BREAKING

Wednesday, November 30, 2022

Professional stealers: opportunistic scammers targeting users of Steam, Roblox, and Amazon in 111 countries


Wazzup Pilipinas!?




Group-IB, one of the global leaders in cybersecurity, has identified 34 Russian-speaking groups that are distributing info-stealing malware under the stealer-as-a-service model. The cybercriminals use mainly Racoon and Redlinestealers to obtain passwords for gaming accounts on Steam and Roblox, credentials for Amazon and PayPal, as well as users' payment records and crypto wallet credentials. 

In the first seven months of 2022, the gangs collectively infected over 890,000 user devices and stole over 50 mln passwords. All the identified groups orchestrate their attacks through Russian-language Telegram groups, although they mainly target users in the United States, Brazil, India, Germany, and Indonesia. In 2022, info-stealing malware has grown into one of the most serious digitalthreats.

Classiscam graduates

By tracking the evolution of the popular scam scheme Classiscam, Group-IB Digital Risk Protection analysts revealed how some "workers" (low-rank online scammers) started shifting to a more dangerous criminal scheme that involves distributing info stealers. Moreover, the illicit business of stealers, which is coordinated via Telegram groups, uses exactly the same operational model as Classiscam

An info stealer is a type of malware that collects credentials stored in browsers (including gaming accounts, email services, and social media), bank card details, and crypto wallet information from infected computers, and then sends all this data to the malware operator. After a successful attack, the scammers either obtain money themselves using the stolen data, or they sell the stolen information in the cybercriminal underground. According to Group-IB, stealers are one of the top threats to watch in the coming year. The threat actor responsible for the most recent attack on Uberpurchased the credentials compromised with the Racoon stealer.


 

According to the Group-IB Digital Risk Protection team, (part of the Unified Risk Platform), the mass Telegram groups and bots designed to distribute info stealers first appeared in early 2021. By investigating a number of accounts, Group-IB analysts were able to confirm that members of several scam groups that previously participated in the Classiscam scheme began using stealers. In 2021 and 2022, Group-IB experts identified 34 active groups on Telegram. On average, such info stealer distribution groups have around 200 active members.

The most popular stealer among the groups examined by Group-IB is RedLine, which is used by 23 out of 34 gangs. Racoon ranks second: 8 groups employ this tool. Custom stealers are used in 3 communities. Administrators usually give workers both RedLine and Racoon in exchange for a share of the stolen data or money. However, the malware in question is offered for rent on the dark web for $150-200 per month. Some groups use 3 stealers at the same time, while others have only one stealer in their arsenal.

Having switched from scamming users of classified websites to stealers, some threat actors reproduced not only the hierarchy and model of Classiscam, but also its technical capabilities. In particular, Telegram bots that generate malicious content, communication between members, and all their shady accounting. The tasks of workers, the scammers of the lower-ranks, have also changed — they must now drive traffic to bait scam websites impersonating well-known companies and convince victims to download malicious files. Cybercriminals embed links for downloading stealers into video reviews of popular games on YouTube, into mining software or NFT files on specialized forums and direct communication with NFT artists, and into lucky draws and lotteries on social media.

Telegram Stealers world tour

Group-IB estimates that between March 1 (when Group-IB started researching the scheme) and December 31, 2021 stealers operated via Telegram groups were able to compromise 538,000 devices. In the first 7 months of 2022, Telegram stealers were found to be almost twice more active infecting more than 890,000 devices in 111 countries.

The top 5 most often attacked countries in 2022 were the United States, Brazil, India, Germany, and Indonesia with 91,565, 86,043, 53,988, 40,750, and 35,345 infected devices respectively.

List of countries in Asia Pacific by the number of infected devices include India, Indonesia, Philippines, Vietnam and Singapore. In India for example, from March - December 2021, the operators of the stealers in question infected 19,249 devices. In the first seven months of 2022, the number grew to 53,988. Scammers were able to retrieve 4,547,020 passwords, 4,657 sets of payment records, and 4,428 sets of crypto wallet information such as credentials, seed phrases, etc.

