Home Blog Page 105

Update Your Chrome Browser to Patch High-severity Zero-day Vulnerability

Chromebook vulnerability

For a third time this year, Google released security updates to fix a zero-day vulnerability in its Chrome browser, which is being exploited in the wild. The vulnerability tracked as CVE-2021-21193 exists in the Blink rendering engine.

The security patch is available with the latest 89.0.4389.90 version for Linux, Windows, and Mac platforms in Google’s Stable Channel Update for Desktop. While the vulnerability was discovered by an anonymous researcher, Google did not reveal more details about the flaw to avoid exploits from threat actors. Google also released patches for two other high-severity vulnerabilities: CVE-2021-21191 – in WebRTC and heap buffer overflow flaw CVE-2021-21192.

Google Addressed 37 Critical Flaws  

In its March 2021 Android Security Bulletin, Google addressed 37 vulnerabilities in its Android Operating System, including a critical flaw in the System component. All the flaws are rated highly severe, which, if exploited, could allow a remote attacker to launch remote code execution, elevation of privilege, and information disclosure attacks. The critical vulnerability “CVE-2021-0397” affects Android products of 8.1, 9, 10, and 11 versions. If exploited successfully, the flaw could allow an attacker to execute a malicious code remotely on vulnerable devices.

Google also recommended certain mitigation measures to reduce the likelihood of security vulnerabilities from becoming exploitable. These include:

  • Exploitation for many issues on Android is made more difficult by enhancements in newer versions of the Android platform All users are encouraged to update to the latest version of Android where possible.
  • The Android security team actively monitors for abuse through Google Play Protect and warns users about Potentially Harmful Applications. Google Play Protect is enabled by default on devices with Google Mobile Services and is especially important for users who install apps from outside of Google Play. 

Related Story: How to Detect Weak Passwords Using Google Chrome

McAfee Reveals the Unknown About Babuk Ransomware

John Fokker, McAfee, babuk ransomware analysis

Babuk Ransomware has turned out to be one of the most successful ransomware campaigns to hit organizations in 2021. At least five organizations confirmed to have been breached by the newly discovered strain in mid-Jan — and one is known to have paid as much as $85,000 to the criminals.

McAfee’s Advanced Threat Research team released new findings into the strategic operations behind this ransomware campaign. In an email interview with Mihir Bagwe of CISO MAG, John Fokker, Head of Cyber Investigations and Principal Engineer, McAfee reveals hitherto unknown findings into how Babuk ransomware spreads, its unique vectors/techniques, and its methods to evade detection.

Prior to joining McAfee, Fokker worked at the National High Tech Crime Unit (NHTCU), the Dutch national police unit dedicated to investigating advanced forms of cybercrime. Within NHTCU he led the data science group, which focused on threat intelligence research. Through his career he has supervised numerous large-scale cybercrime investigations and takedowns. Fokker is also one of the cofounders of the NoMoreRansom Project. He started his career with the Netherlands Police Agency as a digital forensics investigator within a task force against organized crime. Before joining the national police, he served in the special operations and counterterrorism group of the Royal Netherlands Marine Corps.

Formerly a member of Royal Netherlands Marine Corps, Fokker has spent most of his career on the Special Operations team and was deployed to both Afghanistan and Somalia. During this time, he learnt valuable skills like problem solving and how to think outside-of-the-box which have proved critical in his current role, leading investigations against cyber criminals around the world.

John Fokker quote for CISO MAG

Edited excerpts of the email interview follow:

What were the key findings of your research? 

Babuk is the first new Ransomware family of 2021. In spite of being new, they are agile in their development and have high ambitions. Also, it was the first ransomware family that expressed themselves negatively against the BlackLivesMatter (BLM) and LGBT communities.

On doing a deep dive into previous attacks we discovered that this ransomware embeds three different built-in commands to spread itself and encrypt network resources. It checks the services and processes running so it can kill a predefined list and avoid detection.

McAfee’s analysis provides evidence that the adversaries behind Babuk targeted organizations in the transportation, health care, plastics and electronics manufacturing, and agriculture sectors.

