Archive for April 13, 2023

DeathNote Shifts To Targeting The Defense Industry

Posted in Commentary with tags on April 13, 2023 by itnerd

Kaspersky reported yesterday that since April 2020, threat actor Lazarus Group has had an evolution in its techniques and procedures shifting to targeting defense companies instead of crypto businesses as part of their “DeathNote” campaign. 

The payload relies on trojanized open-source PDF viewer software and weaponized documents to collect and report the victim’s information. Initially, the malware author used decoy documents that were related to cryptocurrency but has now switched all the decoy documents to job descriptions related to defense contractors and diplomatic services. 

The focus began to shift:

  • Early 2020 – EU automotive and academic organizations linked to the defense industry
  • May 2021 – IT company that provides solutions for monitoring network devices and servers
  • May 2021 – Defense contractor in Latin America
  • July of 2022 – Defense contractor in Africa 
  • March 2022 – Several similar victims in South Korea

All relied on the same DLL side-loading technique observed in the crypto targeted programs.

Christopher Peacock, Principal Detection Engineer, SCYTHE had this to say:

   “Often governments shift capabilities to address their needs and requirements, so there may have been a strategic shift from targeting crypto businesses for money to more classical espionage attempting to collect defense information.”

This is one of these situations where education and prudent use of tools would make a difference in terms of defending against attacks like these. Hopefully we’ll see defenders make that shift just like Lazarus has made a shift.

Elon Musk’s Desperation For Twitter To Make Money Shows As He Now Will Allow Users To  Trade Stocks And Crypto 

Posted in Commentary with tags on April 13, 2023 by itnerd

One of the things that Elon Musk wants to make Twitter into the “everything app.” Now if you’re not sure what that means, click here for some background. But to be honest, I am not sure even Elon knows what that means. In any case, Twitter has partnered with a company called eToro to advance that goal. And that partnership will give Twitter users to ability to trade stocks and crypto on the platform:

Starting Thursday, a new feature will be rolled out on the Twitter app. It will allow users to view market charts on an expanded range of financial instruments and buy and sell stocks and other assets from eToro, the company told CNBC exclusively.

Currently, it’s already possible to view real-time trading data from TradingView on index funds like the S&P 500 and shares of some companies such as Tesla. That can be done using Twitter’s “cashtags” feature — you search for a ticker symbol and insert dollar sign in front of it, after which the app will show you price information from TradingView using an API (application programming interface).

With the eToro partnership, Twitter cashtags will be expanded to cover far more instruments and asset classes, an eToro spokesperson told CNBC.

You’ll also be able to click a button that says “view on eToro,” which takes you through to eToro’s site, and then buy and sell assets on its platform. EToro uses TradingView as its market data partner.

“As we’ve grown over the past three years immensely, we’ve seen more and more of our users interact on Twitter [and] educate themselves about the markets,” Yoni Assia, eToro’s CEO, told CNBC in an interview. 

“There is very high quality content, real-time content on financial analysis of companies and what’s happening around the world. We believe this partnership will enable us to reach those new audiences [and] connect better the brands of Twitter and eToro.”

I’m sure that the real reason behind this partnership is that Elon gets a cut of anything done on the platform. Which I am sure he hopes will make him lots of money. After all he is desperate for money. And you have to wonder what he will do next when, not if this doesn’t work for Elon.

Trinity Broadcasting Network Chooses Nyriad UltraIO Storage Platform And DigitalGlue creative.space

Posted in Commentary with tags on April 13, 2023 by itnerd

Nyriad and DigitalGlue have announced that Trinity Broadcasting Network (TBN) has chosen Nyriad UltraIO storage and the DigitalGlue creative.space solution as the foundation for its editorial and media asset management environment. In doing so, TBN will be able to improve the performance, resilience, and efficiency of its media production workflows while removing complex IT-centric tasks and simplifying them with a streamlined user experience. TBN can now better optimize its resources, eliminate costly post-production delays, and continue to deliver high-quality content on time and within budget.

Launched in 1973 by Christian television pioneers Paul and Jan Crouch, TBN began as one television station broadcasting a few hours of Christian programming each day to viewers throughout the Los Angeles area. In the years since, TBN has grown into a family of over thirty twenty-four-hour global networks reaching every inhabited continent with entertaining, inspirational, and life-changing programming for every family member and demographic.

