Scammers offer hacking services on government websites

TL;DR Breakdown

  • Scammers have besieged government and university websites to post ads for hacking services.
  • Concerns arise over the security of these websites.

Scammers have carried out a large-scale spam campaign targeting official websites of various U.S. state, county, and local governments, federal agencies, and universities. The campaign involved the uploading of PDF files containing advertisements promoting hacking services and fraudulent activities. Some of the affected websites include those belonging to state governments (California, North Carolina, New Hampshire, Ohio, Washington, and Wyoming), county governments (St. Louis County in Minnesota, Franklin County in Ohio, Sussex County in Delaware), local municipalities (Johns Creek in Georgia), and universities (UC Berkeley, Stanford, Yale, and more).

Scammers post illegal services ads on the websites

The scammers advertisements within the PDF files led to websites offering services for hacking Instagram, Facebook, and Snapchat accounts, cheating in video games, and generating fake followers. Although the campaign primarily aimed to promote scam services, the presence of security vulnerabilities raises concerns about potential malicious activities. The PDFs, found by a senior researcher at Citizen Lab, indicate a larger spam campaign that might be orchestrated by the same group or individual.

Experts have highlighted that the scammers PDF uploads took advantage of misconfigured services, unpatched content management system (CMS) bugs, and other security weaknesses. While investigating the advertised websites, it was discovered that they were part of a scheme to generate revenue through click fraud. The cybercriminals behind the campaign appeared to be utilizing open-source tools to create pop-ups that verify human visitors while generating money in the background. Reviewing the source code revealed that the advertised hacking services were likely fake, despite displaying alleged victims’ profile pictures and names.

Concerns arise over the security of the websites

Representatives from affected entities, such as the town of Johns Creek in Georgia and the University of Washington, mentioned that the issue stemmed from flaws in a content management system called Kentico CMS. However, it is not clear how all the sites were compromised. In some cases, scammers exploited flaws in online forms or CMS software, allowing them to upload PDFs. Affected organizations, including the California Department of Fish and Wildlife and the University of Buckingham in the U.K., acknowledged that their sites were not breached but rather had misconfigured or vulnerable components that facilitated the unauthorized PDF uploads.

While the overall impact of this spam campaign is expected to be minimal, the ability to upload content to .gov websites raises concerns about potential vulnerabilities within the entire U.S. government’s digital infrastructure. Previous incidents, such as Iranian hackers attempting to alter vote counts on a U.S. city’s website, have underscored the importance of securing government and election-related websites against cyber threats.

Efforts are underway to address the issue, with the US cybersecurity agency, CISA, coordinating with affected entities and providing assistance as needed. Affected organizations have taken steps to remove malicious PDFs, fix vulnerabilities, and enhance security measures to prevent similar incidents in the future. However, this incident serves as a reminder of the constant vigilance required to safeguard online platforms against evolving threats.

Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

文章来源于互联网:Scammers offer hacking services on government websites

Disclaimers:

1. You are solely responsible for your investment decisions and this info is not liable for any losses you may incur.

2. The copyright of this article belongs to the writer, it represents the writer's opinions only, not represents the site's ones. Not financial advice.

Previous 2023年6月9日 16:04
Next 2023年6月9日 18:50

Related articles

  • Binance faces leadership exodus amid regulatory crackdown

    TL;DR Breakdown Binance, the world’s largest cryptocurrency exchange, has experienced the departure of two senior executives, Gleb Kostarev and Vladimir Smerkis, who were overseeing operations in Eastern Europe and Russia. They join a list of other high-profile exits, adding to the challenges facing the company. The departures come amid increasing regulatory scrutiny from U.S. and other global authorities, including lawsuits from the U.S. Securities and Exchange Commission and the Commodity Futures Trading Commission. CEO Changpeng Zhao acknowledged the departures but did not elaborate on the reasons. Description Binance, the world’s largest cryptocurrency exchange, has seen the departure of two key executives overseeing its operations in Eastern Europe and Russia. This comes as the exchange faces increasing scrutiny from regulators in the United States and other countries. A spate of high-profile departures Gleb Kostarev, who was the regional head for Eastern Europe, the … Read more Binance, the world’s largest cryptocurrency exchange, has seen the departure of two key executives overseeing its operations in Eastern Europe and Russia. This comes as the exchange faces increasing scrutiny from regulators in the United…

    Article 2023年9月7日
  • US Department of Justice seeks return of FTX-linked political donations