With no local language checks embedded in the malware, their code contrasts other ransomware gangs that normally spare devices in specific countries.

Babuk ransomware is known to use new techniques like multi-threading encryption and abuses Windows Restart Manager. Can you shed more light on these techniques as to how they work and what’s different in them than others?

Multi-threading encryption is often applied by threat actors to maximize the speed of encryption. However, the downside of multi-threading is that it is very CPU and process heavy so it can trigger alerts before the encryption is complete.

We believe changing the “SetProcessShutdownParameters” to 0 is done to confront the user with the Ransomware and force the user to perform a reboot of the machine thus erasing any traces that are left in memory.

Has your research team found any more unique vectors/techniques of Babuk ransomware?

Babuk ransomware binary did not include a local language check option, something that is really common amongst other Ransomware Families.

Files are enumerated in the typical way for ransomware, but Babuk has a curious check that other ransomwares do not have — it encrypts a maximum of 16 folders deep, meaning that if one folder has 17 or more subfolders, the 17th and onward are ignored. This is probably to speed up the encryption process.

Babuk was one of the first ransomware families in 2021 that announced working on a version that could also encrypt Unix/Linux based systems (ESXI and NAS).

What stands out as well with Babuk is the racial and anti-LGBTQ statements in its advertisements.

How does Babuk hide itself and avoid detection?

Babuk itself has relatively simple code structures, for instance the samples we examined were unobfuscated. Given the recruitment specifics for the affiliates we found online, we believe that Babuk is deployed at a stage that the attackers have already gained full control of a victims’ network and have shut down the victims’ security defenses, thus making it less important to build in defense evasion in the code base of the binary.

Do you see a trend emerging where the next generation of Ransomware (and Ransomware gangs) could use some of the same techniques at Babuk ransomware?

This is already happening. Babuk uses very similar techniques as the other big-game ransomware families. The affiliates that perform the actual penetration and exploitation have become very skilled groups that are proficient in compromising a complete network.

Are there any signs of code reuse in Babuk ransomware as we generally see in other ransomware source codes?

We examined that the code similarity between Babuk and other ransomware families that we are tracking; we discovered an 86% overlap with other families including Vasa Locker, even the ransom note showed a high degree of overlap. This relationship can indicate that the group behind Babuk have created their ransomware based on Vasa Locker.

The threat group behind it seems to be targeting multiple sectors. Recent ransomware attacks paint an opposite picture though. They are industry specific and have a clear motivation behind them. What could be Babuk operators’ aim in this case? Are they newbies trying to establish themselves or just targeting larger audiences for better returns?

Babuk, like many other ransomware families, is flexible in its targeting. We don’t believe that the major families are strictly industry specific. This perception mostly lies in the fact that the sectors that are susceptible to being extorted by disclosing stolen data are the attacks that hit the headline news. However, there are far more attacks happening and that shows ransomware gangs largely operate like bull-sharks, attacking anything that moves, or in this case, any organization that is vulnerable and has money.

Are the operators of the Babuk ransomware only going after larger corporations or should smaller organizations also be wary of it?

As McAfee, we would advise every organization to take the threat of ransomware very seriously, even smaller organizations might have a significant revenue and security isn’t always at their top of priority. During our daily research we see many organizations fall victim in situations that could have been avoided with the right pro-active security measures. For instance, using a security solution such as McAfee MVISION Insights, that allows an organization to become action-oriented, and pro-active against cyber threats.

About the Interviewer

CISO MAG Writer - Mihir Bagwe
Mihir Bagwe is a Tech Writer and part of the editorial team at CISO MAG. He writes news features, technical blogs, and conducts interviews on latest cybersecurity tech and trends.

 


Other Interviews from the Author:

After Hafnium, DearCry Ransomware Targets Microsoft Exchange Servers

microsoft, flaws in SonicWall SRA SMA

The Microsoft Exchange attacks are taking new twists day by day. In just days, the threat escalated from limited state-sponsored attacks to numerous targeted attacks by multiple hacking groups. The severity of the attacks also escalated from web shells to ransomware. “We have detected and are now blocking a new family of ransomware being used after an initial compromise of unpatched on-premises Exchange Servers,” Microsoft said.

