Following the arrest in 2018 of a number of suspected leaders of the notorious Fin7/Carbanak cyber-gang, the group was believed to have disbanded. But Kaspersky Lab researchers have detected a number of new attacks by the same groups using GRIFFON malware. According to the company’s experts, Fin7 might have extended the number of groups operating under its umbrella; increased the sophistication of its methods; and even positioned itself as a legitimate security vendor to recruit professional employees and dupe them into helping it steal financial assets.

 

Fin7 is believed to be behind attacks targeting the U.S. retail, restaurant, and hospitality sectors since mid-2015, working in close collaboration and sharing tools and methods with the infamous Carbanak group. While Carbanak focused primarily on banks, Fin7 targeted mostly businesses, potentially making off with millions of dollars in financial assets, such as payment card credentials or account information on the computers of financial departments. Once the threat actors got what they needed, they wired money to offshore accounts.

 

According to Kaspersky Lab’s new investigation, the group has continued its activity – despite the arrest last year of alleged group leaders – implementing sophisticated spear-phishing campaigns throughout 2018 and distributing malware to each target through specially tailored emails. In different cases, the operators exchanged messages with their intended victims over a period of weeks before finally sending the malicious documents as attachments. Kaspersky Lab estimates that by the end of 2018, more than 130 companies might have been targeted in this way.

 

The researchers also discovered other criminal teams operating under the Fin7 umbrella. The use of shared infrastructure and the same tactics, techniques and procedures (TTPs), shows that Fin7 is likely to be collaborating with the AveMaria botnet and groups known as CobaltGoblin/EmpireMonkey, believed to be behind bank robberies in Europe and Central America.

 

Kaspersky Lab also found that Fin7 has created a fake company that claims to be a legitimate cybersecurity vendor with offices across Russia. The company website is registered to the server that Fin7 uses as a Command and Control center (C&C). The fake business has been used to recruit unsuspecting freelance vulnerability researchers, program developers and interpreters through legitimate online job sites. It seems that some of the individuals working in these fake companies did not suspect that they were involved in a cybercrime business, with many including the experience of working in the organizations in their Cvs.

 

“Modern cyberthreats can be compared to the mythical creature Hydra of Lerna – you cut off one of its heads and it grows two new ones. Therefore, the best way to protect yourself from such actors is to implement advanced, multi-layered protection: install all software patches as soon as they are released and do regular security analysis across all networks, systems and devices,” said Yury Namestnikov, Security Researcher at Kaspersky Lab.

 

To reduce the risk of infection, users are advised to:

 

  • Use security solutions with dedicated functionality aimed at detecting and blocking phishing attempts. Businesses can protect their on-premise email systems with targeted applications inside the Kaspersky Endpoint Security for Business suite. Kaspersky Security for Microsoft Office 365 helps to protect the cloud-based mail service Exchange Online inside the Microsoft Office 365 suite.
  • Introduce security awareness training and teach practical skills. Programs such as Kaspersky Automated Security Awareness Platform will help to reinforce skills and conduct simulated phishing attacks.
  • Provide your security team with access to up to date threat intelligence data, to keep pace with the latest tactics and tools used by cybercriminals.

 

Read the full version of the report on
Securelist.com

 


RECOMMENDED ARTICLE FOR TECHWORLD


 
#DiscoverRealValue with realme Philippines’ New Smartphone this March
Techworld Date Posted: 1 March 2019 4:03 PM | 36 Views
Game-changer smartphone brand realme confirms bringing a new phone to the Philippine market third week of March. Similar to its predecessor the realme C1, the new phone is expected to make fans discover. See More
 
#DiscoverRealValue with realme Philippines’ New Smartphone this March
Techworld Date Posted: 4:03 PM | 36 Views
Game-changer smartphone brand realme confirms bringing a new phone to the Philippine market third week of March. Similar to its predecessor the realme C1, the new phone is expected to make fans discoverSee More

 
CES 2018: Kingston to Showcase Upcoming Mobile Lifestyle Products and More
Techworld Date Posted: 11 January 2018 10:00 AM | 358 Views
Kingston, a world leader in memory storage products and technology solutions, is set to share its latest and upcoming products at CES®.. See More
 
CES 2018: Kingston to Showcase Upcoming Mobile Lifestyle Products and More
Techworld Date Posted: 10:00 AM | 358 Views
Kingston, a world leader in memory storage products and technology solutions, is set to share its latest and upcoming products at CES®.See More

 
DJI Introduces Mavic 2 Pro and Mavic 2 Zoom: A New Era for Camera Drones
Techworld Date Posted: 21 September 2018 9:10 AM | 51 Views
DJI, the world’s leader in civilian drones and aerial imaging technology, has introduced a new era for camera drones with two additions to its iconic Mavic series: Mavic 2 Pro, the world’s first drone.... See More
 
DJI Introduces Mavic 2 Pro and Mavic 2 Zoom: A New Era for Camera Drones
Techworld Date Posted: 9:10 AM | 51 Views
DJI, the world’s leader in civilian drones and aerial imaging technology, has introduced a new era for camera drones with two additions to its iconic Mavic series: Mavic 2 Pro, the world’s first drone...See More

