Chinese cybercriminals using advanced tools to carry out NFC fraud at scale
The fraud scheme relies on the use of HCE, a feature on Android that allows a smartphone to emulate a contactless smart card.
The fraud scheme relies on the use of HCE, a feature on Android that allows a smartphone to emulate a contactless smart card.
Kimsuky is also using phishing emails to deliver payloads that exploit another known vulnerability - CVE-2017-11882.
The attackers initiate contact through secure messaging platforms such as Signal and WhatsApp.
The MIVD also warned of a sharp increase in digital operations linked to Russia.
It leverages an advanced NFC-relay attack to authorize fraudulent transactions at POS terminals and ATMs.
The campaign targeted a range of critical sectors, including a government ministry, an air traffic control organization, a telecommunications provider, and a major construction company.
In many cases, the victims were convinced to install remote access software.
In brief: Apple fixes a couple of iOS zero-days, a Windows NTLM bug exploited in real-world attacks, and more.
The flaws have been used in “extremely sophisticated attacks” targeting specific individuals.
The campaign is attributed to a well-known cyber espionage group known as Earth Bluecrow.
Showing elements 661 - 670