Microsoft’s security researcher Phillip Misner stated that ransomware operators are now exploiting recently disclosed ProxyLogon vulnerabilities in their attacks. It was found that the threat actors installed new ransomware dubbed “DearCry” after compromising Microsoft Exchange servers.

What Misner says…

Once compromised, the DearCry ransomware creates a Windows service “msupdate” that encrypts the sensitive information. Thousands of Exchange servers are suspected to be vulnerable to DearCry ransomware. Besides, it is believed that hundreds of servers have already been compromised.

Hafnium is Still Active!

Earlier, Microsoft Threat Intelligence Center (MSTIC) identified a state-sponsored threat actor group targeting unpatched vulnerabilities in Microsoft systems. Dubbed as Hafnium, the hacking group is suspected to be operating from China, with leased virtual private servers (VPS) in the U.S. Earlier, the group targeted several entities in the U.S. to exfiltrate sensitive data from multiple industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs.

Patch Now!

Microsoft released fixes to address four Zero-day vulnerabilities (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) and three other vulnerabilities (CVE-2021-27078, CVE-2021-26854, and CVE-2021-26412) in its Microsoft Exchange servers. The technology giant urged organizations and users to apply the available security patches or temporarily disable external access to Microsoft Exchange as early as possible.

“Our strong recommendation that customers upgrade their on-premises Exchange environments to the latest supported version. For customers that are not able to quickly apply updates, we are providing the following alternative mitigation techniques to help Microsoft Exchange customers who need more time to patch their deployments and are willing to make risk and service function trade-offs,” Microsoft added.

AMD’s Newest EPYC 7003 Series Processors Arrive with Additional Security Features

MediaTek, Intel Processor Vulnerability, chip

On March 15, 2021, AMD launched its latest EPYC (Extreme Performance Yield Computing) 7003 Series processors – “Milan” – intending to improve the speed, agility, and core performance of its EPYC processors for faster business outcomes. Correspondingly, AMD also introduced some salient modern-day security features that give the 7003 Series the edge over its competitors.

AMD’s Latest EPYC 7003 Series Processors

The newest generation of 7003 Series processors imbibes the Zen 3 architecture, which AMD says significantly improves performance for enterprise, cloud, and HPC workloads. The hardware manufacturer claims that it delivers “the best performance of any server CPU with up to 19% more instructions per clock.”

Technically, this is the 3rd Generation of AMD’s EPYC processors, and thus, taking into consideration the current security risks to businesses, AMD has introduced a host of security features like:

  • Secure Memory Encryption (SME)
  • Secure Encrypted Virtualization-Encrypted State (SEV-ES)
  • Secure Encrypted Virtualization-Secure Nested Paging (SEV- SNP)
  • A dedicated security subsystem
  • Hardware-validated secure boot
  • Hardware root of trust

The SEV and SNP Features

AMD Infinity Guard offers a robust set of security features that help complement industry ecosystem partners at both the software and system levels. The SEV and SNP security features are both provided under the AMD Infinity Guard.

SEV-ES: This provides a layer of protection for CPU registers. AMD has added interrupt restrictions that should prevent malicious hypervisors from injecting interrupts and attacking ES guests. The new AMD EPYC processors help safeguard the privacy and integrity of data by encrypting each virtual machine with one of up to 509 unique encryption keys known only to the processor.

SEV-SNP: Another important and new feature that AMD has introduced is SNP, which provides enhanced memory protections against malicious hypervisors carrying out replay, corruption, or remapping attacks. SNP creates an isolated execution environment which helps in adding memory integrity protection capabilities designed to prevent hypervisor attacks.

The AMD EPYC processor ecosystem is expected to grow significantly by the end of 2021 with numerous OEMs, ODMs, cloud providers, and channel partners like AWS, Cisco, Dell Technologies, Google Cloud, HPE, Lenovo, Microsoft Azure, Oracle Cloud Infrastructure, Supermicro, Tencent Cloud and others announce its integration into their respective ecosystems.


