News

Short summaries of the cyber-crime stories moving in India and globally. We link back to the original source — always.

North Korean Job Scams Use Compromised Repositories for Malware Spread
Malware

North Korean Job Scams Use Compromised Repositories for Malware Spread

Recent reports indicate that job scams linked to North Korea are utilizing compromised software repositories to distribute malware. Specifically, these scams employ remote access Trojans (RATs) as part of a contagion-like method to infect users' systems. The compromised repositories act as vectors for spreading the malicious software, enabling unauthorized access and potential data theft. This situation highlights the need for heightened internet safety awareness among job seekers, emphasizing the importance of verifying the legitimacy of job offers and sources before sharing personal information. Vigilance can prevent individuals from falling victim to these cyber threats. Source: [publication name].

via Dark ReadingRead source
Fraud Operations Function Like Professional Call Centers
Social Engineering

Fraud Operations Function Like Professional Call Centers

Recent reports indicate that fraud schemes are adopting a structured approach similar to call centers. Dubbed 'Caller-as-a-Service', cybercriminals are developing organized operations, which include hiring staff, providing extensive training, and monitoring employee performance. This shift highlights how sophisticated and professional these fraud networks have become, functioning much like legitimate businesses. The implications for consumers and businesses alike are significant, as these operations pose a growing threat and are increasingly difficult to distinguish from legitimate calls. Awareness and vigilance remain critical in combating these evolving scams. Source: Flare.

via BleepingComputerRead source
Lotus Wiper Malware Attacks Venezuela's Energy Sector
Malware

Lotus Wiper Malware Attacks Venezuela's Energy Sector

Cybersecurity experts have identified a new piece of malware known as Lotus Wiper, which has been involved in destructive attacks on Venezuela's energy systems. This malware, which was first detected at the end of last year through early 2026, primarily targets the energy and utilities sector. Researchers from Kaspersky reported that the attacks include the use of two batch scripts designed to erase important files and disrupt operations significantly. Such incidents highlight the ongoing vulnerabilities of critical infrastructure to cyber threats. As cyber attacks continue to evolve, the importance of enhancing security measures in crucial sectors is underscored. Source: Kaspersky.

via The Hacker NewsRead source
Businessman loses Rs 20 crore in elaborate crypto fraud scheme
Crypto Scams

Businessman loses Rs 20 crore in elaborate crypto fraud scheme

A Delhi businessman fell victim to a cryptocurrency scam resulting in a loss of approximately Rs 20 crore. The fraudsters operated through a sophisticated network of 76 fake bank accounts to facilitate the illegal transactions. The scam involved convincing the victim to invest in what appeared to be a legitimate cryptocurrency opportunity. Authorities are investigating the case to identify and apprehend the perpetrators behind this organized fraud network. The incident highlights the growing risks associated with cryptocurrency investments and the tactics employed by criminals to exploit unsuspecting victims. Source: The Indian Express.

via GoogleNews: cryptocurrency scamRead source
India Dismisses Crypto Scam Connection to Hormuz Vessel Incident
Crypto Scams

India Dismisses Crypto Scam Connection to Hormuz Vessel Incident

India has officially denied any involvement of cryptocurrency scams in relation to a recent ship attack in the Strait of Hormuz. The statement comes amid reports attempting to link illicit digital currency operations to the maritime incident. Indian authorities clarified that preliminary investigations show no connection between crypto-related fraudulent activities and the vessel attack. This clarification was issued to counter speculation and misinformation circulating about potential criminal networks operating through cryptocurrency channels. The denial underscores India's commitment to distinguishing between various cybercrime categories and maritime security incidents. Source: MSN.

via GoogleNews: cryptocurrency scamRead source
North Korean Hackers Suspected in $300 Million Crypto Heist
Crypto Scams

North Korean Hackers Suspected in $300 Million Crypto Heist

A recent cyberattack resulting in a $300 million cryptocurrency theft is being linked to the Lazarus Group, a hacking group associated with North Korea. The breach affected KelpDAO and exploited weaknesses in LayerZero's servers. Reports suggest that the stolen funds may be used to finance North Korea's nuclear weapons program, raising concerns about the increasing risk of cyber threats globally. This incident underscores the need for enhanced cybersecurity measures to protect digital assets from sophisticated cybercriminals. It also highlights how geopolitical tensions can influence cybercrime activities. Source: [publication name].

