{"id":19064,"date":"2024-11-30T07:00:00","date_gmt":"2024-11-30T05:00:00","guid":{"rendered":"https:\/\/forklog.com\/en\/phishing-from-a-van-wazawaka-arrested-and-other-cybersecurity-events\/"},"modified":"2024-11-30T07:00:00","modified_gmt":"2024-11-30T05:00:00","slug":"phishing-from-a-van-wazawaka-arrested-and-other-cybersecurity-events","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/phishing-from-a-van-wazawaka-arrested-and-other-cybersecurity-events\/","title":{"rendered":"Phishing from a Van, Wazawaka Arrested, and Other Cybersecurity Events"},"content":{"rendered":"<p>We have compiled the most important cybersecurity news of the week.<\/p>\n<div class=\"wp-block-text-wrappers-keypoints article_keypoints\">\n<ul class=\"wp-block-list\">\n<li>A hacker linked to LockBit was arrested in Kaliningrad.<\/li>\n<li>A van with an SMS blaster for phishing was found in Bangkok.<\/li>\n<li>Media reports on a cyber-espionage investigation involving an Exxon Mobil consultant.<\/li>\n<\/ul>\n<\/div>\n<h2 class=\"wp-block-heading\"><strong>Hacker Linked to LockBit Arrested in Kaliningrad<\/strong><\/h2>\n<p>Russian national Mikhail Matveev was arrested in Kaliningrad on charges of developing the Babuk virus and distributing several ransomware programs, including LockBit and Hive, as <a href=\"https:\/\/epp.genproc.gov.ru\/web\/proc_39\/mass-media\/news?item=99391533\">reported<\/a> by the local prosecutor&#8217;s office.\u00a0<\/p>\n<p>Matveev, known by aliases Wazawaka, Uhodiransomwar, m1x, and Boriselcin, encrypted files on victims&#8217; computers during cyberattacks and demanded cryptocurrency.<\/p>\n<p>The criminal case has been sent to the Central District Court of Kaliningrad.<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh7-qw.googleusercontent.com\/docsz\/AD_4nXfgkTF-8I4HP-EiF4ckcmRt_I9yRnD4Z_Xqnz3oZUmZvH0wZVPUi_R9aNnFvB7Gc1Q9LISiTQyXTFkoSFjiSVaFZxBtWhFS_VTuGsLVhK8nrFXgHthpnxMFrZ9LHNHw1KIIISkUhw?key=rLTUxCTeaUs6qAhI-kyJt3G8\" alt=\"Phishing from a Van, Wazawaka Arrested, and Other Cybersecurity Events\"\/><figcaption class=\"wp-element-caption\">Source: <a href=\"https:\/\/www.fbi.gov\/wanted\/cyber\/mikhail-pavlovich-matveev\/@@download.pdf\">FBI<\/a>.<\/figcaption><\/figure>\n<p>The Russian is under US sanctions, where he previously faced similar <a href=\"https:\/\/www.justice.gov\/opa\/pr\/russian-national-charged-ransomware-attacks-against-critical-infrastructure\">charges<\/a>. Authorities estimated the total damage from the ransomware programs he managed at $200 million.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Van with SMS Blaster for Phishing Found in Bangkok<\/strong><\/h2>\n<p>Thai police discovered a van equipped with an SMS blaster used for phishing Bangkok residents. The device had a range of about three kilometers and could send up to 100,000 messages per hour, according to local media <a href=\"http:\/\/www.khaosodenglish.com\/news\/2024\/11\/18\/chinese-cybercrime-bust-in-thailand-over-700-million-calls-using-fake-02-numbers\/\">reports<\/a>.<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh7-qw.googleusercontent.com\/docsz\/AD_4nXfEoeMGc_MwG8SQqvAu2fkYIPYCbZe-6Apsc5V3VHr5HtK4gmT7ipKpqrd_6d41YSuAaNRM90DoNnzZESIlj-37bfW1MRMTM_uYrsvw4EMfDpxFdeT_UgHbBtKFOj2zkiYXZ6jHvQ?key=rLTUxCTeaUs6qAhI-kyJt3G8\" alt=\"SMS blaster in the back of a van in Bangkok\"\/><figcaption class=\"wp-element-caption\">Source: Khaosod English.<\/figcaption><\/figure>\n<p>In three days, nearly a million text messages were sent to mobile phones within the device&#8217;s range. All messages claimed to offer gift points from a major Thai telecom operator, Advanced Info Service, and contained a link to a phishing site.\u00a0\u00a0<\/p>\n<p>Upon visiting the site, users were asked for credit card details, which the perpetrators used to withdraw funds in other countries. The group coordinated their activities through private Telegram channels.\u00a0<\/p>\n<p>The 35-year-old van driver was arrested. Police are searching for at least two accomplices.