Indonesia closely follows with a total of 35,345 infected devices and where scammers were able to retrieve 2,372,893 passwords. The Philippines recorded a total of 31, 745 infected devices and Vietnam with a total of 22,739 devices infected and scammers retrieving 2,032,278 passwords. Australia had 5,794 devices infected and 549,640 passwords retrieved by scammers. Singapore saw 2,179 devices infected, with 185,689 passwords retrieved.

According to the analysis of Telegram groups, for the last 10 months of 2021 cybercriminals collected 27,875,879 sets of passwords, 1,215,532,572 cookie files, 56,779 sets of payment records, and data from 35,791 crypto wallets. In the first 7 months of 2022, threat actors stole 50,352,518 passwords, 2,117,626,523 cookie files, details of 103,150 bank cards, and data from 113,204 crypto wallets. The underground market value of just the stolen logs and compromised card details is around $5.8 million, Group-IB experts estimate.

According to Group-IB, in 2021, threat actors worldwide most frequently collected PayPal account credentials (more than 25%) and Amazon credentials (more than 18%). In 2022, the most targeted services are the same, namely PayPal (more than 16%) and Amazon (more than 13%). However, over the course of the year, cases of stealing passwords for gaming services (Steam, EpicGames, Roblox) in the logs have increased almost five-fold.

"The influx of a huge number of workers into the popular scam Classiscam — which Group-IB's Unified Risk Platformidentified, at its peak, comprised over a thousand criminal groups and hundreds of thousands of fake websites — has led to criminals competing for resources and looking for new ways to make profits," says Ilia Rozhnov, head of Group-IB's Digital Risk Protection in the Asia Pacific. "The popularity of schemes involving stealers can be explained by the low entry barrier. Beginners do not need to have advanced technical knowledge as the process is fully automated and the worker's only task is to create a file with a stealer in the Telegram bot and drive traffic to it. For victims whose computers become infected with a stealer, however, the consequences can be disastrous."

To minimize potential risks, Group-IB Digital Risk Protection experts recommend that users refrain from downloading software from suspicious sources, use isolated virtual machines or alternative operating systems for installation, avoid saving passwords in browsers, and regularly clear browser cookies. To prevent digital risks and unwanted consequences, companies should take a proactive approach to their brand's digital security and use modern technologies for monitoring and response, such as Group-IB's Digital Risk Protection.

About Group-IB

Group-IB, with its headquarters in Singapore, is one of the leading solutions providers dedicated to detecting and preventing cyberattacks, identifying online fraud, investigating high-tech crimes, and protecting intellectual property. The company's Threat Intelligence and Research Centers are located in the Middle East (Dubai), Asia-Pacific (Singapore), and Europe (Amsterdam).

Group-IB's Unified Risk Platform is an ecosystem of solutions that understands each organization's threat profile and tailors defenses against them in real time from a single interface. The Unified Risk Platform provides complete coverage of the cyber response chain. Group-IB's products and services consolidated in Group-IB's Unified Risk Platform include Group-IB's Threat Intelligence, Managed XDR, Digital Risk Protection, Fraud Protection, Attack, Surface Management, Business Email Protection, Audit & Consulting, Education & Training, Digital Forensics & Incident Response, Managed Detection & Response, and Cyber Investigations. Group-IB's Threat Intelligence system has been named one of the best in its class by Gartner, Forrester, and IDC. Group-IB's Managed XDR, intended for proactively searching for and protecting against complex and previously unknown cyber threats, has been recognized as one of the market leaders in the Network Detection and Response category by KuppingerCole Analysts AG, the leading European analyst agency, while Group-IB itself has been recognized as a Product Leader and an Innovation Leader. Gartner has named Group-IB a Representative Vendor in Online Fraud Detection for its Fraud Protection. In addition, Group-IB was granted Frost & Sullivan's Innovation Excellence award for Digital Risk Protection (DRP), an Al-driven platform for identifying and mitigating digital risks and counteracting brand impersonation attacks, with the company's patented technologies at its core. Group-IB's technological leadership and R&D capabilities are built on the company's 19 years of hands-on experience in cybercrime investigations worldwide and over 70,000 hours of cybersecurity incident response accumulated in our leading DFIR Laboratory, High-Tech Crime Investigations Department, and round-the-clock CERT-GIB.

