A Prominent American Express Phish
Every once in a while we see a spam campaign where we dig in to the complexity, expecting to find malware, and find that the criminal has just built an extremely fool-proof phishing system for their...
View ArticleTempting Photo Attachments Lead to Fake AV
One of today's largest malicious spam campaigns continued an occasional theme we've been seeing for a few weeks. A subject line, followed by a single "emoticon" email, with an attachment that promises...
View ArticlePaunch and the BlackHole/Cool Exploit Kit
After months of speculation, the creator of the Blackhole exploit kit can be demonstrated to be in custody. As usual with all things Russian in the Cybercrime world, Brian Krebs broke the story in the...
View ArticleIndian Banks targeted in multi-brand Phishing Attack
Malcovery Security's PhishIQ portal is a fascinating place to explore. This week I did a "Security Year in Review" webinar for an audience of our customers and friends which was so much fun to prepare!...
View Article20 Million Chinese Hotel Guests have data leaked
This morning Secure Computing shared a brief article about Data on 20 Million Chinese Hotel Guests being shared by hackers. Unfortunately the only link in the article was a search for the word Breach...
View ArticleTop Brands Imitated by Malicious Spam
WebSense recently released an InfoGraphic titled "Top Five Subject Lines in Phishing Emails." for January 1, 2013 through September 30, 2013. WebSense has a few differences in the way they gather their...
View ArticleHelp your compromised friends on Twitter and Facebook
Have some of your family and friends on Facebook or Twitter been posting some very strange messages recently? They have lost control of their accounts, possibly by entering their passwords on a...
View ArticleHoliday Delivery Failures lead to Kuluoz malware
As Christmas grew closer and people began to worry about whether their online purchases would reach their destinations in time to be placed beneath the Christmas Tree, online scammers decided to take...
View ArticleASProx spamming Court-Related malware
Court-related malware from ASProxUpdate - new version of malware December 27th @6:15AM. see bottom The same spamming botnet that is sending the Delivery spam that imitates Walmart, CostCo and BestBuy...
View ArticleTracking CryptoLocker with Malcovery & IID
First things first: Here are some IP addresses that Malcovery thinks you should block immediately because they are linked to CryptoLocker. You'll see how as you read on! 46.149.111.28, 62.76.45.1,...
View ArticleYahoo Malware, additional data based on Fox-IT report
This weekend on the news, or perhaps Monday morning on NPR, you heard that the popular Yahoo domain has been targeted by criminals who pushed malicious advertisements through their services to...
View ArticleZeus Financial Crime Malware targets Credit Unions and smaller banks
A trend that we've been seeing in both phishing and malware is that criminals are beginning to aim lower in the Financial services market. While it is still true that some of the biggest financial...
View ArticleTarget Database Breach lead to Very Scary Spam
Several folks that also do security research called and texted and Facebook messaged today asking if we had seen "the New Target Phishing email"? We're normally pretty good folks to ask about that sort...
View ArticleTarget Breach considered in light of Drinkman / Gonzalez data breach gang
Everyone is talking about the Target data breach these days, but unfortunately our collective memory is sometimes too short to connect the dots. Back in August of 2008 this blogger, like so many...
View ArticleConsumer Reports on Smart Phone safety, Malware, and Phishing
Every year Consumer Reports does a "State of the Net" survey. I've found it to consistently be one of the most interesting and accurate measures of what's going on with regards to Computer Safety for...
View ArticleRevenge Porn victims to get Justice?
Revenge Porn has been one of the more despicable trends on the Internet over the past years, but recent court documents and arrests indicate that the business practices of some of the participants were...
View ArticleUnprecedented International Cybercrime Cooperation Nabs Email Hackers
Email Hacking in China, India, RomaniaYesterday we tweeted asking for more information on a statement we found in India's press regarding an email hacker charged in Pune. The article I sited, Pune...
View ArticleRoman Vega (CarderPlanet's Boa) Gets His Sentence!
For some time now I have been following with anticipation the case of Roman Vega, the hacker who went by the pseudonym BOA and ran the notorious BOAFactory website prior to helping spear-head the...
View ArticleMore SpyEye Guilty Pleas
Long-time readers of this blog may remember our post in May 2013 called SpyEye Botherder BX1 - Welcome to Georgia! where we shared a timeline of the case against BX1, including the indictment filed in...
View ArticleYahoo reveals coordinated attack on Yahoo Emails - encourages Password reset
On January 30, 2014, Jay Rossiter, the Senior Vice President for Yahoo's Platforms and Personalization Products shared An Important Security Update for Yahoo Mail Users on the companies Tumblr blog. In...
View Article