iTnews

Wipro hackers targeted gift card and rewards programs

By Juha Saarinen on May 2, 2019 1:22PM
Wipro hackers targeted gift card and rewards programs

Threat actors active for years.

The hackers that gained access to over a hundred computers at Indian outsourcer Wipro were attempting gift card and rewards program fraud, new security research suggests.

At first, the Wipro attack was thought to be the work of state-sponsored threat actors.

Security vendor Flashpoint said the breach that was revealed in April this year saw dozens of Wipro employee Windows accounts being compromised via phishing emails.

This lead to further attacks against 11 Wipro customers, including IT service providers CapGemini, Avanade, Cognizand and Infosys, and cloud hosting company Rackspace.

Flashpoint said the attackers wanted the victims' credentials "likely in order to gain access to the portals managing their gift card and rewards programs."

While the identity of the attackers has not been revealed, Flashpoint found that they had tried to spread a remote administration tool (RAT) malware called Imminent Monitor, which was used used in a phishing campaign in 2017.

Further analysis of re-used infrastructure and file name constructs suggested to Flashpoint that the attackers may have been active as early as 2015.

The attackers abused legitimate security applications in their phishing campaign against Wipro, Flashpoint said.

Among these were phishing templates that matched those provided by a security awareness provider.

The attackers also dropped the ScreenConnect remote access program on computers compromised at Wipro, and some of the domains used in the attack hosted the powerkatz and powersploit scripts that can be used to steal credentials and launch exploits, the security vendor said.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
flashpoint security wipro

Partner Content

Setting a path to self-funded mainframe-to-cloud modernisation with Micro Focus
Promoted Content Setting a path to self-funded mainframe-to-cloud modernisation with Micro Focus
Preventing cybercrime in the world of forex trading
Promoted Content Preventing cybercrime in the world of forex trading
As Australian companies lean more heavily on the cloud, edge security is finding its stride
Partner Content As Australian companies lean more heavily on the cloud, edge security is finding its stride
Improving returns from SD-WAN spending
Partner Content Improving returns from SD-WAN spending

Sponsored Whitepapers

The top 5 tech trends to deliver business outcomes
The top 5 tech trends to deliver business outcomes
10 reasons why businesses need to invest in cloud security training
10 reasons why businesses need to invest in cloud security training
Your guide to application security solutions
Your guide to application security solutions
State of Software Security: Open Source Edition
State of Software Security: Open Source Edition
Five questions to ask before you upgrade to a SIEM solution
Five questions to ask before you upgrade to a SIEM solution

Events

  • On-Demand Webinar: How Poly and Microsoft are Embracing Future Work Environments
  • [iTnews and Micro Focus] Navigating the cloud modernisation minefield
By Juha Saarinen
May 2 2019
1:22PM
0 Comments

Related Articles

  • 86 400 looks to strengthen customer sign-up process
  • Britain's GCHQ cyber spies embrace the AI revolution
  • Critical remote code execution bug found in VMware vCenter
  • SolarWinds, Microsoft, FireEye, CrowdStrike defend actions in major hack
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

TPG Telecom to start enticing NBN customers to move

TPG Telecom to start enticing NBN customers to move

Infosys scores another $40m for Centrelink payments engine build

Infosys scores another $40m for Centrelink payments engine build

Bosch, Microsoft join forces to develop vehicle software platform

Bosch, Microsoft join forces to develop vehicle software platform

Telstra InfraCo opens up telco's own fibre network

Telstra InfraCo opens up telco's own fibre network

You must be a registered member of iTnews to post a comment.
Log In | Register
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.