<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.itpro.com/uk/feeds/tag/social-engineering"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from ITPro UK in Social-engineering ]]></title>
                <link>https://www.itpro.com/uk/tag/social-engineering</link>
        <description><![CDATA[ All the latest social-engineering content from the ITPro  UK team ]]></description>
                                    <lastBuildDate>Tue, 23 Jun 2026 15:40:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ ‘They risk damaging confidence’: A Canadian health board outraged staff with phishing tests offering paid leave – experts say it shows why you need to be careful with cyber awareness campaigns ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/they-risk-damaging-confidence-a-canadian-health-board-outraged-staff-with-phishing-tests-offering-paid-leave-experts-say-shows-why-you-need-to-be-careful-with-cyber-awareness-campaigns</link>
                                                                            <description>
                            <![CDATA[ Phishing tests require a delicate touch, emulating realism while not “exploiting goodwill” ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LfUaaa5ELrjpAENwf6HrXn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iDKidsDKjf2VvPGKQeUDaC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 23 Jun 2026 15:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iDKidsDKjf2VvPGKQeUDaC-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing concept image showing a red-colored email symbol with a hook placed through it dangling over a laptop computer.]]></media:description>                                                            <media:text><![CDATA[Phishing concept image showing a red-colored email symbol with a hook placed through it dangling over a laptop computer.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing concept image showing a red-colored email symbol with a hook placed through it dangling over a laptop computer.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iDKidsDKjf2VvPGKQeUDaC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security experts have urged organizations to take a more considerate approach to cyber awareness training after a Canadian health board sent emails to staff offering paid leave as part of a phishing test. </p><p>Ron Johnson, interim chief executive at Newfoundland and Labrador Health Services, apologized for the phishing test last week, admitting the emails were sent in poor taste. </p><p>“We acknowledge the approach taken in this particular exercise was not appropriate, and we sincerely apologize to employees, physicians, and union representatives,” he <a href="https://nlhealthservices.ca/news/nl-health-services-apologizes-for-the-recent-cybersecurity-awareness-exercise/" target="_blank"><u>wrote</u></a>. </p><p>The <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>simulation prompted backlash after being circulated to hundreds of employees, and has since prompted a review of future activities, Johnson added. </p><p>“We value the feedback and are reviewing how future awareness exercises are developed and communication,” he said. </p><p>“It is important they reflect employee and physician perspectives, as well as our organizational values to foster a respectful and supportive workplace culture.”</p><p>This isn’t the first time an organization has been forced into a U-turn after a controversial phishing test campaign. </p><p>As <em>ITPro </em>reported in late 2024, the University of California Santa Cruz (UCSC) was heavily criticized for a “tone deaf” campaign <a href="https://www.itpro.com/security/how-not-to-conduct-cyber-awareness-training-ucsc-slammed-for-tone-deaf-ebola-phishing-tests"><u>which used a fake Ebola virus track and trace alert</u></a>. </p><p>The campaign caused a panic on campus and was highly convincing, even employing links to a fake webpage set up to support those affected by the “outbreak”. </p><h2 id="phishing-tests-are-a-vital-part-of-cyber-hygiene">Phishing tests are a vital part of cyber hygiene</h2><p>While this particular incident sparked ire among employees, phishing tests are a common practice by cybersecurity professionals to ensure staff remain vigilant to potential security threats. </p><p>Phishing attacks, in particular, are a leading cause of breaches at organizations across a range of industries – and the healthcare sector specifically is a prime target for cyber criminals. </p><p><a href="https://www.itpro.com/security/phishing/ai-generated-phishing-became-the-baseline-for-hackers-last-year-kaseya-warns-its-going-to-get-worse-in-202">Add AI into the equation</a>, and the threat landscape faced by enterprises today is becoming increasingly perilous, with threat actors using the technology to refine techniques and curate highly convincing emails. </p><p>Rob Anderson, head of reactive consulting services at Reliance Cyber, told <em>ITPro </em>that the “best phishing exercises are realistic” – after all, they are intended to emulate the tactics used by cyber criminals. </p><p>"They should use the same sneaky tactics that threat actors may use, hopefully triggering the trained, instinctive suspicion we want staff to develop when handling unexpected emails,” he said. </p><p>“However, there is a fine line. Nobody likes to be made a fool of, especially at sensitive times.”</p><p>Anderson pointed to a phishing exercise by one UK police force’s Information Protection Unit, which circulated emails targeting staff in a typical fashion. Those who fell foul were met with a message stating: “whoops, you’ve failed this training”. </p><p>In this instance, Anderson said the Information Protection Unit had “failed to read the room”. </p><p>“A week earlier, the force had announced a restructure, with likely compulsory redundancies and transfers,” he said. “Police officers can be a vocal and cynical bunch, and they made their feelings known.”</p><h2 id="a-delicate-balancing-act">A delicate balancing act</h2><p>It’s here that phishing tests often become a delicate balancing act, according to Simon McNalley, identity and access management (IAM) technical director at Thales. </p><p>Ultimately, <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>professionals need to ensure that simulations are “realistic enough to reflect the tactics attackers use” without “exploiting goodwill”. </p><p>“Scenarios involving pay, bonuses, annual leave, personal hardship, or other highly sensitive employment matters should be approached with caution, as they risk damaging confidence in legitimate internal communications,” he told <em>ITPro</em>. </p><p>Anderson echoed McNally’s comments, adding that human resources (HR), communications, and senior leadership should be consulted before campaigns go live.</p><p>Ultimately, McNally said the NL Health Services incident should serve as an example to other organizations hoping to keep staff on their guard in light of rising threats. </p><p>“There is a place for phishing simulations as part of building cyber awareness, especially as attackers routinely use such techniques. However, it’s vital that these exercises do not come at the expense of trust between employer and employee. Trust is a critical component of security culture,” he said. </p><p>“If awareness programs leave employees feeling misled, embarrassed or manipulated, organizations risk undermining the very behaviors they are trying to encourage.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are capitalizing on AI hype to ramp up social engineering attacks – and they're using big brands like Anthropic, OpenAI, and DeepSeek as ‘bait’ to lure victims ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/hackers-are-capitalizing-on-ai-hype-to-ramp-up-social-engineering-attacks-and-theyre-using-big-brands-like-anthropic-openai-and-deepseek-as-bait-to-lure-victims</link>
                                                                            <description>
                            <![CDATA[ Microsoft says cyber criminals are impersonating popular AI platforms to deliver malware ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Bt3jnSdxJvJ3eU7nUZAaq5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 11 Jun 2026 11:11:12 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:description>                                                            <media:text><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber criminals are exploiting <a href="https://www.itpro.com/technology/artificial-intelligence/businesses-finding-it-hard-to-distinguish-real-ai-from-the-hype-report-suggests">AI hype</a> to impersonate the branding of AI platforms such as ChatGPT, Microsoft Copilot, DeepSeek, and Anthropic’s Claude, according to new research. </p><p>Microsoft Threat Intelligence said it's observed an uptick in <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a>, malvertising, and search engine optimization (SEO)-driven attacks that ultimately lead to credential theft, financial fraud, or malware infection.</p><p>Campaigns focus on highly anticipated launches or emerging trends, using tried-and-tested tactics such as urgency-driven messaging, abuse of trusted services, and multi-stage redirection chains that require user interaction to evade detection.</p><p>"While traditional lures like invoices, payment notifications, or delivery alerts remain effective and continue to be widely used, AI-themed lures reflect a shift in <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> that is likely to persist as a long-term tactic used by threat actors, from cyber criminal groups to nation states," the company warned. </p><h2 id="chatgpt-users-in-the-crosshairs">ChatGPT users in the crosshairs</h2><p>In one example, Microsoft said it had observed a ChatGPT-themed phishing attack delivering malicious URLs which led to phishing pages that collected credit card and personal information such as names and addresses. </p><p>The emails used the sender display name ChatGPT and the subject line: “To ensure your ChatGPT Plus continues to work – please update your payment method”. </p><p>This phishing activity, which consisted of 4,500 emails sent to targets in South Africa, was part of a broader campaign using similar themes and infrastructure that delivered as many as 100,000 emails on a single day to targets in Switzerland, Austria, and South Africa. </p><p>Microsoft noted the campaign affected a broad range of industries, including higher education and professional services.</p><h2 id="thousands-targeted-in-a-claude-themed-phishing-attack">Thousands targeted in a Claude-themed phishing attack</h2><p>In another example, security experts spotted a phishing campaign impersonating Anthropic-branded services to target users with account-related lures tied to the Claude AI platform. </p><p>The campaign sent phishing emails to targets across more than 2,000 organizations, mainly in the US, UK, and India.</p><p>"The campaign used enforcement-themed messaging claiming that the recipient’s account was in violation of acceptable use policies and required immediate action," the company noted. </p><p>"The emails impersonated Anthropic’s popular AI service Claude using the display names Anthropic Teams and Anthropic PBC, masquerading as legitimate account-related communications. Subject lines followed a consistent structure of 'Claude Appeal Request' combined with date elements."</p><h2 id="deepseek-malvertising-is-a-growing-threat">DeepSeek malvertising is a growing threat</h2><p>Other examples included malvertising campaigns that use AI-themed terms such as 'Awesome AI Windows Plugin' and 'Flux Pro AI' in social engineering lures, and fake DeepSeek V4 installers on GitHub that delivered Vidar Stealer.</p><p>"Within hours of <a href="https://www.itpro.com/security/using-deepseek-at-work-security-risks">DeepSeek </a>previewing their latest version, V4, attackers created a fake GitHub organization and repository.  They copied real branding and benchmark data, added AI and SEO-search-friendly content, and pushed malicious archives that looked like installers," explained John Bruggeman, vCISO at CBTS. </p><p>"What the attacker did was not particularly exotic, but it was well timed and convincingly packaged. A user searching for the newest model could very easily end up in the wrong place, especially because the malicious repository showed up in GitHub, Google, Bing, or AI-assisted search results. The search results added legitimacy to the <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>."</p><h2 id="remain-vigilant">Remain vigilant</h2><p>To counter these rising threats, Microsoft advised customers to configure automatic attack disruption in Microsoft Defender XDR, enforce <a href="https://www.itpro.com/security/how-resellers-can-win-with-smarter-multi-factor-authentication-mfa">multi-factor authentication (MFA)</a> on all accounts, use the Microsoft Authenticator app for passkeys and MFA, and scope conditional access policies to strengthen privileged accounts with <a href="https://www.itpro.com/security/cyber-attacks/how-hackers-bypass-mfa-and-what-to-do-about-it">phishing-resistant MFA</a>.  </p><p>Other tips included:</p><ul><li>Enabling Zero-hour auto purge (ZAP) in Office 365</li><li>Configuring Microsoft Defender for Office 365 Safe Links</li><li>Invest in ‘advanced’ anti-phishing solutions</li></ul><p>"The companies that have a handle on AI governance (policies and procedures) well will be the ones that make safe AI use easy, risky AI use visible, and malicious activity hard to ignore. That means publishing a clear list of approved tools, blocking obvious lookalike domains and very recently registered domains can help stop this kind of threat," said Bruggeman. </p><p>"Monitoring suspicious downloads and sign-ins, and training employees on the AI-themed lures should also be done right now - don't think that generic phishing examples from five years ago are going to cut it today."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Two US nationals sentenced for role in prolific fake worker laptop farms ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/two-us-nationals-sentenced-for-role-in-prolific-fake-worker-laptop-farms</link>
                                                                            <description>
                            <![CDATA[ The Americans were raising money for the North Korean regime by allowing fake IT workers to appear as legitimate US-based employees ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mrNBRbuHM5MZaP4LN7BJGo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rBaWcKkPGkJSvaRS3NHzSB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 11 May 2026 11:17:51 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rBaWcKkPGkJSvaRS3NHzSB-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[North Korean hacker concept image showing a man in military uniform working on a laptop computer with flag of North Korea pictured on screen in background.]]></media:description>                                                            <media:text><![CDATA[North Korean hacker concept image showing a man in military uniform working on a laptop computer with flag of North Korea pictured on screen in background.]]></media:text>
                                <media:title type="plain"><![CDATA[North Korean hacker concept image showing a man in military uniform working on a laptop computer with flag of North Korea pictured on screen in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rBaWcKkPGkJSvaRS3NHzSB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Two US nationals have been sentenced to 18 months in prison for their part in running 'laptop farms' aimed at raising money for the North Korean government.</p><p>Matthew Issac Knoot, of Nashville, Tennessee, and Erick Ntekereze Prince, of New York, were sent company-issued laptops under stolen identities. They then installed unauthorized remote desktop software that allowed <a href="https://www.itpro.com/security/cyber-attacks/north-korean-it-workers-the-growing-threat">fake North Korean IT workers</a> to appear as legitimate US-based employees.</p><p>The two worked separately, but according to the Department of Justice, between them generated more than $1.2 million in revenue for the DPRK and impacted nearly 70 companies in the US.</p><p>"These sentences hold accountable U.S nationals who enabled North Korea’s illicit efforts to infiltrate US networks and profit on the back of US companies,” said assistant attorney general for National Security John A. Eisenberg. </p><p>“These defendants helped North Korean ‘IT workers’ masquerade as legitimate employees, compromising US corporate networks and helping generate revenue for a heavily sanctioned and rogue regime. The National Security Division will continue to pursue those who, through deception and cyber-enabled fraud, threaten our national security.”</p><p>Prince helped at least three DPRK IT workers obtain remote employment at US companies between around June 2020 and August 2024. Prince used his company, Taggcar Inc, to  supply 'certified' IT staff using false and stolen identities. </p><p>He also kept laptops provided by the victim companies at his New York home, installing remote access software without authorization to make it look as if the DPRK IT workers were working there.</p><p>Prince was sentenced to 18 months in prison, followed by three years of supervised release. He was also ordered to forfeit $89,000, the amount the DPRK IT workers paid him for his help.</p><p>Knoot, meanwhile, ran a laptop farm from his Nashville home between around July 2022 and August 2023, supplying North Korean IT workers to at least four US companies. </p><p>These firms paid the DPRK IT workers associated with Knoot’s laptop farm more than $250,000 for their work - most of which was falsely reported to the IRS and Social Security Administration under the name of the actual US citizen whose identity had been stolen. </p><p>He and his co-conspirators cost the victim companies more than $500,000 for auditing and fixing their devices, systems, and networks.</p><h2 id="fake-north-korean-it-workers-are-rampant">Fake North Korean IT workers are rampant</h2><p>The crimes mark the latest in a continuing series of North Korean campaigns to supply fake workers and steal money for the regime. </p><p>Notably, these groups increasingly <a href="https://www.itpro.com/security/is-your-new-hire-an-ai-clone-microsoft-says-north-korean-hackers-are-using-ai-to-impersonate-job-seekers-and-steal-company-secrets"><u>use voice-changing software</u></a> during remote interviews to disguise their accents, or using the AI app Face Swap to place their faces in stolen identity documents and generate convincing headshots for CVs. </p><p>A host of organisations in the US have been affected by these campaigns over the last two years. As <em>ITPro </em>previously reported, cybersecurity company KnowBe4 <a href="https://www.itpro.com/security/cyber-firm-knowbe4-unknowingly-hired-a-north-korean-hacker-and-it-went-exactly-as-you-might-think"><u>unknowingly hired a fake IT worker</u></a>, who immediately began loading malware as soon as they received their Mac workstation.</p><p>“This scheme shows how national security threats now enter through ordinary business systems. These defendants helped North Korean IT workers pose as legitimate employees, gain access to American companies, and generate money for a sanctioned regime,” said US attorney Jason A. Reding Quiñones for the Southern District of Florida. </p><p>"These were not paperwork violations. They were deliberate acts that exposed U.S. businesses, compromised trust, and supported one of the world’s most dangerous adversaries. These sentences send a clear message: if you help foreign actors infiltrate American companies for profit, you will face federal prison and lose the money you made.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Beware of emails threatening a code of conduct review ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/beware-of-emails-threatening-a-code-of-conduct-review</link>
                                                                            <description>
                            <![CDATA[ A widespread phishing campaign has targeted tens of thousands of employees ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">77y4eje5T825eD49NpbPGa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 06 May 2026 09:34:02 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:description>                                                            <media:text><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has <a href="https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise/" target="_blank">issued an alert</a> over a large-scale credential theft campaign that uses lures centered around corporate codes of conduct.</p><p>The emails were related to internal compliance or regulatory issues, with display names such as 'Internal Regulatory COC', 'Workforce Communications', and 'Team Conduct Report'.</p><p>Subject lines included 'Internal case log issued under conduct policy' and 'Reminder: employer opened a non-compliance case log'.</p><p>The emails were sent using a legitimate email delivery service, likely originating from a cloud-hosted <a href="https://www.itpro.com/security/ransomware/ransomware-gangs-are-sharing-virtual-machines-to-wage-cyber-attacks-on-the-cheap-but-it-could-be-their-undoing">Windows virtual machine (VM)</a>. </p><p>The accusations and repeated time-bound action prompts created a sense of urgency, Microsoft researchers said. Similarly, the emails were based on polished, enterprise-style HTML templates with structured layouts and authenticity statements, making them appear more credible than most phishing emails.</p><p>The bodies of the messages claimed that a code of conduct review had been initiated, referenced organization-specific names embedded within the text, and instructed recipients to open a PDF attachment to see the materials of the case. </p><p>When clicked, users were first directed to one of two attacker-controlled domains - acceptable-use-policy-calendly[.]de or compliance-protectionoutlook[.]de. </p><p>The landing pages displayed a <a href="https://www.itpro.com/security/cyber-crime/fake-captcha-attacks-surged-in-late-2024-heres-what-to-look-out-for">Cloudflare CAPTCHA</a>, presented as checking that the user was coming 'from a valid session', and that likely served as a gating mechanism to impede automated analysis and sandbox detonation. </p><p>According to Microsoft, the attack chain ultimately led to a legitimate sign-in experience that formed part of an <a href="https://www.itpro.com/security/cyber-crime/adversary-in-the-middle-attacks-are-becoming-hackers-go-to-method-to-bypass-mfa">adversary in the middle (AiTM)</a> phishing flow. </p><p>Unlike traditional credential harvesting, AiTM attacks intercept authentication traffic in real time, <a href="https://www.itpro.com/security/cyber-attacks/how-hackers-bypass-mfa-and-what-to-do-about-it">bypassing multifactor authentication (MFA)</a>. </p><p>As a result, the attackers were able to proxy the authentication session and capture authentication tokens that could provide immediate account access. </p><p>"<a href="https://www.itpro.com/security/29093/what-is-phishing">Phishing </a>campaigns continue to improve sophistication and refinement in blending social engineering, delivery and hosting infrastructure, and authentication abuse to remain effective against evolving security controls," the researchers warned. </p><h2 id="what-industries-are-affected">What industries are affected?</h2><p>Between 14 and 16 April this year, the Microsoft Defender Research team said it spotted a series of campaigns targeting more than 35,000 users across over 13,000 organizations in 26 countries. Most targets - 92% - were located in the US. </p><p>The campaign didn't focus on a single vertical but instead impacted a broad range of industries, most notably healthcare and life sciences (19%), financial services (18%), professional services (11%), and technology and software (11%).</p><p>Microsoft said organizations should review the recommended settings for Exchange Online Protection and Microsoft Defender for Office 365 to check for essential defenses and the ability to monitor and respond to threat activity. They should also invest in user awareness training and phishing simulations. </p><p>Enabling Zero-hour auto purge (ZAP) in Defender for Office 365 is advised to quarantine sent mail in response to newly acquired threat intelligence. Users are also urged to retroactively neutralize malicious phishing, spam, or <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>messages that have already been delivered to mailboxes.</p><p>It's also worth manually checking for, and purging, unwanted emails containing URLs and/or Subject fields that are similar, but not identical, to those of known bad messages.</p><p>Organizations should enable password-less authentication methods or use authenticator apps, researchers said, and strengthen privileged accounts with phishing resistant MFA.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft and NCSC issue alerts over hacker campaigns targeting WhatsApp, Signal messaging apps ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/microsoft-and-ncsc-issue-alerts-over-hacker-campaigns-targeting-whatsapp-signal-messaging-apps</link>
                                                                            <description>
                            <![CDATA[ Microsoft warns about a sophisticated attack that starts with WhatsApp messages, while the NCSC says such incidents are on the rise ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LJTnJm6NstRzVvKFnCmeyd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Pxt7furBergTPQRSi3WUA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 03 Apr 2026 06:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Pxt7furBergTPQRSi3WUA-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[iOS app icons for WhatsApp and Signal messaging platforms, with top half of Instagram icon pictured in bottom right hand corner.]]></media:description>                                                            <media:text><![CDATA[iOS app icons for WhatsApp and Signal messaging platforms, with top half of Instagram icon pictured in bottom right hand corner.]]></media:text>
                                <media:title type="plain"><![CDATA[iOS app icons for WhatsApp and Signal messaging platforms, with top half of Instagram icon pictured in bottom right hand corner.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Pxt7furBergTPQRSi3WUA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has issued a warning about a sophisticated new malware campaign targeting WhatsApp users. </p><p>Microsoft's security experts spotted a WhatsApp campaign at the end of February that makes use of malicious Visual Basic Script (VBS) files, tricking victims via <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> techniques to run the files. </p><p>"Once executed, these scripts initiate a multi-stage infection chain designed to establish persistence and enable remote access," noted a <a href="https://www.microsoft.com/en-us/security/blog/2026/03/31/whatsapp-malware-campaign-delivers-vbs-payloads-msi-backdoors/" target="_blank"><u>blog post</u></a> by the Microsoft Defender Security Research Team. </p><p>The attack blends into normal system activity by renaming real utilities before downloading dodgy payloads from normally trustworthy cloud services, including AWS and Tencent, taking control of the system by installing malicious Microsoft Installer (MSI) packages. </p><p>"By combining trusted platforms with legitimate tools, the threat actor reduces visibility and increases the likelihood of successful execution, " the post added. </p><p>If successful, attackers can escalate privileges and gain admin control, giving them the ability to stick around on compromised devices for a long time without being spotted. </p><p>To mitigate potential risks, Microsoft advised blocking execution of script hosts in untrusted paths, and monitoring for Windows utilities being renamed or hidden ones being executed. </p><p>More widely, Microsoft advised boosting monitoring of cloud traffic and registry changes, and — as ever — educating users about social engineering. </p><h2 id="whatsapp-signal-in-the-crosshairs">WhatsApp, Signal in the crosshairs</h2><p>The advisory from the tech giant comes after the UK’s <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a> issued a similar warning to “high risk” individuals amid a fresh wave of attacks by state-backed threat actors.</p><p>According to the NCSC, hackers are flocking to popular messaging apps such as WhatsApp and Signal to conduct social engineering campaigns. </p><p>"The NCSC and international partners have seen growing malicious activity from Russia-based actors using messaging apps to target high-risk individuals," the security group said in a<a href="https://www.ncsc.gov.uk/news/ncsc-warns-of-messaging-app-targeting" target="_blank"><u> blog post</u></a>. </p><p>The NCSC pointed to previous campaigns aimed at compromising government officials’ accounts by Chinese state-linked group, APT31, as well as attempts by the Russian-linked threat group Star Blizzard. </p><p>Beyond government officials, the NCSC said that high-risk individuals could include having a public profile but also anyone with "access to, or influence over, sensitive information". </p><p>These attacks could involve attempts to trick users into sharing login or account recovery codes, suddenly being a part of unexpected group chats, attempts to impersonate someone you know, and the usual <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>attempts using dodgy links or QR codes. </p><p>The NCSC said attackers could also add their device to a victim's account without them noticing. </p><p>Adam Boynton, Senior Enterprise Strategy Manager at Jamf, said the NCSC warning is a timely reminder that apps are only as secure as the device they are installed on — even if that app is well encrypted. </p><p>"Users often assume end-to-end encryption means end-to-end protection, but that’s not the case," Boynton said. </p><p>"If a device is compromised, or if a user is socially engineered into linking an attacker’s device to their account, encryption becomes irrelevant."</p><h2 id="staying-safe">Staying safe</h2><p>Be wary when messaging, regardless of the platform, the NCSC advised. Never share verification codes, don't click unexpected links or scan QR codes, and be aware that attackers may attempt to impersonate real contacts, so keep watch for unknown contacts or double entries. </p><p>To boost security in these apps, users are urged to enable two-step verification, or Registration Lock in Signal, and make use of passkeys local to devices in WhatsApp and Signal. </p><p>Turn on disappearing messages where possible to limit what's lost if an attacker does get access. </p><p>"However, you should have regard to any applicable record keeping requirements," the NCSC noted. </p><p>The organization advised against sharing sensitive information via apps, instead using corporate approved messaging services. As ever, ensure devices are well secured and updated to fix security flaws. </p><p>"For organizations with high-risk individuals, the lesson is clear: app-level security is not device-level security," added Boynton. </p><p>"Visibility into linked devices, enforced software updates, and ensuring sensitive communications happen on managed channels should already be baseline. The organisations best prepared for threats like these aren’t reacting to advisories — they’ve already built mobile security into their foundation."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Is your new hire an AI clone? Microsoft says North Korean hackers are using AI to impersonate job seekers and steal company secrets ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/is-your-new-hire-an-ai-clone-microsoft-says-north-korean-hackers-are-using-ai-to-impersonate-job-seekers-and-steal-company-secrets</link>
                                                                            <description>
                            <![CDATA[ The groups are increasingly using face-changing or voice-changing software to make their fake identities more plausible ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9jyHo9d4gA83CkaZBtmvcQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/U7xFHys4ZqNqAUYxH7V7Sa-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 09 Mar 2026 12:23:15 +0000</pubDate>                                                                                                                                <updated>Tue, 10 Mar 2026 12:00:49 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/U7xFHys4ZqNqAUYxH7V7Sa-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Side profile view of a human head with brain synapses and flowing data lines. ]]></media:description>                                                            <media:text><![CDATA[Side profile view of a human head with brain synapses and flowing data lines. ]]></media:text>
                                <media:title type="plain"><![CDATA[Side profile view of a human head with brain synapses and flowing data lines. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/U7xFHys4ZqNqAUYxH7V7Sa-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/should-your-business-worry-about-north-korean-cyber-attacks">North Korean threat groups</a> are using AI to ramp up efforts to infiltrate western companies with fake employees, according to new research.</p><p>Analysis from Microsoft’s Threat Intelligence Team shows three groups – Jasper Sleet, Sapphire Sleet, and Coral Sleet (formerly Storm-1877) – are using voice-changing software during remote interviews to disguise their accents and make their cover stories more convincing.</p><p>They're also using the AI app Face Swap to place their faces in stolen identity documents and generate convincing headshots for CVs.</p><p>"Threat actors are using <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>to shortcut the reconnaissance process that informs the development of convincing digital personas tailored to specific job markets and roles," Microsoft warned in a <a href="https://www.microsoft.com/en-us/security/blog/2026/03/06/ai-as-tradecraft-how-threat-actors-operationalize-ai/" target="_blank"><u>blog post</u></a>. </p><p>"Jasper Sleet leverages generative AI platforms to streamline the development of fraudulent digital personas. For example, Jasper Sleet actors have prompted AI platforms to generate culturally appropriate name lists and email address formats to match specific identity profiles."</p><p>The groups are also using AI to search job postings on jobs platforms such as Upwork, then using AI to make their applications meet the jobs' skill requirements. </p><p>This includes generating realistic names, email formats, and social media handles using AI prompts, writing AI-assisted resumes and cover letters, creating fake developer portfolios using AI-generated content, and using AI-enhanced images to create professional-looking profile photos and forged identity documents. </p><p>Microsoft noted that these personas are used across multiple job applications and platforms.</p><h2 id="voice-cloning-and-agentic-ai-are-in-vogue">Voice cloning and agentic AI are in vogue</h2><p>Elsewhere, Microsoft warned threat groups are using <a href="https://www.itpro.com/security/deepfake-business-risks-are-growing-what-leaders-need-to-know">AI-generated voice cloning</a> to impersonate executives or trusted individuals in vishing and <a href="https://www.itpro.com/security/cyber-attacks/what-is-business-email-compromise-bec">business email compromise (BEC)</a> scams</p><p>Once the fake workers are inside an organization, they use AI-enabled communications to support daily tasks and fit in with role expectations. </p><p>"For example, Jasper Sleet uses AI to help sustain long-term employment by reducing language barriers, improving responsiveness, and enabling workers to meet day-to-day performance expectations in legitimate corporate environments," Microsoft noted.</p><p>"Threat actors are leveraging generative AI in a way that many employees are using it in their daily work, with prompts such as 'help me respond to this email', but the intent behind their use of these platforms is to deceive the recipient into believing that a fake identity is real."</p><p>With the advent of agentic AI, Microsoft warned threat actors are also flocking to powerful new tools. </p><p>The tech giant’s threat intelligence team observed groups using agents to create semi‑autonomous workflows that help refine <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaigns, test and adapt infrastructure, maintain persistence, or monitor open source intelligence for new opportunities.</p><h2 id="north-korean-hackers-are-prolific">North Korean hackers are prolific</h2><p>The problem of North Korean fake workers just won't seem to go away. While this trend primarily affected US companies, Google warned last summer that threat groups are now <a href="https://cloud.google.com/transform/ultimate-insider-threat-north-korean-it-workers"><u>expanding campaigns to target European organizations</u></a>. </p><p>Last month, Security Alliance (SEAL) warned that <a href="https://www.itpro.com/security/fake-north-korean-it-workers-are-rampant-on-linkedin-security-experts-warn-operatives-are-stealing-profiles-to-apply-for-jobs-and-infiltrate-firms">North Korean hackers are hijacking genuine LinkedIn profiles</a> to apply for remote jobs and infiltrate enterprises. </p><p>Hackers typically use real identities, leveraging verified workplace emails and identity badges, and constructing credible employment histories to pass background checks.</p><p>Organizations are advised to tighten up their identity verification processes, including document checks and, wherever possible, in-person interviews.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google issues warning over ShinyHunters-branded vishing campaigns ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/google-issues-warning-over-shinyhunters-branded-vishing-campaigns</link>
                                                                            <description>
                            <![CDATA[ Related groups are stealing data through voice phishing  and fake credential harvesting websites ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zHr8MESTqLrM7FdPM6unGB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6UMt7L8cwrivqQPjJWN3eX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 04 Feb 2026 08:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6UMt7L8cwrivqQPjJWN3eX-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Device code phishing concept image showing cartoon cell phone with a hook attached to a sign-in page. ]]></media:description>                                                            <media:text><![CDATA[Device code phishing concept image showing cartoon cell phone with a hook attached to a sign-in page. ]]></media:text>
                                <media:title type="plain"><![CDATA[Device code phishing concept image showing cartoon cell phone with a hook attached to a sign-in page. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6UMt7L8cwrivqQPjJWN3eX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google Threat Intelligence Group (GTIG) has identified a group with all the hallmarks of ShinyHunters using <a href="https://www.itpro.com/security/cyber-attacks/phishing-tactics-the-top-attacks-trends-in-year">voice phishing</a> (vishing) and fake credential harvesting websites to steal sensitive data. </p><p>In an advisory, the tech giant warned the group primarily gains access to corporate environments by obtaining single sign-on (SSO) credentials and <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">multi-factor authentication (MFA)</a> codes. </p><p>Once inside, the attackers target cloud-based SaaS applications to exfiltrate sensitive data and internal communications that they can use in subsequent extortion demands.</p><p>Google is currently <a href="https://cloud.google.com/blog/topics/threat-intelligence/expansion-shinyhunters-saas-data-theft" target="_blank"><u>tracking</u></a> the activity under several threat clusters, including UNC6661, UNC6671, and UNC6240.</p><p>Last month, for example, UNC6661 pretended to be IT staff and called employees at targeted organisations, claiming that the company was updating MFA settings. </p><p>The threat actor then directed employees to victim-branded credential harvesting sites to capture credentials and MFA codes, with victims thereafter registering their own device for MFA. </p><p>According to Google, threat actors moved laterally through victim customer environments to exfiltrate data from various <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas">SaaS </a>platforms.</p><p>While the attacks are targeted, analysis suggests that subsequent access is probably opportunistic, determined by the specific permissions and applications accessible via the individual compromised SSO session. Google stressed that the activity isn't the result of a security vulnerability in vendors' products or infrastructure. </p><p>"In some cases, they have appeared to target specific types of information. For example, the threat actors have conducted searches in cloud applications for documents containing specific text including 'poc', 'confidential', 'internal', 'proposal', 'salesforce', and 'vpn' or targeted personally identifiable information (PII) stored in Salesforce," researchers said. </p><p>"Additionally, UNC6661 may have targeted Slack data at some victims' environments, based on a claim made in a ShinyHunters-branded data leak site (DLS) entry."</p><h2 id="valuable-intelligence">Valuable intelligence</h2><p>Cory Michal, CSO at AppOmni, praised the level of operational detail in the report, and particularly the volume and specificity of indicators of compromise that weren’t previously public.</p><p>This intelligence could prove vital for organizations that find themselves in the crosshairs moving forward, Michael noted.</p><p>“Publishing concrete domains, tooling names/artifacts, and workflow-level signals gives defenders something they can deploy immediately at scale (email/web filtering, OAuth/app controls, identity telemetry detections, and retro-hunting),” he said.</p><p>“It helps the ecosystem disrupt infrastructure and tradecraft faster by enabling consistent blocking and takedown actions across many organizations rather than each team rediscovering the same indicators in isolation.”</p><h2 id="what-can-enterprises-do-to-protect-themselves">What can enterprises do to protect themselves?</h2><p>Google has published <a href="https://cloud.google.com/blog/topics/threat-intelligence/defense-against-shinyhunters-cybercrime-saas" target="_blank"><u>guidance</u></a> on hardening, logging, and detection against the threats. </p><p>Organizations responding to an active incident should focus on rapid containment steps, such as severing access to infrastructure environments, SaaS platforms, and the specific identity stores typically used for lateral movement and persistence. </p><p>Long-term defense, meanwhile, requires a transition toward phishing-resistant MFA, such as FIDO2 security keys or passkeys, which are more resistant to <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> than push-based or SMS authentication.</p><p>“Companies should treat this as both a hunt and prevent problem: First, take the IoCs in the report and run them through your detection-and-response workflows (SIEM/SOAR, email security, web proxy/DNS, EDR, and SaaS audit logs) to identify any historical or active exposure," Michal added. </p><p>Michael added they should add continuous monitoring for look-alike domain registrations that incorporate their company name or common brands that they use for login, support, and HR. </p><p>"In many of these campaigns, those newly registered domains are a leading indicator, they show up before the first vishing call, so catching and blocking them early (and tightening your help desk/MFA enrollment controls in parallel) can meaningfully reduce the chance the intrusion ever gets to the “mass download and extortion” stage,” he said.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Thousands of Microsoft Teams users are being targeted in a new phishing campaign ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/microsoft-teams-phishing-scam-fake-billing-check-point</link>
                                                                            <description>
                            <![CDATA[ Microsoft Teams users should be on the alert, according to researchers at Check Point ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xYBLYYi6CQjeTaVUDQ9sSk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WwZJrcyz5jLppWLVcEFL8m-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 26 Jan 2026 10:45:59 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WwZJrcyz5jLppWLVcEFL8m-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft Teams login page on desktop app pictured on a laptop screen.]]></media:description>                                                            <media:text><![CDATA[Microsoft Teams login page on desktop app pictured on a laptop screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft Teams login page on desktop app pictured on a laptop screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WwZJrcyz5jLppWLVcEFL8m-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaign is abusing trusted collaboration platforms like <a href="https://www.itpro.com/software/33703/microsoft-teams-review-a-no-brainer-for-microsoft-shops">Microsoft Teams</a> to bypass traditional email security.</p><p><a href="https://www.itpro.com/security/28133/what-is-cyber-security">Cybersecurity</a> researchers at Check Point have <a href="https://blog.checkpoint.com/email-security/attackers-continue-to-target-trusted-collaboration-platforms-12000-emails-target-teams-users/" target="_blank"><u>discovered</u></a> more than 12,000 malicious emails sent to over 6,000 users, most of which use legitimate Microsoft Teams guest invitations to impersonate billing alerts and trick victims into calling fake support lines. </p><p>Rather than relying on <a href="https://www.itpro.com/security/phishing/how-hackers-are-using-legitimate-tools-to-distribute-phishing-links">malicious links</a> or attachments, attackers are exploiting built-in guest invitation options and finance-themed team names to dupe users with fake billing and subscription notifications.</p><p>The attacker starts off by creating a new team in Microsoft Teams and assigning it a finance-themed name designed to resemble an urgent billing or subscription notice. </p><p>One example given by Check Point researchers read: “<em>Subscription Auto-Pay Notice (Ivoice ID: 2025_614632PPOT_SAG Amount 629. 98 USD). If you did not authorize or complete this m0nthly Payment,plese c0ntact our support team urgently.</em>”</p><p>The aim here for attackers is to bypass automated detection by embedding obfuscation techniques in the team name. This includes character substitutions, mixed Unicode characters, visually similar glyphs, and the like.</p><p>After creating the team, the attacker uses the <em>Invite a Guest</em> feature in Microsoft Teams, sending the victim an email invitation from a legitimate Microsoft address, with the fake team name displayed prominently in large font. </p><p>"At first glance, the message appears to be a genuine Microsoft-generated notification, increasing the likelihood that users trust the content and follow the instructions," the researchers warned.</p><p>Recipients are then asked to call a fraudulent support number to resolve the "billing issue".</p><p>The fraudulent emails are being used to target a wide range of organizations, researchers noted, with 27% targeting manufacturing, engineering and construction and 1% technology/SaaS. </p><p>One-in-eight, meanwhile, went to educational organizations, followed by professional services at 11%, government at 8%, and finance at 7%.</p><p>"The distribution likely reflects broad Microsoft Teams adoption across these industries, rather than deliberate targeting," the researchers said. "This suggests the attacker’s primary objective was to exploit a trusted collaboration platform at scale, rather than focus on specific verticals."</p><p>Two-thirds of victims were in the US, with 16% in Europe and 6% in Asia. </p><h2 id="microsoft-teams-scams-are-surging">Microsoft Teams scams are surging</h2><p>Microsoft Teams, and indeed collaboration platforms and trusted brands, have become a common attack vector for cyber criminals. </p><p>This time last year, researchers at Sophos spotted <a href="https://www.itpro.com/security/cyber-attacks/hackers-are-using-microsoft-teams-to-conduct-email-bombing-attacks"><u>threat actors posing at tech support workers</u></a> to launch attacks through the platform.</p><p>More recently, the Scattered Spider hacking group <a href="https://www.itpro.com/security/ransomware/the-scattered-spider-ransomware-group-is-infiltrating-slack-and-microsoft-teams-to-target-vulnerable-employees"><u>expanded this technique</u></a> by impersonating workers to ask IT teams to reset passwords or transfer MFA tokens using both Microsoft teams and Slack.</p><p>The hackers even set up fake identities and took part in company teleconferences and remediation and response calls to gather security information.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft warns of rising AitM phishing attacks on energy sector ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/microsoft-warns-of-rising-aitm-phishing-attacks-on-energy-sector</link>
