<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>social engineering &#8211; EFR Technology Group</title>
	<atom:link href="https://www.efrtechgroup.com/category/social-engineering/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.efrtechgroup.com</link>
	<description>We maintain technology so you don't have to!</description>
	<lastBuildDate>Fri, 17 Jul 2020 19:30:40 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://www.efrtechgroup.com/wp-content/uploads/2019/02/cropped-EFRTG-color-2-32x32.jpg</url>
	<title>social engineering &#8211; EFR Technology Group</title>
	<link>https://www.efrtechgroup.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Twitter&#8217;s Bitcoin hackers had almost limitless access</title>
		<link>https://www.efrtechgroup.com/tech/twitters-bitcoin-hackers-had-almost-limitless-access/</link>
		
		<dc:creator><![CDATA[Randall]]></dc:creator>
		<pubDate>Fri, 17 Jul 2020 19:30:40 +0000</pubDate>
				<category><![CDATA[0day]]></category>
		<category><![CDATA[bitcoin]]></category>
		<category><![CDATA[Entertainment]]></category>
		<category><![CDATA[gear]]></category>
		<category><![CDATA[Hack]]></category>
		<category><![CDATA[hacks]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[tomorrow]]></category>
		<category><![CDATA[Twitter]]></category>
		<guid isPermaLink="false">https://www.efrtechgroup.com/twitters-bitcoin-hackers-had-almost-limitless-access/</guid>

					<description><![CDATA[[ad_1] Just hackers burning up 0day like it’s a fire sale Imagine getting the keys to the Twitter kingdom &#8212; access to all the account admin panels in the world. What would you do? You could grab high-value accounts and sell them on the black market. You could extract unimaginably valuable blackmail material from DMs. [&#8230;]]]></description>
										<content:encoded><![CDATA[<p> [ad_1]<br />
</p>
<div>
<p><strong>Just hackers burning up 0day like it’s a fire sale</strong></p>
<p>Imagine getting the keys to the Twitter kingdom &#8212; access to all the account admin panels in the world. What would you do? You could grab high-value accounts and sell them on the black market. You could extract unimaginably valuable blackmail material from DMs. Or maybe you&#8217;d wait until an event like the upcoming US election to launch an evil plan of some kind.</p>
<p>But if you&#8217;re any kind of seasoned attacker, you wouldn&#8217;t blow your own cover by tweeting from the world&#8217;s biggest accounts &#8212; for a bitcoin scam. Sure, some have posited that the cryptocurrency spam tweets were a distraction for something bigger going on in the background. Maybe the attackers already did their sneaky stuff and are ready to do what&#8217;s called &#8220;burning your 0day.&#8221;</p>
<p>And boy, did they burn that perfectly good 0day hot, bright, and fast.</p>
<p><span>   </p>
<blockquote class="twitter-tweet">
<p>We detected what we believe to be a coordinated social engineering attack by people who successfully targeted some of our employees with access to internal systems and tools.</p>
<p>— Twitter Support (@TwitterSupport) <a href="https://twitter.com/TwitterSupport/status/1283591846464233474?ref_src=twsrc%5Etfw" target="_blank" rel="noopener noreferrer">July 16, 2020</a></p></blockquote>
<p>   </span></p>
<p>Twitter’s response — a worrying five hours later — was to do something few knew the company had the power to do: lock every verified account across the globe. Unfortunately this is akin to discovering a burglar is in your house because they started blasting music in your living room, and your response is to turn off all the lights.</p>
<p>Except freezing the “blue checks” is actually worse, because many essential emergency services around the world use Twitter as a critical communication channel. Like the National Weather Service, which found itself suddenly <a href="https://www.washingtonpost.com/weather/2020/07/16/twitter-outage-affected-national-weather-service-office-during-tornado-warning/" target="_blank" rel="noopener noreferrer">unable to tweet weather warnings</a>.  </p>
<p>The account freezes appeared to be a decision governed by panic. Twitter seemed to have no idea what was happening or how to stop it. And wow, do we have questions about the who, what, why, and future implications of it all. </p>
<p><span>   </p>
<blockquote class="twitter-tweet">
<p>Blue checks trying to communicate through retweets <a href="https://t.co/FIbBmWH4j8" target="_blank" rel="noopener noreferrer">pic.twitter.com/FIbBmWH4j8</a></p>