Related News:

With Pluton, Microsoft Brings Chip-to-Cloud Security Tech to Windows PCs

Is Samsung’s New Data Security Chip a Game Changer?

Not Just Hands, Your PDFs Also Need to be Sanitized

75% Of Security Pros Say Remote Work Led to Changes in Financial Services Cyber Programs: Survey

Most organizations and security agencies publish and share Portable Document Format (PDF) files without proper sanitization, leaving them open to data theft. Cybersecurity experts suggest that most users and businesses are unaware that cybercriminals often target these kinds of PDF documents to pilfer sensitive information and exploit them to attack an organization.

A recent analysis found that security agencies are not sanitizing PDF docs before sending them to others. The analysis collected a corpus of 39,664 PDF files published by 75 security agencies, from 47 countries to find out the quality and quantity of data leaked from these PDF files. It was found that these files can be misused to find loopholes in an organization, like discovering employees who use outdated software.

What is PDF Sanitization? 

PDF sanitization is a process of removing classified and sensitive data from a protected document before its publication. Also known as Data Anonymization, the sanitization process reduces the document’s classification level, possibly making the document an unclassified one.

Low Adoption of Sanitization

Besides, the analysis revealed that the implementation of the sanitization procedure within security agencies is low. It was found that only seven organizations used it to remove hidden sensitive information from their PDF files, before publishing. And 65% of these sanitized PDFs still contained sensitive information. This is because some organizations are using weak sanitization techniques. A proper sanitization procedure requires removing all the hidden sensitive data from the PDF docs and simply deleting important data.

Hidden Data Found in PDF Files 

According to the National Security Agency (NSA), 11 types of hidden data and embedded content can be found in PDF files. These include:

  • Metadata
  • Embedded Content and Attached Files
  • Scripts
  • Hidden Layers
  • Embedded Search Index
  • Stored Interactive Form Data
  • Reviewing and Commenting
  • Hidden Page, Image, and Update Data
  • Obscured Text and Images
  • PDF Comments (Non-Displayed)
  • Unreferenced Data

The NSA stated that a PDF file is safe for publication and distribution only after removing these 11 types of hidden information from it.   

Levels of Sanitization

The NSA also listed four levels of sanitization:

Level-0 – Consists of PDF files that include complete metadata information. There is no sanitization.

Level-1: Consists of PDF files with partial metadata after removing certain metadata fields.

Level-2: Consists of PDF files without any metadata.

Level-3: Consists of PDF files with no information leakage and properly cleaned (Full Sanitization)

“The issue is that popular PDF producer tools are keeping metadata by default with much other information while creating a PDF file. They provide no option for sanitization or it can only be achieved by following a complex procedure. Software producing PDF files needs to enforce sanitization by default. The user should be able to add metadata only as an option,” the researchers said.

Hackers’ Info Leaked from Now Defunct “WeLeakInfo” Platform

phishing campaign, Smishing attacks

Security experts found a threat actor from a hacking forum selling stolen databases that contain sensitive data of more than 24,000 customers from a banned online platform WeLeakInfo.com.  Cybercriminals used to leverage the WeLeakInfo.com platform for trading stolen information and to discuss various hacking techniques with other attackers in the community.

Information Leaked

The hacker posted a ZIP file that contained payment data of WeLeakInfo customers who made illegal purchases using Stripe, an online payment processing service. The leaked file exposed sensitive information including full names, partial credit card data, transaction dates, Stripe reference numbers, currencies and amounts paid for stolen data, email addresses, IP addresses, addresses, and contact numbers. In the post, the hacker also clarified that users who bought stolen data from WeLeakInfo through PayPal or Bitcoin were not affected by the incident.

Hacker’s Post

Image Courtesy: CyberNews

Hackers Domain Resurfaces!

Security experts from Cyble claimed that a member of the WeLeakInfo platform re-registered wli.design, which is one of the domains of WeLeakInfo.

