Hackers spoof SBA to try to compromise companies' computers
Full article690 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The hackers are exploiting businesses' reliance on digital updates from the federal government.
With the U.S. Small Business Administration continuing to play a high-profile role in getting cash to companies that are struggling because of the coronavirus pandemic, cybercriminals are stepping up their efforts to steal money from those very firms.
Research published Monday by IBM’s incident response team shows that attackers are spoofing the SBA in emails to try to install a remote hacking tool capable of stealing passwords and accessing webcams. They are exploiting attention on a nascent SBA program that offers up to $10 million in lending per business.
If an unsuspecting recipient opens the emails found by IBM, a data-stealing remote access trojan (RAT) known as Remcos can take control of the person’s computer. It is another example of how, as U.S. agencies have opened their spigots to provide hundreds of billion of dollars in relief to American businesses during the pandemic, cybercriminals have looked to pounce.
The hackers are “exploiting the reliance of … small businesses on digital updates to obtain guidance on how to receive federal aid,” the researchers wrote in a blog.
It’s unclear who is behind the hacking attempts, or how many, if any, small businesses were compromised. The research doesn’t address why crooks are trying to breach companies that might be short on cash while they wait for the SBA’s help. Regardless, cybercriminals are wont to swindle any victim they can. Even companies that were thriving before the health crisis have been queuing up for SBA loans, widening the pool of targets.
Over the last two years, the Remcos RAT, which is promoted for sale by a software company known as BreakingSecurity, has been used in hacking campaigns against international news organizations and Turkish defense contractors, among other sectors.
The emails found by IBM are written in poor grammar, spoofing a “disaster customer service” SBA email address. The researchers think the hackers breached the domain of a legitimate company, which they did not name, in order to send out the phishing emails under the guise of the SBA.
As U.S. lawmakers prepared to pass the first of multiple stimulus packages last month, security analysts were already warning that COVID-19 relief payments would attract a panoply of fraudsters. A month later, the fleecing shows no signs of letting up, with the FBI issuing multiple advisories on COVID-19 scams. Law enforcement agencies have tried to crack down, announcing the takedown of hundreds of fraud-peddling websites last week.
The hacking attempts discovered by IBM come as the SBA is still cleaning up an unrelated data incident from last month. The agency has been notifying nearly 8,000 businesses whose personally identifiable information may have been exposed because of a flaw in the agency’s online loan-application portal.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/small-business-administration-spoof-ibm-coronavirus/