Scammers offer hacking services on government websites

TL;DR Breakdown

  • Scammers have besieged government and university websites to post ads for hacking services.
  • Concerns arise over the security of these websites.

Scammers have carried out a large-scale spam campaign targeting official websites of various U.S. state, county, and local governments, federal agencies, and universities. The campaign involved the uploading of PDF files containing advertisements promoting hacking services and fraudulent activities. Some of the affected websites include those belonging to state governments (California, North Carolina, New Hampshire, Ohio, Washington, and Wyoming), county governments (St. Louis County in Minnesota, Franklin County in Ohio, Sussex County in Delaware), local municipalities (Johns Creek in Georgia), and universities (UC Berkeley, Stanford, Yale, and more).

Scammers post illegal services ads on the websites

The scammers advertisements within the PDF files led to websites offering services for hacking Instagram, Facebook, and Snapchat accounts, cheating in video games, and generating fake followers. Although the campaign primarily aimed to promote scam services, the presence of security vulnerabilities raises concerns about potential malicious activities. The PDFs, found by a senior researcher at Citizen Lab, indicate a larger spam campaign that might be orchestrated by the same group or individual.

Experts have highlighted that the scammers PDF uploads took advantage of misconfigured services, unpatched content management system (CMS) bugs, and other security weaknesses. While investigating the advertised websites, it was discovered that they were part of a scheme to generate revenue through click fraud. The cybercriminals behind the campaign appeared to be utilizing open-source tools to create pop-ups that verify human visitors while generating money in the background. Reviewing the source code revealed that the advertised hacking services were likely fake, despite displaying alleged victims’ profile pictures and names.

Concerns arise over the security of the websites

Representatives from affected entities, such as the town of Johns Creek in Georgia and the University of Washington, mentioned that the issue stemmed from flaws in a content management system called Kentico CMS. However, it is not clear how all the sites were compromised. In some cases, scammers exploited flaws in online forms or CMS software, allowing them to upload PDFs. Affected organizations, including the California Department of Fish and Wildlife and the University of Buckingham in the U.K., acknowledged that their sites were not breached but rather had misconfigured or vulnerable components that facilitated the unauthorized PDF uploads.

While the overall impact of this spam campaign is expected to be minimal, the ability to upload content to .gov websites raises concerns about potential vulnerabilities within the entire U.S. government’s digital infrastructure. Previous incidents, such as Iranian hackers attempting to alter vote counts on a U.S. city’s website, have underscored the importance of securing government and election-related websites against cyber threats.

Efforts are underway to address the issue, with the US cybersecurity agency, CISA, coordinating with affected entities and providing assistance as needed. Affected organizations have taken steps to remove malicious PDFs, fix vulnerabilities, and enhance security measures to prevent similar incidents in the future. However, this incident serves as a reminder of the constant vigilance required to safeguard online platforms against evolving threats.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:Scammers offer hacking services on government websites

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年6月9日 16:04
Next 2023年6月9日 18:50

Related articles

  • Binance CEO reveals ban on futures trading for staff, amid insider trading claims

    TL;DR Breakdown Changpeng Zhao, the CEO of Binance, has revealed that all employees of Binance, including himself, are now barred from participating in futures trading. Description Changpeng Zhao, the CEO of Binance, has revealed that all employees of Binance, including himself, are now barred from participating in futures trading. The move is a part of the cryptocurrency exchange’s ongoing endeavors to prioritize integrity and prevent potential conflicts of interest within its workforce. Binance prohibited from futures trading Zhao revealed that the … Read more Changpeng Zhao, the CEO of Binance, has revealed that all employees of Binance, including himself, are now barred from participating in futures trading. The move is a part of the cryptocurrency exchange’s ongoing endeavors to prioritize integrity and prevent potential conflicts of interest within its workforce. Binance prohibited from futures trading Zhao revealed that the exchange’s employees, including him, are prohibited from futures trading, and the product testing team has a specially assigned quota account. However, he revealed that they hold.   The exchange’s policy requires employees to maintain positions for 90 days before trading, promoting long-term…

    Article 2023年8月19日
  • South Korean Bitcoin lender Delio to sue financial regulators

