Revolution Crimeware, Hosting Companies Hacked, Dyre Targets Enterprises and more | TWIC - April 3, 2015

2015-04-04 01:40
<em>Each week, the PhishLabs team posts The Week in Cybercrime (TWIC) to recap noteworthy cybercrime articles and reports (open source).</em>

<ul>
<li>
<p><a href="http://krebsonsecurity.com/2015/04/revolution-crimeware-emv-replay-attacks/?utm_campaign=TWIC&amp;utm_content=13930965&amp;utm_medium=social&amp;utm_source=twitter">'Revolution' Crimeware &amp; EMV Replay Attacks</a> (KrebsonSecurity)<br> In October 2014, KrebsOnSecurity examined a novel "replay" attack that sought to exploit implementation weaknesses at U.S. financial institutions that were in the process of transitioning to more secure chip-based credit and debit cards.</p>
</li>
<li>
<p><a href="http://securityintelligence.com/dyre-wolf/#.VR65kfnF_ki">Spear Phishing, Malware and DDoS! Oh My!</a> (IBM)<br> From an initial infection via the Upatre malware through a spear-phishing email to a distributed denial-of-service (DDoS) attack, the criminals carrying out this latest string of attacks are using numerous sophisticated techniques.</p> </li> <li> <p><a href="http://www.darkreading.com/mobile/less-than-1-percent-of-androids-have-potentially-harmful-app-installed-/d/d-id/1319751">Google: Less Than 1% Of Androids Have Potentially Harmful App Installed</a> (Dark Reading)<br>Google's Android security report shows that devices that only install apps from the Google Play store have fewer infections.</p> </li> <li> <p><a href="http://thehackernews.com/2015/03/website-hosting-services.html">5 Biggest Hosting Companies Hacked by Syrian Electronic Army</a> (The Hacker News)<br>Once again, Syrian Electronic Army (SEA) has gain media attention by compromising a number of popular web hosting brands of one of the leading web-hosting companies Endurance International Group INC that manages over 60 different hosting brands.</p> </li> <li> <p><a href="https://nakedsecurity.sophos.com/2015/04/02/obama-signs-executive-order-to-sanction-foreign-hackers/">Obama signs executive order to sanction foreign hackers</a> (nakedsecurity)<br>President Obama just used perhaps the most effective tool in his arsenal to strike against the threat of foreign cyberattacks - that's right, his pen.</p> </li> <li> <p><a href="http://www.theregister.co.uk/2015/04/01/uni_admins_hand_reward_to_data_burglars/">Hacked uni's admins hand ID theft prevention reward to data burglars</a> (The Register)<br>An Illinois university's sysadmins have seemingly handed data burglars a year-long subscription to LifeLock, an identity alert and credit monitoring system, following a data breach at the US institution which left thousands vulnerable to identity theft.</p> </li> <li> <p><a href="http://www.csoonline.com/article/2905232/metrics-budgets/why-you-should-be-spending-more-on-security.html">Why you should be spending more on security</a> (CSO)<br>Many CIOs endanger their companies simply by not spending enough on security. That may seem odd to posit, given that a recent Pricewaterhouse Coopers survey found that businesses now spend a higher percentage of their IT budgets on security than ever before.</p>
</li>
<li>
<p><a href="http://myonlinesecurity.co.uk/all-american-ce-nardin-energycalcs-net-ed-wolfe-fake-pdf-malware/">All American C&amp;E/ Nardin – energycalcs.net – Ed Wolfe – fake PDF malware</a> (My Online Security)<br>All American C&amp;E/ Nardin pretending to come from office &lt;office@energycalcs.net&gt;with&nbsp; a zip attachment is another one from the current bot runs which try to download various Trojans and password stealers especially banking credential stealers, which may include cridex, dridex, dyreza and various&nbsp; Zbots, cryptolocker, ransomware and loads of other malware on your computer.</p>
</li>
<li>
<p><a href="http://www.pcworld.com/article/2905492/chinese-internet-authority-clashes-with-google-over-digital-certificates.html">Chinese Internet authority clashes with Google over digital certificates</a> (PC World)<br>A Chinese Internet administrator blasted Google on Thursday, after the U.S. search giant decided to stop recognizing digital certificates issued by the group following a security lapse.</p>
</li>
<li>
<p><a href="http://www.webroot.com/shared/pdf/CyberThreatIntelligenceReport2015.pdf">The Importance of Cyber Threat Intelligence to a Strong Security Posture</a> (Poneman)<br>A new study by the Poneman Institute examines how companies are using, gathering and analyzing threat intelligence as part of their IT security strategy.</p>
</li>
</ul>

