600,000 Payment Cards Stolen From Swarmshop Darknet Market

600,000 Payment Cards Stolen From Swarmshop Darknet Market

Cryptocurrency Fraud , Cybercrime , Fraud Management & Cybercrime Group-IB: Administrator, Seller and Buyer Data Also Stolen Doug Olenick (DougOlenick) • April 8, 2021     Here’s a guide to the national origin of card data that was stolen from the Swarmshop market. (Source: Group-IB) For the second time in two years, the contents of…

Visa Describes New Skimming Attack Tactics

Visa Describes New Skimming Attack Tactics

Account Takeover Fraud , Card Not Present Fraud , Cybercrime Cybercriminals Using Web Shells to Control Retailers’ Servers Doug Olenick (DougOlenick) • April 9, 2021     Visa’s Payment Fraud Disruption team reports that cybercriminals are increasingly using web shells to establish command and control over retailers’ servers during payment card skimming attacks. See Also:…

Fake Netflix App Allows Hackers to Hijack WhatsApp

Fake Netflix App Allows Hackers to Hijack WhatsApp

A newly-discovered Android malware app called FlixOnline promised users access to Netflix content from all around the world on their smartphones before exploiting access to their WhatsApp, according to Check Point Research. Troubling, the app was not solely on third-party app stores – it was, instead, found on the Google Play Store, using Netflix imagery to…

Lazarus Group Targets Freight Logistics Firm

Lazarus Group Targets Freight Logistics Firm

Cyberwarfare / Nation-State Attacks , Fraud Management & Cybercrime , Governance & Risk Management ESET Report Ties ‘Vyveva’ Backdoor to North Korean APT Group Akshaya Asokan (asokan_akshaya) • April 9, 2021     Example of how the “Vyveva” backdoor works (Source: ESET) The Lazarus Group, a North Korean-linked advanced persistent threat group also known as…

Visa Describes New Skimming Attack Tactics

Visa Describes New Skimming Attack Tactics

Account Takeover Fraud , Card Not Present Fraud , Cybercrime Cybercriminals Using Web Shells to Control Retailers’ Servers Doug Olenick (DougOlenick) • April 9, 2021     Visa’s Payment Fraud Disruption team reports that cybercriminals are increasingly using web shells to establish command and control over retailers’ servers during payment card skimming attacks. See Also:…

Gigaset Android phones infected by malware via hacked update server

Gigaset Android phones infected by malware via hacked update server

Owners of Gigaset Android phones have been repeatedly infected with malware since the end of March after threat actors compromised the vendor’s update server in a supply-chain attack. Gigaset is a German manufacturer of telecommunications devices, including a series of smartphones running the Android operating system. Starting around March 27th, users suddenly found their Gigaset…

LinkedIn denies data leak after two-thirds user base is compromised, IT News, ET CIO

LinkedIn denies data leak after two-thirds user base is compromised, IT News, ET CIO

Pune: Personal data of 500 million LinkedIn users, two thirds of its user base, has been scraped and is for sale online, according to a report from Cyber News. The data up for sale on a popular hacker platform includes account IDs, full names, email addresses, workplace information and links to social media accounts of…

Artist will.i.am launches facemask and other tech news

Artist will.i.am launches facemask and other tech news

Jen Copestake looks at some of the best technology news stories of the week including: Google’s annual I/O developer conference returns in May in a virtual form, the company announces Artist will.i.am announces the launch of a new facemask featuring noise-cancelling headphones, Hepa filters and LED lights – the project is a collaboration with Honeywell…