Home Blog Page 102

Employee Negligence Leads to Phishing Attack on California’s SCO

Phishing, phishing attacks

Sometimes, a single negligent act of an employee can put an organization’s critical information at stake. Despite organizations becoming cyber smart to cope with rising cyberattacks, careless or unintentional actions of employees like responding to a phishing email or downloading malicious attachments become an inevitable threat to several organizations. Recently, the California State Controller’s Office (SCO) became a victim of a phishing attack after one of its employees accidentally allowed a hacker to access the company’s email account for more than a day.

How the California SCO got Phished

According to the official release, an employee of the SCO’s Unclaimed Property Division opened a malicious link in an email by mistake and then entered login credentials as prompted by the phishing page, allowing intruders access to their email account. The hacker unauthorizedly accessed the email account from March 18, 2021, at 1:42 p.m. to March 19, 2021, at 3:19 p.m.

In a phishing attack, the attackers try to illicitly obtain users’ sensitive information like login credentials or financial data by disguising themselves as a legitimate entity online. They usually leverage email spoofing, instant messaging, or malicious URLs in phishing attacks that redirect users to a fake website asking to enter credentials.

The Phishing Impact

The California SCO holds a huge amount of private and financial data that belongs to millions of people and organizations that do business in the state. It was found that the intruder stole several sensitive documents of thousands of state employees and also sent phishing emails to at least 9,000 California state workers and their contacts using the phished employee’s email account.

What the California SCO Says…

It stated that the compromised email account had users’ Personal Identifiable Information (PII) contained in Unclaimed Property Holder Reports.

“The improperly accessed email account was discovered promptly, and access removed. The SCO Unclaimed Property Division personnel immediately began a review of all emails in the account for personal identifying information that may have been viewed. A notice was emailed to all contacts who were sent an email from the unauthorized user, advising them to delete the email and not click on any links therein,” the SCO said.

“Given the nature of the information potentially exposed, we strongly recommend that individuals and companies contacted by SCO about the breach monitor their accounts. Further, we strongly recommend they contact the three credit bureaus and place a fraud alert on their accounts,” the SCO added.

Security Awareness for Organizations and Employees 

The surge in remote work made global businesses enhance both their inner and outer security perimeters. Several organizations invested time and money to improve their security standards and help employees learn how to detect and prevent security threats like phishing attacks. Aiming to do the same, the California Department of Technology (CDT) issued a set of guidelines in October 2020, asking organizations to conduct regular employee training on phishing attack before it occurs.

Related Story: Five Phishing Baits You Need to Know

For many roles, there are few, if any, women candidates

It has been an age-old myth that women prioritize family over work. Women are under-represented in tech and leadership. According to an (ISC)² Cybersecurity Workforce Report, women working in cybersecurity account for about one quarter (24%) of the overall workforce. Though there’s a continuing inequity, things have begun to look brighter. Workforces – especially post-COVID-19 pandemic and lockdown – have been offering flexibility in timings, empowering women to lead, and showing support through digital mediums. Change happens with time, but it requires consistency. There is a need to go beyond the 24%.

Let’s hear what Heather Bentley, Senior Vice President – Customer Success and Support, Mimecast, has to say about Women in Cybersecurity:

On the gender gap: I think reaching out to young women is important to help them understand that they can have a great career in cybersecurity. As more and more of our lives rely on technology, this is a field that isn’t going to go away. I’m surprised that many young people are unaware of this opportunity. As a community, we need to do a better job of highlighting the different opportunities and roles that are available in the cybersecurity sector. You don’t have to be a programmer to hunt the bad guys! Also, we should show how exciting and how much fun the cybersecurity industry is to young people. There are not many industries that offer that many opportunities and new challenges to learn, develop new skills, and grow your career.

Better hiring practices for women: Businesses need to make sure they have a diverse pool of candidates. For many roles, there are few, if any, women candidates. I am a strong advocate of giving people opportunity. Not all roles require you to be a technical expert on day one. With the cybersecurity skills gap we see, there has never been a better time to invest in training academies and provide hard workers the ability to gain new skills. For women especially, businesses need to be flexible. As COVID-19 has shown us, it is possible to be successful and work from home. With the balance many women have between their families and their careers, moving away from a traditional 9 to 5 office environment is key. Let’s embrace this, provide flexibility, and get a more diverse workforce as a result.

