attackers – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Mon, 04 Aug 2025 08:35:50 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 attackers – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Attackers exploit link-wrapping services to steal Microsoft 365 logins https://earlybirdsinvest.com/attackers-exploit-link-wrapping-services-to-steal-microsoft-365-logins/ https://earlybirdsinvest.com/attackers-exploit-link-wrapping-services-to-steal-microsoft-365-logins/#respond Mon, 04 Aug 2025 08:35:50 +0000 https://earlybirdsinvest.com/attackers-exploit-link-wrapping-services-to-steal-microsoft-365-logins/

A threat actor has been abusing link wrapping services from reputed technology companies to mask malicious links leading to Microsoft 365 phishing pages that collect login credentials.

The attacker exploited the URL security feature from cybersecurity company Proofpoint and cloud communications firm Intermedia in campaigns from June through July.

Some email security services include a link wrapping feature that rewrites the URLs in the message to a trusted domain and passes them through a scanning server designed to block malicious destinations.

Legitimizing phishing URLs

Cloudflare’s Email Security team discovered that the adversary legitimized the malicious URLs after compromising Proofpoint and Intermedia-protected email accounts, and likely used their unauthorized access to distribute the “laundered” links.

“Attackers abused Proofpoint link wrapping in a variety of ways, including multi-tiered redirect abuse with URL shorteners via compromised accounts,” the researchers said.

“The Intermedia link wrapping abuse we observed also focused on gaining unauthorized access to email accounts protected by link wrapping“ – Cloudflare Email Security

The threat actor added an obfuscation layer by first shortening the malicious link before sending it from a protected account, which automatically wrapped the link.

The researchers say that the attacker lured victims with fake notifications for voicemail or shared Microsoft Teams documents. At the end of the redirect chain was a Microsoft Office 365 phishing page that collected credentials.

Microsoft 365 phishing delivered by exploiting link-wrapping feature
Microsoft 365 phishing delivered by exploiting link-wrapping feature
source: Cloudflare Email Security

In the campaign that abused Intermedia’s service, the threat actor delivered emails pretending to be a “Zix” secure message notification for a viewing a secure document, or impersonated a communication from Microsoft Teams informing of a newly received message.

The link allegedly leading to the document was a URL wrapped by Intermedia’s service and redirected to a fake page from digital and email marketing platform Constant Contact hosting the phishing page.

Clicking on the reply button in the fake Teams notification led to a Microsoft phishing page that would collect login credentials.

By disguising the malicious destinations with legitimate email protection URLs, the threat actor increased the chances of a successful attack, the Cloudflare researchers said.

It should be noted that abusing legitimate services to deliver malicious payloads is not new but exploiting the link-wrapping security feature is a recent development on the phishing scene.

Picus Red Report 2025

Malware targeting password stores surged 3X as attackers executed stealthy Perfect Heist scenarios, infiltrating and exploiting critical systems.

Discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/attackers-exploit-link-wrapping-services-to-steal-microsoft-365-logins/feed/ 0 51383
Crypto Investor Tim Heath Fought Attackers, Dodged Kidnapping Attempt https://earlybirdsinvest.com/crypto-investor-tim-heath-fought-attackers-dodged-kidnapping-attempt/ https://earlybirdsinvest.com/crypto-investor-tim-heath-fought-attackers-dodged-kidnapping-attempt/#respond Thu, 03 Jul 2025 08:40:12 +0000 https://earlybirdsinvest.com/crypto-investor-tim-heath-fought-attackers-dodged-kidnapping-attempt/

Tim Heath, an Australian crypto investor, fought off a kidnapping attempt in Estonia after being attacked inside his apartment building, according to a July 2 report by Eesti Ekspress.

According to prosecutors, a group of seven had followed Heath for days and even placed a tracker on his car. Two men, dressed as painters, approached him in the stairwell and tried to drag him into a waiting van.

One of the attackers, identified as Allahverdi Allahverdiyev, covered Heath’s mouth to stop him from shouting. Heath bit through the man’s finger during the struggle and managed to run back into his apartment. He reportedly lost a tooth in the process.

