Singaporean financial institution said, “People are biased toward hardware security because it is tangible. We need to assure people that even if the cloud-based hardware is not under their control, it is more secure than the same hardware on premise.”

Remote working is accelerating cloud adoption

With more employees working remotely, companies have moved aggressively to establish virtual work environments. The pressure to move quickly, however, means many businesses are deploying tools that lack adequate data management protection or that are not adapted to existing security processes. As a result, businesses may be exposed to massive security vulnerabilities. Since the COVID-19 pandemic began, for example, the number of cyberattacks on companies globally has risen exponentially as malicious actors introduced new attack vectors, such as the “Co-VID-19” phishing scam. Companies need to review their existing data protection model and security controls to enable fast adoption of cloud-based systems. Accelerating the shift to the cloud would allow businesses to provide remote environments that maintain appropriate data security.

Many advanced cyber solutions exist to help organizations boost their security posture. For example, an Australian bank deployed a fully managed intelligent threat detection service that continuously monitors account activity for malicious or unauthorized behavior to help protect cloud workloads and safeguard customer data.

Many cloud providers also embed sophisticated security protections, such as automated security controls and access provisioning, into their offerings. A financial underwriting company in India found that the cloud security offered by its public-cloud operator included several audit-friendly features that could help the company meet a number of payment, security, and technical compliance standards.

 

Your Road to CMMC can Begin by Putting the Right MSP Partner Behind the Wheel

managed services provider (msp)

CMMC stands for “Cybersecurity Maturity Model Certification.” But what it really means for your company, if you are one of the estimated 350,0000 contractors, manufacturers, and suppliers in the U.S. Department of Defense (DoD) supply chain, is a huge volume of preparatory work.

By Ryan Heidorn, Co-Founder and Managing Partner at Steel Root

The DoD released CMMC version 1.0 on January 31, 2020 in response to wide-scale compromise and exfiltration of defense information stored on contractor information systems. The security requirements in CMMC should sound familiar to companies in the defense industrial base – the requirement to protect the confidentiality of controlled unclassified information (CUI) has been in DoD contracts since 2017.

CMMC has five maturity levels which include (and add to) the 110 security requirements in NIST SP 800-171 already required under DFARS 252.204-7012. This is not a box-checking exercise: CMMC certification requires a third-party audit that measures the maturity of a company’s cybersecurity capabilities. Starting in Fall 2020, the DoD will begin a phased roll-out that will require companies to achieve CMMC certification in order to win new contracts.

A Huge Project for Small Businesses

How does a DoD contractor begin the process of assessing and implementing the practices and plans required to satisfy CMMC requirements? Large prime contractors are likely to have mature cybersecurity practices and the resources to prepare for CMMC without needing outside assistance.

But, according to the RAND Corporation’s 2020 report on Defense Industrial Base (DIB) cybersecurity, “it is estimated that 99% of the DIB is small business.” RAND defines small as less than $100 million in revenue with an average of just 11 FTE employees. Many of these businesses rely on Managed Service Providers (MSPs) to provide IT and cybersecurity services.

The RAND Report continues to say that “unclassified networks of small defense industrial base firms are at higher risk” than their larger peers. Specifically, these small DIB firms are more likely to be deficient in several key areas, including “user authentication, network defenses, vulnerability scanning, software patching, and security information and event management (SIEM), or cyberattack response.”

How should these companies, who may not be equipped to address their cybersecurity risks and requirements, prepare for CMMC? In a 2019 survey, the SANS Institute found that one-third of small business respondents are already outsourcing cybersecurity. For many companies in the DIB, working with a third-party services provider like an MSP is likely the most cost- and time-effective way to establish and manage cybersecurity capabilities.

With that as a backdrop, below are five questions to ask when selecting an MSP for CMMC:

  1. Is the MSP prepared to meet CMMC requirements themselves?

Here’s a great starter question in your quest for a qualified MSP partner: Can the MSP achieve the CMMC certification level required to protect the networks and systems they manage for their DIB customers?

