![]() |
Meng Wanzhou, the CFO of Huawei
Industries arrested.
|
To read the full article and find an archive of related reporting, follow this link to READBOARD.
WWW.WAPACKLABS.COM
![]() |
Meng Wanzhou, the CFO of Huawei
Industries arrested.
|
Researchers report that one in four breaches in the financial services sector were due to lost or stolen devices, while one in five were the result of hacking. Physical security often is viewed as a necessary evil in many corporations, yet remain very important in overall cybersecurity. Many researchers, as well as Wapack Labs, completely understand the critical point that cybersecurity involves hardware and humans as much as it does malware and networks.
This report is an update to previous Wapack Labs postings regarding the SamSam malware. US federal authorities are providing current information about the vulnerabilities and exploits used to deploy SamSam ransomware, also known as MSIL/Samas.A. This malware was being deployed by cyber criminals Mohammad Mehdi Shah Mansouri and Faramarz Shahi Savandi. On 26 November 2018, the District of New Jersey indicted Mansouri and Savandi for developing and deploying SamSam ransomware. SamSam infects whole networks and encrypts victim data, allowing Mansouri and Savandi to demand considerable ransoms in Bitcoin in return for decryption keys.
Cybersecurity researchers have unveiled, the first-ever, UEFI (Unified Extensible Firmware Interface) rootkit being used. It allows hackers to implant persistent malware on targeted computers that could endure a complete hard-drive wipe. Titled LoJax, the UEFI rootkit is part of a malware campaign conducted by the Sednit group, also known as APT28, Fancy Bear, Strontium, and Sofacy, who have targeted government organizations in the Balkans as well as in Central and Eastern Europe.[1] The Sednit group is a state-sponsored hacking group believed to be a unit of the Russian GRU (General Staff Main Intelligence Directorate). The hacking group has been associated with a number of high-profile attacks, including the DNC hack during the US 2016 presidential election.