    TL;DR Breakdown The Department of Justice (DOJ) has called for lawmakers to return political donations linked to FTX, a directive several congressional campaigns have followed. The move comes amid legal scrutiny around FTX’s bankruptcy and its founder Sam Bankman-Fried, prompting lawmakers to redistribute FTX-derived contributions. A new ripple in the political fundraising landscape has emerged as the Department of Justice (DOJ) urges lawmakers who received campaign contributions linked to the cryptocurrency exchange FTX to return the donations. Several Congressional campaigns, including Rep. Bob Latta, R-Ohio, and Lori Chavez-DeRemer, R-Ohio, have reportedly complied with the DOJ’s request. The move comes after substantial donations by Ryan Salame, former chief executive of FTX Global Markets, who contributed close to $23 million to candidates during the 2022 midterm election cycle. These funds were largely directed towards Republican candidates, with Bob Latta’s campaign receiving a hefty $2,900. In an unexpected move, these funds have now been voluntarily surrendered, intending to offer compensation for those defrauded, according to a spokesperson from Lori Chavez-DeRemer’s campaign. Reps. Marc Molinaro, R-N.Y., Elise Stefanik, R-N.Y., and Brian Fitzpatrick, R-Penn., have…

    Article 2023年5月19日
  • French experts weigh in on SEC’s stumbling crypto litigation approach

    TL;DR Breakdown French AMF officials under Marie-Anne Barbat-Layani pride in their crypto legislation process, adding that they are AMF is “resolutely open to innovation.” French officials argue that MiCA, adapts existing rules for trading in financial instruments, while the SEC  holds onto century-old securities laws. France intends to build on its regulatory success by legislating for a new regime for Web3-style games involving monetizable digital objects. Description Bonjour!! According to recent reports, French officials have taken pride in their crypto-ready legislation, which contrasts with the SEC’s halting enforcement campaign. In addition, French officials are interested in the next iteration of Web3 gaming regulations. In the rapidly evolving crypto landscape, legal matters surrounding digital assets have become a pressing concern for regulatory authorities … Read more Bonjour!! According to recent reports, French officials have taken pride in their crypto-ready legislation, which contrasts with the SEC’s halting enforcement campaign. In addition, French officials are interested in the next iteration of Web3 gaming regulations. In the rapidly evolving crypto landscape, legal matters surrounding digital assets have become a pressing concern for regulatory authorities…

    Article 2023年7月21日
  • Here are the 3 drivers that hold the future of crypto in the United States 

    TL;DR Breakdown The United States crypto crackdown by the SEC and the present stringent rules have called into question the future of digital assets in the United States of America. Money laundering schemes have taken the stage in the digital asset industry in the last few years, leading to crypto’s association with illegal trade. The 2024 US presidential election sheds light and attention on crypto and the regulation of the industry. Description One of the most pertinent questions around crypto assets is, will these digital assets still be around in the future? Will the assets ever amount to something, or will regulation finally push them offshore? For most crypto enthusiasts, the technology is here to stay. However, there are still more questions than answers, even as investors … Read more One of the most pertinent questions around crypto assets is, will these digital assets still be around in the future? Will the assets ever amount to something, or will regulation finally push them offshore? For most crypto enthusiasts, the technology is here to stay. However, there are still more questions…

    Article 2023年9月15日
  • US Senate approves $886 billion defense bill, targets crypto mixers with AML provisions

    TL;DR Breakdown The US Senate approved an $886B defense bill with provisions targeting crypto mixers. This reflects the rising global recognition and regulatory trends of cryptocurrencies. The bill has sparked debate about deterring crime versus potential overreach. Description The United States Senate recently approved an $886 billion defense bill, a move that resonates across various sectors, including the cryptocurrency industry. The legislation, known as the National Defense Authorization Act (NDAA), includes anti-money laundering (AML) provisions targeting cryptocurrency mixers. Cryptocurrency mixers, or tumblers, are privacy tools designed to mix potentially identifiable or ‘tainted’ cryptocurrency … Read more The United States Senate recently approved an $886 billion defense bill, a move that resonates across various sectors, including the cryptocurrency industry. The legislation, known as the National Defense Authorization Act (NDAA), includes anti-money laundering (AML) provisions targeting cryptocurrency mixers. Cryptocurrency mixers, or tumblers, are privacy tools designed to mix potentially identifiable or ‘tainted’ cryptocurrency funds with others, making it difficult to track the original source. Although these services are lawful, they have attracted regulatory scrutiny due to their potential misuse by criminals seeking…

    Article 2023年7月29日
TOP