• About the Author

  • 26
    Apr 19

    P2P Weakness Exposes Millions of IoT Devices

    DC Retro Mego Kresge Style Shazam Dr Sivana Series 1 Action Figure

    Apr 19

    The owner of a Swedish company behind a popular remote administration tool (RAT) implicated in thousands of malware attacks shares the same name as a Swedish man who pleaded guilty in 2015 to co-creating the Blackshades RAT, a similar product that was used to infect more than half a million computers with malware, KrebsOnSecurity has learned.

    An advertisement for RevCode WebMonitor.

    At issue is a program called “WebMonitor,” which was designed to allow users to remotely control a computer (or multiple machines) via a Web browser. The makers of WebMonitor, a company in Sweden called “RevCode,” say their product is legal and legitimate software “that helps firms and personal users handle the security of owned devices.”

    MARVEL SELECT di full brood LEGENDS fantastic four 4 toy biz universe hasbro lee

    But critics say WebMonitor is far more likely to be deployed on “pwned” devices, or those that are surreptitiously hacked. The software is broadly classified as malware by most antivirus companies, likely thanks to an advertised feature list that includes dumping the remote computer’s temporary memory; retrieving passwords from dozens of email programs; snarfing the target’s Wi-Fi credentials; and viewing the target’s Webcam.

    Dorbz Ridez Cereal Fruit Brute with Ride MIB Funko limited to 1500 GITD

    In DC Collectibles DC Comics Injustice 2 Harley Quinn Exclusive Statue New, researchers from security firm Palo Alto Networks noted that the product has been primarily advertised on underground hacking forums, and that its developers promoted several qualities of the software likely to appeal to cybercriminals looking to secretly compromise PCs.

    Marvel Legends Action Figure SongbirdFormer adgreenising display stand cardboard Bob Morane Vernes CoriaMedicom Marvel Hero Sofubi Vision Figure avengersSuper Heroes- Harley Quinn with Mallet (Pink Hearts) Funko Pop Vinyl

    For example, RevCode’s website touted the software’s compatibility with all “crypters,” software that can encrypt, obfuscate and manipulate malware to make it harder to detect by antivirus programs. Palo Alto also noted WebMonitor includes the option to suppress any notification boxes that may pop up when the RAT is being installed on a computer.

    A screenshot of the WebMonitor builder panel.

    RevCode maintains it is a legitimate company officially registered in Sweden that obeys all applicable Swedish laws. A few hours of searching online turned up an interesting record at DC Justice League Movie action figures FLASH Wonder Woman BATMAN Guard MATTEL, a credit information service based in Sweden. That record indicates RevCode is owned by 28-year-old Swedish resident Alex Yücel.

    DC Retro Mego Kresge Style Super Friends Sinestro Series 5 Action Figure

    In February 2015, a then 24-year-old Alex Yücel Batman Animated Series Figurines Set Penguin and Scarecrow FIGURE EAGLEMOSS to computer hacking and to creating, marketing and selling DC Universe Infinite Heroes 75 Years WONDER WOMAN 3.75 Action Figure Mattel, a RAT that was used to compromise and spy on hundreds of thousands of computers. Arrested in Moldova in 2013 as part of a large-scale, international takedown against Blackshades and hundreds of customers, Yücel became the first person ever to be extradited from Moldova to the United States. Ghost Rider 3 BlazeAction Figures TOYBIZ 1996 Marvel

    blueE BEETLE INFINITE CRISIS DC Icons figure PVC 16cm of DC Direct
    Apr 19

    Marcus “MalwareTech” Hutchins Pleads Guilty to Writing, Selling Banking Malware

    Marcus Hutchins, a 24-year-old blogger and malware researcher arrested in 2017 for allegedly authoring and selling malware designed to steal online banking credentials, has pleaded guilty to criminal charges of conspiracy and to making, selling or advertising illegal wiretapping devices.


    Marcus Hutchins, just after he was revealed as the security expert who stopped the WannaCry worm. Image: twitter.com/malwaretechblog

    Hutchins, who authors the popular blog Diamond select Marvel Hulk action figure, was virtually unknown to most in the security community until May 2017 when the U.K. media revealed him as the “accidental hero” who inadvertently halted the global spread of Marvel Legends - X-Men 6 Action Figure - Deadpool 2016 Hasbro, a ransomware contagion that had taken the world by storm just days before.

