Malware designers have evolved beyond their initial simplicity, becoming more devious in their abilities to access your personal data. Gone are the days of attempting to hack into corporate systems; they are finding it a lot more lucrative to go after private individuals.
This malware is of particular interest to those in South Africa as a recent 24-billion record data leak from Infostealer has exposed email addresses, usernames, login URLs, and plain text passwords from those in South Africa. This puts a large number of South Africans at risk. The database seems to have come from both new and older breaches and exceeds 8.3TB in size, with over 36 total sources discovered.
Infostealer is one such malware type. It has collected 56 million email accounts and 124 million passwords from stealer logs. This information has been stored in the Have I Been Pwned location for everyone to access to see if they’ve been hacked. Infostealer infects a device then harvests all sensitive information, especially financial data. This approach creates an opportunity for a more broad spectrum cyberattack for the takeover of accounts. This new credential theft has changed to endpoint-focus.
Infostealer quietly steals data and beyond passwords and email addresses, it seeks authentication tokens and usernames. Depending upon the infection, some versions will steal the data then auto-delete the log so that it can’t be detected. The difference with Infostealer is that sometimes the cybercriminals use the stolen data to hack into the accounts of the victims but they can also just simply sell it all on the dark web. Other Infostealer criminals will look for passwords to corporate accounts for those that work outside their office so that they can attack and access corporations. This shows that company breaches are still somewhat of interest for them.
So How Do I Know If I’ve Been Infected?
The first and easiest step is to access the Have I Been Pwned location to see if any of your information is in there. You have the ability to input as many passwords as you want (there’s no limt) to see if you’ve been compromised. The Have I Been Pwned system runs a check in their database and lets you know if any matches have shown up. It’s important to make note that if you have a weak password there’s a chance that someone else also may have used it so it doesn’t necessarily mean that you have been hacked. If a match is detected it’s recommended that you change your password to something else that’s stronger. You can also use this database to check your email address. The good thing about this program is that if your email is detected the system will also include the name of the incident. The system also offers you the option of signing up for automated notifications in case your email address is found in the future.
“Everyone’s financial information is under a constant state of attack from cybercriminals. As their approaches delve into more expanded access points, it’s imperative that all be on the alert in protecting themselves. DaVinci Cybersecurity works diligently to inform, consult, and assist in ensuring that all have the knowledge and tools.”
– Sharon Knowles, CEO DaVinci Cybersecurity
Sources:
https://mybroadband.co.za/news/security/654649-historic-24-billion-record-data-leak-puts-south-africans-at-risk.html?__cf_chl_f_tk=5yC0FB_tX9CbrKTvmNP9CLcUYZiyMvZOQzOq20bpBdE-1783443384-1.0.1.1-tYXzkeidRFWI_xdwgpK8en4kB3xLj_aUig05RWY.D.k