                                                                            <description>
                            <![CDATA[ The campaign abused SharePoint file sharing services to deliver phishing payloads and altered inbox rules to maintain persistence ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Bt6xNvsN2W3SWsSesfhL95</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7F8eeczqdKrpFNsWATj8VL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 23 Jan 2026 11:10:09 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7F8eeczqdKrpFNsWATj8VL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft logo illuminated on the side of a building a night time in Tromso, Norway.]]></media:description>                                                            <media:text><![CDATA[Microsoft logo illuminated on the side of a building a night time in Tromso, Norway.]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft logo illuminated on the side of a building a night time in Tromso, Norway.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7F8eeczqdKrpFNsWATj8VL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The energy sector should be on the alert for a new multi‑stage <a href="https://www.itpro.com/security/cyber-crime/adversary-in-the-middle-attacks-are-becoming-hackers-go-to-method-to-bypass-mfa">adversary‑in‑the‑middle (AitM)</a> campaign, Microsoft has warned.</p><p>Cloud collaboration platforms, particularly Microsoft SharePoint and OneDrive, are popular with threat actors thanks to their widespread presence in enterprise environments. </p><p>They offer built-in legitimacy, flexible file‑hosting capabilities, and authentication flows that attackers can take over and use to hide their presence. </p><p>This latest <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>and <a href="https://www.itpro.com/security/cyber-attacks/what-is-business-email-compromise-bec">business email compromise (BEC)</a> campaign, <a href="https://www.microsoft.com/en-us/security/blog/2026/01/21/multistage-aitm-phishing-bec-campaign-abusing-sharepoint/" target="_blank">Microsoft said</a>, abused SharePoint file sharing services to deliver phishing payloads. Emails with the subject line “NEW PROPOSAL – NDA” appeared legitimate, coming from a previously-compromised email address belonging to a trusted organization. </p><p>A number of user accounts have already been compromised, according to the Microsoft Defender Research team. </p><p>Victims clicking on a link included in the email were redirected to a fake login page, which collected their credentials. The attackers also altered inbox rules to mark all emails as "read", making their activity harder to detect. </p><p>They were then able to make use of trusted internal identities from the target to conduct large‑scale phishing attacks, both within the organization and externally, significantly expanding the scope of the campaign. </p><p>In one example, this phishing campaign involved more than 600 emails with a different phishing URL, which were sent to the compromised user’s contacts within and outside the organization, as well as distribution lists. </p><p>The attackers then made further efforts to avoid suspicion.</p><p>"The attacker read the emails from the recipients who raised questions regarding the authenticity of the phishing email and responded, possibly to falsely confirm that the email is legitimate," said the Microsoft team. </p><p>"The emails and responses were then deleted from the mailbox. These techniques are common in any BEC attacks and are intended to keep the victim unaware of the attacker’s operations, thus helping in persistence."</p><h2 id="tackling-adversary-in-the-middle-attacks">Tackling adversary-in-the-middle attacks </h2><p>Microsoft highlighted the operational complexity of AiTM campaigns, saying that password resets alone are not enough to fix the problem. </p><p>Impacted organizations must, said the firm, make sure that they've revoked active session cookies, reversed the changes to MFA settings made by the attacker on the compromised user’s accounts and removed the altered inbox rules. </p><p>"While AiTM phishing attempts to circumvent <a href="https://www.itpro.com/security/cyber-attacks/how-hackers-bypass-mfa-and-what-to-do-about-it">MFA</a>, implementation of MFA still remains an essential pillar in identity security and highly effective at stopping a wide variety of threats. </p><p>MFA is the reason that threat actors developed the AiTM session cookie theft technique in the first place," the team said.</p><p>The researchers also advised organizations to work with their identity provider to ensure security controls like MFA are in place. </p><p>They added: "Organizations should also consider complementing MFA with conditional access policies, where sign-in requests are evaluated using additional identity-driven signals like user or group membership, IP location information, and device status, among others." </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Warning issued as surge in OAuth device code phishing leads to M365 account takeovers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/warning-issued-as-surge-in-oauth-device-code-phishing-leads-to-m365-account-takeovers</link>
                                                                            <description>
                            <![CDATA[ Successful attacks enable full M365 account access, opening the door to data theft, lateral movement, and persistent compromise ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KvYoW3sdJ4wDkctJHg82bk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cH6m7NRbNRSksBtYe4xHVH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 22 Dec 2025 10:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cH6m7NRbNRSksBtYe4xHVH-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft 365 logo pictured on a smartphone with Microsoft logo pictured in background.]]></media:description>                                                            <media:text><![CDATA[Microsoft 365 logo pictured on a smartphone with Microsoft logo pictured in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft 365 logo pictured on a smartphone with Microsoft logo pictured in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cH6m7NRbNRSksBtYe4xHVH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/28133/what-is-cyber-security">Cybersecurity </a>researchers at Proofpoint have issued a warning over a surge in Microsoft 365 account takeovers through <a href="https://www.itpro.com/security/369985/hackers-target-business-cloud-abusing-microsofts-verified-publisher-status">abuse of OAuth</a> device code authorization.</p><p>This legitimate Microsoft login process is now being weaponized by both cyber criminal and state-aligned actors, who are tricking users into entering a device code on Microsoft’s real login page - instantly granting unauthorized access.</p><p>Proofpoint said the trend signals a major evolution in phishing, shifting attacks away from passwords and towards abusing trusted authentication flows.</p><p>Attacks start with an initial message containing a URL embedded behind a button, as hyperlinked text, or within a <a href="https://www.itpro.com/security/hackers-are-stepping-up-qishing-attacks-by-hiding-malicious-qr-codes-in-pdf-email-attachments">QR code</a>. Once visited, it initiates an attack sequence leveraging the legitimate Microsoft device authorization process. </p><p>The user is presented with a device code with the claim that it's a one-time password (OTP). The user is directed to input the code at Microsoft’s verification URL - and once this is done, the original token is validated, giving the threat actor access to the targeted <a href="https://www.itpro.com/desktop-software/19337/office-365-review">Microsoft 365</a> account.  </p><p>"While this is not necessarily a novel technique, it is notable to see it used increasingly by multiple threat clusters including a tracked cybercriminal threat actor, TA2723," the researchers said. </p><p>"Proofpoint threat researchers have identified a malicious application for sale on hacking forums, which could be used for this type of campaign."</p><p>Meanwhile, some red team tools, such as Squarephish and SquarephishV2, can be used for this type of attack, helping to mitigate the short-lived nature of device codes and enabling larger campaigns than were previously possible. </p><p>In one example, researchers identified a campaign that used a shared document reminder alert to trick users into clicking a Google Share URL hyperlinked as text, to access a fictitious document called “Salary Bonus + Employer Benefit Reports 25”. </p><p>The URL leads to an attacker-controlled website with a domain localized according to browsing IP, and showing the targeted company branding. </p><p>Thereafter, the website prompts the user to input their email address and go through an authentication process that includes a code that, when input into the Microsoft-provided OAuth page, gives the threat actor access to the user’s Microsoft 365 account.</p><p>Proofpoint ascribes this activity to TA2723, a financially-motivated, high-volume credential <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>threat actor notable for its campaigns spoofing Microsoft OneDrive, LinkedIn, and DocuSign. It's seen the group conducting OAuth device code phishing since October. </p><p>But the technique is in use by other state-aligned actors, too, including UNK_AcademicFlare. </p><p>Since September, the Russia-linked group has been using compromised email addresses belonging to multiple government and military organizations to target bodies within government, think tanks, and the higher education and transportation sectors in the US and Europe. </p><p>Earlier this year, Volexity <a href="https://www.volexity.com/blog/2025/02/13/multiple-russian-threat-actors-targeting-microsoft-device-code-authentication/" target="_blank"><u>said</u></a> it had identified several campaigns using the same techniques and carried out by Russian actors. </p><p>The company said it believed that at least one was CozyLarch - overlapping with DarkHalo, APT29, <a href="https://www.itpro.com/security/cyber-attacks/sneak-and-peek-midnight-blizzard-attack-highlights-worrying-flaws-in-microsoft-security-processes">Midnight Blizzard,</a> and CozyDuke. It said it was tracking the remaining activity under UTA0304 and UTA0307.</p><p>Proofpoint expects the abuse of OAuth authentication flows to continue to grow, with the adoption of FIDO compliant MFA controls. Organizations should strengthen their OAuth controls and educate users about these evolving threats. </p><p>"From the use of malicious OAuth applications for persistent access to the abuse of legitimate Microsoft authentication flows with device codes, "threat actors’ tactics to achieve account takeover are evolving with quick adoption across the threat landscape," the researchers said.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Amazon CSO Stephen Schmidt says the company has rejected more than 1,800 fake North Korean job applicants in 18 months – but one managed to slip through the net ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/amazon-cso-stephen-schmidt-says-the-company-has-rejected-more-than-1-800-fake-north-korean-job-applicants-in-18-months-but-one-managed-to-slip-through-the-net</link>
                                                                            <description>
                            <![CDATA[ Analysis from Amazon highlights the growing scale of North Korean-backed "fake IT worker" campaigns ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gyGFEr784jSEooH59LhWxb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3Tm7p8bfs26mzt83tSMjwC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 22 Dec 2025 08:57:02 +0000</pubDate>                                                                                                                                <updated>Mon, 22 Dec 2025 08:57:52 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/3Tm7p8bfs26mzt83tSMjwC-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Amazon senior vice president and chief security officer (CSO) Stephen Schmidt pictured speaking on stage during the HumanX AI Conference 2025 at Fontainebleau Las Vegas.]]></media:description>                                                            <media:text><![CDATA[Amazon senior vice president and chief security officer (CSO) Stephen Schmidt pictured speaking on stage during the HumanX AI Conference 2025 at Fontainebleau Las Vegas.]]></media:text>
                                <media:title type="plain"><![CDATA[Amazon senior vice president and chief security officer (CSO) Stephen Schmidt pictured speaking on stage during the HumanX AI Conference 2025 at Fontainebleau Las Vegas.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3Tm7p8bfs26mzt83tSMjwC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Amazon has had hundreds of fraudulent job applications from North Korean threat actors since April last year, with the company uncovering one successful campaign internally.</p><p>According to <a href="https://www.itpro.com/security/34049/how-to-build-a-comprehensive-cyber-security-strategy">chief security officer (CSO)</a> Stephen Schmidt, the company has prevented more than 1,800 suspected DPRK operatives from joining since April 2024, and has detected 27% more DPRK-affiliated applications quarter over quarter this year.</p><p>“Over the past few years, North Korean (DPRK) nationals have been attempting to secure remote IT jobs with companies worldwide, particularly in the U.S,” Schmidt wrote in a <a href="https://www.linkedin.com/posts/stephenschmidt1_over-the-past-few-years-north-korean-dprk-activity-7407485036142276610-dot7/" target="_blank"><u>post on LinkedIn</u></a>. </p><p>“Their objective is typically straightforward: get hired, get paid, and funnel wages back to fund the regime's weapons programs.”</p><p>With this number of fraudulent applications, Schmidt said the company has a good insight into how these threats are evolving, and there are several notable areas of interest for enterprise security teams. </p><h2 id="north-korean-hackers-are-refining-tactics">North Korean hackers are refining tactics</h2><p>First and foremost, identity theft has become more calculated, Schmidt said, with operatives targeting individual software engineers who provide real credibility, rather than people with minimal online presence.</p><p>Operatives involved in these campaigns often work with facilitators managing “laptop farms”, Schmidt added. US locations that receive shipments and maintain domestic presence, while the worker operates remotely from outside the country.</p><p>LinkedIn strategies are also getting more sophisticated, with the fraudsters hijacking dormant accounts through compromised credentials to gain verification. </p><p>"We've also identified networks where people hand over access to their accounts in exchange for payment," he said.</p><p>Research shows LinkedIn has become a prime hunting ground for cyber criminals, with <a href="https://www.itpro.com/security/cyber-crime/hackers-are-using-a-linkedin-recruitment-scam-to-snare-unsuspecting-jobseekers"><u>analysis by Clear Sky Security</u></a> in late 2024 showing hackers are using the professional networking app to both target victims and build an online presence. </p><p>A more recent <a href="https://www.itpro.com/security/cyber-attacks/linkedin-social-engineering-attacks"><u>study from Bitdefender Labs</u></a> also highlighted the growing threats enterprises face through the platform, uncovering an Iranian-linked campaign which took inspiration from previous North Korean efforts.  </p><p>Notably, Schmidt warned threat actors are increasingly targeting <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI </a>and <a href="https://www.itpro.com/strategy/28071/what-is-machine-learning">machine learning</a> roles, both of which are growing in demand as companies ramp up adoption of the technology.</p><h2 id="one-hacker-slipped-through-the-cracks">One hacker slipped through the cracks</h2><p>The company admitted that one imposter did manage to slip through the cracks in a recent campaign, however. </p><p>According to reports from <a href="https://www.bloomberg.com/news/newsletters/2025-12-17/amazon-caught-north-korean-it-worker-by-tracing-keystroke-data" target="_blank"><u><em>Bloomberg</em></u></a>, the company discovered a fake systems development contractor by tracking keystroke inputs. </p><p>Security teams at the retail giant observed significant keystroke lag which raised the alarm. Typically, a US-based remote worker would record keystroke data within several milliseconds. </p><p>In this instance, however, the worker’s keystroke lag stood at “more than 110 milliseconds”, suggesting they were based outside the country. </p><p>Amazon isn't alone in falling prey to hackers involved in these campaigns. Last year, <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>firm <a href="https://www.itpro.com/security/cyber-firm-knowbe4-unknowingly-hired-a-north-korean-hacker-and-it-went-exactly-as-you-might-think">KnowBe4 inadvertently hired a North Korean hacker</a> in an incident which prompted an overhaul of hiring processes at the company. </p><p>The individual managed to pass background checks, but were discovered after they began loading <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a> shortly after receiving their <a href="https://www.itpro.com/security/mac-endpoint-protection">Mac</a> workstation.</p><h2 id="north-korean-threats-will-continue">North Korean threats will continue</h2><p>Repeated warnings have been issued over the threats posed by North Korean threat actors over the last 18 months. Attack methods have shifted rapidly, with operators choosing to infiltrate enterprises to wreak havoc with malware and to extract valuable intellectual property. </p><p>Earlier this year, the FBI <a href="https://www.itpro.com/security/fbi-issues-guidance-for-enterprises-as-fake-north-korean-it-workers-wreak-havoc"><u>issued guidance</u></a> on how to avoid the scam, urging organisations to practice the principle of least privilege and ramp up monitoring and investigation of network traffic. </p><p>More recently, Google <a href="https://www.itpro.com/security/google-warns-that-fake-north-korean-it-workers-have-expanded-to-europe"><u>warned</u></a> that fake North Korean workers were now popping up in increasing numbers in Europe, using online recruitment platforms including Upwork, Telegram, and Freelancer. They've also been carrying out more extortion attempts and targeting larger organizations.</p><p>"If you’re concerned about these threats in your organization, query your databases for common indicators: patterns in resumes, emails, phone numbers, educational backgrounds," advised Schmidt. </p><p>"Implement identity verification at multiple hiring stages and monitor for anomalous technical behavior: unusual remote access, unauthorized hardware. If you identify suspected DPRK IT workers, report it to the FBI or your local law enforcement."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Complacent Gen Z and Millennial workers are more likely to be duped by social engineering attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/complacent-gen-z-and-millennial-workers-are-more-likely-to-be-duped-by-social-engineering-attacks</link>
                                                                            <description>
                            <![CDATA[ Overconfidence and a lack of security training are putting organizations at risk ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">487j6euuWzVzHbTfjp59jF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QGJdnzL5ujgBmZvWfYVyk7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 16 Dec 2025 11:00:35 +0000</pubDate>                                                                                                                                <updated>Tue, 16 Dec 2025 11:01:19 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QGJdnzL5ujgBmZvWfYVyk7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ethical hacker concept image showing hands of a female pentester typing on a laptop keyboard.]]></media:description>                                                            <media:text><![CDATA[Ethical hacker concept image showing hands of a female pentester typing on a laptop keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Ethical hacker concept image showing hands of a female pentester typing on a laptop keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QGJdnzL5ujgBmZvWfYVyk7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>While most workers believe they can spot a <a href="https://www.itpro.com/security/cyber-attacks/phishing-tactics-the-top-attacks-trends-in-year">phishing attempt</a>, nearly one-in-four under-35s would fall for a suspicious message if they thought it came from a colleague or boss.</p><p>Four-in-five British workers told Accenture researchers they were confident they'd spot a suspicious message, even though more than a third have never received <a href="https://www.itpro.com/security/cyber-security/354950/10-ways-to-get-employees-invested-in-cyber-security-awareness">cybersecurity training</a>. </p><p>Men show the biggest faith in themselves, being nearly twice as likely as women to report high confidence in spotting cyber threats, at 22% compared with 12%.</p><p>But younger workers in particular may be wrong about this. The survey of over 1,000 British employees found that 15% would share company data or make payments via messaging apps, without verifying the sender, if the message seemed to come from a leader or colleague. </p><p>Among under-35s, so those in the millennial and Gen Z demographics, this rose to nearly a quarter (24%).</p><p>“With cyber criminals weaponizing information from social media to deceive people with realistic messages or calls, employees must make faster judgement calls on what’s real and what’s not," said Kamran Ikram, Accenture’s security lead in the UK and Ireland. </p><p>"The workforce feels cyber confident – though its uneven among men and women – there remains a serious skills and training gap across the board. Being overconfident yet undertrained is a dangerous position to be in."</p><h2 id="more-cybersecurity-training-is-needed">More cybersecurity training is needed</h2><p>Notably, more than one-third (37%) of British workers have never received any <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>training, including 44% of over-55s. Meanwhile, only one-in-five have been trained to recognize <a href="https://www.itpro.com/security/preventing-deepfake-attacks-how-businesses-can-stay-protected">deepfakes </a>or AI-generated phishing emails. </p><p>This lack of training is more significant in smaller companies, where 79% of microbusinesses with less than 10 employees and 55% of small firms with between 10 and 49 employees offer no cybersecurity training at all.</p><p>"Organizations must look to be resilient in every area of their operations and supply chain, which means ongoing education on cyber threats," said Ikram. "Businesses can’t rely on patchy preparedness when attackers are advancing by the day.”</p><p>Even when employees are receiving training, it's not adequately covering all the risks, Accenture found. Half of those that have been trained said they've received no guidance on <a href="https://www.itpro.com/technology/artificial-intelligence/office-workers-lack-the-skills-to-use-generative-ai-tools-safely-and-accurately">using AI safely</a>, such as what data should not be shared with public tools or how to identify AI-enabled attacks.</p><p>As a result, 17% have no awareness of <a href="https://www.itpro.com/security/microsoft-the-uk-is-woefully-unprepared-for-future-ai-cyber-threats">AI-driven cyber threats</a> while only 61% are aware of deepfake videos or AI-generated phishing emails, and fewer than half are aware of voice cloning or identity theft.</p><p>“AI is bringing immense opportunity to business, but it also is changing the risk landscape as criminals increasingly incorporate AI into their arsenal," said Ikram. </p><p>"Today, awareness of AI-enabled attacks is still uneven, and that gap is where the next wave of breaches will likely happen. But more than that - building a cyber-savvy workforce isn’t just about protecting your systems, it’s also what allows innovation and trust to scale together.”</p><p>Workers do at least have a sense of collective responsibility. While a quarter of British employees believe that the IT or security department is most responsible for protecting a company against cyber threats, more than twice as many accept that it's a joint responsibility across the organization.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/is-sector-cyber-awareness-crisis-workforce">Are we in a cyber awareness crisis?</a></li><li><a href="https://www.itpro.com/security/phishing/employee-phishing-training-is-working-but-dont-get-complacent">Employee phishing training is working – but don’t get complacent</a></li><li><a href="https://www.itpro.com/business-strategy/careers-training/358117/the-top-online-cyber-security-courses">Best online cyber security courses</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are abusing ConnectWise ScreenConnect, again ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/watch-out-for-fake-zoom-invites-hackers-are-abusing-connectwise-screenconnect-to-take-over-devices</link>
                                                                            <description>
                            <![CDATA[ A new spear phishing campaign has targeted more than 900 organizations with fake invitations from platforms like Zoom and Microsoft Teams. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aufhxNMDzjp8GwNMjv2ojN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iLr5eH4Tgk7GAiwMDELMzG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 28 Aug 2025 10:10:00 +0000</pubDate>                                                                                                                                <updated>Thu, 28 Aug 2025 11:34:51 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iLr5eH4Tgk7GAiwMDELMzG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing email attack concept image showing email with warning symbol on a laptop screen with a fishing hook attached.]]></media:description>                                                            <media:text><![CDATA[Phishing email attack concept image showing email with warning symbol on a laptop screen with a fishing hook attached.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing email attack concept image showing email with warning symbol on a laptop screen with a fishing hook attached.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iLr5eH4Tgk7GAiwMDELMzG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A new spear phishing campaign has targeted more than 900 organizations with fake invitations from platforms like Zoom and Microsoft Teams.</p><p>Analysis from Abnormal.ai shows the campaign involves tricking victims into downloading legitimate remote monitoring and management (RMM) software such as ConnectWise ScreenConnect. </p><p>Thereafter, attackers are able to assume control of end-user devices and extract sensitive information. </p><p>"To manipulate targets into engaging and downloading ScreenConnect, the attackers employ advanced deception techniques built around impressive impersonations and familiar business contexts, effectively creating workflows that align with end-user expectations," researchers said.</p><p>"Specific tactics observed include the utilization of compromised legitimate email accounts, AI-generated phishing components, and strategic URL obfuscation methods, as well as the exploitation of trusted business tools such as file-sharing platforms for hosting malicious links."</p><p>Initial access comes via phishing emails from compromised accounts, disguised as meeting invitations via trusted entities like Zoom and Microsoft Teams. </p><p>Researchers noted the threat actors also incorporate various themes to make these invitations look legitimate, for example, "Meeting Invite - 2024 Tax Organizer".</p><p>Targets are then tricked into installing ScreenConnect through AI-generated landing pages, legitimate file-sharing platforms, direct session links, or executable email attachments.</p><p>Once installed, ScreenConnect gives the attackers remote access capabilities that enable comprehensive system control equivalent to direct access while avoiding detection due to minimal signal activity.</p><p>Attackers then leverage compromised systems for account takeover, including lateral phishing campaigns and credential harvesting. They often use the targetʼs email accounts to target colleagues and business partners with the same techniques.</p><p>"This campaign represents a significant evolution in cybercrime tactics," the researchers said.</p><p>"The weaponization of a legitimate IT administration tool — one designed to grant IT professionals deep system access for troubleshooting and maintenance — combined with <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> and convincing business impersonation creates a multi-layered deception that provides attackers with the dual advantage of trust exploitation and security evasion."</p><h2 id="how-to-stay-safe">How to stay safe</h2><p>Researchers pointed out that the sophisticated and resilient infrastructure supporting these attacks implies a mature criminal ecosystem, with dark web vendors operating like legitimate software providers. </p><p>"The commoditization of advanced attack capabilities —driven by bad actors who profit from widespread tool adoption — has democratized complex cybercrime operations and poses an escalating threat to organizations across all sectors, particularly those with legacy security infrastructure or limited security awareness programs," they said.</p><p>The attackers don't appear to be targeting any particular sector, with a fairly even spread across industries. Most victims were based in the US, with Canadian, Australian and UK organizations also affected.</p><p><a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISOs </a>should deploy AI-powered email security solutions capable of detecting complex <a href="https://www.itpro.com/security/a-new-silent-social-engineering-attack-is-being-used-by-hackers-and-your-security-systems-might-not-notice-until-its-too-late">social engineering</a> attacks that bypass traditional security controls, and establish comprehensive monitoring for legitimate remote access tools, focusing on unauthorized installations and suspicious usage patterns.</p><p>Similarly, researchers urged enterprises to update training programs to address evolving tactics and implement network segmentation and access controls to limit the potential impact of compromised systems with remote access capabilities.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/ransomware/hackers-are-targeting-windows-quick-assist-remote-desktop-features-to-deploy-ransomware">Hackers are targeting Windows Quick Assist remote desktop features to deploy ransomware</a></li><li><a href="https://www.itpro.com/security/ransomware/the-scattered-spider-ransomware-group-is-infiltrating-slack-and-microsoft-teams-to-target-vulnerable-employees">The Scattered Spider ransomware group is infiltrating Slack and Microsoft Teams to target vulnerable employees</a></li><li><a href="https://www.itpro.com/security/clickfix-social-engineering-state-sponsored-hackers">State-sponsored cyber groups are flocking to the 'ClickFix' social engineering technique</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The Allianz Life data breach just took a huge turn for the worse ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/allianz-life-data-breach-customer-accounts-impacted</link>
                                                                            <description>
                            <![CDATA[ Around 1.1 million Allianz Life customers are believed to have been impacted in a recent data breach, making up the vast majority of the insurer's North American customers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ADG2qEJ4qjUX9B5Uh9ZWSX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WyQDsXrph78RGRusAv8L7g-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 20 Aug 2025 10:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WyQDsXrph78RGRusAv8L7g-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo of Allianz, parent company of Allianz Life, pictured in Berlin city center.]]></media:description>                                                            <media:text><![CDATA[Logo of Allianz, parent company of Allianz Life, pictured in Berlin city center.]]></media:text>
                                <media:title type="plain"><![CDATA[Logo of Allianz, parent company of Allianz Life, pictured in Berlin city center.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WyQDsXrph78RGRusAv8L7g-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The true scale of the Allianz Life data breach has been laid bare, with leaked credential notification site <em>Have I Been Pwned</em> putting the number of affected accounts at 1.1 million.</p><p>The numbers represent the vast majority of the company's  1.4 million customers in the North America region, along with the data of financial professionals and some Allianz Life employees contained in Salesforce Accounts and Contacts databases.</p><p>Data exposed in the incident is <a href="https://haveibeenpwned.com/Breach/AllianzLife" target="_blank"><u>believed to include</u></a> dates of birth, email addresses, genders, names, phone numbers, and physical addresses. According to Allianz, Social Security numbers were also taken.</p><p>More than seven-in-ten of the exposed email addresses had already been affected by previously-disclosed data breaches. </p><p>When the <a href="https://www.itpro.com/security/data-breaches/everything-we-know-about-the-allianz-life-data-breach-so-far">breach was first confirmed</a>, Allianz Life said that 'most' of its North American customers had been affected, but that its core network and policy administration systems didn't appear to have been accessed.</p><p>The insurer said it would provide a full consumer notice once it has finished identifying and contacting affected individuals.</p><p>Jon Abbott, CEO of ThreatAware, described the scale of the breach as “significant”, noting that the data leaked represents a treasure trove of information to target victims. </p><p>"The sensitive and valuable information held in CRM tools is exactly why it’s targeted by attackers,” he said. “The data can be used by other cyber criminals for identity theft and <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaigns."</p><h2 id="what-happened-with-the-allianz-life-data-breach">What happened with the Allianz Life data breach?</h2><p>The breach, which took place on July 16 and was discovered a day later, is believed to have involved a <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> attack that involved impersonating IT support staff.</p><p>This saw hackers ask employees to accept a connection to a Salesforce Data Loader, which was then used to exfiltrate data from the <a href="https://www.itpro.com/desktop-software/28214/what-is-crm">CRM </a>system. </p><p>The attackers used malicious OAuth applications to infiltrate Salesforce instances, before downloading the company databases.</p><p>The attack has since been claimed by <a href="https://www.itpro.com/security/hacking/369967/us-extradites-french-shinyhunters-hacker-faces-123-years-in-prison">the notorious ShinyHunters threat group</a>, which is believed to overlap with the <a href="https://www.itpro.com/security/cyber-crime/scattered-spider-group-marks-and-spencer">Scattered Spider</a> and Lapsus groups. They are now believed to be preparing a data leak site to pressure Allianz and other victims into making a ransom payment.</p><p>The group, which first emerged in 2020, is also believed to be responsible for attacks on Salesforce systems at several retailers, as well as at <a href="https://www.itpro.com/security/cyber-attacks/google-cyber-researchers-were-tracking-the-shinyhunters-groups-salesforce-attacks-then-realized-theyd-fallen-victim">Google</a>, Cisco, <a href="https://www.itpro.com/security/cyber-attacks/qantas-cyber-attack-six-million-customers-exposed">Qantas</a>, Santander, Ticketmaster, Tokopedia, AT&T and most recently Workday. </p><p><a href="https://www.itpro.com/security/data-breaches/workday-data-breach-what-we-know-so-far">Workday confirmed it had fallen victim to an attack</a> last week, warning customers that exposed information could then be used in follow-up social engineering attacks - a common tactic for threat actors. </p><p>"Groups such as ShinyHunters rely on fast moving social engineering tactics – this typically involves calling and emailing employees of the victim organization and attempting to extort them. If this does not work, they then launch a leak site with the aim of pressuring victims into payment," said Abbott.</p><p>"This pattern in their attacks is why the security fundamentals are so important. Accurate asset inventories, tamper-proof identity verification and hardened service desk processes are all essential.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/phishing/employee-phishing-training-is-working-but-dont-get-complacent">Employee phishing training is working – but don’t get complacent</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/phishing-tactics-the-top-attacks-trends-in-year">Phishing tactics: The top attack trends</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/phishing-kits-cyber-crime-dark-web">Cheap cyber crime kits can be bought on the dark web for less than $25</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A new, silent social engineering attack is being used by hackers – and your security systems might not notice until it’s too late ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/a-new-silent-social-engineering-attack-is-being-used-by-hackers-and-your-security-systems-might-not-notice-until-its-too-late</link>
                                                                            <description>
                            <![CDATA[ Security researchers have warned the 'FileFix' technique, which builds on the notorious 'ClickFix' tactic, is being used in the wild by threat actors. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VvF4D4ZKrsTsygTTsZZexn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PTMwqLuzdRt65NSfijHDcL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Jul 2025 10:41:29 +0000</pubDate>                                                                                                                                <updated>Thu, 17 Jul 2025 10:41:48 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ jane.mccallion@futurenet.com (Jane McCallion) ]]></author>                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Wq9nnLr7TNkY8gyBRb7YsA.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Jane is managing editor at ITPro and ChannelPro. She started out with the brands as a staff writer specializing in cloud computing before going on to become senior writer and reports editor, managing the content and creation of ITPro’s quarterly whitepapers. During this time, she broadened her expertise to include cybersecurity, data centers and enterprise IT infrastructure. In 2016, she became features editor, managing a pool of freelance and internal writers, while continuing to specialize in enterprise IT infrastructure, data centers, and business strategy.&lt;/p&gt;&lt;p&gt;In October 2021, she became the sites’ deputy editor, before moving to the role of managing editor in June 2024. Although she now has a more strategic role,  she is still a specialist in enterprise IT infrastructure, business strategy, and cybersecurity.&lt;/p&gt;&lt;p&gt;Jane holds an MA in journalism from Goldsmiths, University of London, and a BA in Applied Languages from the University of Portsmouth. She is fluent in French and Spanish, and has written features in both languages.&lt;/p&gt;&lt;p&gt;Prior to joining ITPro, Jane was a freelance business journalist writing as both Jane McCallion and Jane Bordenave for titles such as European CEO, World Finance, and Business Excellence Magazine.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PTMwqLuzdRt65NSfijHDcL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Woman using keyboard with illuminated keys in a darkened room.]]></media:description>                                                            <media:text><![CDATA[Woman using keyboard with illuminated keys in a darkened room.]]></media:text>
                                <media:title type="plain"><![CDATA[Woman using keyboard with illuminated keys in a darkened room.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PTMwqLuzdRt65NSfijHDcL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/28133/what-is-cyber-security">Cybersecurity </a>researchers at Check Point have identified a new, insidious <a href="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business">social engineering</a> technique that requires almost no user interaction.</p><p>The FileFix technique builds on an already widely used tactic called <a href="https://www.itpro.com/security/clickfix-social-engineering-state-sponsored-hackers">ClickFix</a>, which <a href="https://blog.checkpoint.com/research/filefix-the-new-social-engineering-attack-building-on-clickfix-tested-in-the-wild/" target="_blank"><u>according to Check Point</u></a> tricks users into running malicious commands in the Windows Run dialog. </p><p>FileFix, meanwhile, opens a <a href="https://www.itpro.com/security/encryption/359167/how-to-encrypt-files-and-folders-in-windows-10">Windows File Explorer</a> window from a web page and surreptitiously loads a disguised <a href="https://www.itpro.com/operating-systems/microsoft-windows/356552/what-is-windows-powershell">PowerShell </a>command into their clipboard.</p><div class="product"><a data-dimension112="8f0d7a35-072d-4d11-b6cb-f2f3d38a4c63" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="8f0d7a35-072d-4d11-b6cb-f2f3d38a4c63" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="8f0d7a35-072d-4d11-b6cb-f2f3d38a4c63" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>“When the victim pastes into the Explorer address bar, the malicious command executes,” researchers explained. “This attack relies not on software vulnerabilities but on exploiting routine user actions and trust.”</p><p>The researchers added that they have now observed known bad actors using FileFix in the wild. While the payloads are currently benign, they suggest this signals “an imminent shift to delivering real malware”.</p><p>“The rapid rise of the ClickFix technique in 2025 highlights that social engineering remains one of the most cost-effective and enduring methods cyber criminals use to breach defenses,” the researchers said. </p><p>“The fact that FileFix is already being tested and used in the wild mere days after its public disclosure shows how quickly attackers adopt new techniques and adapt to the evolving cyber threat landscape.”</p><p>Commenting on the Check Point findings, Dray Agha, senior manager of security operations at cyber security firm Huntress, said: “Threat actors [are] rapidly iterating to leverage foundational Windows workflows, making defenses that much harder to deploy”.</p><p>“By tricking users into 'pasting a path,' attackers execute malicious PowerShell without triggering standard warnings,” he added. </p><p>Agha warned that Huntress has also seen FileFix being used “aggressively in the wild, and it is succeeding in tricking users in huge numbers”.</p><h2 id="how-to-protect-yourself-from-filefix">How to protect yourself from FileFix</h2><p>Check Point has laid out recommendations for security professionals to help protect against this attack, including:</p><ul><li>Monitoring phishing pages that mimic popular services and security verification screens, especially those using “Cloudflare-like” templates</li><li>Implementing and fine-tuning detection rules to flag suspicious clipboard activity or unusual PowerShell executions triggered by user actions.</li><li>Staying current with emerging social engineering trends and regularly updating user training, incident response plans, and security playbooks.</li></ul><p>It also suggests encouraging “a culture of verification”, which will lead users to confirm unexpected or unusual requests with the relevant IT or security team before acting. </p><p>Users themselves should be “highly suspicious” of any web page or email that asks them to carry out unusual activity – especially copying and pasting. </p><p>They should also be educated that legitimate websites and software “rarely require manual execution of commands to fix issues”.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/hackers-are-using-fake-tool-installers-to-dupe-victims-and-ai-tools-like-chatgpt-are-a-key-target">Hackers are using fake tool installers to dupe victims</a></li><li><a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">Why social engineering is such a problem and how your business can protect itself</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/hackers-are-using-pdfs-to-impersonate-big-brands-like-microsoft-and-docusign-in-a-new-threat-campaign">Hackers are using PDFs to impersonate big brands in a new threat campaign</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The FBI says hackers are using AI voice clones to impersonate US government officials ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/the-fbi-says-hackers-are-using-ai-voice-clones-to-impersonate-us-government-officials</link>
                                                                            <description>
                            <![CDATA[ The campaign uses AI voice generation to send messages pretending to be from high-ranking figures ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3JJQ6ioJ3wdYnc9LwVTMbm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LEn4RWFLrJ7FxZPhnQgKsP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 16 May 2025 10:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LEn4RWFLrJ7FxZPhnQgKsP-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[FBI seal and insignia pictured on the FBI headquarters building in Washington D.C., United States.]]></media:description>                                                            <media:text><![CDATA[FBI seal and insignia pictured on the FBI headquarters building in Washington D.C., United States.]]></media:text>