“The WeLeakInfo operators allegedly used the domain’s email address for payments via Stripe. The actor claimed to have registered the domain and then created an email address on the registered domain used in their Stripe account. Upon access to WeLeakInfo’s Stripe account, the actor allegedly gained access to their customers’ details (including email, address, partial card details, purchase history, and others),” Cyble said.

 FBI’s Take Down of WeLeakInfo

In January 2020,  the FBI and the U.S. Department of Justice seized the WeLeakInfo.com domain for selling sensitive information that was hacked from other sources in the past three years. According to the official notice, published by the U.S. Attorney Jessie K. Liu of the District of Columbia and Special Agent in Charge Timothy M. Dunham of the FBI’s Washington Field Office, WeLeakInfo sold more than 12 billion user records that included names, usernames email addresses, phone numbers, and passwords for online accounts.

Code Girls: The Bluestockings of Cybersecurity

The story dates to 1941, when mysterious letters appeared in the mailboxes of a few select students at Seven Sister colleges, seven liberal arts colleges in the Northeastern United States that are historically women’s colleges. These were students who had shown unparalleled skills in fields like Math, English, history, foreign languages, and Astronomy. Each student who received a letter was asked to meet with senior professors who asked them some rather peculiar questions — did they like crossword puzzles? Did they have wedding plans? All the selected students were women, and they did not have an inkling that they were being inducted into serving their country in a task that would stay secret for the next seventy years or more. These were the “Code Girls.”

By Augustin Kurian, Senior Feature Writer, CISO MAG

While history remembers the contributions of Alan Turing and his celebrated feat of breaking the enigma code helping Britain win World War II, these were his western counterparts who achieved a feat similar to the cryptographers at Bletchley Park. These women of prodigious intellect worked day in and day out translating documents and forming teams to solve the elaborate, ever-changing codes of the Japanese and German navies. Life wasn’t easy for them as they dealt with bureaucratic rivalries and administrative sexism. Liza Mundy in her book “Code Girls: The Untold Story of the American Women Code Breakers of World War II” tells the stories of these female cryptographers who cracked several diabolically difficult systems. In 1944, the code-breakers intercepted and decoded 30,000 water-transport messages a month. They were instrumental in enabling the U.S. Navy to pinpoint and sink several supply ships heading to the Philippines and South Pacific. They also created and spread false intel about Allied landing sites for the Germans to intercept.

The Code Girls were arguably America’s first ethical hackers, or rather the modern-day bluestockings — similar to the intellectual women of the 18th century.

Mundy’s book quotes a code-breaker named Ann Caracristi as saying, “It was generally believed that women were good at doing tedious work, and… the initial stages of cryptanalysis were very tedious, indeed.” She reflected “never in my life since have I felt as challenged as during that period… When the needs of society and the needs of an individual come together, we were fulfilled.”

But after the war was over, the women were expected to give up their jobs and jump right back on the baby-making bandwagon. Only a few were able to get high-level positions at the NSA, while for the rest, their tremendous achievements were buried deep in the classified pages of war secrets.

Cut to the present and women in cybersecurity have been a widely discussed topic. Women make up only 24% of the global cybersecurity workforce. “In the United States, I’ve observed that women consider the field to be too technical, preferring to work with people rather than technology. I don’t see that same reluctance among my international female students. I have to think it must be something tied to the culture—a meme that ‘girls don’t like this work,’” points out Barbara Endicott-Popovsky, Executive Director, Center for Information Assurance and Cybersecurity; Fellow, Aberystwyth University, Wales. “Some say that women don’t like the culture of cybersecurity organizations—they are too rough, too male, unfriendly—perhaps intimating bias. I’ve only had to address a couple of instances of clear female bias in my career; it may have been more prevalent, but my nature is goal-driven and curious, so I don’t allow myself to be distracted from my goals. In my experience, if you are passionate about what you are doing, distracting nonsense fades into the background. Find your passion, know how to prepare yourself, and then the rest of this resolves in the background.”