Training and mentorship for women: Training and mentorship programs are the best opportunities we have to get more women into cybersecurity. It’s important for women to see other women being successful. I do a lot of outreach in schools and I’m surprised how many young female pupils will say “computers are for boys.” We must move beyond this thinking. There is so much opportunity now and in the future in this industry. We need to make sure young women are welcomed and supported. Many women in cybersecurity will tell you, they are often the only woman in a meeting. I am starting to see that change, but more needs to be done to continue to develop and support female leaders in this space.


Disclaimer

Views expressed in this article are personal.

Download CISO MAG’s March issue on Women in Cybersecurity. Preview hereSubscribe now!

Five Social Engineering Trends to Watch for 2021

Threat Alert! Attackers Use Malicious Email Accounts to Launch BEC Attacks

Cybercrime continues to be a growing threat and attack methods constantly evolve with each passing day. At the core of almost every successful cyberattack, one thing remains constant: a victim is persuaded in performing the desired action. Whether it’s clicking on a link, opening an attachment, or complying with a request, crafty cyberattackers resort to clever social engineering tactics that exploit human curiosity, desire, anxiety, eagerness, and urgency. Most attacks rely on some form of social engineering for execution. Let’s look at the top 5 social engineering trends to watch out for in 2021.

By Stu Sjouwerman, CEO of KnowBe4

1. Consent phishing on the rise

Post Covid-19, more and more businesses are moving their workloads to the cloud, and attackers are coming up with ingenious ways to hijack data stored in the cloud. So-called ‘consent phishing’ is one such variant of social engineering that involves the use of malicious apps that seek permission from users (instead of asking them their password) and provide legitimate access to cloud services and applications. Such apps don’t require the code to be executed on the user’s machine so they can easily evade endpoint security.

Authorization technology such as OAuth 2.0 is currently being used by many leading companies like Microsoft, Google, and Facebook. The attack on SANS Institute is one such recent example where a malicious Office 365 add-on caused an employee’s email account to be automatically forwarded to a cybercriminal’s email address. This subsequently led to a breach of 28,000 personally identifiable records.

2. Business Email Compromise gets costlier

 The FBI considers business email compromise (BEC) a.k.a. email account compromise, as one of the most damaging online financial crimes. This is another social engineering attack where cybercriminals impersonate a trusted business contact. By emulating as a trusted entity, cybercriminals convince targets to pay invoices, transfer funds, or give access to data or intellectual property. Currently, the average cost of a BEC attack is estimated at $80,0000 and is estimated to rise every year. In 2019, a Lithuanian attacker posing as a hardware vendor conned Google and Facebook into sending $123 million to his bank accounts. According to Gartner, BEC attacks will continue to double every year through 2023 at a staggering cost of $5 billion to its victims.

 3. Deepfakes create deeper challenges

 While social media enthusiasts use deepfake videos as a form of entertainment, hackers and cybercriminals see this as an opportunity to manipulate information, destroy credibility and impersonate trusted sources. While the real impact of deepfakes has yet to be measured, the technology is so powerful that it can be used to social engineer bogus messages to scam businesses. Nation-state attackers can create fake viral videos of politicians, spread disinformation, manipulate sentiments, spark outrage and hatred and even topple governments. Experts recently ranked deepfake technology as the most worrying use of artificial intelligence that could have serious implications in cybercrime and terrorism.

4. Nation-state attackers with social engineering in their arsenal

Data is the new oil and that’s why rogue nations are consistently upping their ante in cyberwarfare. Whether it’s stealing Covid-19 research or reconnaissance on high-value targets, state-sponsored attacks are growing fast. Between July 2019 and June 2020, Microsoft reportedly sent 13,000 notifications warning account holders of state-sponsored attacks. Google’s threat analysis group recently identified hackers from North Korea pretending to be cybersecurity bloggers and targeting security researchers on Linkedin and Twitter. In 2020, Twitter employees were subject to a co-ordinated social engineering attack that allowed state-sponsored attackers to take control of high-profile accounts and tweet on their behalf. It is estimated that almost 12% of all attacks on Industrial Control Systems (ICS) emerge from nation-state attackers.

5. Expanding Phishing-as-a-Service market

From ransomware attacks to malware infections stemming from people clicking on bogus URLs, fake websites, and malicious attachments, phishing is one of the most common and most potent forms of social engineering attacks. The growth of Phishing-as-a-Service has significantly lowered the bar for anyone looking to enter cybercrime. Similar to the Software-as-a-Service (SaaS) model where consumers access cloud-based applications for a monthly or annual subscription, phishing toolkits can be rented from organized crime syndicates and established hackers for as low as $50 a month. In fact, phishing kit sales grew by 120% in 2019 and the average price of one of these kits more than doubled because of high demand.  The start of 2021 has seen the emergence of a new cybercrime tool, dubbed LogoKit, that can build phishing pages in real-time and has already been detected on more than 700 domains.