                                <media:title type="plain"><![CDATA[FBI seal and insignia pictured on the FBI headquarters building in Washington D.C., United States.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LEn4RWFLrJ7FxZPhnQgKsP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Had a call from a senior US official? It probably wasn't real. The FBI has issued a warning about an ongoing malicious text and voice messaging campaign in which scammers use AI-generated voices to target victims. </p><p>As part of the campaign, threats actors claim to be a senior US official in a bid to access personal accounts. The campaign began in April, according to the law enforcement agency, and it hasn't said which senior US officials are being impersonated.</p><p>AI-generated voice calls have been used in a few high profile attacks. Last year, an executive at Ferrari stymied a similar attack by asking about a book recommended by the person being impersonated. </p><p>Similarly, British engineering company Arup paid out $25 million to scammers who set up a false video call meeting to trick an employee while back in 2019 a <a href="https://www.itpro.com/social-engineering/34308/fraudsters-use-ai-voice-manipulation-to-steal-200000"><u>British energy firm</u></a> was targeted using AI-generated calls to a cost of more than £200,000.</p><p>In its advisory, the FBI said the "smishing" or "vishing" attacks, as the American policing agency called them, may be using AI tools to generate the voices. </p><p>"One way the actors gain such access is by sending targeted individuals a malicious link under the guise of transitioning to a separate messaging platform," the FBI said in a <a href="https://www.ic3.gov/PSA/2025/PSA250515" target="_blank"><u>statement</u></a>. </p><p>Once the account of one person is compromised, it can be used in future attacks. </p><p>"Access to personal or official accounts operated by US officials could be used to target other government officials, or their associates and contacts, by using trusted contact information they obtain," the FBI added. </p><p>"Contact information acquired through social engineering schemes could also be used to impersonate contacts to elicit information or funds."</p><p>The warning comes as <a href="https://www.itpro.com/security/deepfake-attacks-are-prompting-drastic-security-changes-at-enterprises"><u>68% of businesses have said</u></a> they've developed a "deepfake" response plan amid the rise in social engineering attacks, with separate research saying nearly <a href="https://www.itpro.com/security/financial-services-workers-are-facing-a-wave-of-deepfake-scams-and-its-only-going-to-get-worse"><u>two-thirds of finance professionals</u></a> had been targeted by deepfake fraud. </p><h2 id="avoiding-ai-scams">Avoiding AI scams</h2><p>The FBI warning noted that the scammers are using software to generate a phone number that isn't attributed to a specific phone. As such, anyone unsure of a message should verify the identity of the person calling with a bit of research, independently verify their correct number, and check that any information shared is correct. </p><p>However, Max Gannon, intelligence manager at Cofense, noted that threat actors can also spoof known phone numbers of trusted individuals or organizations. This, he said, adds another layer of risk for potential victims. </p><p>“Phone filtering does not typically detect when the number is being spoofed, giving a false sense of security to users who rely on their phones to tell them when something is a scam call,” he said. </p><p>When examining a video or image for signs of AI, the FBI suggested looking for subtle imperfections such as distorted hands or feet, indistinct faces, inaccurate shadows, voices matching facial movements, and other unnatural movements. </p><p>These practices could be the difference between swerving a disaster or falling victim, the agency added. However, it warned that AI-generated content has now “advanced to the point that it is often difficult to identify”.</p><p>As such, the FBI suggested people create a secret word or phrase to prove their identity, as well as the usual security advice of not trusting links or email attachments that haven't been verified. Additionally, individuals and enterprises should never send money, gift cards, or cryptocurrency to someone via the internet or phone. </p><p>"Both smishing and vishing techniques rely on social engineering to manipulate recipients, often by instilling a sense of urgency or fear," Gannon added.</p><p>"Threat actors are increasingly turning to AI to execute <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>attacks, making these scams more convincing and nearly indistinguishable from legitimate communication. For traditional phishing alone, Cofense has observed a <a href="https://tracking.us.nylas.com/l/1c295d7974ff4480905f1dd7a9f81ace/2/2c41c9dae3f171113bafa8bb059a6533ddfa96f079eadd83ad6f8e9d41fdf00f?cache_buster=1747339979" target="_blank"><u>70% increase in BEC attacks from 2023 to 2024</u></a>, which can be attributed to the increasing use of AI."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/ransomware/ransomware-attacks-reporting-fbi">Ransomware attacks are rising — but quiet payouts could mean there's more than actually reported</a></li><li><a href="https://www.itpro.com/security/preventing-deepfake-attacks-how-businesses-can-stay-protected">Preventing deepfake attacks: How businesses can stay protected</a></li><li><a href="https://www.itpro.com/security/fbi-issues-guidance-for-enterprises-as-fake-north-korean-it-workers-wreak-havoc">FBI issues guidance for enterprises as fake North Korean IT workers wreak havoc</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Employee phishing training is working – but don’t get complacent ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/employee-phishing-training-is-working-but-dont-get-complacent</link>
                                                                            <description>
                            <![CDATA[ Educating staff on how to avoid phishing attacks can cut the rate by 80% ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">37z7vZ2GgU3rttv3wGMRRe</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GXhsxEguUZLXXPu6ptYrtW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 15 May 2025 11:22:11 +0000</pubDate>                                                                                                                                <updated>Thu, 15 May 2025 11:22:17 +0000</updated>
                                                                                                                                            <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GXhsxEguUZLXXPu6ptYrtW-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing email attack concept image showing letter symbols being held by dark colored hands.]]></media:description>                                                            <media:text><![CDATA[Phishing email attack concept image showing letter symbols being held by dark colored hands.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing email attack concept image showing letter symbols being held by dark colored hands.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GXhsxEguUZLXXPu6ptYrtW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Increased <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>training is paying dividends for enterprises, according to new research, particularly in larger enterprises. </p><p>Analysis from KnowBe4 shows awareness and resilience are improving based on what it describes as ‘Phish-prone Percentage’ (PPP) metrics. This tracks the percentage of employees likely to fall for social engineering or phishing attacks, the company said. </p><p>According to the firm’s 2025 <a href="https://www.knowbe4.com/hubfs/2025-PIB-UKI-Report_EN-US.pdf"><u><em>Phishing by Industry Benchmarking Report</em></u></a>, organizations have a baseline PPP of around a third worldwide on average - but can improve that dramatically with the right training.</p><p>Globally, PPP drops on average to 19% after three months' training, and to just 4.8% after 12 months. After a year's training, all regions achieved average improvement rates of more than 80%, with North America showing the biggest improvement at 90%, and South America a close second at 89%.</p><p>The highest baseline PPPs were found in South America at 39%, North America at 37%, and Australia and New Zealand at 37%. The most phish-prone of all were organizations with 1,000-plus employees in Australia and New Zealand, with 44.6% happily clicking on simulated phishing hyperlinks. </p><p>The most cautious, meanwhile, were organizations with fewer than 249 employees in both Asia and the United Kingdom and Ireland, where fewer than a quarter of employees clicked the links.</p><p>"The <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>landscape in the UK and Ireland is rapidly evolving, driven by AI advancements, supply chain vulnerabilities, and a shift in how we view the human element in defense," said Javvad Malik, lead security awareness advocate at KnowBe4. </p><p>"AI offers both powerful tools and new risks, while supply chain security has become a critical focus due to its interconnected nature."</p><p>In the UK and Ireland, healthcare and pharmaceuticals, consumer services, and hospitality tend to have a higher initial baseline resilience to phishing attacks, especially in the case of larger organizations.</p><p>Similarly, bigger firms often start with a higher baseline, but show more substantial improvements over time. Researchers suggested this is perhaps because they can afford more comprehensive training resources.</p><p>Notably, KnowBe4 researchers said they have observed a shift in perception, with employers increasingly seeing their staff as a crucial line of defense against cyber threats.</p><p>There's also been a move away from punitive approaches to security training, with organizations now empowering employees to make security decisions and report potential threats without the fear of being penalized.</p><p>"The biggest shift is the growing recognition of employees as an essential line of defense, with organisations now fostering a culture of <a href="https://www.itpro.com/security/cyber-security/354950/10-ways-to-get-employees-invested-in-cyber-security-awareness">cybersecurity awareness</a>," said Malik. </p><p>"While progress is being made, it is clear from the data in the Benchmarking Report that sustained security training is essential to drive long-lasting change."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/malware/fake-file-converter-tools-are-on-the-rise-heres-what-you-need-to-know">Fake file converter tools are on the rise – here’s what you need to know</a></li><li><a href="https://www.itpro.com/security/phishing/device-code-phishing-storm-2372-microsoft">Hackers are using this new phishing technique to bypass MFA</a></li><li><a href="https://www.itpro.com/security/cyber-scams-cost-businesses-1-7-million-per-year-report">Cyber scams cost businesses $1.7 million per year, claims report</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Russian hackers tried to lure diplomats with wine tasting – sound familiar? It’s an update to a previous campaign by the notorious Midnight Blizzard group ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/midnight-blizzard-grapeloader-campaign</link>
                                                                            <description>
                            <![CDATA[ The Midnight Blizzard threat group has been targeting European diplomats with malicious emails offering an invite to wine tasting events, according to Check Point. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gfj5NaQ622X4dJM3a496XK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/N7Ps3tz7EftxHFVrboGb6g-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 06 May 2025 23:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/N7Ps3tz7EftxHFVrboGb6g-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wine tasting concept image showing a man holding up a glass of red wine in a cellar surrounded by barrels. ]]></media:description>                                                            <media:text><![CDATA[Wine tasting concept image showing a man holding up a glass of red wine in a cellar surrounded by barrels. ]]></media:text>
                                <media:title type="plain"><![CDATA[Wine tasting concept image showing a man holding up a glass of red wine in a cellar surrounded by barrels. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/N7Ps3tz7EftxHFVrboGb6g-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Notorious Russian threat group Midnight Blizzard has been mixing up its attack methods in recent months, according to analysis from Check Point, including targeting European diplomats with the lure of luxury events. </p><p>In a <a href="https://research.checkpoint.com/2025/apt29-phishing-campaign/" target="_blank"><u>blog post</u></a> detailing the campaign, researchers said the threat group has been targeting European governments and diplomats since January this year. </p><p>The campaign saw hackers impersonate a “major European Ministry of Foreign Affairs” and target victims with phishing emails inviting them to a wine tasting event. </p><p>Malicious emails curated by the group contained a link to deploy a backdoor dubbed ‘GRAPELOADER’, researchers added. </p><p>“The emails contained a malicious link that led, in some cases, to the download of an archive, eventually leading to the deployment of GRAPELOADER,” the blog post reads. </p><p>“In other cases, the link in the phishing emails redirects to the official website of the impersonated Ministry of Foreign Affairs.”</p><p>The malicious emails in question were sent from two distinct domains, according to Check Point - <em>bakenhof[.]com</em> and <em>silry[.]com</em> - and sought to mimic legitimate communications from a particular individual in the fake Ministry of Foreign Affairs. </p><p>When the target clicks the malicious link, this initiates the download of an archive dubbed <em>‘wine.zip’</em> which sets the next stage of attack in motion. This archive contained three files, including:</p><ul><li>A legitimate PowerPoint executable, ‘wine.exe’, which the group exploited for DLL side loading.</li><li>A hidden DLL, ,AppvIsvSubsystems64.dll’, which researchers said serves as a “required dependency for the PowerPoint executable to run</li><li>Another “hidden and heavily obfuscated” DLL, ppcore.dll, which functions as a loader and used to deliver the payload in later phases of the attack</li></ul><p>Once wine.exe is executed and the GRAPELOADER DLL is side-loaded, researchers explained the malware copies contents of the wine.zip archive to a new location on the device disk. </p><p>“It then gains persistence by modifying the Windows registry’s Run key, ensuring that wine.exe is executed automatically every time the system reboots,” the blog post noted. </p><p>“Next, GRAPELOADER collects basic information about the infected host, such as the host name and username. This collected data is then sent to the Command and Control (C2) server, where it waits for the next-stage shellcode to be delivered.”</p><h2 id="sound-familiar-you-re-not-far-off">Sound familiar? You’re not far off</h2><p>If you’re wondering why this sounds familiar, it’s because a similar campaign has already been carried out by the Midnight Blizzard. </p><p>Last year, the threat group targeted German politicians with fake invitations to a dinner reception using malware dubbed ‘WINELOADER’. This latest campaign, Check Point revealed, is a continuation of that previous flurry of attacks. </p><p>In this instance, GRAPELOADER is designed specifically for the initial stages of an attack. </p><p>“It is primarily used for fingerprinting the infected environment, establishing persistence, and retrieving the next-stage payload,” researchers said. </p><p>Detailed analysis of both show that they share a range of similarities, particularly with regard to code structure, obfuscation techniques, and string decryption processing, the company added. </p><p>Notably, Check Point revealed this particular campaign also included a new variant of WINELOADER being used in conjunction with GRAPELOADER, which suggests “codebase overlaps or shared development tactics”. </p><p>This new variant displayed improved stealth and evasion techniques, which researchers warned will muddle detection efforts. </p><h2 id="midnight-blizzard-doesn-t-quit">Midnight Blizzard doesn’t quit</h2><p>Midnight Blizzard, also known as Cozy Bear, is among the most active and aggressive threat groups operating globally. With links to the Russian government, the group has been identified as the culprit behind a raft of breaches in recent years, including an <a href="https://www.itpro.com/security/cyber-attacks/microsoft-confirms-customer-emails-were-stolen-during-midnight-blizzard-breach"><u>attack on Microsoft</u></a> which saw email communications compromised. </p><p>This particular attack saw the group reportedly use password spraying techniques to compromise a legacy account. In the wake of the incident, Microsoft revealed the group was able to access a “very small percentage” of corporate email accounts.</p><p>Some of these accounts belonged to members of the tech giant’s senior leadership team, as well as staff from its security and legal teams. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/data-breaches/hpe-midnight-blizzard-data-breach-notification">HPE alerts affected staff after Midnight Blizzard breach</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/sneak-and-peek-midnight-blizzard-attack-highlights-worrying-flaws-in-microsoft-security-processes">Sneak-and-peek Midnight Blizzard attack highlights “worrying flaws” in Microsoft security processes</a></li><li><a href="https://www.itpro.com/security/midnight-blizzard-is-on-the-rampage-again-and-enterprises-should-be-wary-of-its-new-tactics">Midnight Blizzard is on the rampage again, and enterprises should be wary of its new tactics</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This hacker group is posing as IT helpdesk workers to target enterprises – and researchers warn its social engineering techniques are exceptionally hard to spot ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/this-hacker-group-is-posing-as-it-helpdesk-workers-to-target-enterprises-and-researchers-warn-its-social-engineering-techniques-are-exceptionally-hard-to-spot</link>
                                                                            <description>
                            <![CDATA[ The Luna Moth hacker group is ramping up attacks on firms across a range of industries with its 'callback phishing' campaign, according to security researchers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">askdj8bRPN3gJq5xf8wMCL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WyQFFy6TAF7mzUvPhASUCd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 06 May 2025 11:29:54 +0000</pubDate>                                                                                                                                <updated>Tue, 06 May 2025 11:29:59 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WyQFFy6TAF7mzUvPhASUCd-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Luna Moth concept image showing cartoon mothman figure with red eyes and wings hovering against the night sky. ]]></media:description>                                                            <media:text><![CDATA[Luna Moth concept image showing cartoon mothman figure with red eyes and wings hovering against the night sky. ]]></media:text>
                                <media:title type="plain"><![CDATA[Luna Moth concept image showing cartoon mothman figure with red eyes and wings hovering against the night sky. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WyQFFy6TAF7mzUvPhASUCd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers are ramping up <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaigns involving fake helpdesk domains to target the legal, financial services, and accounting sectors in the US.</p><p>According to researchers at EclecticIQ, with the help of threat researchers Silent Push, the Luna Moth group - also known as Silent Ransom Group, UNC3753, and Storm-0252 - has carried out a flurry of 'callback phishing' attacks since March this year.</p><p>The group is believed to be linked to the 2021 BazarCall campaign, known for deploying Conti and Ryuk <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a>. However, it's recently turned its focus to data theft and extortion, threatening to expose stolen data on a dedicated leak site and demanding seven-figure ransoms.</p><p>In a <a href="https://blog.eclecticiq.com/from-callback-phishing-to-extortion-luna-moth-abuse-reamaze-helpdesk-and-rmm-tools-against-u.s.-legal-and-financial-sectors?hs_preview=uuwiUNbk-189553948704" target="_blank">blog post</a> detailing the group’s TTP’s, researchers said the campaign begins with a phishing email that lures its victim into calling a fake helpdesk number. Here, live operators posing as IT staff deceive victims into installing remote monitoring and management (RMM) tools. </p><p>These applications, which include Syncro, SuperOps, Zoho Assist, Atera, <a href="https://www.itpro.com/mobile/remote-access/368059/anydesk-review">AnyDesk</a>, and Splashtop won't be flagged by security software as they're legitimate tools, researchers noted. </p><p>However, once installed, they give the attackers access to sensitive data.</p><p>Luna Moth then threatens to leak the data publicly on its own clearweb domain unless the victims pay a ransom of between $1 million and $8 million.</p><p>In order to collect victim data, the attackers have also registered typosquatted domains via GoDaddy, impersonating US firms to collect contact details and enable targeted social engineering. </p><p>Typical examples include <em>[company_name]-helpdesk.com and [company_name]helpdesk.com.</em></p><p>"As of March 2025, EclecticIQ assesses with high confidence that Luna Moth has likely registered at least 37 domains through <a href="https://www.itpro.com/network-internet/web-hosting/368196/godaddy-web-hosting-review">GoDaddy </a>to support its callback-phishing campaigns," researchers said.</p><p>"Most of these domains impersonate <a href="https://www.itpro.com/business/is-there-any-future-for-the-it-helpdesk-ai-and-automation-could-render-it-redundant-within-three-years">IT helpdesk</a> or support portals for major US law firms and financial services firms, using typosquatted patterns."</p><p>One example impersonated a US-based law firm, with a <em>Contact Us</em> form collecting names, emails, and a message from the victim, enabling attackers to identify high-value targets. Another uses a 'CISO Helpdesk’ lure.</p><p>"By impersonating a helpdesk for <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">Chief Information Security Officers (CISOs)</a>, the phishing page leverages the authority and urgency typically associated with executive security communications," said the researchers. </p><p>"This approach is designed to increase victim compliance and maximize the chances of compromising privileged accounts within the target organization."</p><h2 id="luna-moth-tactics-are-hard-to-spot">Luna Moth tactics are hard to spot</h2><p>EclecticIQ warned that Luna Moth’s activities can be hard to spot as no malicious links or attachments appear in the phishing emails. Similarly, victims are installing signed, legitimate software themselves. </p><p>Meanwhile, few security tools can handle voice interactions and activity remains local to the infected machine and network.</p><p>"This slow-paced, trust-based approach slips past both signature-based and behavioral threat detection, revealing a critical blind spot in modern security architectures," they said.</p><p>The best strategy is to lock or restrict installations of Zoho Assist, AnyDesk, and other <a href="https://www.itpro.com/technology/choosing-an-rmm-solution-five-factors-for-msps-to-consider">RMM tools</a> unless they've been explicitly approved, researchers advised. </p><p>Organizations should track the use of RMM tools and file transfer utilities like WinSCP or Rclone for suspicious parameters and execution patterns.</p><p>They should also use email rules to flag messages from impersonated helpdesk domains, and give staff regular training on <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> to help spot spoofed invoices and verify suspicious support requests.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/hackers-are-duping-developers-with-malware-laden-coding-challenges">Hackers are duping developers with malware-laden coding challenges</a></li><li><a href="https://www.itpro.com/security/malware/fake-file-converter-tools-are-on-the-rise-heres-what-you-need-to-know">Fake file converter tools are on the rise – here’s what you need to know</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/why-government-email-servers-are-top-targets-for-state-backed-hackers">Why government email servers are top targets for state-backed hackers</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are using Zoom’s remote control feature to infect devices with malware ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hackers-are-using-zooms-remote-control-feature-to-infect-devices-with-malware</link>
                                                                            <description>
                            <![CDATA[ Security experts have issued an alert over a new social engineering campaign using Zoom’s remote control features to take over victim devices. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m5BG2PenTC4nHGhF3tsKeH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/N8h7uACYqQfmXe3eapwCRD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 24 Apr 2025 09:07:03 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/N8h7uACYqQfmXe3eapwCRD-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Silhouetted hand typing on an illuminated laptop keyboard.]]></media:description>                                                            <media:text><![CDATA[Silhouetted hand typing on an illuminated laptop keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Silhouetted hand typing on an illuminated laptop keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/N8h7uACYqQfmXe3eapwCRD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security experts have issued an alert over a new social engineering campaign using Zoom’s remote control features to take over victim devices. </p><p>In a <a href="https://blog.trailofbits.com/2025/04/17/mitigating-elusive-comet-zoom-remote-control-attacks/" target="_blank"><u>report from Trail of Bits</u></a>, researchers attributed the campaign to a cyber criminal group known as ‘Elusive Comet’, which attempted to target the company’s CEO on social media. </p><p>The campaign in question centers around abusing the video conferencing software’s remote control feature, which allows participants to take control of another users’ computer. </p><p>In a blog post detailing the CEO’s exchange with the group, the firm said the attack started with an invitation to appear on ‘Bloomberg Crypto’ as part of an interview. </p><p>These invitations were sent via social media or email, using phony email addresses mimicking official Bloomberg accounts belonging to journalists. Notably, invitations were sent via Calendly links, the company said, which are intended to lure the victim under the guise of authenticity. </p><p>“Two separate Twitter accounts approached our CEO with invitations to participate in a “Bloomberg Crypto” series—a scenario that immediately raised red flags,” the firm said in a blog post. </p><p>“The attackers refused to communicate via email and directed scheduling through Calendly pages that clearly weren’t official Bloomberg properties. These operational anomalies, rather than technical indicators, revealed the attack for what it was.”</p><p>Trail of Bits identified a number of accounts linked to the campaign and warned organizations to update monitoring systems to include these new indicators.</p><p>These included:</p><ul><li>X: @KOanhHa</li><li>X: @EditorStacy</li><li>Email: bloombergconferences[@]gmail.com</li><li>Zoom URL: https://us06web[.]zoom[.]us/j/84525670750</li><li>Calendly URL: calendly[.]com/bloombergseries</li><li>Calendly URL: calendly[.]com/cryptobloomberg</li></ul><h2 id="zoom-attack-relies-on-user-trust">Zoom attack relies on user trust</h2><p>Trail of Bits warned that with the campaign relying on a feature in a legitimate service, it could pose a serious risk to unwitting users. </p><p>Upon entering a call with the threat actors, they change display names to ‘Zoom’ to make the request “appear as a system notification”. If granted access, the attacker can assume control of the victim’s device to install <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>, exfiltrate data, or steal cryptocurrency. </p><p>“What makes this attack particularly dangerous is the permission dialog’s similarity to other harmless <a href="https://www.itpro.com/software/355486/zoom-review-are-we-alone-now">Zoom </a>notifications,” the firm said. “Users habituated to clicking “Approve” on Zoom prompts may grant complete control of their computer without realizing the implications.”</p><p>Max Gannon, Intelligence Manager at Cofense, echoed Trail of Bits’ comments on the campaign, noting that the use of legitimate software by cyber criminals has become a serious problem for enterprises. </p><p>“The malicious use of legitimate software is a growing trend we've continued to see in 2025,” he said.</p><p>“In this case, threat actors are leveraging legitimate Zoom and Calendly links to bypass security controls. As trusted domains, their use in this attack makes it more difficult to detect and block."</p><p>Analysis from Mimecast earlier this year highlighted the growing threat posed by cyber criminals using legitimate services in attack chains. In its most recent threat intelligence report, the firm flagged more than 5 billion threats in the second half of 2024 alone, with <a href="https://www.itpro.com/security/cyber-crime/threat-actors-are-leaning-on-trusted-services-more-than-ever"><u>‘living off trusted services’ (LOTS) attacks a key cause for concern</u></a>. </p><p>Also known as <a href="https://www.itpro.com/security/cyber-attacks/malware-free-attacks-threat-to-businesses"><u>malware-free attacks</u></a>, this approach is useful in helping cyber criminals circumvent authentication practices at target organizations, the study noted.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/malware/infostealer-malware-threat-to-businesses">Infostealer malware: What’s the threat to businesses?</a></li><li><a href="https://www.itpro.com/security/forget-mfa-fatigue-attackers-are-exploiting-click-tolerance-to-trick-users-into-infecting-themselves-with-malware">Forget MFA fatigue, attackers are exploiting ‘click tolerance’ to trick users into infecting themselves with malware</a></li><li><a href="https://www.itpro.com/security/malware/369299/zoom-themed-cyber-attacks-fuel-rapid-malware-growth">Zoom-themed cyber attacks fuel rapid malware growth</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ State-sponsored cyber groups are flocking to the 'ClickFix' social engineering technique ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/clickfix-social-engineering-state-sponsored-hackers</link>
                                                                            <description>
                            <![CDATA[ State-sponsored hackers from North Korea, Iran, and Russia are exploiting the ‘ClickFix’ social engineering technique for the first time – and to great success. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MbjDgvpVURk5QxAqfYAxYg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PqyG2CKVqrAxfQPt47jHN7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Apr 2025 08:23:01 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PqyG2CKVqrAxfQPt47jHN7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ClickFix social engineering technique concept image showing hand pressing a laptop keyboard button in low light.]]></media:description>                                                            <media:text><![CDATA[ClickFix social engineering technique concept image showing hand pressing a laptop keyboard button in low light.]]></media:text>
                                <media:title type="plain"><![CDATA[ClickFix social engineering technique concept image showing hand pressing a laptop keyboard button in low light.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PqyG2CKVqrAxfQPt47jHN7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>State-sponsored hackers from North Korea, Iran, and Russia are exploiting the ‘ClickFix’ <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> technique for the first time – and to great success.</p><p>Popular for some time with cyber crime groups, ClickFix is a social engineering practice that uses dialog boxes with instructions to copy, paste, and run malicious commands on the target’s machine. </p><p>The technique was first seen in early March last year, employed by initial access broker TA571 and the ClearFake cluster - but it soon spread far more widely.</p><p>According to researchers at Proofpoint, over a three-month period from the end of last year through the beginning of 2025, North Korea's TA457, Iran's TA450, and Russia's UNK_RemoteRogue and TA422 have all been making use of it.</p><p>"This creative technique not only employs fake error messages as the problem, but also an authoritative alert and instructions supposedly coming from the operating system as a solution," <a href="https://www.proofpoint.com/us/blog/threat-insight/around-world-90-days-state-sponsored-actors-try-clickfix" target="_blank"><u>said</u></a> Proofpoint.</p><p>Rather than revolutionizing their campaigns, the technique is replacing the installation and execution stages in existing infection chains. While it's currently limited to a few <a href="https://www.itpro.com/security/cyber-attacks/state-sponsored-cyber-attacks-the-new-frontier">state-sponsored groups</a>, Proofpoint said it expects the attack method to become more widely tested or adopted by threat actors.</p><p>North Korea's TA427 was first spotted using ClickFix at the beginning of this year, Proofpoint noted. The group targeted individuals in a handful of think tanks, masquerading as a Japanese diplomat and offering a meeting with the Japanese ambassador to the US, Shigeo Yamada.</p><p>Iran's TA450, meanwhile, used an attacker-controlled email address - support@microsoftonlines[.]com - to send an English-language phish to targets at more than 39 organizations in the Middle East. </p><p>They deployed the ClickFix technique by persuading the target to first run PowerShell with administrator privileges, then copy and run a command contained in the email body. Doing this installed <a href="https://www.itpro.com/business/business-operations/367876/best-network-monitoring-tools">remote monitoring software</a>, allowing the group to conduct espionage and exfiltrate data from the target’s machine.</p><h2 id="clickfix-abuse-expected-to-surge">ClickFix abuse expected to surge</h2><p>UNK_RemoteRogue has only used ClickFix once, researchers said. Notably, however, none of the aforementioned groups showed repeated use of the technique. </p><p>The security firm first hypothesized that this might be because it represented a trial period, or that the groups found the technique less successful than others for machine compromise.</p><p>With TA427 returning to ClickFix with a slightly varied infection chain in April, researchers now believe that the group is developing how it uses the ClickFix technique in its operations, and that more sightings are likely in the coming months.</p><p>One noteworthy finding from the Proofpoint research is that Chinese state-sponsored groups haven’t jumped on the bandwagon as of yet. This, researchers said, could change in the coming months. </p><p>"Given the technique’s trajectory around the world, there is a conspicuous absence in the use of ClickFix by a Chinese state-sponsored actor in Proofpoint investigations," said the firm. </p><p>"However, this is likely due to visibility, and there is a high probability that a China-nexus group has also experimented with ClickFix, given its appearance across many actors’ campaigns in a short period of time."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/the-iran-cyber-threat">The Iran cyber threat: Breaking down attack tactics</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/russia-is-targeting-unpatched-vulnerabilities-what-to-do">Russia is targeting unpatched vulnerabilities – what can tech leaders do to shore up defenses?</a></li><li><a href="https://www.itpro.com/security/cyber-crime/north-korean-insider-attacks-are-skyrocketing-dozens-of-us-firms-didnt-spot-the-hacker-in-their-midst">North Korean insider attacks are skyrocketing – dozens of US firms didn't spot the hacker in their midst</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Have I Been Pwned owner Troy Hunt’s mailing list compromised in phishing attack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/have-i-been-pwned-owner-troy-hunts-mailing-list-compromised-in-phishing-attack</link>
                                                                            <description>
                            <![CDATA[ Troy Hunt, the security blogger behind data-breach site Have I Been Pwned, has fallen victim to a phishing attack targeting his email subscriber list. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">DeZk4b24SkqhNduybCNMUS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cNZLBdbFMucebEe8kjq7di-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Mar 2025 08:30:00 +0000</pubDate>                                                                                                                                <updated>Wed, 26 Mar 2025 11:20:43 +0000</updated>
                                                                                                                                            <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ jane.mccallion@futurenet.com (Jane McCallion) ]]></author>                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Wq9nnLr7TNkY8gyBRb7YsA.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Jane is managing editor at ITPro, and its sibling titles Cloud Pro and ChannelPro. She started out with the brands as a staff writer specializing in cloud computing before going on to become senior writer and reports editor, managing the content and creation of ITPro’s quarterly whitepapers. During this time, she broadened her expertise to include cybersecurity, data centers and enterprise IT infrastructure. In 2016, she became features editor, managing a pool of freelance and internal writers, while continuing to specialize in enterprise IT infrastructure, data centers, and business strategy.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;In October 2021, she became the sites’ deputy editor, before moving to the role of managing editor in June 2024. Although she now has a more strategic role, &amp;nbsp;she is still a specialist in enterprise IT infrastructure and business strategy.&lt;/p&gt;
&lt;p&gt;Jane holds an MA in journalism from Goldsmiths, University of London, and a BA in Applied Languages from the University of Portsmouth. She is fluent in French and Spanish, and has written features in both languages.&lt;/p&gt;
&lt;p&gt;Prior to joining ITPro, Jane was a freelance business journalist writing as both Jane McCallion and Jane Bordenave for titles such as European CEO, World Finance, and Business Excellence Magazine.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cNZLBdbFMucebEe8kjq7di-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing concept image showing an email symbol with fishing hook.]]></media:description>                                                            <media:text><![CDATA[Phishing concept image showing an email symbol with fishing hook.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing concept image showing an email symbol with fishing hook.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cNZLBdbFMucebEe8kjq7di-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Troy Hunt, the security blogger behind data breach site <em>Have I Been Pwned</em>, has fallen victim to a <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> attack targeting his email subscriber list.</p><p>In <a href="https://www.troyhunt.com/a-sneaky-phish-just-grabbed-my-mailchimp-mailing-list/" target="_blank"><u>a blog post</u></a> disclosing the incident, Hunt described how the attack took place, with screen shots of the phishing email, which purported to come from his email marketing provider, Mailchimp.</p><p>The trap used a classic <a href="https://www.itpro.com/security/cyber-attacks/phishing-tactics-the-top-attacks-trends-in-year">phishing tactic</a> of including a button that linked to a page with a similar url to the legitimate one – mailchimp-sso.com (now deactivated) versus mailchimp.com. </p><p>Hunt, who said he was “really jet lagged and really tired” at the time entered his credentials and the <a href="https://www.itpro.com/security/cyber-crime/a-cyber-criminal-group-behind-an-mfa-bypass-operation-promised-hackers-profit-within-minutes-theyre-now-facing-lengthy-jail-sentences">one time password (OTP)</a> and the page then hung, rather than loading.</p><p>“Moments later, the penny dropped,” Hunt wrote. “I logged onto the official website, which Mailchimp confirmed via a notification email which showed my London IP address.”</p><p>“I immediately changed my password, but not before I got an alert about my mailing list being exported from an IP address in New York,” he added.</p><p>Hunt himself and others in the industry reacting to the news have said this is an example of how hackers <a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">exploit human weaknesses to carry out successful attacks</a>. </p><p>In the case of Hunt, tiredness led to lack of attention, which in turn led to him falling for a phishing scam of the kind he said he would typically have recognized early.</p><p>Erich Kron, security advocate at KnowBe4, said the incident is a prime example of how even a seasoned cybersecurity veteran can fall prey to cyber criminals. </p><p>"<a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">Social engineering</a> is largely getting the right message to the right person at the right time, and that combination can lead to unfortunate situations such as this.”</p><p>Aditi Gupta, principal security consultant at Black Duck, echoed Kron's comments, noting that bad actors deliberately "feed on fear and weaknesses such as tiredness and a sense of urgency" to bait unsuspecting users. </p><p>"This recent phishing attack further highlights that, in the end, we are all humans, and sophisticated phishing attacks could get the best of us." </p><p>Kron commended Hunt, adding that he “deserves kudos” for revealing what had happened to him and using the incident as an opportunity to educate others.</p><p>For his part, Hunt said he has gone through the usual gamut of emotions felt by someone who falls for a scam, including feeling “so stupid” and acknowledged “[his] own foolishness”. </p><p>However, he also hit out at some of Mailchimp's own practices that he claimed are poor in relation to data security. These include not offering phishing-resistant <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication">two factor authentication (2FA)</a> and not automatically deleting unsubscribed email addresses.</p><p>Hunt concluded his blog post by offering his “sincere apologies to anyone impacted by this”, but added that “on balance I think this will do more good than harm and I encourage everyone to share this experience broadly”.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/phishing/device-code-phishing-storm-2372-microsoft">Hackers are using this new phishing technique to bypass MFA</a></li><li><a href="https://www.itpro.com/security/scams/355013/10-quick-tips-for-identifying-phishing-emails">10 quick tips for identifying phishing emails</a></li><li><a href="https://www.itpro.com/security/phishing/how-hackers-are-using-legitimate-tools-to-distribute-phishing-links">How hackers are using legitimate tools to distribute phishing links</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ LinkedIn has become a prime hunting ground for cyber criminals – here’s what you need to know ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/linkedin-social-engineering-attacks</link>
                                                                            <description>
                            <![CDATA[ Cyber criminals are flocking to LinkedIn to conduct social engineering campaigns, research shows. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">s98jboyhATwa4KKMUy99tU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/czRFNitgEevSvBPszapgWG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Feb 2025 10:43:52 +0000</pubDate>                                                                                                                                <updated>Thu, 06 Feb 2025 14:35:55 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a Staff Writer at ITPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/czRFNitgEevSvBPszapgWG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Linkedin logo on a mobile phone in landscape orientation with blue linkedin background behind]]></media:description>                                                            <media:text><![CDATA[Linkedin logo on a mobile phone in landscape orientation with blue linkedin background behind]]></media:text>