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Major Disruption in Russia Due to Yandex Cloud Issues<\/strong><\/h2>\n<p>On November 29, after 4:00 PM MSK, residents of Russia experienced disruptions in banking services, delivery services, and telecom operators, according to <a href=\"https:\/\/downdetector.su\/\">DownDetector<\/a>.<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh7-qw.googleusercontent.com\/docsz\/AD_4nXcmQIo9bmLnyr1BY2r4UlrjhsSyhgpJsI0QeT9SN0oirdEyQsbcvtVKkRo89AV4YUWB1jak5H3acz42r6AEwbK8qlnspcJ28cJwB5_z3i-GNNrSgIcPeNvevW22IjEj23JBHxJN?key=rLTUxCTeaUs6qAhI-kyJt3G8\" alt=\"Phishing from a Van, Wazawaka Arrested, and Other Cybersecurity Events\"\/><figcaption class=\"wp-element-caption\">Source: DownDetector.<\/figcaption><\/figure>\n<p>The cause was network connectivity issues in Yandex Cloud, as the company&#8217;s press service informed <a href=\"https:\/\/www.kommersant.ru\/doc\/7343318?from=top_main_2\">Kommersant<\/a>. The technical team is working to resolve the problem.<\/p>\n<p>Meanwhile, Aeroflot <a href=\"https:\/\/t.me\/aeroflot_official\/2042\">warned<\/a> of difficulties in booking and refunding tickets due to a global failure in the Leonardo reservation system.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Media Reports on Cyber-Espionage Investigation Involving Exxon Mobil Consultant<\/strong><\/h2>\n<p>The FBI is investigating a long-time consultant of Exxon Mobil for his alleged involvement in hacking and data leaks affecting hundreds of the oil company&#8217;s critics, according to <a href=\"https:\/\/www.reuters.com\/business\/energy\/exxon-lobbyist-investigated-over-hack-and-leak-environmentalist-emails-sources-2024-11-27\/\">Reuters<\/a>, citing informed sources.<\/p>\n<p>According to them, since late 2015, the PR firm DCI Group, then working for Exxon, hired an Israeli private investigator to conduct cyberattacks against environmental community representatives and activists.\u00a0<\/p>\n<p>Hired hackers participated in the operation, with victims including Greenpeace, the Union of Concerned Scientists, the Rockefeller Family Fund, and former Democratic presidential candidate and environmental billionaire Tom Steyer.<\/p>\n<p>Several eco-activists told the publication that the hacks disrupted the preparation of city and state attorneys general for lawsuits against Exxon and other energy companies.\u00a0<\/p>\n<p>Representatives of the oil giant stated that the firm &#8220;was not involved and was unaware of any hacking activities,&#8221; calling the allegations &#8220;conspiracy theories.&#8221; It is unknown whether Exxon itself is under investigation \u2014 the case is classified.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Australia Bans Social Media for Children Under 16<\/strong><\/h2>\n<p>The Australian Senate has passed a law banning children under 16 from using social media. It has already been approved by the House of Representatives, reports <a href=\"https:\/\/www.reuters.com\/technology\/australia-passes-social-media-ban-children-under-16-2024-11-28\/\">Reuters<\/a>.\u00a0<\/p>\n<p>The document forces Instagram, X, TikTok, Snapchat, and others to restrict minors&#8217; access to their systems. The fine for violations is up to 49.5 million <span data-descr=\"Australian dollar \" class=\"old_tooltip\">AUD<\/span> ($32 million).\u00a0<\/p>\n<p>The country&#8217;s authorities plan to test an age verification system with biometric identification. The law will come into effect in November 2025.<\/p>\n<p>Tech giants opposed the strict regulation. Alphabet and Meta suggested delaying the ban, <span data-descr=\"owner of TikTok \" class=\"old_tooltip\">Bytedance<\/span> pointed out the need to refine the law, and X saw the initiative as infringing on children&#8217;s rights.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Cybercriminal Crackdown in Africa<\/strong><\/h2>\n<p>Law enforcement agencies in 19 African countries arrested 1,006 suspects involved in cybercriminal activities with a total damage of about $193 million, as <a href=\"http:\/\/www.interpol.int\/en\/News-and-Events\/News\/2024\/Major-cybercrime-operation-nets-1-006-suspects\">reported<\/a> by Europol.