According to Wayne Boline, Board Director at the CMMC Accreditation Body, “Follow the data. The CMMC requirements will follow the flow of CUI – if you’re a small company that wins a contract requiring any level of CMMC certification and you use an MSP that hosts, processes, or can access CUI on your systems, the MSP will absolutely have to meet CMMC requirements to protect this data.”

Furthermore, will the MSP accept a DFARS 252.204-7012 flowdown? If the MSP is willing to accept a contractual obligation to the same safeguarding and reporting requirements for protecting CUI as the defense contractors they support, it’s a good indicator of the MSP’s readiness to support customer requirements under CMMC as well.

Another reason to expect the highest level of cybersecurity from your MSP partner: MSPs themselves are increasingly becoming a target of ransomware operations and other cybercrime activities. According to the Perch 2020 MSP Threat Report, “Last year [2019] saw threat actor groups shifting from enterprises to focus on Managed Service Providers…the world’s most sophisticated criminal groups are focusing their tradecraft and custom malware directly on MSPs.”

  1. Does the MSP have the necessary experience and capabilities?

Ask how many of the MSP’s other customers are subject to DFARS, ITAR, or similar requirements today – and it’s always a good idea to request and check references. Determine whether the MSP has the consulting experience and compliance expertise required to lead your CMMC readiness efforts, or if they are simply looking to sell you a “stack” of software/services. If the MSP is not equipped to guide your full CMMC implementation (and, today, few are), who are the other partners they would leverage to help you prepare for audit and certification?

  1. Where will the MSP be when it’s time for the audit and certification?

How confident is the MSP in the cybersecurity practices and processes they will implement and manage on your behalf? Be sure to work with an MSP that will stand by their work, and stand by you, providing audit support when it’s time to get certified.

  1. Does the MSP employ U.S. Persons?

For companies holding ITAR and EAR data, export control regulations require that the anyone with access to such data be a U.S. Person. This could include the MSP’s employees, contractors, and cloud service providers. If the MSP employs non-U.S. Persons, find out how they are managing access to your network to prevent export control violations.

  1. Do systems used to access and manage a customer’s environment conform to DFARS and CMMC requirements?

Ask plenty of technical questions about the MSP’s own systems and practices – particularly as to whether they conform to DFARS requirements. For example, if the MSP uses a cloud-hosted or SaaS products to manage your network, they should meet the FedRAMP Moderate baseline.

We’ll provide other technical questions you can use to vet an MSP’s cybersecurity maturity and CMMC readiness in a future article. But while we wait for further guidance from the DoD and the CMMC Accreditation Body, these five questions are a great place for a DoD contractor in need of assistance to confidently begin the search for a partner who can guide their journey to CMMC certification.

About the Author

Ryan Heidorn is a Co-Founder and Managing Partner at Steel Root, a cybersecurity services firm that specializes in compliance. Ryan teaches cybersecurity at Endicott College and serves on the Board of the National Defense Industrial Association (NDIA) New England chapter.

 

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

Hackers post Sensitive Data of Wishbone Users on Darknet

From Data Breach to Darknet

Researchers from security firm Cyble discovered a hacker group selling Wishbone.io database on darknet forums. The leaked database contained over 40 million records of Wishbone users–a social platform that allows users to compare social content via voting poll.

According to the researchers the hacker group listed the database for free download on several dark web forums. The exposed database contains users’ personal data including, email addresses, names, usernames, phone numbers, geographic locations, genders, social media profiles, hashed MD5 passwords, Facebook and Twitter access tokens, gender, date of birth, and profile images, etc. The researchers also stressed that the exposed data could be used for several kinds of malicious activities including launching phishing campaigns, identity thefts, account takeovers, and credential stuffing attacks.

Multiple Hackers Involvement

BleepingComputer reported that it was aware of hackers selling the Wishbone database through private deals in various darknet forums. It stated that a different seller advertised the sale of the Wishbone database on a hacker forum at $8,000. It was found that the infamous hacker group “Shiny Hunters” leaked the entire database and kept for free on the same hacker forum. Experts have suggested Wishbone users to change their passwords and be vigilant of their accounts.