                                <media:title type="plain"><![CDATA[Linkedin logo on a mobile phone in landscape orientation with blue linkedin background behind]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/czRFNitgEevSvBPszapgWG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/business-strategy/data-controller/360053/linkedin-data-breach-denial">LinkedIn</a> has emerged as a lucrative hunting ground for cyber criminals in recent years, with threat actors conducting a range of social engineering campaigns centered around fake job offers.</p><p>Last year, security company Clear Sky revealed a <a href="https://www.itpro.com/security/cyber-crime/hackers-are-using-a-linkedin-recruitment-scam-to-snare-unsuspecting-jobseekers">social engineering campaign using fraudulent LinkedIn identities</a> to trick users into downloading malware with these job offers, for example.</p><p>Led by an Iranian threat group, this particular campaign built on techniques first observed being employed by the <a href="https://www.itpro.com/security/cyber-attacks/369035/us-reclaims-30-million-in-crypto-from-lazarus-group">North Korean Lazarus group</a>.</p><p>Now, fresh details on the extent of the threat posed by the Lazarus group have been <a href="https://www.bitdefender.com/en-gb/blog/labs/lazarus-group-targets-organizations-with-sophisticated-linkedin-recruiting-scam" target="_blank">revealed</a> by Bitdefender Labs. A report from the cybersecurity firm details how one scammer approached a researcher who was able to record the tactics employed in the threat campaign.</p><p>The scammer first approached the researcher with an ‘opportunity’ to work on a decentralized <a href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining">cryptocurrency</a> exchange, claiming the final minimal viable product (MVP) was already complete and they would be employed as a front-end developer.</p><p>Bitdefender reported that once the target expressed interest in the vacancy, the scammer requested they provide a CV or personal <a href="https://www.itpro.com/open-source/31833/what-is-github">GitHub</a> repository link, which it said could be used to harvest personal data as well as make the offer appear genuine.</p><p>After these are supplied, the attacker shares a repository with the <a href="https://www.itpro.com/cloud/cloud-deployment/356937/it-pro-live-building-a-cloud-mvp">MVP</a> or the project as well as a feedback document labelled ‘Candidate Evaluation and Feedback For’, which includes questions that cannot be answered unless the target runs the demo.</p><p>Analysis of the heavily obfuscated code revealed that it dynamically loads malicious code from a third-party endpoint. Bitdefender found that the payload is a cross-platform info-stealer engineered to target a range of popular cryptocurrency wallets.</p><p>The next payload drops further dependencies designed to ensure persistence on the target system, establish command and control (C2), and <a href="https://www.itpro.com/security/malware/361009/malware-developers-create-malformed-code-signatures-to-avoid-detection">avoid detection</a>.</p><p><a href="https://www.itpro.com/business/acquisition/bitdefender-snaps-up-singapore-based-horangi-cyber-security">Bitdefender</a> said its analysis of the malware and operational tactics employed by the attacker indicated the attack was part of a larger campaign carried out by the Lazarus Group, a state-sponsored threat actor based in North Korea.</p><p>The attackers’ objectives extend beyond data theft, the report claimed, stating the group has been observed targeting victims working in sensitive sectors such as aviation, defense, and nuclear industries with the aim of exfiltrating classified information, proprietary technology, and <a href="https://www.itpro.com/security/phishing/360714/credential-theft-most-prevalent-threat-to-corporate-inboxes">corporate credentials</a>.</p><p>The group have also been recorded targeting enterprises with <a href="https://www.itpro.com/security/phishing-campaign-targets-developers-with-fake-crowdstrike-job-offers">fake job seeker</a> scams, where hackers posing as remote IT workers based in other parts of the world try to gain entry to businesses in order to establish persistence on their corporate network.</p><h2 id="how-to-protect-yourself-on-linkedin">How to protect yourself on LinkedIn</h2><p>As a professional network, it’s not out of the ordinary to receive job offers via LinkedIn. The platform has an in-built jobs board, allowing enterprises to post vacant positions.</p><p>However, when approached by an individual, it’s wise to remain vigilant and be wary of any telltale signs that you may be prey for a <a href="https://www.itpro.com/security/cyber-crime/cyber-criminal-underground-thriving-as-weekly-attacks-surge-by-75-percent-in-q3-2024">cyber criminal</a>.</p><p>Bitdefender set out a series of red flags individuals can look out for, including offers with vague descriptions of the role that do not correspond to an existing job posting on the platform.</p><p><a href="https://www.itpro.com/security/hackers-are-abusing-githubs-search-function-to-spread-malware">Suspicious repositories</a> that belong to users with ‘random names’ and lack proper documentation or a long contribution history are also strong indicators that the sender has malicious intentions.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="8Vm695nuAZyomreNYWgKoL" name="Enhance End-to-End Data Security with Microsoft SQL Server, Dell™ PowerEdge™ Servers and Windows Server 2022 (1)" caption="" alt="Enhance End-to-End Data Security with Microsoft SQL Server, Dell™ PowerEdge™ Servers and Windows Server 2022" src="https://cdn.mos.cms.futurecdn.net/8Vm695nuAZyomreNYWgKoL.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Dell)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/case-study-optimized-performance-and-energy-efficiency-in-cosmology-using-amd-genoa-cpus"><em>Safeguard sensitive information across the entire tech stack</em></a></p></div></div><p>Finally, users should also look out for spelling errors in any correspondence they have with the suspected scammer, as well as evidence of poor communication such as refusing to provide alternative contact methods.</p><p>There are also best practices Bitdefender recommends users can follow to minimize the risk they face of falling for similar scams, such as never running unverified code outside of virtual machines, sandboxes, or online code testing platforms.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/technology/artificial-intelligence/linkedin-lawsuit-ai-training-dismissed">LinkedIn just swerved a lawsuit over AI model training claims</a></li><li><a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">Why social engineering is a major issue – and how you can stay safe</a></li><li><a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">A month in the life of a social engineering expert</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Phishing campaign targets developers with fake CrowdStrike job offers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing-campaign-targets-developers-with-fake-crowdstrike-job-offers</link>
                                                                            <description>
                            <![CDATA[ Victims are drawn in with the promise of an interview for a junior developer role at CrowdStrike ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">8KsJD5vq3ieSnxtDxoyEVP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/p6mimCvEVhrkHzupt2m8sc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 13 Jan 2025 12:51:17 +0000</pubDate>                                                                                                                                <updated>Tue, 14 Jan 2025 16:40:07 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/z2aSrrbwGAyWwinHzGraAP.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a Staff Writer at ITPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;
&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2018 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;
&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/p6mimCvEVhrkHzupt2m8sc-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Envelope with job offer on the laptop screen. Workplace in office. Vector flat graphic.]]></media:description>                                                            <media:text><![CDATA[Envelope with job offer on the laptop screen. Workplace in office. Vector flat graphic.]]></media:text>
                                <media:title type="plain"><![CDATA[Envelope with job offer on the laptop screen. Workplace in office. Vector flat graphic.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/p6mimCvEVhrkHzupt2m8sc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/software/development">Developers</a> are being targeted in a new <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> campaign using fake CrowdStrike job offers, the security company has warned.</p><p>The firm <a href="https://www.crowdstrike.com/en-us/blog/recruitment-phishing-scam-imitates-crowdstrike-hiring-process/#:~:text=On%20January%207%2C%202025%2C%20CrowdStrike,recipients%20to%20a%20malicious%20website." target="_blank">noted</a> that the campaign, first identified on 7 January, uses CrowdStrike’s recruitment branding to load crypto-mining <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a> onto the victim’s systems.</p><p>The campaign begins with phishing emails purporting to be part of a recruitment process informing victims that they have reached the interview stage for a junior developer role at <a href="https://www.itpro.com/software/crowdstrike-hits-back-at-deltas-public-posturing-as-war-of-words-intensifies">CrowdStrike</a>.</p><p>Victims are redirected to a <a href="https://www.itpro.com/security/368621/hackers-hiding-malicious-links-in-top-google-search-results">malicious website</a> disguised as a legitimate CrowdStrike domain, where they are prompted to install what it describes as an employee <a href="https://www.itpro.com/marketing-comms/customer-relationship-management-crm/369039/how-customer-relationship-management">CRM</a> application to schedule the interview.</p><p>However, the ‘CRM app’ is actually a malicious <a href="https://www.itpro.com/software/microsoft/windows">Windows</a> executable written in Rust that loads the XMRig crypto miner onto their system.</p><p>XMRig is an <a href="https://www.itpro.com/software/28109/what-is-open-source">open source</a> tool used for mining cryptocurrencies such as Monero, but the tool is frequently leveraged by cybercriminals to use the computing resources of compromised machines to <a href="https://www.itpro.com/digital-currency/30249/what-is-cryptocurrency-mining">mine cryptocurrency</a> on their behalf.</p><p>The miner is configured to run in the background on the target’s machine, using “minimal <a href="https://www.itpro.com/hardware/367907/how-to-check-if-your-cpu-is-running-cool-enough">CPU</a> resources to avoid detection” CrowdStrike noted.</p><p>The firm said the campaign highlights the importance of staying vigilant against phishing attacks that target <a href="https://www.itpro.com/business/careers-and-training/half-of-jobseekers-turned-down-offers-last-year-amid-growing-demands-on-employers">jobseekers</a>, advising developers currently in the recruitment process to verify all communications with CrowdStrike and avoid downloading “unsolicited files”.</p><p>It added that CrowdStrike does not interview potential applicants via <a href="https://www.itpro.com/tag/instant-messaging">instant message</a> or <a href="https://www.itpro.com/security/31659/whatsapp-exploit-lets-hackers-manipulate-group-chat-messages">group chat</a>, and never asks candidates to download software for interviews.</p><h2 id="recruitment-space-is-a-happy-hunting-ground-for-social-engineers">Recruitment space is a happy hunting ground for social engineers</h2><p><a href="https://www.itpro.com/security/29093/what-is-phishing">Phishing campaigns</a> targeting jobseekers have become a recurring issue in the modern threat landscape, with the promise of a potential job offer often leading victims to let their guard down.</p><p>In November 2024, an investigation by Clear Sky Security highlighted one social engineering campaign using <a href="https://www.itpro.com/security/cyber-crime/hackers-are-using-a-linkedin-recruitment-scam-to-snare-unsuspecting-jobseekers">fraudulent LinkedIn identities to trick job seekers</a> looking for a role in the highly competitive aerospace industry.</p><p>Earlier that year, in February, a group tracked as Moonstone Sleet by Microsoft was observed <a href="https://www.itpro.com/security/this-new-hacker-group-is-targeting-software-developers-with-phony-job-offers-and-fake-projects">targeting software developers with a fake opportunity to work on a video game</a> <em>DeTankWar</em>, which was actually a custom malware loader.</p><p>Commenting on the recently uncovered fake CrowdStrike campaign, Chance Caldwell, senior director of the Phishing Defense Center at <a href="https://www.itpro.com/business/business-strategy/365514/cofense-moves-to-a-100-channel-sales-model">Cofense</a>, noted the focus of the campaign targeting prospects who had already applied for a role at CrowdStrike.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="TvvE5WdSJQ4L6t3FNpUL4J" name="Dell-Technologies-GettyImages-1247616181.jpg" caption="" alt="The Dell Technologies logo hanging in a conference centre" src="https://cdn.mos.cms.futurecdn.net/TvvE5WdSJQ4L6t3FNpUL4J.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Getty Images)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/infrastructure/data-centres/powerstore-resiliency"><em>Improve resiliency against cyberattacks</em></a></p></div></div><p>"While interview and job-related <a href="https://www.itpro.com/security/phishing/358706/10000-emails-hit-with-fake-fedex-and-dhl-phishing-attacks">phishing emails</a> are not uncommon, this is a very targeted campaign that goes beyond the vast majority of malicious campaigns we see with this theme,” he explained.</p><p>“The campaign uses URLs that were created to look like they might actually belong to CrowdStrike and the downloaded malware provides a pop-up that directs users to the real CrowdStrike support portal."</p><p>Caldwell added that the majority of phishing campaigns Cofense observes exhibit far less sophisticated mimicry, offering potential targets advice on how to spot a malicious <a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">social engineering</a> campaign before it’s too late.</p><p>“Most of the use cases we see are lucky to have proper branding, much less the extended work done here to really portray themselves as CrowdStrike,” he said.</p><p>“It is very unlikely that a recruiter will direct someone to download an executable as part of the <a href="https://www.itpro.com/network-internet/web-hosting/368133/hostinger-web-hosting-interview-growth-remote-working-and-more">interview</a> process. Any suspicious requests, such as this one, should be sufficiently verified before downloading anything and contact information should be verified through the legitimate company website."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Iranian hackers targeted nuclear expert, ported Windows infection chain to Mac in a week ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/iranian-hackers-targeted-nuclear-expert-ported-windows-infection-chain-to-mac-in-a-week</link>
                                                                            <description>
                            <![CDATA[ Fresh research demonstrates the sophistication and capability of state-sponsored threat actors to compromise diverse targets ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Wa6FcqEdzsGaaHytker7tT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RBmH3m9HDsh4cfAWBqaJqf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Jul 2023 09:36:20 +0000</pubDate>                                                                                                                                <updated>Thu, 06 Jul 2023 13:19:08 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ richard.speed@futurenet.com (Richard Speed) ]]></author>                    <dc:creator><![CDATA[ Richard Speed ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9i9jXkpYyoBCECh2PbJBGP.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RBmH3m9HDsh4cfAWBqaJqf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Iranian hackers: Iran flag digital distorted to denote a disruption caused by a hack]]></media:description>                                                            <media:text><![CDATA[Iranian hackers: Iran flag digital distorted to denote a disruption caused by a hack]]></media:text>
                                <media:title type="plain"><![CDATA[Iranian hackers: Iran flag digital distorted to denote a disruption caused by a hack]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RBmH3m9HDsh4cfAWBqaJqf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>New research has shown the flexibility of threat actors to rapidly iterate attack patterns in order to bypass security controls.</p><p>An investigation from security firm Proofpoint into a recent attack targeting a nuclear security expert at a US-based think tank revealed how well-resourced attackers change tactics on the fly to compromise different machines.</p><p>After realizing their initial payload wouldn’t work on a Mac, they quickly pivoted to new techniques known to work on targets who used Apple hardware.</p><p>The sophisticated operation saw skilled threat actors devise a seemingly benign email chain with the high-profile target and continue the conversation over the course of weeks to build trust and rapport, exploiting that to launch further attacks.</p><h2 id="how-the-attack-unfolded">How the attack unfolded</h2><p>The mid-May 2023 attack came from TA453, an Iranian state-affiliated threat actor, also tracked under the monikers: Charming Kitten; APT42; Mint Sandstorm; and Yellow Garuda, and saw them posing as members of the Royal United Services Institute (RUSI).</p><p>Using a multi-persona approach, the attackers - known for conducting espionage operations - started an email chain with the target seemingly seeking feedback on a project titled ‘Iran in the Global Security Context’.</p><p>The attackers sent multiple messages from different accounts, all referencing each other to generate a feeling of authenticity - a technique seen before in <a href="https://www.itpro.com/security/ransomware/361417/microsoft-exchange-servers-distribute-squirrelwaffle-malware"><u>email hijacking campaigns</u></a>.</p><p>After a single seemingly benign interaction, a malicious Google Script macro was delivered, intended to direct the target to a Dropbox URL. The URL hosted a <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers"><u>password</u></a>-encrypted .rar file, which contained a dropper masquerading as a PDF but was actually a Windows LNK file.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ovMSxaaARrLd4LYsh7bM4m" name="The Business Value of Zscaler Data Protection_listing.jpg" caption="" alt="Whitepaper cover with male and female colleague looking at, and pointing to, a digital padlock" src="https://cdn.mos.cms.futurecdn.net/ovMSxaaARrLd4LYsh7bM4m.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Zscaler)</span></figcaption></figure><p class="fancy-box__body-text"><strong>The business value of Zscaler Data Protection</strong></p><p class="fancy-box__body-text"><em>Understand how this tool minimizes the risks related to data loss and other security events</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-protection/the-business-value-of-zscaler-data-protection"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>Using <a href="https://www.itpro.com/security/exploits/368742/malware-campaigns-abuse-windows-shortcuts-bypass-macros"><u>LNK files</u></a> has been a hallmark of cyber attacks since Microsoft <a href="https://www.itpro.com/security/cyber-security/368513/microsoft-confirms-vba-macro-backtrack-is-only-temporary"><u>blocked VBA macros by default</u></a> last year. Exploiting VBA macros had for years been the go-to method for installing malware using maliciously crafted <a href="https://www.itpro.com/business-operations/productivity/368062/10-best-features-of-microsoft-365-for-small-businesses"><u>Microsoft 365</u></a> files.</p><p>Proofpoint said, “Using a .rar and LNK file to deploy malware differs from TA453’s typical infection chain of using VBA macros or remote template injection”.</p><p>“The LNK enclosed in the RAR used <a href="https://www.itpro.com/operating-systems/microsoft-windows/356552/what-is-windows-powershell"><u>PowerShell</u></a> to download additional stages from a cloud hosting provider.”</p><p>However, the target was using an Apple computer, meaning that the delivered file would not run. The file it attempted to deliver was a newly identified PowerShell-based backdoor called GorjolEcho.</p><p>Once it realized GorjolEcho would not execute on macOS, TA453 then pivoted to re-launch the attack at a later date using a ported version of the backdoor that worked on Apple hardware.</p><p>The attackers continued the same seemingly innocent email conversation with the target and roughly a week after the initial Windows-based attempt, they relaunched the attack with the Apple-ported backdoor.</p><p>In this case, the malware was delivered via a password-protected ZIP file masquerading as a RUSI <a href="https://www.itpro.com/security/27098/best-vpn-services"><u>VPN solution</u></a> and shared drive. </p><p>After some interactions with the threat actor, the user would be persuaded to open the file. A series of bash scripts would have then installed a backdoor, dubbed <em>NokNok</em>.</p><p>Proofpoint judged that this was intended to serve as a foothold for further instruction and was almost certainly a port of the PowerShell backdoor.</p><p>The incident serves as a reminder of the adaptability of the threat actors. In this instance, LNK files were sent instead of Microsoft Word documents with macros, and swiftly ported to macOS when the opportunity arose. </p><h2 id="the-state-of-mac-malware">The state of Mac malware</h2><p>As Apple hardware has become progressively more popular in the enterprise, it has become correspondingly more of a target for threat actors.</p><p>That said, according to Apple management specialist Jamf, in 2022 there was a drop in new malware infections. </p><p>In its 2023 State of Malware <a href="https://go.malwarebytes.com/rs/805-USG-300/images/MWB_State_of_Malware_Report_2023.pdf" target="_blank">report</a>, Malwarebytes noted that while Mac malware was rare, it did exist. 11% of machines with detection events were infected by malware.</p><p>However, Michael Covington, VP of portfolio strategy at Jamf, told <em>ITPro </em>that 2023 had been a very active period for Apple security.</p><p>He said: “In the first half of the year, we saw some noteworthy developments in the threat landscape indicating that attacks against Apple devices were changing, both in terms of intensity and purpose”. </p><p>“During this time, we saw the <a href="https://www.itpro.com/security/ransomware/lockbit-macos-ransomware-strain-discovered-sparks-concerns-over-shifting-tactics"><u>first real instance of ransomware</u></a> emerge that was built specifically to target macOS. We also saw new <a href="https://www.itpro.com/malware/28076/what-is-malware"><u>malware</u></a> in distribution, attributed to state-sponsored attackers, that used novel evasion techniques to avoid detection and bypass built-in platform protections to take root.”</p><p>Covington also noted the rise of cryptojacking threats aimed at Apple processors and the continued evolution of <a href="https://www.itpro.com/security/malware/368629/mysterious-macos-spyware-using-public-cloud-storage-control-server"><u>spyware</u></a> being used against high-risk individuals - primarily in government and media, but also commended Apple’s actions to address active exploits.</p><p>He also warned of the risk posed by gullible or distracted users, particularly with regard to phishing attacks.</p><p>Proofpoint’s research is evidence of the adaptability of threat actors, their ability to respond to changes in the environment, and the continually evolving threat landscape.</p><p>Joshua Miller of Proofpoint said: “TA453’s capability and willingness to devote resources into new tooling to compromise its targets exemplifies the persistence of state-aligned cyber threats”. </p><p>“The threat actor’s continued efforts to iterate their infection chains to bypass security controls demonstrate how important a strong community-informed defense is to frustrate even the most advanced adversaries.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Malware being pushed to businesses by search engines remains a pervasive threat ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware-being-pushed-to-businesses-by-search-engines-remains-a-pervasive-threat</link>
                                                                            <description>
                            <![CDATA[ High-profile malvertising campaigns in recent months have surged ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pchGDUBTRbnkWNFyK5X3N3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FRRDLEFjuVCi2yG5QJMqoU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 02 May 2023 11:37:34 +0000</pubDate>                                                                                                                                <updated>Tue, 02 May 2023 12:55:05 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FRRDLEFjuVCi2yG5QJMqoU-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware and security denoted by blue and gold mockup of motherboard with lock]]></media:description>                                                            <media:text><![CDATA[Malware and security denoted by blue and gold mockup of motherboard with lock]]></media:text>
                                <media:title type="plain"><![CDATA[Malware and security denoted by blue and gold mockup of motherboard with lock]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FRRDLEFjuVCi2yG5QJMqoU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Search engines pushing malware to users continue to be one of the most pervasive cyber security threats facing organizations around the world.</p><p>Netskope’s 2022 Cloud and Threat report found that nearly 10% of all malware downloads in Q1 2022 were referred from search engines. </p><p>Downloads of malicious software “mostly resulted” from weaponized data voids, or a combination of search terms that specifically appealed to business web users, the study found. </p><p>Data voids occur when there is a lack of clearcut information available on search terms found in Google. Netskope said this means that content matching certain terms appears “very high in search results” - which in turn appeals to threat actors targeting certain users. </p><p>The research revealed that threat actors are increasingly relying on malicious web content to target users by developing finely-catered websites spanning a range of categories, such as business, marketing, technology, education, and retail. </p><p>These websites are often developed and populated in a patient manner by attackers to ensure they appear legitimate and dupe unknowing users. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="aciHQVJDYgcjpVWvmP9mYF" name="How to reduce the risk of phishing and ransomware_listing.jpg" caption="" alt="Whitepaper cover with title over shaded green letter O" src="https://cdn.mos.cms.futurecdn.net/aciHQVJDYgcjpVWvmP9mYF.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>How to reduce the risk of phishing and ransomware</strong></p><p class="fancy-box__body-text"><em>Top security concerns and tips for mitigation</em></p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/360247/how-to-reduce-the-risk-of-phishing-and-ransomware"><strong>DOWNLOAD FOR FREE</strong></a></p></div></div><p>“Attackers have been populating their websites with enough content to make them seem legitimate, and only using them to host malicious content after they have been around long enough to blend in,” the <a href="https://www.netskope.com/wp-content/uploads/2023/01/cloud-and-threat-report-2022-year-in-review.pdf" target="_blank"><u>report stated</u></a>. </p><p>“They have also been abusing free hosting services and compromising existing websites to deliver malicious content.”</p><p>Netskope’s findings on malvertising align with previous research into this attack method, which has surged in popularity among threat actors in recent months. </p><p><a href="https://www.itpro.com/security/369951/bitwarden-users-raise-alarm-over-highly-convincing-google-malvertising-risks"><u>An investigation by Bitwarden in January</u></a> found that the volume of fake ads promoting malicious software and websites impersonating popular brands has increased markedly over the last year.  </p><p>Similar research from HP Wolf Security’s threat research division observed a surge in malvertising across 2022. </p><p>In a blog post in January, the security firm warned that businesses were facing a significant volume of malicious websites aimed at compromising user accounts and targeting operations. </p><p>“In the last two months, we’ve seen a significant increase in malware distributed through malvertising, with multiple threat actors currently using this technique,” researchers said.</p><p>The rise of malvertising has reached such a point in the last 12 months that researchers have <a href="https://www.itpro.com/security/malware/369892/google-ads-malvertising-campaign-prompts-questions-around-search-security"><u>raised questions over Google’s handling of the issue</u></a>.</p><p>In a January Twitter thread, security researcher Will Dormann questioned why VirusTotal, which is owned by Google, was not being used to automatically examine sponsored links for malware. </p><p>Dormann’s criticism followed an incident in which a popular crypto influencer fell victim to a malicious OBS link promoted in Google Search results. </p><h2 id="social-engineering-risks-still-acute">Social engineering risks still acute</h2><p>Malvertising represents “just one of many” <a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">social engineering techniques</a> frequently employed by threat actors, the Netskope study warned. </p><p>In addition to leveraging search engines, attackers still focus heavily on targeting users via <a href="https://www.itpro.com/network-internet/email-providers/358887/the-most-secure-email-services">email platforms</a>, collaboration apps, and chat applications to dupe victims. </p><p>The study noted that the two most prevalent forms of malware still harnessed by attackers include Trojans, which accounted for 60% of all malware downloads in Q1 2022, and phishing downloads, which accounted for 13% of all incidents.</p><p>“Phishing scams, credit card skimmers, exploit kits, and other malicious web content continued to rise in 2022,” the report stated. </p><p>“Compromised sites, sites created using free hosting services, and fake websites hosting seemingly legitimate content have helped attackers disguise malicious web content, making it difficult to filter malicious content using URL categorization alone.”</p><p>“The rise in cloud malware delivery and malicious web content underscores the importance of inspecting all content, from all destinations, for both web and cloud.”</p><h2 id="cloud-apps-placing-users-at-risk-xa0">Cloud apps placing users at risk </h2><p>Malware delivery via cloud applications remained a key point of concern, the study found. </p><p>Over the last year, cloud malware delivery increased significantly, with malware downloads occurring from more than 400 cloud apps. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="z56E3EaY7r8uT8bzBsoUrm" name="Destination Cyber resilience_listing.jpg" caption="" alt="Whitepaper cover with red title over shaded image of female working at a desk in an office" src="https://cdn.mos.cms.futurecdn.net/z56E3EaY7r8uT8bzBsoUrm.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>Destination: Cyber resilience</strong></p><p class="fancy-box__body-text"><em>Cyber preparedness report</em></p><p class="fancy-box__body-text"><strong>DOWNLOAD FOR FREE</strong></p></div></div><p>Microsoft <a href="https://www.itpro.com/cloud-storage/34661/how-to-use-onedrive-a-guide-to-microsofts-cloud-storage-service">OneDrive</a> remained the most popular weapon of choice for threat actors in this regard. </p><p>However, Netskope observed a marked increase in the popularity of Google Cloud Storage, which saw “significant increase in usage as it gained popularity for object hosting across the web”. </p><p>To mitigate rising malware threats, Netskope recommended that organizations deploy “multi-layered, inline threat protection” for cloud and web traffic.</p><p>In doing this, businesses can prevent inbound and outbound <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a> communications.</p><p>Similarly, it advised implementing “real-time coaching” for users to ensure safer app alternatives and to monitor unusual activity. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Novel social engineering attacks soar 135% amid uptake of generative AI ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/technology/artificial-intelligence-ai/370366/social-engineering-attacks-generative-ai-soar-135</link>
                                                                            <description>
                            <![CDATA[ 82% of employees are worried about hackers using generative AI to create scam emails ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9cQnS99X2wdNYiaMqhYwyW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/eNr8jgtoakTWYJA7GBQr6m-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 03 Apr 2023 07:00:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GFZtdGsYoXrkh3Jhj4ZKTc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/eNr8jgtoakTWYJA7GBQr6m-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Abstract image showing an envelope floating above digital blocks to symbolise phishing emails]]></media:description>                                                            <media:text><![CDATA[Abstract image showing an envelope floating above digital blocks to symbolise phishing emails]]></media:text>
                                <media:title type="plain"><![CDATA[Abstract image showing an envelope floating above digital blocks to symbolise phishing emails]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/eNr8jgtoakTWYJA7GBQr6m-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Researchers from Darktrace have seen a 135% increase in novel social engineering attack emails in the first two months of 2023.</p><p>The cyber security firm said the email attacks targeted thousands of its customers in January and February 2023, an increase which it said matches the adoption rate of ChatGPT.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/28744/4-giveaways-that-show-an-email-is-a-phishing-attack" data-original-url="/security/28744/4-giveaways-that-show-an-email-is-a-phishing-attack">Five giveaways that show an email is a phishing attack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/370322/can-generative-ai-change-security" data-original-url="/technology/artificial-intelligence-ai/370322/can-generative-ai-change-security">Can generative AI change security?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai" data-original-url="/technology/artificial-intelligence-ai/369959/what-is-generative-ai">What is generative artificial intelligence (AI)?</a></p></div></div><p>The novel social engineering attacks make use of “sophisticated linguistic techniques”, which Darktrace said include increasing text volume, sentence length, and punctuation in emails.</p><p>Darktrace also found there’s been a decrease in the number of malicious emails that are sent with an attachment or link.</p><p>The firm said that this behaviour could mean that generative AI, including ChatGPT, is being used by malicious actors to construct targeted attacks rapidly.</p><p>“Email is the key vulnerability for businesses today. Defenders are up against sophisticated <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai" target="_blank" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai">generative AI</a> attacks and entirely novel scams that use techniques and reference topics that we have never seen before,” said Max Heinemeyer, chief product officer at Darktrace.</p><p>“In a world of increasing AI-powered attacks, we can no longer put the onus on humans to determine the veracity of communications they receive. This is now a job for artificial intelligence.”</p><p>Survey results indicated that 82% of employees are worried about <a href="https://www.itpro.com/security/hacking/357971/how-do-hackers-choose-their-targets" target="_blank" data-original-url="https://www.itpro.com/security/hacking/357971/how-do-hackers-choose-their-targets">hackers</a> using generative AI to create scam emails which are indistinguishable from genuine communication. It also found that 30% of employees have fallen for a scam email or text in the past.</p><p>Darktrace asked survey respondents what the top-three characteristics are that suggest an email is a phish and found:</p><ul><li>68% said it was being invited to click a link or open an attachment</li><li>61% said it was due to an unknown sender or unexpected content</li><li>Poor use of spelling and grammar was chosen by 61% too</li></ul><p>In the last six months, 70% of employees reported an increase in the frequency of <a href="https://www.itpro.com/security/28744/4-giveaways-that-show-an-email-is-a-phishing-attack" target="_blank" data-original-url="https://www.itpro.com/security/28744/4-giveaways-that-show-an-email-is-a-phishing-attack">scam emails</a>. Additionally, 79% said that their organisation’s spam filters prevent legitimate emails from entering their inbox.</p><p>87% of employees said they were worried about the amount of their personal information online which could be used in phishing or email scams.</p><h2 id="defending-ai-social-engineering-attacks">Defending AI social engineering attacks</h2><p>Email services have always been one of the primary vectors through which attackers can breach an organisation. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="cDuYPAWDnMxAG5xUHEbeqe" name="cDuYPAWDnMxAG5xUHEbeqe.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/cDuYPAWDnMxAG5xUHEbeqe.png" mos="https://cdn.mos.cms.futurecdn.net/cDuYPAWDnMxAG5xUHEbeqe.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The near and far future of ransomware business models</strong></p><p class="fancy-box__body-text">What would make ransomware actors change their criminal business models?</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/370159/the-near-and-far-future-of-ransomware-business-models" data-original-url="/security/ransomware/370159/the-near-and-far-future-of-ransomware-business-models">FREE DOWNLOAD</a></p></div></div><p>One of the most common ways to install malware on a victim's machine would be to embed malicious code inside a Microsoft Office document, such as an Excel file.</p><p>Microsoft has recently implemented a number of measures to help minimise the abuse of its software in phishing attacks. Most notably in 2022, it <a href="https://www.itpro.com/software/microsoft-office/362184/microsoft-disables-vba-macros-in-office-by-default" data-original-url="https://www.itpro.com/software/microsoft-office/362184/microsoft-disables-vba-macros-in-office-by-default">disabled VBA macros</a> - the abused component which facilitated the automatic loading of malware via tampered Office documents.</p><p>The decision was greeted warmly, but the company didn't escape criticism. Some said the industry had been calling for such action to be taken against VBA macros for years, and that Microsoft could have prevented an untold number of attacks if it had acted faster.</p><p>More recently, it took the decision to <a href="https://www.itpro.com/network-internet/mail-servers/370340/microsoft-set-to-block-emails-from-unsupported-exchange" data-original-url="https://www.itpro.com/network-internet/mail-servers/370340/microsoft-set-to-block-emails-from-unsupported-exchange">block emails sent from potentially vulnerable Exchange servers</a>.</p><p>Microsoft Exchange servers have been <a href="https://www.itpro.com/security/ransomware/361417/microsoft-exchange-servers-distribute-squirrelwaffle-malware" data-original-url="https://www.itpro.com/security/ransomware/361417/microsoft-exchange-servers-distribute-squirrelwaffle-malware">abused by hackers for years</a> to launch highly convincing email campaigns, such as those involving email hijacking - using genuine email addresses to continue previous chains to increase the feeling of legitimacy.</p><p>The threat of AI to cyber security has been feared for some time and extends beyond just generative AI.</p><p>AI-driven malware, for example, was conceptualised years ago - malware that could install and analyse a specific environment, changing its payload to exploit its host most effectively. In reality, such attacks have been few and far between.</p><p>There are also fears around what <a href="https://www.itpro.com/security/phishing/368299/deepfake-attacks-expected-to-be-next-big-threat-to-businesses" data-original-url="https://www.itpro.com/security/phishing/368299/deepfake-attacks-expected-to-be-next-big-threat-to-businesses">deepfake technology could achieve in the phishing space</a>. One possible attack could see a CEO's likeness abused to send video and/or audio instructions to employees in the finance department, for example, encouraging them to make payments to accounts under the attackers' control.</p><p>The latest work from Intel and its <a href="https://www.itpro.com/technology/artificial-intelligence-ai/370325/intel-facecatcher-eradicate-deepfakes" data-original-url="https://www.itpro.com/technology/artificial-intelligence-ai/370325/intel-facecatcher-eradicate-deepfakes">FakeCatcher system</a> has aimed to develop a tool to detect deepfakes analysing the bloodflow in faces.</p><p>At present, Intel told <em>IT Pro</em> that it has a 96% success rate in identifying deepfake footage, and the technology could be embedded within video conferencing software to prevent deepfake phishing and social engineering attacks in the near future.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ CISA: Phishing campaign targeting US federal agencies went undetected for months ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/369942/cisa-phishing-campaign-federal-agencies-undetected-for-months</link>
                                                                            <description>
                            <![CDATA[ Threat actors used legitimate remote access software to maliciously target federal employees ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gRhdcSP5BVzXPatsqLBvLs</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/oajyUSRG44FA5WTmRw4Jcg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 26 Jan 2023 13:08:42 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/oajyUSRG44FA5WTmRw4Jcg-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Abstract image of a fishing hook through a red email to represent a phishing attack]]></media:description>                                                            <media:text><![CDATA[Abstract image of a fishing hook through a red email to represent a phishing attack]]></media:text>
                                <media:title type="plain"><![CDATA[Abstract image of a fishing hook through a red email to represent a phishing attack]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/oajyUSRG44FA5WTmRw4Jcg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US' Cybersecurity and Infrastructure Security Agency (CISA) has revealed that several federal civilian executive branch (FCEB) agencies have fallen victim to a widespread phishing campaign.</p><p>The campaign abused legitimate remote monitoring and management (RMM) software and emails were sent to staff starting in the middle of 2022. The majority were themed around helpdesk emails falsely notifying victims that they had been sent an accidental refund, or needed to cancel a subscription. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/development/programming-languages/369932/report-regulatory-monetary-incentives-adopt-safe-programming-languages" data-original-url="/development/programming-languages/369932/report-regulatory-monetary-incentives-adopt-safe-programming-languages">Report: Regulatory and monetary incentives needed to adopt safer programming languages</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/369910/mailchimp-data-breach-impact-unravels-second-customer-damage" data-original-url="/security/data-breaches/369910/mailchimp-data-breach-impact-unravels-second-customer-damage">Mailchimp data breach impact unravels as second customer reveals extent of damage</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/369252/cisa-issues-orders-to-polish-vulnerability-detection-in-federal-agencies" data-original-url="/security/369252/cisa-issues-orders-to-polish-vulnerability-detection-in-federal-agencies">CISA issues fresh orders to polish security vulnerability detection in federal agencies</a></p></div></div><p>Links included in the emails led to a first-stage malicious domain which would launch an executable that connected to a second-stage domain that downloaded an RMM program. </p><p>CISA said threat actors would remotely monitor the victim’s screen and instruct them to access their bank account, then alter the balance to make it seem as though the victim had been sent money. They would then instruct for the 'excess' amount to be sent back to an account set up for the scam.</p><p>Although the agency did not provide specifics on the scam, its description bears a strong resemblance to the methods used prevalently by online scammers targeting vulnerable civilians.</p><p>Often claiming to be calling from tech support at a large company, such as Microsoft, they would block the victim's view of their display using the RMM tools and use a browser's 'inspect element' function to make the bank balance appear as though it had changed.</p><p>According to CISA's account, the threat actors used <a href="https://www.itpro.com/mobile/remote-access/368052/what-is-anydesk" data-original-url="https://www.itpro.com/mobile/remote-access/368052/what-is-anydesk">AnyDesk</a> and ScreenConnect as portable executables, which can run without administrator privileges and are not flagged as malicious by <a href="https://www.itpro.com/antivirus/28144/best-antivirus" data-original-url="https://www.itpro.com/antivirus/28144/best-antivirus">antivirus</a> programs or <a href="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools" data-original-url="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools">malware removal tools</a>.</p><p>This allowed the software to run without being approved by network administrators at the affected agencies, and could have facilitated an attack on devices that shared an intranet with that of the victim.</p><p>Another method saw threat actors send victims emails urging victims to call a phone number on similar financial pretences to the emails containing links. They would then be urged to manually navigate to one of the threat actors’ malicious domains.</p><p>In June 2022, one FCEB employee called the number and was given instructions to open a malicious domain on their device. At the time the CISA detected the campaign in October 2022, traffic was being sent and received between a compromised FCEB server and the malicious domain ‘myhelpcare[.]cc’.</p><p>"Targets can include managed service providers (MSPs) and IT help desks, which regularly use legitimate RMM software for technical and security end-user support, network management, endpoint monitoring, and to interact remotely with hosts for IT-support functions," the CISA said.</p><p>"These threat actors can exploit trust relationships in MSP networks and gain access to a large number of the victim MSP's customers. MSP compromises can introduce significant risk - such as <a href="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware" data-original-url="https://www.itpro.com/security/29241/what-are-the-different-types-of-ransomware">ransomware</a> and <a href="https://www.itpro.com/security/28170/what-is-cyber-warfare" data-original-url="https://www.itpro.com/security/28170/what-is-cyber-warfare">cyber espionage</a> - to the MSP’s customers."</p><p>The CISA has urged organisations to follow best practices for blocking phishing emails, and train employees to recognise techniques used by <a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one" data-original-url="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">social engineers</a>.</p><p>It has additionally recommended the use of enhanced application controls to prevent the installation and execution of portable unauthorised RMM software, and for RMM ports to be blocked at network perimeters.</p><p>In an <a href="https://www.cisa.gov/uscert/ncas/alerts/aa23-025a">advisory</a>, the CISA noted that the threat actors behind the campaign appear to have run it for profit only but that similar techniques could be used by threat actors for significant harm.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="L47gbigPjNi8zfgWvSgmk3" name="L47gbigPjNi8zfgWvSgmk3.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/L47gbigPjNi8zfgWvSgmk3.png" mos="https://cdn.mos.cms.futurecdn.net/L47gbigPjNi8zfgWvSgmk3.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>2022 Magic quadrant for Security Information and Event Management (SIEM)</strong></p><p class="fancy-box__body-text">SIEM is evolving into a security platform with multiple features and deployment models</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/security-information-and-event-management-siem/369560/2022-magic-quadrant-for-security" data-original-url="/security/security-information-and-event-management-siem/369560/2022-magic-quadrant-for-security">FREE DOWNLOAD</a></p></div></div><p>The CISA, National Security Agency (NSA), and Multi-State Information Sharing and Analysis Center (MS-ISAC) SAID that threat actors could have sold remote access to victim accounts to more dangerous groups such as advanced persistent threat actors (APTs).</p><p>The agencies also warned that the attacks prove the potential for legitimate <a href="https://www.itpro.com/desktop-software/28122/the-best-remote-access-solutions" data-original-url="https://www.itpro.com/desktop-software/28122/the-best-remote-access-solutions">RMM programs</a> to be used by threat actors to seize control of devices remotely, and bypass administrator controls to launch <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a> operations.</p><p>“In October, CISA identified a widespread cyber campaign in which cyber criminal actors leveraged RMM software to gain command and control of devices and accounts,” said the NSA in its <a href="https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/3277084/nsa-cisa-and-ms-isac-release-guidance-for-securing-remote-monitoring-and-manage">press release</a>.</p><p>“Malicious cyber actors could leverage these same techniques to target National Security Systems (NSS), Department of Defense (DoD), and Defense Industrial Base (DIB) networks and use legitimate RMM software on both work and home devices and accounts. Other RMM software solutions could be abused to similar effect.”</p><p>Over the past 12 months, the CISA has enacted strong, government-wide policies to strengthen the nation's cyber security posture. A notable example from the past year, was the bill that passed in August <a href="https://www.itpro.com/business/policy-legislation/368843/us-government-set-to-outlaw-leaky-software-in-military" data-original-url="https://www.itpro.com/business/policy-legislation/368843/us-government-set-to-outlaw-leaky-software-in-military">outlawing software containing any vulnerabilities</a> to ensure secure-by-design federal systems.</p><p>In November 2021, it also launched a 'mandatory patch list' for FCEB agencies to abide by. This was comprised of the most dangerous and commonly exploited security vulnerabilities, complete with deadlines for each agency by which to apply the patches.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google Ads malvertising campaign prompts questions around Search security ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/369892/google-ads-malvertising-campaign-prompts-questions-around-search-security</link>
