{"id":28133,"date":"2019-05-10T06:00:11","date_gmt":"2019-05-10T12:00:11","guid":{"rendered":"https://www.webroot.com/blog/?p=28133"},"modified":"2019-05-09T15:26:03","modified_gmt":"2019-05-09T21:26:03","slug":"cyber-news-rundown-dharma-diversion","status":"publish","type":"post","link":"https://www.webroot.com/blog/2019\/05\/10\/cyber-news-rundown-dharma-diversion\/","title":{"rendered":"Cyber News Rundown: Dharma Diversion"},"content":{"rendered":"\n<h2>Dharma Ransomware Employs Diversion Tactics<\/h2>\n\n\n\n<p>Researchers recently discovered a new ransomware variant\nthat displays an <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/dharma-ransomware-uses-legit-antivirus-tool-to-distract-victims\/\">ESET\nAV removal<\/a> screen once launched in order to divert the a victim\u2019s attention\nfrom the silent encryption taking place. Initially dropped by an email spam\ncampaign, the payload comes as a password protected zip archive, with the\npassword made available in the body of the email to entice curious readers. In\naddition to the ESET removal instructions, the archive also contains a\ntraditional ransom demand with instructions for purchasing and transferring Bitcoin.\n<\/p>\n\n\n\n<h2>Binance Crypto-Exchange Hacked<\/h2>\n\n\n\n<p>At least 7,000 Bitcoin were illicitly removed from the hot\nwallet of <a href=\"https:\/\/www.infosecurity-magazine.com\/news\/hackers-steal-7k-btc-from-binance-1\/\">Binance<\/a>,\nan international cryptocurrency exchange, in a single transaction. By\ncompromising the personal API keys and bypassing two-factor authentication, the\nhackers were able to access the wallet and steal roughly $41 million worth of\nBitcoin. The complete details of the breach are still unknown. <\/p>\n\n\n\n<h2>Global Malvertiser Sentenced in US<\/h2>\n\n\n\n<p>A man operating several fake companies distributing hundreds\nof millions of <a href=\"https:\/\/www.zdnet.com\/article\/malvertiser-behind-100-million-bad-ads-arrested-and-extradited-to-the-us\/\">malicious\nads<\/a> across the globe has been arrested and is facing charges after his extradition\nto the U.S. For nearly five years, Mr. Ivanov and his co-conspirators created\ndozens of malvertising campaigns, usually starting a new one immediately after\nthe previous one was flagged by a legitimate ad network. While this is not the\nonly case of malvertising campaigns causing chaos on the web, it is one of the\nfirst to see actual indictments. <\/p>\n\n\n\n<h2>Robbinhood Ransomware Shuts Down Two US Cities<\/h2>\n\n\n\n<p>Both Baltimore City Hall and the city of Amarillo, Texas,\nwere victims of a variant of <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/local-authorities-in-texas-and-maryland-hit-by-ransomware\/\">Robbinhood\nransomware<\/a> this week. Following the attack,\ncitizens of both cities will be seeing online bill payment options temporarily\noffline as they work to restore networks that were damaged or disconnected to\nstop the spread of the infection. This is the second cyber attack to hit both\ncities within the past year, with Potter County, Texas recovering from a\nsimilar attack just a couple weeks ago. Neither city has released more\ninformation on the ransom amount or when the attack began.<\/p>\n\n\n\n<h2>Freedom Mobile Exposes Payment Credentials<\/h2>\n\n\n\n<p>An unencrypted database containing millions of customer\nrecords for <a href=\"https:\/\/www.infosecurity-magazine.com\/news\/canadian-telco-exposes-unencrypted-1\/\">Freedom\nMobile<\/a>, a Canadian telecom provider, was discovered to be left freely\navailable to the public. While the database was secured in less than a week, the\ntime it was left accessible to criminals is cause for concern. The data\ncontained full payment card information, including essentially everything a\ncriminal would need to commit identity fraud against millions of people. Though\nFreedom Mobile claims the 15,000 were affected, it calls into question the\npractices used to store their sensitive data. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Dharma Ransomware Employs Diversion Tactics Researchers recently discovered a new ransomware variant that displays an ESET AV removal screen once launched in order to divert the a victim\u2019s attention from the silent encryption taking place. Initially dropped by an email spam campaign, the payload comes as a password protected zip archive, with the password made [&hellip;]<\/p>\n","protected":false},"author":47,"featured_media":28135,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[3005],"tags":[21944],"yst_prominent_words":[8061,3563,24559,14215,19377,19613,18763,3493,24555,24553,21863,18915,24551,3523,4933,8223,5423,3937,24557,5439],"acf":[],"_links":{"self":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/28133"}],"collection":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/users\/47"}],"replies":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/comments?post=28133"}],"version-history":[{"count":1,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/28133\/revisions"}],"predecessor-version":[{"id":28137,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/28133\/revisions\/28137"}],"wp:featuredmedia":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media\/28135"}],"wp:attachment":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media?parent=28133"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/categories?post=28133"},{"taxonomy":"post_tag","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/tags?post=28133"},{"taxonomy":"yst_prominent_words","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/yst_prominent_words?post=28133"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}