Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
LinkedIn Spear-Phishing Campaign Targets Job Hunters

https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg LinkedIn Spear-Phishing Campaign Targets Job HuntersPost Views: 60
style="display:block"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="8337846400"
data-ad-format="auto"
data-full-width-responsive="true">
Reading Time: 1 Minute A threat group called Golden Chickens is delivering the fileless backdoor more_eggs through a spear-phishing campaign targeting professionals on LinkedIn with fake job offers.A threat group called Golden Chickens is delivering the fileless backdoor more_eggs through a spear-phishing campaign targeting professionals on LinkedIn with fake job offers, according to researchers at eSentire.

The phishing emails try to trick a victim into clicking on a malicious .ZIP file by picking up the victim’s current job title and adding the word “position” at the end, making it appear like a legitimate offer.

“For example, if the LinkedIn member’s job is listed as ‘Senior Account Executive—International Freight,’ the malicious .ZIP file would be titled ‘Senior Account Executive—International Freight position’ (note the ‘position’ added to the end),” according to the report. “Upon opening the fake job offer, the victim unwittingly initiates the stealthy installation of the fileless backdoor, more_eggs.”

Once downloaded, more_eggs can fetch additional malware and provide access to the victim’s system, the report said. The Golden Chickens group is also selling more_eggs as malware-as-a-service to other cybercriminals, who use it to gain a foothold in victim’s systems to install other types of malware, including banking malware, credential stealers and ransomware, or just to exfiltrate data, eSentire reported.
See Also: Facebook data on 533 million users posted online More_Eggs Malware: A ‘Formidable Threat’Rob McLeod, eSentire’s Threat Response Unit director ,highlighted three specific aspects of the more_eggs trojan that make it what he described as a “formidable threat to business and business professionals.”

First, it abuses normal Windows processes to avoid antivirus protections. Second, McLeod pointed out the personalized spear phishing emails are effective in enticing victims to click on the fake job offer. What’s perhaps most pernicious is that the malware exploits job hunters desperate to find employment in the midst of a global pandemic and skyrocketing unemployment rates, he added.

While eSentire hasn’t been able to pinpoint the group behind more_eggs, researchers have observed the groups FIN6, Cobalt Group and Evilnum have each used the more_eggs malware as a service for their own purposes. More_Eggs Malware-As-A-ServiceThe financial threat gang FIN6 used the more_eggs malware to target various e-commerce companies back in 2019. At the same time, attackers used more_eggs to breach retail, entertainment and pharmaceutical companies’ online payments systems, which reSentire esearchers haven’t definitively linked to FIN6, but are suspected to be linked.

Other groups have used the malware too. Evilnum likes to attack financial tech companies, according to eSentire, to steal spreadsheets, customer lists and trading credentials, while Cobalt Group is usually focused on attacking financial companies with the more_eggs backdoor.

Rather than attack someone who is unemployed, experts agree that the goal of the campaign is likely to attack people who are employed and have access to sensitive data.
See Also: Offensive Security Tool: DirDar How to Avoid Being a LinkedIn VictimThe motivation for the attacks is unclear, researchers said.

“Not much t[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking LinkedIn Spear-Phishing Campaign Targets Job Hunters https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg LinkedIn Spear-Phishing Campaign Targets Job HuntersPost Views: 60 style…
o gain from an unemployed worker using their own personal device,” Chris Morales, Netenrich’s CIO, told Threatpost. “Other than perhaps intel on who they are talking to and hoping to infiltrate a future network. During the work-from-home state we are in, personal and organization devices coexist on the same network.”

In the report, eSentire follows the more_eggs LinkedIn attack on someone in the health care technology sector. Chris Hazelton with mobile security provider Lookout told Threatpost that the victim that said was likely chosen so that  cybercriminals could gain “access to an organization’s cloud infrastructure, with a potential goal of exfiltrating sensitive data related to intellectual property or even infrastructure-controlling medical devices. He added, “Connected devices, particularly medical devices, could be a treasure trove for cybercriminals.” See Also: Hacking Stories: When two young hackers played war games with PentagonMorales added that to avoid compromise, all users on LinkedIn should be on the lookout for spear-phishing scams.