User awareness is no longer optional – it’s a strategic imperative

It’s pretty clear that attackers are crafting social engineering attacks that are becoming more convincing and more successful with each passing day. Now more than ever, it is of significant importance for users to keep their guard up at all times and trust nothing at face value. Studies have shown that the probability of a social engineering attack reduces significantly if users undergo security awareness training and develop muscle memory in identifying red flags and security anomalies. The social engineering minefield is vast and the most effective means for any business to achieve cyber resilience is through building and maintaining a culture of cybersecurity.


About the Author

Stu Sjouwerman is the founder and CEO of KnowBe4, developer of security awareness training and simulated phishing platforms, with over 35,000 customers and more than 25 million users. He was co-founder of Sunbelt Software, the anti-malware software company acquired in 2010. Stu is the author of four books, his latest being “Cyberheist: The Biggest Financial Threat Facing American Businesses.” He can be reached at [email protected].

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Borderless Cyberattacks Among Bordering Nations Soar

U.S.-Russia Summit

Whenever we read about state-sponsored threat actors, the two countries that strike our minds are Russia and China. Government-motivated cybercriminal groups from these countries have been reportedly ruling the underground darknet markets with innovative attack techniques and malware campaigns.

Cyberattacks from these organized groups even blurred the relations among their bordering countries. For instance, economic relations between India and China have worsened after troops from both sides were involved in a skirmish in May 2020. While the duel did not lead to direct war, the cyberespionage campaigns from Chinese attackers continued to disrupt several organizations in India. Recently, security researchers found Chinese hackers targeting multiple Indian organizations in the power and transportation sectors, using common infrastructure tactics, techniques, and procedures (TTPs).

The Anti-Relation Between Russia and U.S.

Most of the cyberattacks or disinformation campaigns that occurred in the U.S. are attributed to Russian government-backed threat actors. The scale of cyber activities by Russian attackers had increased after the Department of Homeland Security (DHS) notified in 2017, that 21 U.S. states were targeted by Russian hackers to sway the 2016 U.S. presidential elections in favor of Donald Trump.

From harvesting Americans’ sensitive information to meddling with the elections, the infamous Russian threat actor groups like APT28, Cozybear, and Strontium performed various cyber-espionage operations on U.S.-based organizations, think tanks, political personalities, and users.

What the Experts Say…

Commenting on the current threat landscape across countries, Admiral (ret.) Michael S. Rogers stated that cyberattacks by nation-states are becoming more proficient and aggressive. Speaking at CyberCube’s webinar, Rogers stated that the extent of cyberattacks has changed with the recent SolarWinds attacks and attacks on Microsoft Exchange servers this month, which are evidence of increased nation-state cyber activities. Rogers is also the former Director of the National Security Agency (NSA) and Commander of U.S. Cyber Command.

“We went through a period between about 2011 and 2017, during which nation-states increased levels of activity. This includes the NotPetya hits in the summer of 2017, probably the largest global event we’ve ever seen. And after that, given its repercussions, there seems to have been a bit of a step back. You’re seeing criminal groups share tools, and you’re seeing the lines between nation-state and criminal groups blur a little bit. The Russians in particular, often tend to use criminal groups to engage in a state-associated activity. This proliferation of tools is creating a challenging environment,” Rogers said.

“We’re not all sitting behind a central security stack right now. Now we’re dispersed. We’ve blurred the lines between what is ‘business infrastructure’ and what is ‘personal infrastructure’. The bottom line is the attack surface is just proliferated as a result,” Rogers added.

New Chinese Malware “CopperStealer” Thieving Credentials Saved by Browsers

Malware and Vulnerability Trends Report, Mobile malware threats

Cybersecurity researchers discovered a new malware making rounds online via fake software sites that targeted popular service providers like Facebook, Google, Instagram, Amazon, and Apple. The undocumented malware, dubbed CopperStealer, is a specially crafted credentials and cookies stealer with a downloader that installs additional malicious payloads on targeted browsers.

Possible Links to Chinese Hackers

According to an investigation from ProofPoint, CopperStealer operates similar to SilentFade malware, which is linked to Chinese hackers that targeted Facebook’s ad platform between late 2018 and February 2019.  “Proofpoint believes CopperStealer to be a previously undocumented family within the same class of malware as SilentFade, StressPaint, FacebookRobot, and Scranos,” Proofpoint said.

