Posts

Showing posts with the label USA

Massive SMS stealer campaign infects Android devices in 113 countries

Image
By Bill Toulas,  Bleeping Computer A malicious campaign targeting Android devices worldwide utilizes thousands of Telegram bots to infect devices with SMS-stealing malware and steal one-time 2FA passwords (OTPs) for over 600 services. Zimperium researchers discovered the operation and have been tracking it since February 2022. They report finding at least 107,000 distinct malware samples associated with the campaign. The cybercriminals are motivated by financial gain, most likely using infected devices as authentication and anonymization relays. Telegram entrapment The SMS stealer is distributed either through malvertising or Telegram bots that automate communications with the victim. In the first case, victims are led to pages mimicking Google Play, reporting inflated download counts to add legitimacy and create a false sense of trust. On Telegram, the bots promise to give the user a pirated application for the Android platform, asking for their phone number before they share the ...

CrowdStrike update crashes Windows systems, causes outages worldwide

Image
By Ionut Ilascu,  Bleeping Computer A faulty component in the latest CrowdStrike Falcon update is crashing Windows systems, impacting various organizations and services across the world, including airports, TV stations, and hospitals. The glitch is affecting Windows workstations and servers, with users reporting massive outages that took offline entire companies and fleets of hundreds of thousands of computers. According to some reports, emergency services in the U.S. and Canada have also been impacted. Worldwide outage By the time of the correction, though, many large organizations across multiple verticals had already been affected. Some reports say that CrowdStrike’s update impacted some 911 emergency service agencies in the state of New York (EMS, police, fire department), Alaska, and Arizona, as well as 911 services in parts of Canada. A 911 telecommunicator in Illinois said that they were “working off of paper until things come back.” There also reports that the health hotlin...

Former IT employee accessed data of over 1 million US patients

Image
By Bill Toulas,  Bleeping Computer Geisinger , a prominent healthcare system in Pennsylvania, has announced a data breach involving a former employee of Nuance , an IT services provider contracted by the organization. Geisinger is a non-profit organization that operates 134 care sites, ten hospitals, and the Geisinger Health Plan, serving a total of 1.2 million people. It employs 26,000 staff, including 1,600 doctors, and is considered one of Pennsylvania’s most important organizations. An announcement published earlier this week explains that in November 2023, Geisinger detected unauthorized access to its patients’ database by a former Nuance employee. Nuance was promptly informed and took action to block the former employee’s access to Geisinger’s systems holding patient records. “On Nov. 29, 2023, Geisinger discovered and immediately notified Nuance that a former Nuance employee had accessed certain Geisinger patient information two days after the employee had been terminated,” ...

Kaiser Permanente: Data breach may impact 13.4 million patients

Image
By Bill Toulas, Bleeping Computer Healthcare service provider Kaiser Permanente disclosed a data security incident that may impact 13.4 million people in the United States. Kaiser Permanente is an integrated managed care consortium and one of the largest nonprofit health plans in the U.S. It operates 40 hospitals and 618 medical facilities in California, Colorado, the District of Columbia, Georgia, Hawaii, Maryland, Oregon, Virginia, and Washington. In a statement, the organization said that information from "approximately 13.4 million current and former members and patients" was leaked to third-party trackers installed on its websites and mobile applications. “Kaiser Permanente has determined that certain online technologies, previously installed on its websites and mobile applications, may have transmitted personal information to third-party vendors Google, Microsoft Bing, and X (Twitter) when members and patients accessed its websites or mobile applications” - Kaiser Perma...

Over 100 US and EU orgs targeted in StrelaStealer malware attacks

Image
By Bill Toulas, Bleeping Computer A new large-scale StrelaStealer malware campaign has impacted over a hundred organizations across the United States and Europe, attempting to steal email account credentials. StrelaStealer was first documented in November 2022 as a new information-stealing malware that steals email account credentials from Outlook and Thunderbird. One notable characteristic of the malware was using a polyglot file infection method to evade detection from security software. At the time, StrelaStealer was seen targeting predominately Spanish-speaking users. However, according to a recent report by Palo Alto Networks' Unit42, this has changed as the malware now targets people from the U.S. and Europe. StrelaStealer is distributed through phishing campaigns that showed a significant uptick in November 2023, some days targeting over 250 organizations in the U.S. The elevated phishing email distribution volumes continued into 2024, with a significant wave of activity bei...

