Security Awareness Training Blog

Keeping You Informed. Keeping You Aware.
Stay on top of the latest in security including social engineering, ransomware and phishing attacks.

Doh! New "Bart" Ransomware from Threat Actors Spreading Dridex and Locky

Proofpoint researchers discovered a new strain of ransomware called "Bart" - no kidding. The Russian Cyber Mafia behind Dridex 220 and Locky are using the RockLoader malware to download ...
Continue Reading

New Study Shows Your Apps Could Be Putting Your Personal Information At Risk

A recent study by Cloudlock, a cyber security company, revealed several popular apps that could allow hackers an easy gateway to access your personal information.
Continue Reading

IT pros: Half Of Our CEOs Fall Victim To Phishing Scams

Executive boards need better cyber security training, given half of C-level execs fall victim to phishing attacks, according to research conducted by security firm AlienVault. The ...
Continue Reading

[ZERO DAY ALERT] Ransomware Targets MS Office 365 Users

Apparently, MS Office 365 built-in security tools are not cutting it. A new strain of the Cerber Ransomware is now targeting MS Office 365 email users with a massive zero-day attack that ...
Continue Reading

Intel Thinks Antivirus Is Shit And Dumps Useless McAfee

Remember that in a gray past, Intel had an antivirus product called Intel LanDesk Virus Protect? Well, that Intel LanDesk Virus Protect got acquired by Symantec in 1998, and Intel must ...
Continue Reading

"BadTunnel" Social Engineering Attack Hijacks Your Network Traffic

A researcher in China has discovered a design flaw in Microsoft Windows that affects all versions of the operating system using NetBIOS spoofing —including Windows 10— and lets an ...
Continue Reading

Top website domains are vulnerable to email spoofing

Don’t be surprised if you see spam coming from the top websites in the world. Lax security standards are allowing anyone to "spoof" emails from some of the most-visited domains, according ...
Continue Reading

Russian Cyber Mafia Is Back From Vacation With Smarter Locky Ransomware Strain

Threatpost reported that the notorious Necurs botnet is back in business, after mysteriously going dark for nearly a month. Researchers report the Necurs has returned to spewing massive ...
Continue Reading

IT'S SHOWTIME! Kevin Mitnick Episode on NATIONAL GEOGRAPHIC - THIS SUNDAY

National Geographic has done a special on Kevin Mitnick and it plays this Sunday!
Continue Reading

New KnowBe4 Survey: Ransomware Infections Double In Two Years

We have just released the first long-time study focusing on IT Pros experience with ransomware. In June 2016 we surveyed 1,138 companies in a variety of industries and compared your ...
Continue Reading

Expect Micro Ransomware: Extortion One Document At A Time

I have been following the development of ransomware closely since September 2013 when the ransomware plague was unleashed on the internet in the form of CryptoLocker and its copycats. At ...
Continue Reading

New RAA Ransomware Strain Created Entirely Using Javascript

Larry Abrams, who runs Bleepingcomputer was first to report on a new strain of ransomware called RAA. The criminal coders took the somewhat unusual step of writing the whole thing in ...
Continue Reading

Scam Of The Week: Orlando Nightclub Phishing Attacks

Just when you think they cannot sink any lower, criminal internet scum is now exploiting the tragedy in Orlando. Unfortunately, from this spot I have been warning about these lowlifes ...
Continue Reading

FBI: Business e-mail scam losses top $3 billion, a 1,300% increase in since Jan.

The FBI’s Internet Crime Complaint Center (IC3) this week said the scourge it calls the Business Email Compromise continues to rack-up victims and money – over $3 billion in losses so ...
Continue Reading

New Type of Spear Phishing Directly Targeted at IT Pros

A member of the SpiceWorks IT forums reported he had received a new type of hybrid attack: first a phone call to his desk, followed up with a phishing email laced with malware, promoting ...
Continue Reading

Scam Of The Week: Nasty Two-factor Auth Text Hack

We all know that two-factor authentication (2FA) is much better than just simple user/password credentials. However, there is a nasty spoofing trick that bypasses 2FA if the user does not ...
Continue Reading

Individual ransomware payments skyrocket to a whopping $20,000

Heads-up! Individual ransomware payments are getting very expensive. Companies are stockpiling Bitcoin in case they are hit, and a new low-profile strain of ransomware is actually causing ...
Continue Reading

Yikes: Ransomware scam targets lawyers with phony ethics complaints

Mike Mosedale at the Minnesota Lawyer wrote: "Talk about your dirty tricks. A new internet scam is targeting lawyers by exploiting one of their great fears: getting slapped with a ...
Continue Reading

CyberheistNews Vol #6 #23

Continue Reading

Scam Of The Week: FBI Warns Against Email Extortion

Your employees are being attacked both inside and outside the office. This new email extortion scam called CEO fraud can hit in both places, so it makes sense to warn them about this ...
Continue Reading

UltraDeCrypter Ransomware DOES NOT Decrypt Your Files

KnowBe4 gets regular calls from system admins who found us on the internet that are between a rock and a hard place. Backups failed and they have no way to revert to normal files. Worse, ...
Continue Reading

[ALERT] 93% of phishing attacks now have ransomware payloads

Oh boy. Things have gotten from bad to worse in an awful hurry. I remember the first time I reported on ransomware in the CyberheistNews Issue Feb 11, 2014, where an attorney's office ...
Continue Reading

Looks Like 8 More Cyberheists By North Koreans

Gottfried Leibbrandt, chief executive of the world’s largest interbank funds-transfer system SWIFT, has said repeatedly that the prospect of cybercrime is what keeps him awake at night. ...
Continue Reading

[INFOGRAPHIC] Don't Be The Victim Of A Cyberheist

We have created a new infographic for your users, as part of your ongoing security awareness training program. It's a few good reminders how to stay safe online, and to keep their ...
Continue Reading

Top Ransomware campaign managers make 13 times more than avg Russian wages

A short report by Flashpoint gives us some insight into a recent ransomware campaign, which so far has generated a serious amount of profit considering it takes little effort to operate.
Continue Reading

Phishing Attacks Ramp Into 2016 With Major Increase

In its most recent Phishing Trends Report, the APWG noted a 250% increase in phishing sites between October 2015 and March 2016 — and the 2016 increase shows the never ending criminal ...
Continue Reading

Ransomware domains increased 3500% in Q1 2016

There has been a whopping 3500% increase in ransomware domains in the first quarter of 2016, compared to the last quarter of 2015. Those are the highlights of a new report by network ...
Continue Reading

Get the latest about social engineering

Subscribe to CyberheistNews