<p>— Andrew Roth (@RothTheReporter) <a href="https://twitter.com/RothTheReporter/status/1283549521159610368?ref_src=twsrc%5Etfw" target="_blank" rel="noopener noreferrer">July 15, 2020</a></p></blockquote>
<p>   </span></p>
<p>In <a href="https://twitter.com/TwitterSupport/status/1283591846464233474" target="_blank" rel="noopener noreferrer">a tweet thread</a> posted during and after the hack attack, Twitter wrote: “We detected what we believe to be a coordinated social engineering attack by people who successfully targeted some of our employees with access to internal systems and tools.”</p>
<p>The verified account freeze also impacted those users’ ability to reset their passwords.</p>
<p><span>   </p>
<blockquote class="twitter-tweet">
<p>We know they used this access to take control of many highly-visible (including verified) accounts and Tweet on their behalf. We’re looking into what other malicious activity they may have conducted or information they may have accessed and will share more here as we have it.</p>
<p>— Twitter Support (@TwitterSupport) <a href="https://twitter.com/TwitterSupport/status/1283591848729219073?ref_src=twsrc%5Etfw" target="_blank" rel="noopener noreferrer">July 16, 2020</a></p></blockquote>
<p>   </span></p>
<p>Twitter bracketed the thread with a caveat that its investigation is “ongoing.”</p>
<p><strong>Don’t worry the rich celebrities will be okay</strong></p>
<p>The compromised accounts included Jeff Bezos, Bill Gates, Elon Musk, Bill Gates, Barack Obama, Apple, Kanye West, Joe Biden, Uber, Mike Bloomberg, Floyd Mayweather, Wiz Khalifa, and others. Twitter updated its ongoing <a href="https://twitter.com/TwitterSupport/status/1283957911841054721" target="_blank" rel="noopener noreferrer">incident report support thread</a> Thursday evening to state that <a href="https://twitter.com/TwitterSupport/status/1283957911841054721" target="_blank" rel="noopener noreferrer">130 accounts were affected</a> by the attack.</p>
<p><span>   </p>
<blockquote class="twitter-tweet">
<p>Based on what we know right now, we believe approximately 130 accounts were targeted by the attackers in some way as part of the incident. For a small subset of these accounts, the attackers were able to gain control of the accounts and then send Tweets from those accounts.</p>
<p>— Twitter Support (@TwitterSupport) <a href="https://twitter.com/TwitterSupport/status/1283957911841054721?ref_src=twsrc%5Etfw" target="_blank" rel="noopener noreferrer">July 17, 2020</a></p></blockquote>
<p>   </span></p>
<p>The problem is that the tweets looked normal to anyone following Kanye or Elon Musk, who basically tweet out <a href="https://www.engadget.com/2015-09-08-john-mcafee-2016-presidential-run.html">John McAfee-style crazy claptrap</a> on the regular, and a significant number of people fell for the scam. As we <a href="https://www.engadget.com/twitter-hack-bitcoin-money-laundering-140031258.html">reported yesterday</a>, the haul equaled around $118,000 and “At the time of writing, all but $114 of that $118,000 haul has been transferred to other wallets.”</p>
<p>That&#8217;s a paltry amount of money, especially when, <a href="https://www.glassdoor.com/Salary/Twitter-San-Francisco-Salaries-EI_IE100569.0,7_IL.8,21_IM759.htm" target="_blank" rel="noopener noreferrer">according to Glassdoor</a>, the lower end of what most engineers at Twitter make $131,403 a year. This was an intrusion with enormous impact, the potential for extreme scope, and a serious amount of damage. </p>
<p>You’d assume the attackers wanted more than what it takes to eat and sleep in the poor parts of San Francisco. But again, even though <a href="https://www.vice.com/en_us/article/889mjx/major-twitter-accounts-seemingly-hacked-in-bitcoin-scam" target="_blank" rel="noopener noreferrer">the attack began</a> with a slightly different bitcoin scam, the perpetrators went public immediately, guaranteeing they&#8217;d be found out and shut down right away. </p>
<p>Of course, one very strong possibility is that the attackers were just really bad at crime.</p>
<p>Many observers immediately assumed that these high-profile accounts must have lax security standards, or don’t have two-factor enabled. However, Reuters <a href="https://www.reuters.com/article/us-twitter-cyber-security/twitter-hacking-spree-alarms-experts-concerned-about-the-platforms-security-idUSKCN24H0FE?il=0&amp;utm_medium=Social&amp;utm_source=Twitter" target="_blank" rel="noopener noreferrer">reported</a> that “Several users with two-factor authentication — a security procedure that helps prevent break-in attempts — said they were powerless to stop it.”</p>