CISA shares critical infrastructure defense tips against Chinese hackers

Image
By Sergiu Gatlan,  Bleeping Computer CISA, the NSA, the FBI, and several other agencies in the U.S. and worldwide warned critical infrastructure leaders to protect their systems against the Chinese Volt Typhoon hacking group. Together with the NSA, the FBI, other U.S. government agencies, and partner Five Eyes cybersecurity agencies, including cybersecurity agencies from Australia, Canada, the United Kingdom, and New Zealand, it also issued defense tips on detecting and defending against Volt Typhoon attacks. Last month, they also warned that Chinese hackers had breached multiple U.S. critical infrastructure organizations and maintained access to at least one of them for at least five years before being discovered. Authorities have observed that the cyber espionage group Volt Typhoon's targets and tactics differ from typical activities, suggesting their goal is to obtain access to Operational Technology (OT) assets within networks, which could be exploited to disrupt critical infra...

Top US cybersecurity agency hacked and forced to take some systems offline

Image
By Sean Lyngaas, CNN A federal agency in charge of cybersecurity discovered it was hacked last month and was forced to take two key computer systems offline, an agency spokesperson and US officials familiar with the incident told CNN. One of the US Cybersecurity and Infrastructure Security Agency’s affected systems runs a program that allows federal, state and local officials to share cyber and physical security assessment tools, according to the US officials briefed on the matter. The other holds information on security assessment of chemical facilities, the sources said. A CISA spokesperson said in a statement that “there is no operational impact at this time” from the incident and that the agency continues to “upgrade and modernize our systems.” “This is a reminder that any organization can be affected by a cyber vulnerability and having an incident response plan in place is a necessary component of resilience,” the spokesperson said, adding that the impact from the hack “was limite...

Rhysida ransomware wants $3.6 million for children’s stolen data

Image
By Bill Toulas,  Bleeping Computer The Rhysida ransomware gang has claimed the cyberattack on Lurie Children's Hospital in Chicago at the start of the month. Lurie is a leading pediatric acute care institution in the U.S. that provides care to over 200,000 children annually. The cyberattack forced the healthcare provider to take its IT systems offline and postpone medical care in some cases. Email, phone, access to MyChart, and on-premises internet were all impacted. Ultrasound and CT scan results were rendered unavailable, patient service prioritization systems were taken down, and doctors were forced to switch to pen and paper for prescriptions. Today, the Rhysida ransomware gang has listed Lurie Children's on its extortion portal on the dark web, claiming to have stolen 600 GB of data from the hospital. Rhysida ransomware now offers to sell the stolen data for 60 BTC ($3,700,000) to a single buyer. The deadline was set to seven days, after which the data will either be sol...

FBI, CISA warn US hospitals of targeted BlackCat ransomware attacks

Image
By Sergiu Gatlan,  Bleeping Computer Today, the FBI, CISA, and the Department of Health and Human Services (HHS) warned U.S. healthcare organizations of targeted ALPHV/Blackcat ransomware attacks. "ALPHV Blackcat affiliates have been observed primarily targeting the healthcare sector," the joint advisory cautions. Today's warning follows an April 2022 FBI flash alert and another advisory issued in December 2023 detailing the BlackCat cybercrime gang's activity since it surfaced in November 2021 as a suspected rebrand of the DarkSide and BlackMatter ransomware groups. The FBI linked BlackCat to over 60 breaches during its first four months of activity (between November 2021 and March 2022) and said the gang has raked in at least $300 million in ransoms from over 1,000 victims until September 2023. "Since mid-December 2023, of the nearly 70 leaked victims, the healthcare sector has been the most commonly victimized," the three federal agencies warned in today...

UnitedHealth confirms Optum hack behind US healthcare billing outage

Image
By Bill Toulas,  Bleeping Computer Healthcare giant UnitedHealth Group confirmed that its subsidiary Optum was forced to shut down IT systems and various services after a cyberattack by “nation-state” hackers on the Change Healthcare platform. United Health Group (UHG) is a health insurance company with a presence across all 50 US states. The organization is the world's largest healthcare company by revenue ($324.2 billion in 2022), employing 440,000 people worldwide. Its subsidiary, Optum Solutions, operates the Change Healthcare platform, which is the largest payment exchange platform between doctors, pharmacies, healthcare providers, and patients in the US healthcare system. Optum suffers massive cyberattack Change Healthcare first started warning customers Wednesday that some of its services had become unavailable, later stating a cybersecurity incident caused it. An 8-K filing submitted by UnitedHealth Group with the SEC yesterday confirmed that a cyberattack by suspected ...

