Incidents

Checking your credit card

This week I received a letter from American Express which stated that my credit card had been temporarily blocked because of potential fraudulent activity. It also said that I needed to call a number to confirm the recent transactions and get the card unlocked.

That seems like a very reasonable thing to do. However the number they asked me to call was not listed on the American Express web site. Though the letter seemed legit I did the only right thing – call their regular number and work things out from there. While digital phishing is the current hot thing to do there are still criminals forging good old snail mail letters to trick users.

It turned out that the number listed was a direct number to their fraud department which isn’t listed on the site. I’ve requested American Express to change their practices.

Checking your credit card

Your email address will not be published. Required fields are marked *

 

Reports

Focus on DroxiDat/SystemBC

An unknown actor targeted an electric utility in southern Africa with Cobalt Strike beacons and DroxiDat, a new variant of the SystemBC payload. We speculate that this incident was in the initial stages of a ransomware attack.

APT trends report Q2 2023

This is our latest summary of the significant events and findings, focusing on activities that we observed during Q2 2023.

Meet the GoldenJackal APT group. Don’t expect any howls

GoldenJackal is an APT group, active since 2019, that usually targets government and diplomatic entities in the Middle East and South Asia. The main feature of this group is a specific toolset of .NET malware, JackalControl, JackalWorm, JackalSteal, JackalPerInfo and JackalScreenWatcher.

Subscribe to our weekly e-mails

The hottest research right in your inbox