article thumbnail

Disneyland Malware Team: It’s a Puny World After All

Krebs on Security

A financial cybercrime group calling itself the Disneyland Team has been making liberal use of visually confusing phishing domains that spoof popular bank brands using Punycode , an Internet standard that allows web browsers to render domain names with non-Latin alphabets like Cyrillic. Bank customers. Bank customers.

Malware 273
article thumbnail

‘Spam Nation’ Villain Vrublevsky Charged With Fraud

Krebs on Security

years in a Russian penal colony for convincing one of his top affiliates to launch a distributed denial-of-service (DDoS) attack against a competitor that shut down the ticketing system for the state-owned Aeroflot airline. What Pavel does is he blackmails those Ukrainian banks using his connections and knowledge.

Banking 193
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Why is.US Being Used to Phish So Many of Us?

Krebs on Security

domains were the worst in the world for spam, botnet (attack infrastructure for DDOS etc.) domains were registered to attack some of the United States’ most prominent companies, including Bank of America , Amazon, Apple , AT&T , Citi , Comcast , Microsoft , Meta , and Target. As far back as 2018, Interisle found.US

Phishing 232
article thumbnail

US Harbors Prolific Malicious Link Shortening Service

Krebs on Security

domains were the worst in the world for spam, botnet (attack infrastructure for DDOS etc.) domains were registered to attack some of the United States’ most prominent companies, including Bank of America, Amazon, Apple, AT&T, Citi, Comcast, Microsoft, Meta, and Target. As far back as 2018, Interisle found.US US phishing domains.

Phishing 269
article thumbnail

SSNDOB marketplace shut down by global law enforcement operation

Malwarebytes

DDoS attacks from rivals are common, so several domains working together keeps things ticking over. One breach taking your login from a gaming forum can quickly become something that exposes Government service logins or bank accounts. SSNDOB attempted to ward off a permanent shut down by spreading the data across four different URLs.

DDOS 103
article thumbnail

How $100M in Jobless Claims Went to Inmates

Krebs on Security

Much of this fraud exploits weak authentication methods used by states that have long sought to verify applicants using static, widely available information such as Social Security numbers and birthdays. Many states also lacked the ability to tell when multiple payments were going to the same bank accounts.

Scams 313