<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>malicious actors &#8211; Bitfinance</title>
	<atom:link href="https://bitfinance.news/en/etiqueta/malicious-actors/feed/" rel="self" type="application/rss+xml" />
	<link>https://bitfinance.news</link>
	<description>Fintech &#38; new economy info</description>
	<lastBuildDate>Fri, 30 Jan 2026 20:13:01 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://bitfinance.news/wp-content/uploads/2025/01/favicon-64.png</url>
	<title>malicious actors &#8211; Bitfinance</title>
	<link>https://bitfinance.news</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Malicious actors hunt and manipulate on the important LinkedIn network; we must protect ourselves</title>
		<link>https://bitfinance.news/en/malicious-actors-hunt-and-manipulate-on-the-important-linkedin-network-we-must-protect-ourselves/</link>
		
		<dc:creator><![CDATA[Marilin Pino]]></dc:creator>
		<pubDate>Fri, 30 Jan 2026 19:30:21 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Financial security]]></category>
		<category><![CDATA[Analysis and opinion]]></category>
		<category><![CDATA[attacks]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[ESET]]></category>
		<category><![CDATA[ESET Latam]]></category>
		<category><![CDATA[ESET Venezuela]]></category>
		<category><![CDATA[How to protect yourself]]></category>
		<category><![CDATA[Hunt and manipulate on LinkedIn]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[malicious actors]]></category>
		<category><![CDATA[Malicious campaigns]]></category>
		<category><![CDATA[Mario Micucci]]></category>
		<category><![CDATA[prevention]]></category>
		<category><![CDATA[protection]]></category>
		<category><![CDATA[Researcher]]></category>
		<category><![CDATA[threats]]></category>
		<guid isPermaLink="false">https://bitfinance.news/?p=118992</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="1000" height="667" src="https://bitfinance.news/wp-content/uploads/2026/01/Imagen-referencial-Por-que-LinkedIn-es-un-terreno-de-caza-para-los-actores-maliciosos-y-como-protegerse-Suministrada-por-ESET-y-Comstat-Rowland.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="ESET analiza como esta red social profesional es una vasta base de datos pública de información corporativa en la que no todas las personas son quienes dicen ser" decoding="async" fetchpriority="high" srcset="https://bitfinance.news/wp-content/uploads/2026/01/Imagen-referencial-Por-que-LinkedIn-es-un-terreno-de-caza-para-los-actores-maliciosos-y-como-protegerse-Suministrada-por-ESET-y-Comstat-Rowland.jpg 1000w, https://bitfinance.news/wp-content/uploads/2026/01/Imagen-referencial-Por-que-LinkedIn-es-un-terreno-de-caza-para-los-actores-maliciosos-y-como-protegerse-Suministrada-por-ESET-y-Comstat-Rowland-300x200.jpg 300w, https://bitfinance.news/wp-content/uploads/2026/01/Imagen-referencial-Por-que-LinkedIn-es-un-terreno-de-caza-para-los-actores-maliciosos-y-como-protegerse-Suministrada-por-ESET-y-Comstat-Rowland-768x512.jpg 768w" sizes="(max-width: 1000px) 100vw, 1000px" /></div><p>Last November, the UK&#8217;s Security Service alerted members of Parliament about a foreign intelligence-gathering scheme: two LinkedIn profiles were contacting people working in British politics to request &#8220;insider information.&#8221; The MI5 revelations triggered a £170 million ($230 million) government initiative to address espionage threats against Parliament. While this is a high-profile case, ESET, a leading [&#8230;]</p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/malicious-actors-hunt-and-manipulate-on-the-important-linkedin-network-we-must-protect-ourselves/">Malicious actors hunt and manipulate on the important LinkedIn network; we must protect ourselves</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news">Bitfinance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="1000" height="667" src="https://bitfinance.news/wp-content/uploads/2026/01/Imagen-referencial-Por-que-LinkedIn-es-un-terreno-de-caza-para-los-actores-maliciosos-y-como-protegerse-Suministrada-por-ESET-y-Comstat-Rowland.