Security
  • Menu
  • All Tips
  • FAQs
  • Categories
  • Guidelines
  • Data Security Support
  • Tools
  • Have I Been Pwned?
  • Pwned Passwords
  • Email Checker
  • Password Generator
  • My IP
  • Privacy
DATA PRIVACY NOTICE AND CONSENT FORM

Cloudstaff is committed to protecting the privacy of its data subjects, and ensuring the safety and security of personal data under its control and custody. This policy provides information on what personal data is gathered by Cloudstaff Security Tips about its current, past, and prospective employees; how it will use and process this; how it will keep this secure; and how it will dispose of it when it is no longer needed. This information is provided in compliance with the Philippine Republic Act No. 10173, also known as, the Data Privacy Act of 2012 (DPA) and its Implementing Rules and Regulations (DPA-IRR). It sets out Cloudstaffs’ data protection practices designed to safeguard the personal data of individuals it deals with, and also to inform such individuals of their rights under the Act.

The personal data obtained from this application is entered and stored within the Cloudstaff system and will only be accessed by the Cloudstaff’s authorized personnel. Cloudstaff have instituted appropriate organizational, technical and cloud security measures (Amazon Web Services Shared Responsibility) to ensure the protection of the users personal data.

Information collected will be automatically deleted after three (3) years inactivity.

Furthermore, the information collected and stored in the application are as follows:
  • Given Name
  • Family Name
  • Avatar [Profile Picture]

USER CONSENT

I have read the Data Privacy Statement and expressed my consent for Cloudstaff to collect, record, organize, update or modify, retrieve, consult, use, consolidate, block, erase or destruct my personal data as part of my information.

I hereby affirm my right to be informed, object to processing, access and rectify, suspend or withdraw my personal data, and be indemnified in case of damages pursuant to the provisions of the Republic Act No. 10173 of the Philippines, Data Privacy Act of 2012 and its corresponding Implementing Rules and Regulations.

If you want to exercise any of your rights, or if you have any questions about how we process your personal data, please contact Cloudstaff’s Data Protection Officer, through the following channel:

Email to privacy@cloudstaff.com

  • Log in Now
Deceptive Google Ad Campaign Exploits Chinese Users Through Counterfeit Messaging Apps

Chinese users face a targeted malvertising campaign through malicious Google ads promoting restricted messaging apps like Telegram. Malwarebytes' Jérôme Segura revealed that threat actors exploit Google advertiser accounts to create these deceptive ads, leading users to download Remote Administration Trojans (RATs). The ongoing campaign, known as FakeAPP, is a continuation of a prior assault that initially targeted Hong Kong users searching for messaging apps in late October 2023. The attackers have expanded their tactics by adding LINE to the list of targeted messaging apps, redirecting users to fraudulent websites on Google Docs or Google Sites.

The malicious Google infrastructure embeds links controlled by threat actors, delivering installer files that deploy trojans like PlugX and Gh0st RAT. Malwarebytes traced the fraudulent ads to two advertiser accounts, Interactive Communication Team Limited and Ringier Media Nigeria Limited, based in Nigeria. The threat actor appears to prioritize quantity over quality, constantly introducing new payloads and infrastructure for command-and-control purposes.

In a related development, Trustwave SpiderLabs highlighted a surge in the use of a phishing-as-a-service (PhaaS) platform called Greatness, priced at $120 per month. Greatness facilitates the creation of authentic-looking credential harvesting pages targeting Microsoft 365 users. It allows personalization of various elements, such as sender names, email addresses, subjects, messages, attachments, and QR codes, enhancing relevance and engagement. The kit is sold to criminal actors, making it more accessible and enabling large-scale attacks.

Attack chains in these phishing campaigns involve sending emails with malicious HTML attachments that direct recipients to fake login pages, capturing login credentials, and transmitting them to the threat actor via Telegram. Some attack sequences deploy malware on victims' machines to facilitate information theft. The phishing emails often use tactics like spoofing trusted sources, such as banks and employers, and create a false sense of urgency with subjects like "urgent invoice payments" or "urgent account verification required."

Trustwave noted the widespread use of Greatness, with its own Telegram community providing operational guidance and additional tips. Additionally, phishing attacks have been observed in South Korea, where malicious Windows shortcut (LNK) files impersonate tech companies like Kakao to distribute AsyncRAT. The disguised shortcut files can be mistaken for normal documents as the '.LNK' extension is not visible in the file names.


Source: https://thehackernews.com/2024/01/malicious-ads-on-google-target-chinese.html


Caitlin Joyce (CaitlinG) Galanza | News
Created: January 29 2024 | Updated: on 1/29/24
Comments


  2021 © Mazer

Security Tips v2.0.1 | Crafted with by Saugi