Fraudulent – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Sun, 31 Aug 2025 04:47:57 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Fraudulent – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 TamperedChef infostealer delivered through fraudulent PDF Editor https://earlybirdsinvest.com/tamperedchef-infostealer-delivered-through-fraudulent-pdf-editor/ https://earlybirdsinvest.com/tamperedchef-infostealer-delivered-through-fraudulent-pdf-editor/#respond Sun, 31 Aug 2025 04:47:57 +0000 https://earlybirdsinvest.com/tamperedchef-infostealer-delivered-through-fraudulent-pdf-editor/

TamperedChef infostealer delivered through fraudulent PDF Editor

Threat actors have been using multiple websites promoted through Google ads to distribute a convincing PDF editing app that delivers an info-stealing malware called TamperedChef.

The campaign is part of a larger operation with multiple apps that can download each other, some of them tricking users into enrolling their system into residential proxies.

More than 50 domains have been identified to host deceiving apps signed with fraudulent certificates issued by at least four different companies.

The campaign appears to be widespread and well-orchestrated as the operators waited for the ads to run their course before activating the malicious components in the applications, researchers say.

Full update delivers infostealer

A technical analysis from cybersecurity services company Truesec describes the process of TamperedChef infostealer being delivered to a user’s system.

The researchers discovered that the malware was delivered through multiple websites that promoted a free tool called AppSuite PDF Editor.

Based on internet records, the investigators determined that the campaign started on June 26, when many of the websites involved were either registered or started to advertise AppSuite PDF Editor.

However, the researchers found that the malicious app had been verified through the VirusTotal malware scanning services on May 15th.

It appears that the program behaved normally until August 21st, when it received an update that activated malicious capabilities built to collect sensitive data like credentials and web cookies.

According to Truesec, TamperedChef infostealer is delivered with the “-fullupdate” argument for the PDF editor’s executable.

The malware checks for various security agents on the host. It also queries the databases of installed web browsers using the DPAPI (Data Protection Application Programming Interface) –  a component in Windows that encrypts sensitive data.

TamperedChef infostealer checking for installed security agents
TamperedChef infostealer checking for installed security agents
source: Truesec

Digging deeper for the distribution method, Truesec researchers found evidence suggesting that the threat actor spreading TamperedChef within AppSuites PDF Editor relied on Google advertising to promote the malicious program.

“Truesec has observed at least 5 different google campaign IDs which suggests a widespread campaign” – Truesec

The threat actor likely had a strategy to maximize the number of downloads before activating the malicious component in AppSuites PDF Editor, as they delivered the infostealer just four days before the typical expiration period of 60 days for a Google ad campaign.

Looking further into AppSuites PDF Editor, the researchers found that different versions of the program were signed by certificates “from at least four companies,” among them ECHO Infini SDN BHD, GLINT By J SDN. BHD, and SUMMIT NEXUS Holdings LLC, BHD.

Joining a residential proxy

Truesec found that the operator of this campaign has been active since at least August 2024 and promoted other tools, including OneStart and Epibrowser browsers.

It is worth noting that OneStart is usually flagged as a potentially unwanted program (PUP), which is typically the term for adware.

However, researchers at managed detection and response company Expel also investigated incidents involving AppSuites PDF Editor, ManualFinder, and OneStart, all “dropping highly suspicious files, executing unexpected commands, and turning hosts into residential proxies,” which is closer to malware-like behavior.

They found that OneStart can download AppSuite-PDF (signed by an ECHO INFINI SDN. BHD certificate), which can fetch  PDF Editor.

“The initial downloads for OneStart, AppSuite-PDF, and PDF Editor are being distributed by a large ad campaign advertising PDFs and PDF editors. These ads direct users to one of many websites offering downloads of AppSuite-PDF, PDF Editor, and OneStart,” Expel.

The code-signing certificates used in this campaign have already been revoked, but the risk is still present for current installations.

In some instances of PDF Editor, the app would show users a message asking for permission to use their device as a residential proxy in return for using the tool for free.

The researchers note that the proxy network provider may be a legitimate entity not involved in the campaign and that the operator of PDF Editor is capitalizing as affiliates.

It appears that whoever is behind PDF Editor is trying to maximize their profit at the expense of users worldwide.

Even if the programs in this campaign are considered PUPs, their capabilities are typical of malware and should be treated as such.

The researchers warn that the operation they uncovered involves more apps, some of them not yet weaponized, capable of distributing malware or suspicious files, or executing commands surreptitiously on the system.

Both reports from Truesec and Expel [1, 2] include a large set of indicators of compromise (IoCs) that could help defenders protect users and assets from getting infected.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/tamperedchef-infostealer-delivered-through-fraudulent-pdf-editor/feed/ 0 55991
Woman To Serve Four Years in Prison for Role in $800,000 Business Email Hack That Tricked Victims Into Sending Fraudulent Bank Wires https://earlybirdsinvest.com/woman-to-serve-four-years-in-prison-for-role-in-800000-business-email-hack-that-tricked-victims-into-sending-fraudulent-bank-wires/ https://earlybirdsinvest.com/woman-to-serve-four-years-in-prison-for-role-in-800000-business-email-hack-that-tricked-victims-into-sending-fraudulent-bank-wires/#respond Mon, 16 Jun 2025 06:57:53 +0000 https://earlybirdsinvest.com/woman-to-serve-four-years-in-prison-for-role-in-800000-business-email-hack-that-tricked-victims-into-sending-fraudulent-bank-wires/

An accountant and adjunct business instructor from Scranton, Pennsylvania, is sentenced to federal prison for her involvement in a multi-state business email compromise scheme.

