cryptocurrency - Tagged - Security Boulevard The Home of the Security Bloggers Network Wed, 06 Nov 2024 17:29:24 +0000 en-US hourly 1 https://wordpress.org/?v=6.7.1 https://securityboulevard.com/wp-content/uploads/2021/10/android-chrome-256x256-1-32x32.png cryptocurrency - Tagged - Security Boulevard 32 32 133346385 Schneider Electric Confirms Ransom Hack — Hellcat Demands French Bread as ‘Joke’ https://securityboulevard.com/2024/11/schneider-electric-hellcat-richixbw/ Wed, 06 Nov 2024 17:29:24 +0000 https://securityboulevard.com/?p=2035664 Baguettes

That’s a lot of pain: $125,000 ransom seems small—but why do the scrotes want it paid in baguettes?

The post Schneider Electric Confirms Ransom Hack — Hellcat Demands French Bread as ‘Joke’ appeared first on Security Boulevard.

]]>
2035664
Perfectl Malware https://securityboulevard.com/2024/10/perfectl-malware/ Mon, 14 Oct 2024 11:06:27 +0000 https://www.schneier.com/?p=69468 Perfectl in an impressive piece of malware:

The malware has been circulating since at least 2021. It gets installed by exploiting more than 20,000 common misconfigurations, a capability that may make millions of machines connected to the Internet potential targets, researchers from Aqua Security said. It can also exploit CVE-2023-33246, a vulnerability with a severity rating of 10 out of 10 that was patched last year in Apache RocketMQ, a messaging and streaming platform that’s found on many Linux machines.

The researchers are calling the malware Perfctl, the name of a malicious component that surreptitiously mines cryptocurrency. The unknown developers of the malware gave the process a name that combines the perf Linux monitoring tool and ctl, an abbreviation commonly used with command line tools. A signature characteristic of Perfctl is its use of process and file names that are identical or similar to those commonly found in Linux environments. The naming convention is one of the many ways the malware attempts to escape notice of infected users...

The post Perfectl Malware appeared first on Security Boulevard.

]]>
2033274
FBI Warns of North Korea Attacks Against the Crypto Industry https://securityboulevard.com/2024/09/fbi-warns-of-north-korea-attacks-against-the-crypto-industry/ Wed, 04 Sep 2024 17:38:00 +0000 http://securityboulevard.com/?guid=be2bffdc2da0a0c864de741d6430b137  

The decentralized finance (DeFi) and
cryptocurrency industries are being targeted by North Korean social engineering
schemes in highly personalized and convincing ways.

 

Here is an example that the FBI is showcasing:

1.      
A
person from your dream company, using the name of an old colleague, contacts
you on social media, mentioning a conference you both recently attended and
discussing shared interests.

2.      
He
asks if you're job hunting and reveals his company needs your skills, offering
a significant pay raise.  He arranges an
interview with his CTO and during the interview, the CTO gives you a
“pre-employment” test that involves troubleshooting code from some GitHub
repositories you do not recognize.

3.      
You
clone the repositories, execute the code, find the bugs, and pass the test with
flying colors.

 

Congrats - you have fallen for a well-disguised
social engineering scheme conducted by North Korean cyber actors. One of those
GitHub repositories was malicious and landed a malware dropper on your machine
which installed a key logger and acquired your credentials to access your
company’s network.

 

The North Korean attackers gain access and moving
laterally, eventually getting access to the seed phrases and security
signatures for your company’s cryptocurrency assets.  Shortly thereafter all the company’s crypto
assets disappear and everything you and your colleagues worked for is gone.

 

The threat is real.

 

Check out the full FBI public warning here: https://www.ic3.gov/Media/Y2024/PSA240903

The post FBI Warns of North Korea Attacks Against the Crypto Industry appeared first on Security Boulevard.

]]>
2029636
Pig Butchering at Heart of Bank Failure — CEO Gets 24 Years in Jail https://securityboulevard.com/2024/08/shan-hanes-htsb-ceo-pig-butchering-richixbw/ Fri, 23 Aug 2024 16:54:40 +0000 https://securityboulevard.com/?p=2028729 A pig in a muddy farm field

Oink, oink, FAIL—you’re in jail: Kansas bank chief exec Shan Hanes stole money from investors, a church and others to buy cryptocurrency to feed a scam.

The post Pig Butchering at Heart of Bank Failure — CEO Gets 24 Years in Jail appeared first on Security Boulevard.