How CopperStealer Spreads

It was found that threat actors behind the CopperStealer malware campaign are leveraging compromised accounts to run malicious ads and deliver additional malware on targeted sources.

The researchers identified certain suspicious websites, advertised as KeyGen, Crack, keygenninja, piratewares, startcrack, and crackheap, which hosted CopperStealer malware samples. All these sites have advertised themselves as software crack services to evade licensing restrictions and ultimately provide Potentially Unwanted Programs/Applications (PUP/PUA) or run malicious exploits to install additional malware payloads.

Proofpoint’s researchers stated that CopperStealer malware can find and send saved browser passwords. The multiple browsers searched by malware operators to get Facebook saved credentials are:

  • Chrome
  • Edge
  • Yandex
  • Opera
  • Firefox

Once downloaded, CopperStealer sends the exfiltrated data to the C2 server via a POST request to several targeted URIs. The exfiltrated data is then stored in the info key and is encrypted in the C2 Traffic encryption section.

“In addition to the saved browser passwords, the malware uses stored cookies to retrieve a User Access Token from Facebook.  Once the User Access Token is gathered, the malware requests several API endpoints for Facebook and Instagram to gather additional context, including a list of friends, any advertisement accounts configured for the user, and a list of pages the user has been granted access to,” Proofpoint explained.

Malware Analysis

The CopperStealer malware used various basic anti-analysis techniques to avoid running within researcher systems. These include:

  • IsDebuggerPresent() check
  • GetSystemDefaultLCID() == 0x804 (Chinese (Simplified, PRC)   zh-CN) check
  • Window/class enumeration looking for common analysis tools:
  • TCPViewClass
  • TStdHttpAnalyzerForm
  • HTTP Debugger
  • Telerik Fiddler
  • ASExplorer
  • Charles
  • Burp Suite
  • Device enumeration looking for indicators of virtualization
  • VMware
  • virtual
  • vbox

“While CopperStealer isn’t the most nefarious credential/account stealer in existence, it goes to show that even with basic capabilities, the overall impact can be large.  Findings from this investigation point towards CopperStealer being another piece of this ever-changing ecosystem. CopperStealer’s active development and use of DGA based C2 servers demonstrate operational maturity as well as redundancy,” Proofpoint added.

Unleashing XDR to Transform Enterprise Threat Detection and Response

Endpoint Security

Have you ever wondered why during the outbreak of war, it’s not just one of the armed forces that’s deployed — Army, Navy, Air Force, or Intelligence — but all of them? It’s the classic case of – “The whole is greater than the sum of its parts.” The same analogy applies to cybersecurity, making it pertinent for enterprises to fortify their cybersecurity posture across all possible vectors to avoid an impending breach. That’s why governments, enterprises, and other organizations would do well to re-evaluate their cybersecurity strategy.

By Vijendra Katiyar, Director – Enterprise Business, India & SAARC, Trend Micro

Notwithstanding the increase in investments in cybersecurity in the last five years, the threat landscape is burgeoning. According to a report by Verizon, the meantime to identify a breach has increased to 197 days, and containing it increased to 69 days across the industry vertical.

Traditionally, the endpoint protection platform (EPP) was considered “THE” solution to protect your organization. However, this philosophy has drastically changed with the assumption of the genuine possibility, “I will be breached.” It leads to the next question of effective detection and response strategy to deal with the threat once the network is compromised. EDR strategy has helped organizations to identify and respond to attacks they believe would have gone unnoticed. With the volume and sophistication of modern attacks, does it still hold good?

EDR an Eye-opener: Starting Point in Detection and Response Strategy

EDR was an eye-opener to the industry and a must-have starting point to redefine enterprise-wide Threat Detection and Response (TDR). EDR gives a lot of visibility on what is happening on endpoints by capturing activity data, using which we can detect and respond. However, in an enterprise, the endpoint is just one piece of an IT infrastructure, and there could be EDR blind spots like IoT, printer, contractor/ guest endpoints, etc.

While 94% of attacks start with phishing, email becomes a vital vector to consider. With the increasing cloud adoption and serverless platforms, it has become pertinent to have an effective detection and response strategy for cloud infrastructure. Additionally, there is an entire IT/OT convergence underway, where OT is increasingly becoming part of the IT infrastructure connected to the network. With this scenario, the effective detection and response strategy has to be extended beyond endpoint to email, network, cloud, and IIoT.