                                                                            <description>
                            <![CDATA[ A leading security researcher has called into question why Google still allows malware links to top search results ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5PuVkfbQkhJvcdrRaRKqs6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/H2CzH5wHcCjNXMDWfqbmpX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 18 Jan 2023 12:59:28 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/H2CzH5wHcCjNXMDWfqbmpX-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Google logo shown on a landscape phone, held by a hand in silhouette against a dark blue background]]></media:description>                                                            <media:text><![CDATA[The Google logo shown on a landscape phone, held by a hand in silhouette against a dark blue background]]></media:text>
                                <media:title type="plain"><![CDATA[The Google logo shown on a landscape phone, held by a hand in silhouette against a dark blue background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/H2CzH5wHcCjNXMDWfqbmpX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Paid advertising links on Google Search are being used by cyber criminals to push malware, in a strategy that could threaten businesses looking to use free software.</p><p>Top listings on the search engine that purport to link to legitimate software websites were instead found to be decoys leading to websites containing malware such as infostealers.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/368621/hackers-hiding-malicious-links-in-top-google-search-results" data-original-url="/security/368621/hackers-hiding-malicious-links-in-top-google-search-results">Hackers hiding malicious links in top Google search results, researchers warn</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/32128/google-at-20-how-a-search-engine-changed-the-business-world" data-original-url="/network-internet/32128/google-at-20-how-a-search-engine-changed-the-business-world">Google at 20: How a search engine changed the business world</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/privacy/369517/google-agrees-record-3915m-settlement-in-us-digital-tracking-case" data-original-url="/security/privacy/369517/google-agrees-record-3915m-settlement-in-us-digital-tracking-case">Google agrees record $391.5m settlement in US digital tracking case</a></p></div></div><p>The abuse of Google's ubiquitous search engine was brought to light after a cryptocurrency influencer mistakenly downloaded a malicious package after clicking on an advertising link for popular streaming software OBS.</p><p>After running the executable file provided on the website, the victim's accounts on Substack and Twitter were hacked, and their NFT wallet was stolen.</p><p>Security researcher Will Dormann detailed the issue in a Twitter <a href="https://twitter.com/wdormann/status/1614675821578395655">thread</a>, and openly questioned why Google-owned threat analyser VirusTotal cannot be used to automatically check sponsored links for malware.</p><p>The popular file and link-checking website was <a href="https://www.itpro.com/642751/google-acquires-online-security-startup-virustotal" data-original-url="https://www.itpro.com/642751/google-acquires-online-security-startup-virustotal">acquired by Google</a> in 2012, and flagged the malvertising links used in the campaign as threats when manually fed into the system.</p><p>Despite this, Google had not prevented the links from being blacklisted on their Ads platform, seemingly accepting money from threat actors without checking the listed links for threats at all.</p><p>In other cases, Dormann noted that VirusTotal didn’t flag links as malicious even though inspection of the packages they pushed contained highly suspicious Powershell commands.</p><p>He alleged that the threat actor behind this package is still paying Google for fake listings on software such as VLC Media Player, Rufus, and uTorrent.</p><p><a href="https://www.itpro.com/business-strategy/smb/360136/the-most-significant-challenges-facing-smbs-post-pandemic" data-original-url="https://www.itpro.com/business-strategy/smb/360136/the-most-significant-challenges-facing-smbs-post-pandemic">Small and medium businesses</a> could be at particular risk from this campaign, as these firms typically rely on free media and <a href="https://www.itpro.com/business-operations/productivity/355569/optimize-your-workflow-our-9-best-productivity-apps" data-original-url="https://www.itpro.com/business-operations/productivity/355569/optimize-your-workflow-our-9-best-productivity-apps">productivity software</a>, the likes of which are being mimicked.</p><p>Some software developers appear to be aware of the issue, as those behind Notepad++ appear to have spent money to ensure their software appears in results first. OBS has issued an official warning and linked the only legitimate site from which its software may be obtained.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1615033901809913856"></a></p></blockquote><div class="see-more__filter"></div></div><p>Malvertising, the method through which malicious software or links are hidden in seemingly safe advertising, is often used by hackers on untrustworthy websites behind suspicious banner ads. </p><p>“Protecting users is our top priority,” said a Google spokesperson in response to a request from <em>IT Pro</em>.</p><p>“We take dishonest business practices very seriously and consider them to be an egregious violation of our policies. Where we find ads that breach our policies we take immediate action.”</p><p>Google's <a href="https://support.google.com/adspolicy/answer/6008942?hl=en">ad policy</a> prohibits the posting of links that hide malware, and in January 2021 the firm began to ask advertisers registered in certain countries to <a href="https://support.google.com/adspolicy/answer/10268745">verify their identity</a>.</p><p>The company did not directly respond to questions regarding why it has not implemented automatic VirusTotal scans for links on their platform.</p><h2 id="malvertising-a-deeper-issue">Malvertising: A deeper issue</h2><p>The HP Wolf Security Threat Research Team published a <a href="https://threatresearch.ext.hp.com/adverts-mimicking-popular-software-leads-to-malware">report</a> on malvertising campaigns that used fake listings for popular free software as an attack vector.</p><p>Programs such as Audacity, Teams, Discord, and the Adobe Creative Cloud suite of apps were used as bait by threat actors to distribute malware.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="KoCPGWaMFabR4Q4NgSnY4D" name="KoCPGWaMFabR4Q4NgSnY4D.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/KoCPGWaMFabR4Q4NgSnY4D.png" mos="https://cdn.mos.cms.futurecdn.net/KoCPGWaMFabR4Q4NgSnY4D.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Threat hunting for MSPs</strong></p><p class="fancy-box__body-text">Are you ready to take your Managed Security Service to the next level?</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-operations/managed-service-provider-msp/369833/threat-hunting-for-msps" data-original-url="/business-operations/managed-service-provider-msp/369833/threat-hunting-for-msps">FREE DOWNLOAD</a></p></div></div><p><a href="https://www.itpro.com/security/malware/369299/zoom-themed-cyber-attacks-fuel-rapid-malware-growth" data-original-url="https://www.itpro.com/security/malware/369299/zoom-themed-cyber-attacks-fuel-rapid-malware-growth">Vidar Stealer</a>, a malware strain used to steal data such as passwords and cryptocurrency wallets from victims, was one such program spread in the campaign, along with the <a href="https://www.itpro.com/security/30081/what-is-a-trojan-virus" data-original-url="https://www.itpro.com/security/30081/what-is-a-trojan-virus">Trojan</a> IcedID which is used to steal financial credentials and compromise corporate networks.</p><p>Researchers noted that malicious packages downloaded through the campaign were large, with one example being 343MB. This is believed to be an <a href="https://www.itpro.com/antivirus/28144/best-antivirus" data-original-url="https://www.itpro.com/antivirus/28144/best-antivirus">antivirus</a> evasion tactic, as larger files can circumvent automatic scans with some software.</p><p>“Many organisations use software distribution systems, which means that the software does not have to be downloaded by the end user but is provided by the system administrator,” said Patrick Schläpfer, malware analyst at HP Wolf Security.</p><p>“If you even block the download of such software for end users, you greatly limit this attack vector and are even more protected against such attacks.”</p><p>The use of Google Ads to deliver malware was also previously highlighted in July 2022 when Malwarebytes researchers warned of <a href="https://www.itpro.com/security/368621/hackers-hiding-malicious-links-in-top-google-search-results" data-original-url="https://www.itpro.com/security/368621/hackers-hiding-malicious-links-in-top-google-search-results">Google search results hiding malicious links</a>. The sophisticated campaign used inline frames to push malicious domains onto users without revealing their URLs.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Uber hacked via basic smishing attack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/369091/uber-hack-started-with-smishing-social-engineering-attack</link>
                                                                            <description>
                            <![CDATA[ The self-taught hacker impersonated an IT worker to gain an Uber employee's password, obtaining broad access to internal systems and posting taunting messages ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vLbKrTfMtRYf5ycwWUEDhh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PKwJ8kpXaP8pPN3aFsFbAK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 16 Sep 2022 11:25:01 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PKwJ8kpXaP8pPN3aFsFbAK-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Black cards of Uber logos lined up in a row]]></media:description>                                                            <media:text><![CDATA[Black cards of Uber logos lined up in a row]]></media:text>
                                <media:title type="plain"><![CDATA[Black cards of Uber logos lined up in a row]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PKwJ8kpXaP8pPN3aFsFbAK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A smishing attack on Thursday led to a wide range of Uber's internal systems being breached by a seemingly unaffiliated teenage hacker, it has been claimed.</p><p>A <a href="https://www.nytimes.com/2022/09/15/technology/uber-hacking-breach.html">report</a> first emerged in <em>The New York Times</em> that the ride-sharing company had been hacked, with the threat actor themselves getting in touch with the publication to allege that he had gained access to internal systems such as Uber’s internal email, cloud storage systems and code repositories through a simple social engineering attack. In a text message sent to an Uber employee, the hacker impersonated an IT worker and convinced them that it was necessary to share an internal password.</p><p>As a variant of <a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> in which SMS is used to mine targets for sensitive information, <a href="https://www.itpro.com/security/phishing/361625/what-is-smishing" data-original-url="https://www.itpro.com/security/phishing/361625/what-is-smishing">smishing</a> is often combined with <a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one" data-original-url="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">social engineering</a> tricks for increased effectiveness. Victims may be more easily persuaded to hand over credentials to a supposedly trustworthy source if the attacker makes the situation seem urgent or seems to be suitably authoritative, both of which may have prompted the hacker to claim to be a key IT worker. <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">Two-factor authentication (2FA)</a> is a recommended measure to dull the impact of smishing attacks, and prevent compromised credentials from being used by hackers effectively.</p><p>Smishing and social engineering were recently used in <a href="https://www.itpro.com/security/368768/twilio-account-breach-result-of-sophisticated-social-engineering-campaign" data-original-url="https://www.itpro.com/security/368768/twilio-account-breach-result-of-sophisticated-social-engineering-campaign">sophisticated attacks on Twilio</a> and <a href="https://www.itpro.com/security/data-breaches/368456/marriott-hit-by-data-breach-through-social-engineering" data-original-url="https://www.itpro.com/security/data-breaches/368456/marriott-hit-by-data-breach-through-social-engineering">Marriott</a>. A report from September 2021 revealed that in the first six months of the year, <a href="https://www.itpro.com/security/scams/360873/smishing-attacks-increase-700-percent-2021" data-original-url="https://www.itpro.com/security/scams/360873/smishing-attacks-increase-700-percent-2021">smishing attacks surged 700%</a> more than in the preceding six months.</p><p>The hacker claims to be just 18 years old, with self-taught skills in cyber security, and explained that he performed the breach because Uber’s security was especially weak. On Thursday, Uber <a href="https://twitter.com/Uber_Comms/status/1570584747071639552">confirmed</a> that it was subject to a cyber attack through its official Twitter channel, and also stated that it is in dialogue with law enforcement. The company has not offered an in-depth description of the attack.</p><p>As part of the breach, the hacker gained administrator control of Uber’s <a href="https://www.itpro.com/security/368417/hackerone-employee-fired-for-using-position-to-steal-bug-bounties" data-original-url="https://www.itpro.com/security/368417/hackerone-employee-fired-for-using-position-to-steal-bug-bounties">HackerOne</a> account, which it uses to pay <a href="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained" data-original-url="https://www.itpro.com/hacking/30282/what-is-ethical-hacking-white-hat-hackers-explained">white hat hackers</a> bug bounties. The attacker proceeded to leave comments on all active bounty tickets reading “UBER HAS BEEN HACKED (domain admin, aws admin, vsphere admin, gsuite SA) AND THIS HACKERONE ACCOUNT HAS BEEN ALSO”.</p><p>The attacker also used this access to send out an email via policy update - which sends an automatic alert to the inboxes of anyone following a particular bounty programme - including a screenshot of a Telegram exchange, providing more details on how the hacker allegedly compromised Uber's systems.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1570582547415068672"></a></p></blockquote><div class="see-more__filter"></div></div><p>In it, the hacker (identified in the conversation as 'Tea Pot') said that after he had gained access to the intranet, he obtained PowerShell scripts that "contained the username and password for a admin user in [privileged access management tool] Thycotic", which he said allowed him to "extract secrets for all services, [including] DA, DUO, Onelogin, AWS, [and] GSuite".</p><p><em>The New York Times</em> also quoted two Uber employees, who wished to remain anonymous, who said the company had put out a warning to not engage with the company’s <a href="https://www.itpro.com/collaboration/33647/slack-review-free-your-business-comms" data-original-url="https://www.itpro.com/collaboration/33647/slack-review-free-your-business-comms">Slack</a> channels while the attack was active, and shortly after all employees received a message reading “I announce that I am a hacker and Uber has suffered a data breach.”</p><p>There are concerns that younger people are increasingly turning to hacking as a hobby, driven by lack of opportunity amidst the <a href="https://www.itpro.com/business/business-strategy/367391/cost-of-living-crisis-savage-tech" data-original-url="https://www.itpro.com/business/business-strategy/367391/cost-of-living-crisis-savage-tech">cost of living crisis</a>. A recent report by Censuswide, on behalf of International Cyber Expo, revealed growing concern among parents that hacking could become a pastime for young people.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/368815/signal-confirms-1900-users-impacted-by-twilio-breach" data-original-url="/security/cyber-attacks/368815/signal-confirms-1900-users-impacted-by-twilio-breach">Signal confirms 1,900 of its users were hit by Twilio breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/369058/cisco-confirms-data-breach-by-yanluowang-ransomware-attack-from-may" data-original-url="/security/ransomware/369058/cisco-confirms-data-breach-by-yanluowang-ransomware-attack-from-may">Cisco confirms data breach following Yanluowang ransomware attack in May</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/369028/the-it-pro-podcast-are-phishing-tests-a-waste-of-time" data-original-url="/security/phishing/369028/the-it-pro-podcast-are-phishing-tests-a-waste-of-time">The IT Pro Podcast: Are phishing tests a waste of time?</a></p></div></div><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="X45j9iJmNPhLBRNurdifFT" name="X45j9iJmNPhLBRNurdifFT.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/X45j9iJmNPhLBRNurdifFT.jpg" mos="https://cdn.mos.cms.futurecdn.net/X45j9iJmNPhLBRNurdifFT.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Cyber resiliency and end-user performance</strong></p><p class="fancy-box__body-text">Reduce risk and deliver greater business success with cyber-resilience capabilities</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/368832/cyber-resiliency-and-end-user-performance" data-original-url="/security/368832/cyber-resiliency-and-end-user-performance">FREE DOWNLOAD</a></p></div></div><p>“With hacking tools becoming increasingly accessible and affordable on the internet, we have witnessed a rise in ‘script kiddies’; inexperienced hackers who carry out cyber attacks,” stated Simon Newman, CEO of Cyber Resilience Centre for London and International Cyber Expo Advisory Council member.</p><p>“While ‘kiddies’ do not necessarily refer to the hacker’s age so much as their experience, many have been found to be teenagers. In fact, in the UK the average age of a referral to the National Cyber Crime Unit is just 15 years old.”</p><p>“Although law enforcement agencies are working hard to take down the websites and forums that promote hacking, the results of this survey also demonstrate a need for parents/guardians to take an active interest in what their children are doing online to prevent them from falling on the wrong side of the law.”</p><p>Uber has a history of hacking, having been very publicly compromised in a 2016 attack that resulted in the exposed information of 57 million users of its app and resulted in <a href="https://www.itpro.com/security/data-breaches/357941/how-much-will-a-data-breach-really-damage-your-organisations" data-original-url="https://www.itpro.com/security/data-breaches/357941/how-much-will-a-data-breach-really-damage-your-organisations">reputational damage</a> for the firm. In June, a judge decided that the company’s former chief security officer (CSO) Joseph Sullivan would <a href="https://www.itpro.com/security/data-breaches/368386/former-uber-security-chief-to-face-fraud-charges-over-hack-coverup" data-original-url="https://www.itpro.com/security/data-breaches/368386/former-uber-security-chief-to-face-fraud-charges-over-hack-coverup">face wire fraud charges</a> for his role in an attempted cover-up of the attack.</p><p>Uber declined to provide further comment to <em>IT Pro</em>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Signal confirms 1,900 of its users were hit by Twilio breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-attacks/368815/signal-confirms-1900-users-impacted-by-twilio-breach</link>
                                                                            <description>
                            <![CDATA[ Last week's phishing attack on Twilio has exposed phone numbers exposed and compromised user accounts ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jZzZsHxtNptnmQut9gm4Vt</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/najgS7VeKqTawCG5Th9gXC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 16 Aug 2022 11:58:11 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/najgS7VeKqTawCG5Th9gXC-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A smartphone sat on top of a white keyboard with the Signal app logo superimposed onto the phone&amp;#039;s display - an image all set in dark blue and black lighting]]></media:description>                                                            <media:text><![CDATA[A smartphone sat on top of a white keyboard with the Signal app logo superimposed onto the phone&amp;#039;s display - an image all set in dark blue and black lighting]]></media:text>
                                <media:title type="plain"><![CDATA[A smartphone sat on top of a white keyboard with the Signal app logo superimposed onto the phone&amp;#039;s display - an image all set in dark blue and black lighting]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/najgS7VeKqTawCG5Th9gXC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Encrypted messaging platform Signal has confirmed that a number of its customers have been affected by the phishing attack on Twilio last week.</p><p>The company believes around 1,900 of its users are potentially affected by the breach of the communication API firm, with phone numbers and SMS verification codes potentially exposed to the hackers.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/368768/twilio-account-breach-result-of-sophisticated-social-engineering-campaign" data-original-url="/security/368768/twilio-account-breach-result-of-sophisticated-social-engineering-campaign">Twilio account breach result of sophisticated social engineering campaign</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/368798/cloudflare-scuppers-twilio-like-cyber-attack-with-hardware-keys" data-original-url="/security/cyber-security/368798/cloudflare-scuppers-twilio-like-cyber-attack-with-hardware-keys">Cloudflare scuppers Twilio-like cyber attack with hardware keys</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/361625/what-is-smishing" data-original-url="/security/phishing/361625/what-is-smishing">What is smishing?</a></p></div></div><p>Signal said Twilio informed it of the breach at the time, and a subsequent investigation revealed the hackers gained access to Twilio’s customer support console.</p><p>“During the window when an attacker had access to Twilio’s customer support systems it was possible for them to attempt to register the phone numbers they accessed to another device using the SMS verification code,” said Signal in a <a href="https://support.signal.org/hc/en-us/articles/4850133017242-Twilio-Incident-What-Signal-Users-Need-to-Know-">public disclosure</a>. “The attacker no longer has this access, and the attack has been shut down by Twilio.”</p><p>It added that the attackers specifically searched for three phone numbers out of the total 1,900 exposed, and the owner of one of these numbers has confirmed to Signal that their account was re-registered.</p><p>Re-registering a user’s account does not give the attacker access to any messages, profile information, or contact lists, Signal said, since this data is stored on a user’s device only.</p><p>“Your contact lists, profile information, whom you’ve blocked, and more can only be recovered with your Signal PIN which was not (and could not be) accessed as part of this incident,” it told customers.</p><p>By re-registering a user’s account, an attacker would be able to send and receive Signal messages from that phone number, however.</p><p>Signal is currently in the process of notifying all affected users by SMS and is de-registering Signal on all affected users’ devices. The 1,900 users will be required to re-register their accounts with their phone numbers on all devices they use.</p><p>This process began on Monday and Signal expects to complete it by the end of the day.</p><p>Since the action taken by Signal following Twilio’s breach, some users will have seen a banner in the app saying their account has been de-registered.</p><p>This may mean they were affected by the incident, it said, or it could indicate their account had been inactive for a long period.</p><p>Signal had previously prepared for this type of attack and is the reason it developed functionalities like Signal PINs and registration lock – a feature that prevents anyone else from registering an account with a user’s phone number.</p><p>This feature is not enabled by default, and Signal has recommended all users to enable it in the app’s settings menu, using a Signal PIN.</p><h2 id="what-happened-in-the-twilio-breach">What happened in the Twilio breach?</h2><p>Last week, several Twilio employees were <a href="https://www.itpro.com/security/368768/twilio-account-breach-result-of-sophisticated-social-engineering-campaign" data-original-url="https://www.itpro.com/security/368768/twilio-account-breach-result-of-sophisticated-social-engineering-campaign">targeted</a> by <a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one" data-original-url="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">socially engineered</a> phishing attacks which resulted in some staff handing over <a href="https://www.itpro.com/security/368438/the-psychology-of-secure-passwords" data-original-url="https://www.itpro.com/security/368438/the-psychology-of-secure-passwords">passwords</a> to the attackers.</p><p><a href="https://www.itpro.com/security/phishing/361625/what-is-smishing" data-original-url="https://www.itpro.com/security/phishing/361625/what-is-smishing">SMS messages</a> were sent with password reset links which directed targets to fake Twilio pages where attackers harvested the login credentials of some staff members.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="wE3UT9aDVGm6fZh2yRZMu6" name="wE3UT9aDVGm6fZh2yRZMu6.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/wE3UT9aDVGm6fZh2yRZMu6.jpg" mos="https://cdn.mos.cms.futurecdn.net/wE3UT9aDVGm6fZh2yRZMu6.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>An EDR buyer's guide</strong></p><p class="fancy-box__body-text">How to pick the best endpoint detection and response solution for your business</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/368443/an-edr-buyers-guide" data-original-url="/security/cyber-security/368443/an-edr-buyers-guide">FREE DOWNLOAD</a></p></div></div><p>Targets were addressed by their name, in some cases, and texts appeared to be sent from Twilio’s IT department, the company said.</p><p>It’s unclear who was behind the attack but it was thought the attackers were well-equipped given the thorough understanding of the company, able to link current and former employees with phone numbers and real names.</p><p>Twilio said it was aware that other companies were also targeted at the same time, one of which was revealed as Cloudflare.</p><p>The DDoS mitigation company <a href="https://www.itpro.com/security/cyber-security/368798/cloudflare-scuppers-twilio-like-cyber-attack-with-hardware-keys" data-original-url="https://www.itpro.com/security/cyber-security/368798/cloudflare-scuppers-twilio-like-cyber-attack-with-hardware-keys">confirmed</a> it was also targeted by a <a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> attack at around the same time as Twilio, but was not breached as a result due to the company-wide use of hardware-based, FIDO2-compliant <a href="https://www.itpro.com/security/361870/five-things-to-consider-before-choosing-an-mfa-solution" data-original-url="https://www.itpro.com/security/361870/five-things-to-consider-before-choosing-an-mfa-solution">multi-factor authentication (MFA)</a> keys.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Twilio account breach result of sophisticated social engineering campaign ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/368768/twilio-account-breach-result-of-sophisticated-social-engineering-campaign</link>
                                                                            <description>
                            <![CDATA[ Employees were subjected to personalised texts that impersonated Twilio's IT department, in a strategic credential harvesting operation ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bAduugM21z9zexTEHn8NP4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QuF5R6vL3xkkxUAYNY8XSd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 09 Aug 2022 10:32:42 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QuF5R6vL3xkkxUAYNY8XSd-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Man typing code on a laptop]]></media:description>                                                            <media:text><![CDATA[Man typing code on a laptop]]></media:text>
                                <media:title type="plain"><![CDATA[Man typing code on a laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QuF5R6vL3xkkxUAYNY8XSd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cloud communications platform Twilio has admitted that hackers gained access to some customer data last week after a social engineering attack handed internal login credentials to threat actors.</p><p>Twilio employees were subjected to <a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> texts requesting that they change their company passwords, each including a link with the keywords “Twilio”, “Okta” and “SSO” to make the URLs look more legitimate.</p><p>If an employee clicked the link, they were asked for their current credentials, which the threat actors harvested and used to access internal systems. </p><p>In an <a href="https://www.twilio.com/blog/august-2022-social-engineering-attack">incident report</a>, Twilio stated that the attacks were halted after the company “worked with the U.S. carriers to shut down the actors and worked with the hosting providers serving the malicious URLs to shut those accounts down.”</p><p>The phishing element of the breach was enhanced by <a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one" data-original-url="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">social engineering</a> on the part of the threat actors, who made the texts appear as if they were sent by the Twilio IT department. Texts also addressed employees by name in some examples.</p><p>The company also stated that it has heard first-hand that other companies were subjected to similar attacks, and that despite coordination with carrier networks the threat actors continue to operate. Investigations are ongoing.</p><p>The fact that former employees, as well as current employees, received the texts along with the threat actors’ reported ability to link phone numbers to individual names of employees, suggests a well-equipped operation backed by an understanding of the firm.</p><p>Twilio has been in touch with those customers whose data was potentially compromised and has no reason at this stage to suspect malicious activity outside of the accounts it has identified.</p><p>“We have reemphasized our security training to ensure employees are on high alert for social engineering attacks and have issued security advisories on the specific tactics being utilized by malicious actors since they first started to appear several weeks ago.</p><p>“We have also instituted additional mandatory awareness training on social engineering attacks in recent weeks. Separately, we are examining additional technical precautions as the investigation progresses.”</p><p>Social engineering attacks are difficult to mitigate because defence is only as strong as an individual’s ability to <a href="https://www.itpro.com/security/scams/355013/10-quick-tips-for-identifying-phishing-emails" data-original-url="https://www.itpro.com/security/scams/355013/10-quick-tips-for-identifying-phishing-emails">recognise something is wrong</a>. There is little that security systems can do to protect a company's infrastructure if users are willing to give up their passwords over the phone, and clicking links sent from an unrecognised number carries a similar risk.</p><p>It is always best to double-check the origin of communications claiming to be from officials and to question requests to change your password. <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">Two-factor authentication (2FA)</a> can also be a good barrier between employees and unwanted login attempts. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/368695/halborn-warns-of-active-metamask-phishing-campaign" data-original-url="/security/phishing/368695/halborn-warns-of-active-metamask-phishing-campaign">Halborn warns of active MetaMask phishing campaign</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/368751/cyber-attack-on-software-supplier-causes-major-outage-across-the-nhs" data-original-url="/security/cyber-attacks/368751/cyber-attack-on-software-supplier-causes-major-outage-across-the-nhs">Cyber attack on software supplier causes "major outage" across the NHS</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/malware/368764/defence-enterprises-and-government-agencies-in-russia-and-ukraine-targeted-by-state-hackers" data-original-url="/security/malware/368764/defence-enterprises-and-government-agencies-in-russia-and-ukraine-targeted-by-state-hackers">Defence enterprises, government agencies in Russia and Ukraine targeted by state-sponsored hackers</a></p></div></div><p>“Phishing is an important component of social engineering,” stated Paul Brucciani, a cyber security advisor at WithSecure.</p><p>“Email recipients are more likely to be deceived by a phishing email read on a smartphone than a desktop machine. Other risk factors are time pressure and organisational change which makes it harder to discern whether the context of the email is appropriate (unusual requests are not regarded as suspicious by email recipients if they are not familiar with organisational changes that have been made).</p><p>"A well-crafted, untargeted phishing email can dupe as many as 30% of users in almost any organisation.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers hiding malicious links in top Google search results, researchers warn ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/368621/hackers-hiding-malicious-links-in-top-google-search-results</link>
                                                                            <description>
                            <![CDATA[ Malicious adverts made to resemble links to websites are targeting some of the world’s most popular websites ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nCRefqmh6MDgEgK8MJrmQk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gVasdn9tFbj3pTsMGTj2TP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 21 Jul 2022 14:48:25 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gVasdn9tFbj3pTsMGTj2TP-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A phone showing the google homepage is held in someone&amp;#039;s hand in close-up, with a dimly-lit red wall in the background]]></media:description>                                                            <media:text><![CDATA[A phone showing the google homepage is held in someone&amp;#039;s hand in close-up, with a dimly-lit red wall in the background]]></media:text>
                                <media:title type="plain"><![CDATA[A phone showing the google homepage is held in someone&amp;#039;s hand in close-up, with a dimly-lit red wall in the background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gVasdn9tFbj3pTsMGTj2TP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google users have been warned of a new malvertising campaign in which people searching for popular websites are instead redirected to scam sites by malicious adverts.</p><p>Searches for some of the most popular websites were found to produce adverts that had been crafted to appear as if they were legitimate links to the desired website, with some appearing as the first listing on a results page.</p><p>Websites mimicked by the threat actors include YouTube, <a href="https://www.itpro.com/security/privacy/368542/amazon-gave-police-ring-footage-without-permission" data-original-url="https://www.itpro.com/security/privacy/368542/amazon-gave-police-ring-footage-without-permission">Amazon</a>, Facebook and Walmart, and in all cases appear to lead to a browser locker website where users are given scam warnings to call Microsoft support, or fake alerts from <a href="https://www.itpro.com/desktop-software/26635/how-to-turn-on-windows-defender" data-original-url="https://www.itpro.com/desktop-software/26635/how-to-turn-on-windows-defender">Windows Defender</a>, according to <a href="http://blog.malwarebytes.com/threat-intelligence/2022/07/google-ads-lead-to-major-malvertising-campaign">researchers at Malwarebytes</a>.</p><p>Malvertising, or the practice of hiding malware payloads behind online adverts, typically occurs on websites in more obvious ways, such as advertising that promises users free products or cash prizes.</p><p>In this case, however, researchers noted the sophistication of the campaign, with an example of a Facebook malvertising link containing no obvious discrepancies that might alert a user to its illegitimate nature.</p><p>However, because the malvertising uses <a href="https://www.itpro.com/security/malware/359716/fake-anydesk-ads-on-google-are-serving-malware" data-original-url="https://www.itpro.com/security/malware/359716/fake-anydesk-ads-on-google-are-serving-malware">Google Ads</a> as its platform, it is still denoted as an advert with bold text in the top-left corner reading ‘Ad’. This allows discerning users to at least identify that it is not a direct link to the website they were searching for, although this still does not reveal its malicious nature.</p><p>Researchers also noted that the redirect mechanism used by the threat actors is complex enough to make it difficult to ascertain where the advert will send would-be victims through HTML analysis.</p><p>Upon clicking on the advert, the page the user is sent to will either redirect to the legitimate website as a ‘decoy’, or load a secondary script where the malicious URL is found.</p><p>This is then loaded within an inline frame, an HTML element that loads a page within another. This has the effect of replacing the page with the scam element, but the user is not actually redirected a second time.</p><p>In this way, the URL of the malicious browser locker page is hidden from the user, who only sees the interim of the .com ‘cloaking domain’ (in the case of Malwarebytes Labs, this was named ‘shopmealy’).</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/368574/global-ransomware-activity-surges-again-following-a-short-decline-in-q1" data-original-url="/security/ransomware/368574/global-ransomware-activity-surges-again-following-a-short-decline-in-q1">Global ransomware activity surges again following a short decline in Q1</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/368476/why-are-ransomware-gangs-pivoting-to-rust" data-original-url="/security/ransomware/368476/why-are-ransomware-gangs-pivoting-to-rust">Why are ransomware gangs pivoting to Rust?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/368456/marriott-hit-by-data-breach-through-social-engineering" data-original-url="/security/data-breaches/368456/marriott-hit-by-data-breach-through-social-engineering">Marriott hit by data breach through social engineering</a></p></div></div><p>The fact that the adverts are listed on the search results before even some of the most popular websites in the world implies that the threat actors are willing to pay money in order to perpetrate the scam, which would be necessary in order to target keywords of such popularity.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="R6iyh2uD6GhaqjMMViGud" name="R6iyh2uD6GhaqjMMViGud.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/R6iyh2uD6GhaqjMMViGud.jpg" mos="https://cdn.mos.cms.futurecdn.net/R6iyh2uD6GhaqjMMViGud.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The Total Economic Impact™ of IBM Security MaaS360 with Watson</strong></p><p class="fancy-box__body-text">Cost savings and business benefits enabled by MaaS360</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/endpoint-security/367053/the-total-economic-impacttm-of-ibm-security-maas360-with-watson" data-original-url="/security/endpoint-security/367053/the-total-economic-impacttm-of-ibm-security-maas360-with-watson">FREE DOWNLOAD</a></p></div></div><p>Moreover, researchers found that the threat actors had separated the flows of the cloak and browser locker to prevent being taken down by authorities holistically, and used a mixture of expensive and free domains. The infrastructure of the malvertising also appears to have been hosted on both paid <a href="https://www.itpro.com/virtualisation/31628/what-is-server-virtualisation" data-original-url="https://www.itpro.com/virtualisation/31628/what-is-server-virtualisation">virtual private servers</a> and free cloud providers <a href="https://www.itpro.com/cloud/platform-as-a-service-paas/362593/what-is-paas" data-original-url="https://www.itpro.com/cloud/platform-as-a-service-paas/362593/what-is-paas">(PaaS)</a>.</p><p>“Google's proprietary technology and malware detection tools are used to regularly scan all creatives,” reads the Google support page on malware in advertising.</p><p>“Fourth-party calls or sub-syndication to any uncertified advertisers or vendors are forbidden. Any ad distributing malware is pulled to protect users from harm. Any Authorized buyer whose creative is found to contain malware is subject to a minimum three-month suspension.”</p><p>Malwarebytes Labs have stated that all necessary reports have been filed to notify Google of the adverts, and researchers reported every such advert under the label ‘An ad/listing violates other Google Ads policies’.</p><p><em>IT Pro</em> has contacted Google for comment.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Roblox hacker posts stolen documents online ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/368570/roblox-hacker-posts-stolen-documents-online</link>
                                                                            <description>
                            <![CDATA[ The company said that it has been investigating a phishing incident in which an employee was targeted through social engineering ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9KMC5w5oityezXFqJKumj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/E7KidiHhAmqLrjK5Uncted-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 18 Jul 2022 09:54:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/ncLkbsDMZ6b76Lc5iS6mZh.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/E7KidiHhAmqLrjK5Uncted-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A smartphone with Roblox characters and logo on the screen]]></media:description>                                                            <media:text><![CDATA[A smartphone with Roblox characters and logo on the screen]]></media:text>
                                <media:title type="plain"><![CDATA[A smartphone with Roblox characters and logo on the screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/E7KidiHhAmqLrjK5Uncted-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A hacker has reportedly posted several internal documents online stolen from a Roblox employee, which the company said were stolen by cyber criminals through <a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one" target="_blank" data-original-url="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">social engineering</a> tactics.</p><p>The documents appear to contain personal information of multiple individuals and relate to some of the most popular games and creators on the platform, as reported by <a href="https://www.vice.com/en/article/g5vqx3/hacker-posts-internal-roblox-employee-documents-online" target="_blank"><em>Motherboard</em></a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/368541/bandai-namco-finally-confirms-cyber-attack-ransomware" data-original-url="/security/ransomware/368541/bandai-namco-finally-confirms-cyber-attack-ransomware">Bandai Namco finally confirms massive cyber attack as ransomware outfit claims responsibility</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/368529/australian-university-suffers-data-breach-of-47000-students" data-original-url="/security/data-breaches/368529/australian-university-suffers-data-breach-of-47000-students">Australian university suffers data breach of 47,000 students</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/data-breaches/368556/chinese-authorities-summon-alibaba-executives-over-data-breach" data-original-url="/security/data-breaches/368556/chinese-authorities-summon-alibaba-executives-over-data-breach">Chinese authorities summon Alibaba executives over data breach</a></p></div></div><p>The hacker behind the attack released a 4GB archive of documents and posted a selection of images in a Roblox forum post. The files include email addresses, identification documents, and spreadsheets which appear to relate to creators from Roblox.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="hrPU5QE6XSvhX9ZzKzUfbd" name="hrPU5QE6XSvhX9ZzKzUfbd.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/hrPU5QE6XSvhX9ZzKzUfbd.png" mos="https://cdn.mos.cms.futurecdn.net/hrPU5QE6XSvhX9ZzKzUfbd.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>An analysis of the European cyber threat landscape</strong></p><p class="fancy-box__body-text">Human risk review 2022</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-crime/368501/an-analysis-of-the-european-cyberthreat-landscape" data-original-url="/security/cyber-crime/368501/an-analysis-of-the-european-cyberthreat-landscape">FREE DOWNLOAD</a></p></div></div><p>Roblox is a platform that allows users to create and design their own <a href="https://www.itpro.com/business-strategy/careers-training/358460/game-on-how-playing-video-games-could-level-up-your" target="_blank" data-original-url="https://www.itpro.com/business-strategy/careers-training/358460/game-on-how-playing-video-games-could-level-up-your">games</a> or worlds and play other users’ games while deploying microtransactions to monetise them. It’s worth around $68 billion and the company has claimed in the past that half of all children in the US play it in some form.</p><p>“Roblox has been actively investigating a phishing incident, which involved a Roblox employee being targeted by cyber criminals through social engineering tactics and using highly personalised scare tactics,” a Roblox spokesperson told <em>IT Pro</em>. “These stolen documents were illegally obtained as part of an <a href="https://www.itpro.com/security/ransomware/367624/the-rise-of-double-extortion-ransomware" target="_blank" data-original-url="https://www.itpro.com/security/ransomware/367624/the-rise-of-double-extortion-ransomware">extortion</a> scheme that we refused to cooperate with. We acted quickly upon learning of the incident, engaged independent experts to complement our information security team and have tuned our systems to seek to detect and prevent similar attempts.”</p><p>This isn’t the first time the gaming platform has been targeted by hackers, as in 2020 a <a href="https://www.vice.com/en/article/qj4ddw/hacker-bribed-roblox-insider-accessed-user-data-reset-passwords" target="_blank">hacker bribed a Roblox employee</a> to gain access to its back-end customer support panel. This allowed them to look up the personal information of over 100 million users and grant virtual in-game currency. The hacker was able to see users’ email addresses and change their passwords too. They could also ban users and remove two-factor authentication from their accounts.</p><p>Meanwhile, Bandai Namco, a video gaming giant, <a href="https://www.itpro.com/security/ransomware/368541/bandai-namco-finally-confirms-cyber-attack-ransomware" target="_blank" data-original-url="https://www.itpro.com/security/ransomware/368541/bandai-namco-finally-confirms-cyber-attack-ransomware">confirmed last week</a> it had been the victim of a cyber attack. The organisation confirmed that several of its companies in Asian regions were breached by a third party on 3 July 2022. Some reports claimed that a ransomware group, that uses the names AlphV and BlackCat, were behind a large ransomware attack on the gaming company.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Marriott hit by data breach through social engineering ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/368456/marriott-hit-by-data-breach-through-social-engineering</link>
