Cyber Crime

Pierluigi Paganini February 10, 2016
Russian Metel group manipulated ruble-dollar exchange rate with malware

A Russian group of cyber criminals known as METEL has hacked the systems at the Kazan-based Energobank and manipulate Ruble-Dollar Exchange Rate infecting them with a malware. A Russian cyber gang has hacked the systems at the Kazan-based Energobank and manipulate Ruble-Dollar Exchange Rate infecting them with a malware. The event occurred exactly one year ago, in […]

Pierluigi Paganini February 09, 2016
Rent the infamous AlienSpy backdoor is now quite easy

Security experts at Kaspersky have spotted in the wild a new variant of AlienSpy RAT Family openly offered with a model of malware-as-a-service. Today we will speak about a case of malware-as-a-service, in the specific case the threat is a remote access trojan, aka RAT, that could be used to gain control over multiple platforms, including […]

Pierluigi Paganini February 09, 2016
Carbanak cybergang is back and it is not alone

Experts at Kaspersky Lab discovered that Carbanak cybergang is back and other groups are adopting similar APT-style techniques to steal money. Security researchers at the 2016 edition of SAS in Tenerife revealed that the infamous Carbanak gang is back, and it is not the unique group that is adopting APT-style techniques to steal money from banks. […]

Pierluigi Paganini February 08, 2016
T9000 backdoor, a sophisticated malware that spies on Skype users

The T9000 backdoor discovered by PaloAlto Networks is able to infect victims’ machines to steal files, take screengrabs, and records Skype conversations. A new threat is targeting Skype users, it is a backdoor trojan dubbed T9000 that is able to infect a victim’s machine to steal files, take screengrabs, and record conversations. The T9000 backdoor was spotted […]

Pierluigi Paganini February 08, 2016
Hackers leaked DHS staff records, 200GB of files are in their hands

A hacker accessed an employee’s email account at the Department of Justice and stole 200GB of files including records of 9,000 DHS staffers and 20,000 FBI employees. Yesterday, the data related a Department of Homeland Security (DHS) staff directory were leaked online, a Twitter account shared the link to an archive containing 9,355 names. The responsible […]

Pierluigi Paganini February 08, 2016
Reuse of login credentials put more than 20M Alibaba accounts at risk

The reuse of login credentials on Taobao exposed more than 20 million accounts on Alibaba’s websites to attacks. According to the state media reports, hackers have targeted over 20 million active accounts on Alibaba Group’s Taobao e-commerce website using Alibaba’s own cloud computing service. The Chinese Giant detected the attack in “the first instance” and responded […]

Pierluigi Paganini February 07, 2016
Dyre crackdown, the biggest effort to date by Russian authorities against cybercrime

Russian authorities raided offices of a Russian film distribution and production company as part of an operation against the Dyre gang. Russian law enforcement and intelligence agencies in November raided offices of a Russian film distribution and production company as part of an operation against one of the world’s most notorious cybercrime ring. The authorities […]

Pierluigi Paganini February 06, 2016
Researchers spotted a new OS X scareware campaign

Experts at the SANS Technology Institute spotted an OS X scareware campaign that leverages fake Adobe Flash Player installers. Johannes Ullrich, security expert at the SANS Technology Institute, spotted an OS X scareware campaign that leverages fake Adobe Flash Player installers to trick users into downloading malicious software. The expert discovered the malicious campaign while analyzing […]

Pierluigi Paganini February 05, 2016
Emergency. Hundreds of compromised WordPress sites serve TeslaCrypt ransomware

Operators running websites based on the WordPress must be aware of a spike in the number of compromised platforms used to deliver the TeslaCrypt ransomware. Administrators running websites based on the popular WordPress CMS must be aware of a spike in hacks that are resulting in the silent delivery of ransomware to the visitors. According to […]

Pierluigi Paganini February 05, 2016
Someone has pwned the Dridex botnet serving the Avira Antivirus

Unknowns have pwned the Dridex botnet and are using it to spread a legitimate copy of the Avira Antivirus software instead the malicious payload. This story is very intriguing, someone has hacked a portion of the dreaded Dridex botnet and replaced malicious links with references to installers for the Avira Antivirus. The Antivirus company denies […]