Last March, we reported on Operation C-Major, an active information theft campaign that was able to steal sensitive information from high profile targets in India. The campaign was able to steal large amounts of data despite using relatively simple malware because it used clever social engineering tactics against its targets. In this post, we will focus on the mobile part of their operation and discuss in detail several Android and BlackBerry apps they are using. Based on our investigation, the actors behind Operation C-Major were able to keep their Android malware on Google Play for months and they advertised their apps on Facebook pages which have thousands of likes from high profile targets.Read More
The FBI has issued a warning on the dramatic increase of Business Email Compromise (BEC) scams, swindling over US$2.3 billion from companies worldwide, notably the US and Europe. The scams do not discriminate, with targets ranging from small businesses to large corporations. All the perpetrators need is the company executive’s email address (or someone close, like their personal assistant) and the ability to make a convincing fake email.Read More
Every registered voter in the Philippines is now susceptible to fraud and other risks after a massive data breach leaked the entire database of the Philippines’ Commission on Elections (COMELEC). While initial reports have downplayed the impact of the leak, our investigations showed a huge number of sensitive personal identifiable information (PII)–including passport information and fingerprint data–are included in the data dump.Read More
There’s a reason why the FBI estimates that the average loss caused by Business Email Compromise (BEC) to be $130,000 per company. Employees are not familiar with current social engineering strategies, and the network setup is not equipped enough to keep the threat from getting in the network. And this same situation is clearly depicted in an ongoing BEC campaign targeting companies in the US, Middle East, and Asia.
The attack, which has been traced back to Lagos and Kuala Lumpur, targets companies from several industries such as real estate, manufacturing, and construction.Read More