<\/p>\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/lh7-qw.googleusercontent.com\/docsz\/AD_4nXd0X9HqNSlbwuD4xRCtsuo-s4IaN9_GaPueDCobjlWqarDrVvRIxLeIbcVi5aJBQNRfQE8QWaNaYu2gQ7xfqF4ekzaZedRp33iJWBKyYXbODghUpE9bUu5Br3IAGkfPxx7jyk-z?key=rLTUxCTeaUs6qAhI-kyJt3G8\" alt=\"Phishing from a Van, Wazawaka Arrested, and Other Cybersecurity Events\"\/><figcaption class=\"wp-element-caption\">Source: Europol.<\/figcaption><\/figure>\n<p>The detainees managed ransomware programs, hacked corporate emails, offered fake cryptocurrency investment services, engaged in extortion, and online fraud.\u00a0<\/p>\n<p>Police dismantled 134,089 malicious infrastructures and identified 35,224 victims of the perpetrators. About $44 million of the total damage was recovered.\u00a0<\/p>\n<h2 class=\"wp-block-heading\"><strong>Russia Maintains Lead as Most Hacked Country<\/strong><\/h2>\n<p>Since 2022, Russia remains the most targeted country by hackers worldwide, according to <a href=\"https:\/\/iz.ru\/1795235\/valentina-averanova\/cifrovoe-oruzie-rossia-stala-samoi-atakuemoi-hakerami-stranoi-v-mire\">Izvestia<\/a>, citing experts from Kaspersky Lab.<\/p>\n<p>Private businesses and government structures are under attack. Most often, industrial enterprises, telecom, construction companies, and the IT sector are targeted by perpetrators.<\/p>\n<p>According to Positive Technologies, 220 successful attacks were conducted on Russian organizations in 2022. In 2023, the number decreased to 167. In incomplete 2024, 217 cyber incidents were recorded.<\/p>\n<p>The Solar 4RAYS center team found that this year, 54% of attacks aimed at espionage, 20% involved direct extortion (including data encryption) and cryptocurrency mining. Another 11% of cases were related to the destruction of the attacked company&#8217;s data.<\/p>\n<p>Also on ForkLog:<\/p>\n<ul class=\"wp-block-list\">\n<li>Damage from the DEXX hack increased to $30 million.<\/li>\n<li>Analysts named leading countries in crypto project failures and scams.<\/li>\n<li>XT exchange was hacked \u2014 $1.7 million stolen.<\/li>\n<li>Gifto rejected ZachXBT&#8217;s accusations of issuing 1.2 billion coins.<\/li>\n<li>A YouTuber was caught in a $3.5 million meme coin scam.<\/li>\n<li>Media learned of possible escape of OneCoin creator Ruja Ignatova to Russia.<\/li>\n<li>Pump Science reported a wallet hack and fake tokens.<\/li>\n<li>Sanctions against Tornado Cash deemed illegitimate, while the mixer developer&#8217;s detention was extended.<\/li>\n<li>An investment manager illegally invested $18.5 million of client funds in crypto lending.<\/li>\n<li>UTONIC and TonBit formed a security alliance for TON and Telegram.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\"><strong>What to Read Over the Weekend?<\/strong><\/h2>\n<p>We discuss with a lawyer why the desire for anonymity is not illegal.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We have compiled the most important cybersecurity news of the week. A hacker linked to LockBit was arrested in Kaliningrad. A van with an SMS blaster for phishing was found in Bangkok. Media reports on a cyber-espionage investigation involving an Exxon Mobil consultant. Hacker Linked to LockBit Arrested in Kaliningrad Russian national Mikhail Matveev was [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":19063,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"","news_style_id":"","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1238,1233],"class_list":["post-19064","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-cybersecurity-digest","tag-industry-digests"],"aioseo_notices":[],"amp_enabled":true,"views":"58","promo_type":"","layout_type":"","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/19064","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=19064"}],"version-history":[{"count":0,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/19064\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media\/19063"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=19064"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=19064"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=19064"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}