breached – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Sat, 26 Jul 2025 04:46:19 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 breached – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Women’s safety app Tea breached, leaking 13,000 user photos to 4chan https://earlybirdsinvest.com/womens-safety-app-tea-breached-leaking-13000-user-photos-to-4chan/ https://earlybirdsinvest.com/womens-safety-app-tea-breached-leaking-13000-user-photos-to-4chan/#respond Sat, 26 Jul 2025 04:46:19 +0000 https://earlybirdsinvest.com/womens-safety-app-tea-breached-leaking-13000-user-photos-to-4chan/

A dating safety app designed to protect women has exposed the very users it promised to shield. Tea, which recently topped Apple’s App Store charts, suffered a data breach that leaked 13,000 verification photos and government IDs of its female users, as reported by NBC News.

The hack came after users on 4chan called for a “hack and leak” campaign against the platform. Tea requires women to submit selfies and identification to verify their gender before they can join the service, where they share information about men they’ve dated, marking them as “red flags” or “green flags.”

The company confirmed that attackers accessed a two-year-old database containing approximately 72,000 images. A Tea spokesperson told NBC News the stored data “was originally stored in compliance with law enforcement requirements related to cyberbullying prevention.”

Tea was created by Sean Cook after witnessing his mother’s “terrifying experience with online dating,” including encounters with catfishers and men with undisclosed criminal records.

The breach has already had real-world consequences. Users on 4chan and X have been sharing the stolen photos, and someone created a Google Map showing coordinates of affected Tea users, though without names or addresses.

“Protecting our users’ privacy and data is our highest priority. Tea is taking every necessary step to ensure the security of our platform and prevent further exposure,” the Tea spokesperson told NBC News. Are they going to hire security details for all 13,000 women who’ve been doxxed?

Previously:
• A quantitative analysis of doxing: who gets doxed, and how can we detect doxing automatically?

]]>
https://earlybirdsinvest.com/womens-safety-app-tea-breached-leaking-13000-user-photos-to-4chan/feed/ 0 49712
Malware campaign ‘DollyWay’ breached 20,000 WordPress sites https://earlybirdsinvest.com/malware-campaign-dollyway-breached-20000-wordpress-sites/ https://earlybirdsinvest.com/malware-campaign-dollyway-breached-20000-wordpress-sites/#respond Thu, 20 Mar 2025 04:17:14 +0000 https://earlybirdsinvest.com/malware-campaign-dollyway-breached-20000-wordpress-sites/

WordPress

A malware operation dubbed ‘DollyWay’ has been underway since 2016, compromising over 20,000 WordPress sites globally to redirect users to malicious sites.

The campaign has evolved significantly in the past eight years, leveraging advanced evasion, re-infection, and monetization strategies.

According to GoDaddy researcher Denis Sinegubko, DollyWay has been functioning as a large-scale scam redirection system in its latest version (v3). However, in the past, it has distributed more harmful payloads like ransomware and banking trojans.

“GoDaddy Security researchers have uncovered evidence linking multiple malware campaigns into a single, long-running operation we’ve named ‘DollyWay World Domination’,” explains a recent report by Godaddy.

“While previously thought to be separate campaigns, our research reveals these attacks share common infrastructure, code patterns, and monetization methods – all appearing to be connected to a single, sophisticated threat actor.

“The operation was named after the following tell-tale string, which is found in some variations of the malware: define(‘DOLLY_WAY’, ‘World Domination’).”

Thousands of stealthy infections

DollyWay v3 is an advanced redirection operation that targets vulnerable WordPress sites using n-day flaws on plugins and themes to compromise them.

As of February 2025, DollyWay generates 10 million fraudulent impressions per month by redirecting WordPress site visitors to fake dating, gambling, crypto, and sweepstakes sites.

Landing page DollyWay redirects victims to
Landing page DollyWay redirects victims to
Source: GoDaddy

The campaign is monetized through VexTrio and LosPollos affiliate networks after filtering visitors through a Traffic Direction System (TDS).

A Traffic Distribution System analyzes and redirects web traffic based on various aspects of a visitor, such as their location, device type, and referrer. Cybercriminals commonly use malicious TDS systems to redirect users to phishing sites or malware downloads.

The websites are breached via a script injection with ‘wp_enqueue_script,’ which dynamically loads a second script from the compromised site.

The second stage collects visitor referrer data to help categorize the redirection traffic and then loads the TDS script that decides on the validity of the targets.

Direct website visitors that have no referrer, are not bots (the script has a hardcoded list of 102 known bot user-agents), and are not logged-in WordPress users (including admins) are considered invalid and are not redirected.

