Tag

Vishing

All articles tagged with #vishing

Teams Impersonations Fuel Chaos Ransomware Deployments Across North America
security2 hours ago

Teams Impersonations Fuel Chaos Ransomware Deployments Across North America

Sophos warns of STAC4749, a vishing campaign in which external Microsoft Teams calls impersonate IT staff to gain remote access, deploying backdoors and culminating in Chaos ransomware across dozens of North American organizations (Canada ~50%, US ~45%). Attackers used fake IT domains under the .top TLD, relied on Quick Assist or RemSupp, then PowerShell to install persistence and remote access tools like DWAgent/AnyDesk, with RDP used for lateral movement. Ransomware encrypts files and may accompany data theft; Chaos-as-a-service is linked to Conti offshoots. The techniques evolved to evade detection; no confirmed link to MuddyWater.

Google Addresses Security Warnings Amid Hacker Threats and Data Breaches
technology11 months ago

Google Addresses Security Warnings Amid Hacker Threats and Data Breaches

ShinyHunters, a cybercrime group known for data breaches and now employing voice-based social engineering tactics like vishing, has targeted major companies including Salesforce, affecting millions of users. The group has links with other hacking groups and is involved in selling stolen data and offering ransomware services. Protecting against such attacks involves vigilance, employee training, and enhanced security measures like multi-factor authentication. The rise of AI-generated deepfakes makes these scams more sophisticated and harder to detect.

FakeCall Malware Exploits Androids for Banking Scams
mobile-security-financial-fraud1 year ago

FakeCall Malware Exploits Androids for Banking Scams

A new variant of the FakeCall Android malware has been discovered, using voice phishing techniques to deceive users into divulging personal information. This sophisticated malware can intercept and hijack calls, redirecting them to fraudulent numbers controlled by attackers, while mimicking legitimate banking interfaces. It exploits accessibility services to gain control over devices, capturing sensitive data and performing unauthorized actions. The malware's evolution highlights ongoing challenges in mobile security, despite efforts to enhance defenses against such threats.

"American Companies' Vulnerability Exposed: Lessons from the MGM Cyber Attack"
cybersecurity2 years ago

"American Companies' Vulnerability Exposed: Lessons from the MGM Cyber Attack"

MGM Resorts experienced a cyberattack that disrupted its systems, including hotel room digital keys and slot machines. The attack was believed to be carried out by a group known as Scattered Spider, specializing in social engineering techniques like vishing. The hackers impersonated an employee in a phone call to MGM's IT help desk to gain access to the systems. The group claims to have stolen and encrypted MGM's data and is demanding a ransom in crypto. Another casino chain, Caesars Entertainment, also experienced a cyberattack around the same time. Vishing, a combination of voice and phishing, is a growing cybersecurity threat that targets human vulnerabilities. Organizations are urged to strengthen their defenses against social engineering attacks and provide better training to employees.