The first step towards solving any problem must be identifying that there is one. Several studies around women in cybersecurity point out how the disparity traces its roots back to school. “Lack of awareness among those advising students/girls of the many opportunities in high-paying cybersecurity careers is at the root of the problem. Colleagues who have held cybersecurity events specifically for young women have found a huge interest can be developed. The field is fun, exciting, ever-changing—like being a sleuth, tracking down adversaries, putting a puzzle together,” suggests Barbara. “This field wasn’t here 20 years ago when educators and advisors were getting prepared to teach and counsel. We need targeted programs to raise awareness among educators from K-12 through bachelor’s degree programs. We need a pipeline.”

In an online survey, Kaspersky Labs and Arlington Research pointed out that the average age at which young women decide on their future career is 15 years and 10 months, and those that haven’t decided by this time expect to have decided by the age of 21 and 9 months, making it very difficult for cybersecurity firms to influence their choices after this point. In 2010, even though 57% of undergraduate degree recipients were female, only 14% of them pursued majors in the same field.

Often, even when women do venture into the field, they struggle to make it into management positions. A global survey of nearly 22,000 firms revealed that “almost 60% of firms have no female board members, just over half have no female ‘C-suite’ executives, and roughly one-third of the sample has no women in either C-level or board positions. The results suggest that the presence of women on corporate boards and in C-suite positions may contribute to firm performance. The impact is greatest for female executive shares, followed by female board shares; the presence of female CEOs has no noticeable effect. This pattern underscores the importance of creating a pipeline of female managers and not simply getting women to the very top.

Gender diversity comes coupled with surprising benefits

“Let me start by explaining why I think having more women in cybersecurity makes us all safer. In cyber, you need diverse points of view or you’ll miss potential threats. You must be right 100 percent of the time. The flawed hypothesis methodology – with which I fully agree — ensures having a diversity of perspectives when you form a vulnerability assessment team. This diversity is critical because if your organization recruits people with similar backgrounds, you’ll end up seeing everything the same way; however, if you have a diversity of views, then your organization will benefit from a wider situational awareness of possible flaws in the system. What I would really recommend women do is set their sails and don’t look back,” Barbara stresses.

According to her, “There is something for everybody – pathways range from purely managerial to deeply technical. Go through the framework and find what you’re interested in. Think about your gaps and how to fill them with further education and training. I encourage women to do what they’re passionately interested in and be persistent in pursuing their goals.”

Women were in the vanguard of cybersecurity and played a pivotal role in World War II, but their potential has not been tapped in the digital war the world is currently fighting.

While CISO MAG has discussed, Turing possibly being the first and the greatest ethical hacker who ever lived, the stories of these young women aren’t that different from his. They were among the first to work in cryptography and early ethical hacking, making huge advancements for their country in a time of war. In an industry that has been marred by the oft-reported lack of gender diversity, these women’s stories should remind us that the realm of information security wasn’t always dominated by men. Their stories should also highlight the fact that we have a long way to go, as the 1940s weren’t all that different from some women’s experiences today in some respects. As Mundy points out in her book, “It was not easy being a smart girl in the 1940s. People thought you were annoying.”


Augustin KurianAbout the Author

Augustin Kurian is part of the editorial team at CISO MAG and writes interviews and features.

 

CISO MAG’s March issue on Women in Cybersecurity is out. Preview hereSubscribe now!

 

How to Know if You’re Being Stalked by Stalkerware

Doxing attacks

At a time when everyone is more connected than ever, cybercriminals too have become more active looking for ways to turn an adverse situation to their advantage. Since the beginning of the pandemic, threat actors have been leveraging innovative techniques to stalk their targets. A recent analysis revealed a 51% increase in the use of spying and stalking apps globally since the lockdown started.

 By Rudra Srinivas, Senior Feature Writer, CISO MAG

What is Stalkerware?

Whether it is a malicious actor, suspicious partner, or a spying employer, the use of Spyware and Stalkerware apps has significantly increased in recent times. Such apps serve as powerful surveillance tools capable of working in stealth mode. Stalkerware has the ability to spy on users’ online activities like tracking their location; accessing their personal data, communications from WhatsApp and Facebook; eavesdropping on phone calls; and making covert recordings of conversations without the target’s knowledge. Stalkerware often runs under disguise and requires disabling anti-viruses or the built-in protection in the operating system.