Going back to the analogy, to be victorious in war, enemy threats and attacks need to be confronted vehemently at all fronts (i.e., air, land, water) to avoid penetration and siege. You don’t go to war with the Army alone; you usually need the assistance of the Air Force, Navy, and Intelligence side-by-side to complement your overall combat strategy. If we were to juxtapose this analogy to cybersecurity: the endpoint in XDR is the Army; Air support is cloud security; network visibility is the Navy at sea, threat research is Military Intelligence, and the centralized console is your Unified Command.

Emergence of XDR

If you can record what happened on the endpoint, why couldn’t you record everything on the intrusion kill chain for later review? XDR expanded the EDR idea. The XDR platform would give you complete visibility at every phase of the kill chain, including the endpoints, giving enterprises the ability to monitor and account for compromise, no matter where it originates.

The dwell time (MTTD/MTTR) is adequately addressed by XDR through:

  • Full visibility – the complete picture
  • Speed and confidence to respond
  • High fidelity alerts
  • Vendor consolidation
  • Correlation and collaboration

Choosing the Right XDR Solution

An attack that resulted in alerts on email, endpoint, and network can be combined into a single incident. An XDR solution’s primary goals are to increase detection accuracy and improve security operations efficiency and productivity. Effective XDR solution should have:

  • Multi-prevention techniques and not rely on AI/ ML only.
  • Complement existing SIEM/SOAR by sending consolidated high fidelity alerts, which minimizes the level of noise and raw information.
  • Managed services to address skill shortage.
  • Solution/platform to break silos and tell a story of the attack life cycle.

The XDR approach delivers faster detection and response across the multiple security layers because it breaks down the silos, and it tells a STORY instead of making noise.

When you have incomplete threat data, you see an incomplete security picture. Or worse, you may see the wrong picture. And in cybersecurity, the price to pay for seeing the wrong picture is hefty.

This story first appeared in the December issue of CISO MAG. Subscribe now!

About the Author

Vijendra Katiyar is the Director – Enterprise Business, India & SAARC, Trend Micro. He has more than 14 years of experience in technical, sales and cybersecurity consulting. He has driven strategic business decisions with practical tools and processes, translating to Trend Micro’s enterprise revenue growth to 100% in the last four years. He holds Masters of Business IT from RMIT and has successfully pursued the ISB team leadership program along with various other certifications.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

“The sophistication of attacks has changed”

In the times of remote working, ransomware attacks and cyberthreats are the #1 challenge faced by organizations today and are drawing attention to the pressing need for data protection and deploying multiple layers of security into the systems for smooth business continuity.

Keeping this in mind, Augustin Kurian, Senior Feature Writer from CISO MAG, interacted with Anthony Spiteri, a Senior Global Technologist, vExpert, VCIX-NV, and VCAP-DCV working in the Product Strategy group at Veeam. He discusses how Veeam is ushering in the next generation of data protection capabilities that will increase data availability, portability, and extensibility along with the need for continuous data protection and the need for the end-to-end backup environment for business continuity.

Spiteri currently focuses on Veeam’s Service Provider products and partners. He previously held Architectural Lead roles at some of Australia’s leading cloud providers. He is also responsible for generating content, evangelism, collecting product feedback, and presenting at events. Anthony can be found blogging on anthonyspiteri.net.

Here are a few bites from the interview:

DDoS Attacks Surge, DDoS Booters Used to Exploit D/TLS Servers

Multiple Banks and Telecoms in Hungary Affected in a DDoS Attack

Cybersecurity experts found cybercriminals leveraging DDoS booters to exploit misconfigured or outdated Datagram Transport Layer Security (D/TLS) servers to launch Distributed Denial of Service (DDoS) attacks. A D/TLS is a communications protocol that provides security to datagram-based applications and prevents eavesdropping, tampering, and message forgery in apps and services.

What is a DDoS Booter?

A DDoS booter is a DDoS-for-hire service platform that provides threat actors the ability to attack any targeted resource online anonymously. Most threat actors build their DDoS infrastructure by using DDoS booter services to cause various levels of disruption attacks.

In a DDoS attack, threat actors try to make a targeted system or service unavailable to its users by flooding with unwanted incoming traffic from different sources.

Risk of Amplification Attacks

According to a report from NETSCOUT Systems, misconfigured D/TLS servers don’t execute the “HelloClientVerify” anti-spoofing mechanism that can be exploited to launch amplification attacks (DDoS) with an amplification ratio of 37.34:1. In an amplification attack, the attacker uses the amplification factor to multiply the intensity of the attack. Typically, amplification attacks use low-level resources that eventually cause significantly higher-level damage to targeted resources.

