{"id":12129,"date":"2024-03-30T07:00:00","date_gmt":"2024-03-30T05:00:00","guid":{"rendered":"https:\/\/forklog.com\/en\/cybersecurity-threats-gamers-bitcoins-at-risk-and-facebooks-surveillance-tactics\/"},"modified":"2024-03-30T07:00:00","modified_gmt":"2024-03-30T05:00:00","slug":"cybersecurity-threats-gamers-bitcoins-at-risk-and-facebooks-surveillance-tactics","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/cybersecurity-threats-gamers-bitcoins-at-risk-and-facebooks-surveillance-tactics\/","title":{"rendered":"Cybersecurity Threats: Gamers&#8217; Bitcoins at Risk and Facebook&#8217;s Surveillance Tactics"},"content":{"rendered":"<p>We have compiled the most significant cybersecurity news of the week.<\/p>\n<div class=\"wp-block-text-wrappers-keypoints article_keypoints\">\n<ul class=\"wp-block-list\">\n<li>Call of Duty players warned about malware stealing crypto wallets.<\/li>\n<li>Facebook spied on YouTube, Amazon, and Snapchat users.<\/li>\n<li>Phishing kit creators earned over $250,000 in bitcoins.<\/li>\n<li>Telegram users in Russia, Ukraine, and Belarus to restrict incoming messages.<\/li>\n<\/ul>\n<\/div>\n<h2 class=\"wp-block-heading\"><strong>Call of Duty Players Warned About Malware Stealing Crypto Wallets and Passwords<\/strong><\/h2>\n<p>Video game developer Activision is investigating a hacking campaign aimed at stealing user credentials, reports <a href=\"https:\/\/techcrunch.com\/2024\/03\/28\/activision-says-its-investigating-password-stealing-malware-targeting-game-players\/\">TechCrunch<\/a>.<\/p>\n<p>Hackers are reportedly uploading malware onto victims&#8217; computers, stealing passwords to their gaming accounts and cryptocurrency wallets.<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh7-eu.googleusercontent.com\/FfRQ3d56v8T_a9HX87qufmbCzMATMX5ZIa0vGKISsiZy5cmpM82pkksGB2XeVgXH8IEXU6LPycCo6UE86p63aTBAGTwjIlg9rW6JGpakvArtRvgzqe0m22IuvdfeUTWUNxBpGAwN0qGScWhon4Q-I3Y\" alt=\"Gamers' Bitcoins at Risk, Facebook Spied on YouTube, and Other Cybersecurity Events\"\/><figcaption class=\"wp-element-caption\">Data: Activision.<\/figcaption><\/figure>\n<p>According to an Activision representative, only players using unauthorized software (cheats) were compromised. The company&#8217;s servers remain secure, he asserts.<\/p>\n<p>Users suspecting a breach are advised to change their passwords and enable two-factor authentication.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Facebook Spied on YouTube, Amazon, and Snapchat Users<\/strong><\/h2>\n<p>Since 2016, Meta launched a secret project to gather analytics on Facebook&#8217;s competitors by intercepting and decrypting user traffic in third-party mobile apps, reports <a href=\"https:\/\/techcrunch.com\/2024\/03\/26\/facebook-secret-project-snooped-snapchat-user-traffic\/?guccounter=1\">TechCrunch<\/a> citing court documents.<\/p>\n<p>Initially named <a href=\"https:\/\/www.documentcloud.org\/documents\/24520332-merged-fb\">\u201cGhostbusters\u201d<\/a>, the project targeted Snapchat, later expanding to YouTube and Amazon.<\/p>\n<p>Tracking was conducted using Onavo VPN, owned by the corporation, marketed as a private network access service. In reality, tens of millions who installed it allowed Facebook to spy on competitors, bypassing their encryption.<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh7-eu.googleusercontent.com\/Si07Iijy-7idhhZvFq2CRv2B4EZmQ3FEo0a9IREgFkQ0A2PF5ZfDxeLpp7p7hz0a0pCoEmA17ndzccK-JFK2qAtqAWZwMXkSTJQLfwdsQkyX4Lb7QwHmZut66xpHqWxbvBryj5GFEYWNBv0YKpT6E40\" alt=\"Gamers' Bitcoins at Risk, Facebook Spied on YouTube, and Other Cybersecurity Events\"\/><figcaption class=\"wp-element-caption\">Mark Zuckerberg&#8217;s letter to Facebook employees from June 2016 asking how to bypass Snapchat encryption. Data: court documents.<\/figcaption><\/figure>\n<p>This gave the social network access not only to the volume of traffic and actions within third-party apps but also to user names and passwords.<\/p>\n<p>The disclosed documents are part of a class-action lawsuit against Facebook filed in 2020, accusing the company of deceitfully extracting data and using it for unfair competition.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Google&#8217;s AI Algorithms Begin Promoting Scams<\/strong><\/h2>\n<p>Google&#8217;s new AI-based algorithms are offering fraudulent sites in search results, noted SEO consultant Lily Ray.