The Rise of Stalkerware

According to a Unwitting users targeted by full-throttle spyware detected as TrojanSpy reached 26,620 in the first eight months of 2019. It is found that Russia (23.4%), Brazil (9.4%), India (9%), and the U.S. (5.6%) are the most prominent regions for Stalkerware. While in Europe – Germany (3.1%), Italy (2.4%) and France (1.8%) are the top three affected places.

How is Stalkerware installed?

Usually, attackers use social engineering techniques like phishing emails/malicious attachments to lure unwitting users into downloading Stalkerware on their devices. Sometimes, users may unknowingly download Spyware that comes bundled with other software from unsecured third-party sources.

Once installed, the Stalkerware leverages the permissions of other apps in the victim’s device to get control over the device. With this accessibility, a hacker can compromise device data, make phone calls, get SIM serial numbers, obtain contact details, read and send text messages, record calls/audio, query call logs, and access device location and ID.

How to know if someone is stalking you?

Stalkerware apps are designed to be hidden, making them difficult to detect. Users need to be more vigilant about their device behaviors to find out whether they are a victim of Stalkerware. Usually, Stalkerware requires permissions from the victim’s phone to collect and send information to the attackers. You can suspect that a Stalkerware/Spyware is installed on your device when:

  • Your mobile data usage increases drastically
  • Your phone’s battery drains faster than usual
  • If your device turns on Wi-Fi or mobile internet even though you turned them off
  • If location and Bluetooth options are turned on automatically
  • When you spot unusual notifications on your device
  • When certain app permissions enable/disable without your consent
  • If you find any login activities on social media, bank apps, or other accounts without your knowledge

How to protect against Spyware/Stalkerware?

Cybercriminals often rely on Spyware apps to compromise the sensitive information of victims. Users and organizations must enhance their mobile application security to defend against evolving threats from Stalkerware. The end-users must also follow certain security precautions while installing and using mobile apps. These include:

  • Check the URL protocol (HTTPS) for secure communication.
  • Never install apps from unknown sites, as they might be malicious. Always download original applications from trusted sources (Google Play Store or Apple Store).
  • Secure your mobiles against all unauthorized physical and online access.
  • Install a paid antivirus and a mobile security app to scan for malware and viruses.
  • Always check the app’s permission list (both Android and iOS) before downloading an app. Restrict or deny access to functions that are not needed for the app to work.
  • Avoid downloading an app if it is asking for permissions unrelated to its functionality.

Conclusion

Despite multiple security checks, Spyware/Stalkerware apps are making their way into victims’ mobile devices, evading and breaching security, and allowing cybercriminals to pilfer sensitive information. It is users’ responsibility to maintain robust cyber hygiene to protect their devices from such evolving threats.

About the Author

Rudra Srinivas is a Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.

 

Netflix Runs a 2FA Test to Limit Account Sharing

reusing passwords

The widespread use of video streaming services in the market made password sharing with friends and family a common practice. However, security experts suggest that this practice increases the chances of accounts getting hacked, further leading to the theft of users’ sensitive data and credentials. Hence, to avoid the risks of data breaches, video content platform Netflix recently introduced a new password security test to prevent password sharing among multiple users.

According to a report, Netflix launched a trial version of the password test – a form of two-factor authentication (2FA) – that prevents users from sharing the same account if they do not live together. The test came to light after several users reported that a popup is being displayed on the login page saying, “if you don’t live with the owner of this account, you need your own account to keep watching.”

Commenting on the new initiative, a spokesperson from Netflix said, “This test is designed to help ensure that people using Netflix accounts are authorized to do so.”

While it is unknown whether the company will roll the trail across its network, the users can verify their eligibility to access the account via a code, text message, or email.