<figure><img decoding="async" src="https://www.efrtechgroup.com/wp-content/uploads/2020/07/Twitters-Bitcoin-hackers-had-almost-limitless-access.jpeg" alt="Twitter 'blacklist'" credit="Motherboard / Vice" crediturl="" data-ops=""/></p>
<p>Motherboard / Vice</p>
</figure>
<p>Motherboard <a href="https://www.vice.com/en_us/article/jgxd3d/twitter-insider-access-panel-account-hacks-biden-uber-bezos" target="_blank" rel="noopener noreferrer">obtained anonymous comment from sources</a> at Twitter who said the account takeovers were done via access to an internal account management tool; Vice published screenshots of the tool (while anyone on Twitter publishing the same screenshots got put in Twitter jail real quick).</p>
<p>If Twitter was trying to stop the spread of those images, this is the internet after all. They spread quickly to news sites and forums. The hack’s forbidden screencaps revealed the presence of “blacklist” buttons on individual account pages. Many now want to know, <a href="https://www.xbiz.com/news/253359/twitter-hack-offers-rare-glimpse-into-anti-porn-shadowbanning-practices" target="_blank" rel="noopener noreferrer">is that evidence of shadowban and blacklisting we see</a>? </p>
<p>Twitter users who work in and around human sexuality have for years made a case that they are being “<a href="https://www.engadget.com/2018-07-26-twitter-shadow-ban.html">shadowbanned</a>” by Twitter, the practice of silencing accounts by hiding them in various ways. Only recently have far-right conspiracy theorists <a href="https://www.engadget.com/2018-09-05-twitter-shadow-banning-bug-accounts-jack-dorsey.html">co-opted the shadowban concept</a> to “play the [censorship] refs” in their favor. Now Twitter will be facing direct questions it has struggled to <a href="https://www.engadget.com/2018-07-26-twitter-shadow-ban.html">avoid confronting head-on</a>.</p>
<p>When reached for comment about “blacklist” buttons seen on account pages in Twitter’s compromised management tool, Tthe company’s spokesperson did not directly address the question. Instead, they said via email, “Since July 2018<a href="https://blog.twitter.com/official/en_us/topics/company/2018/Setting-the-record-straight-on-shadow-banning.html" target="_blank" rel="noopener noreferrer"> we’ve made clear</a> that we do not shadowban.” </p>
<p>Twitter’s rep included a boilerplate listing Twitter policy on Trends content inclusion and exclusion, content newsworthiness, trending topic hashtag exclusion policy, and <a href="https://help.twitter.com/en/rules-and-policies/twitter-search-policies" target="_blank" rel="noopener noreferrer">search rules and restrictions</a>.</p>
<p>A different source told Motherboard the allegedly compromised Twitter employee was paid for their participation in the low-rent bitcoin scheme. “A Twitter spokesperson told Motherboard that the company is still investigating whether the employee hijacked the accounts themselves or gave hackers access to the tool,” Vice wrote.</p>
<p><span>   </p>
<blockquote class="twitter-tweet">
<p>Turns out having an unregulated cartoon crime currency and policy conducted by planetary internet chatroom had some easily forseeable drawbacks</p>
<p>— Pinboard (@Pinboard) <a href="https://twitter.com/Pinboard/status/1283616868469633025?ref_src=twsrc%5Etfw" target="_blank" rel="noopener noreferrer">July 16, 2020</a></p></blockquote>
<p>   </span></p>
<p>Since the tool allowed account management, this confirmed early speculation that the attackers not only had the ability to change account emails and reset passwords, but that it also granted them access to the targeted users’ direct messages (DMs). That is a breathtaking problem, considering that many people — including celebrities and politicians — don’t understand that Twitter DMs are not protected with end-to-end encryption, and are not particularly secure.</p>
<p>Senator Ed Markey (D-MA) addressed exactly that in a statement saying Twitter must fully disclose what happened and what it is doing to ensure this never happens again”. This was in addition to Senator Josh Hawley (R-MO) firing off an angry letter to Jack Dorsey, and Senator Ron Wyden (D-OR) issuing a similar statement, adding “this is a vulnerability that has gone on too long.”</p>
