Home Blog Page 109

Open Data Day: Celebrating Online Transparency, Accuracy, and Honesty

March 7, every year marks the International Open Data Day. A day that is observed to promote awareness and use of open data. Forums and groups from across the globe organize events on this day where they use open data in their communities. Open Data Day also serves as an opportunity to show the world the benefits of open data. It also encourages government, businesses, and civil society to adopt open data policies.

CISO MAG approached industry leaders to seek insight on the open data and its cybersecurity implications. Here are a few brief excerpts.

1. Shepherding and expanding open datasets will be necessary

“The freedom to access and leverage public information is a categorical right for all citizens that need to be embraced and firmly upheld. Open Data Day is a day to recognize and celebrate how open datasets have increased government transparency, reshaped social initiatives, and galvanized individuals to actively partake in broader community issues. The COVID-19 pandemic has shined a light on the importance of keeping public data resources front and center, and recent cyberattacks on the U.S. federal government have further suggested that increasing disclosed intelligence may also help deter future hackers.

Public data that is easily accessible and available to the masses is a vital resource for internet users across the globe. It’s an invaluable way to educate the masses with factual information on local governments, agencies, and scientific councils, while also holding these federal entities responsible for being publicly accountable. Over time, this has helped propel economic development, fight global crises and strengthen democracy. Shepherding and expanding open datasets will be necessary to yield a more socially active and sophisticated global community.”

 

2. It’s essential to keep valuable information available and easily accessible for everyone

“Since its inception and rise to prominence as a fundamental aspect of daily life, the internet has been a means for expanding communications and spreading knowledge across the globe. Today, almost sixty percent of the worldwide population are active internet users working, learning, researching, and communicating online. Open data day serves as an important reminder of how this platform allows the public to tap into millions of data sets across scientific, government, and non-profit organizations.

By making data readily available to the public, online participation increases along with education. Further, open data keeps online institutions honest, transparent, and accountable for having accurate information disseminated across the web. State and local leaders who release data on important issues such as the ongoing pandemic, climate, transportation, disaster response, and other critical current events inspire online consumers to take a more active role in communities. It’s essential to keep this valuable information available and easily accessible for everyone.”

 

3. Open datasets will hold governments to a higher standard

“Open Data Day is an important occasion to celebrate and encourage online transparency, accuracy, and honesty. Open data is inherently critical to ensuring that governments, nonprofits, and public scientific entities are rightfully presenting accurate information to help educate the public. In light of the current COVID-19 pandemic, it’s never been more important to properly inform people about ongoing health and safety information. Open datasets are playing an essential role in apprising local communities about current protocols, vaccination efforts, and proper safety precautions.

The increase in open data access over the past decade has empowered citizens to collaborate and take action, enabling local communities to develop innovative new services that have bolstered initiatives in health, climate, transportation, education, and social welfare. It has also dramatically increased online and public participation for marginalized groups in less developed regions. Continuing to support and advance open datasets will hold governments to a higher standard and embolden citizens to strengthen the foundations of their communities and, as a result, society as a whole.”

 

Hackers Hacked a Hacking Forum!

SEO poisoning

Underground darknet forums enable cybercriminals to trade and exchange hacking tools and stolen data. However, sometimes they can also be the targets of cyberattacks from their community. In what could be called a surprising hacking incident, hackers turned against their peers after leaking users’ sensitive data. They compromised the Maza cybercriminal forum.

Security researchers from Flashpoint stated that they found a security breach on Maza, which has been active since 2003. The attackers also posted a warning message saying, “Your data has been leaked / This forum has been hacked.”

Also known as Mazafaka earlier, the hacking forum is a closed and restricted platform for Russian-speaking threat actors. The threat actors on this forum are involved in various criminal activities like carding stolen financial data and payment card information, exchanging techniques on malware distribution, vulnerability exploits, spam, money laundering, and more.

