Quotidien Hebdomadaire Mensuel

Quotidien Shaarli

Tous les liens d'un jour sur une page.

November 3, 2022

Crimson Kingsnake: BEC Group Impersonates…

Recently, we identified a new BEC group leveraging blind third-party impersonation tactics to swindle companies around the world. The group, which we call Crimson Kingsnake, impersonates real attorneys, law firms, and debt recovery services to deceive accounting professionals into quickly paying bogus invoices.

Exploiting Static Site Generators: When Static Is Not Actually Static

Over the last ten years, we have seen the industrialization of the content management space. A decade ago, it felt like every individual and business had a dynamic WordPress blog, loaded up with a hundred plugins to do everything from add widgets to improve performance. Over time, we realised this was a bad idea, as ensuring the security of third-party plugins seemed increasingly impossible.

Black Basta Ransomware | Attacks Deploy Custom EDR Evasion Tools Tied to FIN7 Threat Actor

Black Basta operational TTPs are described here in full detail, revealing previously unknown tools and techniques and a link to FIN7.

Malware on the Google Play store leads to harmful phishing sites

A family of malicious apps from developer Mobile apps Group are listed on Google Play and infected with Android/Trojan.HiddenAds.BTGTHB. In total, four apps are listed, and together they have amassed at least one million downloads.

Older versions of these apps have been detected in the past as different variants of Android/Trojan.HiddenAds. Yet, the developer is still on Google Play dispensing its latest HiddenAds malware.

Malicious App Developer Remains on Google Play

A report shows four Bluetooth-centered apps by the same developer have been downloaded 1 million times combined while containing malicious code.

U.S. banks processed about $1.2 billion in ransomware payments in 2021
  • U.S. banks and financial institutions processed more than $1 billion in potential ransomware-related payments in 2021.
  • It’s a new record and almost triple the amount that was reported the previous year.
  • Over half the ransomware attacks are attributed to suspected Russian cyber hackers, according to a new report.