<figure><img decoding="async" src="https://www.efrtechgroup.com/wp-content/uploads/2020/07/1595021232_311_Twitters-Bitcoin-hackers-had-almost-limitless-access.jpeg" alt="U.S. Senator Ron Wyden, D-Ore., speaks at a Senate Finance Committee hearing on President Donald Trump's 2020 Trade Policy Agenda on Capitol Hill in Washington, D.C., U.S., June 17, 2020. Anna Moneymaker/Pool via REUTERS" credit="POOL New / Reuters" crediturl="" data-ops=""/></p>
<p>POOL New / Reuters</p>
</figure>
<p>Which is an interesting point to make, if the “vulnerability” in question was a paid-off employee — the vulnerability was human. That means the attack wasn’t necessarily as technical as it was a pretty capital feat of social engineering. This would most likely be a quid pro quo social engineering attack, where the human vulnerability is offered something in exchange for the access, information, or credentials the attacker wants. </p>
<p>It’s also plausible that the attacker used pretexting, where they pretend to be a person with a legitimate need for access, relying on the victim’s trust and gullibility. (“No, I swear, I really <em>need</em> to get in that server closet.”) Another possibility would be baiting, or a bait-and-switch in which the attacker might trick an employee into inserting a malicious USB stick or file into a computer to compromise it.</p>
<p>While this is certainly a huge black eye for Twitter, what might be more interesting to explore is what the attack tells us about who did this, and why. Which is something we’ll most likely find out, based on my colleague’s excellent point that bitcoin is not actually anonymous, and hiding the loot conversion trail is not trivial. Certainly not for hackers who decided to make what could have been the heist of the century into a clumsy bitcoin smash and grab &#8212; and didn’t even ban a single Nazi in the process.</p>
</p></div>
<p><script async src="http://platform.twitter.com/widgets.js" charset="utf-8"></script><br />
<br />[ad_2]<br />
<br /><a href="https://www.engadget.com/twitter-bitcoin-scam-social-engineering-hack-access-193040357.html">Source link </a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>&#8216;Roblox&#8217; insider sold user data access to a hacker</title>
		<link>https://www.efrtechgroup.com/tech/roblox-insider-sold-user-data-access-to-a-hacker/</link>
		
		<dc:creator><![CDATA[Randall]]></dc:creator>
		<pubDate>Mon, 04 May 2020 22:01:38 +0000</pubDate>
				<category><![CDATA[data breach]]></category>
		<category><![CDATA[Games]]></category>
		<category><![CDATA[Gaming]]></category>
		<category><![CDATA[gear]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[roblox]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[Tech]]></category>
		<category><![CDATA[Video Games]]></category>
		<guid isPermaLink="false">https://www.efrtechgroup.com/roblox-insider-sold-user-data-access-to-a-hacker/</guid>

					<description><![CDATA[[ad_1] Hackers don’t necessarily need to break into networks to compromise game companies — sometimes, it’s just about coercing the right people. An anonymous attacker talking to Motherboard has revealed that they bribed a Roblox customer support representative to get access to the customer support panel for the online game platform. The intruder could see [&#8230;]]]></description>
										<content:encoded><![CDATA[<p> [ad_1]<br />
</p>
<div>
<p>Hackers don’t necessarily need to break into networks to <a href="https://www.engadget.com/2017-06-08-hackers-swipe-witcher-3-cyberpunk.html">compromise game companies</a> — sometimes, it’s just about coercing the right people. An anonymous attacker <a href="https://www.vice.com/en_us/article/qj4ddw/hacker-bribed-roblox-insider-accessed-user-data-reset-passwords" target="_blank" rel="noopener noreferrer">talking</a> to <em>Motherboard</em> has revealed that they bribed a <em>Roblox</em> customer support representative to get access to the customer support panel for the online game platform. The intruder could see email addresses, change passwords, strip two-factor authentication and even ban users.</p>
<p>This was done solely to “prove a point,” the hacker claimed. As evidence, they provided photos showing details of a handful of players, including high-profile examples. However, this wasn’t a strictly virtuous act — the perpetrator changed passwords for two accounts, sold items and updated two-factor settings once it became clear an attempt to claim a bug bounty (for a non-existent flaw) wasn’t going to work.</p>
</p></div>
<p>[ad_2]<br />
<br /><a href="https://www.engadget.com/hacker-pays-roblox-worker-for-user-data-access-220138846.html">Source link </a></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