    MARVEL LEGENDS ICONS Series Collection_YELLOW DAREDEVIL 12 figure_New_Unopened

    In August 2017, Hutchins was arrested by FBI agents in Las Vegas on suspicion of authoring and/or selling “Kronos,” a strain of malware designed to steal online banking credentials. A British citizen, Hutchins has been barred from leaving the United States since his arrest.

    Many of Hutchins’ supporters and readers had trouble believing the charges against him, and in response KrebsOnSecurity 2007 GI JOE 25TH ANNIVERSARY COBRA NINJA STORM SHADOW 4 FIGURE FACTORY SEALED into activities tied to his various online personas over the years.

    Imaginext DC Super Friends, Batman BeyondGUARDIANS OF THE GALAXY STAR-LORD UNMASKED POP VINYL FIGURE EXCLUSIVEStar Wars Action Figure Bundle aMarvel Legends Series HULK 14 Articulated Action Figure MINTBatman Hush Jim Lee Collector Action Figure by DC Direct New Sealed HTF

    As I wrote in summary of that story, the clues suggested “Hutchins began developing and selling malware in his mid-teens — only to later develop a change of heart and earnestly endeavor to leave that part of his life squarely in the rearview mirror.” Nevertheless, there were a number of indications that Hutchins’ alleged malware activity continued into his adulthood.

    DC Comics Designer Serie 7 Actionfigur Harley Quinn by Darwin Cooke

    In (2) DC Comics Super Heroes Die Cast MetalPenguinSupermanBatmanRobin & Joker posted to DC First Appearance Series 1 Wonder Woman Action Figure and to malwaretech.com, Hutchins said today he had pleaded guilty to two charges related to writing malware in the years prior to his career in security. Continue reading →

    Apr 19

    Apr 19
    Marvel Play Arts Kai Deadpool VARIANT 10 PVC Action Figure Collectible Toy+box

    Apr 19

    Experts: Breach at IT Outsourcing Giant Wipro

    Indian information technology (IT) outsourcing and consulting giant Wipro Ltd. [Green Lantern Classics Justice Society ALAN SCOT action figure] is investigating reports that its own IT systems have been hacked and are being used to launch attacks against some of the company’s customers, multiple sources tell KrebsOnSecurity. Wipro has refused to respond to questions about the alleged incident.

    DC Gallery Catwoman 9-Inch Collectible PVC Statue

    Earlier this month, KrebsOnSecurity heard independently from two trusted sources that Wipro — India’s third-largest IT outsourcing company — was dealing with a multi-month intrusion from an assumed state-sponsored attacker.

    Both sources, who spoke on condition of anonymity, said Wipro’s systems were seen being used as jumping-off points for digital fishing expeditions targeting at least a dozen Wipro customer systems.

    Marvel Legends 13 Onslaught Series Crown of Lies Loki Variant Figure - ToybizEaglemoss DC - DC Universe Collector's Bust WW Movie and Mag PREORDERBatman The New Batman Adventures - Scarecrow 6 inch Figure - DC Comics Free ShiDC Collectibles Animated Justice League JLU Exclusive Aquaman MIB

    The security experts said Wipro’s customers traced malicious and suspicious network reconnaissance activity back to partner systems that were communicating directly with Wipro’s network.

    Pottery Barn Kids DC Comics Wooden Car & 5 Figures Set

    On Friday, Apr. 12, Nair sent a statement that acknowledged none of the questions Wipro was asked about an alleged security incident involving attacks against its own customers.

    Marvel Legends BAF Ronan The Accuser Series Mr Fantastic 11 inch action figure

    Wipro has not responded to multiple additional requests for comment. Since then, two more sources with knowledge of the investigation have come forward to confirm the outlines of the incident described above.


    Hasbro Marvel Legends Deadpool with Scooter 6 Figure Vehicle Set - New

    DC JLA Justice League of America THE FLASH 10 Fully Poseable Figure Hasbro NIP
    Apr 19
    New Diamond Select Marvel Modern Iron Man Action Figure
    McFarlane Toys Spawn Series 31 Necro Cop Action Figure MIB Sealed Complete New

    Apr 19


    Marvel Legends Captain America Series 1 with Bonus Comic Book NEW SEALED
    Apr 19

    Marvel Comics Now Emma Frost ArtFX+ 1 10th scale Statue X-Men Figure Kotobukiya

    A Year Later, Cybercrime Groups Still Rampant on Facebook

    Marvel Iron Fist Gallery Statue by Diamond Select