Bullish vs Bearish Markets: How to Predict it? (Animated)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Investigators said the attackers planned to take Heath to a rented sauna and force him to hand over his crypto holdings. The group is accused of entering Estonia using fake Georgian passports.

Before the attack, they bought painter uniforms and tools to disguise themselves as workers. The plan also involved a hacker to help transfer the digital assets.

Allahverdiyev claimed he pretended to go along with the plan but later told others to call it off, despite being promised €100,000. Another suspect, Georgian citizen Ilgar Mamedov, said he was only passing through Estonia. The alleged leader of the group, Najaf Najafli, and two others remain at large.

After the incident, Heath received a message on Telegram that included photos of his home and demanded 30 Bitcoin
BTC


$109,236.58

, worth about $3.3 million at the time. He did not reply, and no further contact was made.

Tushal Rathod from New York was recently accused of using fake checks and email scams to collect nearly $1.7 million, and converting most of it into Bitcoin. How did the case unfold? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/crypto-investor-tim-heath-fought-attackers-dodged-kidnapping-attempt/feed/ 0 45502
64,000,000 T-Mobile Records Containing Highly Sensitive Customer Data Allegedly Leaked Online As Mobile Giant Refutes Attackers’ Claims https://earlybirdsinvest.com/64000000-t-mobile-records-containing-highly-sensitive-customer-data-allegedly-leaked-online-as-mobile-giant-refutes-attackers-claims/ https://earlybirdsinvest.com/64000000-t-mobile-records-containing-highly-sensitive-customer-data-allegedly-leaked-online-as-mobile-giant-refutes-attackers-claims/#respond Sat, 14 Jun 2025 11:24:15 +0000 https://earlybirdsinvest.com/64000000-t-mobile-records-containing-highly-sensitive-customer-data-allegedly-leaked-online-as-mobile-giant-refutes-attackers-claims/

Hackers say they just posted a massive new trove of T-Mobile customer data online – but the details of the data dump are in question.

Cyber thieves uploaded the data to a popular dark web forum, according to Cybernews.

The outlet’s researchers say a sample of the data appears to contain some emails linked to prior T-Mobile breaches, along with “some new data points not seen in previous T-Mobile attacks.”

But the mobile giant says the malicious actors are flat-out lying.

“Any reports of a T-Mobile data breach are inaccurate. We have reviewed the sample data provided and can confirm the data does not relate to T-Mobile or our customers.”

Researchers say the data contains full names, dates of birth, tax IDs, addresses, phone numbers, email addresses, device IDs, cookie IDs and IP addresses.

“If this data is legitimate, exposing 64M lines of highly sensitive information poses a serious threat of identity theft/fraud, surveillance, and further, better-targeted attacks on customers.”

The alleged data dump comes as 76 million T-Mobile customers begin to receive their share of a $350 million payout following a 2021 data breach and class action settlement.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/64000000-t-mobile-records-containing-highly-sensitive-customer-data-allegedly-leaked-online-as-mobile-giant-refutes-attackers-claims/feed/ 0 41975
AI Tool Helps Biker Catch Gurugram Attackers via Instagram https://earlybirdsinvest.com/ai-tool-helps-biker-catch-gurugram-attackers-via-instagram/ https://earlybirdsinvest.com/ai-tool-helps-biker-catch-gurugram-attackers-via-instagram/#respond Tue, 22 Apr 2025 23:16:53 +0000 https://earlybirdsinvest.com/ai-tool-helps-biker-catch-gurugram-attackers-via-instagram/

An artificial intelligence (AI) tool helped a Gurugram biker trace the men who assaulted him and his group before the police were able to identify them.

According to a report from NDTV, a group of men, believed to be drunk, stopped Hardik Sharma and ten others on the Dwarka Expressway and began hitting them and damaging their motorcycles.

Sharma said he rode away but returned on foot when he realized a friend might have been left behind. By the time he got back, that friend had already left, and one of the men had taken hold of Sharma’s motorcycle.