Flashpoint stated that over 2,000 accounts and sensitive information like user IDs, usernames, email addresses, messenger app links — including Skype, MSN, and Aim — and passwords, both hashed and obfuscated — were exposed in the incident.

“Flashpoint is actively monitoring cybercriminal discussions of Maza across the entire cybercriminal forum ecosystem commenting on the recent disruptions to many elite services and communities. Users on the Exploit forum are discussing moving away from using emails to register on forums as recent disruption efforts may have increased exposure of their online activities. Others are claiming that the database leaked by the attackers is either old or incomplete,” Flashpoint said.

Tasting One’s Own Medicine

This is not the first time cybercriminals targeted their fellow operators. Earlier, researchers discovered database leaks of three hacking forums – Sinful Site, SUXX.TO, and Nulled. These databases have been exposing hackers’ personal information since the beginning of May 2020. Hacking forums are the places of aggregation for cybercriminals to participate in general discussions with other hackers to share and sell data leaks, hacking tools, malware, and tutorials, etc. They can easily buy and own malware and ransomware via such forums and dark web market networks.

The Pandemic-hit World Witnessed a 150% Growth of Ransomware

covid-19 malware ransomware, netwalker ransomware

2020 was a difficult year for most people around the globe. It brought upon unprecedented hardships and the situation became worse than just hand-to-mouth. However, there was a set of individuals who were having the time of their life, the ransomware masterminds. While industries and businesses struggled to adapt to a post-pandemic reality, threat actors thrived, attacking bigger targets, and demanding more money. The year 2020 saw the growth of Ransomware-as-a-Service (RaaS) programs, which exceedingly became popular on underground forums. The data exfiltration tactic employed by the operators gave them added assurance of returns and thus it became a popular choice among their peers.  However, to stand a chance against threat actors in 2021, it is vital to not only understand their TTPs, but also understand what actions need to be taken against them. Focusing more on these lines Group-IB, a cybersecurity firm, has released a report titled “Ransomware Uncovered 2020-2021.

The Growth of Ransomware Report

The report dives deep into the global ransomware outbreak in 2020 and analyzes major players’ TTPs (tactics, techniques, and procedures). By the end of 2020, the ransomware market, fueled by the pandemic turbulence, had turned into the biggest cybercrime money-making business. Based on the analysis of more than 500 attacks observed researchers estimate that the number of ransomware attacks grew by more than 150% in 2020.

In 2020, ransomware attacks on average caused 18 days of downtime for the affected companies, while the average ransom amount increased by twofold and amounted to $170,000. Ransomware operations have now become robust and competitive business structures going after larger enterprises and companies for better returns. Talking about the most active ransomware gangs, researchers found that Maze, Conti, and Egregor ransomware gangs were at the forefront of it in the past year. Of these, Maze, DoppelPaymer, and RagnarLocker were termed as the greediest groups, as their ransom demands averaged between $1 million and $2 million.

top ransomware attacks 2020

Analyzing the geo-targets of the ransomware gangs, researchers spotted that the most attacked regions in the world were North America, EuropeLatin America, and the Asia-Pacific.

Technical Findings

On a technical level, public-facing RDP servers were the most common target for many ransomware gangs last year. The pandemic caused many people to work from home and thus the number of such servers grew exponentially. In 52% of all attacks analyzed by Group-IB researchers, publicly accessible RDP servers were used to gain initial access. This tactic was closely followed by phishing (29%), and exploitation of public-facing applications (17%). In the credential access stage, threat actors often used brute force with NLBrute and Hydra being the most popular tools. To obtain valid privileges, ransomware operators in 2020 often used credential dumping – retrieving all the passwords from the attacked machine.

Besides, PowerShell was the most frequently abused interpreter for launching the initial payload. Its popularity among the attackers is explained by the fact that the interpreter is part of every Windows-based system, hence it is easier to disguise malicious activity.