]]>
2028729
Squarespace Hacked — DeFi Wallets Drained (Imaginary Money Stolen) https://securityboulevard.com/2024/07/squarespace-defi-domain-hijack-richixbw/ Tue, 16 Jul 2024 16:26:44 +0000 https://securityboulevard.com/?p=2024491 Colorful squares floating in space

DeFAIL: Cryptocurrency fans lose their worthless tokens via phishing attacks on decen­tral­ized finance sites.

The post Squarespace Hacked — DeFi Wallets Drained (Imaginary Money Stolen) appeared first on Security Boulevard.

]]>
2024491
Cybercriminals Target Trump Supporters with Donation Scams https://securityboulevard.com/2024/06/cybercriminals-target-trump-supporters-with-donation-scams/ Tue, 18 Jun 2024 21:47:06 +0000 https://securityboulevard.com/?p=2021923 Trump donation scam

Donald Trump’s presidential campaign is known for aggressively trying to raise money, even sending emails to donors hoping to cash in on setbacks like his conviction late last month on 34 felony counts for illegally influencing the 2016 campaign. Bad actors now are trying to do the same, running donation scams by impersonating the campaign..

The post Cybercriminals Target Trump Supporters with Donation Scams appeared first on Security Boulevard.

]]>
2021923
Breaking a Password Manager https://securityboulevard.com/2024/06/breaking-a-password-manager/ Tue, 04 Jun 2024 11:08:16 +0000 https://www.schneier.com/?p=68987 Interesting story of breaking the security of the RoboForm password manager in order to recover a cryptocurrency wallet password.

Grand and Bruno spent months reverse engineering the version of the RoboForm program that they thought Michael had used in 2013 and found that the pseudo-random number generator used to generate passwords in that version—­and subsequent versions until 2015­—did indeed have a significant flaw that made the random number generator not so random. The RoboForm program unwisely tied the random passwords it generated to the date and time on the user’s computer­—it determined the computer’s date and time, and then generated passwords that were predictable. If you knew the date and time and other parameters, you could compute any password that would have been generated on a certain date and time in the past...

The post Breaking a Password Manager appeared first on Security Boulevard.

]]>
2020520
Brothers Indicted for Stealing $25 Million of Ethereum in 12 Seconds https://securityboulevard.com/2024/05/brothers-indicted-for-stealing-25-million-of-ethereum-in-12-seconds/ Fri, 17 May 2024 20:16:21 +0000 https://securityboulevard.com/?p=2018924 Blackwire, Blockchain, Ethereum scam

It took two brothers who went to MIT months to plan how they were going to steal, launder and hide millions of dollars in cryptocurrency -- and only 12 seconds to actually pull off the heist.

The post Brothers Indicted for Stealing $25 Million of Ethereum in 12 Seconds appeared first on Security Boulevard.

]]>
2018924
Ukrainian REvil Hacker Gets 13-Year Sentence Plus $16M Fine https://securityboulevard.com/2024/05/ukrainian-revil-hacker-gets-13-year-sentence-plus-16m-fine/ Fri, 17 May 2024 07:00:47 +0000 https://tuxcare.com/?p=17494 In a significant victory against cybercrime, the Ukrainian REvil hacker has been sentenced to over 13 years in prison and ordered to pay a hefty fine of $16 million for orchestrating thousands of ransomware attacks, resulting in cyber extortion of victims worldwide. In this blog, we’ll look at the details of this Kaseya supply chain […]

The post Ukrainian REvil Hacker Gets 13-Year Sentence Plus $16M Fine appeared first on TuxCare.

The post Ukrainian REvil Hacker Gets 13-Year Sentence Plus $16M Fine appeared first on Security Boulevard.

]]>
2019039
Crypto Mixer Money Laundering: Samourai Founders Arrested https://securityboulevard.com/2024/05/crypto-mixer-money-laundering-samourai-founders-arrested/ Thu, 09 May 2024 07:00:30 +0000 https://tuxcare.com/?p=17416 The recent crackdown on the crypto mixer money laundering, Samourai, has unveiled a sophisticated operation allegedly involved in facilitating illegal transactions and laundering criminal proceeds. The cryptocurrency community was shocked by the sudden Samourai Wallet shutdown. The U.S Department of Justice (DoJ) revealed the arrest of two co-founders, shedding light on the intricacies of their […]

The post Crypto Mixer Money Laundering: Samourai Founders Arrested appeared first on TuxCare.

The post Crypto Mixer Money Laundering: Samourai Founders Arrested appeared first on Security Boulevard.

]]>
2017412