The third stage selects three random infected sites to serve as TDS nodes and then loads hidden JavaScript from one of them to perform the final redirection to VexTrio or LosPollos scam pages.

JavaScript snippet designed to perform conditional redirection to a scam website
JavaScript snippet that performs conditional redirection to a scam website
Source: GoDaddy

The malware uses affiliate tracking parameters to ensure attackers get paid for each redirection.

It’s worth noting that the final redirect only occurs when the visitor interacts with a page element (clicks), evading passive scanning tools that only examine page loads.

Auto-reinfection ensures persistence

Sinegubko explains that DollyWay is a very persistent threat that automatically reinfects a site with every page load, so removing it is particularly hard.

It achieves this by spreading its PHP code across all active plugins and also adds a copy of the WPCode plugin (if not already installed) that contains obfuscated malware snippets.

WPCode is a third-party plugin allowing admins to add small snippets of “code” that modify WordPress functionality without directly editing theme files or WordPress code.

Obfuscated PHP code injected into plugins
Obfuscated PHP code injected into plugins
Source: GoDaddy

As part of an attack, the hackers hide WPCode from the WordPress plugin list so administrators cannot see or delete it, making disinfection complicated.

DollyWay also creates admin users named after random 32-character hex strings and keeps those accounts hidden in the admin panel. They are only visible through direct database inspection.

GoDaddy shared the complete list of the indicators of compromise (IoCs) associated with DollyWay to help defend against this threat. 

It will publish more details about the operation’s infrastructure and shifting tactics in a follow-up post.

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/malware-campaign-dollyway-breached-20000-wordpress-sites/feed/ 0 26142
Australian IVF giant Genea breached by Termite ransomware gang https://earlybirdsinvest.com/australian-ivf-giant-genea-breached-by-termite-ransomware-gang/ https://earlybirdsinvest.com/australian-ivf-giant-genea-breached-by-termite-ransomware-gang/#respond Wed, 26 Feb 2025 15:16:27 +0000 https://earlybirdsinvest.com/australian-ivf-giant-genea-breached-by-termite-ransomware-gang/

Genea

​The Termite ransomware gang has claimed responsibility for breaching and stealing sensitive healthcare data belonging to Genea patients, one of Australia’s largest fertility services providers.

The IVF (in vitro fertilization) provider has been operating since 1986 (when it was known as Sydney IVF). It offers a wide range of services, including fertility treatments, tests, genetic services, preservation options, and donor programs, in 22 fertility clinics in New South Wales, South Australia, Western Australia, Melbourne, Canberra, and Queensland.

According to Australia’s national broadcaster, Genea and two other companies (Monash IVF and Virtus) account for over 80% of the industry’s total revenue in the country.

Genea first revealed last Wednesday it was investigated a “cyber incident” after detecting “suspicious activity” on its network. In an updated statement issued today, the fertility services giant confirmed the attackers stole data from its systems, which was later published online.

The company said it obtained a court-ordered injunction to prevent the leaked data from being shared by others, and it’s also working with the Office of the Australian Information Commissioner and the Australian Cyber Security Centre to investigate an incident.

The redacted court order reveals that the threat actors breached Genea’s network on January 31, 2025, through a Citrix server. Subsequently, they gained access to the company’s primary file server, domain controller, backup program, and BabySentry primary patient management system. Two weeks later, on February 14, the attackers exfiltrated 940.7GB of data from Genea’s compromised systems to a DigitalOcean cloud server under their control.

The ongoing investigation also discovered that Genea’s compromised patient management systems contained the following types of personal and health data, with the exposed information varying for each affected individual: 

  • Full names, emails, addresses, phone numbers, date of birth, emergency contacts, and next of kin,
  • Medicare card numbers, private health insurance details, Defence DA numbers, medical record numbers, patient numbers,
  • Medical history, diagnoses and treatments, medications and prescriptions, patient health questionnaire, pathology and diagnostic test results, notes from doctors and specialists, appointment details, and schedules.

“At this stage there is no evidence that any financial information such as credit card details or bank account numbers have been impacted by this incident,” Genea added.

“The investigation is however ongoing, and we will keep you updated of any relevant further findings should they come to light.”

A Genea spokesperson has not replied to several requests for comment since the company disclosed the breach on February 19.

Breach claimed by Termite ransomware

While Genea didn’t attribute the attack to a specific threat group or cybercrime operation, the Termite ransomware gang claimed responsibility on Monday.

In a new entry on their dark web leak site, they said they stole roughly 700GB of data and leaked screenshots of identification documents and patients’ files allegedly stolen from Genea’s network.

“We have ~700gb of data from company’s servers such as confidential, personal data of clients,” the threat actors claim.