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="ESET analiza como esta red social profesional es una vasta base de datos pública de información corporativa en la que no todas las personas son quienes dicen ser" decoding="async" srcset="https://bitfinance.news/wp-content/uploads/2026/01/Imagen-referencial-Por-que-LinkedIn-es-un-terreno-de-caza-para-los-actores-maliciosos-y-como-protegerse-Suministrada-por-ESET-y-Comstat-Rowland.jpg 1000w, https://bitfinance.news/wp-content/uploads/2026/01/Imagen-referencial-Por-que-LinkedIn-es-un-terreno-de-caza-para-los-actores-maliciosos-y-como-protegerse-Suministrada-por-ESET-y-Comstat-Rowland-300x200.jpg 300w, https://bitfinance.news/wp-content/uploads/2026/01/Imagen-referencial-Por-que-LinkedIn-es-un-terreno-de-caza-para-los-actores-maliciosos-y-como-protegerse-Suministrada-por-ESET-y-Comstat-Rowland-768x512.jpg 768w" sizes="(max-width: 1000px) 100vw, 1000px" /></div><p style="text-align: justify;">Last November, the <strong>UK&#8217;s Security Service</strong> alerted members of <strong>Parliament</strong> about a <strong>foreign intelligence-gathering scheme:</strong> two <strong>LinkedIn</strong> profiles were contacting people working in British politics <a href="https://www.bbc.co.uk/news/articles/c4gpnz05kr8o" target="_blank" rel="noopener">to request &#8220;insider information.&#8221;</a> The <strong>MI5</strong> revelations triggered a £170 million ($230 million) government initiative to address espionage threats against Parliament. While this is a high-profile case, <strong><a href="https://www.eset.com/latam/" target="_blank" rel="noopener">ESET</a></strong>, a leading company in proactive threat detection, states that it is far from the first or only one. The site could also be a veritable treasure trove of corporate data that could be maliciously used to support fraud or threat campaigns.</p>
<p style="text-align: justify;">Therefore, it is important to <strong>learn from this analysis and valuable professional opinion</strong> provided by ESET.</p>
<p style="text-align: justify;">LinkedIn has amassed over one billion members worldwide since its founding in 2003. This represents a vast pool of <strong>potential targets for state-backed or financially motivated threat actors.</strong> Firstly, it is an <strong>extraordinary source of information</strong> where malicious actors can discover the roles and <a href="https://www.welivesecurity.com/es/seguridad-corporativa/oversharing-que-esta-en-juego-si-empleados-comparten-demasiado/" target="_blank" rel="noopener">responsibilities of key individuals within a target company</a> and reconstruct or reshape the relationships between individuals and projects they might be working on. Furthermore, it <strong>provides credibility and cover</strong> because, as a professional network, it is frequented by both high-level executives and lower-level employees, and it is a context in which a victim is more likely to open a direct message or InMail from someone on the platform than an unsolicited email.</p>
<p style="text-align: justify;">On the other hand, it <strong>bypasses “traditional” security</strong> because there is no guarantee that phishing messages, malware, or spam won&#8217;t get through; and due to the site&#8217;s perceived credibility, target users may be more likely to click on malicious content. Finally, <strong>it&#8217;s easy to start operating;</strong> anyone can create a profile and begin lurking on the site to gather intelligence or send phishing messages and Business Enforcement (BEC) scams. Furthermore, attackers can hijack existing accounts <a href="https://bitfinance.news/en/the-fed-keeps-rates-current-without-short-term-cuts-expectations/" target="_blank" rel="noopener">or create fake identities before posing as candidates and recruiters</a> for positions and jobs. The large number of compromised credentials circulating on cybercrime forums (<a href="https://bitfinance.news/en/amazon-to-cut-more-jobs-to-focus-on-ai/" target="_blank" rel="noopener">due in part to infostealers</a>) makes this relatively easy.</p>
<h3 style="text-align: justify;">There are several ways threat actors can operationalize their malicious campaigns:</h3>