The Rise of RaaS

The Ransomware-as-a-Service (RaaS) model has largely been the driving force behind the sensational growth of ransomware attacks. This modus operandi involves the developers selling/leasing malware to the program affiliates for further network compromise and ransomware deployment. The profits are then shared between the operators and program affiliates. Owing to this backdrop, Group-IB researchers observed that 64% of all the ransomware attacks it analyzed in 2020 came from operators using the RaaS model.

growth of ransomware 2020

Oleg Skulkin, Senior Digital Forensics Analyst at Group-IB, said, “The pandemic has catapulted ransomware into the threat landscape of every organization and has made it the face of cybercrime in 2020. From what used to be a rare practice and an end-user concern, ransomware has evolved last year into an organized multi-billion industry with competition within, market leaders, strategic alliances, and various business models. This successful venture is only going to get bigger from here. Due to their profitability, the number of RaaS programs will keep growing, more cybercriminals will focus on gaining access to networks for resale purposes.

Given that most attacks are human operated it is paramount for organizations to understand how attackers operate, what tools they use to be able to counter ransomware operators’ attacks and hunt for them proactively. It is everyone’s concern now.”

Related News:

Ryuk Ransomware Gets Intelligent, Spreads on its Own!

Why is Ransomware Still a Problem?

Malware with Sandbox Evasion Abilities Trending Among Hackers

Malware and Vulnerability Trends Report, Mobile malware threats

Threat actors constantly enhance their hacking skills and use innovative techniques to spread malware on targeted devices. They often use a combination of advanced methods to escape security scans and penetrate vulnerable devices.

Recently, security experts from Positive Technologies found threat actors combining sandbox evasion and anti-analysis methods in their malware distribution. The researchers analyzed 36 malware families that contain sandbox detection and evasion capabilities that have been active in the last 10 years. The findings suggest that 25% of that malware was active in 2019–2020. Nearly, 23% of Advance Persistent Threat (APT) groups globally used malware in cyberattack campaigns, and over 69% of the malware analyzed was used for espionage.

What is Sandbox?

A sandbox is an isolated testing environment that enables security admins to run programs or execute files without affecting the application or system. IT professionals use sandboxes to test new programming code and potentially malicious software.

There is a significant evolution of sandbox evasion and anti-analysis techniques from cybercriminals after security experts performed more investigations of malware samples. Positive Technologies researchers found that attackers used the same malware code in different attacking methods in different years to evade organizations’ security scans.

“This malware is used to perform reconnaissance and gather information about the target system. If attackers spot that the malware is running inside a virtual environment, such as a sandbox, they will not pursue this attack vector or download the payload. Instead, the malware goes dormant to maintain stealth,” said Olga Zinenko, senior analyst at Positive Technologies.

“Hackers do all they can to hide malicious functions from security researchers and avoid tripping any known indicators of compromise. Traditional defenses may not be able to detect malicious programs. For detecting today’s malware, we recommend analyzing file behavior in a secure sandbox environment. Using a sandbox enriches IOC databases and provides companies with information for improving cyber threat response,” said Alexey Vishnyakov, Head of Malware Detection at Positive Technologies. 

Fortune 500 Company Adecco Group Suffers Data Breach

data breach

Darknet forums enable cybercriminals to promote their hacking skills and trade stolen digital assets to other threat actor groups in the community. A large amount of compromised sensitive information is being dumped across various hacking forums regularly. Recently, security experts from Cybernews discovered an unknown hacker allegedly selling stolen credentials belonging to Adecco Group. Headquartered in Switzerland, Adecco Group is a  Fortune 500 global human resource and temporary staffing company.

The database kept for sale contained over five million records from six Latin American/South American countries: Peru, Brazil, Argentina, Colombia, Chile, and Ecuador.