A US-UK agreement is changing how tech companies respond to law enforcement requests

What you should know about the Data Access Agreement. By Colleen Hagerty,  Popular Science An agreement between the United States and United Kingdom to improve cross-border law enforcement data sharing will go into effect later this year, the two nations announced in a joint statement published Thursday.  Called the Data Access Agreement, it will allow investigators from each country to “gain better access to vital data to combat serious crime,” according to the Department of Justice, as they will now be able to directly request data like messages and pictures, for example, from telecommunications providers in the other’s jurisdiction.  The US agency said that this is a first-of-its-kind agreement that could help with time-sensitive investigations, including those related to terrorism and child abuse. These requests will be “compliant with the relevant existing domestic obligations a public authority is bound by.” The agreement was created in 2019 to address the challenge...

Roaming Mantis hits Android and iOS users in malware, phishing attacks

By Bill Toulas,  Bleeping Computer After hitting Germany, Taiwan, South Korea, Japan, the US, and the U.K. the Roaming Mantis operation moved to targeting Android and iOS users in France, likely compromising tens of thousands of devices. Roaming Mantis is believed to be a financially-motivated threat actor that started targeting European users in February. In a recently observed campaign, the threat actor uses SMS communication to lure users into downloading malware on their Android devices. If the potential victim uses iOS, they are redirected to a phishing page for Apple credentials.

Meet the Administrators of the RSOCKS Proxy Botnet

Image
By  Krebs On Security Authorities in the United States, Germany, the Netherlands and the U.K. last week said they dismantled the “RSOCKS” botnet, a collection of millions of hacked devices that were sold as “proxies” to cybercriminals looking for ways to route their malicious traffic through someone else’s computer. While the coordinated action did not name the Russian hackers allegedly behind RSOCKS, KrebsOnSecurity has identified its owner as a 35-year-old Russian man living abroad who also runs the world’s top Russian spamming forum. According to a statement by the U.S. Department of Justice, RSOCKS offered clients access to IP addresses assigned to devices that had been hacked: “A cybercriminal who wanted to utilize the RSOCKS platform could use a web browser to navigate to a web-based ‘storefront’ (i.e., a public web site that allows users to purchase access to the botnet), which allowed the customer to pay to rent access to a pool of proxies for a specified daily, weekly, or ...

Microsoft 365 credentials targeted in new fake voicemail campaign

By Bill Toulas,  Bleeping Computer A new phishing campaign has been targeting U.S. organizations in the military, security software, manufacturing supply chain, healthcare and pharmaceutical sectors to steal Microsoft Office 365 and Outlook credentials. The operation is ongoing and the threat actor behind it uses fake voicemail notifications to lure victims into opening a malicious HTML attachment. Campaign overview According to researchers at cloud security company ZScaler, the recently discovered campaign shares tactics, techniques, and procedures (TTPs) with another operation analyzed in mid-2020. The threat actors leverage email services in Japan to route their messages and spoof the sender's address, making it look like the emails come from an address belonging to the targeted organization. The email has an HTML attachment that uses a music note character in the naming to make it appear as if the file is a sound clip. In reality, the file contains obfuscated JavaScript code th...

U.S., EU Plan Joint Foreign Aid for Cybersecurity to Counter China

Russia’s invasion of Ukraine shows the importance of supporting countries vulnerable to nation-state cyberattacks, officials say By Catherine Stupp, Wall Street Journal The U.S. and the European Union plan to introduce joint funding of secure digital infrastructure in developing countries, according to officials involved in the talks. The effort marks the first time the EU and U.S. will work together to fund and help protect other countries’ critical infrastructure against cyberattacks. By working together on cybersecurity, the EU and U.S. aim to help countries that otherwise might be eager to accept funding from China, an EU official said. Initial projects, likely in Africa or Latin America, could be under way by the end of the year, officials said. Russia’s invasion of Ukraine has underscored the importance of supporting telecommunications networks and other hardware in countries vulnerable to nation-state cyberattacks, they said. The EU official said that Chinese technology can come...

