Posts

Showing posts with the label cybersecurity

When Malware is Digitally Signed by an Anti-Malware Company

Image
  In October 2024, a sneaky malware campaign started spreading. The threat actors used a message that looked like it came from the Israeli partner of ESET, a well-known anti-malware company. They targeted Israeli businesses and educational institutions. But here’s the catch: the message didn’t show any signs of having malicious content. Analysts who initially checked out the email thought there was nothing fishy about it. The email warns recipients that their company is being targeted by “state-sponsored threat actors.” It suggests downloading and installing the “ESET Unleashed” app to protect against this threat. The email’s link seems legitimate, pointing to a valid ESET server. The file on the download link contains an executable file (Setup.exe) and four DLL files. Upon closer inspection, it turns out that the DLL files are part of ESET’s anti-virus software, but the EXE file is actually a malicious data wiper but it was digitally signed by ESET. This malware has an interesting...

New Cybersecurity Attack Vector: Baguetteware

Image
  I am uncertain how to respond to this news report. Schneider Electric recently experienced a cyberattack and the hacking group known as Greppy has issued a demand for $125,000 worth of baguettes. Failure to meet this demand will result in the release of the 40 GB of data allegedly exfiltrated by the group. If the report is accurate, this constitutes an unprecedented occurrence, rendering my initial intention to rename this blog as The Hungry Hacker unfeasible Read the report here:  Hackers demand France’s Schneider Electric pay a $125k ransom in baguettes | Tom's Hardware

I'm Rich! Rich I Tells Ya!

Image
  ...and all I need to do is send personal information to the International Monetary Fund Director of ATM Department, Mr. Arjun Rajesh (who inexplicably uses arjunrajesh@ gmail.com)  and I will have ₱1,634,980,891.97 in my bank account! But seriously , I can't believe how there are still people that gets scammed by emails like this. If you (and of my three blog readers) reads this, please do your share and inform everyone you know of this scam.

Beware of Fake Docusign Emails

Image
  Let this serve as a friendly reminder to refrain from digitally signing documents that you may unexpectedly receive. Such actions may inadvertently provide your digital signature to threat actors (hackers), which could subsequently be exploited for unauthorized financial transactions in your name. According to Bleeping Computer : Threat actors are abusing DocuSign's Envelopes API to create and mass-distribute fake invoices that appear genuine, impersonating well-known brands like Norton and PayPal.   Using a legitimate service, the attackers bypass email security protections as they come from an actual DocuSign domain, docusign.net. The goal is to have their targets e-sign the documents, which they can then use to authorize payments independently from the company's billing departments. The best way to avoid this is to double-check that the digital documents you received in your inbox are real and you expect it. If the message simply appears on your inbox unexpectedly, do not...

Quickie Post: Proton Mail Black Friday Deal!

Image
  I just found this in my Proton Mail inbox.  This, in my opinion, is a very good deal if you are looking for a safe and reliable email service,  I personally use Proton Mail as my "professional" email service and it had served me well in the past couple of years,

WARNING: GCash Phishing Leveraging the SIM Registration Act

Image
A lot has happened since the Philippine SIM Registration Act has been implemented.  There are people who are for and against its implementation.  That is an issue that can only be resolved in time.  However there is a bigger issue has stemmed from it.  The law is now being leveraged by threat actors that seeks to gather personal information from their potential victims. While reviewing my SPAM folder for legitimate messages that have slipped into the cracks, I noticed this interesting sender. A casual look makes it appear as if it came from GCash, a service I use for my digital wallet needs.  Although the display name says "admin@gcashmobile.com", it was sent "via sendgrid".  Just to let you know, legitimate emails from GCash comes from the "@gcash.com" email domain so this is already a big red flag.   Here is the body of the message: Looks convincing, right?  However, one thing that everyone should be aware of is this: Companies will always refer...