Finance | SC Media

Finance

Phishing emails imitate North American banks to infect recipients with TrickBot

By

An spam-based phishing campaign recently targeted North American banking customers with malicious Excel documents designed to infect victims with a new variant of the information-stealing TrickBot banking trojan, researchers reported earlier this week. The scam dates back to at least Jan. 27 and peaked in volume on Jan. 30, according a new blog post from…

Russians targeted in Redaman banking malware operation

By

An ongoing email phishing campaign designed to spread Redaman banking malware aggressively targeted Russian-speakers, especially those with .ru addresses, over the last four months of 2018. Researchers at Palo Alto Networks’ Unit 42 division reported this week in a company blog post that from September through December, its threat intelligence service detected 3,845 email sessions…

Google Play boots fake apps that spy on devices’ motion sensor data before dropping Anubis malware

By

A fake currency converter and a phony battery utility program are among the latest fraudulent apps to be expunged from Google Play, according to researchers who discovered they were infecting users with a version of the Anubis banking malware family. Both fraudulent apps employ a crafty technique to determine whether it is safe for them…

Threat actors spoof thousands of debit cards at Tampa Bay Credit Union

By

Tampa Bay Credit Union members had their debit card information spoofed after threat actors generated false cards using the financial institution’s bin numbers. Threat actors identified the credit union’s bin numbers, the first six numbers on a debit card, and used software from the dark web to attach the Bin numbers to actual account holder’s…

Ukrainian nationals charged with hacking SEC docs in $4.1 million scam

Ukrainian nationals charged with hacking SEC docs in $4.1 million scam

By

The Department of Justice has charged two Ukrainian nationals for hacking into the Security and Exchange Commission’s (SEC) computer system to steal confidential corporate information and sell it to the highest bidder or to make trades. Artem Radchenko and Oleksandr Ieremenko were charged in the United States Court District of New Jersey with securities fraud…

Phishing kit leverages web fonts to obfuscate source code

By

In an apparent first, researchers last year observed an unusual phishing kit that obfuscates its landing page’s source code with web fonts as a means to avoid detection. Attackers recently used the kit as part of a credential harvesting scheme that targeted a major retail bank, researchers from Proofpoint revealed in a Jan. 3 blog…

‘Sharpshooter’ cyberespionage campaign scopes out defense, critical infrastructure sectors

By

A global phishing campaign called Operation Sharpshooter was discovered using fake job recruitment documents to infect defense, government and critical infrastructure organizations with a malicious backdoor implant, presumably for cyber espionage purposes. The implant, nicknamed Rising Sun, was observed in least 87 impacted organizations over the course of October and November, McAfee Labs reported today…

DanaBot banking trojan adds sly spam feature, distributes GootKit malware

By

The DanaBot banking trojan is branching out into new territories, adding email address harvesting and spam distribution to its bag of tricks, while apparently partnering with the actors behind GootKit, another banking malware program. In a company blog post today, researchers at ESET said they observed DanaBot’s sudden evolution while investigating a September 2018 campaign that…

Venture capital investments

By

November 29, 2018Venafi closed a $100 million round of financing that was led by TCV along with investment from QuestMark Partners and NextEquity Partners. The company said the funding will be used to accelerate its growth and part of the money will be made available to third-party developers in the first tranche of the new…

Bitcoin scammers impersonate Elon Musk, hack Target’s Twitter account

By

Scammers impersonating Elon Musk managed to hack the verified Twitter accounts of Target and several others in a cryptocurrency fraud scheme promising huge Bitcoin giveaways Tuesday morning. Hackers were briefly able to get ahold of the Target Twitter page for about a half hour when they used the big-box retailer’s account to promote “the biggest crypto-giveaway…

Next post in Cryptocurrency