Newsletters

Written content from the Risky Business Media team

Risky Bulletin: BEC campaign steals €35 million from French notaries

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Hackers have stolen more than €35 million from French notaries in a massive campaign over the past four years.

The attackers breached companies via phishing, took over their networks, and slowly and silently modified transaction details to hijack wired payments.

According to French newspaper Le Monde, the campaign hit more than 500 victims, or about 7% of all French notary offices, France's notary supervisory agency, the Conseil Supérieur du Notariat (CSN).

Risky Bulletin: Russia tells data centers to deploy drone defenses

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

The Russian government has instructed data center operators to deploy protections against drone strikes and other physical threats as part of a national effort to boost defenses at critical infrastructure organizations.

Companies that fail to follow the Kremlin's instructions risk having their operations put under the state's administration.

Russian President Vladimir Putin signed a presidential decree last month allowing the state to temporarily take over the operations of critical infrastructure operators who fail to protect against Ukrainian hacks and drone strikes, or take too long to repair damage.

Srsly Risky Biz: China's Private Sector Botnets Are Worth Disrupting

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

This week, the US Department of Justice (DoJ) announced it had disrupted two Chinese cyberespionage systems. The government has disrupted several Chinese botnets in recent years, but Beijing won't be giving up anytime soon. The botnets are simply too useful. 

The disrupted systems were known as QScan and QTRouter. An FBI affidavit says the group running the platforms, QTFY, works for the private Chinese company Nanjing Xinjiuwei Network Technology.

QScan and QTRouter are just two components of a complex system, but both used hard-coded domains, making them susceptible to court-authorised domain seizures. 

Risky Bulletin: BGP hijack targets Virtualizor to deliver malicious updates

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

An unidentified threat actor has pulled off a successful BGP hijack that commandeered some of the IP address space and internet routing for software company Softacolous to deliver malicious updates for the Virtualizor web hosting management platform.

The BGP hijack took place for almost 33 hours, from Friday to Sunday last week.

The Virtualizor team says the hacker performed the BGP hijack, obtained a TLS certificate in its name, and hosted a clone website that delivered the malicious updates.

Risky Bulletin: Dutch intel services to get extensive new powers

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

The Dutch government has put forward a new bill that would greatly expand the surveillance powers of the country's two intelligence agencies.

The new bill simplifies procedures to improve operational speed but also adds new requirements and capabilities.

Officials cited the threat of war with Russia and the increasing aggressiveness of countries like China and Iran as the main reason to overhaul the capabilities of AIVD, its domestic security and intelligence service, and MIVD, its military counterpart.

Risky Bulletin: Two TeamPCP members arrested in Australia

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

The Australian Federal Police has arrested on Wednesday two suspects believed to be part of the TeamPCP hacking group.

The suspects were detained in Cottesloe and Mandurah, near the city of Perth, in Western Australia. They appeared in front of a Perth magistrate to be charged on Thursday.

According to local media, the suspect arrested in Cottesloe was identified as Ruben Thomson, 21, the group's alleged leader. The Mandurah man was identified as Louis Gaebler, 23.

China's AI-Enabled APT Operations Are Getting Interesting

Presented by

Tom Uren
Tom Uren

Policy & Intelligence

A new report describes how a Chinese cyberespionage outfit is using AI to beef up its malware arsenal. If this is a sign of things to come, clustering threat actor behaviour together for attribution purposes is about to get a lot harder.

The Bitdefender report, released last week, describes seven remote access tool (RAT) families. All seven were created by a single cyberespionage actor Bitdefender called SilkParasite and five were previously undocumented. The report authors have medium confidence that SilkParasite is, ahem, a "China-nexus actor" targeting governments across Central Asia including Uzbekistan, Turkmenistan and Kazakhstan. 

Back in November we wrote about what looked like an experiment to see how AI-assisted hacking could support China's Ministry of State Security. The approach those threat actors took at the time was to build an attack framework and let Claude do the hacking. It was error-prone and noisy, but sometimes successful.

Risky Bulletin: Russia starts blocking DoH and DoT

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

Russian internet users started reporting issues with connecting to DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT) servers, suggesting the government might have cracked down on the two protocols.

Both DoH and DoT are privacy-centric versions of the DNS protocol that hide a user's DNS queries and intended destination from ISPs and other threat actors on the wire.

Both protocols have seen increased usage in Russia. They are typically used together with a VPN client as a way to bypass the Kremlin's ever-increasing and overbearing internet censorship, and access Western websites.

Risky Bulletin: Expired cards can be used for new transactions

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

A team of academics from the University of Massachusetts Amherst have developed an attack that can revive old expired contactless cards to perform new (illegal) transactions.

The attack exploits the fact that NFC card data is not fully encrypted when making a payment and some parameters can be modified without breaking the card's digital hash/signature.

The researchers created a rig that intercepts transaction data through an NFC Man-in-the-Middle attack, updates the expiration date, and relays the modified payment to a Point-of-Sale (POS) terminal.

Risky Bulletin: Academics find source code overlaps between Geedge and China's Great Firewall

Presented by

Catalin Cimpanu
Catalin Cimpanu

News Editor

A team of American academics have found source code overlaps between the products of a Chinese tech company and the country's Great Firewall traffic filtering and censorship system.

According to research presented at this year's USENIX security conference, the Chinese government is using the Geedge Networks Tiangou Secure Gateway (TSG) device as one of the Great Firewall's three known traffic filtering capabilities.

Researchers linked Geedge's device to the Great Firewall after more than 100,000 files leaked from Geedge's network last year.