The Leaked Data

The data dump, which was later taken down by the hacker, supposedly contained different categories of data:

  • “Candidatos_datos_personales” (candidates’ personal data) with 4,543,938 lines
  • “Candidatos_candidatos_by_email” with 3,763,836 lines
  • “Candidatos_login” with 5,321,943 lines

In common, all the categories exposed candidates’ sensitive information including full name, gender, marital status, birth dates, email addresses, passwords, and country of residence.

The Impact

While it is unclear why the post was taken down by the threat actor, Cybernews suspects that the database was sold out. The data could be misused for various malicious purposes, including:

  • Targeted spear-phishing attacks
  • Collecting and spamming users’ emails and phones
  • Brute-forcing users’ other online accounts

 Mitigation Measures

Cybernews also recommended certain security measures for users whose data may have been compromised in the security incident. These include:

  • Change your passwords immediately. You should be using a unique password for each account you create.
  • Add two-factor authentication (2FA) on your most sensitive accounts, including your primary email account. That way, even if a bad actor were able to uncover your credentials, they wouldn’t be able to get into your account.
  • Watch out for suspicious emails, as they may be phishing attempts. Avoid clicking on links from suspicious emails.
  • Watch out for suspicious activity on your financial accounts and set up identity theft monitoring.

Researchers suspected that the latest security incident appears to be from the same threat actors responsible for the recent VPN leaks, in which cybercriminals traded three databases that contained user credentials and device data from three Android Virtual Private Network (VPN) services – SuperVPN, GeckoVPN, and ChatVPN. Read more…

Emphasize the “Spirit” of Compliance Over Simply “Checking all the Boxes”

Security and Compliance in Cloud

If you’re about to face a compliance audit, undergo an assessment, or produce an industry certification — and are doing so without much serious consideration for what it means to embody information security and data privacy throughout the organization — you are likely missing the forest for the trees. If the actions taken are solely about achieving certification and remain unclear and impractical from the intent of the regulatory requirements, what you don’t see can come back to haunt you.

By Bryan Cline, Ph.D., Chief Research Officer at HITRUST

Compliance isn’t supposed to be about ticking a bunch of checkboxes, which when “completed” represents a binary result: pass or fail. What may not be as clear, even by achieving compliance, is that you may still be left with substantial exposure to compliance risk.

In effect, by simply achieving the letter of compliance, you leave your company unnecessarily exposed to business risk: plain and simple. There is a residual risk in the continuum that falls between doing the bare minimum to address compliance requirements and doing what is actually needed to address the intent of the requirements: providing a reasonable level of due diligence and due care.

The Three Levels of Compliance Maturity

Achieving a risk score isn’t the solution. Neither is ticking a bunch of non-verifiable checkboxes. The correct solution involves moving beyond the binary state of the letter of compliance and, instead, striving to achieve compliance in a way that meets the intent of the regulations and standards. To get to the right solution, let’s first take a broad view at three levels of compliance maturity.

1. Zero visibility and disorganized control

At this level, businesses are subject to maximum unmitigated exposure. IT risk assessments are limited as most regulations are concerned with information security (more so than IT) and individual privacy, which information security supports. The business is likely stuck at this maturity level because there is an unclear association between compliance risk, information security risk, privacy risk, and business risk.

2. The letter of compliance is achieved

Organizations that reach this level recognize the connection between information risk and business risk but have minimum mitigations in place. At this level, compliance risk still exists as organizations have implemented an incomplete set of controls, and many times, those that have been implemented fail to meet the outcomes intended by the regulation — as interpreted by the regulator.

The drivers to achieve this level include the risk of fines, penalties, and loss of business. Many businesses choose to stop at this level because compliance is enough, and the self-assessments show everything is OK; after all, the letter of compliance was achieved.