<ul>
<li style="text-align: justify;"><strong>Phishing and spearphishing:</strong> By using the information users share in their profiles, attackers can customize phishing campaigns (fake emails) to increase their success rate.</li>
<li style="text-align: justify;"><strong>Direct attacks:</strong> Contact can be made directly through malicious links designed to deploy malware, such as infostealers, or promote fake job offers intended to steal credentials.</li>
<li style="text-align: justify;"><strong>BEC:</strong> Similar to phishing, LinkedIn provides a wealth of intelligence that can be used to make Business Email Compromise attacks appear more convincing. It can help scammers identify who reports to whom, what projects they are working on, and the names of partners or suppliers.</li>
<li style="text-align: justify;"><strong>Deepfakes:</strong> LinkedIn can also host videos of targeted individuals, which can be used to create <a href="https://www.welivesecurity.com/es/seguridad-digital/herramientas-para-detectar-deepfakes-combatir-desinformacion/" target="_blank" rel="noopener">deepfakes</a> and employ them in subsequent phishing, BEC, or social media scams.</li>
<li style="text-align: justify;"><strong>Account hijacking:</strong> Fake LinkedIn pages (phishing), infostealers, credential stuffing, and other techniques can help attackers take control of user accounts. These hijacked accounts can then be used in subsequent attacks targeting their contacts.</li>
<li style="text-align: justify;"><strong>Attacks on suppliers:</strong> LinkedIn can also be tracked for information about partners of a target company, who would also be targeted with phishing as part of a malicious “domino effect” strategy.</li>
</ul>
<p style="text-align: justify;"><em>“The challenge posed by threats on LinkedIn is that IT departments find it difficult to obtain accurate information about the extent of the risk their employees face, and the tactics used to attack them. However, <strong>it makes sense to include LinkedIn threat scenarios like those described above in security awareness training courses.</strong> Employees should also be warned about the risk of oversharing information on the platform and given guidance on how to detect fake accounts and typical phishing lures,”</em> says <strong>Mario Micucci, Cybersecurity Researcher at ESET Latin America.</strong></p>
<h3 style="text-align: left;">ESET provides information on various threat groups that have used some of these tactics</h3>
<ul>
<li style="text-align: justify;"><strong>The Lazarus Group (North Korea)</strong> has posed as recruiters on LinkedIn to install malware on the computers of people working at an aerospace company, according to ESET Research. In fact, the research team also recently described the “Wagemole” campaigns, in which individuals aligned with North Korea attempt to obtain employment at foreign companies.</li>
<li style="text-align: justify;"><strong>ScatteredSpider</strong> contacted MGM&#8217;s help desk, impersonating an employee whose identity they obtained from LinkedIn, in order to gain access to the organization. The subsequent ransomware attack resulted in losses of $100 million.</li>
<li style="text-align: justify;">A <a href="https://www.darkreading.com/application-security/ducktail-spearphishing-linkedin-hijack-facebook-business-accounts" target="_blank" rel="noopener">spearphishing campaign called “Ducktail”</a> targeted marketing and human resources professionals on LinkedIn, delivering malware and stealing information through links sent via direct message. The malware was hosted in the cloud.</li>
</ul>
<h2>Prevention</h2>
<p style="text-align: justify;"><em>“<strong>To prevent account hijacking, a policy of regularly updating patches should be followed, security software should be installed on all devices (from a trusted vendor), and multifactor authentication should be enabled.</strong> Additionally,<strong> in corporate environments, it may be worthwhile to organize specific training sessions for executives,</strong> who are often the most frequent targets of attacks. Above all, ensure that <strong>the team is aware that, even on a network considered trustworthy like LinkedIn, not everyone acts in good faith or in their best interest,”</strong></em> recommends the ESET researcher.</p>
