Showing posts with label FBI. Show all posts
Showing posts with label FBI. Show all posts

Friday, May 23, 2025

Deepfaking of Some Senior US Government Officials


Do you think AI-powered smishing and vishing are far off? Then do think again. (Smishing uses text messages to trick users; vishing relies on voice calls to do the same.)


Today, these social engineering attacking tactics might seem low-level, but the developments in AI-technology is rapidly changing that. With tools that can generate natural-sounding texts and mimic real voices, attacks are getting more sophisticated and convincing. What’s now a minor risk could soon escalate into a widespread and highly effective threat.


The FBI has warned that fraudsters are impersonating "senior US officials" using deepfakes as part of a major fraud campaign.


According to the agency, the campaign has been running since April and most of the messages target former and current US government officials. The attackers are after login details for official accounts, which they then use to compromise other government systems and try to harvest financial account information.


https://bit.ly/4ks5Jff


Headlines:

"'AI-generated content has advanced to the point that it is often difficult to identify,' the FBI advised. 'When in doubt about the authenticity of someone wishing to communicate with you, contact your relevant security officials or the FBI for help.'"


"Attackers have used this approach for over five years. The technology needed to run such attacks is so commonplace and cheap that it's an easy attack vector. Deepfake videos have been around for a similar period, although they were initially much harder and more expensive to do convincingly."

Tuesday, January 2, 2024

FBI vs. BlackCat

Ransomware attacks keep increasing. It is quite limited what local or international authorities can do against these attacks. The authorities intervene mostly after the ransomware attacks occurred and most of the time it is too late for after you got hit by a ransomware gang.

So be aware that it is YOU who can prevent ransomware attacks and it must be YOU who take actions against the ransomware gangs. DO take actions before you got hit. Allocate enough budget for cyber security before it's too late.


Well, it seems that cat-and-mouse-game between local or international authorities and ransomware gangs won't come to an end in the near future. (You guess who is the cat and who is the mouse in this game.)


Close to the end of the last year (2023), FBI seized the website of a ransomware gang, who are known as BlackCat or AlphV, and obtained some decryptor keys. The cat seems to have nine lives and the gang denied this partly and claimed that they are still -almost- fully operational though.


https://bit.ly/48Fq0av


"The FBI created a decryption tool for the ransomware used by the gang known as BlackCat and/or AlphV, as part of a wider disruption campaign against the extortionists.


The existence of the decryptor was revealed in a Tuesday announcement by the United States Department of Justice that reports the FBI has offered the tool to over 500 orgs and believes $68 million of ransom payments were avoided as a result."


"...The Feds said they were able to access 946 public-private key pairs for Tor-hidden sites the BlackCat gang used to communicate with victims and host its blog,..."


"In other words, it sounds as though the Feds were not only able to seize and shut down the ransomware-as-a-service crew's dark-web presence, agents also obtained enough internal info to provide decryption assistance to victims..."


"The FBI operation was carried out in partnership with the plod in the UK and Australia, and Europol. Their probe into AlphV is ongoing and authorities have advised a reward may be offered to those who offer further information about the crew."


"The gang, believed to be Russian, today boasted it had "unseized" its main dark-web site by pointing it at a web server the miscreants control, rather than an FBI one. The crew used its restored blog to name new alleged victims of its ransomware."


"The FBI's claim of offering a decryptor to more than 500 victims has also been watered down by the group. According to the criminals, the number sits more at the 400 mark while still leaving 3,000 without a decryptor key."


Wednesday, November 30, 2022

FBI Conducts Cyber Offensive Operations

 

FBI director Christopher Wray told senate lawmakers that his agency has been conducting offensive cyber operations against STATE and non-state actors.

Fancy phrases aside, this means that FBI does cyber attacks. Well most of the people would find it quite normal. Which intelligence agency doesn't? Well, we all knew it. Head of FBI only declared it. So be a good guy else...

What was the saying? Umm... "The best defense is a good offense"? Or something like that? And what did legendary Sun Tzu say about it? Here it comes: "Attack is the secret of defense; defense is the planning of an attack." (Maybe Christopher Wray just finished the book "The Art of War". Who knows? =)) )

https://thehill.com/policy/cybersecurity/3740758-wray-tells-lawmakers-that-fbi-conducts-cyber-offensive-operations/

“'Offense is a critical part of our overall effort to push back against cyber adversaries,' Wray said during a Senate Homeland Security Committee hearing in which he was testifying."