3. Intent to protect is embodied throughout the organization

Those that reach this level have an understanding of risk and visibility into how it can affect the business. Furthermore, that risk is sufficiently mapped to business risk and paired with proactive controls and responses designed to meet the letter of compliance and support, with a clear and focused goal of keeping the company’s information safe, which is often the intent of information security and individual privacy regulations. The common drivers that cause organizations to reach this level often include direct experience with a breach, awareness of a breach at another company, or the loss of business due to an inability to articulate proactive risk management. Perhaps it’s time organizations don’t wait for one of these negative drivers to surface before taking action.

Achieving an Appropriate Level of Assurance

But even if you are following the spirit of compliance, you may not be able to adequately demonstrate compliance when a regulator comes knocking at your door. For example, self-assessments are generally less trustworthy than independent assessments and are almost always inflated due to a lack of understanding of the requirements and a desire to cross the finish line to pass an audit or close on new business.

Ultimately, though, compliance boils down to achieving an appropriate level of assurance:

  • What level of assurance do you want to achieve?
  • What level of assurance can you demonstrate?
  • Can you demonstrate assurance to ALL stakeholders?

Then consider whether you have provided the level of assurance you want and that your stakeholders require. Have you gone beyond ticking the boxes of compliance, or is it just a charade?

The Three Dimensions of Intent-Driven Assurance

To answer these questions, we will explore the three dimensions of assurance and the attributes associated with each:

1. Suitability: The controls must manage risk to a level deemed acceptable by the organization, not just what is described in the regulation(s) you are managing to.
2. Impartiality: For both the letter of compliance and the intent of compliance, independent assessments are more trustworthy than a self-assessment, and help improve the level of assurance provided.
3. Rigor: The results must accurately reflect the organization’s information security posture as it relates to the regulatory requirements.

This story first appeared in the November 2020 issue of CISO MAG. To read the full story: Subscribe now!

About the Author

Dr. Bryan Cline provides thought leadership on risk management and compliance and develops the methodologies used in various components of the HITRUST ApproachTM. This includes a focus on the design of the HITRUST CSF® and the assessment and certification models used in the HITRUST CSF Assurance Program, for which he provides technical direction and oversight. He’s also responsible for addressing emerging trends impacting risk management and compliance to ensure the HITRUST Approach sets the bar for organizations seeking the most comprehensive privacy and security frameworks available. Dr. Cline is currently leading a joint public-private effort to update NIST Cybersecurity Framework implementation guidance for the health care sector, which will better support the use of NIST’s Online Informative References like the HITRUST CSF in organizational cybersecurity programs. He is also working with the FAIR Institute to integrate elements of their quantitative approach to risk analysis with HITRUST’s control-based risk management framework, which will allow organizations that use the framework to more easily communicate risk in business terms and better facilitate risk-based decision making. Dr. Cline previously served as HITRUST’s Vice President of Standards and Analysis.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Samsung Card, Samsung Electronics and Mastercard Sign an MoU for Fingerprint Biometric Payment Card

Cardholder payment data

Payment card frauds have been on a gradual rise since the opening of physical stores in many parts of the world. Cash-strapped economies and job cuts have made fraudsters turn towards notorious ways like payment card skimming. To address this concern, Samsung Card, Mastercard, and Samsung Electronics have decided to form an alliance and counter the rising threat of card skimming by developing a fingerprint scanner-enabled biometric card to authorize transactions securely at in-store payment terminals.

Why you need a fingerprint biometric payment card

Through this collaborated research, the companies aim to provide faster and more secure payment experiences to their users. Biometric authentication allows safer interactions with reduced physical contact points. It eliminates the need to enter a PIN on a keypad, which is a necessary feature in the current pandemic scenario. Additionally, it provides an extra jacket of security and satisfies the third factor of authentication – “Something you are” – to the currently available credit cards by verifying the cardholder’s identity via a unique fingerprint.