Group-IB is an active partner in global investigations led by international law enforcement organizations such as Europol and INTERPOL. Group-IB is also a member of the Europol European Cybercrime Centre's (EC3) Advisory Group on Internet Security, which was created to foster closer cooperation between Europol and its leading non-law enforcement partners.

Group-IB's experience in threat hunting and cyber intelligence has been fused into an ecosystem of highly sophisticated software and hardware solutions designed to monitor, identify, and prevent cyberattacks. Group-IB's mission is to protect its clients in cyberspace every day by creating and leveraging innovative solutions and services.


Pawstival 2022: Let's give Dogs a round of A-paws


Wazzup Pilipinas!?


It’s that time of year again! Christmas is coming to town and that means it’s time to start thinking about what gift to get your loved ones. But what about your furry friends? They’re part of the family too, so why not include them in the holiday fun?

The biggest and magical christmas bazaar in the country is back to give you more exciting treats and fun! The World Bazaar Festival is happening at World Trade Center Metro Manila from December 10 to 19, 2022! You and your pet will surely enjoy a day of live entertainment, delicious foods, and plenty of opportunities to socialize with other pet-lovers and fur parents. World Bazaar Festival is organized by Worldbex Services International and continues to be the longest charity bazaar in the country - for the benefit of ABS CBN Foundation Inc. So come and celebrate the holidays with your pets at the World Bazaar Festival! Here are some tips on how to make sure your pets will have a paw-sitively wonderful Christmas.

One way to include your pet in the holiday festivities is to get them a special Christmas gift. Woobie’s Pet Zone has it all for you! A new toy? A festive collar? Or even some yummy holiday treats! Whatever you give them, always make sure it is something that they will enjoy and is safe for their heart's content.

And there’s more! It’s time to let our fur friends shine the main stage as the World Bazaar Festival presents Woobie’s Pawstival, an adorable competition exclusively for pets. Watch as they strut their stuff and show off their unique fashion, beauty and talents! This event highlight will definitely make the best holiday card this year! A great way to show your friends and family how much your pet means to you.

The World Bazaar Festival wants nothing but the best for you! Celebrating the Christmas season wouldn’t be complete without our loving pets. Let them roam around and wag their beautiful tails along the halls of the Bazaar! And if you’re wondering what to bring with you during the long day of shopping with your fur baby, don’t worry we got you covered! Here is a checklist for a shop worry free day at the World Bazaar Festival:

1. Vaccination Card - present an original copy of your pet’s vaccination card upon

entry to the event halls

2. Your furry friends must be properly groomed/bathed prior admission to the

event

3. Furry Fashion - make sure their fashion forward clothing are ready for the

catwalk

4. Leash - Oops! It has to be matchy matchy with their OOTD’s

5. Pet toiletries - make sure your pets are wearing their nappies or diapers at all times

6. Own receptacle - proper disposal is a must!

7. Pocket money - be ready to do a sudden shopping spree for your fur baby

8. Stroller - just in case they feel like taking another long nap!

9. Fully Charged Mobile Phone - you wouldn’t want to miss out a moment with your cute pet

10. Most importantly - Be responsible of your own pet, do not leave them unattended at all times!

So what are you waiting for? Grab your leash and head on down to the World Bazaar Festival at World Trade Center Metro Manila from December 10 to 19, 2022! Spend a great day out with the whole family, including your furry friends. With plenty of gift ideas, food and entertainment to offer, it’s the perfect way to get into the holiday spirit – your pet is sure to thank you for it!