<p style="text-align: justify;">ESET invites you to learn more about cybersecurity by visiting:  <a href="https://www.welivesecurity.com/es/" target="_blank" rel="noopener">https://www.welivesecurity.com/es/</a>.</p>
<p style="text-align: justify;">For other useful preventative information, also available in Venezuela at: <a href="https://www.eset.com/ve/" target="_blank" rel="noopener">https://www.eset.com/ve/</a>, and on their social media channels @eset_ve. Also on Instagram (<a href="https://www.instagram.com/esetla/" target="_blank" rel="noopener">@esetla</a>)  and Facebook (<a href="https://www.facebook.com/ESETLA" target="_blank" rel="noopener">ESET</a>).</p>
<p>Information and image provided by ESET</p>
<p><em><strong>Follow our news on Google!</strong></em><em> For current, interesting, and accurate information, </em><a href="https://www.google.com/search?q=site:bitfinance.news&amp;tbm=nws&amp;tbs=sbd:1" target="_blank" rel="noopener"><strong><em>click here</em></strong></a><em> to see all the content on <strong>Bitfinance.news</strong>. You can also find us on </em><a href="https://twitter.com/BitFinance_News" target="_blank" rel="noopener"><strong><em>X/Twitter</em></strong></a><em> and </em><a href="https://www.instagram.com/bitfinancenews/?hl=es" target="_blank" rel="noopener"><strong><em>Instagram</em></strong></a></p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/malicious-actors-hunt-and-manipulate-on-the-important-linkedin-network-we-must-protect-ourselves/">Malicious actors hunt and manipulate on the important LinkedIn network; we must protect ourselves</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news">Bitfinance</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Hackers enter Google accounts in the cloud to mine cryptocurrencies</title>
		<link>https://bitfinance.news/en/hackers-enter-google-accounts-in-the-cloud-to-mine-cryptocurrencies/</link>
		
		<dc:creator><![CDATA[María Belén]]></dc:creator>
		<pubDate>Mon, 29 Nov 2021 15:00:26 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Legal & legislative]]></category>
		<category><![CDATA[accounts]]></category>
		<category><![CDATA[bitcoin]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[cryptocurrencies]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[malicious actors]]></category>
		<category><![CDATA[mining]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>
		<guid isPermaLink="false">https://bitfinance.news/?p=73470</guid>

					<description><![CDATA[<div style="margin-bottom:20px;"><img width="2000" height="1333" src="https://bitfinance.news/wp-content/uploads/2021/11/Google-para-minar-criptomonedas-271121.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="In a report published by Google, they point out that hackers use accounts in the cloud to carry out mining activities for cryptocurrencies such as bitcoin." decoding="async" srcset="https://bitfinance.news/wp-content/uploads/2021/11/Google-para-minar-criptomonedas-271121.png 2000w, https://bitfinance.news/wp-content/uploads/2021/11/Google-para-minar-criptomonedas-271121-300x200.png 300w, https://bitfinance.news/wp-content/uploads/2021/11/Google-para-minar-criptomonedas-271121-1024x682.png 1024w, https://bitfinance.news/wp-content/uploads/2021/11/Google-para-minar-criptomonedas-271121-768x512.png 768w, https://bitfinance.news/wp-content/uploads/2021/11/Google-para-minar-criptomonedas-271121-1536x1024.png 1536w" sizes="(max-width: 2000px) 100vw, 2000px" /></div><p>Hackers enter Google cloud accounts to mine cryptocurrencies. The internet giant recently published a report on “Google&#8217;s threat horizon”, where it points out its concern about the use of cloud accounts that have been hacked to mine cryptocurrencies. According to what was disseminated in the report: &#8220;Malicious actors have been observed mining cryptocurrencies in compromised [&#8230;]</p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/hackers-enter-google-accounts-in-the-cloud-to-mine-cryptocurrencies/">Hackers enter Google accounts in the cloud to mine cryptocurrencies</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news">Bitfinance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div style="margin-bottom:20px;"><img width="2000" height="1333" src="https://bitfinance.news/wp-content/uploads/2021/11/Google-para-minar-criptomonedas-271121.