Page 5 - Threat Intelligence 10-3-2019
P. 5
Security News
NSA launches new cyber defense directorate. The National Security Agency on Tuesday will launch an
organization to prevent cyberattacks on sensitive government and defense-industry computers — with an eye
also toward helping shield critical private-sector systems. For decades the agency had a cyberdefense
organization, the Information Assurance Directorate (IAD), that focused on safeguarding the government’s
classified and sensitive networks, as well as the private sector’s, when asked. What is new, NSA officials said, is
that the agency is hitching together under one roof threat detection, cyberdefense and future-technologies
personnel. They are calling it the Cybersecurity Directorate.
Source: https://www.washingtonpost.com/national-security/nsa-launches-new-cyber-defense-
directorate/2019/09/30/c18585f6-e219-11e9-be96-6adb81821e90_story.html
Dutch police shut down bulletproof service hosting tens of DDoS botnets. A joint operation conducted by the
Netherlands’ National Criminal Investigation Department and National Cyber Security Center allowed to track
down and seize five servers that were composing a cybercrime underground bulletproof hosting service. The
servers were hosted at an unnamed data center in Amsterdam, it was used by tens of IoT botnets involved in
DDoS attacks worldwide. The bulletproof hosting service was used to host malware and command and control
systems of several DDoS botnets.
Source: https://securityaffairs.co/wordpress/92070/cyber-crime/dutch-police-seized-bulletproof-
hosting-service.html
Discovery of Geost Botnet Made Possible by Attacker OpSec Fails. A series of operational security (OpSec)
failures on the part of attackers enabled researchers to discover the Geost botnet. In mid-2018, Virus Bulletin
researchers Sebastian Garcia, María José Erquiaga and Anna Shirokova discovered Geost, one of the largest
Android banking botnets known today, while analyzing another malware family called HtBot. The researchers
found that HtBot converted victims into unwilling proxies that received traffic from the malware’s network and
then sent it to the web. While analyzing that traffic, they observed someone logging into the command-and-
control (C&C) panel of what was then a previously undocumented botnet.
Source: https://www.tripwire.com/state-of-security/security-data-protection/discovery-of-geost-
botnet-made-possible-by-attacker-opsec-fails/
FBI warns about high-impact Ransomware attacks on U.S. Organizations. In a wake of the recent string of
attacks against cities, school districts and hospitals, the U.S. Federal Bureau of Investigation (FBI) Internet
Crime Complaint Center (IC3) issued organizations about high-impact ransomware attacks. “Ransomware
attacks are becoming more targeted, sophisticated, and costly, even as the overall frequency of attacks
remains consistent.” reads the public service announcement published by the IC3.
Source: https://securityaffairs.co/wordpress/92092/malware/fbi-ransomware-attacks-alert.html
www.accumepartners.com
5