
Cyber criminals are exploiting online platforms and services to launch sophisticated attacks, according to a report from HP. Using online advertising tools, they spread malware and hack into computers. Additionally, Google's Cloud Run service has been identified as a platform for large-scale email phishing attacks, distributing banking trojans such as Astaroth, Mekotio, and Ousaban. Over 8,000 subdomains of recognized brands and organizations have been hijacked for malicious email distribution, bypassing common email security measures like SPF, DKIM, and DMARC with a technique dubbed 'ResurrecAds'. Researchers have detailed a spam campaign that utilizes hijacked abandoned domains and subdomains from reputable brands like eBay and VMware, managing to send approximately 5 million malicious emails daily. An operation manipulating more than 8,000 subdomains affiliated with major brands was reported by @GuardioSecurity to dispatch vast quantities of spam and malicious emails, effectively evading most common security controls.
An operation that manipulated more than 8,000 subdomains belonging to or affiliated with major brands was found to dispatch vast quantities of spam and malicious emails that were able to slip past most common security controls, @GuardioSecurity reported. https://t.co/1y5K7OAcBM
Researchers detail a spam campaign using hijacked abandoned domains and subdomains from reputable brands like eBay and VMware to send ~5M malicious emails daily (@billtoulas / BleepingComputer) https://t.co/l0LutISKtj https://t.co/edzigsboqN
8,000+ Subdomains of Trusted Brands Hijacked for Massive Spam Operation: https://t.co/FSJfw9hjZW by The Hacker News #infosec #cybersecurity #technology #news