The programming requirements for TBN are substantial and require a team of writers, producers, and creatives to generate fresh and engaging content that appeals to their audience. This task involves producing a wide range of television shows, documentaries, films, news programs, educational programs, and more. Additionally, TBN constantly refreshes its content to keep audiences engaged and interested, which requires a continuous stream of new ideas, scripts, and concepts. Supporting a network of this size and scope was beginning to put a strain on its aging data storage infrastructure, and it was decided that a replacement solution was required.

After careful consideration of its current storage, as well as an exhaustive review of another nine potential solutions, the Nyriad UltraIO storage platform and DigitalGlue creative.space combined solution was found to be the most highly performant, more resilient, and dramatically more cost-effective – from both a cost of acquisition and overall TCO standpoint, than every one of the competitors.

To learn more about the joint Nyriad UltraIO and DigitalGlue creative.space solution, please visit: https://www.nyriad.io/nyriad-and-digitalglue-solution-brief/ and https://www.creative.space/partnerships/nyriad.

Cradlepoint Recognized As A Leader And Outperformer In GigaOm Radar Report

Posted in Commentary with tags on April 13, 2023 by itnerd

Cradlepoint, the global leader in cloud-delivered LTE and 5G wireless network solutions, has been named as a Leader and Outperformer in GigaOm’s Radar Report for SD-WAN for its 5G-optimized solution. GigaOm rated Cradlepoint’s SD-WAN offerings “exceptional” in the categories of scalability, manageability, and vendor support.  

The report specifically highlights Cradlepoint’s NetCloud Exchange (NCX) as one of the company’s strengths. An extension of Cradlepoint’s NetCloud Service, NetCloud Exchange allows enterprises to enhance the benefits of 5G with advanced SD-WAN and zero trust capabilities. As more enterprises take advantage of the ability to connect from anywhere using 5G, providing modern security and application assurance features will enhance the overall quality of experience while reducing the overall attack surface. 

5G is rapidly becoming an essential WAN infrastructure technology, enabling agile connectivity for use cases such as vehicles, IoT devices, sites, and remote work. With 5G standalone deployments on the horizon, Cradlepoint’s 5G-optimized SD-WAN solution is also a nod to the future of connectivity, due to its ability to support application-based traffic steering into network slices. This critical functionality will help carriers make network slicing a reality in the enterprise. It will also enable enterprises to take advantage of differentiated services over 5G networks, facilitating the transition of wired to wireless WANs.   

Earlier this month, Cradlepoint furthered its SD-WAN and security ambitions with the acquisition of Ericom and its cloud-based security solution, ZTEdge. The move solidifies Cradlepoint’s SASE, zero trust, and cloud-based security strategies for hybrid 5G and wireline environments. The Ericom acquisition is a key part of Cradlepoint’s strategy of building a full-stack enterprise security service optimized for 5G. 

For further insights into GigaOm’s SD-WAN Radar Report and a look into the future of the intersection of SD-WAN and 5G, Cradlepoint will host a webinar on Wednesday, May 3rd, 2023 at 1:00 p.m. EST, co-presented with Howard Holton, CTO of GigaOm.  

PBS Dumps Twitter…. I Wonder In What Immature Way Will Elon Musk React To This?

Posted in Commentary with tags on April 13, 2023 by itnerd

Yesterday, I wrote about NPR dumping Twitter because Elon Musk slapped a “government-funded media” label on their Twitter account. At the time, I said this:

This could be the start of other news organizations dumping Twitter. Which will add to the death spiral that Twitter is already in as nobody wants to go someplace where there is no content to view. Perhaps Elon should have thought about that before he decided to slap “government-funded media” labels on both NPR and BBC.

Today, we have PBS announcing that it will be dumping Twitter as well:

The public broadcaster joined NPR in saying it is no longer interested in sharing its content on the platform, after owner Elon Musk slapped a “government-funded” label on its account, which carries more than 2 million followers.

“PBS stopped tweeting from our account when we learned of the change and we have no plans to resume at this time,”a spokesman for the outlet told The Hill. “We are continuing to monitor the ever-changing situation closely.”

Well, that’s going to sting. And it validates that this is going to be one of those situations where you’re likely to see other news outlets do the same thing. But that’s over the medium to long term. In the short term, I wonder how Elon will react to this. In his typical immature way, he posted this Tweet after NPR dumped Twitter:

I fully expect something equally as immature from Elon at any time. Which shows you what type of person he is.

New Zelle Phishing Attack Has Hackers Spoofing Popular Money Transfer Site: Avanan

Posted in Commentary with tags on April 13, 2023 by itnerd

Zelle has become a top-rated money-transfer service, making it easy for users to instantly send money to friends or businesses. Unfortunately, its popularity has also attracted the attention of hackers who are now spoofing Zelle to steal money from unsuspecting end-users. 