Netflix claimed that several ineligible users are using its platform against their terms of service. Earlier, Netflix co-founder and chief executive Reed Hastings said, “Password sharing is something you have to learn to live with, because there’s so much legitimate password sharing, like you are sharing with your spouse, with your kids, so there’s no bright line, and we’re doing fine as is.”

Poor Password Practices

An analysis from ESET revealed that 60% of users share their accounts with at least one person. It was found that one in three account holders shared their services with two or more users. Besides, the majority of the users keeping easy-to-guess passwords, making it easy for cybercriminals to compromise accounts.

“When it comes to media services such as Netflix, Amazon Prime, and Spotify, such password sharing is quite common. It may sound innocent, but when people are using the same password for their media service that they use for other accounts, it starts to become worryingly dangerous, and the risk of account compromises increases. With daily data breaches and a lack of public cyber-awareness, we need to start to understand the risks of cybercrime. A good place to start is with password education,” ESET said.

“This may not sound worrying when you know the other party with whom you are sharing the password, but what if they pass it on to someone without thinking? However, it is unrealistic to expect that people are going to stop sharing their accounts completely, so my advice would be to regularly change your passwords to flush out anyone who has gained access over the last year who shouldn’t have,” ESET added.

Though Netflix’s new password test is in its nascent stage, adding a stringent layer like 2FA can go a long way.

Unsecured Server Exposes PII of 50,000 Patients in Utah

Healthcare Data Breaches, Premier Diagnostics data exposed

A Utah-based COVID-19 testing service, Premier Diagnostics, accidentally exposed the personally identifiable information (PII) belonging to 50,000 patients through an unsecured server. The exposé was done by Comparitech’s lead researcher Bob Diachenko, who discovered the unsecured database of Premier Diagnostics during one of his routine scans. The exposed data included patients’ sensitive information like scanned passport copies, medical/health insurance IDs, driver’s licenses, and so on. According to Diachenko’s investigation, the exposed data majorly belonged to people from Utah and the neighboring states of Nevada and Colorado.

About the Exposé

As per Comparitech’s blog, Diachenko found two large unsecured Amazon S3 Buckets of Premier Diagnostics, however, he was initially unaware of who they belonged to. One of these S3 buckets was named patient-images and contained 207,524 images of patients’ photo ID scans. Whereas the second S3 bucket, which was named paper-records, included a tabular database of names, dates of birth, and test sample IDs from patients who took COVID-19 tests from their 11 diagnostic centers across Utah. Giving a detailed case study of how things panned out, Comparitech published the following timeline:

  • January 25, 2021 – The first of the two databases was indexed by a search engine.
  • February 22, 2021 – Diachenko discovered the exposed data and began his investigation to identify the owner.
  • February 24, 2021 – Unable to identify the owner, Diachenko sent an alert to the Amazon Web Services security team. He received a response that the owner would be informed via internal channels.
  • February 25, 2021 – After further examination of exposed data, Diachenko identified Premier Diagnostics as the likely owner, and sent a disclosure accordingly.
  • March 1, 2021 – After several days with no response, Comparitech’s editorial team was able to establish contact with Premier Diagnostics. The data was secured later in the day.
  • March 5, 2021 – Premier Diagnostics requested additional time for security experts to review their infrastructure.

Related News:

Cybercriminals Attacked Unsecured Databases 18 Times Per Day

Doing the math, the number of images exposed was more than 200,000 however, the number of patients affected was only over 50,000. Something did not add up correctly. Comparitech reached out to Premier Diagnostics and found that “each patient is associated with four images: the front and back of a medical insurance card, and the front and back of a second ID such as a driver’s license or passport. That means roughly 52,000 patients are affected.”

The data has now been secured by Premier Diagnostics and no exploitation of the details has been registered as of now. However, the type of data exposed in this incident can lead to identity theft, phishing attacks, health insurance fraud, etc. against the patients who have been affected. Owing to this we request all the patients who have taken the COVID-19 tests at Premier Diagnostics to be alert and monitor all financial and important services associated with them that are linked with the exposed data.

Related News:

Microsoft’s Unsecured Bing Mobile App Exposes 6.5TB of Users’ Data