Genea entry on Termite's leak site
Genea entry on Termite’s leak site (BleepingComputer)

Termite is a ransomware operation that surfaced in mid-October, according to threat intelligence company Cyjax, and has since listed 18 victims on its dark web portal from all over the world and various industry sectors.

In December, the ransomware gang also claimed to have breached the network of Arizona-based service (SaaS) provider Blue Yonder. This worldwide supply chain software provider has over 3,000 customers, including high-profile companies such as Microsoft, Renault, Bayer, Tesco, Lenovo, DHL, 3M, Ace Hardware, Procter & Gamble, Carlsberg, Dole, Wallgreens, Western Digital, and 7-Eleven.

Like other ransomware gangs, the Termite cybercrime group is involved in data theft, extortion, and encryption attacks. According to cybersecurity firm Trend Micro, they’re using a version of the Babuk encryptor leaked in September 2021 and are known to drop a “How To Restore Your Files.txt” ransom note on the victims’ encrypted systems.

Trend Micro also added that Termite’s ransomware encryptor is still likely a work in progress, as it will terminate prematurely due to a code execution flaw.

]]>
https://earlybirdsinvest.com/australian-ivf-giant-genea-breached-by-termite-ransomware-gang/feed/ 0 22007
Ghost ransomware breached orgs in 70 countries https://earlybirdsinvest.com/ghost-ransomware-breached-orgs-in-70-countries/ https://earlybirdsinvest.com/ghost-ransomware-breached-orgs-in-70-countries/#respond Wed, 19 Feb 2025 22:03:28 +0000 https://earlybirdsinvest.com/ghost-ransomware-breached-orgs-in-70-countries/

Ghost

CISA and the FBI said attackers deploying Ghost ransomware have breached victims from multiple industry sectors across over 70 countries, including critical infrastructure organizations.

Other industries impacted include healthcare, government, education, technology, manufacturing, and numerous small and medium-sized businesses.

“Beginning early 2021, Ghost actors began attacking victims whose internet facing services ran outdated versions of software and firmware,” CISA, the FBI, and the Multi-State Information Sharing and Analysis Center (MS-ISAC) said in a joint advisory released on Wednesday.

“This indiscriminate targeting of networks containing vulnerabilities has led to the compromise of organizations across more than 70 countries, including organizations in China.”

Ghost ransomware operators frequently rotate their malware executables, change the file extensions of encrypted files, alter the contents of their ransom notes, and utilize multiple email addresses for ransom communications, which has often led to fluctuating attribution of the group over time.

Names linked to this group include Ghost, Cring, Crypt3r, Phantom, Strike, Hello, Wickrme, HsHarada, and Rapture, with ransomware samples used in their attacks including Cring.exe, Ghost.exe, ElysiumO.exe, and Locker.exe.

This financially motivated ransomware group leverages publicly accessible code to exploit security flaws in vulnerable servers. They target vulnerabilities left unpatched in Fortinet (CVE-2018-13379), ColdFusion (CVE-2010-2861, CVE-2009-3960), and Exchange (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).

To defend against Ghost ransomware attacks, network defenders are advised to take the following measures:

  1. Make regular and off-site system backups that can’t be encrypted by ransomware,
  2. Patch operating system, software, and firmware vulnerabilities as soon as possible,
  3. Focus on security flaws targeted by Ghost ransomware (i.e., CVE-2018-13379, CVE-2010-2861, CVE-2009-3960, CVE-2021-34473, CVE-2021-34523, CVE-2021-31207),
  4. Segment networks to limit lateral movement from infected devices,
  5. Enforce phishing-resistant multi-factor authentication (MFA) for all privileged accounts and email services accounts.

Right after Amigo_A and Swisscom’s CSIRT team first spotted Ghost ransomware in early 2021, their operators were dropping custom Mimikatz samples, followed by CobaltStrike beacons, and deploying ransomware payloads using the legitimate Windows CertUtil certificate manager to bypass security software.

In addition to being exploited for initial access in Ghost ransomware attacks, state-backed hacking groups that scanned for vulnerable Fortinet SSL VPN appliances also targeted the CVE-2018-13379 vulnerability.

Attackers also abused the same security vulnerability to breach Internet-exposed U.S. election support systems reachable over the Internet.

Fortinet warned customers to patch their SSL VPN appliances against CVE-2018-13379 multiple times in August 2019, July 2020, November 2020, and again in April 2021.

The joint advisory issued by CISA, the FBI, and MS-ISAC today also includes indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs), and detection methods linked to previous Ghost ransomware activity identified during FBI investigations as recently as January 2025.

]]>
https://earlybirdsinvest.com/ghost-ransomware-breached-orgs-in-70-countries/feed/ 0 20575