Experts Speak

Mark Bower, senior vice president at data security specialists comforte AG, said, “It looks like security and privacy have been an afterthought, not a matter of culture and software development process. If the passwords are hashed with MD5, then the users affected should be immediately making sure their ID’s and passwords aren’t used elsewhere with the same password. MD5 is a goner as far as security is concerned but used by mistaken developers unfamiliar with its security risks, or using older code libraries using MD5. Hashed MD5 passwords aren’t difficult to brute force. The bigger issue here is the personal data though – so now attackers have a bunch more data for social engineering.”

Shiny Hunters Flood the Darknet with Leaked Databases

Shiny Hunters have been responsible for numerous data breaches including the breach of 73.2 million user records from over 11 companies. The hackers are also behind the Tokopedia data breach, in which 91 million user records were compromised and kept on sale on the hacking forums for $5,000. Later, the group breached India-based online learning platform Unacademy, which exposed details of 22 million users and kept the records for sale on the darknet forums for $2,000.

 

Indian Cybersecurity Services Industry to Grow to $13.6 Bn by 2025: DSCI

SideCopy Malware Campaign

Data Security Council of India (DSCI), today released the “India Cybersecurity Services Landscape – A Global Hub in the Making” report. It was launched by Ajay Sawhney, Secretary, Ministry of Electronics & Information Technology (MeitY) in the presence of Rajendra S Pawar, Chairman, DSCI and Debjani Ghosh, President, NASSCOM.

The report said the Indian Cybersecurity Services Industry is expected to grow from $4.3 billion in FY 2019 to $7.6 billion in 2022. The industry will register an overall CAGR of 21% by 2025 and grow to $13.6 billion. The report has been commissioned through an extensive primary and secondary research of cybersecurity services companies in India and provides Services Market projections from FY 2019 to 2025, putting the spotlight on capabilities, talent, innovation and business strategies.

This growth has been fuelled by the COVID-19 pandemic, with cybersecurity gaining an even higher attention from the Boards and Governments. The global cybersecurity services market is expected to reach $89 billion by 2022, with an overall CAGR of 10%. The report cited Managed Security Services (MSS) and System Integration as the most attractive service lines. Identity and Access Management, Big Data Analytics and Cloud Security are expected to garner high demand.

Cyber Security holds the key as 95% of the IT industry workforce had to work from home during this unprecedented time. NASSCOM and DSCI have been working relentlessly putting ahead the issues of the IT Industry to the government and forging a vital partnership to mitigate the COVID impact and ensure business continuity.

Ajay Sawhney, Secretary, Ministry of Electronics & IT

The report aims to put spotlight on offerings, current and future market perspectives of Indian cybersecurity service companies and global companies with significant cybersecurity operations conducted from India.

Key trends and findings 

  • Enterprise spending on cloud security solutions is predicted to increase from
  • $636 million in 2020 to $1.63 billion in 2023.
  • There has been a 667% increase in spear-fishing e-mail attacks related to COVID-19, since the end of February 2020.
  • MSS is the most dominant and fastest growing service line.
  • Cybersecurity services companies in India are transforming from traditional SOC model to innovative cyber fusion centres and focusing on in-house talent for innovation.
  • The Indian industry is moving towards holistic offerings to support all aspects of cybersecurity. Technological Innovations are creating new service lines.
  • The industry is moving from sporadic usage of cybersecurity solutions to a continuous model, which in turn is creating need for cybersecurity services
  • Security services delivery models are continuously evolving over time, moving towards outcome and value creation based models.
  • Indian cybersecurity services companies are expanding their global presence because of rising demand for security from within and outside India, coupled with our unique value proposition.

Products and Services ecosystem are the twin pillars of our Cyber Security Industry. The Indian Cybersecurity Services Industry is growing twice as fast as the global market. All challenges come with opportunities, so while COVID is a challenge, it is also a huge opportunity for accelerating the already existing high-level growth in Cyber Security.

