Hacker Newsnew | past | comments | ask | show | jobs | submit | sat_nam's commentslogin

Thanks for sharing this. I was looking for it on the mercurial repo at sudo.ws, but the commit didn't match. I found it here: https://www.sudo.ws/repos/sudo/rev/f666191a4e80


Some more details can be found in Malwarebytes blog about this: https://blog.malwarebytes.com/malwarebytes-news/2021/01/malw...


Zero days may get the headlines, but attackers are finding a lot of value in leveraging old vulnerabilities. CISA, FBI and NSA have issued several advisories over the last month highlighting an overarching theme of advanced persistent threat groups targeting unpatched vulnerabilities lately.


I observed something similar that began earlier this year. I wrote about it on the Tenable blog. They impersonate many of the people following Trump and engaging with his tweets, irrespective of party affiliation.

https://www.tenable.com/blog/cryptocurrency-scams-fake-givea...


Wow, amazing. I had no idea it was so prevalent. Thanks for writing this up!


It's true that all of the platforms you listed have dealt with scams over the years. It's part of the maturation process of any social network. In the case of TikTok, it officially just celebrated its 2nd year as a platform, and I just began to observe a slew of ads on the platform pushing scams unabated. Scammers follow the trends and where the users are, so an extremely popular app like TikTok became a platform ripe for the picking.


In the advisory, Mozilla states it was being used as part of targeted attacks. Qihoo 360 ATA is credited with discovering the vulnerability and the in-the-wild exploitation of the flaw. Catalin Cimpanu says Qihoo 360 deleted a tweet connecting this bug to an undisclosed Internet Explorer zero-day [1] so it remains to be seen if there is another bug out there that remains unpatched. Mozilla also patched a pair of vulnerabilities that were used in targeted attacks last year [2]

[1] https://twitter.com/campuscodi/status/1215020566656299011

[2] https://www.tenable.com/blog/cve-2019-11707-cve-2019-11708-m...


"We’re always updating our rules based on how online behaviors change. Today we're expanding our policies to prohibit financial scams."

https://twitter.com/TwitterSafety/status/1176190505757106177


Zhuowei Zhang (@zhuowei) published a proof of concept that crashes Chrome 70: https://worthdoingbadly.com/sqlitebug/


This is a great effort. I wrote about this at the end of January (https://research.satnam.co/2018/01/30/scammers-impersonating...) and was working on a script last month that did the same thing but I was searching the Streaming API for specific keywords that I knew were triggers for their tweets. I set-up a Twitter account to also identify and report these scammers accounts. The problem I was having was I did not account for the variety of currencies that were being utilized, so I had to write new regexes for the different address types. By then, they had switched up tactics and I hadn't followed up on it since.


They won't accept only taking a portion of the ivory and leaving the rest for the elephant. The demand and the value for ivory incentivizes an "all or nothing" approach. That's why you see cases where elephants have been poisoned but their tusks remain in tact. It's because the poachers didn't have enough time to get whole tusks. The people actually poaching the elephants aren't the ones who make the big bucks, so they're likely taught by the traffickers how to obtain the tusks in order to maximize THEIR value.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: