Showing posts with label passwords. Show all posts
Showing posts with label passwords. Show all posts

Thursday, November 11, 2021

Who is DEV-0343??

It has been reported by the Microsoft Intelligence center that malicious password spray attacks which first occurred in July have been attributed to Iranian cybercriminals codenamed DEV-0343, according to the Microsoft Information center.

The term password spray usually refers to a brutal attack in which a cybercriminal uses the same password on multiple accounts, with the goal of locking the account with repeated attempts to gain unauthorized access.

DEV-0343 seeks to target more than 250 Office 365 tenants associated with US, Israeli and EU defense companies, as well as ports and shipping companies in the Persian Gulf. However less than 20 tenants have been successfully hacked.


DEV-0343 

These attacks were simulated by DEV-0343 using an emulated Firefox browser and rotated through IPs hosted on a TOR proxy network. This attempt to remain anonymous did not work, because after analyzing the lifestyle and geographical targeting of known Iranian cybercriminals, it became clear that this was the work of this vicious and intrusive regime. At 7:30 a.m. and 8:30 p.m. Iranian time the group targets hundreds of accounts at a time, praying for just one account for weak cyber security measures.

Friends please protect yourself from this criminal group 🙏. Enable 2FA authentication on all your accounts, block all incoming traffic from anonymous services, and make sure all of your Microsoft Exchange access policies are up to date.

When will this regime stop interfering with the rest of the world while the Iranian people are starving? While Internet blackouts occur regularly? How can the Iranian government continue to claim its lack of money while supporting criminal acts like this? 😡


Follow me on Twitter and Instagram: @_0x7c3

#cybercrime #cybersecurity #cybercrime #DEV0343 #PasswordSpray #cyber #attack #Office365 #Microsoft  

Wednesday, November 26, 2014

Regin Malware is "Groundbreaking"



Symantec has revealed details about malware called "Regin". This shows a multi-stage attack that is capable of being adapted easily to gather different types of data. According to Symantec this is not just screen grabs and password information but something far more sophisticated. Symantec claims that it has identified dozens of different payloads that Regin has access to. 
 
Once Regin has acquired the data it encrypts the data and then exfiltrates it. The stolen data may never be written to disk but may be sent back immediately and the encryption means that security devices and software do not easily detected this.

Symantec describes how Regin uses special features to stay below the detection radar: "These include anti-forensics capabilities, a custom-built encrypted virtual file system (EVFS), and alternative encryption in the form of a variant of RC5, which isn’t commonly used. Regin uses multiple sophisticated means to covertly communicate with the attacker including via ICMP/ping, embedding commands in HTTP cookies, and custom TCP and UDP protocols."

Regin has been found in 10 countries and the targets seem to be key business sectors, individuals and small businesses. The full list of countries and targets which Symantec gives are:
  • 28% Russian Federation
  • 24% Saudi Arabia
  • 9% Mexico
  • 9% Ireland
  • 5% India
  • 5% Afghanistan
  • 5% Iran
  • 5% Belgium
  • 5% Austria
  • 5% Pakistan
  • 48% Private individuals and small businesses
  • 28% Telecoms backbone
  • 9% Hospitality
  • 5% Energy
  • 5% Airline
  • 5% Research
Symantec describes Regin as follows: "In the world of malware threats, only a few examples can truly be considered groundbreaking and almost peerless. What we have seen in Regin is just such a class of malware."

Friday, October 17, 2014

Serious Flaw: POODLE SSL 3.0



A bug has been found in the Secure Sockets Layer (SSL) 3.0 cryptography protocol (SSLv3) which could be exploited to intercept data that is supposed to be encrypted between computers and servers. Three Google security researchers discovered the flaw and detailed how it could be exploited through what they called a Padding Oracle On Downgraded Legacy Encryption (POODLE) attack (CVE-2014-3566). 
 
It is important to note that this is NOT a flaw in SSL certificates, their private keys or their design but in the old SSLv3 protocol. SSL Certificates are not affected and customers with certificates on servers supporting SSL 3.0 do not need to replace them.

This flaw is highly likely not to be as serious as the Heartbleed bug in OpenSSL, since the attacker needs to have a privileged position in the network to exploit the latest. The usage of Hotspots, public Wi-Fi, makes this attack a real problem. This type of attack is a “Man-in-the-middle” attack. 

Solution:
  1. Check to see if SSL 3.0 is disabled on your browser (for example in Internet Explorer it is under Internet Options, Advanced Settings).
  2. Make sure “HTTPS” is always on the websites you visit to avoid MITM attacks.
  3. Monitor any notices from the vendors who you use regarding recommendations to update software or passwords.
  4. Avoid potential phishing emails from attackers who ask you to update your password. Stick with the official site domain to avoid going to an impersonated website.

Thursday, September 11, 2014

5 Million Gmail Account Usernames & Passwords Hacked



Nearly 5 million usernames and passwords associated with Gmail accounts have been leaked on a Russian Bitcoin forum. The database contains 4.93 million Google accounts belonging to English, Russian and Spanish speaking users.

The list has since been taken down, and there is no evidence that Gmail itself was hacked, just that these passwords have been leaked. Most sources are saying that lots of the information is quite old, so it is likely they were leaked long ago, though others claim that 60% of the passwords are still valid.

You should change your passwords now and ideally use 2-factor authentication for extra protection.

Friday, May 23, 2014

eBay Hacked: Change Your Passwords! NOW!


Online marketplace eBay is forcing users to change their passwords after a cyber-attack compromised its systems.

The US firm said a database was hacked between late February and early March and had contained encrypted passwords and other non-financial data.

The company added that it has no evidence of unauthorised activity on its members accounts.

However it said that changing the passwords is "best practice and will help enhance security for eBay users".

The California company has 128 million active users and recorded $212bn commerce on its various marketplaces and other services in 2013.

Facebook said it will contact users via email, its website, adverts and social media to alert them of the issue. 
 
Cyber-attackers accessed the information after obtaining "a small number of employee log-in credentials", that allowed them to access its systems, which facebook first became aware of this only two weeks ago.

Facebook said: "The database... included eBay customers' name, encrypted password, email address, physical address, phone number and date of birth.

However, the database did not contain financial information or other confidential personal information.
Extensive forensics subsequently identified the compromised eBay database, resulting in the company's announcement today."

Although the firm also owns the PayPal money transfer service, but it said that the PayPal data is stored separately and encrypted and there is no evidence that it was accessed.