Finance

Finance

BianLian banking trojan adds screen recorder to face off against Android users

Researchers have discovered a new version of the Android banking trojan BianLian that introduces the ability to record device screens and set of proxies. Named after the Chinese art of “face-changing,” BianLian first appeared as a dropper in October 2018. But it quickly evolved and adopted banking trojan functionality, including overlay attacks that trick users…

Inconvenience stores: Thieves steal $500K from users of 7-Eleven Japan’s new payment app

Convenience chain 7-Eleven Japan has suspended a brand new mobile cashless payment service after an authorized third party accessed approximately 900 user accounts and made fraudulent charges totally 55 million yen, or roughly $500,000 dollars. The service, 7pay, reportedly had only been launched three days earlier, and allows participating customers to automatically charge purchased goods…

TA505 cybergang debuts ‘AndroMut” downloader to deliver FlawedAmmyy RAT globally

The cybercriminal group TA505 appears to have launched two malware campaigns last June, delivering the FlawedAmmyy RAT to victims in multiple countries using the newly created downloader program AndroMut. Both campaigns infected victims using phishing emails with links for downloading Microsoft Word and Excel files, according to a July 2 blog post by Proofpoint If…

WannaLocker ransomware found combined with RAT and banking trojan

Researchers are warning that a new version of WannaLocker – essentially a mobile derivative of WannaCry ransomware – has been enhanced with spyware, remote access trojan and banking trojan capabilities. Cybercriminals have been using the all-in-one malware package in a campaign targeting Brazilian banks and their Android mobile customers, according to a July 1 blog…

facebook

Facebook unveils Libra cryptocurrency

Facebook announced its own cryptocurrency Libra that will be backed and controlled by the Libra Association which also includes founding members Uber, Lyft and Spotify. The platform will allow users to buy and send money without racking up as many fees as traditional financial platforms. Users can buy or cash out the cryptocurrency at local…

ScarCruft ATP campaign leverages ‘rare’ data-harvesting tool for Bluetooth devices

A recent malware campaign targeting investment companies and diplomatic agencies has shed light on some of the newest practices and tools of reputed North Korean APT group ScarCruft. While investigating this campaign, researchers from Kaspersky Lab observed a tool for harvesting Bluetooth device data and were able to analyze the group’s multistage binary infection procedure.…

Report: G7 institutions to simulate cyberattack on financial sector

Twenty-four financial organizations from countries comprising the Group of Seven (G7) nations will reportedly simulate a major cross-border cyberattack on the financial sector next month. The exercise will present a scenario in which malware infects a technical component that is commonly used in the financial sector, according to a Reuters report citing Nathalie Aufauvre, director…

ghostlyskullmobilemalware_826540

Retefe Revisited: Banking trojan reemerges, adopts new set of tools

Researchers have noticed a recent upswing in attacks against banks featuring the Retefe banking trojan, following what was apparently a fairly quiet 2018 for the malware. The trojan is historically known for targeting the banking industry in countries like Austria, Sweden, Switzerland and the UK. Rather than using malicious web injects to execute man-in-the-browser attacks…

Malvertising scheme abuses Yandex.Direct, targets Russian accountants with assorted malware

Cybercriminals are abusing the Yandex.Direct online advertising service in order to serve up malicious ads that target Russian accountants with the goal of infecting them with banking trojans and ransomware. Researchers from ESET have so far linked six malware programs to this campaign, which began in October and continues to this day. During periods of…

Next post in Security News