Researchers have identified a new ransomware called "GoodWill", which forces its victims to donate money and clothes to the poor. The threat actor may be based in India according to authorities.
More:
The threat actor asks for social donations from its victims rather than money as ransom, making it a highly unusual case.
GoodWill is written in .NET, as it was first identified in March 2022. The ransomware renders sensitive files inaccessible without decrypting them. The malware, which uses the AES algorithm for encryption, is unique in sleeping for 722.45 seconds to interfere with dynamic analysis.
The encryption process is followed by displaying a multiple-paged ransom note that requires the victims to carry out three socially-driven activities to be able to obtain the decryption kit. The steps include donating new clothes and blankets to the homeless, taking five underprivileged children to Domino's Pizza, Pizza Hut, or KFC for a treat, and offering financial support to patients who need urgent medical attention but don't have the financial means to acquire it.
Additionally, the victims are asked to record themselves during the activities and post the recordings on Facebook or Instagram, writing a specific line that says "How you transformed yourself into a kind human being by becoming a victim of a ransomware called GoodWill."
A 37-year-old man from New York was sentenced to four years in prison for using and selling stolen credit cards. He sold the information on the Infraud carding portal.
More:
John Telusma is one of 36 individuals U.S. authorities indicted in February 2018 for alleged roles in the Infraud Organization criminal enterprise.
The operation was active from Oct. 2010 until Feb. 2018, when Infraud and its portal were taken down following a law enforcement operation. Out of 10,901 registered Infraud members in March 2017, 13 members were apprehended by law enforcement agencies in the United States and six other countries (Australia, the United Kingdom, France, Italy, Kosovo, and Serbia).
The threat actors used malware to facilitate the acquisition, sale, and distribution of stolen identity information and payment cards, counterfeit documents, personally identifiable data, bank account, and credit account information.
Infraud members caused victims losses of more than $568M, while the organization's members remained anonymous to each other to evade law enforcement.
A message from SECURITY COMPASS
Have you given up on making your development team more productive? Figuring out the best approach to mature application security programs can be difficult, especially with increasing internal demands for a faster time to market.
Many solutions claim to help organizations build more secure software. However, measuring the value provided by the solution compared to its economic and organizational cost can be difficult.
That’s why Security Compass commissioned Forrester Consulting to conduct a Total Economic Impact™ study to examine the quantifiable ROI enterprises can realize by deploying SD Elements.
According to this study, SD Elements enabled its users to decrease the time needed to develop security requirements for products by up to 90%.
The study also found that organizations’ ROI could be as high as 332%, with a payback period of less than 6 months.
FBI warned that Russian cybercrime forums are selling network credentials and virtual private network info from U.S. colleges and universities. The leaks could lead to hacks.
More:
The FBI stated that U.S. college and university credentials are being advertised across cybercrime forums. In May 2021, the FBI found more than 36,000 email and password combinations posted on publicly available instant messaging platforms. The information provided access to email accounts ending in .edu.
When hackers gain the login information, they can proceed to conduct brute-force credential stuffing attacks to break into victim accounts spanning multiple internet sites, and services. If attackers are successful in compromising a victim's account, they may steal information from the account, potentially re-selling credit card numbers and other personally identifiable information for money.
Most of the credentials are stolen through spear-phishing, ransomware, or other cyberattacks. The use of these kinds of attacks on U.S. colleges and universities has become more prevalent over the last few years.
U.S. colleges and universities usually claim that they have no idea whether they have been hacked or if they have been a victim of a breach.
More than 75 vulnerabilities have been added to the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities Catalogue. Cisco, Microsoft, Adobe, and others are on the list.
More:
Many of the vulnerabilities range from 2010 to 2019, but one of the most recent examples is Cisco's IOS XR Open Port Vulnerability CVE-2022-20821.
This flaw, which was patched on May 20, 2022, could allow an unauthenticated, remote attacker to access the Redis instance that runs within the NOSi container, a health device software package used for medical purposes.
Among the new additions to the list are two 2021 Android Kernel vulnerabilities tracked as CVE-2021-1048 and CVE-2021-0920, and an Apple memory corruption vulnerability tracked as CVE-2021-30883.
The list includes 34 flaws that were posted on May 25, 2022, 20 added on May 24, and another 21 previously added on May 24, 2022.
Microsoft says Android apps with millions of downloads are exposed to high-severity vulnerabilities. The flaws could potentially expose users to remote attacks.
More:
Microsoft's security team has uncovered high-severity vulnerabilities in a mobile framework owned by mce Systems and used by multiple large mobile service providers in pre-installed Android System apps that potentially exposed users to remote or local attacks. The vulnerabilities, which affected apps with millions of downloads, have now been patched.
The company first found that the apps were embedded in the devices’ system image, suggesting that they were default applications installed by phone providers. All of these apps were available on the Google Play Store where they went through Google Play Protect’s automatic safety checks, but the checks failed to identify these types of issues.
Icelander cybersecurity management platform Nanitor raised $1.7M in a private funding round.
A nascent Linux-based botnet named Enemybot has expanded its capabilities to include recently disclosed security vulnerabilities. It uses these new capabilities to target web servers, Android devices, and content management systems.
Nearly 100,000 NPM users' credentials were stolen in GitHub OAuth breach.
The Space Systems Command rolled out a new process to assess the cybersecurity of commercial satellite operators that do business with the Defense Department.