The report identified over 4,283 abusable D/TLS servers so far. “The collateral impact of D/TLS reflection/amplification attacks is potentially quite high for organizations with D/TLS servers and/or load-balancers that are as reflectors/amplifiers. Failure to upgrade or safely reconfigure abusable D/TLS servers so that they can no longer be leveraged by attackers may result in blockage of legitimate production services running on abusable D/TLS servers by network operators utilizing layer-3 or -4 mitigation techniques to defend themselves and/or their customers from D/TLS reflection/amplification DDoS attacks,” the report stated.

Uprise in DDoS Attacks Concern Organizations

The latest analysis from the German DDoS protection vendor Link11 revealed that DDoS attacks attained a record high, leveraging the rapid digital transformation during the pandemic.

Key Findings

  • The number of DDoS attacks nearly doubled from February to September 2020. It Is estimated that there were 50 million DDoS attacks worldwide in a year.
  • Businesses with inadequate cybersecurity measures suffered from high-volume attacks of over 50Gbps.
  • Nearly, 59% of incidents used so-called multi-vector attacks, which are harder to prevent and defend against DDoS attacks.
  • Numerous new DDoS vectors were detected; in particular, DVR DHCPDiscovery, Plex Media Server, and Citrix Netscaler.
  • The longest DDoS attack was 5,698 minutes equating to four full days of continuous bombardment.

“We’ve seen a large increase in vulnerabilities that can be exploited by DDoS attacks. Attackers are constantly scanning the internet for new ports and protocols that can be used to overload companies’ IT infrastructures. Not all companies have adapted to this threat, and there have been many headline-grabbing outages as a result,” said Marc Wilczek, Managing Director of Link11.

Related Stories:

On ethics, morals, and information security

active directory
active directory

In the early noughties, the demand for IT professionals spiked in India. Becoming a software engineer and migrating to the United States was a goal for many. However, the recession in 2008 reduced the demand for human resources in the U.S., and many IT companies in India were not hiring because of low demand in its key market. With fewer enticing packages available, a breed of entrepreneurs emerged – especially in the tech space – laying the foundation for India’s startup culture. Space also opened up for information security, particularly ethical hacking, to become a sought-after career.

By Augustin Kurian, Senior Feature Writer, CISO MAG

Eventually, India surpassed several other countries and started producing more ethical hackers than anywhere else in the world, which led to India becoming the number one bug bounty collector, globally. Despite this boom, the old cycle emerged where working for a foreign country seemed to be a wiser choice. Other countries in the developing world have under-utilized pools of ethical hackers. A recent report on AFP pointed how Indian ethical hackers are rewarded everywhere but not in their country of origin. “It was a familiar tale for India’s army of “ethical hackers,” who earn millions protecting foreign corporations and global tech giants from cyber-attacks but are largely ignored at home, their skills and altruism misunderstood or distrusted,” the report points out.

The report highlighted several young ethical hackers in India who have earned tens and thousands of dollars in bug bounties for the quick-responding technology tycoons like Facebook. When notified about a technical glitch, large, typically foreign companies respond positively and quickly. Similar encounters with Indian companies are ignored most of the time, or are met with the legal team of the company saying “What are you doing hacking our site?”

This lackluster attitude must explain why the country with the most ethical hackers was ranked 23rd in the last Global Cybersecurity Index. What’s even more staggering is the fact that the country’s immediate neighbor China is an example of the exact opposite situation.

What makes China different?

China is the country with the most internet users in the world. In 2014, the number stood at 640 million. But there is a dark side to all this surfing China accounts for 41 percent of global cybercrime, which was thrice that of countries like the U.S. Hacking continues to be one of the most lucrative business opportunities for information technology professionals in the region.

Unlike India, where contributions of hackers are not appreciated, China employs the creme-de-la-creme to work for the government for secret government missions. A former prominent Chinese hacker interviewed by the New York Times admitted: “I have personally provided services to the People’s Liberation Army, the Ministry of Public Security and the Ministry of State Security. If you are a government employee, there could be secret projects or secret missions.”

Aftermath of Stuxnet

Countries like Iran also have a similar perspective toward hackers. Iran has grown to be a hacker nation. The country is among the most wired nations in the Middle East, with over 70 percent of the population having access to the Internet. Since the Stuxnet attack, the country has increased its cybersecurity spending 12 fold. President Hassan Rouhani, immediately after taking office, increased the annual cybersecurity budget by roughly $20 million. Hacking is legal in the country if you are doing it for the government. Unlike most countries in the world, hackers in Iran have a rather public life and a celebrated job.

