In this episode of Breaking Badness, we delve into the cybersecurity trends shaping the holiday season. We unpack the 60% surge in scam domain registrations targeting holiday shoppers, discuss the tactics of TAG-112, a Chinese state-sponsored threat group, and analyze their use of compromised websites to deliver Cobalt Strike malware. Plus, we share actionable insights on mitigating these threats. Tune in for expert analysis, lighthearted banter, and a few cybersecurity holiday tips to keep you safe this season!
"Retail scamming is a year-round hobby for some people," - Tim Helming, capturing the evergreen nature of these threats.
Holiday shoppers are prime targets for scammers, and recent research highlights a 60% spike in scam domain registrations. These fake domains impersonate major retailers like Walmart, Amazon, and Target, using enticing offers and counterfeit websites to steal credentials and financial data.
Mitigation Tips:
The episode transitions to a deep dive into TAG-112, a Chinese state-sponsored group targeting Tibetan community websites. Their methods included exploiting vulnerabilities in Joomla CMS to deliver Cobalt Strike malware.
Attack Overview:
● Connection to TAG-102: TAG-112 is considered a subset of the more advanced TAG-102, aka "Evasive Panda."
"They’re aging malicious domains like fine wines," joked Tim, highlighting how attackers use aged domains to bypass security filters.
Mitigation Recommendations:
The team discusses practical steps for consumers and businesses to stay ahead of threats during the holiday season.
For Consumers:
For Businesses:
As holiday shopping heats up, so do the efforts of cybercriminals. Whether you’re a consumer or a business, staying vigilant and informed is key to navigating these seasonal threats. Catch the full episode to learn more about how to protect yourself and your organization.
That’s about all we have for this week, you can find us on Mastodon and Twitter/X @domaintools, all of the articles mentioned in our podcast will always be included on our podcast recap. Catch us Wednesdays at 9 AM Pacific time when we publish our next podcast and blog.
*A special thanks to John Roderick for our incredible podcast music!