Researchers uncover massive hack for hire operation

in LeoFinance4 years ago

Researchers uncover massive hack for hire operation (Citizen Lab & University of Toronto

  • The report (extensively covered in the FT) stated that researchers from Citizen Lab found 28k web pages set up to steal passwords from hedge funds, government officials, lawyers, advocacy groups & journalists.
  • It is claimed this is the work of a group dubbed “Dark Basin”, which it is claimed carried out the hacking on behalf of clients. Dark Basin has been linked back to India.
  • The IT security company NortonLifeLock (previously Symantec) has reported a similar story, which they dubbed Mercenary.Amanda. They believe this group are responsible for persistent credential spearphishing attacks going back to 2013. Mercenary.Amanda behind wave of phishing attacks

Analysis and Comments

  • Spearphishing attacks are where emails are sent to individuals in the target organisation with the aim of capturing sensitive information such as account credentials or financial information.
  • It is believed that in this case they used emails that mimicked notifications from online services or sent emails that contained material that would have embarrassed the recipient, encouraging them to click unsubscribe
    *** In this case Dark Basin seemed to be targeting environmental & advocacy non profits, including Greenpeace, the Rockefeller Family Fund & the Union of Concerned Scientists. This has raised questions about who might has commissioned these attacks.**
  • The shift to working from home, driven by COVID disruption, has opened up an new market for this type of cyber risk.
  • Most analysts expect this type of attack to grow, giving a material tailwind to the cyber security sector.

image.png

➡️ Publish0x
➡️ UpTrennd
➡️ Minds
➡️ Hive
➡️ Twitter
➡️ Facebook
➡️ Be paid daily to browse with Brave Internet Browser

Proud member of:

image.png

image.png

image.png

Posted Using LeoFinance

Sort:  

Working from home is definitely going to cause a rise in cyber crimes, I received and email yesterday proposing business and asking if I can help to keep the funds in my account. I immediately deleted the email because I could tell that a cyber attack already.

Hello @joetunex,

I think you did the right thing, we are never too prudent.

I added you as a friend on Discord, hit me up when you are connected.

Scary! This is a real threat for those who work from home. Good article.

It is, we need to be careful !
Thanks for the follow ;)