"Although Wray did not provide specifics into the type of cyber offensive operations the agency has conducted, he did say that the department engages in other types of activities, including conducting counterintelligence operations, targeting adversaries’ infrastructure, disrupting malicious cryptocurrency schemes, and indicting cyber criminals."

"Other U.S. agencies have also said that they’ve engaged in cyber offensive operations against nation-state threat actors.

In June, Gen. Paul Nakasone, the head of U.S. Cyber Command, publicly confirmed for the first time that the U.S. had helped Ukraine on the offensive side."

"However, he warned that deterring nation-state threat actors from continuing to engage in illegal cyber activity is much more difficult than disrupting their operations.

'We’re not going to deter the Chinese or the Russians from spying, but we can make it hellishly difficult for them to do it,' Wray said. "



Saturday, October 29, 2022

Daixin Ransomware Team

 

Ransomware does not slow down. Bad guys saw the gain in this attack technique and they are highly motivated to carry on this attack.


A ransomware warning against the Daixin Team for healthcare sector came from CISA (Cybersecurity and Infrastructure Security Agency), FBI and HHS (Health and Human Services) in USA.


Daixin Team attackers have been linked to multiple health sector ransomware incidents since (at least) June 2022.


"U.S. health organizations are advised to take the following measures to defend against Daixin Team's attacks:

- Install updates for operating systems, software, and firmware as soon as they are released.

- Enable phishing-resistant MFA for as many services as possible.

- Train employees to recognize and report phishing attempts."


https://www.bleepingcomputer.com/news/security/us-govt-warns-of-daixin-team-targeting-health-orgs-with-ransomware/


"'The Daixin Team is a ransomware and data extortion group that has targeted the HPH Sector with ransomware and data extortion operations since at least June 2022,' the advisory revealed.


Since June, Daixin Team attackers have been linked to multiple health sector ransomware incidents where they've encrypted systems used for many healthcare services, including electronic health records storage, diagnostics, imaging services, and intranet services."


"The ransomware gang gains access to targets' networks by exploiting known vulnerabilities in the organizations' VPN servers or with the help of compromised VPN credentials belonging to accounts with multi-factor authentication (MFA) toggled off."



Wednesday, May 20, 2020

Is China a (Digital) Threat to Global Health?

According to me USA wants to "bite" China somehow and is trying to find some excuses for it. Nowadays the hot topic is "Covid-19" between them.

But care must be taken in case of the allegations are true, the health care organizations and pharmaceutical companies DO have to be careful against the cyber threats,
(News from cyberscoop.com)

"The Department of Homeland Security and the FBI on Wednesday blamed hackers linked with the Chinese government for attempting to steal U.S. research into a coronavirus vaccine,..."

"The U.S. agencies accused Chinese hackers as well as spies of trying to pilfer intellectual property and other information related to coronavirus treatments."

"Beijing has denied all of those allegations. “It is immoral to target China with rumors and slanders in the absence of any evidence,” Zhao Lijian, China’s Ministry of Foreign Affairs spokesperson, said Monday after media reports that the DHS-FBI statement was imminent."

"...The Trump administration has accused Beijing of misleading the world about the virus’s severity, which first emerged in the Chinese city of Wuhan. The White House has also labeled the illness the “Chinese virus” as the U.S. federal government has struggled to respond to an outbreak that has infected some 1.4 million people in the U.S."

"Tonya Ugoretz, deputy assistant director of the FBI’s cyber division, said last month that state-sponsored hackers were spying on U.S. organizations researching the coronavirus, but did not name a specific government. Last week, cybersecurity officials from DHS and Britain’s National Cyber Security Centre echoed that warning by saying that spies are targeting multiple global health care organizations and pharmaceutical companies worldwide."

"This would not be the first time that Chinese hackers have been mobilized in Beijing’s response to a public health threat. Faced with a surging cancer rate in China, hackers have repeatedly targeted organizations conducting cancer research, according  to cybersecurity company FireEye."

(For more: https://www.cyberscoop.com/coronavirus-vaccine-china-hacking-dhs-fbi/)