June 30 - HR Strategies to Retain Remote Employees (Register Here)
*This is a sponsored listing
Arbër is an Inside writer who also has experience in entrepreneurship. He has experience covering Consumer Tech, Venture Capital, NFTs, Crypto, etc. Arbër holds a Bachelor's degree in Business from XAMK University in Finland. When he is not reading(and writing) business news, he chooses to watch sports or anime...and then read news about sports or anime.
Editor
Gregory Bridgman is a writer and researcher with an academic background in politics and the philosophy of science and technology. He holds a bachelor's degree in Political Science from the University of Cape Town and is currently completing a PhD at the University of Cambridge. He is interested in climate issues, technological changes, and the implications of the fourth industrial revolution.
Security Compass is on a mission to accelerate software time-to-market while managing risk.
Watch the performance: The ULTIMATE every-day carry. Make the physical light on the back of your iPhone come to life and move around. Then hand everything out for examination. This is a wildly innovative idea you have to see to believe. ...
Plus, Saks to shut down e-commerce fulfillment center Inside Ecommerce For November 30, 2023 Thank you to our sponsor Today's e-commerce briefing digs into: Cyber Monday's strong YoY sales growth this year Walmart's announcement of its first shoppable video series Saks' plan to shut down a fulfillment center in Pennsylvania Enjoy! Gregory p/Gregory_Bridgman 1 U.S. digital sales on Cyber Monday rose 9.6% YoY in 2023. Online shoppers made widespread use of mobile buy now, pay later (BNPL) offerings, according to an Adobe Analytics report . More: U.S. shoppers spent $12.4B online on Cyber Monday, up 9.6% YoY. Online sales between Thanksgiving and Cyber Monday rose 7.8% YoY to $38B. Sales over the Thanksgiving weekend rose 7.7% to 10.3B. BNPL purchases between Nov. 1 and Nov. 27 expanded 17% YoY to $8.3B This month is set to be the biggest ever for installment payment transactions, according to Ad...
Swift Daily update ⋅ November 28, 2017 NEWS The World's Best Driver's Car Under $18000 Is A Suzuki Swift Sport Forbes What better way to regain the interest of a generation that has fallen out of love with the car than to give it a super hot hatch like the Suzuki Swift Sport? Flag as irrelevant Taylor Swift tops Billboard chart for second week in a row... after breaking record with Reputation ... Daily Mail She broke a personal best record by selling 1.29 million copies of Reputation in the first week of it's release last week. And Taylor Swift has kept the success train running. The 27-year-old singer's latest album has topped the charts for the second week in a row according to Billboard. According to the ... Taylor Swift's 'Reputation' Is No. 1 Again, but Will It Maintain Its Momentum? - New York Times Chart Watch: Ta...
Presented by New Jersey Coalition of Automotive Retailers: Matt Friedman's must-read briefing on the Garden State's important news of the day Mar 06, 2025 View in browser By Matt Friedman Presented by ...
Watch full performances of each trick here, and get fooled 3 times! ! (there are 3 separate videos) https://www.penguinmagic.com/p/16584 "Strong, really fooling ... there is no way it can be reconstructed." - Nique Tan I love these 3 tricks so much. 1. They're virtually impossible to figure out! They're so hard to figure out in fact, that even when you know the secret it's fun to perform, because it feels magical. 2. No sleight of hand . These tricks are super easy to perform. You can comb...
"This is the best mentalism device I've seen in many years! Bar none." - Steven Palmer TL;DR: Our most requested upgrade from pros. The best selling mind-reading wallet is now available for the first time in genuine leather for only $59.95 . It's also available in a new color, midnight blue for only $39.95 We only have 150 genuine leather Razor Wallets, so they'll go fast. No more will arrive before Christmas. Genuine Leather Razor Wallet (only 150 available) https://www.penguinmagic.com/p/16650 ...
Wages increase 1% in Q4 2021 Inside.com Part of Network January 31, 2022 Presented by US Markets Stock Market futures are down slightly on the last trading day of January, which is on track to be the worst month for U.S. equities since March 2020. The S&P 500 is down 7% in January and down 8% from its highest point this month. The Nasdaq is down 12% this month and 15% from its November high. The current 10 Year U.S. Treasury yield is set at 1.79400% Dow Jones 34,725.47 1.65% S&P 500 4,431.85 2.43% Nasdaq 13,770.57 3.13% Russell 2000 1,968.51 1.93% *Stock Market data as of the last closing bell. Data received directly from the references indexes through ICE Data Services. Do you not understand any of these figures? Check out our explainer. ...
A lot has happened on Facebook since you last logged in. Here are some notifications you've missed from your friends. Ludo Maallam 2 new friends You have new notifications. A lot has happened on Facebook since you last logged in. Here are some notifications you've missed from your friends. Ludo Maallam 2 new friends Go to Facebook View Notifications This message was sent to ludomallam@idiot.cloudns.cc . If you don't want to receive these emails from Facebook in the future, please unsubscribe . Facebook, Inc., Attention: Community Support, 1 Facebook Way, Menlo Park, CA 94025 To help k...
Ludo, see the post that he shared. Facebook 📷 Naveed Hussain shared Vijy Kumar 's photo. 4 June at 21:05 View This message was sent to ludomallam@idiot.cloudns.cc . If you don't want to receive these emails from Facebook in the future, please unsubscribe . Facebook, Inc., Attention: Community Support, 1 Facebook Way, Menlo Park, CA 94025 To help keep your account secure, please don't forward this email. Learn more.
Comments
Post a Comment