Mandiant’s X Account Was Hacked Using Brute-Force Attack

January 11, 2024 at 04:01AM Mandiant’s X account was compromised by a brute-force attack, enabling the intruder to spread a cryptocurrency drainer called CLINKSINK. The attack targeted Solana cryptocurrency users and utilized phishing pages to redirect victims to approve fraudulent transactions. This incident reflects a growing trend of financially motivated threat actors targeting cryptocurrency assets … Read more

Mandiant’s X account hacked by crypto Drainer-as-a-Service gang

January 10, 2024 at 05:26PM Mandiant, a cybersecurity firm and Google subsidiary, had its Twitter account hijacked by a Drainer-as-a-Service gang. The attacker redirected over 123,000 followers to a phishing page to steal cryptocurrency, with an estimated minimum of $900,000 in assets stolen. Verified organizations like the U.S. Securities and Exchange Commission have also been … Read more

X marks the spot: Mandiant restores hijacked Twitter account after attempted crypto heist

January 4, 2024 at 03:11PM On Wednesday, miscreants seized control of security firm Mandiant’s Twitter account to attempt cryptocurrency theft. After being renamed as a phony crypto wallet service account, the hijackers lured users to a fraudulent website for free tokens, prompting concerns of financial losses. The incident highlights Twitter’s ongoing security concerns and risks … Read more

In Other News: Ubisoft Hack, NASA Security Guidance, TikTok Requests iPhone Passcode

December 29, 2023 at 08:54AM SecurityWeek weekly roundup provides a concise compilation of cybersecurity stories that may have been overlooked. This week’s stories include a $60 million crypto theft, Android backdoor infection, Microsoft warning of malware distribution, Mint Mobile data breach, and NASA’s space security guidance. Other topics covered are hacking claims, Chrome Safety Check, … Read more

CERT-UA Uncovers New Malware Wave Distributing OCEANMAP, MASEPIE, STEELHOOK

December 29, 2023 at 06:54AM Ukraine’s CERT-UA has warned of a new phishing campaign by the Russia-linked APT28 group targeting government entities through email messages, deploying malware such as OCEANMAP, MASEPIE, and STEELHOOK to harvest sensitive information. The attacks utilize various tools, including the Python-based MASEPIE and the C#-based OCEANMAP, with communications employing encrypted channels. … Read more

Fresh Qakbot Sightings Confirm Recent Takedown Was a Temporary Setback

December 19, 2023 at 06:22PM Qakbot malware has resurfaced, distributed through phishing emails targeting hospitality organizations. Microsoft, Zscaler, and Proofpoint reported sightings of a new 64-bit version using AES encryption. Despite a takedown in August, Qakbot’s operators continue distributing other malware. Lumu observed 1,581 attempted attacks in September, indicating the group’s resilience. The group’s continued … Read more

Qakbot’s backbot: FBI-led takedown keeps crims at bay for just 3 months

December 19, 2023 at 04:33AM Qakbot malware has resurged with a new phishing campaign targeting the hospitality sector. The gang uses malicious PDF attachments disguised as IRS documents to distribute the malware. Despite earlier efforts to take it down, Qakbot has reappeared, demonstrating the challenge of combating cybercrime. Similar to Emotet’s revival, Qakbot’s resurgence poses … Read more

QakBot Malware Resurfaces with New Tactics, Targeting the Hospitality Industry

December 18, 2023 at 05:52AM A new wave of QakBot malware phishing targeting the hospitality industry was discovered by Microsoft. The phishing campaign began on December 11, 2023, distributing a PDF with a URL leading to an MSI file. Cisco Talos had previously noted QakBot affiliates using phishing to distribute ransomware and other malware. The … Read more

Qbot malware returns in campaign targeting hospitality industry

December 17, 2023 at 04:44PM The QakBot malware, previously disrupted by law enforcement, has resurfaced in new phishing campaigns. Microsoft warns of email phishing attacks impersonating IRS employees, distributing QakBot via a malicious PDF file. The malware, initially a banking trojan, has evolved into a delivery service for ransomware attacks and data theft, using various … Read more

Microsoft seizes websites used to sell phony email accounts to Scattered Spider and other crims

December 14, 2023 at 05:02PM Microsoft took down US-based infrastructure and websites used by the cybercrime group, Storm-1152, to sell fraudulent online accounts, earning “millions of dollars” in ill-gotten gains. The gang leaders, based in Vietnam, operated and wrote code for the illicit websites, victimizing Microsoft and other tech companies, and aiding clients in ransomware … Read more