In Other News: Ukraine Hacks Russia, CVE for Water ICS Attacks, New Intel Xeon CPUs 

December 15, 2023 at 09:54AM SecurityWeek’s weekly cybersecurity roundup offers a concise compilation of notable stories, covering topics like Chinese APT hacking, Ukraine’s server destruction, cryptocurrency theft, ransomware gang arrests, vulnerabilities, and software patches. It also highlights industry news such as Dragos CEO joining DataTribe and the launch of 5th Gen Intel Xeon processors with … Read more

Kraft Heinz investigates hack claims, says systems ‘operating normally’

December 14, 2023 at 06:35PM Kraft Heinz confirmed their systems are normal with no evidence of a breach listed by an extortion group. Kraft Heinz, a leading food and beverage company, is being threatened by the Snatch extortion group, but no proof of breach was provided. The company is investigating claims but sees no evidence … Read more

Microsoft seizes websites used to sell phony email accounts to Scattered Spider and other crims

December 14, 2023 at 05:02PM Microsoft took down US-based infrastructure and websites used by the cybercrime group, Storm-1152, to sell fraudulent online accounts, earning “millions of dollars” in ill-gotten gains. The gang leaders, based in Vietnam, operated and wrote code for the illicit websites, victimizing Microsoft and other tech companies, and aiding clients in ransomware … Read more

Microsoft disrupts cybercrime gang behind 750 million fraudulent accounts

December 14, 2023 at 01:34PM Microsoft’s Digital Crimes Unit seized multiple domains used by a Vietnam-based cybercrime group, Storm-1152, which was involved in selling over 750 million fraudulent accounts. The group provided services to bypass various verification challenges and supplied accounts to other cybercriminal groups for use in ransomware and phishing attacks. Microsoft filed a … Read more

Microsoft Disrupts Cybercrime Service That Created 750 Million Fraudulent Accounts

December 14, 2023 at 06:24AM Microsoft announced the dismantling of Storm-1152, a cybercrime-as-a-service network that generated 750 million fraudulent Microsoft accounts for phishing and other criminal activities. The illicit group made millions by selling these accounts and tools to other cybercrime groups, prompting Microsoft to seize their infrastructure and reveal the identities of key operators. … Read more

Surprise! Email from personal. [email protected] is not going to contain good news

December 14, 2023 at 05:03AM The FBI, CISA, and other US government agencies have issued a security advisory about the Karakurt extortion gang, notorious for using harassment and IT exploitation to demand ransoms ranging from $25,000 to $13 million in Bitcoin. The gang uses various tactics and tools to exfiltrate massive amounts of data, with … Read more

Microsoft Takes Legal Action to Crack Down on Storm-1152’s Cybercrime Network

December 14, 2023 at 01:12AM Microsoft obtained a court order to seize infrastructure set up by cybercriminal group Storm-1152, which sold approximately 750 million fraudulent Microsoft accounts and tools to other criminal actors, netting millions of dollars. This cybercrime-as-a-service operation facilitated mass phishing, identity theft, DDoS attacks, ransomware, and fraud. The group was attributed to … Read more

Microsoft seizes domains used to sell fraudulent Outlook accounts

December 13, 2023 at 06:47PM Microsoft’s Digital Crimes Unit seized Storm-1152’s domains, used by a Vietnam-based cybercrime group, involved in selling millions of fraudulent accounts and tools to bypass identity verification. These accounts were used in various cybercrimes, resulting in substantial financial damages. Microsoft also took legal action against individuals linked to this operation, as … Read more

French police arrests Russian suspect linked to Hive ransomware

December 13, 2023 at 03:27PM French authorities arrested a Russian national in Paris for alleged involvement in money laundering related to the Hive ransomware gang. He was linked to receiving millions of dollars from suspicious sources through digital wallets. This follows the dismantling of Hive’s servers by the FBI and Dutch police, preventing significant ransom … Read more

LockBit ransomware now poaching BlackCat, NoEscape affiliates

December 13, 2023 at 01:25PM LockBit ransomware operation is recruiting affiliates and developers from the recently disrupted BlackCat/ALPHV and NoEscape operations. NoEscape’s exit scam has raised concerns of lost ransom payments and decryption keys for victims, while BlackCat/ALPHV suffered a disruption possibly related to law enforcement. LockBitSupp, LockBit’s manager, seeks to recruit affiliates and a … Read more