AI news is bad news, an online service to catch your cheating partner, and an IoT-enabled dick cage fails to keep a grip on its own security. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Mark Stockley. Plus don't miss our featured interview with Alex Lawrence, principal security architect at Sysdig.

In January of this year, the UK police disclosed that some schools in Ghana were teaching school kids above the age of 10 to catfish single women from Britain and engage in romance scams with them, exploiting them for money exchange.

The issue was brought to light when a team of journalists from a reputed daily engaged in an undercover operation to unravel the people behind catfishing. To their surprise, they found a few school children groomed with cyber lessons to smartly coax males and females from developed nations into engaging in such embarrassing activities that they had no choice but to pay the hacker a hefty amount to avoid any online embarrassment.

Now, authorities in the UK have issued an advisory to the Ghanaian Police on the damage caused by romance scams and how to prevent children from being groomed into catfishing and other activities such as defrauding people in Britain.

Nik Adams is leading the response against fraud and has stipulated certain preventive guidelines to school-going would-be hackers on how to not fall prey to online hackers and fraudsters and target wealthy single women, as it can lead to serious legal consequences.

As this crime and related crimes are seeing a sharp rise in and around London, the police authorities contacted the Ghanaian government with a scheme to increase the morale of people, especially children, to speak out against crime and its perpetuation.

Note 1: Catfishing is nothing but luring an online victim into a relationship with a fake profile and then engaging in the crime of extortion, which can lead to the death of the victim under certain circumstances.

Note 2: For the past few weeks, a new WhatsApp scam has emerged on the web, where scammers from countries like Singapore, Malaysia, and Vietnam are calling victims to gain personal information or to win their trust in order to take the romance scam to the next level. As per the analysis conducted by South Indian Police officials, people as young as teens are being hired to engage the victims in scams and are being lured with hefty paychecks on a monthly basis.

The post Ghanian children involved in Britain Catfishing Romance Scams appeared first on Cybersecurity Insiders.

Pulchritudinous women with glossy long hair are targeting Israeli officials via Facebook - but why? Scammers have found a new way to gain access to your most sensitive information - but how? And armchair detectives are helping investigating cold cases involving DNA - but should they? All this and much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Maria Varmazis.

According to a discovery made by security researchers from Cybereason, top-ranking officials from Israel were being targeted by spear phishing cyber attacks. And the hackers group behind this campaign is suspected to be AridViper, a notorious cyber criminal group from Middle East.

AridViper aka Desert Falcon or APT-C-23 is an advanced persistent group that is being run by some Saudi politicians on a secret note.

Also known as a two-scaled scorpion, this APT group was initially assigned the duty of preying on Palestine law enforcement officers and people behind educational institutions.

In February this year, security researchers from Cisco Talos found that the Israel Palestine Conflict was fueling the AridViper to launch catfishing attacks.

Now, in March this year, Cybereason’s Nocturnus Research Team found that the cyber crime group has started a new campaign dubbed “Operation Bearded Barbie” through which it was targeting Israel individuals through cat fishing campaigns to infect their PCs and mobile devices with spying and data stealing tools.

Already 17 of the law enforcement officials, three working for defense and 8 from the emergency service sector, were found targeted, and the number is said to increase as the campaign unfolds.

Catfishing cyber attack campaign is simple, just to create fake social media account pages and target individuals and trick them into downloading malware.

In most cases, profiles of beautiful women or upcoming models from fashion circuit are used to hook the victims in downloading trojanized messaging apps such as Barbwire Backdoor.

Barbwire had capabilities such as conducting surveillance, capturing keylogs, screen capturing, and eavesdropping and recording on digital conversations taking place between targeted individuals.

Also, the downloader has the capabilities of exfiltrating data to remote servers from compromised machines. And the information includes details such as MS office documents, archives, images and videos.

Additionally, Cybereason researchers also found an android malware dubbed VolatileVenom during the installation of discrete apps and is also found having capabilities of conducting espionage and data theft.

VolatileVenom being spread from Catfishing attacks had capabilities of spying on the victims through his/her WhatsApp, Facebook, twitter, Instagram, Skype and IMO messages.

Why the campaign is targeting only Israel government officials through Catfishing campaign is yet to be figured out?

 

The post Israel government officials targeted by spear phishing attacks appeared first on Cybersecurity Insiders.