Recorded Futures Payment Fraud Intelligence team has identified a scam e-commerce network, named the ERIAKOS campaign, targeting Facebook users. This campaign, detected on April 17, 2024, involves 608 fraudulent websites using brand impersonation and malvertising tactics
Continue ReadingCategory: Recorded Future
Security Challenges Rise as QR Code and AI-Generated Phishing Proliferate
SummaryBetween Q4 2023 and Q1 2024, cybercriminals increasingly used QR codes and AI-generated phishing tactics to target executives, exploiting AWS SNS for malicious SMS and VAST tags for malvertising. These sophisticated methods enable threat actors to
Continue ReadingDespite Sanctions, North Koreans Continue to Use Foreign Technology
Summary:Insikt Group's recent analysis reveals that North Koreans continue to use foreign technology to access the internet despite heavy sanctions. This includes Apple, Samsung, and Huawei devices, as well as various social media platforms. A notable
Continue ReadingTAG-100 Uses Open-Source Tools in Suspected Global Espionage Campaign, Compromising Two Asia-Pacific Intergovernmental Bodies
SummaryRecorded Futures Insikt Group identified a suspected cyber-espionage campaign by TAG-100, targeting global government and private sector organizations. TAG-100 exploited internet-facing devices and used open-source tools like the Go backdoor Pantegana. The campaign compromised two Asia-Pacific
Continue ReadingRansomHub Draws in Affiliates with Multi-OS Capability and High Commission Rates
RansomHub, a new ransomware-as-a-service (RaaS) platform, emerged in February 2024, targeting Windows, Linux, and ESXi systems with malware written in Go and C++. Its high 90% commission rate attracts seasoned affiliates, leading to a surge in
Continue ReadingThe Travels of “markopolo”: Self-Proclaimed Meeting Software Vortax Spreads Infostealers, Unveils Expansive Network of Malicious macOS Applications
Recorded Futures Insikt Group identified that Vortax, a purported virtual meeting software, spreads three infostealersRhadamanthys, Stealc, and Atomic macOS Stealer (AMOS). This extensive campaign targets cryptocurrency users, exploiting macOS vulnerabilities. Operated by the threat actor markopolo,
Continue ReadingIsrael-Hamas Conflict and US Elections Drive Violent Extremist Threats in 2024
The ongoing Israel-Hamas conflict, the upcoming 2024 US presidential election, and the rise of violent extremist content online are likely to escalate homegrown and domestic violent extremist (HVE and DVE) threats. HVEs and DVEs are expected
Continue ReadingOilAlpha Malicious Applications Target Humanitarian Aid Groups Operating in Yemen
SummaryInsikt Group's research reveals that OilAlpha, a likely pro-Houthi group, continues to target humanitarian and human rights organizations operating in Yemen. They use malicious Android applications to steal credentials and gather intelligence, potentially to control aid
Continue ReadingCaught in the Net: Using Infostealer Logs to Unmask CSAM Consumers
SummaryIn this proof-of-concept report, Recorded Future's Identity Intelligence analyzed infostealer malware data to identify consumers of child sexual abuse material (CSAM). Approximately 3,300 unique users were found with accounts on known CSAM sources. A notable 4.2%
Continue ReadingSombres Influences: Russian and Iranian Influence Networks Target French Elections
SummaryInsikt Group's research assesses that Russian and Iranian influence networks are targeting the upcoming French elections, and so far, they are having a negligible impact. The Russia-linked Doppelgnger network uses cloned websites and social media bots
Continue Reading