 
Lenovo Addresses Shifting Workspace Needs
Techworld Date Posted: 23 March 2018 1:11 PM | 68 Views
Lenovo (HKSE: 992) (ADR: LNVGY), the world’s leading PC manufacturer, launched its 8th-generation Lenovo ThinkPads and ThinkStations–specifically designed to provide enhanced agility and performance to support the ever-evolving workspace spurred by millennial workers.. See More
 
Lenovo Addresses Shifting Workspace Needs
Techworld Date Posted: 1:11 PM | 68 Views
Lenovo (HKSE: 992) (ADR: LNVGY), the world’s leading PC manufacturer, launched its 8th-generation Lenovo ThinkPads and ThinkStations–specifically designed to provide enhanced agility and performance to support the ever-evolving workspace spurred by millennial workers.See More

 
Longer, Expanding, Demanding: Botnet DDoS Attacks Highlighted in Kaspersky Lab Quarterly Report
Techworld Date Posted: 24 August 2017 11:42 AM | 370 Views
The second quarter of 2017 was proof that long-lasting DDoS attacks are back in business. The longest attack in the quarter was active for 277 hours (more than 11 days) - which is a.... See More
 
Longer, Expanding, Demanding: Botnet DDoS Attacks Highlighted in Kaspersky Lab Quarterly Report
Techworld Date Posted: 11:42 AM | 370 Views
The second quarter of 2017 was proof that long-lasting DDoS attacks are back in business. The longest attack in the quarter was active for 277 hours (more than 11 days) - which is a...See More

 
Technology and Security Leaders Unite at Tech Talk 2018
Techworld Date Posted: 26 November 2018 5:19 PM | 97 Views
The tech industry is evolving at an unprecedented pace and if people are not fully invested in keeping up with the latest developments, they might feel overwhelmed with the sheer amount of information available..... See More
 
Technology and Security Leaders Unite at Tech Talk 2018
Techworld Date Posted: 5:19 PM | 97 Views
The tech industry is evolving at an unprecedented pace and if people are not fully invested in keeping up with the latest developments, they might feel overwhelmed with the sheer amount of information available....See More

 
OpenSignal Cites Smart for Having the Country’s Fastest LTE Network
Techworld Date Posted: 17 April 2018 1:46 PM | 55 Views
Mobile analytics firm OpenSignal has recognized PLDT wireless unit Smart Communications, Inc. for having the country’s fastest LTE network, bestowing the company four citations including best in 4G LTE download speed; best in overall.... See More
 
OpenSignal Cites Smart for Having the Country’s Fastest LTE Network
Techworld Date Posted: 1:46 PM | 55 Views
Mobile analytics firm OpenSignal has recognized PLDT wireless unit Smart Communications, Inc. for having the country’s fastest LTE network, bestowing the company four citations including best in 4G LTE download speed; best in overall...See More

 
Ground Zero Esports Lounge: Bringing the Premier Gaming Experience to North Metro Manila
Techworld Date Posted: 2 October 2018 11:08 AM | 335 Views
Ground Zero Esports Lounge, located in Xentro Mall, Antipolo aims to be the one-stop-shop for the gamer looking for a high-end gaming experience with premier amenities.. See More
 
Ground Zero Esports Lounge: Bringing the Premier Gaming Experience to North Metro Manila
Techworld Date Posted: 11:08 AM | 335 Views
Ground Zero Esports Lounge, located in Xentro Mall, Antipolo aims to be the one-stop-shop for the gamer looking for a high-end gaming experience with premier amenities.See More

 
Tech4ED Named as Finalist in IDC Smart City Asia Pacific Awards (SCAPA) 2017
Techworld Date Posted: 20 June 2017 2:32 PM | 44 Views
MANILA – IDC Government Insights Asia Pacific announced today that Tech4ED has been chosen as one of the finalists in the annual IDC Smart City Asia Pacific Awards (SCAPA) 2017 under the category of.... See More
 
Tech4ED Named as Finalist in IDC Smart City Asia Pacific Awards (SCAPA) 2017
Techworld Date Posted: 2:32 PM | 44 Views
MANILA – IDC Government Insights Asia Pacific announced today that Tech4ED has been chosen as one of the finalists in the annual IDC Smart City Asia Pacific Awards (SCAPA) 2017 under the category of...See More

 
PLDT, Smart Kick Off ‘Road to Nationals’ Open eSports Tournament
Techworld Date Posted: 7 August 2018 4:39 PM | 49 Views
  Leading telco and digital services provider, PLDT Inc. and its wireless arm Smart Communications, Inc. have kicked off the Road to Nationals, a nationwide multi-game grassroots tournament in search of the best eSports.... See More
 
PLDT, Smart Kick Off ‘Road to Nationals’ Open eSports Tournament
Techworld Date Posted: 4:39 PM | 49 Views
  Leading telco and digital services provider, PLDT Inc. and its wireless arm Smart Communications, Inc. have kicked off the Road to Nationals, a nationwide multi-game grassroots tournament in search of the best eSports...See More


Power by

Download Free AZ | Free Wordpress Themes