— Rajendra S Pawar, Chairman DSCI & Chairman & Co-Founder, NIIT Group

Data Security Council of India (DSCI) is a premier industry body on data protection in India, setup by NASSCOM, committed to making the cyberspace safe, secure and trusted by establishing best practices, standards and initiatives in cyber security and privacy. DSCI brings together governments and their agencies, industry sectors including IT-BPM, BFSI, Telecom, industry associations, data protection authorities and think tanks for public advocacy, thought leadership, capacity building and outreach initiatives.

Rama Vedashree, CEO, DSCI, said, “The Indian Services Industry is playing a seminal role in securing enterprises worldwide from the ever-increasing cyber threats amid the COVID-19 crisis. The cybersecurity services companies are stepping up their competencies across the three facets of People, Process and Technology and this is making them a trusted partner of choice for global enterprises in their digitization journey.”

Download the full report here.

Unprotected Server Exposes Facebook Scraped Data of 12 Mn Users in Vietnam

Unprotected Server Exposes Facebook Scraped Data of 12 Mn Users in Vietnam

Security researchers at Safety Detectives discovered an open Elasticsearch server containing scraped data related to 12 million Facebook users in Vietnam, which raised concerns over the company’s security measures. The leaked data is as much as 3GB.

According to researchers, the exposed personal information included full name, email address, Facebook username and ID, hometown and current location, birth dates, GPS coordinates, profile scores, family relations with other Facebook users, etc. The leaked server has been taken down after researchers reported the breach.

“The data that our research found is on top of what was already found and adds another 12 million records to the list. Many, but not all, of the entries included full details of personally identifying information (PII), stemming from multiple sources – Facebook included. We still do not know who is ultimately responsible for this scrape and how they were able to perform such an extensive and invasive action,” the researchers said in a statement.

Scraped Data

Data scraping is a process of extracting users’ personal data from websites. It is a common practice for third-party vendors, web developers, business intelligence analysts, and authentic businesses to scrape users’ data for market research purposes. Social media companies like Facebook allows users to access third-party websites by using their existing Facebook login information. However, this process can also allow unauthorized users/threat actors to perform malicious activities including identity theft and financial fraud.

Facebook vs Vietnam

The latest data breach in Vietnam follows the history of Facebook’s data privacy issues with Vietnam. In December 2019, an unprotected public database containing over 267 million Facebook user IDs, names, and contact details were left online without password protection. According to researcher Bob Diachenko, the incident occurred due to illegal scraping operation or Facebook API abuse by cybercriminals in Vietnam. The exposed data was also posted on a hacker forum for download. Earlier, in a similar leaky server incident in 2018, Facebook leaked millions of users’ personal data online. The database contained more than 419 million records of Facebook users across the globe, including more than 50 million records of Vietnamese users.

The government of Vietnam criticized Facebook for violating the country’s cybersecurity laws. It claimed that Facebook allowed users to post anti-government comments on its platform and failed to maintain the norms on managing content, online advertising, and tax liability.

In a similar incident, cybersecurity firm Cyble found hackers selling over 267 million Facebook records for £500 (US$623) on dark websites and hacker forums. Cyble claimed that the records contain information that could allow attackers to perform spear phishing or SMS attacks to steal credentials.

 

Cybercriminals Target Israeli Websites Ahead of the “Quds Day”

Candiru DevilsTongue

Israel reported a cyberattack, which defaced websites of the country’s major organizations, political groups, and industrial ranks. The hack took place on Thursday morning (21 May) through uPress, a website hosting provider. Soon after, uPress released a statement on its official Facebook page stating that the root cause of the cyberattack was a WordPress vulnerability exploited by cybercriminals. It is now working with the National Cyber Security Authority (NCSA) of Israel to reinstate all the original content to the last known point before the cyberattack took place.

