The U.S. Department of State has announced a $10 million reward for “information leading to the identification or location of any person who, while acting at the direction or under the control of a foreign government, participates in malicious cyber activities against U.S. critical infrastructure in violation of the Computer Fraud and Abuse Act (CFAA).”
malware
CISA/FBI Advisory Warns of Destructive Malware Used Against Ukraine
The Cybersecurity and Infrastructure Security Agency (CISA) and the FBI issued a joint advisory this week alerting organizations of destructive malware that is being used to target organizations in Ukraine, with the ongoing warnings of increased cyber-attacks against U.S. organizations.
The malware, WhisperGate and HermeticWiper, is used to “destroy computer systems and render them inoperable.”…
Apple + Microsoft Release Patches for Identified Vulnerabilities
This week, both Apple and Microsoft issued patches to fix serious zero-day vulnerabilities that should be applied as soon as possible. That means that if you have an iPhone or iPad, you may want to plug your phone or iPad in and apply the newest iOS 15.0.2, which is what I just did as I…
New Russian Based Ransomware Group Targeting Large Companies and Hospitals
Threat intelligence firm Mandiant released findings about a new Russian based hacking group dubbed FIN12, which is targeting the health care industry and companies with revenue over $300 million. Mandiant said that FIN12 is “very aggressive and brazen in who they target.”
According to Mandiant, FIN12 uses different hacking techniques and tools to infiltrate targets,…
Privacy Tip #294 – Online Gamers Beware: Crackonosh Malware Hidden in Free Games
Security researchers from Avast have discovered that “Crackonosh” malware has been installed on free versions of some popular online games for the purpose of cryptomining. It is believed to be sourced from a Czech author.
Avast reports that the malware may be included in free (often pirated) versions of well-known games such as NBA2K19, Grand…
Las Vegas’ University Medical Center Hit with REvil Ransomware
University Medical Center in Las Vegas announced that it recently became the victim of a ransomware attack by REvil, a well-known threat actor that has attacked many hospitals and health systems with the Sodinokibi malware variant.
It is being reported that during the attack, REvil was able to exfiltrate personal information that it then published…
Phishing, Vishing, and Smishing—Your Employees Need to Know the Newest Schemes
New dictionary words have been formed to describe online scams. Phishing, one that everyone knows by now, is when a scammer uses a pretext in an email to get someone to click on a link or attachment in the email to deploy malicious malware and ransomware.
Social engineering is when criminals conduct online search of…
Coveware Q1 2021 Report Shows Increase in Ransomware Payments Over Q4 2020
Coveware issued its Q1 2021 Ransomware Report on April 26, 2021, which concludes that “[D]ata exfiltration extortion continues to be prevalent and we have reached an inflection point where the vast majority of ransomware attacks now include the theft of corporate data.”
The Report states that the average ransom payment increased 43 percent from $154,108…
Cisco/Talos Researchers Find Attackers Using Slack and Discord to Distribute Malware
Another example of the resiliency and creativity of cyber-attackers is outlined in a new blog by Cisco/Talos researchers, which outlines how, over the past year, and in particular as a result of the migration from work at the office to work from home during the pandemic, cyber-attackers are using collaboration platforms like Slack and Discord…
Vehicle Inspections in Multiple States Disrupted by Malware
Applus Technologies, Inc., a vendor of multiple state Departments of Motor Vehicles that assists states with vehicle inspections, recently announced that its systems have been affected by malware, disrupting motor vehicle inspections in Connecticut, Georgia, Idaho, Illinois, Massachusetts, New York, Texas, and Utah. As a result of the outage, vehicle inspections have not been able…