“Out of any country on the planet, I can’t think of a country that has been more focused than Iran from the high levels of government on cyber, and that includes the United States,” Dmitri Alperovitch, co-founder of cybersecurity firm CrowdStrike, told The Hill. The hacker community of Iran is not made up of college dropouts hacking computers from basements or dorm rooms. Hackers in Iran are highly educated, possessing master’s degrees and Ph.Ds. According to a Business Insider report, “Many Iranian professors are educated in the West and maintain close ties to institutions like MIT, Carnegie Mellon, Virginia Tech, and Northeastern University.” Apart from these, Iran itself has numerous great universities like Islamic Azad University, Yazd University, Sharif University of Technology, and Isfahan University. Most of these are top-notch schools with multiple specialization courses reaching the standards of Ivy League.

The Pariah Nation and its Cybersecurity Capabilities

Ethical hacking is defined differently in different nations. For a country that has been on the top of the notorious list like North Korea, the term ethical hacking might mean cyber warfare with other nations.

On November 22, 2014, the employees at Sony noticed skulls appearing on their screens with a message threatening to expose secrets from data obtained in a sophisticated hack. The team troubleshooter identified it as an attack. It wasn’t like any other worm or virus they had come across before. They had been targeted by nation-sponsored actors and this triggered a frantic alert. The computers were crippled and the employees were forced to work with pen and paper. The hacker group Lazarus was linked to the attack. An investigation by the Federal Bureau of Investigation went on to conclude that North Korea was behind the breach.

Through the years, North Korea has been linked to series of cyber-attacks, either to display its cyber prowess or just to fund their activities. One of the most brazen attacks occurred in February 2016 when hackers tried to steal $101 million from a Bangladesh Central bank account at the New York Federal Reserve and move it to Sri Lanka. Only a spelling error caused the banks to realize they were under attack. Un’s minions got away with nearly $81 million––most of which is yet to be recovered. “Security researchers later established that similar tactics had been used to attack banks in Ecuador, the Philippines, and Vietnam. But that was only part of the picture: Researchers at cybersecurity firm Kaspersky Lab said in April Lazarus also attacked financial institutions in Costa Rica, Ethiopia, Gabon, India, Indonesia, Iraq, Kenya, Malaysia, Nigeria, Poland, Taiwan, Thailand, and Uruguay,” according to CNN. “The Lazarus hackers carefully routed their signal through France, South Korea, and Taiwan to set up their attack server, according to Kaspersky. But researchers noticed one mistake: A connection that briefly came from North Korea.”

The Center of The Earth

On the other hand, there is Israel, a country where a huge number of its soldiers are trained in the art of cyber-warfare. Many of them continue in jobs that protect their businesses and infrastructure once they leave the military, supplying the country with a steady stream of cyber experts.

Singapore is another example of a country that has made huge strides toward keeping cyber threats at bay. The Global Cybersecurity Index rated Singapore as the best country as far as its approach to cyber security, outperforming many richer nations. A recent example of the country’s commitment to information security is when the Singapore government was deciding whether to establish cybersecurity standards with the Association of Southeast Asian Nations (ASEAN) to strengthen the protection of critical information infrastructure. Several government officials highlighted the urgent need for stronger safeguards against cyber-attacks and called on the ASEAN to cooperate in the cross-border protection of internet-based systems. The Singapore Parliament has also passed the Cybersecurity Bill in which owners of key bodies like national security, defense, foreign relations, economy, public health, public safety, or public order, which the bill calls critical information infrastructure (CII), will have to comply with the standards and regulations mandated by the bill. The bill also mandated CIIs to conduct cybersecurity audits and risk assessments, and routinely participate in cybersecurity exercises.

The Westworld

In the Global Cybersecurity Index survey, the U.S. came second. Estonia ranked highest of the European economic area (EEA) countries at number five, while France came ninth, Norway came eleventh, just ahead of the UK in 12th position overall. One trends in all this data is that many of the top-ranked countries were small or developing nations. The survey also pointed out how nearly 50 percent of countries did not have a national security strategy. “There is still an evident gap between countries in terms of awareness, understanding, knowledge and finally capacity to deploy the proper strategies, capabilities and programs,” the survey said.  “Cybersecurity is an ecosystem where laws, organizations, skills, cooperation and technical implementation need to be in harmony to be most effective. The degree of interconnectivity of networks implies that anything and everything can be exposed, and everything from national critical infrastructure to our basic human rights can be compromised.”

