Phishing


Nov. 28, 2018

The FBI Created a Fake FedEx Website to Unmask a Cybercriminal

The FBI Created a Fake FedEx Website to Unmask a Cybercriminal

The FBI has started deploying its own hacking techniques to identify financially-driven cybercriminals, according to court documents unearthed by Motherboard. The news signals an expansion of the FBI’s use of tools usually reserved for cases such as child pornography and bomb threats. But it also ushers in a potential normalization of this technologically-driven approach, as criminal suspects continually cover up their digital trail and law enforcement have to turn to more novel solutions.

Apr. 13, 2018

All Your Base64 Are Belong To Us – Dynamic vs. Static Analysis of Web Content

All Your Base64 Are Belong To Us – Dynamic vs. Static Analysis of Web Content

I recently encountered an interesting phishing scheme when reviewing telemetry of incidents blocked by Trustwave Secure Web Gateway (SWG). My investigation into the scheme uncovered some interesting points and led me here:

Source: trustwave.com

Mar. 9, 2018

Russian hackers stole 860,000 euros from 32 ATMs belonging to the Raiffeisen Romania in just one night

Russian hackers stole 860,000 euros from 32 ATMs belonging to the Raiffeisen Romania in just one night

Cybercriminals stole 3.8 million slopes (860,000 euros) from 32 ATMs belonging to the Raiffeisen Romania bank using an infected RTF document. The criminal organization led by Dmitriy Kvasov operated in Romania, the gang stole the money in just one night in 2016.

Source: securityaffairs.co

Mar. 8, 2018

Look-Alike Domains and Visual Confusion

Look-Alike Domains and Visual Confusion

Go ahead and click on the link above or cut-and-paste it into a browser address bar. If you’re using Google Chrome, Apple’s Safari, or some recent version of Microsoft‘s Internet Explorer or Edge browsers, you should notice that the address converts to “xn–80a7a.com.” This is called “punycode,” and it allows browsers to render domains with non-Latin alphabets like Cyrillic and Ukrainian.

Source: krebsonsecurity.com

Mar. 7, 2018

Fraudsters Jailed for £37m Copycat Website Scam

Fraudsters Jailed for £37m Copycat Website Scam

National Trading Standards said that the defendants set up copycat websites between January 2011 and November 2014 that mimicked government services such as applying for or renewing passports, visas, birth or death certificates, driving licences and tests, car tax discs and the London Congestion Charge.

Source: bbc.com