Cyber Crime

Pierluigi Paganini January 15, 2015
KL-Remote toolkit allows criminals to easily hack online banking accounts

 Researchers at IBM Trusteer discovered a new toolkit dubbed KL-Remote that allows criminals to run Remote Overlay Attacks without specific skills. It is even more simple for cyber criminals to arrange scams and conduct illegal activities thanks the offer in the cyber criminal ecosystem, for example KL-Remote is a newborn toolkit that could be used to compromise online banking accounts by […]

Pierluigi Paganini January 15, 2015
CryptoWall 3.0 hides C&C Communications with I2P Anonymity Network

Security Experts at Microsoft discovered a new variant of CryptoWall 3.0 ransomware that adopts I2P Anonymity Network for C&C Communications. A new version of CryptoWall ransomware has been detected in the wild by experts at Microsoft, just a week after I reported that Cisco’s Talos Security Intelligence and Research Group detected a new strain of the same […]

Pierluigi Paganini January 14, 2015
Skeleton Key Malware modifies the Active Directory authentication process

Dell SecureWorks detected the Skeleton Key malware, which modifies authentication process on Active Directory (AD) systems protected by only passwords. The experts at Dell SecureWorks Counter Threat Unit(TM) (CTU) have recently discovered a malware dubbed Skeleton Key that bypasses single-factor authentication on Active Directory (AD) systems. The attackers can use to have total access to remote […]

Pierluigi Paganini January 13, 2015
Silk Road Reloaded, an important development in the world of black markets

The newborn Silk Road Reloaded black marketplace adopts I2P Anonymous Network and different virtual currency scheme to protect illegal business. The Operation Onymous conducted by law enforcement allowed the seizure of dozens of black markets on Tor Networks. While all the underground marketplaces in the DeepWeb, including Silk Road 2.0, went down due to the operation of […]

Pierluigi Paganini January 12, 2015
Hackers running Linux Operation Windigo are changing tactics targeting porn sites

Security Experts at ESET firm discovered that Windigo campaign is still active and that bad actors are changing their tactics to remain under the radar. Windigo is a sophisticated malware-based campaign uncovered by security Experts at ESET in March 2014, hackers behind the campaign that exploited the Linux/Ebury backdoor compromising more than 500,000 computers and 25,000 dedicated servers. The […]

Pierluigi Paganini January 11, 2015
Rex Mundi hackers leaked customers’ data of the Swiss Bank they hacked

The hackers of the Rex Mundi group have released online data stolen from The Banque Cantonale de Geneve that refused to pay 10000 EURO. Last week The Banque Cantonale de Geneve has been hacked by the criminal crew Rex Mundi that has tried to blackmail the financial institution. The group of Rex Mundi hackers threatened to […]

Pierluigi Paganini January 11, 2015
Foreign hackers target UK Power Grid every minute

The British Parliament reveals that UK Power Grid is under cyber attack from foreign hackers every minute, but the emergency is for infrastructure worldwide. UK Power Grid is targeted by hackers every minute according to James Arbuthnot, a member of parliament who chaired the Defense Select Committee until last year. As reported by Bloomberg, Arbuthnot plans […]

Pierluigi Paganini January 11, 2015
Financial malware poses as ICS/SCADA Software

Researcher Kyle Wilhoit discovered a spike in traditional financial crimeware targeting ICS/SCADA networks attributing it to attack run by cyber criminals. The senior threat researcher with Trend Micro, Kyle Wilhoit, has recently discovered 13 different types of crimeware disguised as new versions for human machine interface (HMI) software for Siemens Simatic WinCC, GE Cimplicity, and Advantech device drivers. The […]

Pierluigi Paganini January 10, 2015
Lizard Stresser hacking tool relies on compromised home routers

Security expert Brian Krebs and a research team discovered that the Lizard Stresser DDoS tool relies on compromised Home Routers. Over the holidays the Lizard Squad team knocked out the networks of Sony PSN and Microsoft Xbox live service using a tool they have designed to run DDoS attacks. The tool is dubbed Lizard Stresser and according to […]

Pierluigi Paganini January 10, 2015
Cryptowall Ransomware is resurrected with new features

Researchers at Cisco’s Talos group published an analysis of a new variant of Cryptowall ransomware that implements new features. CryptoWall ransomware is one of the most popular malware used in the cybercriminal ecosystem for extortions. Ransomware is a specific family of malicious code that lock victims’ resources and demands a ransom to unlock them. CryptoWall is considered […]