Cybersecurity varies in a myriad of ways from country to country, and so does the knowledge and awareness and very definition of ethical hacking. The gap between nations and their cybersecurity prowess among countries and their ecosystem also differs. “To set up a cybersecurity process, it is important to identify correctly the assets and resources that need to be protected, so as to accurately define the scope of security needed for effective protection. This requires a global approach to security, one that is multidisciplinary and comprehensive. Cybersecurity does not sit well with a freewheeling world that places a premium on permissiveness. What is required is a set of core principles of ethical behavior, responsibility and transparency, embodied in an appropriate legal framework and a pragmatic body of procedures and rules. These must be enforced locally, of course; but they must also be applied across the international community and be compatible with the existing international directives,” suggests ITU in its report titled Cybersecurity Guide for Developing Countries.

What should be learned?

Countries like India with the most ethical hackers have shown some sour results when it comes to protecting its infrastructure, while there are several nations that has information security oddly misplaced on their moral grounds like in the case of North Korea, where a sizable cyber infrastructure is involved in clandestine cyber warfare. What is considered ethical in one country isn’t in another and moral relativisim plays into the definitions of an entire industry. The world has come to a point where it is imperative for countries to differentiate between hacking and ethical hacking, as keeping a higher moral ground is the key here. The world needs more hackers, more white hat hackers.


Augustin KurianAbout the Author

Augustin Kurian is part of the editorial team at CISO MAG and writes interviews and features.

Indian Transport Sector on Hackers’ Radar; CERT-In Warns

Indian bus

As a country with the second-largest population and the third-largest economy, India-based organizations are a prime target for cybercriminals. Several cyberattacks have been reported on various industries and sectors in India that affected a large number of people in the country. Recently, the Indian Ministry of Road Transport and Highways warned the National Highway Authority of India (NHAI) and other transportation agencies to reinforce their security standards and immediately perform a thorough security audit of all their IT systems.

What the Indian Ministry says…

The Indian Ministry of Road Transport and Highways stated that it recently received an alert from the Indian Computer Emergency Response Team (CERT-In) about a potential cyberattack on the transport sector.

Along with NHAI, the Ministry also warned other transport bodies like the National Highways and Infrastructure Development Corporation (NHIDCL), Indian Road Congress (IRC), Indian Academy of Highway Engineers (IAHE), testing agencies, and automobile manufacturers.

“Ministry of Road Transport and Highways received an alert from CERT-In regarding targeted intrusion activities directed towards Indian Transport sector with possible malicious intentions. The Ministry has advised departments and organizations under the transport sector to strengthen the security posture of their infrastructure,” the Ministry said.

“Accordingly, NIC, NHAI, NHIDCL, IRC, IAHE, State PWDs, Testing agencies, and Automobile manufacturers have been requested to conduct the security audit of the entire IT system by CERT-In certified agencies regularly and take all actions as per their recommendations.  The audit report and the ATR must be regularly submitted to the Ministry,” the Ministry added.

The Chinese Angle

CERT-In stated that it has noticed continued intrusions from Chinese threat actors against the Indian transport sector to pilfer critical intelligence information and perform cyber-espionage campaigns. As per a report, cybercriminal groups like APT41 (Barium), Tonto Team, APT101 (StonePanda), APT15 (K3yChang), APT27 (Emissary Panda), Winnti groups & RedEcho have been targeting Indian organizations that have been involved in national strategic activities.

The adversaries have allegedly used spear-phishing techniques or exploited known vulnerabilities to break into the enterprise network systems.  Indian transportation agencies like Indian Railway Catering and Tourism Corporation (IRCTC), Tata Motors, NHAI, Rail India Technical and Economic Service (RITES), Dedicated Freight Corridor Corporation of India (DFCCIL), Centre for Railway Information Systems (CRIS), and Roads & Building Dept, Andhra Pradesh have been asked to stay vigilant and strengthen their security infrastructure.

 How a Cyberattack could affect the Transport Sector

There have been vast improvements and enhancements in IT and interconnectivity in the Indian transportation industry. For instance, IRCTC is one of the largest ticketing, catering, and tourism services providers globally. Transportation companies are widely deploying GPS tracking systems, signaling systems, and IoT sensors on vehicles. Cyberattacks on such systems may cause disruption in supply chains (freight) and public transportation. There would be revenue losses due to security data breaches, identity theft, and property damage. Hackers would exploit a transportation company’s digital assets and engage in cyber extortion (ransomware).

The potential cyberthreat alert to the transport sector comes just weeks after security experts discovered a Chinese state-sponsored group “Red Echo” that targeted ten Indian Power Sector Companies and two Seaports. Microsoft also warned its users and clients about recent cyberattacks from China-based malicious actors against Microsoft’s Exchange Server software.