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="In a report published by Google, they point out that hackers use accounts in the cloud to carry out mining activities for cryptocurrencies such as bitcoin." decoding="async" srcset="https://bitfinance.news/wp-content/uploads/2021/11/Google-para-minar-criptomonedas-271121.png 2000w, https://bitfinance.news/wp-content/uploads/2021/11/Google-para-minar-criptomonedas-271121-300x200.png 300w, https://bitfinance.news/wp-content/uploads/2021/11/Google-para-minar-criptomonedas-271121-1024x682.png 1024w, https://bitfinance.news/wp-content/uploads/2021/11/Google-para-minar-criptomonedas-271121-768x512.png 768w, https://bitfinance.news/wp-content/uploads/2021/11/Google-para-minar-criptomonedas-271121-1536x1024.png 1536w" sizes="(max-width: 2000px) 100vw, 2000px" /></div><p style="text-align: justify;"><strong>Hackers</strong> enter Google cloud accounts to mine cryptocurrencies. The internet giant recently published a report on “Google&#8217;s threat horizon”, where it points out its concern about <strong>the use of cloud accounts that have been hacked to mine cryptocurrencies.</strong></p>
<p style="text-align: justify;">According to what was disseminated in the report: &#8220;Malicious actors have been observed mining cryptocurrencies in compromised cloud instances.&#8221; Noting that &#8220;of the 50 recent examples, 86 % of the cases showed that hackers were mining cryptocurrencies with the accounts.&#8221;</p>
<p style="text-align: justify;">The report published by Google&#8217;s Cybersecurity Action team attempts to meet two fundamental objectives: the first is <strong>&#8220;profit making</strong>&#8221; and the second is related to <strong>&#8220;traffic pumping</strong>&#8220;.</p>
<p style="text-align: justify;">With this document the internet leading company tries to provide actionable information that allows organizations to assert that <strong>their cloud environments are better protected.</strong></p>
<p style="text-align: justify;">The document also refers to other registered cyber threats such as: <strong>malware,</strong> hosting of unauthorized content on the Internet, <strong>spam </strong>and the launch of <strong>DDoS bots</strong>.</p>
<h2 style="text-align: justify;">Hackers broadcast live</h2>
<p style="text-align: justify;">The group responsible for making the report on Google&#8217;s Threat Analysis, last month raised the alarms by warning about the presence of hackers in <strong>YouTube accounts to spread cryptocurrency scams.</strong></p>
<p style="text-align: justify;">The representatives of the technology company pointed out that &#8220;the name of the channel, the image of the profile and the content were replaced by the brand of the cryptocurrency to impersonate <strong>large technology companies or cryptocurrency exchange</strong>.&#8221;</p>
<p style="text-align: justify;">In addition, they highlighted that the hackers made live broadcasts where they offered gifts in <strong>&#8220;cryptocurrencies in exchange for the first contributions</strong>.&#8221; Google pointed out that hackers were fluent in the Russian language.</p>
<p style="text-align: justify;">M. Rodríguez</p>
<p style="text-align: justify;">Source: <a href="https://decrypt.co/es/87048/hackers-entran-en-cuentas-de-la-nube-para-minar-criptomonedas-google" target="_blank" rel="noopener">decrypt.co</a></p>
<p>La entrada <a rel="nofollow" href="https://bitfinance.news/en/hackers-enter-google-accounts-in-the-cloud-to-mine-cryptocurrencies/">Hackers enter Google accounts in the cloud to mine cryptocurrencies</a> apareció primero en <a rel="nofollow" href="https://bitfinance.news">Bitfinance</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
