Posts

TrickMo Android Trojan Exploits Accessibility Services for On-Device Banking Fraud

Image
Cybersecurity researchers have uncovered a new variant of an Android banking trojan called TrickMo that comes packed with new capabilities to evade analysis and display fake login screens to capture victims' banking credentials. "The mechanisms include using malformed ZIP files in combination with JSONPacker," Cleafy security researchers Michele Roviello and Alessandro Strino  said . "In addition, the application is installed through a dropper app that shares the same anti-analysis mechanisms." "These features are designed to evade detection and hinder cybersecurity professionals' efforts to analyze and mitigate the malware." TrickMo, first caught in the wild by CERT-Bund in September 2019, has a  history  of targeting Android devices, particularly targeting users in Germany to siphon one-time passwords (OTPs) and other two-factor authentication (2FA) codes to facilitate financial fraud. The mobile-focused malware is assessed to be the work of the ...

23andMe to pay $30 million in genetics data breach settlement

Image
  DNA testing giant 23andMe has agreed to pay $30 million to settle a lawsuit over a data breach that exposed the personal information of 6.4 million customers in 2023. The  proposed class action settlement , filed Thursday in a San Francisco federal court and awaiting judicial approval, includes cash payments for affected customers, which will be distributed within ten days of final approval. "23andMe believes the settlement is fair, adequate, and reasonable," the company said in a  memorandum filed Friday . 23andMe has also agreed to strengthen its security protocols, including protections against credential-stuffing attacks, mandatory two-factor authentication for all users, and annual cybersecurity audits. The company must also create and maintain a data breach incident response plan and stop retaining personal data for inactive or deactivated accounts. An updated Information Security Program will also be provided to all employees during annual training sess...

Port of Seattle hit by Rhysida ransomware in August attack

Image
  Image: Midjourney Port of Seattle, the United States government agency overseeing Seattle's seaport and airport, confirmed on Friday that the Rhysida ransomware operation was behind a cyberattack impacting its systems over the last three weeks. The agency  revealed  on August 24 that the attack forced it to isolate some of its critical systems to contain the impact. The resulting IT outage disrupted reservation check-in systems and delayed flights at Seattle-Tacoma International Airport. Today, three weeks after the initial disclosure, the Port officially confirmed that the August breach was a ransomware attack coordinated by Rhysida ransomware affiliates. "This incident was a "ransomware" attack by the criminal organization known as Rhysida. There has been no new unauthorized activity on Port systems since that day. It remains safe to travel from Seattle-Tacoma International Airport and use the Port of Seattle's maritime facilities," it  said  in a press ...

Chinese hackers linked to cybercrime syndicate arrested in Singapore

Image
  Six Chinese nationals and a Singaporean have been arrested on Monday in Singapore for their alleged role in malicious cyber activities committed in connection with a "global syndicate." During raids on Monday, the police arrested six of the men and seized electronic devices with hacking tools installed and ready for carrying out cyberattacks, stolen personally identifiable information (PII), and credentials for servers known to be controlled by known hacker groups. The operation involved 160 officers of Singapore’s police, intelligence agencies, and internal security department. “On 9 September 2024, about 160 officers from the Singapore Police Force’s Criminal Investigation Department, Police Intelligence Department, Special Operations Command and the Internal Security Department conducted simultaneous raids at multiple residential locations island-wide,”  reads the police’s announcement . “The operation led to the arrest of the six men who are believed to be...

Flipper Zero releases Firmware 1.0 after three years of development

Image
  After three years of development, the Flipper Zero team has announced the release of the first major firmware version for the portable, customizable hacking device. Flipper Zero is a programmable device for pentesters that has faced controversy after users posted videos online showcasing illegal activities. Because of this, the gadged has been banned or restricted in some countries  Canada ,  Brazil , and on the  Amazon  e-commerce platform. At a glance, the first stable major firmware release solidifies support for 89 radio, 4 infrared, and 20 RFID protocols. It adds faster Bluetooth and NFC communications, JavaScript support, dynamic third-party application loading, and a month of battery life in standby mode. Overview of Firmware 1.0 features Source: Flipper Zero It is important to underscore that while Flipper Zero's previous firmware versions had  introduced  some of the features present in the latest revision, such as  they ...

Hackers Posed as Aerobics Instructors for Years to Target Aerospace Employees

Image
  An Iranian cyberespionage group masqueraded as an aerobics instructor on Facebook in an attempt to infect the machine of an employee of an aerospace defense contractor with malware as part of a years-long social engineering and targeted malware campaign. Enterprise security firm Proofpoint attributed the covert operation to a state-aligned threat actor it tracks as TA456, and by the wider cybersecurity community under the monikers Tortoiseshell and Imperial Kitten. "Using the social media persona 'Marcella Flores,' TA456 built a relationship across corporate and personal communication platforms with an employee of a small subsidiary of an aerospace defense contractor," Proofpoint   said   in a report shared with The Hacker News. "In early June 2021, the threat actor attempted to capitalize on this relationship by sending the target malware via an ongoing email communication chain." Earlier this month, Facebook  revealed  it took steps to dismantle a "...

Payment gateway data breach affects 1.7 million credit card owners

Image
  Payment gateway provider Slim CD has disclosed a data breach that compromised credit card and personal data belonging to almost 1.7 million individuals. In the notification sent to impacted clients, the company says that hackers had access to its network for nearly a year, between August 2023 and June 2024. Slim CD is a provider of payment processing solutions that enables businesses to access electronic and card payments via web-based terminals, mobile, or desktop apps. The firm first detected suspicious activity on its systems this year on June 15. During the investigation, the company discovered that hackers had gained access to its network since August 17, 2023.  “The investigation identified unauthorized system access between August 17, 2023, and June 15, 2024,” reads the  notification  to impacted individuals. However, Slim CD says that the threat actor viewed or obtained access to credit card information this year for two days, between June 14th an...

Meta fixes easily bypassed WhatsApp ‘View Once’ privacy feature

Image
  A privacy flaw in WhatsApp, an instant messenger with over 2 billion users worldwide, is being exploited by attackers to bypass the app's "View once" feature and view messages again. Meta says that WhatsApp's "View once" feature (introduced  three years ago ) enables users to share photos, videos, and voice messages privately, seeing that the recipient shouldn't be able to forward, share, copy, or screenshot their messages because they will automatically disappear from chats after being opened once. "Once you send a view once photo, video, or voice message, you won’t be able to view it again," the company  explains  on its support website. "Any photos or videos you send won’t be saved to the recipient’s Photos or Gallery. The recipient also can’t take a screenshot of anything you send using view once." However, "View once" will only block WhatsApp users from screenshotting what is being sent on mobile devices because deskt...