                                                                            <description>
                            <![CDATA[ Unknown attackers were reportedly able to exfiltrate 20GB of information from the company ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dvcgK8tKUiapA6TiovgJzn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/CFxwA7UAstGuhYrP76KiES-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 06 Jul 2022 11:22:36 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/ncLkbsDMZ6b76Lc5iS6mZh.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/CFxwA7UAstGuhYrP76KiES-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Marriott International logo as seen on one of its hotels]]></media:description>                                                            <media:text><![CDATA[The Marriott International logo as seen on one of its hotels]]></media:text>
                                <media:title type="plain"><![CDATA[The Marriott International logo as seen on one of its hotels]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/CFxwA7UAstGuhYrP76KiES-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Marriott International has revealed that unknown hackers infiltrated its computer networks and then attempted to extort the company.</p><p>The incident reportedly took place a month ago and the attackers were able to exfiltrate 20GB of data including credit card and confidential information, according to <a href="https://www.databreaches.net/exclusive-marriott-hacked-again-yes-heres-what-we-know" target="_blank"><em>DataBreaches</em></a>. The hotel impacted appears to be BWI Airport Marriott in Maryland in the US.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/357600/marriott-international-fined" data-original-url="/policy-legislation/general-data-protection-regulation-gdpr/357600/marriott-international-fined">Marriott International fined £18.4m for 2014 data breach</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/361401/thailand-luxury-hotel-chain-hit-by-desorden-group" data-original-url="/security/cyber-attacks/361401/thailand-luxury-hotel-chain-hit-by-desorden-group">Luxury hotel chain hit twice by hackers after reneging on ransomware payment</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one" data-original-url="/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">A month in the life of a social engineer – part one</a></p></div></div><p>The <a href="https://www.itpro.com/security/28810/how-to-react-to-a-data-breach" target="_blank" data-original-url="https://www.itpro.com/security/28810/how-to-react-to-a-data-breach">breach</a> occurred because an attacker carried out <a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one" target="_blank" data-original-url="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">social engineering</a> and successfully tricked an associate at a Marriott hotel into giving them access to the associated computer, Marriott said in a statement to <em>IT Pro</em>. </p><p>“Our investigation determined that the information accessed primarily contained non-sensitive internal business files regarding the operation of the property,” added the hotel chain.</p><p>Marriott claimed that the incident was contained in six hours and that it had identified and was investigating it before they were contacted by the unknown attackers. The hotel chain hasn’t made any kind of payment to the attackers so far, although it didn’t reveal whether it had negotiated at all. </p><p>“They were communicating with us and went silent for no reason, it might be because of the high pricing, but we are always willing to find a deal with our clients and told Marriott that we can provide all the discounts in the world,” the attackers said, who contacted <em>DataBreaches</em>.</p><p>Marriott said that while most of the data acquired by the attackers was “non-sensitive internal business files”, the company will be notifying around 300 to 400 individuals and any regulators as required. It didn’t provide a full description as to what kind of information was involved for the individuals being notified. Law enforcement has reportedly been notified and Marriott said it was supporting that investigation.</p><p>The attackers provided samples of the data, some of which reportedly appeared to be internal business documents with confidential and proprietary information such as how to access a labour management and scheduling platform. Additionally, there appears to be a relatively recent file detailing the average wages by department.</p><p>Other documents contained information on hotel guests and personnel, including their names and jobs, as well as corporate credit card numbers for some companies paying for employees to stay at Marriott.</p><p>The attackers revealed they are an international group that has been working for approximately five years. They claimed to have avoided media coverage by establishing a reputation for keeping communications and relationships confidential.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="s7hnF2HF5HjCJogZeSiun4" name="s7hnF2HF5HjCJogZeSiun4.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/s7hnF2HF5HjCJogZeSiun4.png" mos="https://cdn.mos.cms.futurecdn.net/s7hnF2HF5HjCJogZeSiun4.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Understanding the economics of in-cloud data protection</strong></p><p class="fancy-box__body-text">Data protection solutions designed with cost optimisation in mind</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-computing/367728/understanding-the-economics-of-in-cloud-data-protection" data-original-url="/cloud/cloud-computing/367728/understanding-the-economics-of-in-cloud-data-protection">FREE DOWNLOAD</a></p></div></div><p>The group also claimed to never encrypt anything as it doesn’t want to interfere with business. It also added it doesn’t attack critical government infrastructure but focuses only on businesses.</p><p><em>IT Pro</em> has contacted Marriott for comment.</p><p>This isn’t the first time that Marriott has experienced a data breach. In 2020, it was <a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/357600/marriott-international-fined" target="_blank" data-original-url="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/357600/marriott-international-fined">fined £18.4 million</a> by a UK data regulator for a 2014 data breach that affected 339 million guest records worldwide. The ICO found that the company failed to put appropriate technical or organisational measures in place to <a href="https://www.itpro.com/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach" target="_blank" data-original-url="https://www.itpro.com/security/data-breaches/358455/10-ways-to-protect-your-company-from-the-next-big-data-breach">protect the personal data</a> being processed on its systems, as required by GDPR.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ BRATA malware has evolved to target online banking across Europe, researchers warn ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/368330/brata-malware-has-evolved-to-target-online-banking</link>
                                                                            <description>
                            <![CDATA[ The new variant can now access SMS, GPS, and device control to better steal financial data ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kymLkrtaBkhXie5yhAfKFF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vmH28pzrtFdvcUoS5Rnk6B-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jun 2022 13:43:21 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rory Bathgate ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DnNrFxEA7RRECVgFxXR4V7.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vmH28pzrtFdvcUoS5Rnk6B-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An animated mockup of a login in form being lifted out of a laptop screen to symbolise a phishing attack]]></media:description>                                                            <media:text><![CDATA[An animated mockup of a login in form being lifted out of a laptop screen to symbolise a phishing attack]]></media:text>
                                <media:title type="plain"><![CDATA[An animated mockup of a login in form being lifted out of a laptop screen to symbolise a phishing attack]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vmH28pzrtFdvcUoS5Rnk6B-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>An Android malware strain, known for its attacks on the Google Play store, has been spotted targeting the login pages of online banks, in what experts believe is a long-term shift in strategy by its developers.</p><p>The Brazilian Remote Access Tool (BRATA) first surfaced in 2018, <a href="https://www.itpro.com/security/malware/359189/brata-malware-disguises-itself-as-security-tools-on-google-play" data-original-url="https://www.itpro.com/security/malware/359189/brata-malware-disguises-itself-as-security-tools-on-google-play">targeting Android users with fake antivirus apps</a> and similar security software in an effort to steal credentials.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="PGoruQcVQLZaD3tFfbynhC" name="PGoruQcVQLZaD3tFfbynhC.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/PGoruQcVQLZaD3tFfbynhC.png" mos="https://cdn.mos.cms.futurecdn.net/PGoruQcVQLZaD3tFfbynhC.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>The Total Economic Impact™ of Mimecast</strong></p><p class="fancy-box__body-text">Cost savings and business benefits enabled by using Mimecast with Microsoft 365</p><p class="fancy-box__body-text">FREE DOWNLOAD</p></div></div><p>However, new attacks suggest the group behind the <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a> has pivoted towards targeting financial institutions directly, attempting to put fake login pages in front of users trying to access online banking services.</p><p>The new variant has been <a href="https://www.cleafy.com/cleafy-labs/brata-is-evolving-into-an-advanced-persistent-threat#4">flagged by the cyber security organisation Cleafy</a>, who provided screenshots of a phishing page new to BRATA that mimics the login field for a prominent bank, asking users to input their PIN and client number.</p><p>“They usually focus on delivering malicious applications targeted to a specific bank for a couple of months, and then moving to another target,” Cleafy explained in a blog post on the discovery.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="uXXvndVZJhDUnW5YXqF3qc" name="" alt="A screenshot of a fake Italian bank login screen asking the users to enter a client number and PIN" src="https://cdn.mos.cms.futurecdn.net/uXXvndVZJhDUnW5YXqF3qc.png" mos="https://cdn.mos.cms.futurecdn.net/uXXvndVZJhDUnW5YXqF3qc.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Moves to <a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one" data-original-url="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">socially engineer</a> the customers of specific banks indicate that BRATA’s threat actors are curating their pool of targets. Formerly localised to South America, efforts to steal financial information have resulted in a shift in focus towards users across mainland Europe and the UK, with Italy-based Cleafy first discovering the variant through increased activity across the region.</p><p>The evolution has also seen the introduction of new features, which allow the strain to seek permissions over SMS, GPS, and <a href="https://www.itpro.com/mobile/29775/best-mdm-solutions" data-original-url="https://www.itpro.com/mobile/29775/best-mdm-solutions">device management</a>. Additionally, on install an event-logger plugin labelled 'unrar.jar' is downloaded from the BRATA command and control (C2) infrastructure. Cleafy expressed concerns that these additions “could be used to perform a complete Account Takeover (ATO) attack”.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/362292/microsoft-releases-analysis-of-web3-ice-phishing-attack" data-original-url="/security/phishing/362292/microsoft-releases-analysis-of-web3-ice-phishing-attack">Microsoft releases analysis of Web3 'ice phishing' attack</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/368284/what-is-phishing-as-a-service-phaas" data-original-url="/security/cyber-security/368284/what-is-phishing-as-a-service-phaas">The rise of phishing as a service (PhaaS) and how to tackle it</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/361693/android-banking-trojan-infects-300000-devices" data-original-url="/security/hacking/361693/android-banking-trojan-infects-300000-devices">Over 300,000 Android users downloaded banking trojan malware</a></p></div></div><p>At time of writing, targeted devices do not appear to be exchanging information with the threat actors behind the malware, and that this may indicate that the newest variant BRATA.A is still undergoing development, according to researchers.</p><p>However, the organisation has already identified a separate SMS stealer app connected to the BRATA C2 infrastructure, also targeting users in mainland Europe and the UK. With threat actors testing out new attack vectors linked by a common framework, there are fears that, once active, this variant could prove effective at taking over users’ financial accounts.</p><p>For this reason, Cleafy has assigned BRATA an Advanced Persistent Threat (APT) status, which they define as “an attack campaign in which criminals establish a long-term presence on a targeted network to steal sensitive information".</p><p>As malware evolves to deceive in more sophisticated ways, it is important that users keep up to date with threat prevention tactics, and only download apps from trusted sources.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security BSides commits to greater conference diversity after speaker backlash ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/cyber-security/368327/security-bsides-conference-diversity-after-speaker-backlash</link>
                                                                            <description>
                            <![CDATA[ A surprise booking of a divisive social engineer prompted a number of cyber security experts to pull out of BSides Cleveland ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kRpiWLT2rv85Ni6GcAuLi7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/XWquzj52tUqi8c5SQFJHdc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jun 2022 10:47:14 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/XWquzj52tUqi8c5SQFJHdc-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A close up of a man stood at lectern speaking at business conference]]></media:description>                                                            <media:text><![CDATA[A close up of a man stood at lectern speaking at business conference]]></media:text>
                                <media:title type="plain"><![CDATA[A close up of a man stood at lectern speaking at business conference]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/XWquzj52tUqi8c5SQFJHdc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security BSides has promised to bring greater diversity to the organisation of future conferences after the secret booking of a banned conference speaker prompted anger among the security community.</p><p>The two-day US-based BSides Cleveland cyber security event hosted Chris Hadnagy, a social engineer previously banned by DEF CON for undisclosed misconduct claims, as a mystery guest speaker on its second day.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business/business-strategy/367629/diversity-in-tech-change-is-painfully" data-original-url="/business/business-strategy/367629/diversity-in-tech-change-is-painfully">Diversity in tech is a well-trodden path, but change is painfully slow</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/careers-training/361629/fifth-of-uk-security-pros-discriminated-against-in-2021" data-original-url="/business-strategy/careers-training/361629/fifth-of-uk-security-pros-discriminated-against-in-2021">Fifth of UK security pros discriminated against in 2021</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/business-strategy/careers-training/357871/what-makes-an-effective-diversity-strategy" data-original-url="/business-strategy/careers-training/357871/what-makes-an-effective-diversity-strategy">What makes an effective diversity strategy?</a></p></div></div><p>Hadngay gave his talk at 9am, with the event’s digital schedule only revealing his name after his talk had ended. This prompted a number of prominent cyber security experts to pull out of the remainder of the event, with many claiming the event had manipulated attendees.</p><p>Hadnagy was originally billed to speak at BSides Cleveland as far back as autumn 2021, but pulled out following the DEF CON controversy.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1538166123035824129"></a></p></blockquote><div class="see-more__filter"></div></div><p>BSides has now promised that a team of four organisers will run each Cleveland event, with the team made up of <a href="https://www.itpro.com/business/business-strategy/367629/diversity-in-tech-change-is-painfully" data-original-url="https://www.itpro.com/business/business-strategy/367629/diversity-in-tech-change-is-painfully">diverse backgrounds</a>, rather than just the one organiser. Security BSides will also step in to assist the organisers with logistics and advice on how to book guests.</p><p>The lone organiser tasked with running the most recent BSides Cleveland later apologised for the booking and has now stepped down, the organisation said.</p><p>“The decision to include Chris Hadnagy in the 2022 BSides Cleveland event was my decision,” said event organiser Rockie Brockway. “Furthermore, the decision to keep the opening speaker slot as special guest instead of naming Chris specifically was also my decision. I am apologising to everyone that my decisions harmed, whether strangers, family, sponsors, or friends, and I am deeply sorry for that.</p><p>“I understand that my decisions may have destroyed the trust that I have built over my years in the BSides community, and I accept accountability for my actions. Effective immediately I resign from BSidesCLE leadership.”</p><p>Following up on Twitter, Security BSides <a href="https://twitter.com/SecurityBSides/status/1539058902570000387">did not confirm</a> if Hadnagy or similarly divisive speakers would be banned from other BSides regional events.</p><p>The organisations said it was a decentralised movement and that there is no central governing body that can prohibit future event organisers from selecting individual speakers. It conceded that the BSides Cleveland event “will likely inform others’ decisions”.</p><p>“2022 was the first year BSidesCLE had a two-day event,” said Security BSides in a <a href="http://www.securitybsides.com/w/page/149536464/Security%20BSides%20Response%20to%20the%20BSides%20Cleveland%20Incident">statement</a>. “It was well attended and successful by any metric, up until the morning of day two, when Hadnagy was revealed as the morning’s surprise guest. Cleveland has a sizeable security community that can continue to benefit from a healthy BSides.</p><p>“Conversations and debates will continue and wounds will take time to heal. This is only the first step in moving BSidesCLE into its next chapter.”</p><h2 id="who-is-chris-hadnagy">Who is Chris Hadnagy?</h2><p>Hadnagy is a widely referenced expert on <a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one" data-original-url="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">social engineering</a> and author of a book on human hacking. Most recently in February 2022, he was banned from the prominent cyber security conference DEF CON for violations of its code of conduct, the nature of which have never been made public.</p><p>It is a rare occurrence that a <a href="https://www.itpro.com/security/28133/what-is-cyber-security" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">cyber security</a> conference bans individuals from speaking at events. Although the nature of the accusations against Hadnagy are not public knowledge, those with inside information believe the ban was justified.</p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1538510774095826945"></a></p></blockquote><div class="see-more__filter"></div></div><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr"><a href="https://twitter.com/cantworkitout/status/1538508044333613058"></a></p></blockquote><div class="see-more__filter"></div></div><p>In a follow-up statement regarding his banning, Hadnagy dismissed the allegations of misconduct as sexual in nature, having been told by organisers this was not the case, though he also said “I still don’t know what the accusations are”.</p><p>Hadnagy had previously been criticised for insulting a non-binary individual online, and used a previous BSides appearance to apologise for it.</p><p>He also said he has drawn criticism from his training courses between 2015 and 2017. Without drawing examples himself, notorious reviews included one from <a href="https://shafpatel.wordpress.com/2015/05/21/hello-world">a blind person seeking advice to access one of Hadnagy’s courses</a> but received unsympathetic responses from the social engineer.</p><p>Hadnagy said in his post-DEF CON statement that he was sorry for any offence caused and that he does not <a href="https://www.itpro.com/business-strategy/careers-training/361629/fifth-of-uk-security-pros-discriminated-against-in-2021" data-original-url="https://www.itpro.com/business-strategy/careers-training/361629/fifth-of-uk-security-pros-discriminated-against-in-2021">discriminate</a> against anyone on any characteristic or trait.</p><p>At the most recent BSides Cleveland event, he delivered the same talk as the one he gave at the BSides Idaho Falls event last year. The talk’s topic was on cancel culture. The title of the talk at both events was also exactly the same: ‘Who needs a court of law? I have social media”.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Deepfake attacks expected to be next major threat to businesses ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/368299/deepfake-attacks-expected-to-be-next-big-threat-to-businesses</link>
                                                                            <description>
                            <![CDATA[ Cisco’s cyber security experts agreed that social norms may also become “super weird” as a result ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">w9Re8JS8C8n1fqPDgFFV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NEaP2bkgWaYcnUW3jeQDTL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jun 2022 08:51:43 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Connor Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LPjgE2kGKixS9aF7Jdp2mT.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NEaP2bkgWaYcnUW3jeQDTL-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An abstract image showing two digital faces looking at each other]]></media:description>                                                            <media:text><![CDATA[An abstract image showing two digital faces looking at each other]]></media:text>
                                <media:title type="plain"><![CDATA[An abstract image showing two digital faces looking at each other]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NEaP2bkgWaYcnUW3jeQDTL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Deepfake-driven cyber attacks are set to become more popular in the near future as the artificial intelligence technology (AI) becomes more widely used, security experts at Cisco warned this week.</p><p>Such attacks could involve fake videos of companies’ CEOs being sent to employees, telling them to conduct wire transfers, for example.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="NJSDBJZzAjpg5aq4yVq3A8" name="NJSDBJZzAjpg5aq4yVq3A8.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/NJSDBJZzAjpg5aq4yVq3A8.png" mos="https://cdn.mos.cms.futurecdn.net/NJSDBJZzAjpg5aq4yVq3A8.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Recommendations for managing AI risks</strong></p><p class="fancy-box__body-text">Integrate your external AI tool findings into your broader security programs</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence-ai/367499/recommendations-for-managing-ai-risks" data-original-url="/technology/artificial-intelligence-ai/367499/recommendations-for-managing-ai-risks">FREE DOWNLOAD</a></p></div></div><p><a href="https://www.itpro.com/security/357591/why-deepfakes-could-threaten-everything-from-biometrics-to-democracy" data-original-url="https://www.itpro.com/security/357591/why-deepfakes-could-threaten-everything-from-biometrics-to-democracy">Deepfake technology</a> involves training an AI program with large amounts of data in order for it to learn how any given individual would look when saying certain words, and how they sound, including accurate intonation and speech pauses.</p><p>“Well, your targets are those that have public personas, because you need lots of training footage to do this,” said Nick Biasini, head of outreach at Cisco Talos. “So it'd be much easier to pick your CEO, go after the CEO, because they're on video constantly, and they're talking constantly. You could use that to easily make a video of them that all of a sudden your CEO is calling you, it looks like your CEO sounds like your CEO, and they're telling you to do a wire transfer.”</p><p>“There literally is a threshold of how much data you need to establish a ground truth to model the voiceprint and once that model is sufficient, shove whatever you want through it,” said TK Keanini, VP of security architecture and CTO at Cisco Secure.</p><p>Keanini also said that social norms could become “super weird” if such attacks became more popular. Giving the example of a family member calling a loved one, knowledge of this kind of attack may result in scenarios where additional questions will need to be asked just to check that the person they are dealing with is real. In this sense, it's seen as an evolution of the type of <a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing attacks</a> we know today, with a layer of suspicion attached to communication from specific people.</p><p>Fears around the use of deepfake technology in the cyber security landscape have been present for a number of years. Trend Micro revealed that such attacks <a href="https://www.itpro.com/ransomware/34432/deepfake-ransomware-among-experts-list-of-cyber-fears" data-original-url="https://www.itpro.com/ransomware/34432/deepfake-ransomware-among-experts-list-of-cyber-fears">were on its list of top cyber threats</a> for the future as far back as 2019, when it presented to delegates of CloudSec.</p><p>When asked if deepfake use in cyber security was simply a gimmick that would never materialise, Keanini said: “It's definitely real. It doesn't take much to fake the backgrounds, it's not that much further to fake the foreground”.</p><p>“And as we move more and more to [hybrid working] collaboration, everybody's on video conferencing now, so it makes it even easier to launch those types of attacks than it would have been before,” said Biasini.</p><p>The pair revealed their expectations during a discussion about emerging cyber threats, chief among which was the idea that <a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one" data-original-url="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">social engineering</a> tactics would become more sophisticated and more pervasive.</p><p>Speaking at Cisco Live, JJ Cummings, managing principal of threat intelligence and interdiction at Cisco, said that foreign adversaries, specifically, were using increasingly sophisticated social engineering tactics on victims, based on the cases Cisco Talos has seen.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one" data-original-url="/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">A month in the life of a social engineer – part one</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/367737/what-makes-for-the-most-deceptive-phishing-attacks" data-original-url="/security/phishing/367737/what-makes-for-the-most-deceptive-phishing-attacks">What makes for the most deceptive phishing attacks?</a></p></div></div><p>“One of the things that we started to see and one of the groups that we're tracking, since at least September of 2021, is very directed, very effective social engineering,” said Cummings.</p><p>“[It involves] making phone calls to specific strategically targeted individuals within an organisation, convincing those individuals that they're members of IT, or some support staff, and those individuals are doing one of two things: possibly giving up a password, certainly accepting a <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">multifactor authentication</a> push to their device, letting the bad guy in because the bad guy’s stolen the password.”</p><p>Biasini said that social engineering should be one of the biggest concerns for businesses over the coming years, adding that because the security industry is getting better at stopping systems from being exploited, attackers will turn to people instead.</p><p>Deepfake technology is what’s going to make the threat “exponentially worse” and that “people have a hard enough time not trusting stuff that they read online; just wait until they're having to not trust their eyes and their ears when they're watching people say the things that they're saying,” he said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ LAPSUS$ breached T-Mobile systems, stole source code ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/367483/lapsus-breached-t-mobile-systems-stole-source-code</link>
                                                                            <description>
                            <![CDATA[ T-Mobile has denied that the hackers obtained customer or government information ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2Fcn3q3Ahi8FtWUUDpSWxH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zRLtQpjde4eD4Rxqtkapzc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 25 Apr 2022 11:23:26 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sabina Weston ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zRLtQpjde4eD4Rxqtkapzc-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A pink T-Mobile logo on a storefront in Aachen, Germany]]></media:description>                                                            <media:text><![CDATA[A pink T-Mobile logo on a storefront in Aachen, Germany]]></media:text>
                                <media:title type="plain"><![CDATA[A pink T-Mobile logo on a storefront in Aachen, Germany]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zRLtQpjde4eD4Rxqtkapzc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The LAPSUS$ hacking collective managed to breach T-Mobile systems using employee credentials and downloaded more than 30,000 of the company’s source code repositories.</p><p>This is according to evidence obtained by investigative reporter Brian Krebs, who detailed the data breach on his <em>KrebsOnSecurity</em> blog.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/367246/lapsus-globant-breach-exposes-apple-facebook-data" data-original-url="/security/hacking/367246/lapsus-globant-breach-exposes-apple-facebook-data">LAPSUS$ returns with Globant breach, leaking trove of data on top global businesses</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/367236/leaked-mandiant-report-okta-breach-lapsus-operation" data-original-url="/security/cyber-security/367236/leaked-mandiant-report-okta-breach-lapsus-operation">Leaked report on Okta breach reveals finer details of LAPSUS$ operation</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/367416/t-mobile-allegedly-tried-to-buy-leaked-data-from-a-hacker-forum-for-200k" data-original-url="/security/hacking/367416/t-mobile-allegedly-tried-to-buy-leaked-data-from-a-hacker-forum-for-200k">T-Mobile allegedly tried to buy leaked data from a hacker forum for $200k</a></p></div></div><p><a href="https://www.itpro.com/security/cyber-attacks/367199/what-is-the-lapsus-group-who-is-behind-the-criminal-operation" data-original-url="https://www.itpro.com/security/cyber-attacks/367199/what-is-the-lapsus-group-who-is-behind-the-criminal-operation">LAPSUS$</a> members accessed T-Mobile's internal company tools on several occasions in March, using T-Mobile VPN credentials purchased through the <a href="https://www.itpro.com/security/32117/what-is-the-dark-web" data-original-url="https://www.itpro.com/security/32117/what-is-the-dark-web">dark web</a>, including a stolen data trading platform known as the Russian Market.</p><p><a href="https://krebsonsecurity.com/wp-content/uploads/2022/04/anothertmob.png">Conversation screenshots</a> obtained by Krebs show how easy it was for the hackers to find new login credentials in the case that a targeted employee had changed their password, using <a href="https://www.itpro.com/security/hacking/358575/eight-brits-arrested-over-hacking-celeb-mobile-phones" data-original-url="https://www.itpro.com/security/hacking/358575/eight-brits-arrested-over-hacking-celeb-mobile-phones">SIM-swapping</a> to bypass two-factor authentication. LAPSUS$ member ‘Amtrak’ had detailed to a member known as ‘White’, who has been using the Lapsus Jobs account, how they had found a new T-Mobile employee account to target, allowing them to access the company’s <a href="https://www.itpro.com/collaboration/33647/slack-review-free-your-business-comms" data-original-url="https://www.itpro.com/collaboration/33647/slack-review-free-your-business-comms">Slack</a> communications.</p><p>‘White’, also known as ‘WhiteDoxbin’ and ‘Oklaqq’, is an Oxford-based teenager who was one of the LAPSUS$ members arrested and charged in late March. He is believed to be one of the leaders of the hacking group, despite his young age – estimated to be 16 or 17 years old at the time of the attacks.</p><p><a href="https://krebsonsecurity.com/wp-content/uploads/2022/04/parentsknowisimswap.png">Screenshots</a> obtained by Krebs seem to hint that the hackers’ legal guardians are aware of criminal activity, with ‘Amtrak’ telling ‘White’: “Parents knkw [sic] I simswap [sic]”.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="nrLP4J9zrGeXVej3Fjg2DP" name="nrLP4J9zrGeXVej3Fjg2DP.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/nrLP4J9zrGeXVej3Fjg2DP.png" mos="https://cdn.mos.cms.futurecdn.net/nrLP4J9zrGeXVej3Fjg2DP.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Secure hybrid cloud for dummies</strong></p><p class="fancy-box__body-text">Accelerate transformation with hybrid cloud</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/hybrid-cloud/362139/secure-hybrid-cloud-for-dummies" data-original-url="/cloud/hybrid-cloud/362139/secure-hybrid-cloud-for-dummies">FREE DOWNLOAD</a></p></div></div><p>Apart from T-Mobile’s Slack channels and Bitbucket source code repository, LAPSUS$ also managed to gain access to the company’s customer account management platform Atlas.</p><p>Despite this, T-Mobile has stated that “the systems accessed contained no customer or government information or other similarly sensitive information, and we have no evidence that the intruder was able to obtain anything of value”.</p><p>“Several weeks ago, our monitoring tools detected a bad actor using stolen credentials to access internal systems that house operational tools software. Our systems and processes worked as designed, the intrusion was rapidly shut down and closed off, and the compromised credentials used were rendered obsolete,” the company told <a href="https://krebsonsecurity.com/2022/04/leaked-chats-show-lapsus-stole-t-mobile-source-code"><em>KrebsOnSecurity</em></a>.</p><p>This is the third known data breach for T-Mobile in 15 months, following an incident affecting <a href="https://www.itpro.com/security/data-breaches/358221/hackers-breach-t-mobile-customer-records" data-original-url="https://www.itpro.com/security/data-breaches/358221/hackers-breach-t-mobile-customer-records">around 200,000 customers</a> in January 2021 and <a href="https://www.itpro.com/security/data-breaches/360609/t-mobile-confirms-hackers-accessed-almost-50-million-records" data-original-url="https://www.itpro.com/security/data-breaches/360609/t-mobile-confirms-hackers-accessed-almost-50-million-records">47.8 million customers in August 2021</a>. The company also fell victim to three other breaches between 2018 and 2020.</p><p>Commenting on the news, Mike Newman, CEO of identity & access management (IAM) solution provider My1Login told <em>IT Pro</em> that “this latest breach on T-Mobile is yet another example of how attackers are relying on credential theft to carry out ransomware attacks”.</p><p>“Today all ransomware gangs, from BlackCat to LAPSUS$ to <a href="https://www.itpro.com/security/359580/new-darkside-ransomware-variant-targets-disk-partitions" data-original-url="https://www.itpro.com/security/359580/new-darkside-ransomware-variant-targets-disk-partitions">DarkSide</a> have been relying on compromised user accounts to gain an initial foothold on an organisation’s network and then turn off security controls, steal data and deploy ransomware. This means to fight back against these attacks we need to focus on improving the security of user credentials and passwords, so they can’t be stolen or <a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one" data-original-url="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">socially engineered</a> out of victims in the first place,” he added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ IT Pro 20/20: The new frontier of innovation ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/hardware/362979/it-pro-2020-the-new-frontier-of-innovation</link>
                                                                            <description>
                            <![CDATA[ Businesses are putting green tech at their heart of their buying decisions, and manufacturers and paying attention ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3Hw5YYDLsAqWCeqd41bWG8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/djYrrSSs7crFEWKMBxSgVk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Feb 2022 12:28:01 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dale Walker ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/YhUVp3rWtcZPM5XznPeTmX.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/djYrrSSs7crFEWKMBxSgVk-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[IT Pro 20/20: The new frontier of innovation]]></media:description>                                                            <media:text><![CDATA[IT Pro 20/20: The new frontier of innovation]]></media:text>
                                <media:title type="plain"><![CDATA[IT Pro 20/20: The new frontier of innovation]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/djYrrSSs7crFEWKMBxSgVk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Welcome to issue 25 of IT Pro 20/20, distilling the most important themes of the previous month into a simple, easy-to-read package.</p><p>This month we look at the industry-wide push for sustainable development, which was very much on display at this year’s CES. We’ve highlighted a handful of major players that are doing some pretty interesting things.</p><p>A new year also brings new opportunities, and so we’ve also explained why there’s never been a better time to start a side hustle, and how to go about it.</p><div ><table><tbody><tr><td  ><a href="https://dennis.cvtr.io/lp/it-pro-2020-email?wp=8353&locale=1">DOWNLOAD ISSUE 25 OF IT PRO 20/20 HERE</a></td></tr></tbody></table></div><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="CbEwa7LXVuQcBKDsZqj3EX" name="" alt="IT Pro 20/20: The new frontier of innovation" src="https://cdn.mos.cms.futurecdn.net/CbEwa7LXVuQcBKDsZqj3EX.jpg" mos="https://cdn.mos.cms.futurecdn.net/CbEwa7LXVuQcBKDsZqj3EX.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>The next IT Pro 20/20 will be available on 28 January – previous issues can be found here. If you would like to receive each issue in your inbox as they release, you can <a href="https://www.itpro.com/magazine-signup" rel="noopener" target="_blank" data-original-url="https://www.itpro.com/magazine-signup">subscribe to our mailing list here</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ LinkedIn phishing attacks have surged 232% since start of February ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/362291/linkedin-phishing-attacks-increased-by-232-in-february</link>
                                                                            <description>
                            <![CDATA[ Hackers are tricking users into clicking on fake LinkedIn alerts in an effort to steal login information ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uatpPFhLH7REHnLk9kesvF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3ovKafEKKxutjECgSx7y9N-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Feb 2022 12:47:31 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GFZtdGsYoXrkh3Jhj4ZKTc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/3ovKafEKKxutjECgSx7y9N-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The LinkedIn logo displayed on a smartphone resting on a keyboard]]></media:description>                                                            <media:text><![CDATA[The LinkedIn logo displayed on a smartphone resting on a keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[The LinkedIn logo displayed on a smartphone resting on a keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3ovKafEKKxutjECgSx7y9N-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Email <a href="https://www.itpro.com/security/phishing" target="_blank" data-original-url="https://www.itpro.com/search/phishing">phishing</a> attacks that use the LinkedIn brand have increased by 232% since 1 February, 2022, research has revealed.</p><p>The attacks tend to use display name spoofing and stylised HTML templates to <a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one" target="_blank" data-original-url="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">socially engineer victims</a> into clicking on phishing links and then entering their credentials into fraudulent websites, according to cyber security firm <a href="https://www.egress.com/resources/cybersecurity-information/phishing/linkedin-phishing-attacks" target="_blank">Egress</a>.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one" data-original-url="/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">A month in the life of a social engineer – part one</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/362006/dhl-overtakes-microsoft-as-the-most-imitated-brand-in-phishing-attacks" data-original-url="/security/phishing/362006/dhl-overtakes-microsoft-as-the-most-imitated-brand-in-phishing-attacks">DHL overtakes Microsoft as the most imitated brand in phishing attacks</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/360713/phishing-attacks-increase-as-hackers-take-advantage-of-pandemic" data-original-url="/security/phishing/360713/phishing-attacks-increase-as-hackers-take-advantage-of-pandemic">Phishing attacks increase as hackers take advantage of pandemic</a></p></div></div><p>The emails use targeted subject lines associated with LinkedIn, including “You appeared in 4 searches this week” or “You have 1 new message”. The emails contain the LinkedIn logo and brand colours, as well as using other well-known organisation names, like American Express, to make the attacks more convincing.</p><p>When clicked, the phishing links send the victim to a website that harvests their LinkedIn log-in credentials, according to the research.</p><p>Current employment trends are making these kinds of attacks more convincing, with the research citing how “The Great Resignation” continues to dominate headlines as a record number of US citizens left their jobs in 2021 for new opportunities.</p><p>“It is likely these phishing attacks aim to capitalise on jobseekers (plus curious individuals) by flattering them into believing their profile is being viewed and their experience is relevant to household brands,” Egress stated in its report.</p><p>Although the display name is always LinkedIn and the emails follow a similar pattern, they are sent from different webmail addresses.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/EiyiaUoQvOU" allowfullscreen></iframe></div></div><p>The <a href="https://www.itpro.com/security" target="_blank" data-original-url="https://www.itpro.com/security">security</a> company said that it’s unknown whether these attacks are the work of one cyber criminal or a gang operating together. However, most targets are companies in North America and the UK, operating across a variety of industries.</p><p>Egress advised that individuals should take extreme caution when reading notification emails that request them to click on a hyperlink, especially on mobile devices. It recommends hovering over links before clicking on them to ensure they are going to a trusted source, and going directly to LinkedIn to check for messages and updates.</p><p>Last month, <a href="https://www.itpro.com/security/phishing/362006/dhl-overtakes-microsoft-as-the-most-imitated-brand-in-phishing-attacks" target="_blank" data-original-url="https://www.itpro.com/security/phishing/362006/dhl-overtakes-microsoft-as-the-most-imitated-brand-in-phishing-attacks">DHL overtook Microsoft as the most frequently mimicked brand for phishing attacks</a>, accounting for 23% of all phishing attempts. Microsoft accounted for only 20% of all attempts, down from 29% the previous quarter. LinkedIn came fifth in the rankings, accounting for 8% of all phishing attempts.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A month in the life of a social engineer – part one ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one</link>