“Targeting LinkedIn is not rocket science,” he added. “It is social media for the corporate world with a description of the key players in every industry. I assume that I am a target too and always look for that.”
Source: threatpost.com (Click Link)style="display:block"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="8337846400"
data-ad-format="auto"
data-full-width-responsive="true"> Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/pf9bzNs3hHRgAcgDQTPPa3-1200-80-90x90.jpg Facebook data on 533 million users posted online1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/NAS-Bug-90x90.jpg Legacy QNAP NAS Devices Vulnerable to Zero-Day Attack4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/iphone-privacy-90x90.jpg Apple, Google Both Track Mobile Telemetry Data, Despite Users Opting Out5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Monero-Mining-90x90.png Malicious Docker Cryptomining Images Rack Up 20M Downloads6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/phph-90x90.jpg PHP Infiltrated with Backdoor Malware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/ransomware_global_small-90x90.jpg Insurance Giant CNA Hit with Novel Ransomware Attack1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/Microsoft-Teams-90x90.jpg Microsoft Offers Up To $30K For Teams Bugs2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/thrive-themes-1030x391-1-90x90.png Active Exploits Hit WordPress Sites Vulnerable to Thrive Themes Flaws2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/HL-color-90x90.jpg Hobby Lobby Exposes Customer Data in Cloud Misconfiguration2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/03/adobe_coldfusion-700x412-e1542041238507-90x90.jpg Adobe Fixes Critical ColdFusion Flaw in Emergency Update2 weeks ago
The post LinkedIn Spear-Phishing Campaign Targets Job Hunters first appeared on Black Hat Ethical Hacking.
hacking: security in practice
Hacking DS/3DS

Hi everyone! When I was in college I had a friend who was really good at information technology and hacking and stuff and he was able to hack my Pokémon Heart Gold game for the Nintendo DS to get me Mew and Celebi since they were then unobtainable (events expired and game was no longer popular). I have since lost touch with my friend but wanted to play a new game while also being able to have Mew and Celebi as Pokémon but I have no idea how he managed to hack a portable gaming console (I have no experience with hacking) so I was wondering how I could go about it. Any ideas? I don’t know if this is important but I no longer have a DS, only a 3DS that I can play my DS game on

submitted by /u/fmdmlvr
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Facebook Leak? เกิดอะไรขึ้นและเราทำอะไรเพื่อป้องกันตัวได้บ้าง?

https://cdn-images-1.medium.com/max/600/1*6W2ZkZfI-YOHCRH--HDLlQ.jpeg
ปัญหาความเป็นส่วนตัว, การเก็บข้อมูลและการรักษาความลับดูจะเป็นปัญหาของเฟซบุ๊กมาทุกยุคทุกสมัย นับตั้งแต่ข้อมูลหลุดบ่อยครั้งในปี 2017-2018…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The Polkatrain hacking incident is a malicious attack by hacker using problem similar with…

According to the latest official news, Polkatrain team has identified and verified that the hacking incident is a malicious attack by…

Continue reading on Medium »
Burp Suite: Match And Replace

IntroductionContinue reading on Medium »
Read more...
hacking: security in practice
[Android Hacking] How does Lucky Patcher work? And how to manually patch apks?

I wanted to learn more about how LuckyPatcher patches apks and removes ads and in app purchases and how it does various other custom patches. I want to learn the procedure for manually patching apks. I couldn't find any useful resources online. Most places just teach you how to use LuckyPatcher.

submitted by /u/GamerWael
[link] [comments]
hacking: security in practice
How to get started?

My sister recently got scammed in an online game and I wish to get back at the scammer and to get her stuff back. How do I get started?

The game is Animal Jam and the accounts are not very secure.

submitted by /u/BorkiDoggo0w0
[link] [comments]