Attack ahead of “Quds Day”

Quds Day or Jerusalem Day (Quds in Arabic means Jerusalem) is an annual event held on the last Friday of Ramadan by the Islamic Republic of Iran since 1979, in support of Palestinians and to oppose Zionism and Israel.

Amid the COVID-19 social distancing scenario, there are very limited mass gatherings legalized by the Iranian government for the “Quds Day”. Thus, it seems likely that threat actors took advantage of cyberspace to launch attacks without physical combat. uPress claimed that the hackers were Iranian, however, it provided no further details.

The attack also came within a couple of weeks of a cyberattack that aimed at disrupting operations at Iran’s Strait of Hormuz Port (Shahid Rajaee Port, near the city of Bandar Abbas). In a press release to the Fars News Agency, Mohammad Rastad, Managing Director of the Ports and Maritime Organization (PMO), mentioned the hand of a foreign entity aimed at disrupting the critical operations and trade in the region. Thus, experts also fear that this could be a retaliatory cyberattack from Iran towards Israel.

Experts Speak

The video posted on the defaced website warned about the destruction of Israel in the coming days and a mention of a malicious threat group “Hackers of Saviors”. This prompted one of the experts to link the cyberattack ties to Turkey, North African countries, and the Gaza Strip. It gave no clear indication of Iran’s involvement though. Later in the day, however, Channel 12 News said it did not appear to have been initiated by Iran but may have involved Iranian threat actors.

85% Organizations Anticipate Remote Working Will Threaten Business Operations: Study

Remote Work

A new study from HiveIO revealed the impact of COVID-19 on corporate data security. It highlighted the effect of the new virtual economy on security professionals and organizations across a wide variety of industry verticals. Nearly 85% of organizations anticipate a larger remote workforce will threaten operations because of new risks.

“The IT departments are working at a deficit in their ability to support and maintain business continuity while optimizing IT support,” the report said.

The study stated that several organizations are unable to introduce new security solutions designed to improve the efficiency of work-from-home employees. Around 70% of respondents admitted that they have suffered increased costs due to the ongoing pandemic. Nearly 25% of respondents reported shrinking staff support and another 18% fear additional staff reductions.

It also found that before the pandemic, 70% of respondents had only 10% of employees working remotely, however, at present 100% of employees are working at-home, resulting in IT teams supporting 90% more remote workers. Around 70% of organizations that were surveyed have not deployed new technologies to monitor, manage, and support remote employees.

“This pandemic left organizations little opportunity to initiate new technology projects, which traditionally require multiple months to deploy. That lack of manpower, budget, and time, shrinking IT teams cannot provide physical on-site or data center support,” said Yama Habibzai, COO at HiveIO.

Security Risks with Larger Remote Workforce

The stress on IT staff escalated due to the sudden switch to a remote workforce, which also invited new risks, including:

  • Digital communications issues (54%)
  • Employee productivity loss due to family distractions and/or a new approach to work (49%)
  • Security risks involving cybersecurity – ransomware, data breach concerns, compliance issues, etc. (46%)
  • General security issues protecting intellectual properties (31%)
  • Reduced business due to travel restrictions (23%)
  • Increase in business costs to support remote staff (22%)

Recently, a similar study revealed that remote work increases the risks of cyberthreats like never before. According to the research, businesses in financial, healthcare, federal, and state agencies that deal with sensitive data might get severely impacted due to remote working conditions.

Guidelines for At-Home Employees to Thwart Cyber Risks:

  • Be wary of suspicious emails, downloads, USB drives or other things that could introduce malicious software onto your computer and into the network. These could include spoofing and phishing attacks from hackers pretending to be IT personnel asking for your credentials
  • Promptly install patches and updates, including to your anti-virus software, to all devices on your home network
  • Go into your Wi-Fi router’s management software to ensure it is running the latest firmware, which can update security flaws
  • Connect to corporate networks using a secure means (e.g., a virtual private network), and store data on available encrypted network drives to avoid loss in the event of a computer virus or other malfunction

It is essential for work-from-home employees to comply with their company security standards to maintain the required cyber hygiene.