                                                                            <description>
                            <![CDATA[ With hackers finding more ingenious ways to exploit human flaws, we get inside the planning stages of a social engineering attack ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mZrd9tGzmrCpz2YgXkrFPB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TAKzjjQEdiyosJwT5XWDgZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Jan 2022 09:11:08 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jane Hoskyn ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/tBZadTMWfrLojxUt4fjfGA.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TAKzjjQEdiyosJwT5XWDgZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The outline of a mysterious figure surrounded by red and blue lights]]></media:description>                                                            <media:text><![CDATA[The outline of a mysterious figure surrounded by red and blue lights]]></media:text>
                                <media:title type="plain"><![CDATA[The outline of a mysterious figure surrounded by red and blue lights]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TAKzjjQEdiyosJwT5XWDgZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><strong><em>With <a href="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business" target="_blank" data-original-url="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business">social engineering</a> set to plague 2022, understanding cyber criminals’ tactics, and the mistakes they make, might help us defend against their efforts.</em></strong> <strong><em>This is the first entry in a four-part series, published weekly, exploring how social engineers plan their attacks – from identifying targets to exploitation.</em></strong></p><p>Human beings are hard-wired to trust, help, connect and impress. It's what makes us so valuable to your organisation. These traits, unfortunately, also make humans your <a href="https://www.itpro.com/security/28967/surviving-human-error" target="_blank" data-original-url="https://www.itpro.com/security/28967/surviving-human-error">fatal flaw</a>. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business" data-original-url="/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business">Social engineering: The biggest security risk to your business</a></p></div></div><p>Social engineering is the art of tricking people into doing something that's in your interests and not in your victims’, with a view to gathering information or achieving an action, such as letting you into their house. It's a criminal tactic as old as time, and a perfect fit for today's <a href="https://www.itpro.com/infrastructure/network-internet/359635/navigating-connectivity-for-your-staff" target="_blank" data-original-url="https://www.itpro.com/infrastructure/network-internet/359635/navigating-connectivity-for-your-staff">networked workplace</a>. </p><p>Cyber criminals have utilised social engineering effectively through the years, turning the best employees into unwitting accomplices in <a href="https://www.itpro.com/security/data-breaches/360389/data-breach-costs-surge-to-record-high-in-2021" target="_blank" data-original-url="https://www.itpro.com/security/data-breaches/360389/data-breach-costs-surge-to-record-high-in-2021">security breaches</a>. The consequence, warn experts, has been a surge in active threats to critical and sensitive systems. </p><h2 id="know-thy-enemy">Know thy enemy</h2><p>"There's a tidal wave of it coming," former cyber criminal and We Fight Fraud founder, Tony Sales, tells <em>IT Pro</em>. "National infrastructure is at risk because of social engineering. I think the whole country is at risk without even realising it." </p><p>Figures bear out this alarming language, with <a href="https://www.verizon.com/business/resources/reports/dbir" target="_blank">Verizon finding</a> 85% of data breaches involve attempts to prey on human weaknesses. <a href="https://purplesec.us/resources/cyber-security-statistics">Purplesec claims</a>, meanwhile, 98% of attacks rely on some form of social engineering.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="usDgyxpNazobG5oMazKCfd" name="" alt="Tony Sales is a former fraudster and the founder of We Fight Fraud" src="https://cdn.mos.cms.futurecdn.net/usDgyxpNazobG5oMazKCfd.jpg" mos="https://cdn.mos.cms.futurecdn.net/usDgyxpNazobG5oMazKCfd.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Adam Boome)</span></figcaption></figure><p><em><strong>Tony Sales is a former fraudster and founder of We Fight Fraud</strong></em></p><p>It's easy to see why cyber criminals find social engineering so effective; it takes much less effort and ingenuity to con an individual into giving you access to company computers than <a href="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale" target="_blank" data-original-url="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale">hacking through corporate code</a>. The poor weaponised employee has no idea what's going on.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/34320/hackers-exploiting-popular-social-engineering-toolkits-to-refine-cyber-attacks" data-original-url="/security/34320/hackers-exploiting-popular-social-engineering-toolkits-to-refine-cyber-attacks">Hackers exploiting popular social engineering 'toolkits' to refine cyber attacks</a></p></div></div><p>If you're to stand any chance of avoiding this threat, you must know your enemy and recognise their tactics. "Unless you <a href="https://www.itpro.com/security/cyber-security/354950/10-ways-to-get-employees-invested-in-cyber-security-awareness" target="_blank" data-original-url="https://www.itpro.com/security/cyber-security/354950/10-ways-to-get-employees-invested-in-cyber-security-awareness">teach your staff about the human element</a>, you are going to become a victim," says Sales, whose 30-year criminal career included identity fraud and two stints in prison. "If you do train them, though, you'll force the attackers to look elsewhere, at your less secure competitors." You must try, therefore, to get inside a social engineer’s heads before they can get inside yours.</p><h2 id="the-attack-plan">The attack plan</h2><p>Social engineering is, by its nature, a stealthy, hard-to-spot, compromising tactic that plays a role in most multi-stage attacks that demand long-term infiltration and observation. Usually, the attacker will use a combination of steps to achieve their aims. These can be as simple as tricking someone into revealing their system password (not difficult, given how many of us still use our pets' names and football teams <a href="https://www.itpro.com/security/cyber-security/361813/top-200-most-common-passwords-of-2021-revealed" target="_blank" data-original-url="https://www.itpro.com/security/cyber-security/361813/top-200-most-common-passwords-of-2021-revealed">as passwords</a>), or as sophisticated as securing a job with a particular organisation in order to infiltrate its global security networks. <a href="https://www.itpro.com/security/34436/us-sues-edward-snowden-over-his-memoir" target="_blank" data-original-url="https://www.itpro.com/security/34436/us-sues-edward-snowden-over-his-memoir">Edward Snowden</a>, in a way, did both.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale" data-original-url="/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale">What's behind the explosion in zero-day exploits?</a></p></div></div><p>Long before an ambitious social engineer can get stuck into spoofing finance staff with AI <a href="https://www.itpro.com/security/357591/why-deepfakes-could-threaten-everything-from-biometrics-to-democracy" target="_blank" data-original-url="https://www.itpro.com/security/357591/why-deepfakes-could-threaten-everything-from-biometrics-to-democracy">deepfakes</a> pretending to be the CFO, however, they must decide how their action fits into the attack plan. They must also determine which employee to target, how to gain their trust, and to what ends: To steal money? Seize data and intellectual property (IP), which can then be sold on the black market or used in further attacks? Or are they hoping to exploit a flaw and infiltrate the organisation's network, then set off a row of domino compromises in a <a href="https://www.itpro.com/business-strategy/public-sector/360162/it-pro-news-in-review-kaseya-supply-chain-attack-us-dod" data-original-url="https://www.itpro.com/business-strategy/public-sector/360162/it-pro-news-in-review-kaseya-supply-chain-attack-us-dod">supply-chain attack</a>?</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="bkc3RAUWV2nxFUsAw3K973" name="" alt="Edward Snowden's face on a pile of books" src="https://cdn.mos.cms.futurecdn.net/bkc3RAUWV2nxFUsAw3K973.jpg" mos="https://cdn.mos.cms.futurecdn.net/bkc3RAUWV2nxFUsAw3K973.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p><em><strong>Edward Snowden was at the heart of a sensational whistleblowing scandal early last decade</strong></em></p><p>"Sophisticated attackers have a very clear understanding of how they’ll profit from their activities, just like a successful business," says James Stanger, chief technology evangelist at IT education group CompTIA. "If they want to <a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers" target="_blank" data-original-url="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">steal passwords</a>, for instance, they'll decide exactly how they will monetise those passwords to increase their profit at the lowest possible risk."</p><h2 id="cover-your-tracks">Cover your tracks</h2><p>The nature of social engineering helps threat actors stay hidden or disguised, right up to the final breach, and even after the wider effects are noticed. The technique's heavy reliance on research, however, risks leaving a large online footprint, so this has to be addressed in the attack plan.</p><p>"They'd probably use Tor and a <a href="https://www.itpro.com/security/27098/best-vpn-services" target="_blank" data-original-url="https://www.itpro.com/security/27098/best-vpn-services">VPN</a> to be as obfuscated as possible," says Kevin Curran, senior IEEE member and professor of cyber security at Ulster University. "It takes incredible concentration to be successful, there's a lot of effort involved in staying under the radar."</p><iframe allow="encrypted-media" frameborder="0" height="" width="100%" data-lazy-priority="low" data-lazy-src="https://open.spotify.com/embed-podcast/episode/0BOVaViWn7N6skr7bGSb7L"></iframe><p>To reduce the effort, the social engineer may hire accomplices with complementary skillsets. Sales, for example, teamed up with hacker Solomon Gilbert. "Sol was probably one of the best hackers on the planet," says Sales. "My criminal mind works out a plan, and Solomon attaches what he needs to it, and then you get the 'boom'. We were ten times deadlier together than we'd ever have been individually."</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="kVYvFQ3Z7Cx7aPiv3GEG6K" name="kVYvFQ3Z7Cx7aPiv3GEG6K.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/kVYvFQ3Z7Cx7aPiv3GEG6K.jpg" mos="https://cdn.mos.cms.futurecdn.net/kVYvFQ3Z7Cx7aPiv3GEG6K.jpg" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Identity's role in zero trust</strong></p><p class="fancy-box__body-text">Zero trust starts with a change in philosophy</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/identity-and-access-management-iam/361716/identity-zero-trust" data-original-url="/security/identity-and-access-management-iam/361716/identity-zero-trust">FREE DOWNLOAD</a></p></div></div><p>An experienced social engineer, though, will exploit human flaws from the word go, and hire accomplices who have no idea what they're getting into. This reduces any risk for the criminal by limiting the number of people with knowledge of the conspiracy. "You could probably end up being a translator for a criminal gang and not know it," SE Labs founder Simon Edwards tells <em>IT Pro</em>. "If I was going to convince you to do something for me, I would pretend to be Apple, so you'd believe you were working for Apple to help them edit their messaging – and you wouldn't know any different."</p><p><strong><em>In the next part of our series, we reveal how a social engineer smokes out the weakest links in an organisation and turns these people into attack vectors.</em></strong></p><p><em><strong>With <a href="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business" target="_blank" data-original-url="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business">social engineering</a> set to plague 2022, understanding cyber criminals’ tactics, and the mistakes they make, might help us defend against their efforts. The second in our four-part series, published weekly, navigates the infiltration process and how criminals prey on our greatest weaknesses.</strong></em></p><p>Once a master plan is formulated, the social engineer must find a way into their targeted system. The primary route of entry, of course, is a human being.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business" data-original-url="/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business">Social engineering: The biggest security risk to your business</a></p></div></div><p>An attacker only needs to fool one person within your organisation to gain access to your core networks and sensitive data. They'll start with a pool of candidates, before whittling down this list, perhaps after first making contact to establish a basis of trust and learn who's most amenable to the lie and willing to unwittingly help out.</p><h2 id="smoking-out-weak-links">Smoking out weak links</h2><p>The <a href="https://www.itpro.com/security/24136/talktalk-hack-two-men-plead-guilty-to-talktalk-hack" data-original-url="https://www.itpro.com/security/24136/talktalk-hack-two-men-plead-guilty-to-talktalk-hack">TalkTalk breach</a> of 2015 demonstrated how attackers use social engineering to find easy targets. First, the stolen data delivered a pool of targets with TalkTalk accounts alongside detailed contact information. Then, when cold-calling potential victims, the attackers only tried to <a href="https://www.itpro.com/security/phishing/361625/what-is-smishing" data-original-url="https://www.itpro.com/security/phishing/361625/what-is-smishing">scam</a> those who believed the story.</p><p>Businesses aren’t above being scammed in the same way. Former fraudster and We Fight Fraud founder Tony Sales tells <em>IT Pro</em>: "Social engineering's just a buzzword for lying. Some people understand what the lies are and are able to defend against them, and some people don't. We're seeing this happen to brands; it happened to <a href="https://www.itpro.com/security/cyber-attacks/361764/uk-spar-stores-closed-supply-chain-attack" data-original-url="https://www.itpro.com/security/cyber-attacks/361764/uk-spar-stores-closed-supply-chain-attack">Spar</a>, and it impacted everyone in their supply chain."</p><p>The social engineer might start by choosing a particular department whose employees have access to a network through which you want to spread <a href="https://www.itpro.com/security/trojans/355479/four-steps-to-exterminating-rats-controlling-your-computer" target="_blank" data-original-url="https://www.itpro.com/security/trojans/355479/four-steps-to-exterminating-rats-controlling-your-computer">remote-access malware</a>, explains Freeform Dynamics analyst Tony Lock. "If you can attack someone on the help desk, maybe customer support, who then gets attacked and compromised, it'll then trickle up to the line manager and the group manager, and then it gets up to the top."</p><iframe allow="encrypted-media" frameborder="0" height="" width="100%" data-lazy-priority="low" data-lazy-src="https://open.spotify.com/embed-podcast/episode/0BOVaViWn7N6skr7bGSb7L"></iframe><p>Finance, IT and reception staff are common targets, and have the added bonus of being accustomed to dealing with urgent demands from outsiders every day. Workers within these departments are, therefore, unlikely to be overly suspicious when a new "client" tries to get to know them. If the attacker has experience of a particular department, it’ll also give them a head start in gaining trust. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/trojans/355479/four-steps-to-exterminating-rats-controlling-your-computer" data-original-url="/security/trojans/355479/four-steps-to-exterminating-rats-controlling-your-computer">Four steps to exterminating RATs controlling your computer</a></p></div></div><p>"I understand what HR does within a corporate organisation and what its processes are," says Sales. In addition, he adds, HR staff deal with job applications, any one of which could be loaded with a backdoor that's set to install as soon as the "application" is opened.</p><h2 id="probing-for-holes">Probing for holes</h2><p>Insecure <a href="https://www.itpro.com/business-strategy/collaboration/361582/managing-the-oversaturation-of-workplace-platforms" target="_blank" data-original-url="https://www.itpro.com/business-strategy/collaboration/361582/managing-the-oversaturation-of-workplace-platforms">workplace tech</a> helps in any breach, of course, and any competent social engineer will take that into account when selecting their target. A new recruit who's struggling with <a href="https://www.itpro.com/operating-systems/microsoft-windows/361104/how-to-install-windows-11" target="_blank" data-original-url="https://www.itpro.com/operating-systems/microsoft-windows/361104/how-to-install-windows-11">Windows updates</a> on a decade-old computer will be valuable prey, for example.</p><p>Not much ingenuity is required to find flaws in a company's network. Firstly, the attacker might make a friendly, fraudulent call or two to IT to ask for advice on "<a href="https://itpro-master.prod.cms.didev.co.uk/microsoft-windows/32524/the-windows-update-fiasco-shows-just-how-out-of-date-the-os-is" target="_blank">updating my Windows 11</a>", thereby confirming what operating system is being used. After that, they'd simply look up previous Microsoft patches. "You'd find out what's been fixed in older versions of Windows, then see if the same components are in Windows 10 and 11," says Kevin Curran, senior IEEE member and professor of cybersecurity at Ulster University.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/network-internet/internet-of-things-iot/360850/iot-devices-are-more-vulnerable-than-ever" data-original-url="/network-internet/internet-of-things-iot/360850/iot-devices-are-more-vulnerable-than-ever">IoT devices are more vulnerable than ever</a></p></div></div><p>Other perfectly above-board tools that social engineers may use at this stage include <a href="https://www.shodan.io" target="_blank">Shodan</a>, which finds compromised IoT devices, and the flaw-detecting framework <a href="https://www.metasploit.com" target="_blank">Metasploit</a>. "The attackers could do a bit of probing and find out a department is running Apache 2.34, which they know has this certain flaw," Curran adds. "Then they'd use Metasploit to target it on the victim's machine."</p><h2 id="gathering-intelligence">Gathering Intelligence </h2><p>The attacker's next step is to collect information about the person they plan to exploit. This will be infinitely useful in softening them up, gaining trust, and then exploiting that trust with a pretext, such as a <a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> email laced with a backdoor. The idea is to prepare the ground so the email or call isn't suspicious at all, and to gather all the intelligence needed to craft a convincing and irresistible message.</p><p>Ambitious attackers approach this stage "like a marketing professional studying their target audience," says James Stanger, chief technology evangelist at IT education group at CompTIA. They'll use <a href="https://www.itpro.com/business-strategy/recruitment/361860/hired-by-machines-exploring-recruitments-machine-driven-future" target="_blank" data-original-url="https://www.itpro.com/business-strategy/recruitment/361860/hired-by-machines-exploring-recruitments-machine-driven-future">AI tools</a>, data analytics and online stalking to get intimate knowledge of that person, including their devices, work roles and behaviour patterns, right down to when they have lunch.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="low" data-lazy-src="https://www.youtube-nocookie.com/embed/EiyiaUoQvOU" allowfullscreen></iframe></div></div><p>Our human instinct to share and connect makes this easy for social engineers, suggests Sales. "My friends see me constantly beating on about this stuff on social media, but they still click video links they shouldn't, and they still share information they shouldn't. We all want to connect with the world and have a little story with it."</p><p>Sales is far from laying blame for criminal espionage at the feet of victims who are just trying to do their jobs. After all, social engineers will glean personal information from their victims one way or another, Lock concludes. "Machine learning mechanisms can troll and accumulate a huge swathe of information from social media, then do some analysis on that before anyone even looks at it."</p><p><em><strong>In the next part of our series, we find out how social engineers exploit the trust of your best employees to break into a network or even bring down a supply chain.</strong></em></p><p><strong><em>With</em></strong> <a href="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business" target="_blank" data-original-url="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business"><strong><em>social engineering</em></strong></a> <strong><em>set to plague 2022, understanding cyber criminals’ tactics, and the mistakes they make, might help us defend against their efforts. The third in our four-part series, published weekly, navigates the exploitation phase and how cyber criminals embark on betraying our trust.</em></strong></p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business" data-original-url="/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business">Social engineering: The biggest security risk to your business</a></p></div></div><p>Exploitation is at the heart of a social engineering attack. Using a carefully-chosen employee, and based on extensive research, the social engineer now takes advantage of their target’s human flaws and best professional intentions.</p><p>The most common way to do this is by sending a <a href="https://www.itpro.com/security/29093/what-is-phishing" target="_blank" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> email. Once the preserve of rookie hackers who couldn't spell 'Nigeria', phishing in today’s age is considered a sophisticated form of social engineering, designed to glean credentials or trick the target into downloading remote-access <a href="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools" target="_blank" data-original-url="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools">malware</a>. Phishing instances rose nearly one-third (32%) during 2021, according to <a href="https://www.phishlabs.com/blog/phishing-increases-as-industries-new-and-old-face-a-barrage-of-threats" target="_blank">PhishLabs</a>, while F-Secure <a href="https://www.f-secure.com/en/press/p/a-third-of-suspicious-emails-reported-by-employees-are-phishing" target="_blank">reported</a> that email is now the most common method used to spread malware.</p><h2 id="long-and-short-phishing-trips">Long and short phishing trips</h2><p>If they're in a hurry, the social engineer could fire off an email immediately. "A pretty common technique would be for me to send you an email that appears to be from Microsoft," says Simon Edwards, founder of SE Labs. "There are a number of ways I could do that, and if it works, then job done."</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="low" data-lazy-src="https://www.youtube-nocookie.com/embed/EiyiaUoQvOU&t" allowfullscreen></iframe></div></div><p>A more sophisticated attacker might stage a number of social engineering steps. For instance, they could hijack an email account, research its owner, and then pose as that person when contacting the employee they want to exploit.</p><p>Numerous tools help social engineers craft their phishing bait. From software that makes emails appear to come from anywhere, to AI algorithms that work out which sender would be the most convincing, these tools can be acquired in custom bundles. "There's an entire ecosystem of tools for this," says Freeform Dynamics analyst Tony Lock. "On the dark web you can buy a pre-packaged bunch of components, right down to tools that let you process the Bitcoin you extract in a ransomware attack. It's a mix and match."</p><h2 id="hooking-human-flaws">Hooking human flaws</h2><p>Emotions such as eagerness to please – and fear of being found out – are gold dust for social engineers, because they motivate the target to take the bait. The attacker must, therefore, make sure their pretext presses emotional buttons.</p><p>In a recent <a href="https://www.actionfraud.police.uk/news/fraudsters-are-continuing-to-send-victims-their-own-passwords-in-sextortion-scam" target="_blank">sextortion scam</a>, whose attempted targets included at least two of our work contacts, fraudsters conned victims out of their passwords by threatening to release a video captured-by-webcam of them watching porn. No such video existed, but the victims were so terrified that they gave out their passwords anyway.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/34320/hackers-exploiting-popular-social-engineering-toolkits-to-refine-cyber-attacks" data-original-url="/security/34320/hackers-exploiting-popular-social-engineering-toolkits-to-refine-cyber-attacks">Hackers exploiting popular social engineering 'toolkits' to refine cyber attacks</a></p></div></div><p>Greed is a powerful phishing lure. Kevin Curran, senior <a href="https://www.ieee.org" target="_blank">IEEE</a> member and professor of cybersecurity at Ulster University, discovered this during a white-hat hacking job for a law firm. Asked to catch a Twitter troll, Curran tried to lure the perpetrator with assorted social media traps, but the only thing that worked was a fake email from a fake café, saying "we've found this iPad, is it yours?". Lo and behold, the troll got in touch. "He fell for it; he gave me his address," says Curran. "His greed got to him in the end."</p><p>Unpatchable human flaws are even easier to exploit in the workplace. Greed, nosiness and fear are common ingredients of corporate life. "We want to keep our bosses happy, because our livelihood depends on it," says Edwards. "If you don't want to lose your job, it's quite hard to ignore that text that appears to come from the CEO, saying you've got to pay this invoice now, otherwise we're going to lose £100,000."</p><h2 id="if-the-phish-doesn-39-t-bite">If the phish doesn't bite</h2><p>A successful social engineer will have backup targets in case the first attempt doesn't work, such as a supplier with less sophisticated security measures. A bill, spreadsheet, or PDF from that supplier could forge a backdoor into the target system – from where it may then move on up through the supply chain.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/357591/why-deepfakes-could-threaten-everything-from-biometrics-to-democracy" data-original-url="/security/357591/why-deepfakes-could-threaten-everything-from-biometrics-to-democracy">Why deepfakes could threaten everything from biometrics to democracy</a></p></div></div><p>Other methods the criminal might consider include business process compromise (BPC), for example, posing as cleaning staff, or 'pharming' (aka watering hole), whereby they lure users to a bogus website or Wi-Fi hotspot then harvest sensitive information, such as system passwords or banking transactions.</p><p>The tactic of leaving <a href="https://www.itpro.com/623410/usb-top-method-to-spread-malware" target="_blank" data-original-url="https://www.itpro.com/623410/usb-top-method-to-spread-malware">malware-laced USB sticks</a> lying around may be old hat, but devices are still useful lures. Curran recalls a Canadian cybercrime police team who treated a suspect to a gift to help them gather intel. "Inevitably, they give him a really good phone," says Curran, "and, of course, this phone was already compromised with a backdoor."</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="AwiTQbKokghduC3fiCJVd7" name="AwiTQbKokghduC3fiCJVd7.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/AwiTQbKokghduC3fiCJVd7.png" mos="https://cdn.mos.cms.futurecdn.net/AwiTQbKokghduC3fiCJVd7.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Outlook 2022: Five priorities for boards, management & governance professionals</strong></p><p class="fancy-box__body-text">What’s driving the future of governance</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/policy-legislation/it-governance/361795/outlook-2022-five-priorities-for-boards-management" data-original-url="/policy-legislation/it-governance/361795/outlook-2022-five-priorities-for-boards-management">FREE DOWNLOAD</a></p></div></div><p>There are also <a href="https://www.itpro.com/security/357591/why-deepfakes-could-threaten-everything-from-biometrics-to-democracy" target="_blank" data-original-url="https://www.itpro.com/security/357591/why-deepfakes-could-threaten-everything-from-biometrics-to-democracy">deepfakes</a> to contend with. This may sound like the stuff of TikTok, but Curran adds deepfake audio is "one of the biggest things we've seen in phishing over the last year". He recalls the case of a secretary transferring money to a criminal's account after a deepfake phone call that used her <a href="https://www.itpro.com/social-engineering/34308/fraudsters-use-ai-voice-manipulation-to-steal-200000" target="_blank" data-original-url="https://www.itpro.com/social-engineering/34308/fraudsters-use-ai-voice-manipulation-to-steal-200000">CEO's sampled voice</a>. "She heard what she thought was her boss, so she did it without hesitation." Deepfakes are such a real and present danger that <a href="https://www.itpro.com/security/cyber-security/357015/banks-and-fintech-firms-using-tech-firms-to-fight-deepfake-fraud" target="_blank" data-original-url="https://www.itpro.com/security/cyber-security/357015/banks-and-fintech-firms-using-tech-firms-to-fight-deepfake-fraud">banks</a> are now developing biometric authentication systems aimed at beating them. It’s simply the latest evolution in this long-running saga as the cyber security industry attempts to keep on top of the innovation in the social engineering space.</p><p><strong><em>In the final part of our series, we reveal how an ambitious social engineer continues to manipulate their victim for months or years before – and after – the big attack.</em></strong></p><p><strong><em>With</em></strong> <a href="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business" target="_blank" data-original-url="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business"><strong><em>social engineering</em></strong></a> <strong><em>set to plague 2022, understanding cyber criminals’ tactics, and the mistakes they make, might help us defend against their efforts. The final entry in our four-part series reveals how to avoid devastating consequences when a social engineer pulls the trigger.</em></strong></p><p>Once an attacker has tricked an employee into compromising a corporate network, you might be forgiven for thinking the social engineering exercise is over. This process can, however, carry on for years without the target organisation, or even those within its global supply chain, ever knowing.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business" data-original-url="/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business">Social engineering: The biggest security risk to your business</a></p></div></div><p><a href="https://www.itpro.com/security/cyber-attacks/358738/intern-blamed-for-weak-password-that-may-have-sparked-solarwinds" data-original-url="https://www.itpro.com/security/cyber-attacks/358738/intern-blamed-for-weak-password-that-may-have-sparked-solarwinds">SolarWinds</a> was a cleverly identified target. Once attackers had established a backdoor into SolarWinds' code, they moved automatically into the networks of clients, <a href="https://www.itpro.com/security/cyber-attacks/360017/solarwinds-hackers-target-microsoft-customers" target="_blank" data-original-url="https://www.itpro.com/security/cyber-attacks/360017/solarwinds-hackers-target-microsoft-customers">including Microsoft</a>, when they updated their software. The malware roamed through US computer networks for at least nine months undetected.</p><p>It's difficult to predict how regularly this happens <a href="https://www.itpro.com/strategy/28710/what-is-the-supply-chain-1" target="_blank" data-original-url="https://www.itpro.com/strategy/28710/what-is-the-supply-chain-1">in other supply chains</a>. Once a social engineer has installed a backdoor, they can then come and go; studying transactions, monitoring communications, gathering information about customers and clients, and even collecting audio samples to use in a deepfake attack. All this activity allows the cycle of infiltration and manipulation to continue undetected.</p><h2 id="look-and-learn">Look and learn</h2><p>Even in relatively simple attacks, the social engineer will bide their time between the initial compromise and making off with data or money. Kevin Curran, senior IEEE member and professor of cyber security at Ulster University, points to a cash theft from a law firm. First, an employee was tricked into downloading <a href="https://www.itpro.com/malware/28076/what-is-malware" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a> to the company's <a href="https://www.itpro.com/network-internet/email-delivery/361896/y2k22-bug-breaks-microsoft-exchange-servers" data-original-url="https://www.itpro.com/network-internet/email-delivery/361896/y2k22-bug-breaks-microsoft-exchange-servers">Microsoft Exchange network</a>. The attacker then spent weeks patiently studying the servers, before finally using what they learned to craft a second fake message, this time to steal a mortgage deposit.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="zDMfot5kyySAUEmYNvBgSP" name="" alt="SolarWinds logo on the side of a building" src="https://cdn.mos.cms.futurecdn.net/zDMfot5kyySAUEmYNvBgSP.jpg" mos="https://cdn.mos.cms.futurecdn.net/zDMfot5kyySAUEmYNvBgSP.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><p><strong><em>Once hackers established a backdoor into SolarWinds, they remained undetected for months</em></strong></p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-attacks/361764/uk-spar-stores-closed-supply-chain-attack" data-original-url="/security/cyber-attacks/361764/uk-spar-stores-closed-supply-chain-attack">Spar stores forced to close following supply chain attack</a></p></div></div><p>"They were hiding in plain sight," says Curran. "From reading emails, they knew when a deposit transfer would be legitimate and what it would look like. The client knew they'd have to send £40,000, so they were expecting it. And, of course, they sent the money off to the wrong account. A few days later, they rang up the law firm and said: “Did you get the deposit?” They hadn't; the money was completely gone."</p><p>Sophisticated <a href="https://www.itpro.com/malware/28076/what-is-malware" target="_blank" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a> is able to delete itself and its audit trails once the attack is done, but most malware stays on the system and is never found, says Curran. "Your average IT administrator would find it really hard to detect a backdoor. We have <a href="https://www.itpro.com/malware/28153/whats-the-difference-between-antimalware-and-antivirus" target="_blank" data-original-url="https://www.itpro.com/malware/28153/whats-the-difference-between-antimalware-and-antivirus">intrusion detection and prevention</a> systems, we have SIEMs (real-time monitoring) software that looks for outliers and nefarious activity as such, but it's generally impossible. There's literally millions of packets of data flowing through a corporate network every second. How do you control and monitor every single subsystem?"</p><h2 id="carry-on-conning">Carry on conning</h2><p>Most social engineering attacks end with the theft of data. The attacker also has to monetise the stolen data, for instance by using it to scam the company's customers, or in the next stage of a supply-chain attack. Often, though, they'll sell it to third parties and then fence their ill-gotten goods. This helps to lower the risk while maximising profit in the shortest possible time.</p><iframe allow="encrypted-media" frameborder="0" height="" width="100%" data-lazy-priority="low" data-lazy-src="https://open.spotify.com/embed-podcast/episode/2znUT5UIPFAM1pGya83iwT"></iframe><p><a href="https://www.itpro.com/security/ransomware/361250/how-not-to-get-hit-by-ransomware-in-2022" target="_blank" data-original-url="https://www.itpro.com/security/ransomware/361250/how-not-to-get-hit-by-ransomware-in-2022">Ransomware</a> is a particularly efficient way to monetise a social engineering attack. With 84% of US organisations reporting phishing or ransomware incidents in July last year, <a href="https://www.itpro.com/security/ransomware/360191/84-of-organizations-experienced-phishing-or-ransomware-attacks-in-last" target="_blank" data-original-url="https://www.itpro.com/security/ransomware/360191/84-of-organizations-experienced-phishing-or-ransomware-attacks-in-last">according to Trend Micro</a>, it seems attackers frequently use both tactics. Indeed, ransomware management requires good human manipulation skills. A carefully-crafted ransomware demand can tie the victim into a long-term hostage arrangement that keeps on paying.</p><p>"A lot of companies pay the ransom secretly, because they don't want to damage their brands," former fraudster and <a href="https://www.wefightfraud.org">We Fight Fraud</a> founder Tony Sales tells <em>IT Pro</em>. "That's dangerous, because now you're in an agreement with a criminal who owns you forever. It's like criminals getting an officer under their wing in prison."</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="usDgyxpNazobG5oMazKCfd" name="" alt="Tony Sales is a former fraudster and the founder of We Fight Fraud" src="https://cdn.mos.cms.futurecdn.net/usDgyxpNazobG5oMazKCfd.jpg" mos="https://cdn.mos.cms.futurecdn.net/usDgyxpNazobG5oMazKCfd.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="credit" itemprop="copyrightHolder">(Image credit: Adam Boome)</span></figcaption></figure><p><strong><em>Tony Sales is a former fraudster and founder of We Fight Fraud</em></strong></p><p>What's the answer? Security software can't stop human manipulation, but it can block the technical exploit, so <a href="https://www.itpro.com/security/29665/does-antivirus-software-do-more-harm-than-good" data-original-url="https://www.itpro.com/security/29665/does-antivirus-software-do-more-harm-than-good">antivirus remains vital</a>. Email security solutions can keep malicious messages at bay, but they need to be configured carefully. <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication" data-original-url="https://www.itpro.com/security/29982/what-is-two-factor-authentication">Two-factor authentication (2FA)</a>, disabling remote access to unnecessary servers, and bringing in audio passwords to defeat deepfakes will all help.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/malware/28083/best-free-malware-removal-tools" data-original-url="/security/malware/28083/best-free-malware-removal-tools">6 of the best free malware removal tools in 2023</a></p></div></div><p>Tech solutions are only effective if staff are able to use them, however, cautions Sales, whose organisation trains companies and employees to spot attackers' tricks. "The tech guys understand all that stuff, but not poor old Bob or Sheila who gets caught out on the company email they've been using forever,” he says. “Security is convoluted and complex, and that's part of the problem.”</p><p>Perhaps the answer is to fight <a href="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one" target="_blank" data-original-url="https://www.itpro.com/security/social-engineering/361911/month-in-the-life-of-social-engineer-week-one">social engineering</a> with social engineering. Don't blame employees for falling for <a href="https://www.itpro.com/security/scams/355013/10-quick-tips-for-identifying-phishing-emails" target="_blank" data-original-url="https://www.itpro.com/security/scams/355013/10-quick-tips-for-identifying-phishing-emails">phishing tricks</a>, or exclude them from security decisions. Instead, get them involved. One "highly effective" option is to encourage staff to report suspected phishing attempts, finds a 2021 F-Secure <a href="https://www.f-secure.com/en/press/p/a-third-of-suspicious-emails-reported-by-employees-are-phishing" target="_blank">report</a>. A full one-third (33%) of emails reported by staff as suspicious were, indeed, malicious.</p><p>Harnessing your employees’ eagerness to excel at their jobs, and their desire to be involved in decisions, before a criminal has the chance to exploit those very qualities, is among the most viable routes to overcoming a social engineer in action.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Education and government most at risk from email threats ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/361663/education-and-government-most-at-risk-from-email-threats</link>
                                                                            <description>
                            <![CDATA[ New report finds phishing remains most dominant threat to IT security ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vNnC2PPzH3zWJLmgzSueM4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/oajyUSRG44FA5WTmRw4Jcg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 26 Nov 2021 09:48:19 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/oajyUSRG44FA5WTmRw4Jcg-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Abstract image of a fishing hook through a red email to represent a phishing attack]]></media:description>                                                            <media:text><![CDATA[Abstract image of a fishing hook through a red email to represent a phishing attack]]></media:text>
                                <media:title type="plain"><![CDATA[Abstract image of a fishing hook through a red email to represent a phishing attack]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/oajyUSRG44FA5WTmRw4Jcg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Organizations in the education sector and local and state government are most at risk from email threats, according to a new report.</p><p>The report, published by IT security firm Cyren, also found that phishing remains the dominant form of attack against all industries.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/scams/355013/10-quick-tips-for-identifying-phishing-emails" data-original-url="/security/scams/355013/10-quick-tips-for-identifying-phishing-emails">10 quick tips for identifying phishing emails</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="/security/29093/what-is-phishing">What is phishing?</a></p></div></div><p>Based on data gathered from nearly 45,000 incidents, researchers found that the education sector received over five threats per thousand emails received. State and local government bodies received just over two threats per thousand emails received, nearly double the amount received by the next most targeted industry, software.</p><p>The report also looked at the number of attacks per 100 users across a wide range of industries. It found that there were nearly 400 per 100 users in education compared to just over 150 in the construction industry.</p><p>Researchers said there was a surprisingly low rate for manufacturing, especially when compared to the construction industry, which is closely related.</p><p>“We observed 20 confirmed threats per 100 users in the manufacturing vertical. Without solid detection and automated incident response, a manufacturer with 100 Office 365 users would spend at least 16 hours manually investigating and remediating emails,” they added.</p><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="low" data-lazy-src="https://www.youtube-nocookie.com/embed/EiyiaUoQvOU" allowfullscreen></iframe></div></div><p>In a <a href="https://www.cyren.com/blog/articles/phishing-by-the-numbers-october-2021">blog post</a>, <a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">security</a> researchers found that the data supported a widely held theory that phishing is a precursor to more damaging attacks such as business email compromise (BEC) and ransomware.</p><p>The report looked at phishing compared with malware and BEC attacks across four industries. Phishing remained the dominant threat in healthcare (76%), finance and insurance (76%), manufacturing (85%), and real estate (93%).</p><p>In healthcare, BEC attacks made up the remaining 24%. Researchers said that robust malware detection capabilities in the healthcare industry explains the high rate of BEC attempts. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="JwSoyQgoyuGSpPdZKLFeqQ" name="JwSoyQgoyuGSpPdZKLFeqQ.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/JwSoyQgoyuGSpPdZKLFeqQ.png" mos="https://cdn.mos.cms.futurecdn.net/JwSoyQgoyuGSpPdZKLFeqQ.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>2021 state of email security report: Ransomware on the rise</strong></p><p class="fancy-box__body-text">Securing the enterprise in the COVID world</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/359471/2021-state-of-email-security-report-ransomware-on-the-rise" data-original-url="/security/ransomware/359471/2021-state-of-email-security-report-ransomware-on-the-rise">FREE DOWNLOAD</a></p></div></div><p>“Attackers understand that they can’t easily slip malware past automated defenses, so they have shifted to social engineering tactics,” said researchers.</p><p>Researchers said that when it comes to solving the email threat problem, user education is an important component, but several organizations have “over-rotated” on the idea that users are responsible for keeping sophisticated email threats at bay.</p><p>“The predominant trend is to use an email hygiene technology such as Microsoft Defender for Office 365 to catch 80% of threats, deploy a specialized add-on to catch and contain zero-day phishing and most BEC attempts, enable employees to perform initial analysis on the small percentage of emails that are classified as suspicious (rather than malicious or clean), and automate incident response workflows to save time and reduce exposure,” added researchers.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Robinhood hack exposes data from millions of customers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/hacking/361479/robinhood-hack-social-engineering-exposes-millions-customers</link>
                                                                            <description>
                            <![CDATA[ An attacker socially engineered an employee at the stock-trading platform to gain access to customer support systems ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ofhoGcxM4WcCAsn4z5NcPz</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fdppapxuM6M8ViJVosgUhT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 09 Nov 2021 10:53:04 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Zach Marzouk ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GFZtdGsYoXrkh3Jhj4ZKTc.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fdppapxuM6M8ViJVosgUhT-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Robinhood logo displayed on a mobile phone with a stock trading chart in the background]]></media:description>                                                            <media:text><![CDATA[The Robinhood logo displayed on a mobile phone with a stock trading chart in the background]]></media:text>