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">OH GOOD. <\/p>\n<p>SGE WILL EVEN RECOMMEND THE SPAM SITES AS PART OF THE ANSWER. <a href=\"https:\/\/t.co\/wqgFFXqbMB\">pic.twitter.com\/wqgFFXqbMB<\/a><\/p>\n<p>\u2014 Lily Ray ? (@lilyraynyc) <a href=\"https:\/\/twitter.com\/lilyraynyc\/status\/1771217301863289140?ref_src=twsrc%5Etfw\">March 22, 2024<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>The Search Generative Experience feature provides brief summaries for search queries, including recommendations of other relevant sites. However, the AI algorithm&#8217;s suggested links lead to unwanted Chrome extensions, fake iPhone giveaways, browser spam subscriptions, and tech support scams.<\/p>\n<p>Similar site templates suggest they were indexed through search poisoning, speculates <a href=\"https:\/\/www.bleepingcomputer.com\/news\/google\/googles-new-ai-search-results-promotes-sites-pushing-malware-scams\/\">Bleeping Computer<\/a>.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Phishing Kit Creators Earn Over $250,000 in Bitcoins<\/strong><\/h2>\n<p>In recent months, the phishing <span data-descr=\"Adversary-in-The-Middle \u2014 a type of man-in-the-middle attack.\" class=\"old_tooltip\">AiTM<\/span> kit Tycoon 2FA has gained popularity among cybercriminals, report <a href=\"https:\/\/blog.sekoia.io\/tycoon-2fa-an-in-depth-analysis-of-the-latest-version-of-the-aitm-phishing-kit\/\">Sekoia analysts<\/a>.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">We just released an analysis of the latest version of Tycoon 2FA Phishing-as-a-Service (<a href=\"https:\/\/twitter.com\/hashtag\/PhaaS?src=hash&#038;ref_src=twsrc%5Etfw\">#PhaaS<\/a>), uncovered by the Sekoia TDR team in October 2023.<a href=\"https:\/\/twitter.com\/hashtag\/Tycoon?src=hash&#038;ref_src=twsrc%5Etfw\">#Tycoon<\/a> 2FA remains one of the most prevalent Adversary-in-The-Middle (<a href=\"https:\/\/twitter.com\/hashtag\/AiTM?src=hash&#038;ref_src=twsrc%5Etfw\">#AiTM<\/a>) <a href=\"https:\/\/twitter.com\/hashtag\/phishing?src=hash&#038;ref_src=twsrc%5Etfw\">#phishing<\/a> kits in early 2024.<a href=\"https:\/\/t.co\/TC5Ly7hC6h\">https:\/\/t.co\/TC5Ly7hC6h<\/a><\/p>\n<p>\u2014 Sekoia.io (@sekoia_io) <a href=\"https:\/\/twitter.com\/sekoia_io\/status\/1772207799658758170?ref_src=twsrc%5Etfw\">March 25, 2024<\/a><\/p><\/blockquote>\n<p> <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>The new version of the service has received significant feature expansions and improved obfuscation. It currently uses 1100 domains and has been observed in thousands of phishing attacks.<\/p>\n<p>Cybercriminals intercept victims&#8217; input data, pass it to a legitimate service, and then send a request for multi-factor authentication. Once all session cookies are in the hackers&#8217; hands, they can act on behalf of the user.<\/p>\n<p>The service is most often used to attack Microsoft 365 and Gmail accounts. Prices for Tycoon 2FA range from $120 to $320.<\/p>\n<p>Since the kit&#8217;s creation in August 2023 until March 12, 2024, the <a href=\"https:\/\/blockexplorer.one\/bitcoin\/mainnet\/address\/19NReVFKJsYYCCFLq1uNKYrUqQE2bB4Jwx\">attackers&#8217; bitcoin wallet<\/a> processed about 700 incoming transactions totaling over $250,000.<\/p>\n<h2 class=\"wp-block-heading\"><strong>US Sanctions State-Sponsored Chinese Hackers<\/strong><\/h2>\n<p>The <span data-descr=\"Office of Foreign Assets Control of the US Treasury Department\" class=\"old_tooltip\">OFAC<\/span> <a href=\"https:\/\/home.treasury.gov\/news\/press-releases\/jy2205\">added to the sanctions list<\/a> the Wuhan-based company Wuhan XRZ, used by China&#8217;s Ministry of State Security as a front for attacks on US critical infrastructure.<\/p>\n<p>Also included are two Chinese nationals, Zhao Guangzong and Ni Gaobin, linked to the Chinese government-backed hacker group APT31. They are accused of a 2020 phishing operation against the US Naval Academy and the China Maritime Studies Institute at the US Naval War College.<\/p>\n<p>Similar sanctions have been imposed by the UK authorities.<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh7-eu.googleusercontent.com\/fXCR8HDYaWT2jnFGXujGlXEFO8ctmSNKBYR2Y41lAGjX0Q6qYJTeBvFuxbAoamxLXcnBiRsRF1vtSWxpG9R2BWpRxh1_u_ZEg-4r0gcOPorBW6LMBmbv_9zATOFUbcisHTR_ySmfRDWze_p8ms5wG20\" alt=\"Gamers' Bitcoins at Risk, Facebook Spied on YouTube, and Other Cybersecurity Events\"\/><figcaption class=\"wp-element-caption\">Data: US State Department.