• John Hammond
  • Posts
  • Cybersecurity Shenanigans #006: Less malware, more pumpkin pie, please

Cybersecurity Shenanigans #006: Less malware, more pumpkin pie, please

This month's cybersecurity scoop.

šŸ‘‹ Hey friend,

Who else is kiiiinda just dreaming of stuffing and pumpkin pie at this point? šŸ˜…

Unfortunately, Thanksgiving is still a week away, so Iā€™m putting my dreams on hold to crank out another one of these newsletters.

ā€˜Tis the season, so Iā€™ll be a lil bit sappy by saying Iā€™m grateful for you and appreciate your humoring me with these things. Weā€™ve managed to build quite the community together, and I love being able to ā€œtalkā€ to you more personally in these monthly newsletters. So, thank you for being here!

Just one more week til mashed potatoes and gravy. We can do this.

ā€” JH

News & Commentary

Fancy AI video generators serving up malware šŸ¤–

Have you ever used a program called EditPro to edit and generate photos and videos through AI? If so, get to changing those passwords. šŸ˜…

Ads are floating around on X for EditPro, which claims to be a program that you can use to ā€œcreate as in your dreams Image.ā€ (???)

Source: urlscan.io screenshot of the malicious site editproai[.]org

When you download the program, youā€™re also downloading infostealing malware (often Lumma Stealer, which is usually disguised as a CAPTCHA with a few additional steps). And apparently, the threat actors behind this one used up all their capacity for fanciness in their ā€œsoftware,ā€ because they didnā€™t try too hard at all with their malware.

Source: BleepingComputer

From there, the malware relies on a panel to exfiltrate stolen data, keeping it on standby for whenever the malicious actors are ready to call on it.

And Macs arenā€™t safe from this one, either! So if you downloaded this program on your Mac, you might wanna change your passwords, too. šŸ˜…

Man extorts orthodontist using RaaS šŸ¦·

Know how even script kiddies can be eLiTe h4Ɨ0rs these days?

Such is the case for one Idahoan, who purchased ransomware-as-a-service (RaaS) tools to steal data and extort an orthodontist. One of the 43,000 records he was able to get hold of belongs to none other than the orthodontistā€™s child. And yes, this guy stooped low enough to threaten releasing that childā€™s personally identifiable information if a ransom wasnā€™t paid. šŸ™

Fortunately, the FBI was able to track this guy down and make him pay for his crimes. He has to serve 10 years in prison, 3 years of supervised release, and pay up more than $1M for the damages he caused.

Fake Facebook ads for Bitwarden distributing malware šŸ¦ 

Bitwarden users, take note: If youā€™ve seen Facebook ads warning you of outdated software, ignore them.

Bitdefender Labs reported a malicious campaign on Facebook targeting users of their Bitwarden (password manager) product. Cybercriminals have exploited Facebookā€™s advertising platform and hijacked verified Facebook pages, renaming them to impersonate entities like "Meta Ads Manager" or Bitwarden. (Apparently, being ā€œverifiedā€ means very little these days. šŸ˜…)

They ran fake ads claiming to offer Bitwarden software downloads. And they look pretty legit, to be honest:

Source: Bitdefender Labs

But instead of downloading Bitwarden, users who clicked the ads ended up on a malware-packed site aimed at gathering login credentials and session cookies from browsers. And the page looks creepily legitimate:

Source: Bitdefender Labs

Bitdefender is asking users to remain vigilant, avoid downloading software from unverified sources, and use robust cybersecurity tools to protect against these threatsā€‹.

Latest Content

YouTube Videos

// Letā€™s explore a recent malware incident in the Cities: Skylines 2 modding community. šŸ‘€

// Based on a post that reads, ā€œWho needs a web shell, when we can just enable PSWA?ā€ šŸ˜…

Just Hacking Training Update šŸ¤“

If you were subscribed to this newsletter last month, you know we launched Just Hacking Training: our take on hands-on, affordable cybersecurity training.

Since then, weā€™ve released a new thing or two. šŸ¤©

Put on your blue hard hat and get ready to get your hands dirty in Constructing Defense, or ConDef! (See what we did there?)

ConDef by Anton Ovrutsky is three courses combined into a single ā€œpath.ā€ Itā€™s all about constructing a defensive playground in a massive, web-based virtual environment that mimics a typical enterprise, including cloud. Youā€™ll get hands-on experience with throwing attacks at it and seeing what happens from a defensive perspective.

And weā€™re running an introductory special, so nowā€™s the time to enroll if this one sounds like fun.

Additional November releases:

And hereā€™s a sneak peek at whatā€™s coming up in December! šŸ‘€

Come hang out with us hackers in Discord and engage with me, our All-Star instructors, students, and the rest of our community.

Social

Livestream Recap

I recently hosted a livestream to hang out with some fine folks on YouTube and geek out over OSINT. If you missed it, no sweat ā€” it still exists on the internet! šŸ˜…

Hoping to do more of these super soon. Stay tuned!

You All Have Jokes. šŸ˜‚

I recently changed up how folks subscribe to this thing. To appease the Email Overlords, Iā€™ve asked new subscribers to reply to an email from me with their best joke (to make sure future newsletters donā€™t land in spam). And send me their best jokes, they did. šŸ¤£

Here are a few of my favorite replies that landed in my inbox this month.

Why do cows have hooves and not feet? Because they lactose.

bincotase

How did the computer get drunk? It took screenshots.

lrjsec

What do you call a deer with no eyes? No eye-deer!

Gina

Cybersecurity is like an onion. Thereā€™s layers, and at some point, you start to cry.

Andrew

If youā€™d already subscribed before I started asking for your favorite joke, please reply to this email with your favorite joke. It may just be featured in next monthā€™s newsletter. šŸ˜‰

Got feedback?

Tell me to be entered to win a free course on Just Hacking Training! šŸ„³

Love this thing? Have some pointers on how I can make it better? Please reply to this email and let me know. I really want these newsletters to be worth reading to you, and your feedback makes that possible!

Allow me to sweeten the pot. šŸ˜ One person who replies to this email with helpful feedback will win access to my course on Just Hacking Training: Script-Based Malware Analysis! Iā€™ve received so much helpful feedback thatā€™s already made this newsletter better, and Iā€™d like to give back to encourage you all to keep it coming. šŸ˜‰

Hope to hear from you soon!