In the Shadow of WannaCry, Jaff Ransomware Arrives Using Familiar Phishing Techniques
May 16, 2017 by Cofense in Malware AnalysisPhishingRansomwareAdding another entry to the ever-growing list of encryption ransomware, the Jaff Ransomware made its debut onto the threat landscape with large sets of phishing emails on May 11, 2017 – one day before the sensational impact of the WannaCry ransomware attack. However, the risks posed by the Jaff ransomware should not be overlooked. This, too, is a robust ransomware that leverages some of the most prolifically-used delivery mechanisms in phishing email and embodies characteristics associated with other very successful malware.
What You Can Do About the WCry (WannaCry) Ransomware
May 15, 2017 by Cofense in Internet Security AwarenessCyber Incident ResponseMalware AnalysisAs most of you are aware, a fast moving, self-propagating attack blew across the internet over the weekend, and it’s not over yet. Using an alleged NSA exploit , this malware is able to quickly traverse a network and deliver a ransomware payload affecting hundreds of countries and hundreds of thousands of users.
WCry / WannaCry Ransomware Devastates Across the Globe
May 12, 2017 by Cofense in Malware AnalysisInternet Security AwarenessPhishingA strain of encryption malware, or ransomware, is making a global presence today as numerous organizations struggle to respond. Reports of infections were found all over the globe.
Aaron Higbee Chats Google Doc Scam and other Phishing Trends on the Charles Tendell Show
May 11, 2017 by Cofense in PhishingInternet Security AwarenessThis week, our co-founder and Chief Technology Officer Aaron Higbee had an opportunity to discuss the recent Google Docs phishing scam on the The Charles Tendell Show.
FireEye: Russians, Others Exploiting Zero-day Microsoft Office Vulnerabilities
May 9, 2017 by Cofense in PhishingFireEye has identified three new zero-day vulnerabilities in Microsoft Office products that have been exploited by Russian cyber espionage entities and a yet-to-be-identified group.
Bogus Claim: Google Doc Phishing Worm Student Project
May 5, 2017 by Aaron Higbee in PhishingInternet Security AwarenessMalware AnalysisAccording to internet sources, Eugene Pupov is not a student at Coventry University. Since the campaign’s recent widespread launch, security experts and internet sleuths have been scouring the internet to discover the actor responsible for yesterday’s “Google Doc” phishing worm. As parties continued their investigations into the phishing scam, the name “Eugene Popov” has consistently popped up across various blogs that may be tied to this campaign. A blog post published yesterday by endpoint security vendor Sophos featured an interesting screenshot containing a string of tweets from the @EugenePupov Twitter handle claiming the Google Docs phishing campaign was not a...
Google Doc Phishing Attack Hits Fast and Hard
May 3, 2017 by Cofense in PhishingPhishing Defense CenterGoogle Doc Campaign Makes a Mark In the process of managing phishing threats for our customers, our Phishing Defense Center and PhishMe Intelligence teams saw a flood of suspicious emails with subject line stating that someone has “has shared a document on Google Docs with you”, which contained a link to “Open in Docs”. The “Open in Docs” link goes to one of several URLs all within the https://accounts.google.com website.
April Sees Spikes in Geodo Botnet Trojan
May 2, 2017 by Cofense in PhishingPhishing Defense CenterThroughout April, our Phishing Defense Team observed an increase in malicious URLs that deliver the financial crimes and botnet trojan known as Geodo. These emails take a simple approach to social engineering, using just a sentence or two prompting the victim to click on a link to see a report or invoice that has been sent to them. An example of a typical phishing email used in these attacks is shown below: Following the malicious links will lead the victim to download a hostile JavaScript application or PDF document tasked with obtaining and executing Geodo malware. One common attribute of...
Orange is the New Hack?
May 1, 2017 by Cofense in PhishingInternet Security AwarenessOne of the most popular Netflix series, Orange is the New Black, scored an early parole due to some bad behavior this weekend. TheDarkOverload, the group claiming responsibility for the hack, already released the season five premier and is threatening to release “a trove of unreleased TV shows and movies.”