Microsoft successfully rescued 50 domain names from the notorious hacker group
Add a resounding victory for Microsoft against the sponsored hacker groups. The East Virginia District Court recently issued a decision agreeing to allow Microsoft to confiscate 50 domain names from the notorious Thallium hacker group.
Thallium is a large hacker organization with strong ties to the Korean government. The group designed many malicious networks, which are used to target identified victims and then compromise online accounts, infect malware on computer systems, compromise network security. and stealing sensitive information from victims. The Thallium targets are primarily government officials, university staff, academics, members of world peace and human rights organizations, and working individuals. in the nuclear field. Most targets are in the United States, Japan and South Korea.
Thallium often tries to trick the victim through a technique called spear phishing. By collecting targeted personal information through social media accounts, in networks from relevant organizations and other public sources, Thallium can create an extremely specialized phishing email. You can now deceive a victim to deceive the victim in response to the request outlined in the email. The email content may look legitimate at first glance, but a closer review shows that Thallium has faked Microsoft by combining the letters' r 'and' n 'so that when placed next to each other will look like the letter' m ', such as' rnicrosoft.com'.
The link in the fake email of Thallium will redirect the user to a website that requires credentials for authentication, then they will use this information to log in to the victim account. After successfully penetrating the victim's account, Thallium can review emails, contacts, calendar appointments and anything else they are interested in. In addition, they often create a new mail forwarding rule in the victim account settings. This mail forwarding rule will forward all new emails the victim receives to Thallium-controlled accounts. By using forwarding rules, Thallium can continue to access any email the victim receives, even after this account password is updated.
In addition to hijacking unauthorized login credentials, Thallium also uses malware to infect systems and steal data. The two types of malware commonly used by this group are called 'BabyShark' and 'KimJongRAT.'
To protect against these threats, Microsoft recommends users enable two-factor authentication on all personal and business email accounts they hold. Second, users need to learn how to detect phishing scams and protect themselves from them. Finally, turn on security alerts for links, files from suspicious websites and carefully check email forwarding rules on your account.
You should read it
- [Infographic] 4 types of Phishing are easy to trap users
- How to report phishing emails in Outlook.com
- Warning: New email phishing tactics appear
- How to identify phishing emails
- Microsoft warns of phishing campaigns targeting Outlook Web App and Office 365 users
- What is Domain Hijacking? How dangerous is it?
- Beware of the 7 most common types of spam
- 5 signs to identify phishing websites
May be interested
- Many websites were hacked, changing content into gambling advertisementsmany websites have gov.vn domain names of state agencies hijacked by hackers, changing the content into advertisements for pages for online gambling website v8 *****.
- Google introduces new .page high-level domain namescurrently there are about 1543 domain names in operation and many of them are owned by google. they just added a new name .page.
- Good group names and meaningsthe following article, invite readers to consult the best, meaningful and impressive group names in vietnamese and english.
- Famous websites have changed domain names before 'being successful'domains like google.com or facebook.com ... have become too familiar. however, few people know that before becoming famous like today, many big websites have brought strange and memorable domain names.
- The hacker claimed to successfully steal 63.2GB of Microsoft source code from GitHuban anonymous hacker recently announced that he successfully stole 63.2gb of microsoft source code from github - the largest online code sharing and storage platform in the world.
- Request to revoke VNG's Zalo.vn and Zalo.me domain names because social networking activities are not allowedinspector of the department of information and communications of ho chi minh city has written a request to register and manage domain names to recover 2 domain names of zalo owned by vng jsc and zalo.vn and zalo.me before july 19 due to the operation of an unauthorized social network model.
- Lapsus$ hacker group claims to be in possession of Microsoft's source codeon the morning of sunday, march 20, 2022, the lapsus$ hacker group announced that they were in possession of some microsoft source code.
- Discovered a group of Vietnamese hackers specializing in stealing credit cards for the past 8 yearsaccording to security firm volexity, a group of suspected vietnamese hackers has been conducting activities to steal credit card information for the past 8 years.
- What is Domain Hijacking? How dangerous is it?the domain name is one of the most important assets in the internet.
- What is top-level domain name (TLD) and how do they work?each time you enter a domain name, you always need to type something after the dot like .com, .net, .org, etc. these three letters are very important to the address you enter to get you where you need it and they are called top level domains (tld).