Avanan, a Check Point Software Company, has revealed how hackers spoofed Zelle to obtain money from their victims. Avanan’s cybersecurity researchers have prepared an attack brief discussing the tactics used by these hackers to deceive their victims.

In this attack, hackers send out well-crafted spoofed Zelle emails to trick users into sending money directly to them. Using social engineering and brand impersonation techniques, cybercriminals convincingly mimic Zelle’s email communications, luring users to click on a malicious link.

You can read the report here.

Mega Tax Time Phishing Scheme Detailed By INKY

Posted in Commentary with tags on April 13, 2023 by itnerd

INKY has published a new Fresh Phish. Tax season can bring out the worst in phishers, but this scam has an interesting twist! 

This report details how the phisher is targeting tax professionals and stealing the data and credentials they need to file false claims, all with the help of a service called ‘Mega’, that the notorious crime ringleader Kim Dotcom founded.

The report can be found here.

New Python-Based Credential Harvester & Hacktool Malware Emerges: Cado Security

Posted in Commentary with tags on April 13, 2023 by itnerd

Cado Security will release a report on a newly discovered Python-based credential harvester and hacktool called Legion, which targets various services for email exploitation. Cado’s research indicates that Legion is likely linked to the AndroxGh0st malware family, first reported in December 2022. Interestingly, the tool is being marketed and sold via Telegram messenger.

Legion is designed to exploit web servers running CMS, PHP, or PHP-based frameworks. It can retrieve credentials for a wide range of web services, such as email providers, cloud service providers, server management systems, databases, and payment platforms like Stripe and PayPal. Furthermore, Legion can hijack SMS messages and compromise AWS credentials.

A unique aspect of Legion, not previously covered in the research, is its ability to send SMS spam messages to users of mobile networks in the United States. The report will provide a comprehensive list of targeted carriers, including AT&T, Sprint, Verizon, and others.

Cado Labs discovered a YouTube channel containing tutorial videos on Legion, indicating that the tool is widely distributed and likely paid malware. Cado also found several Indonesian-language comments, suggesting the developer may be Indonesian or based in Indonesia.

You can read the report here.

Geotab Drives Industry Standard in Electric Vehicle Fleet Management with Data IntelligenceSolutions for Over 300 EV Makes and Models

Posted in Commentary with tags on April 13, 2023 by itnerd

 Geotab Inc. is revolutionizing the way electric vehicles are managed with its comprehensive telematics and data intelligence solutions. Geotab’s platform provides near real time data on battery charge, range, energy and fuel usage and charging history for over 300 different EV makes and models, making it the global leader in EV telematics.  

Geotab announced the world leading milestone at the grand opening of its new Innovation and Research Hub in High Wycombe, England. This state-of-the-art facility, which has been active since 2020, is dedicated to advancing the data intelligence required to support the electrification of the transportation sector at scale. The hub is home to some of the brightest minds in the industry who are pioneering the way forward in developing cutting-edge technologies to support connected vehicles of all kinds. With a focus on delivering innovative solutions, this center of excellence is at the forefront of driving a cleaner and more sustainable future for transportation.

Despite the rapid growth of the EV industry, there is still a lack of official vehicle information standards, creating unique data challenges for fleet managers. Through Geotab’s technology and reverse engineering process, the company offers comprehensive data insights that provide fleet managers with the information needed to make informed decisions for fleet electrification and sustainability goals, such as vehicle range, efficiency and state-of-charge. Without access to this data, fleets can face issues such as inefficiency, unexpected breakdowns, decreased productivity and an unsatisfactory electric vehicle experience. 

Geotab has been at the forefront of innovation for over 20 years. It has continuously evolved to meet the changing needs of the industry, and for the past decade, has been specializing in electric vehicles. The company’s ability to provide rich and comprehensive data signals for virtually any EV make or model is a remarkable milestone that reflects the hard work of hundreds of engineers and data scientists.

Geotab offers a range of tools for EV fleet management, including an EV Suitability Assessment (EVSA) that analyzes unique driver profiles and patterns to identify which fleet vehicles are suitable for electrification. The Green Fleet Dashboard compares performance against similar fleets, including EV performance, usage, and cost savings, and the Fleet Electrification Knowledge Center provides data-driven analyses and resources for fleets of any size along the EV conversion journey, including analyses to help fleets understand EV battery lifespans and real-world range impacts.

To learn more about how Geotab can fully support your fleet’s transition to electric, visit https://www.geotab.com/fleet-management-solutions/electric-vehicles/