    TL;DR Breakdown South Korean Bitcoin lender Delio is preparing to file an administrative lawsuit against the Financial Service Committee (FSC) over allegations of fraud and embezzlement, which Delio claims are based on a flawed interpretation of existing laws. The lawsuit highlights the regulatory ambiguity surrounding virtual asset deposit and management products in South Korea and the broader challenges faced by the crypto industry. Description South Korean Bitcoin lender Delio is gearing up to file an administrative lawsuit against the country’s Financial Service Committee (FSC).  The firm contends that the FSC’s allegations of fraud and embezzlement are unfounded and stem from a flawed interpretation of existing laws. Delio argues that the regulatory body has acted unreasonably. The Financial Intelligence Unit … Read more South Korean Bitcoin lender Delio is gearing up to file an administrative lawsuit against the country’s Financial Service Committee (FSC).  The firm contends that the FSC’s allegations of fraud and embezzlement are unfounded and stem from a flawed interpretation of existing laws. Delio argues that the regulatory body has acted unreasonably. The Financial Intelligence Unit (FIU), a subsidiary…

    Article 2023年9月15日
  • Bakkt delists Solana, Polygon, and Cardano amid regulatory uncertainty

    TL;DR Breakdown New York-based digital assets platform Bakkt is delisting Solana (SOL), Polygon (MATIC), and Cardano (ADA) in response to regulatory uncertainty and recent SEC lawsuits against crypto exchanges. Bakkt has adopted a compliance-first approach and has been actively reducing its list of tokens to ensure regulatory compliance. The delisting reflects the increasingly hostile regulatory environment in the U.S., with Bakkt aiming to navigate the evolving landscape until there is further clarity on compliant offerings. New York-based digital assets platform Bakkt has decided to delist three major cryptocurrencies, namely Solana (SOL), Polygon (MATIC), and Cardano (ADA). However, the move comes in response to recent regulatory developments and lawsuits filed by the U.S. Securities and Exchange Commission (SEC) against crypto exchanges Binance and Coinbase. The SEC’s complaints labeled Solana’s SOL, Polygon’s MATIC, and Cardano’s ADA as securities, prompting Bakkt to take proactive action. Compliance-first approach and delisting process Bakkt, initially launched by Intercontinental Exchange (ICE) in 2018, has adopted a compliance-first approach in the face of evolving regulatory requirements. Following its acquisition of trading infrastructure provider Apex Crypto in a $155…

    Article 2023年6月19日
  • Tether Ventures into Bitcoin Mining with Innovative Software

    TL;DR Breakdown Tether is developing a new Bitcoin mining software designed to enhance efficiency and streamline operations in the Bitcoin mining ecosystem. Despite legal challenges, Tether continues to invest in the crypto mining sector. The company has launched Tether Energy in Uruguay. Description Tether, a leading issuer of stablecoins, is making significant strides in the Bitcoin mining sector. The company’s Chief Technology Officer (CTO), Paolo Ardoino, has confirmed the development of a new Bitcoin mining software. This innovative software is expected to revolutionize the Bitcoin mining industry by enhancing efficiency and streamlining operations. Contents hide 1 Tether’s New … Read more Tether, a leading issuer of stablecoins, is making significant strides in the Bitcoin mining sector. The company’s Chief Technology Officer (CTO), Paolo Ardoino, has confirmed the development of a new Bitcoin mining software. This innovative software is expected to revolutionize the Bitcoin mining industry by enhancing efficiency and streamlining operations. Contents hide 1 Tether’s New Bitcoin Mining Software 2 The Role of Moria and Holepunch Technology 3 Tether’s Commitment to the Bitcoin Mining Sector 4 Conclusion Tether’s New Bitcoin…

    Article 2023年8月7日
  • Blackpink makes entrance into Roblox’s metaverse

    TL;DR Breakdown South Korean pop group Blackpink has entered the metaverse through Roblox. The group sets its sight on an expansion in the metaverse. Description South Korean pop sensation Blackpink, known for making history as the first K-pop group to headline Coachella, is venturing into the virtual realm of Roblox. The quartet is set to grace the metaverse with a dedicated fan hub, marking a significant step in its digital presence. Named “Blackpink: The Palace,” this immersive experience promises to … Read more South Korean pop sensation Blackpink, known for making history as the first K-pop group to headline Coachella, is venturing into the virtual realm of Roblox. The quartet is set to grace the metaverse with a dedicated fan hub, marking a significant step in its digital presence. Named “Blackpink: The Palace,” this immersive experience promises to be a permanent addition to Roblox, allowing devoted fans (affectionately referred to as Blinks) to engage with the group’s music and recreate their iconic choreography within the virtual realm. The hub will serve as a hub for fans to connect, celebrate, and…

    Article 2023年8月23日
TOP