WORLD BAZAAR FESTIVAL is organized by Worldbex Services International.

Website: https://worldbazaarfestival.com/

Facebook: https://www.facebook.com/worldbazaarfestival

Instagram: https://instagram.com/worldbazaarfestival

Galing Pook Foundation Recognizes Outstanding Local Government Programs for 2022


Wazzup Pilipinas!?




Ten outstanding local governance programs were recognized in the 2022 Galing Pook Awards held at the Ceremonial Hall of Malacanang Palace last Tuesday, November 22, 2022.

Galing Pook Foundation with its co-presenters SM Prime Holdings Inc., and the DILG-Local Government Academy, and sponsors Cebu Pacific and Airspeed named local government units from Luzon, Visayas, and Mindanao that promote innovation and excellence.

President Ferdinand Marcos Jr. commended the Galing Pook Foundation for recognizing and incentivizing top performing LGUs. He stressed how strong collaboration between the public and private sector can lead to more meaningful and successful programs that truly benefit the Filipino people.

“The recognition that you give to cities and municipalities inspires them to accelerate their drive towards improvement and it encourages LGUs to adopt practices that make us paragons of excellence in public service. It is necessary for us to underscore the importance of strengthening partnerships between the government and private organizations, such as the Galing Pook Foundation, especially as we bring about meaningful progress in the country.”

Galing Pook Chairperson Mel Sarmiento expressed his gratitude to all the local executives and LGU teams that participated this year: “It’s truly inspiring to see the impact of the work that you do, and I’m sure you’ve brought value to many Filipinos all over the country. Our collaborations bring us closer to realizing our shared vision, na ang bawat pamilyang Pilipino, may simple pero kumportableng buhay.”

The winners of the 2022 Galing Pook Awards were: The Green Wall of Alcala (Alcala, Cagayan);

Advancing and Sustaining Good Governance and Community Actions towards Resiliency and Empowerment (Basilan Province); Bataan Public-Private Partnership Programs (Bataan Province);

Balik-Biñan Project: Tourism Development through Heritage Conservation (Biñan City, Laguna); From Black to Green: Fishponds, Eco-Tourism and Full Employment (Brgy. Cayabu, Tanay, Rizal);

Trekking to Unlock Community Ailments and Difficulties (TUCAD) (Goa, Camarines Sur); “I-BIKE” A Program Promoting the Development of the Iloilo City Bike Culture (Iloilo City); Yaru: A Whole-of-Community Approach Towards Disaster Management (Itbayat, Batanes); Libertad Fish Forever Savings Club (Libertad, Antique); and

Basta Piddigueño, AgriHenyo: Consolidated Farm Production System (Piddig, Ilocos Norte).

The 10 winners were chosen from 18 finalists and a record field of 196 applications from different LGUs in the country.

Launched on October 21, 1993, the Galing Pook Awards has recognized 329 LGU programs from 200 LGUs in the country that have been promoted for replication to benefit more communities.


Caption: President Ferdinand Marcos, Jr. recognizes the 10 winners of the Galing Pook Foundation 2022 at the Ceremonial Hall of Malacanang Palace. He commended the Galing Pook Foundation for recognizing and incentivizing top performing LGUs. With them in the photo are: Galing Pook Foundation chairman Mel Sarmiento, Local Government secretary Benjamin Abalos, Senate President Juan Miguel Zubiri.
Ang Pambansang Blog ng Pilipinas Wazzup Pilipinas and the Umalohokans. Ang Pambansang Blog ng Pilipinas celebrating 10th year of online presence
 
Copyright © 2013 Wazzup Pilipinas News and Events
Design by FBTemplates | BTT