US Federal Agencies Uncover Massive Chinese Hacker Cyber Espionage Spying Campaign

By Nathan Wasson, Hot Hardware Much of the discussion surrounding cyberwarfare has centered around Russia and Ukraine, in recent months. While it may have been pushed into the background, however, China’s aggressive cyber activity continues apace, whether it rises to the level of warfare or not. Only a month ago, we covered news that Chinese state-sponsored hackers had been deploying malware to steal US intellectual property in an operation that went undetected for years. Just a month before that, we wrote about a Chinese state-sponsored hacking group that had been using VLC Media Player to deploy malware in targeted attacks on foreign governments and NGOs. Both of these Chinese-backed cyber operations were discovered by private cybersecurity researchers, but US federal agencies have been monitoring Chinese cyber activity as well. This week, the National Security Agency (NSA), Cybersecurity & Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) published...

Russia says West risks ‘direct military clash’ over cyberattacks

By Reuters Russia warned the West on Thursday that cyber attacks against its infrastructure risked leading to direct military confrontation, and that attempts to challenge Moscow in the cyber sphere would be met with targeted countermeasures. The warning comes after Russia’s housing ministry website appeared to be hacked over the weekend, with an internet search for the site leading to a “Glory to Ukraine” sign in Ukrainian. In a statement, the foreign ministry said that Russia’s critical infrastructure and state institutions were being hit by cyberattacks and pointed to figures in the United States and Ukraine as being responsible. “Rest assured, Russia will not leave aggressive actions unanswered,” it said. “All our steps will be measured, targeted, in accordance with our legislation and international law.” The statement, issued by the ministry’s head of international information security, said Washington was “deliberately lowering the threshold for the combat use” of cyberweaopns. “...

US Government Ordered Travel Companies To Spy On Russian Hacker For Years And Report His Whereabouts Every Week

Image
By Thomas Brewster, Forbes In 2015, the U.S. Secret Service was on the hunt for Aleksei Burkov, an infamous Russian hacker suspected of facilitating the theft of $20 million from stolen credit cards on the Cardplanet website. The methods the agency used to pursue him, revealed for the first time as a result of a Forbes legal challenge, show how the U.S. government was able to strong-arm two data companies into spying on him for two years based on the authority of a 233-year-old law and to issue weekly reports on his whereabouts. The government has never disclosed how many other individuals could be under such prolonged and unconventional surveillance. The two companies, Sabre in the U.S. and Travelport in the U.K., were perfect suppliers to American law enforcement because of the business they’re in. For decades, they’ve been collecting and storing information about international tourists in a so-called global distribution system. GDSs are essentially hubs of information that make trav...

US: Chinese govt hackers breached telcos to snoop on network traffic

Image
By Sergiu Gatlan, Bleeping Computer Several US federal agencies today revealed that Chinese-backed threat actors have targeted and compromised major telecommunications companies and network service providers to steal credentials and harvest data. As the NSA, CISA, and the FBI said in a joint cybersecurity advisory published on Tuesday, Chinese hacking groups have exploited publicly known vulnerabilities to breach anything from unpatched small office/home office (SOHO) routers to medium and even large enterprise networks. Once compromised, the threat actors used the devices as part of their own attack infrastructure as command-and-control servers and proxy systems they could use to breach more networks. "Upon gaining an initial foothold into a telecommunications organization or network service provider, PRC state-sponsored cyber actors have identified critical users and infrastructure including systems critical to maintaining the security of authentication, authorization, and accou...

Military-made cyberweapons could soon become available on the dark web, Interpol warns

By Ryan Browne, CNBC Digital tools used by the military to conduct cyberwarfare could eventually end up in the hands of cybercriminals, a top Interpol official has warned. Jurgen Stock, the international police agency’s secretary general, said he’s concerned state-developed cyberweapons will become available on the darknet — a hidden part of the internet that can’t be accessed through search engines like Google — in a “couple of years.” “That is a major concern in the physical world — weapons that are used on the battlefield and tomorrow will be used by organized crime groups,” Stock said during a CNBC-moderated panel at the World Economic Forum in Davos, Switzerland, Monday. “The same applies for the digital weapons that, maybe today are used by the military, developed by military, and tomorrow will be available for criminals,” he added. Cyberweapons come in many forms, with ransomware — where hackers lock down a company’s computer systems and demand a ransom payment to restore contro...