Related News:

SmartMetric Biometric Payment Cards Now Have Over 9 years Battery Life

Samsung’s New Chipset

The biometric cards are set to be integrated with a new security chipset from Samsung’s System LSI Business. This chipset will integrate the work of several key discrete chips, streamlining the overall component design and enabling more efficient development. These cards will be authenticated at in-store payment counters with the help of a point of sale (POS) terminal where Mastercard will come into the picture. Mastercard chip terminal or point of sale (POS) terminal will be ready with the changes for payments through the fingerprint biometric payment card.

Related News:

Is Samsung’s New Data Security Chip a Game Changer?

Karthik Ramanathan, Senior Vice President, Cyber & Intelligence Solutions, Asia Pacific, Mastercard, said, “As consumers embrace the safety and convenience of contactless payments, Mastercard will leverage its cybersecurity and intelligence expertise and global payments network in this three-way partnership to enhance cardholder security with a biometric solution supporting fast, frictionless payment experiences that are protected at every point”.

Hanjoo Yoon, Vice President, Planning & Communication, Samsung Card, added, “We have big data expertise and have set the standard in the domestic market for digital transformation and fraud detection system (FDS). Leveraging these experiences, we will deliver a powerful solution to enhance payment experiences in close partnership with Samsung Electronics and Mastercard.”

Samsung Card will soon lead the rollout in South Korea, with plans to introduce the biometric card later this year. The adoption of the solution will be a gradual process, starting from corporate credit cards which are frequented for international transactions.

Related News:

Samsung Admits Galaxy S10 Fingerprint Reader Vulnerability, says “Will Fix it Soon”

Password Reuse Still Rife: 2021 Credential Exposure Report

User Verification Policy, zero trust approach

Researchers at security solutions provider SpyCloud recovered over 4.6 billion records of personally identifiable information (PII) and nearly 1.5 billion stolen account credentials from 854 data breach sources in 2020. In its 2021 Credential Exposure Report, the company revealed that the number of data breach sources increased 33% over 2019, with an average 2020 breach size of 5,455,813 records. SpyCloud’s researchers found that 60% of the credentials were reused across multiple accounts, making cybercriminals launch account takeovers attacks.

Poor Password Security

The report indicated that the password reuse rate was unchanged from last year, making it easy for an attacker to misuse one stolen password to hijack other accounts. “Despite years of advice about the importance of strong passwords, people inevitably end up reusing or recycling the same credentials for multiple sites. Outdated password complexity requirements have complicated the issue by providing people with a false sense of security when they recycle a favorite password with a few simple changes, like capitalizing the first letter and adding a 1 or ! in the end,” SpyCloud said.

Key Findings

  • Topical passwords – Not surprisingly, passwords frequently reflected current events. More than 1.6 million passwords included “2020.” Another 107,595 included “corona,” “virus” or “coronavirus.” Thousands more were found using “Trump,” “Biden,” “BLM,” “vote” and “mask.”
  • The 1,486,416,779 exposed credentials include email addresses or usernames connected to plaintext passwords.
  • Most common passwords – As usual, the most common password found was “123456,” followed by “123456789” and “12345678.” “Password” and “111111” showed up more than 1.2 million times each.
  • Government accounts exposed – SpyCloud found 269,690 sets of credentials for .gov accounts. Password reuse for .gov emails was 87%, 27 points higher than the overall reuse rate.

“These staggering numbers indicate a continued threat for account takeovers, identity theft, and fraud at a time when people have been spending more time online during the Covid-19 pandemic. Criminals didn’t stop for the coronavirus. In fact, attackers have been able to use the disruption of the pandemic to their advantage,” said David Endler, Co-founder and Chief Product Officer at SpyCloud.

Related Story: 6 Practices to Strengthen Your Password Hygiene in 2020

CallX Suffers Data Breach; Over 100,000 Files Exposed

microsoft, flaws in SonicWall SRA SMA

Security experts from research firm vpnMentor discovered a data breach that exposed tens of thousands of private data belonging to CallX, a California headquartered telemarketing company. vpnMentor claimed that CallX failed to secure audio recordings, chats, and text transcriptions from its clients. The security incident exposed more than 100,000 private files online, making them publicly accessible.