<\/figcaption><\/figure>\n<p>Additionally, the US Department of Justice has charged Guangzong, Gaobin, and five other individuals (pictured) with conducting malicious cyberattacks for at least 14 years on behalf of China&#8217;s foreign intelligence.<\/p>\n<p>The US State Department offers a reward of up to $10 million for information on APT31 or its members.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Telegram Users in Russia, Ukraine, and Belarus to Restrict Incoming Messages<\/strong><\/h2>\n<p>Starting April 1, Telegram users in Russia, Ukraine, and Belarus will be able to limit who can send them private messages, announced the messenger&#8217;s founder <a href=\"https:\/\/t.me\/durov_russia\/52\">Pavel Durov<\/a>.<\/p>\n<p>The decision follows numerous complaints from Russian-speaking users about messages from strangers inciting terrorism.<\/p>\n<p>Telegram will also implement an AI-based solution for more effective spam filtering.<\/p>\n<p>Deputy Chairman of the Russian State Duma&#8217;s Information Policy Committee Anton Gorelkin suggested to <a href=\"https:\/\/t.me\/bloodysx\/35033\">Ostorozhno Media<\/a> that Durov create a mechanism to automatically monitor and block conversations in private chats and channels.<\/p>\n<p>Also on ForkLog:<\/p>\n<ul class=\"wp-block-list\">\n<li>Searches conducted in Moscow offices of bitcoin exchanges Beribit and ABCeX.<\/li>\n<li>Fake ENA, Prisma fund movements, and industry losses of $336 million.<\/li>\n<li>TRM confirmed Tron&#8217;s dominance in the criminal crypto economy.<\/li>\n<li>Experts identified an attack on the DeFi protocol Prisma, estimating damages at $11 million.<\/li>\n<li>Bloomberg learned of US and UK investigations into Garantex.<\/li>\n<li>Sber explained the procedure for unfreezing a card after cryptocurrency transactions.<\/li>\n<li>Hackers stole $380,000 in bitcoins from the founder of Ordinal Rugs.<\/li>\n<li>Web3 project Munchables recovered $97 million lost in a hack.<\/li>\n<li>The US accused bitcoin exchange KuCoin of laundering $9 billion.<\/li>\n<li>Portuguese authorities ordered Worldcoin to stop collecting biometric data.<\/li>\n<li>Binance joined a platform to comply with FATF requirements.<\/li>\n<li>GitHub users fell victim to malware stealing bitcoin wallets.<\/li>\n<li>CommEX announced a gradual suspension of operations, Binance accused it of breaching a deal. ForkLog analyzed the situation.<\/li>\n<li>The US imposed sanctions on the Atomyze and Bitpapa platforms.<\/li>\n<li>A hacker released 1 billion CGT tokens in the Curio ecosystem.<\/li>\n<li>Fraudsters stole millions from BlockFi and FTX creditors.<\/li>\n<li>Ripple team warned of a failure in AMM pools.<\/li>\n<li>Polygon zkEVM resumed operations after a failure.<\/li>\n<li>ParaSwap will return funds to users after discovering a vulnerability.<\/li>\n<li>European Parliament committees approved a ban on anonymous crypto transactions.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\"><strong>Weekend Reading Suggestions<\/strong><\/h2>\n<p>We discuss what information cryptocurrency exchanges and exchangers will need to share about clients according to the new <span data-descr=\"Financial Action Task Force\" class=\"old_tooltip\">FATF<\/span> guidelines.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We have compiled the most significant cybersecurity news of the week. Call of Duty players warned about malware stealing crypto wallets. Facebook spied on YouTube, Amazon, and Snapchat users. Phishing kit creators earned over $250,000 in bitcoins. Telegram users in Russia, Ukraine, and Belarus to restrict incoming messages. Call of Duty Players Warned About Malware [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"","news_style_id":"","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1238,1233],"class_list":["post-12129","post","type-post","status-publish","format-standard","hentry","category-news-and-analysis","tag-cybersecurity-digest","tag-industry-digests"],"aioseo_notices":[],"amp_enabled":true,"views":"16","promo_type":"","layout_type":"","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/12129","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=12129"}],"version-history":[{"count":0,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/12129\/revisions"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=12129"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=12129"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=12129"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}