 

New Android Malware “WolfRAT” Targets WhatsApp, Facebook Messenger and Other Android Apps

BotenaGo, malware over encrypted connections

Security pros at Cisco Talos discovered a new malware targeting messaging apps like WhatsApp, Line, and Facebook Messenger on Android devices. The malware, codenamed “WolfRAT”, was recently discovered in espionage campaigns affecting users in Thailand.

The researchers stated that WolfRAT malware is operated by Wolf Research crew, a Germany-based spyware organization that sells espionage-based malware to governments. It also found that WolfRAT is a modified version of the “DenDroid” malware family. According to Cisco Talos, DenDroid is an Android malware discovered in 2014, containing espionage-based commands for stealing photos, videos, and audio files.

“The chat details, WhatsApp records, messengers and SMSs of the world carry some sensitive information and people choose to forget these when communications occur on their phone. We see WolfRAT specifically targeting Line, a highly popular encrypted chat app in Asia,  which suggests that even a careful user with some awareness around end-to-end encryption chats would still be at the mercy of WolfRAT and it’s prying eyes,” researchers said in a statement.

The Infection Vector

According to researchers, the infection vector of WolfRAT malware is via phishing or smishing links sent to users’ devices. It is found that the command-and-control (C2) server domain is hosted in Thailand and contains references to Thai food, aimed at tricking users to click on those links. Once downloaded, WolfRAT operates in stealth mode by using legitimate apps icons and package names. The malware uses a package named as “com.google.services” to pretend to be a Google Play application, the researchers said.

“The name appears generic enough to make a non-tech savvy user think it is related to Google and is a required part of the Android Operating System. If the user presses the application icon, they will only see generic Google application information injected by the malware authors. This is aimed at ensuring the application is not uninstalled by the victim,” the researchers added.

Malware Attacks on Android Devices

In a similar discovery, security researchers from Kaspersky Lab found threat actors exploiting the Google Play Store for years to distribute advanced Android malware to steal a wide range of sensitive data from users. According to the researchers, a malicious campaign named “PhantomLance” has been targeting Android devices with malware and spyware payloads embedded in applications delivered via multiple platforms including Google’s Play Store and other Android app stores like APKpure and APKCombo.

 

 

Ukraine Police Busts “Megabreach” Cybercriminal, Sanix

Ukraine

The Security Service of Ukraine (SBU) identified and detained a cybercriminal known by the name of Sanix, who is reportedly the face behind the “Megabreach,” which took place early last year. This operation was carried out jointly with the cyber police and the National Police investigators of Ukraine under the procedural guidance of the Prosecutor’s Office. The authorities additionally found two terabytes worth stolen data during the raid.

The “Megabreach” Cybercriminal

In early 2019, Sanix announced the sale of a database consisting of nearly 773  million email addresses and 21,000 unique passwords. This was big news at the time as the data set, which he put on sale, was probably the largest stolen data set in recent history. However, a popular cybersecurity researcher and writer Brian Krebs on his blog said that although the stolen data set seemed to be large,  as it was possibly collected from previously executed data breaches.

SBU said that they recovered an 87 GB database, which was only a small fraction of the actual misappropriated data. Sanix at least had seven other such databases consisting of stolen and broken passwords, which amounted to almost a terabyte and included personal and financial data of citizens from the European Union and North America. SBU also confirmed that Sanix sold “databases with logins and passwords to e-mail boxes, PIN numbers to bank cards, BTC e-wallets, PayPal accounts, as well as information about computers broken for further use in botnets and DDoS attacks.”

The evidence of his illegal activities was also collected during the raid as the authorities confiscated his computers and mobile phones used in the cybercriminal acts. Additionally, hard cash worth UAH 190,000 (approximately US$7,308) and more than $3,000 earned from these acts were also recovered. Owing to this evidence, under Part 2 Art.361, Part 1 Art.361-2 of the Criminal Code of Ukraine, Sanix will now undergo a trial for unauthorized interference with computers and unauthorized sale or dissemination of restricted computer-stored information.