What is a MetaMask Wallet? (And How to Use it - Animated)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

He mentioned that the attackers warned him not to record videos. “They also said that they will shoot me if I shoot their videos”, Sharma said.

He added that registering a police report was another challenge. Sharma had to visit several police stations before his complaint was accepted. It took about 12 hours for the FIR to be filed.

Frustrated by the delay, Sharma decided to use AI tools that analyze photos and videos to trace the attackers. “We use some paid AIs on which if you upload photos or videos, it can lead you to the social media of the person in them if they have a public profile”, he explained.

He also shared the gym where the men were believed to work out, along with other related media, with the police.

Meanwhile, the UK Ministry of Justice has recently been developing an AI tool to predict violent crimes. How does it work? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/ai-tool-helps-biker-catch-gurugram-attackers-via-instagram/feed/ 0 32283
Microsoft says attackers use exposed ASP.NET keys to deploy malware https://earlybirdsinvest.com/microsoft-says-attackers-use-exposed-asp-net-keys-to-deploy-malware/ https://earlybirdsinvest.com/microsoft-says-attackers-use-exposed-asp-net-keys-to-deploy-malware/#respond Thu, 06 Feb 2025 22:55:26 +0000 https://earlybirdsinvest.com/microsoft-says-attackers-use-exposed-asp-net-keys-to-deploy-malware/

Key

Microsoft warns that attackers are deploying malware in ViewState code injection attacks using static ASP. NET machine keys found online.

As Microsoft Threat Intelligence experts recently discovered, some developers use ASP.NET validationKey and decryptionKey keys (designed to protect ViewState from tampering and information disclosure) found on code documentation and repository platforms in their own software.

However, threat actors also use machine keys from publicly available sources in code injection attacks to create malicious ViewStates (used by ASP.NET Web Forms to control state and preserve pages) by attaching crafted message authentication code (MAC).

When loading the ViewStates sent via POST requests, the ASP.NET Runtime on the targeted server decrypts and validates the attackers’ maliciously crafted ViewState data because it uses the right keys, loads it into the worker process memory, and executes it.

This allows them to execute code remotely on the IIS server and deploy additional malicious payloads.

In one instance observed in December 2024, an unattributed attacker used a publicly known machine key to deliver the Godzilla post-exploitation framework, which comes with malicious command execution and shellcode injection capabilities, to a targeted Internet Information Services (IIS) web server.

ViewState code injection attack chain
ViewState code injection attack chain (Microsoft)

“Microsoft has since identified over 3,000 publicly disclosed keys that could be used for these types of attacks, which are called ViewState code injection attacks,” the company said on Thursday.

“Whereas many previously known ViewState code injection attacks used compromised or stolen keys that are often sold on dark web forums, these publicly disclosed keys could pose a higher risk because they are available in multiple code repositories and could have been pushed into development code without modification.”

To block such attacks, Microsoft recommends developers securely generate machine keys, not use default keys or keys found online, encrypt machineKey and connectionStrings elements to block access to plaintext secrets, upgrade apps to use ASP.NET 4.8 to enable Antimalware Scan Interface (AMSI) capabilities, and harden Windows Servers by using attack surface reduction rules such as Block Webshell creation for Servers.

Microsoft also shared detailed steps for removing or replacing ASP.NET keys in the web.config configuration file using either PowerShell or the IIS manager console and removed key samples from its public documentation to further discourage this insecure practice.

“If successful exploitation of publicly disclosed keys has occurred, rotating machine keys will not sufficiently address possible backdoors or persistence methods established by a threat actor or other post-exploitation activity, and additional investigation may be warranted,” Redmond warned.

“In particular, web-facing servers should be fully investigated and strongly considered for re-formatting and re-installation in an offline medium in cases where publicly disclosed keys have been identified, as these servers are most at risk of possible exploitation.”

]]>
https://earlybirdsinvest.com/microsoft-says-attackers-use-exposed-asp-net-keys-to-deploy-malware/feed/ 0 17857