Most of the exposed files include audio recordings of phone conversations, transcripts from over 2,000 text chats, conversations between CallX clients and their customers, along with customers’ private data, including, full names, phone numbers, home addresses, and callback dates for phone calls.

Threat Summary:

What caused the data leak

 vpnMentor’s researchers stated that CallX used an unsecured Amazon Web Services (AWS) S3 bucket to store audio files of its client. vpnMentor notified the data leak to CallX authorities to fix the issue.

“Our team discovered CallX’s S3 bucket and was able to view it due to insufficient security. We found an image of the company’s logo amongst the files stored on the S3 bucket and, upon further investigation, confirmed the company as its owner. AWS S3 buckets are a popular form of enterprise cloud storage, but users must set up their own security protocols. Many companies using AWS are not aware of this,” vpnMentor said.

How to Secure an Open S3 Bucket

vpnMentor also recommended certain security measures to boost Open S3 Bucket security. These include:

  • It’s important to note that publicly viewable S3 buckets are not a flaw of AWS. They’re usually the result of an error by the owner of the bucket. Amazon provides detailed instructions to AWS users to help them secure S3 buckets and keep them private.
  • In the case of CallX, the quickest way to fix this error would be to make the bucket private and add authentication protocols.
  • Follow AWS access and authentication best practices.
  • Add more layers of protection to their S3 bucket to further restrict who can access it from every point of entry.

State-sponsored Attackers Exploit Zero-day Microsoft Exchange Vulnerabilities

Brand Phishing Attacks

Security experts from Volexity discovered state-sponsored hacking groups exploiting just patched critical Microsoft Exchange bugs from January 6, 2021. The technology giant recently addressed four Zero-day vulnerabilities (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) and three other vulnerabilities (CVE-2021-27078, CVE-2021-26854, and CVE-2021-26412) in its Patch Tuesday security update.

Volexity claimed that threat actors were exploiting the CVE-2021-26855 Microsoft Exchange Server vulnerability in their ongoing attacks to obtain remote code execution on vulnerable Exchange servers. Volexity identified a massive amount of information being transferred from the Exchange servers to unknown IP addresses legitimate users.

“The logs showed inbound POST requests to valid files associated with images, JavaScript, cascading style sheets, and fonts used by Outlook Web Access (OWA). It was initially suspected the servers might be backdoored and that webshells were being executed through a malicious HTTP module or ISAPI filter. This investigation revealed that the servers were not backdoored and uncovered a zero-day exploit being used in the wild,” Volexity said.

Volexity’s researchers found that the attackers were exploiting a zero-day server-side request forgery (SSRF) to steal the entire contents of several user mailboxes. As the CVE-2021-26855 vulnerability is remotely exploitable, an attacker does not require any kind of authentication or access to a target environment.

Indicators of Compromise

/owa/auth/Current/themes/resources/logon.css
/owa/auth/Current/themes/resources/owafont_ja.css
/owa/auth/Current/themes/resources/lgnbotl.gif
/owa/auth/Current/themes/resources/owafont_ko.css
/owa/auth/Current/themes/resources/SegoeUI-SemiBold.eot
/owa/auth/Current/themes/resources/SegoeUI-SemiLight.ttf
/owa/auth/Current/themes/resources/lgnbotl.gif

Volexity urged organizations and users to apply the available security patches or temporarily disable external access to Microsoft Exchange as early as possible.

“Highly skilled attackers continue to innovate to bypass defenses and gain access to their targets, all in support of their mission and goals. These vulnerabilities in Microsoft Exchange are no exception. These attackers are conducting novel attacks to bypass authentication, including two-factor authentication, allowing them to access e-mail accounts of interest within targeted organizations and remotely execute code on vulnerable Microsoft Exchange servers,” Volexity added.