Skeleton Key Malware, Park 'N Fly Data Breach, Crowti Ransomware and more | TWIC - January 16, 2015

2015-01-17 02:05
<img alt="TWIC_branding" src="http://info.phishlabs.com/hs-fs/hub/326665/file-1326531266-png/TWIC_branding.png" style="width: 225px;" width="225"> <p><em>Each week, the PhishLabs team posts The Week in Cybercrime (TWIC) to recap noteworthy cybercrime articles and reports (open source).</em></p> <ul> <li> <p><a href="http://www.bloomberg.com/news/2015-01-12/biggest-u-s-hack-case-is-tale-of-gamers-interrupted-vacation.html">Behind Giant Credit Card Hack: Smart Young Russians With Bad Job Prospects</a> (Bloomberg)<br> Vladimir Drinkman says he met Dmitriy Smilianets online playing Counter-Strike, a shooter game in which cyber-combatants assume the roles of either terrorists or counter-terrorists: bad guys or good guys.</p> </li> <li> <p><a href="http://www.darkreading.com/skeleton-key-malware-bypasses-active-directory/d/d-id/1318570">'Skeleton Key' Malware Bypasses Active Directory</a> (DarkReading)<br>Malware lets an attacker log in as any user, without needing to know or change the user's password, and doesn't raise any IDS alarms.</p> </li> <li> <p><a href="http://www.securityweek.com/remote-overlay-toolkit-makes-online-banking-fraud-easy">Remote Overlay Toolkit Makes Online Banking Fraud Easy</a> (Security Week)<br>A new toolkit discovered late last year by researchers at IBM Trusteer allows even less skilled cybercriminals to steal online banking credentials and abuse them for fraudulent transactions.</p> </li> <li> <p><a href="http://www.net-security.org/malware_news.php?id=2940">Beware of malware masquerading as Oracle security patches</a> (HelpNetworkSecurity)<br>Oracle is warning users about malware sites actively offering Oracle patches for download. This is not the first time cyber crooks tried to masquerade malware as an Oracle software update, and it probably won't be the last.</p> </li> <li> <p><a href="http://www.bankinfosecurity.com/park-n-fly-confirms-data-breach-a-7789">Park 'N Fly Confirms Data Breach</a> (BankInfoSecurity)<br>Park 'N Fly is notifying an undisclosed number of customers that their payment card information was exposed following a compromise of the company's e-commerce website.</p> </li> <li> <p><a href="http://krebsonsecurity.com/2015/01/toward-better-privacy-data-breach-laws/">Toward Better Privacy, Data Breach Laws</a> (KrebsOnSecurity)<br>President Obama on Monday outlined a proposal that would require companies to inform their customers of a data breach within 30 days of discovering their information has been hacked.</p> </li> <li> <p><a href="http://www.zdnet.com/article/hackers-claim-breach-at-u-s-central-command/">Pro-ISIS hackers claim breach at U.S. Central Command</a> (ZDNet)<br>Hackers named "CyberCaliphate" attack the Twitter account of U.S. Central Command (CENTCOM), and also claim to have released internal military files.</p> </li> <li> <p><a href="http://threatpost.com/new-strain-of-crowti-ransomware-moving-in-i2p-network/110416#sthash.nnK2gXap.dpuf">New Strain of Crowti Ransomware Moving in I2P Network</a> (threatpost)<br>A new strain of the Crowti ransomware, also dubbed Cryptowall 3.0, was spotted by researchers early this week after a quiet period during the holiday season.</p> </li> <li> <p><a href="https://nakedsecurity.sophos.com/2015/01/14/obamacare-phishing-email-leads-to-banking-malware%e2%80%8f/">"Obamacare" phishing email leads to Vawtrak banking malware</a>‏ (NakedSecurity)<br>Looking through the SophosLabs spamtraps recently revealed an interesting malware distribution campaign. A phishing email purporting to be from the Department of Labor is really a link that sends victims to a downloader program that infects your computer with a variant of the Vawtrak banking malware, detected by Sophos products as Mal/Vawtrak-H.</p> </li> <li> <p><a href="http://torrentfreak.com/extratorrent-down-after-huge-ddos-attack-150112/">Extratorrent down after huge DDoS Attack</a> (TF)<br>ExtraTorrent, one of the largest torrent sites on the Internet, remains down following a huge DDoS attack. The site's operators are working hard to mitigate the assault and hope to have the site back online soon.</p> </li> </ul> <img src="http://track.hubspot.com/__ptq.gif?a=326665&amp;k=14&amp;r=http%3A%2F%2Fblog.phishlabs.com%2Fthe-week-in-cybercrime-january-16-2015&amp;bu=http%253A%252F%252Fblog.phishlabs.com&amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important">