                                <media:title type="plain"><![CDATA[The Robinhood logo displayed on a mobile phone with a stock trading chart in the background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fdppapxuM6M8ViJVosgUhT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Robinhood has revealed that an unauthorised third party has gained access to millions of customers’ data, adding to the company’s troublesome 2021.</p><p>The stock-trading platform <a href="https://blog.robinhood.com/news/2021/11/8/data-security-incident" target="_blank">said in a blog post</a> that on 3 November a hacker <a href="https://www.itpro.com/tag/social-engineering" target="_blank" data-original-url="https://www.itpro.com/search/social%20engineering">socially engineered</a> a customer support employee by phone and obtained access to certain customer support systems. The company said the unauthorised party obtained a list of <a href="https://www.itpro.com/infrastructure/email-providers" target="_blank" data-original-url="https://www.itpro.com/search/email">email</a> addresses for approximately five million people, and full names for a different group of two million people.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/625651/inside-the-mind-of-a-social-engineer" data-original-url="/625651/inside-the-mind-of-a-social-engineer">Inside the mind of a social engineer</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/360645/criminals-caught-trying-to-recruit-insiders-to-plant-ransomware" data-original-url="/security/ransomware/360645/criminals-caught-trying-to-recruit-insiders-to-plant-ransomware">Criminals caught trying to recruit insiders to plant ransomware</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/360428/microsoft-warns-of-dangerous-bazacall-call-centre-ransomware-scam" data-original-url="/security/ransomware/360428/microsoft-warns-of-dangerous-bazacall-call-centre-ransomware-scam">Microsoft warns of dangerous ‘BazaCall’ call centre ransomware scam</a></p></div></div><p>Robinhood added that for around 310 people, personal information like name, date of birth, and zip code were exposed, with a subset of around 10 customers having more extensive account details revealed, although it did not disclose what these details were.</p><p>Following the breach, the unauthorised party demanded an extortion payment, said the company, which informed law enforcement and is continuing to investigate the incident with the help of an outside security firm.</p><p>Robinhood is also in the process of making disclosures to those affected but believes that no social security numbers, bank account numbers, or debit card numbers were exposed. There has been no financial loss to any customers as a result of the incident.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="JwSoyQgoyuGSpPdZKLFeqQ" name="JwSoyQgoyuGSpPdZKLFeqQ.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/JwSoyQgoyuGSpPdZKLFeqQ.png" mos="https://cdn.mos.cms.futurecdn.net/JwSoyQgoyuGSpPdZKLFeqQ.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>2021 state of email security report: Ransomware on the rise</strong></p><p class="fancy-box__body-text">Securing the enterprise in the COVID world</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/359471/2021-state-of-email-security-report-ransomware-on-the-rise" data-original-url="/security/ransomware/359471/2021-state-of-email-security-report-ransomware-on-the-rise">FREE DOWNLOAD</a></p></div></div><p>“As a Safety First company, we owe it to our customers to be transparent and act with integrity,” said Robinhood chief security officer Caleb Sima. “Following a diligent review, putting the entire Robinhood community on notice of this incident now is the right thing to do.”</p><p>2021 has been a tricky year for Robinhood, which was summoned to a Congressional hearing in February after the company’s app facilitated a January GameStop squeeze. It was instigated by the subreddit r/WallStreetBets and the platform decided to halt trade on popular stocks, as reported by <a href="https://www.theverge.com/2021/2/18/22290110/house-financial-services-robinhood-gamestop-squeeze-roaringkitty-hearing" target="_blank"><em>The Verge</em></a>.</p><p>In July, the company had the worst debut ever for an IPO of its size, according to <a href="https://www.bloomberg.com/news/articles/2021-07-29/robinhood-flirts-with-worst-debut-ever-for-ipo-of-its-size" target="_blank"><em>Bloomberg</em></a>. Shares in the broker fell 8.4% below the IPO price in the company’s first trading session, the worst debut among 51 US firms that raised as much cash as Robinhood or more.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft warns of dangerous ‘BazaCall’ call centre ransomware scam ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/ransomware/360428/microsoft-warns-of-dangerous-bazacall-call-centre-ransomware-scam</link>
                                                                            <description>
                            <![CDATA[ Human operators are tricking victims into manually downloading malware onto their systems ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vPjdXSQ2Cy6euaco1bXEWH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VESrDDAbYw2rrajvhqwvY9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 30 Jul 2021 09:56:27 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VESrDDAbYw2rrajvhqwvY9-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A fraudulent call centre agent in a dark room surrounded by monitors]]></media:description>                                                            <media:text><![CDATA[A fraudulent call centre agent in a dark room surrounded by monitors]]></media:text>
                                <media:title type="plain"><![CDATA[A fraudulent call centre agent in a dark room surrounded by monitors]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VESrDDAbYw2rrajvhqwvY9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/28084/what-is-ransomware" target="_blank" data-original-url="https://www.itpro.com/security/28084/what-is-ransomware">Ransomware</a> operators are spreading BazaCall <a href="https://www.itpro.com/malware/28076/what-is-malware" target="_blank" data-original-url="https://www.itpro.com/malware/28076/what-is-malware">malware</a> by tricking people into phoning fraudulent call centres and speaking with real humans, who provide step-by-step instructions on how to download a payload.</p><p>Attacks from BazaCall operators can move rapidly within a network, with hackers able to conduct extensive data exfiltration and credential theft, <a href="https://www.microsoft.com/security/blog/2021/07/29/bazacall-phony-call-centers-lead-to-exfiltration-and-ransomware" target="_blank">Microsoft has warned</a>. They can even distribute ransomware within 48 hours of the initial compromise.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/ransomware/360243/new-ransomware-group-is-attacking-us-firms-and-educational" data-original-url="/security/ransomware/360243/new-ransomware-group-is-attacking-us-firms-and-educational">New ransomware group is attacking US firms and educational establishments</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business" data-original-url="/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business">Social engineering: The biggest security risk to your business</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/641470/so-you-want-to-be-an-ethical-hacker" data-original-url="/641470/so-you-want-to-be-an-ethical-hacker">How do you become an ethical hacker?</a></p></div></div><p>Apart from having backdoor capabilities, the BazaLoader payload also gives a remote attacker hands-on keyboard control for an affected user’s device.</p><p>“Our continued investigation into BazaCall campaigns, those that use fraudulent call [centres] that trick unsuspecting users into downloading the BazaLoader malware, shows that this threat is more dangerous than what’s been discussed publicly in other security blogs and covered by the media,” said the Microsoft 365 Defender Threat Intelligence Team.</p><p>“BazaCall campaigns forgo malicious links or attachments in email messages in [favour] of phone numbers that recipients are misled into calling. It’s a technique reminiscent of vishing and tech support scams where potential victims are being cold-called by the attacker, except in BazaCall’s case, targeted users must dial the number.”</p><p>When users are tricked into calling the number, they’re connected with actual humans on the other end of the line, who provide detailed guidance for installing malware on their devices.</p><p>The campaign relies on direct phone communication, as well as <a href="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business" target="_blank" data-original-url="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business">sophisticated social engineering tactics</a> to succeed, but the tactic is proving difficult to prevent given the lack of obvious malicious techniques.</p><p>It starts with an email that uses various social engineering lures to trick victims into calling a number. This might include informing users about a trial that’s about to expire and that their card is set to be charged, asking them to phone the number provided in case they have any concerns. There are <a href="https://www.itpro.com/security/scams/355013/10-quick-tips-for-identifying-phishing-emails" target="_blank" data-original-url="https://www.itpro.com/security/scams/355013/10-quick-tips-for-identifying-phishing-emails">no attachments, links</a>, or any other type of malicious call to action that would be spotted by a security filter.</p><p>Each message is sent from a different sender, normally through a free email service and compromised email addresses, with lures including fake business names that are similar to real companies.</p><p>Victims who do call the number will speak to a real person from a fraudulent call centre, whose aim is to direct the caller to visit a malicious website, disguised as a legitimate one. They’re asked to navigate to a page and download a file to cancel their subscription.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="NbL4bsEWBgYWJXNmhVccek" name="NbL4bsEWBgYWJXNmhVccek.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/NbL4bsEWBgYWJXNmhVccek.png" mos="https://cdn.mos.cms.futurecdn.net/NbL4bsEWBgYWJXNmhVccek.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Employees behaving badly?</strong></p><p class="fancy-box__body-text">Why awareness training matters</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-security/356982/employees-behaving-badly" data-original-url="/security/cyber-security/356982/employees-behaving-badly">FREE DOWNLOAD</a></p></div></div><p>These files are macro-enabled Excel documents, which might be flagged by Microsoft Defender SmartScreen, although Microsoft has observed users bypassing these warnings to download the files anyway, likely at the instruction of the hacker. Users are then prompted to enable editing, and enable macros, which triggers the BazaLoader malware to be delivered.</p><p>“The BazaCall campaign replaces links and attachments with phone numbers in the emails it sends out, posing challenges in detection, especially by traditional antispam and anti-phishing solutions that check for those malicious indicators,” the research team added.</p><p>“The lack of typical malicious elements in BazaCall’s emails and the speed with which their operators can conduct an attack exemplify the increasingly complex and evasive threats that [organisations] face today.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers target US taxpayers with NetWire and Remcos malware ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/malware/358961/hackers-target-us-taxpayers-with-netwire-and-remcos-malware</link>
                                                                            <description>
                            <![CDATA[ Attackers are attempting to lure victims with malware-laced Word documents that purport to contain tax-related content ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">quqV6FVHHpRpnhgcSc6aif</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vpHsn9vsq2uzXyRNKTvGs4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 19 Mar 2021 12:53:12 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rene Millman ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/vwWuTPNRCuw9vEaWzuXYnR.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vpHsn9vsq2uzXyRNKTvGs4-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware in code ]]></media:description>                                                            <media:text><![CDATA[Malware in code ]]></media:text>
                                <media:title type="plain"><![CDATA[Malware in code ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vpHsn9vsq2uzXyRNKTvGs4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security" data-original-url="https://www.itpro.com/security">Security</a> researchers have uncovered a new campaign targeting US taxpayers with malware-laced Microsoft Word documents that purport to contain tax-related content. </p><p>The scam ultimately aims to install NetWire and Remcos, two powerful <a href="https://www.itpro.com/security/trojans/355446/decade-of-the-rats-remote-access-trojans" target="_blank" data-original-url="https://www.itpro.com/security/trojans/355446/decade-of-the-rats-remote-access-trojans">remote access trojans</a> (RATs) that enable attackers to take control of the victims' machines in order to steal sensitive information. </p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/cyber-crime/358946/fbi-over-4-billion-lost-to-cyber-crime-in-2020" data-original-url="/security/cyber-crime/358946/fbi-over-4-billion-lost-to-cyber-crime-in-2020">FBI: Over $4 billion lost to cyber crime in 2020</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/hacking/358944/desperate-job-seekers-turn-to-hacking-forums-for-paid-work" data-original-url="/security/hacking/358944/desperate-job-seekers-turn-to-hacking-forums-for-paid-work">"Desperate" job seekers turn to hacking forums for paid work</a></p></div></div><p>The scam could result in steep financial losses for taxpayers. Last year alone, the IRS identified more than $2.3 billion in tax fraud schemes.</p><p>According to a <a href="https://www.cybereason.com/blog/cybereason-exposes-malware-targeting-us-taxpayers">blog post</a> by researchers at Cybereason, the new infection process is designed to evade antivirus tools and tricks targets into installing the malware via a tax-themed Word document containing a malicious macro that downloads an OpenVPN client on the targeted machine. </p><p>The malware dropper establishes a connection to the legitimate cloud service “Imgur” and downloads the NetWire or Remcos payloads by way of a technique called steganography, where the malicious code is hidden within an innocuous-looking jpeg image file.</p><p>Researchers said that the malware includes a variety of functions including the remote execution of shell commands on the infected machine, browser credential and history theft, the downloading and execution of additional malware payloads, screen captures and <a href="https://www.itpro.com/91638/keylogging-trojan-uses-unique-attack" target="_blank" data-original-url="https://www.itpro.com/91638/keylogging-trojan-uses-unique-attack">keylogging</a>, as well as file and system management capabilities.</p><p>Assaf Dahan, senior director and head of threat research at Cybereason, said that <a href="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business" target="_blank" data-original-url="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business">social engineering</a> via phishing emails continues to be the preferred infection method among both cyber criminals and nation-state threat actors. </p><p>“The potential for damage is serious and the malware allows threat actors to gain full control over a victim’s machine and steal sensitive information from users or their employers. In this research, we demonstrate how the attackers are leveraging the US tax season to infect targets at will,” he said </p><p>“The use of various techniques such as steganography, storing payloads on legitimate cloud-based services, and exploiting DLL sideloading against a legitimate software makes these campaigns very difficult to detect. The sensitive information collected from the victims can be sold in the underground communities and used to carry out all manner of identity theft and financial fraud,” said Dahan.</p><p>Paul Bischoff, privacy advocate at Comparitech, told <em>IT Pro</em> that this attack is particularly clever because it gets its payload from an image stored on a popular and trusted site, Imgur, instead of trying to download from the hacker's server.</p><p>“The attack is easy to prevent with good digital hygiene. Never click on links or attachments in unsolicited emails. Always verify the sender before clicking a link or attachment. Be especially skeptical of MS Office documents and be sure that macros are disabled by default on your MS Office apps,” he said.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft remains the most-spoofed brand for the second quarter in a row ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/phishing/358316/microsoft-the-most-phished-brand-for-the-second-quarter-in-a-row</link>
                                                                            <description>
                            <![CDATA[ Malicious use of the tech giant's brand increased by 24% in the last quarter of 2020, according to Check Point ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">r4nqMvh1CrBNF7HJg77iNf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bRe7SSwuWFQGLMoRXKUNRb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 14 Jan 2021 12:53:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bRe7SSwuWFQGLMoRXKUNRb-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A sign in page for a Microsoft service ]]></media:description>                                                            <media:text><![CDATA[A sign in page for a Microsoft service ]]></media:text>
                                <media:title type="plain"><![CDATA[A sign in page for a Microsoft service ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bRe7SSwuWFQGLMoRXKUNRb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft ended 2020 as the brand most frequently targeted by cyber criminals, with 43% of all brand <a href="https://www.itpro.com/security/29093/what-is-phishing" target="_blank" data-original-url="https://www.itpro.com/security/29093/what-is-phishing#:~:text=From%20banking%20scams%20to%20industrial,why%20phishing%20is%20so%20lucrative&text=Phishing%20is%20a%20rather%20personal,friends%20%2D%20needs%20something%20from%20you.">phishing</a> attempts related to the tech giant in Q4.</p><p>This was a 24% increase from the third quarter of the year, which saw <a href="https://www.itpro.com/security/357479/microsoft-becomes-the-most-spoofed-brand-for-phishing-attacks" target="_blank" data-original-url="https://www.itpro.com/security/357479/microsoft-becomes-the-most-spoofed-brand-for-phishing-attacks">19% of all attempts linked to the tech giant</a>, according to Check Point research.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="/security/29093/what-is-phishing">What is phishing?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/357479/microsoft-becomes-the-most-spoofed-brand-for-phishing-attacks" data-original-url="/security/357479/microsoft-becomes-the-most-spoofed-brand-for-phishing-attacks">Microsoft becomes the most-spoofed brand for phishing attacks</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/100197/phishing-attacks-in-the-uk-on-the-rise" data-original-url="/100197/phishing-attacks-in-the-uk-on-the-rise">Phishing attacks in the UK on the rise</a></p></div></div><p>The attempts are from criminals looking to steal personal information or payment credentials by impersonating well-known brands that are likely to be used by the employee and their organisation.</p><p>The technology industry was the most likely to be targeted by '<a href="https://www.itpro.com/security/357751/phishing-grows-by-220-as-cyber-criminals-leverage-covid-19-pandemic" target="_blank" data-original-url="https://www.itpro.com/security/357751/phishing-grows-by-220-as-cyber-criminals-leverage-covid-19-pandemic">brand phishing</a>', according to Check Point, closely followed by <a href="https://www.itpro.com/security/357796/sharp-spike-in-phishing-attacks-in-the-weeks-ahead-of-black-friday" target="_blank" data-original-url="https://www.itpro.com/security/357796/sharp-spike-in-phishing-attacks-in-the-weeks-ahead-of-black-friday">retail</a> and shipping. Across October, November and, December, Microsoft was the brand most often imitated by hackers.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="Qare3jicxMydbQ3PBKAnPM" name="" alt="An example of a phishing scam using Microsoft" src="https://cdn.mos.cms.futurecdn.net/Qare3jicxMydbQ3PBKAnPM.png" mos="https://cdn.mos.cms.futurecdn.net/Qare3jicxMydbQ3PBKAnPM.png" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>"Criminals increased their attempts in Q4 2020 to steal peoples personal data by impersonating leading brands, and our data clearly shows how they change their phishing tactics to increase their chances of success," said Maya Horowitz, director, threat intelligence and research, products at Check Point.</p><p>"As always, we encourage users to be cautious when divulging personal data and credentials to business applications, and to think twice before opening email attachments or links, especially emails that claim to from companies, such as Microsoft or Google, that are most likely to be impersonated."</p><p>Shipping firm DHL was the second most-spoofed brand for the end of 2020, as criminals sought to take advantage of the significantly higher number of shoppers placing their orders online. Many of these attacks involved delivery failure notices, asking the target to pay a nominal fee to arrange a new delivery.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="V7Hw2ywxB8Do9DDLSEcRca" name="" alt="An example of a phishing scam using the DHL website" src="https://cdn.mos.cms.futurecdn.net/V7Hw2ywxB8Do9DDLSEcRca.jpg" mos="https://cdn.mos.cms.futurecdn.net/V7Hw2ywxB8Do9DDLSEcRca.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Google actually came 7th on the list with only 2% of all brand-related phishing in its name. Amazon ended the year in fourth with 5% while <a href="https://www.itpro.com/security/357779/people-cant-resist-opening-linkedin-phishing-emails" target="_blank" data-original-url="https://www.itpro.com/security/357779/people-cant-resist-opening-linkedin-phishing-emails">LinkedIn</a>, a Microsoft-owned platform, was third with 6%.</p><p><em>IT Pro</em> has approached Microsoft as the findings will be of huge concern to the tech giant, especially as phishing attempts in its name have doubled over a sixth month period.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The IT Pro Podcast: The power of disinformation ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/marketing-comms/social-media/358088/the-it-pro-podcast-the-power-of-disinformation</link>
                                                                            <description>
                            <![CDATA[ Social media is a great innovation - but falsehoods and manipulation are rife ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9DJ5KRb81kiAFDhQRuSsRu</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qEE2TWDyCD6FuV7ppeaLkC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Dec 2020 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Social Media]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ IT Pro ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qEE2TWDyCD6FuV7ppeaLkC-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The IT Pro Podcast: The power of disinformation]]></media:description>                                                            <media:text><![CDATA[The IT Pro Podcast: The power of disinformation]]></media:text>
                                <media:title type="plain"><![CDATA[The IT Pro Podcast: The power of disinformation]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qEE2TWDyCD6FuV7ppeaLkC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The internet has been one of the most revolutionary technologies of our age, and most agree that the transformation it’s brought to our society has been beneficial. Social media – one of the more recent arrivals on the scene – has also generally been a good thing, allowing us to connect with friends and family across the world, find people who have similar interests to us, and rapidly share jokes, memes and information.</p><p>This latter element, however, has slowly turned from a benefit into a problem. Disinformation and what might be termed “fake news” is seeping in everywhere, making it difficult to know what and who to believe.</p><p>In this week’s episode of the IT Pro Podcast, we speak to Andy Patel, a researcher with cyber security firm F-Secure, about what disinformation is, how it spreads and the negative effects it could have on businesses.</p><iframe allow="encrypted-media" frameborder="0" height="" width="100%" data-lazy-priority="low" data-lazy-src="https://open.spotify.com/embed-podcast/episode/50WjaS5Rb6JvwLj408hjAj"></iframe><h3 class="article-body__section" id="section-footnotes"><span>Footnotes</span></h3><ul><li><a href="https://www.bbc.co.uk/news/53498434">QAnon: What is it and where did it come from?</a></li><li><a href="https://www.itpro.com/security/cyber-security/357887/fbi-warns-of-hackers-spoofing-its-domain" data-original-url="https://www.itpro.com/security/cyber-security/357887/fbi-warns-of-hackers-spoofing-its-domain">FBI warns of hackers spoofing its domain</a></li><li><a href="https://www.itpro.com/business/policy-legislation/356416/dems-ask-facebook-google-and-twitter-for-coronavirus" data-original-url="https://www.itpro.com/business/policy-legislation/356416/dems-ask-facebook-google-and-twitter-for-coronavirus">Dems ask Facebook, Google and Twitter for coronavirus disinformation reports</a></li><li><a href="https://www.itpro.com/mobile/5g/355244/whatsapp-restricts-message-forwarding-to-curb-spread-of-5g-myths" data-original-url="https://www.itpro.com/mobile/5g/355244/whatsapp-restricts-message-forwarding-to-curb-spread-of-5g-myths">WhatsApp restricts message forwarding to curb spread of 5G myths</a></li><li><a href="https://www.itpro.com/security/29093/what-is-phishing" data-original-url="https://www.itpro.com/security/29093/what-is-phishing">What is phishing?</a></li><li><a href="https://www.itpro.com/marketing-comms/social-media/356928/fighting-terrorism-with-technology" data-original-url="https://www.itpro.com/marketing-comms/social-media/356928/fighting-terrorism-with-technology">IT Pro Live: Fighting terrorism with technology</a></li><li><a href="https://www.itpro.com/strategy/28108/fake-news-is-killing-our-minds-says-tim-cook" data-original-url="https://www.itpro.com/strategy/28108/fake-news-is-killing-our-minds-says-tim-cook">Fake news 'is killing our minds', says Tim Cook</a></li><li><a href="https://www.itpro.com/security/357811/trend-micro-launches-free-misinformation-and-fraud-checker-in-the-us" data-original-url="https://www.itpro.com/security/357811/trend-micro-launches-free-misinformation-and-fraud-checker-in-the-us">Trend Micro's free web-based tool takes on hackers and fake news</a></li><li><a href="https://www.itpro.com/marketing-comms/communications/356650/whatsapp-counters-false-viral-messages-with-new-google-search" data-original-url="https://www.itpro.com/marketing-comms/communications/356650/whatsapp-counters-false-viral-messages-with-new-google-search">WhatsApp counters fake viral messages with new fact-check tool</a></li><li><a href="https://www.itpro.com/marketing-comms/communications/355905/satirical-websites-target-mark-zuckerberg-with-fake-news" data-original-url="https://www.itpro.com/marketing-comms/communications/355905/satirical-websites-target-mark-zuckerberg-with-fake-news">Satirical websites target Mark Zuckerberg with fake news</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/356417/trump-confirms-cyber-attacks-on-russia-election-trolls" data-original-url="https://www.itpro.com/security/cyber-attacks/356417/trump-confirms-cyber-attacks-on-russia-election-trolls">Trump confirms US cyber attack on Russia election trolls</a></li><li><a href="https://www.itpro.com/hacking/30203/what-is-hacktivism" data-original-url="https://www.itpro.com/hacking/30203/what-is-hacktivism">What is hacktivism?</a></li><li><a href="https://www.itpro.com/business-strategy/data-insights/357582/the-it-pro-podcast-what-covid-19-can-teach-us-about-open" data-original-url="https://www.itpro.com/business-strategy/data-insights/357582/the-it-pro-podcast-what-covid-19-can-teach-us-about-open">The IT Pro Podcast: What COVID-19 can teach us about open data</a></li><li><a href="https://www.itpro.com/business/policy-legislation/358014/biden-team-signals-change-on-section-230" data-original-url="https://www.itpro.com/business/policy-legislation/358014/biden-team-signals-change-on-section-230">Biden team signals president-elect may target Section 230 and data privacy</a></li><li><a href="https://www.itpro.com/business/policy-legislation/356416/dems-ask-facebook-google-and-twitter-for-coronavirus" data-original-url="https://www.itpro.com/business/policy-legislation/356416/dems-ask-facebook-google-and-twitter-for-coronavirus">Dems ask Facebook, Google and Twitter for coronavirus disinformation reports</a></li><li><a href="https://www.itpro.com/technology/32872/google-turns-its-hand-to-fighting-election-abuse" data-original-url="https://www.itpro.com/technology/32872/google-turns-its-hand-to-fighting-election-abuse">Google turns its hand to fighting election abuse</a></li><li><a href="https://www.itpro.com/policy-legislation/32973/facebook-facing-scrutiny-amid-claims-it-encourages-spread-of-misinformation" data-original-url="https://www.itpro.com/policy-legislation/32973/facebook-facing-scrutiny-amid-claims-it-encourages-spread-of-misinformation">Facebook facing scrutiny amid claims it encourages spread of misinformation</a></li><li><a href="https://www.itpro.com/mobile/5g/356134/the-it-pro-podcast-the-truth-about-5g" data-original-url="https://www.itpro.com/mobile/5g/356134/the-it-pro-podcast-the-truth-about-5g">The IT Pro Podcast: The truth about 5G</a></li></ul><h3 class="article-body__section" id="section-subscribe"><span>Subscribe</span></h3><ul><li><a href="https://podcasts.apple.com/gb/podcast/the-itpro-podcast/id1483810154">Subscribe to The IT Pro Podcast on Apple Podcasts</a></li><li><a href="https://podcasts.google.com/?feed=aHR0cHM6Ly9pdHByb3BvZGNhc3QubGlic3luLmNvbS9yc3M">Subscribe to The IT Pro Podcast on Google Podcasts</a></li><li><a href="https://open.spotify.com/show/7HpYehTy752KmtbwpOAgRZ">Subscribe to The IT Pro Podcast on Spotify</a></li><li><a href="https://www.itpro.com/newsletter-signup" data-original-url="https://www.itpro.com/newsletter-signup">Subscribe to the IT Pro newsletter</a></li><li><a href="https://www.itpro.com/business-strategy/smb/356631/it-pro-2020-starting-afresh" data-original-url="https://www.itpro.com/business-strategy/smb/356631/it-pro-2020-starting-afresh">Subscribe to IT Pro 20/20</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ More than half of businesses saw rising fraud levels this year ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/357866/one-in-two-businesses-witnessed-rise-in-fraud-levels-this-year</link>
                                                                            <description>
                            <![CDATA[ Each individual identity fraud attempt could cost an organisation between £1,000 and £4,999 on average ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eeEdGCBVY5vVKnwUSBsP7N</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AEaJn4dBVm2zS6KPMMVaVW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 23 Nov 2020 12:14:58 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sabina Weston ]]></dc:creator>                                                                                    <dc:source><![CDATA[ null ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/AEaJn4dBVm2zS6KPMMVaVW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A graphic presenting two people emerging from laptops with one person being a criminal posing as a customer]]></media:description>                                                            <media:text><![CDATA[A graphic presenting two people emerging from laptops with one person being a criminal posing as a customer]]></media:text>
                                <media:title type="plain"><![CDATA[A graphic presenting two people emerging from laptops with one person being a criminal posing as a customer]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AEaJn4dBVm2zS6KPMMVaVW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>More than half of <a href="https://www.itpro.com/business" data-original-url="https://www.itpro.com/business">businesses</a> across the UK, Germany, France, Spain, and Italy have seen a rise in fraud levels this year, according to new research commissioned by identity management provider GBG.</p><p>Some of the most frequent attacks were credit and debit card fraud (56% of respondents), followed by phishing (46%), and e-transfer fraud (37%).</p><p>However, respondents said that they are currently least prepared to defend themselves from synthetic identity fraud (26%), IP piracy (26%), and <a href="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business" data-original-url="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business">social engineering</a> attempts (25%).</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/357860/new-free-police-led-tool-to-help-businesses-monitor-cyber-crime" data-original-url="/security/357860/new-free-police-led-tool-to-help-businesses-monitor-cyber-crime">Police CyberAlarm monitoring tool rolls out across England and Wales</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/31723/what-is-shoulder-surfing" data-original-url="/security/31723/what-is-shoulder-surfing">What is shoulder surfing?</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/356488/phishing-and-fraud-report" data-original-url="/security/phishing/356488/phishing-and-fraud-report">Phishing and fraud report</a></p></div></div><p>What's more, one in three consumers said they had become more worried about becoming a victim of fraud as a result of the COVID-19 pandemic. Unfortunately, their fears may be justified; according to GBG, fraud has become a prevalent issue in 2020, with one in five consumers affected by identity fraud only this year. </p><p>The rise in incidents can be attributed to the digital acceleration powered by government-imposed lockdown restrictions and social distancing. This year saw many consumers open online accounts, with the most popular being shopping (47%), social media (35%), and online banking (31%), using mobile numbers (50%), email addresses (48%), and biometric data (28%) to log in.</p><p>GM of Identity Fraud, Europe at GBG, Gus Tomlinson, said that the research “shows that not only is identity fraud already prolific, the ‘trust gap’ it creates poses a risk to industries which will depend on digital trust if they are to thrive in 2021 and beyond”. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qG8vMhfHtBczgFT5DicnnL" name="qG8vMhfHtBczgFT5DicnnL.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/qG8vMhfHtBczgFT5DicnnL.png" mos="https://cdn.mos.cms.futurecdn.net/qG8vMhfHtBczgFT5DicnnL.png" link="" align="" fullscreen="" width="0" height="0" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><strong>Best practices for protecting remote work</strong></p><p class="fancy-box__body-text">Staying safe and secure while working from home</p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/357754/best-practices-for-protecting-remote-work" data-original-url="/security/357754/best-practices-for-protecting-remote-work">FREE DOWNLOAD</a></p></div></div><p>“For some businesses and even entire sectors, we are nearing a tipping point: get this balance wrong, and lose trust – and therefore customers – for good.”</p><p>GBG also warned that each individual identity fraud attempt could cost an organisation between £1,000 and £4,999 on average.</p><p>At the height of the pandemic in April, it was reported that <a href="https://www.itpro.com/security/cyber-security/355350/google-highlights-coronavirus-related-phishing-emails" data-original-url="https://www.itpro.com/security/cyber-security/355350/google-highlights-coronavirus-related-phishing-emails">about £2 million was lost to coronavirus-related fraud</a> in the UK, with the NCSC warning that “an increasing number of malicious cyber actors are exploiting the current COVID-19 pandemic for their own objectives".</p><p>"In the UK, the NCSC has detected more UK government branded scams relating to COVID-19 than any other subject," the report added.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Twitter investigates possibility that DMs were accessed during Bitcoin hack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/356472/twitter-targeted-by-social-engineering-attack-as-hackers-launch</link>
                                                                            <description>
                            <![CDATA[ Twitter maintains the attack was the result of 'social engineering', although reports suggest an employee may have been bribed ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7gZAUxGPBpfRJWXQEBdrEX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sALtP3tiD8GGSo385E6757-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jul 2020 09:24:27 +0000</pubDate>                                                                                                                                <updated>Fri, 17 Jul 2020 09:42:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/sALtP3tiD8GGSo385E6757-1280-80.png">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Screenshots of compromised accounts, obtained through Twitter]]></media:description>                                                            <media:text><![CDATA[The Twitter logo in the background of a a coin representing the physical embodiment of Bitcoin]]></media:text>
                                <media:title type="plain"><![CDATA[The Twitter logo in the background of a a coin representing the physical embodiment of Bitcoin]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sALtP3tiD8GGSo385E6757-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Twitter is investigating whether hackers gained access to the direct messages belonging to accounts of dozens of high-profile individuals following Wednesday’s hack.</p><p>The company has confirmed that approximately 130 accounts were targeted by attackers during the incident, including a handful of instances where hackers were able to send tweets.</p><div  class="fancy-box"><div class="fancy_box-title"></div><div class="fancy_box_body"><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/cryptocurrencies/356311/bitcoin-scam-exposes-the-personal-details-of-250000-people" data-original-url="/technology/cryptocurrencies/356311/bitcoin-scam-exposes-the-personal-details-of-250000-people">Bitcoin scam exposes the personal details of 250,000 people</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/cryptocurrencies/355603/halving-of-bitcoin-will-hurt-miners-in-the-short-term" data-original-url="/technology/cryptocurrencies/355603/halving-of-bitcoin-will-hurt-miners-in-the-short-term">Bitcoin halving is expected to hurt miners in the short term</a> <a data-analytics-id="inline-link" href="https://www.itpro.com/technology/34288/pat-gelsinger-bitcoin-today-is-not-ok" data-original-url="/technology/34288/pat-gelsinger-bitcoin-today-is-not-ok">Pat Gelsinger: “Bitcoin today is not OK”</a></p></div></div><p>Despite being able to access accounts to the degree where sending tweets was possible, Twitter said there’s currently no evidence that attackers accessed user passwords, so resetting these is not considered a necessary measure at this stage.</p><p>Although Twitter described the infiltration as a “social engineering attack”, the company is also investigating the possibility that an employee was bribed, according to <a href="https://www.nytimes.com/2020/07/16/technology/twitter-hack-investigation.html?auth=login-google&login=email"><em>the New York Times</em></a>.</p><p>The company also hasn’t ruled out whether private data like direct messages had been accessed, although the extent to which the hackers gained access to a handful of the 130 compromised accounts suggests this is entirely possible.</p><p>“We’re working with impacted account owners and will continue to do so over the next several days,” <a href="https://twitter.com/TwitterSupport/status/1283957910708662273">Twitter said</a>. “We are continuing to assess whether non-public data related to these accounts was compromised, and will provide updates if we determine that occurred.”</p><p>The option to download data from your Twitter account has been switched off during the ongoing investigation. The company also said it is taking “aggressive steps” to secure its systems.</p><p><strong><em>This story has been updated to reflect new information. The original story is published below</em></strong></p><p>Hackers targeted Twitter employees with access to company tools and internal systems in a “co-ordinated social engineering attack” to seize control of high profile accounts and <a href="https://www.itpro.com/strategy/28296/what-is-bitcoin" target="_blank" data-original-url="https://www.itpro.com/strategy/28296/what-is-bitcoin">launch a Bitcoin scam</a>.</p><p><a href="https://twitter.com/morphonios/status/1283514099750625285?s=20" target="_blank">Several major account holders</a> began posting suspicious messages last night on a co-ordinated basis, including Elon Musk, Bill Gates, Barack Obama, and Jeff Bezos, which between them have hundreds of millions of followers.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="knapmBYTxTztRYeS4BicUh" name="" alt="Screenshots of compromised accounts, obtained through Twitter" src="https://cdn.mos.cms.futurecdn.net/knapmBYTxTztRYeS4BicUh.jpg" mos="https://cdn.mos.cms.futurecdn.net/knapmBYTxTztRYeS4BicUh.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Screenshots of compromised accounts, obtained through Twitter </span></figcaption></figure><p>These messages described a scheme whereby all Bitcoin donated to a particular wallet, the same in each fraudulent tweet, would be sent back doubled, in light of that individual deciding to “give back”.</p><p>Having tracked the Bitcoin wallet, the hackers have, at the time of writing managed to solicit 376 fraudulent donations to the tune of 12.87 Bitcoin, equivalent to approximately £93,000.</p><p>Twitter confirmed at 10:45PM BST that it was aware of a security incident, and would investigate this urgently. The company subsequently placed heavy restrictions on many account holders, especially those who are verified, preventing them from tweeting or resetting their passwords, alongside “some other account functionalities”.</p><p>Those accounts that were compromised, having posted the fraudulent message, were also temporarily blocked entirely. These restrictions have been gradually lifted, with a handful of users only regaining the capacity to tweet as normal this morning.</p><p>Twitter soon confirmed in the early hours of the morning it had detected what it believed to be a <a href="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business" target="_blank" data-original-url="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business">coordinated social engineering attack</a> by people who successfully targeted some of its employees with access to internal systems and tools.</p><p>“We know they used this access to take control of many highly-visible (including verified) accounts and Tweet on their behalf,” the company said. “We’re looking into what other malicious activity they may have conducted or information they may have accessed and will share more here as we have it.</p><p>“We also limited functionality for a much larger group of accounts, like all verified accounts (even those with no evidence of being compromised), while we continue to fully investigate this. This was disruptive, but it was an important step to reduce risk. Most functionality has been restored but we may take further actions and will update you if we do.”</p><p>The company has confirmed it’s taken “significant steps” to limit access to internal systems and tools during its investigation, although these haven’t been outlined in any great detail.</p><p>It also appears employees targeted in the social engineering attack had direct access to users' accounts. For example, fraudulent Bitcoin tweets were often 'pinned', which could normally only be performed by logging into accounts.</p><p>Alarmingly, some of those involved in the hack <a href="https://www.vice.com/en_us/article/jgxd3d/twitter-insider-access-panel-account-hacks-biden-uber-bezos" target="_blank">told <em>Motherboard</em></a> they actually paid a Twitter employee to grant them access to their own account, with the accounts taken over using an internal Twitter tool. Some users have posted screenshots of the tool in question, and have been circulating these images online.</p><figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="9a6seG4h2fi4UCQKsTUfvH" name="" alt="Screenshot of an internal Twitter tool being circulated online, obtained through Twitter" src="https://cdn.mos.cms.futurecdn.net/9a6seG4h2fi4UCQKsTUfvH.jpg" mos="https://cdn.mos.cms.futurecdn.net/9a6seG4h2fi4UCQKsTUfvH.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div><figcaption itemprop="caption description" class="pull-"><span class="caption-text">Screenshot of an internal Twitter tool being circulated online, obtained through Twitter </span></figcaption></figure><p>The incident is certainly one of the company’s biggest security breaches in history and follows a string of <a href="https://www.itpro.com/security/28133/what-is-cyber-security" target="_blank" data-original-url="https://www.itpro.com/security/28133/what-is-cyber-security">smaller-scale hacks</a> over the previous few months and years.</p><p>Only last month <a href="https://www.itpro.com/security/data-breaches/356190/twitter-alerts-business-customers-after-flagging-data-breach" target="_blank" data-original-url="https://www.itpro.com/security/data-breaches/356190/twitter-alerts-business-customers-after-flagging-data-breach">Twitter alerted business customers after flagging a data breach</a>, suggesting their personal details may have been compromised due to an issue with the way Twitter cached data on web browsers. The information of those who were signed up to the company’s advertising or analytics platform may have been accessed by third-parties as a result of the glitch.</p><p>This follows an incident in August 2019 in which <a href="https://www.itpro.com/data-breaches/34166/twitter-owns-up-to-third-party-data-breaches" target="_blank" data-original-url="https://www.itpro.com/data-breaches/34166/twitter-owns-up-to-third-party-data-breaches">Twitter found an issue with its privacy settings</a>, meaning musers may have inadvertently been sharing data with third-parties. This, however, was more of a privacy violation than an out-and-out security breach.</p><p>The largest breach to date, barring this week’s incident, however, arose in 2018 after <a href="https://www.itpro.com/security/31060/twitter-alerts-users-after-squashing-password-revealing-internal-bug" target="_blank" data-original-url="https://www.itpro.com/security/31060/twitter-alerts-users-after-squashing-password-revealing-internal-bug">a bug allowed company staff to view account passwords in an unencrypted form</a>. The company asked 330 million users, as a result, to change their passwords urgently for fear of their accounts being compromised.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>