Rewterz Threat Advisory – CVE-2018-0732 – F5 Multiple Products OpenSSL Denial of Service Vulnerability
December 28, 2018Rewterz Threat Alert – Compromised Email account used for targeting financial organizations
January 1, 2019Rewterz Threat Advisory – CVE-2018-0732 – F5 Multiple Products OpenSSL Denial of Service Vulnerability
December 28, 2018Rewterz Threat Alert – Compromised Email account used for targeting financial organizations
January 1, 2019SEVERITY: Medium
CATEGORY: Informative updates
ANALYSIS SUMMARY
An old tactic of scareware messages (message hoaxing) has resurfaced, targeting employees from different sectors. The campaign spreads via emails claiming that the attackers have got passwords of the victims’ social media accounts. The attackers use the fear factor to get a BitCoin payment while threatening with consequences that spoil reputation. This is an old tactic which has been going on for a while in different parts of the world and now it has emerged in Pakistan.
Targets fall victim to these emails due to the subject used, i.e. usernames and password. Hackers are using real time data (i.e passwords) to blackmail the targets. The emails looks like this:
The email contains a bitcoin address and tolerates zero negotiation, discouraging any risk-taking. Therefore most victims will be blackmailed into making the payment, as the hoax offers no flexibility.
REMEDIATION
- Do not respond to this email.
- Change your password if this seems to be correct. (it is likely that the sender of this email got your password from the leak on the dark web).
- Check your computer for Firewall and RDP of what ports are open to the world.
- Make sure you’re running the latest version of Anti Virus that blocks malicious software and other threats.