via Economic Times TechRead source
Vodafone and Google Cloud Join Forces for Small Business Cybersecurity
Data Breaches

Vodafone and Google Cloud Join Forces for Small Business Cybersecurity

Vodafone has announced a collaboration with Google Cloud aimed at enhancing cybersecurity and artificial intelligence capabilities specifically for small businesses. The initiative will first launch in Germany, adhering to the region's strict data protection regulations. Following its initial rollout, the services are expected to expand to more European markets later this year. This partnership is part of Vodafone's strategy to equip smaller enterprises with advanced security measures, helping them safeguard their operations against cyber threats. The focus on small businesses reflects a growing recognition of their vulnerability to cyber attacks. Source: [publication name].

via Economic Times TechRead source
India Establishes AI Centre to Enhance Defence Capabilities
Phishing

India Establishes AI Centre to Enhance Defence Capabilities

India is set to strengthen its defence system with the establishment of a new Centre of Excellence for Artificial Intelligence, funded with Rs 300 crore. Collaborative discussions are underway between local AI labs, including Sarvam, and the defence ministry to develop AI technologies specifically suited to the country's operational requirements. This initiative aims to decrease India's dependence on foreign technology while promoting self-reliance in national security. The focus on homegrown solutions is expected to contribute positively to the nation's defense industry and innovation.

via Economic Times TechRead source
US to Reassess Previous Green Card Approvals for Fraud Risks
Cyber Law (India)

US to Reassess Previous Green Card Approvals for Fraud Risks

The U.S. Citizenship and Immigration Services (USCIS) plans to review older green card cases from the Biden administration to investigate potential fraud. USCIS Director Joseph B. Edlow announced this initiative to implement more stringent oversight regarding green card issuance, coinciding with an increase in denial rates. The move aims at strengthening the integrity of the immigration process amid growing concerns about fraudulent applications. Individuals who have recently received green cards during this period might face additional scrutiny as part of this review. These changes highlight the ongoing challenges within the U.S. immigration system and reflect a shift towards more rigorous assessment practices. Source: [publication name].

via Economic Times TechRead source
French Government Agency Confirms Data Breach Incident
Data Breaches

French Government Agency Confirms Data Breach Incident

France Titres, the agency responsible for issuing and managing official documents in France, has confirmed a data breach. A hacker has claimed responsibility for the attack and is allegedly attempting to sell the stolen personal data of French citizens. The agency is working to assess the extent of the breach and to implement necessary security measures to prevent further incidents. Authorities are urging affected individuals to be vigilant against possible identity theft and fraud stemming from the breach. This incident highlights the ongoing risks posed by cyber threats, emphasizing the importance of maintaining robust cybersecurity practices.

via BleepingComputerRead source
Ransomware Negotiator Admits Guilt in BlackCat Case
Ransomware

Ransomware Negotiator Admits Guilt in BlackCat Case

A ransomware negotiator has pleaded guilty in relation to the BlackCat ransomware operation. Legal experts suggest this case highlights an important lesson in cybersecurity: individuals involved in negotiating should remain separate from the ransom payment process. This distinction is crucial to ensure integrity and transparency during negotiations with cybercriminals. The BlackCat ransomware group has been involved in various attacks affecting organizations by demanding significant sums for the return of stolen data. This case serves as a reminder of the ethical dilemmas and legal implications surrounding ransom payments in cybercrime. Source: [publication name].

via Dark ReadingRead source
Active Exploits Target Windows Defender Security Features
Malware

Active Exploits Target Windows Defender Security Features

Three new exploits have been discovered that can manipulate Microsoft's Windows Defender, turning it into a tool for attackers. This has raised concerns as two of these vulnerabilities remain unpatched, leaving the built-in security software vulnerable during ongoing attacks. Users are advised to remain vigilant and keep their systems updated to minimize risks. Regular updates can help protect against potential exploits and maintain system integrity. It is essential for users to stay informed about such vulnerabilities to ensure better cybersecurity practices.

via Dark ReadingRead source