{"id":29513,"date":"2019-12-06T06:00:46","date_gmt":"2019-12-06T13:00:46","guid":{"rendered":"https://www.webroot.com/blog/?p=29513"},"modified":"2019-12-05T17:52:51","modified_gmt":"2019-12-06T00:52:51","slug":"cyber-news-rundown-zerocleare-malware","status":"publish","type":"post","link":"https://www.webroot.com/blog/2019\/12\/06\/cyber-news-rundown-zerocleare-malware\/","title":{"rendered":"Cyber News Rundown: ZeroCleare Malware"},"content":{"rendered":"\n<h2>ZeroCleare Malware Wiping Systems<\/h2>\n\n\n\n<p>IBM researchers have been tracking the steady rise in <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-iranian-zerocleare-data-wiper-malware-used-in-targeted-attacks\/\">ZeroCleare<\/a>\ndeployments throughout the last year, culminating in a significant rise in\n2019. This malware is deployed on both 32 and 64-bit systems in highly targeted\nattacks, with the capability to completely wipe the system by exploiting the\nEldoS RawDisk driver (which was also used in prior targeted attacks). The\nmalware itself appears to be spreading through TeamViewer sessions and, though\nthe 32-bit variant seems to crash before wiping can begin, the 64-bit variant\nhas the potential to cause devastating damage to the multi-national\ncorporations being targeted. <\/p>\n\n\n\n<h2>FTC Scam Threatens Victims with Terrorism Charges<\/h2>\n\n\n\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/ftc-warns-of-ongoing-scam-spreading-scary-terrorism-allegations\/\">FTC<\/a> officials recently made an announcement regarding scam letters purporting to be from the commission and the numerous complaints the letters have sparked from the public. Victims of the scam are told that, due to some suspicious activity, they will be personally and financially monitored as well as face possible charges for terrorism. These types of scams are fairly common and have been in use for many years, often targeting the elderly with greater success.<\/p>\n\n\n\n<p style=\"text-align:center\"><a href=\"https:\/\/www.webroot.com\/us\/en\/home\/products\/vpn-wifi-security\"><strong>Take back your privacy. Learn more about the benefits of a VPN.<\/strong><\/a><\/p>\n\n\n\n<h2>Misreported Data Breach Costs Hospital Millions<\/h2>\n\n\n\n<p>Following an April 2017 complaint, the Office of Civil\nRights has issued a fine of $2.175 million after discovering that <a href=\"https:\/\/www.infosecurity-magazine.com\/news\/sentara-hospitals-fined-2175m-over\/\">Sentara\nHospitals<\/a> had distributed the private health information for 577 patients,\nbut only reported eight affected. Moreover, it took over a year for the\nhealthcare provider to take full responsibility for the breach and begin\ncorrecting their security policies for handling sensitive information. HIPAA\nviolations are extremely time-sensitive and the slow response from Sentara\nstaff could act as a lesson for other organizations to ensure similar events don\u2019t\nreoccur. <\/p>\n\n\n\n<h2>Android Vulnerability Allows Hackers Easy Access<\/h2>\n\n\n\n<p>Researchers have identified a new <a href=\"https:\/\/www.helpnetsecurity.com\/2019\/12\/03\/strandhogg-vulnerability\/\">Android\nexploit<\/a> that allows hackers access to banking applications by quickly\nstealing login credentials after showing the victim a legitimate app icon,\nrequesting additional permissions, and then sending the user to their expected\napp. Even more worrisome, this vulnerability exists within all current versions\nof AndroidOS and, while not found on the Google Play Store, some illicit\ndownloaders were distributing it. <\/p>\n\n\n\n<h2>Smith &amp; Wesson Hit by Magecart<\/h2>\n\n\n\n<p>In the days leading up to Black Friday, one of the largest\nretail shopping days of the year, malicious skimming code was placed onto the\ncomputer systems and, subsequently, the website of <a href=\"https:\/\/www.infosecurity-magazine.com\/news\/magecart-hackers-fire-smith-wesson\/\">Smith\n&amp; Wesson<\/a>. In a slight break from the normal Magecart tactics, they\nattackers were masquerading as a security vendor to make their campaign less\nvisible. The card-skimming code was initially placed onto the website on November\n27 and was still active through December 2. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>ZeroCleare Malware Wiping Systems IBM researchers have been tracking the steady rise in ZeroCleare deployments throughout the last year, culminating in a significant rise in 2019. This malware is deployed on both 32 and 64-bit systems in highly targeted attacks, with the capability to completely wipe the system by exploiting the EldoS RawDisk driver (which [&hellip;]<\/p>\n","protected":false},"author":47,"featured_media":29517,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[3005],"tags":[],"yst_prominent_words":[25243,25237,3565,20973,4965,25249,25245,23285,3477,7771,16235,5573,25251,5003,7787,25247,5439,3989,25241,25239],"acf":[],"_links":{"self":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/29513"}],"collection":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/users\/47"}],"replies":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/comments?post=29513"}],"version-history":[{"count":2,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/29513\/revisions"}],"predecessor-version":[{"id":29521,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/29513\/revisions\/29521"}],"wp:featuredmedia":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media\/29517"}],"wp:attachment":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media?parent=29513"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/categories?post=29513"},{"taxonomy":"post_tag","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/tags?post=29513"},{"taxonomy":"yst_prominent_words","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/yst_prominent_words?post=29513"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}