In a statement, the U.S. Attorney’s Office for the Northern District of Iowa says that 63-year-old Margo Ann Williams laundered $800,000 of proceeds from a scheme that was carried out between December 2022 and July 2023.

According to evidence presented at the trial, the email accounts of the five victims – a Cedar Rapids church, two businesses, a non-profit and an individual – were hacked while they were in the process of making large wire and automatic clearinghouse (ACH) transfers. 

The victims received spoofed emails containing instructions to change the routing information for the wire and ACH transfers. Believing that the emails were from legitimate and trusted sources, the victims instructed their banks to wire the funds according to the supposed new payment instructions.

The funds were rerouted to bank accounts that Williams controlled.

She subsequently relocated the funds to other bank accounts under her control before transferring the money to two crypto exchanges and another person in Florida. 

The banks discovered William’s fraudulent activities and closed her accounts, but she kept opening new ones at other banks in an effort to keep the scheme alive. She earned approximately $25,000 from the operation and spent the funds on many personal purchases, including an Apple watch and a luxury bag.

Williams, who claimed that she perpetrated the scheme at the direction of a famous British actor with whom she became romantically involved, was sentenced to four years in prison. She’s also ordered to pay $594,037 in restitution to her victims and must also serve a three-year term of supervised release following her imprisonment.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/woman-to-serve-four-years-in-prison-for-role-in-800000-business-email-hack-that-tricked-victims-into-sending-fraudulent-bank-wires/feed/ 0 42296
Feds Charge Atlanta Man for Allegedly Applying for Over $3,390,000 in Fraudulent Small Business Loans During COVID https://earlybirdsinvest.com/feds-charge-atlanta-man-for-allegedly-applying-for-over-3390000-in-fraudulent-small-business-loans-during-covid/ https://earlybirdsinvest.com/feds-charge-atlanta-man-for-allegedly-applying-for-over-3390000-in-fraudulent-small-business-loans-during-covid/#respond Thu, 22 May 2025 03:48:44 +0000 https://earlybirdsinvest.com/feds-charge-atlanta-man-for-allegedly-applying-for-over-3390000-in-fraudulent-small-business-loans-during-covid/

US authorities arrested an Atlanta man this week on charges related to his alleged connection to a COVID-19 relief loan application fraud ring.

The Department of Justice (DOJ) alleges that Ian Patrick Jackson, 37, conspired with another Atlanta man to recruit at least nine business owners to submit fraudulent Paycheck Protection Program (PPP) loan applications using fake tax documents.

Jackson allegedly told the business owners to falsely claim they each employed 16 individuals and paid monthly wages of $120,000. The DOJ says the owners then wrote falsified payroll checks to people who didn’t work for them and then either kept the money for themselves or paid Jackson via his co-conspirator.

Jackson is allegedly connected to 15 fraudulent COVID-19 relief loan applications that inked $3.39 million in proceeds. He’s the 12th person to be charged in connection with an Atlanta-based PPP fraud ring, with the 11 previous defendants having already pled guilty or been convicted at trial. The DOJ says authorities have recovered nearly $1.2 million of the defrauded funds.

Jackson also allegedly applied for a separate $237,500 PPP loan using fabricated tax forms and used a forged driver’s license and false revenue statements to fraudulently apply for approximately $100,000 in PPP and Economic Injury Disaster Loan (EIDL) program loans. The DOJ also says he fraudulently secured another $240,035 PPP loan and $125,000 in EIDL program loans and grants on behalf of another company.

Jackson has been charged with conspiracy to commit bank fraud, two counts of bank fraud, two counts of wire fraud and two counts of money laundering. The charges could result in decades in prison.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/feds-charge-atlanta-man-for-allegedly-applying-for-over-3390000-in-fraudulent-small-business-loans-during-covid/feed/ 0 37589
US Consumers Lose $2,088,000,000 to Fraudulent Bank Transfers and Payments, According to FTC https://earlybirdsinvest.com/us-consumers-lose-2088000000-to-fraudulent-bank-transfers-and-payments-according-to-ftc/ https://earlybirdsinvest.com/us-consumers-lose-2088000000-to-fraudulent-bank-transfers-and-payments-according-to-ftc/#respond Mon, 24 Mar 2025 17:54:10 +0000 https://earlybirdsinvest.com/us-consumers-lose-2088000000-to-fraudulent-bank-transfers-and-payments-according-to-ftc/

The losses suffered by Americans as a result of fraudulent bank transfers and payments have significantly increased over the past five years, according to government numbers.

Data from the Federal Trade Commission (FTC) shows that US consumers lost $2.088 billion to fraudulent bank transfers and payments in 2024.

The amount is significantly higher than the figure recorded in 2020 when consumers reported losing $319.6 million to fraudulent bank transactions. The losses increased to $745.1 million in 2021, $1.58 billion in 2022 and $1.86 billion in 2023.

The most recent data from the FTC, which was published on March 7th, shows that in the first quarter of 2024, consumers lost $508.3 million via bank transfers or payments. The number slightly rose to $511.1 million in the third quarter and surged to $563.7 million in the last quarter of the year.

Fraudulent bank transfers or payments were the leading cause of financial losses among payment methods last year, far surpassing cryptocurrency transactions, which account for the second-highest amount of losses of about $1.42 billion in 2024, slightly up from $1.41 billion in 2023. Transactions by payments app or services was third with $391 million in losses.

The FTC says it shares fraud reports with over 2,800 law enforcers.

“We can’t resolve your individual report, but we use reports to investigate and bring cases against fraud, scams, and bad business practices.”

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/us-consumers-lose-2088000000-to-fraudulent-bank-transfers-and-payments-according-to-ftc/feed/ 0 26980