Home Blog Page 115

This CVE in Agora.io’s SDK Left Video Calling Apps Open to Snooping

Doxing attacks

McAfee Advanced Threat Research (ATR) team uncovered a critical security vulnerability in Agora, a video calling software development kit (SDK), which could allow an attacker to spy on ongoing video and audio calls. Agora is a video, audio, and live interactive streaming platform used by many social media applications like eHarmony, MeetMe, Plenty of Fish, and Skout, along with health care apps like Talkspace, Practo, and Dr. First’s Backline.

Agora allows app developers to embed voice and video chat, live streaming, real-time recording, and messaging into their applications. It is estimated that Agora’s SDKs are deployed on more than 1.7 billion devices globally.

Vulnerability Patched

The flaw, CVE-2020-25605, transmits cleartext of users’ sensitive information in Agora’s SDK (before 3.1 version) allowing a remote attacker to obtain access to audio and video of any ongoing Agora video call through observation of cleartext network traffic. Upon successful exploitation, the vulnerability could allow threat actors to launch Man-in-the-Middle Attacks (MITM), which occur when a perpetrator stealthily alters the communications between two unwitting users or a user and an application.

While there is no information on whether the vulnerability is being exploited in the wild, McAfee alerted Agora about the vulnerability. As a response, the company released a new SDK (version 3.2.1), which mitigated the vulnerability and eliminated the potential risks to users.

“Agora’s SDK implementation did not allow applications to securely configure the setup of video/audio encryption, thereby leaving a potential for hackers to snoop on them. In the world of online dating, a breach of security or the ability to spy on calls could lead to blackmail or harassment by an attacker. Other Agora developer applications with smaller customer bases, such as the temi robot, are used in numerous industries such as hospitals, where the ability to spy on conversations could lead to the leak of sensitive medical information,” McAfee said.

DopplePaymer Ransomware Gang Behind Kia Motors IT Outage?

Kia motors ransomware attack

Kia Motors has quickly climbed the sales ladder in the U.S. It has captured the market across the country with its gold-standard product offerings like the Telluride, which is incidentally named the “2020 World Car of the Year.” Kia owes a huge part of this success to its latest technology adaptations. It offers great build quality, but it is the tech on offer that woes its customers – its connected car tech. The ability to interact with your car remotely and enjoy functions like remote start and stop of ignition, climate control, seat warming, and boot opening is stunning. But what happens when this goes down? It is an owner’s nightmare and the company’s embarrassment. This is what Kia is going through right now because the company has announced a nationwide IT outage in the U.S.

Kia IT Outage a Ransomware Attack?

On February 13, several Kia customers complained that they were unable to use Kia’s official UVO mobile application for initiating remote commands.

Later Kia put out an “IT service outage” note on its website (refer to the image below) to assure their customers that they would be back soon.

KIA motors IT outage, KIA motors ransomware attack
Image Credit: KIA Motors America

However, it has been nearly five days, and yet the services seem to be down and some reports, which surfaced recently, suggest that Kia Motors America was attacked by the DopplePaymer ransomware gang. This possibly explains the delay in the restoration of services.

According to the reports, the ransom note was left in the name of Hyundai Motors America, which is the parent company of Kia Motors. However, Hyundai Motors does not seem to be affected by this ransomware attack. The DopplePaymer gang informed that they have stolen “sensitive data” and shall require a ransom of 404 BTC (equivalent to $20 million) in exchange for the decryption key. The note carries a link to their TOR page where a countdown timer is set for a deadline, which if not met increases the ransom amount to 600 BTC.

Speaking exclusively to CISO MAG, Purandar Das, CEO and Co-Founder of Sotero Software, said,

One more ransomware incident. While the focus is on recovering the stolen data, minimizing customer exposure, and restoring normal operation, as it rightfully should be, companies ought to start revisiting their security approaches.

There are two parts to this. One, start by making the data useless when stolen. That eliminates a big part of the leverage the criminals have. The data is just as valuable as the operational aspects of the system that are affected. The stolen data also causes long-term damage to innocent consumers who trust organizations to protect their data and privacy.

Adopting newer encryption technologies, which keep data encrypted even while in use, is a must. Second, enabling secure backups of operational systems with fast recovery paths is another. Layering on more security products is not a viable or scalable solution.

Don’t Pay the Ransom, It’s Illegal!

Ransomware is a growing plague and currently, there seems to be no antidote to it other than paying. However, paying the ransom is now illegal in the U.S. as per an advisory issued by the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC). Read more about it here!

Related News:

Why is Ransomware Still a Problem?

The State of Ransomware: From Evolution to Progression

These Unpatched Flaws in SHAREit App Could Leak Your Data

vulnerability in SHAREit App

Multiple security vulnerabilities in the Android version of the SHAREit mobile application could allow an attacker to run Remote Code Execution (RCE). According to an analysis from Trend Micro, the unpatched flaws in the SHAREit app, which has more than one billion downloads in the Play Store, can be misused to pilfer users’ sensitive data and execute arbitrary code by injecting a malicious code.

SHAREit’s Critical Vulnerabilities

Trend Micro  found that SHAREit app’s code declares the broadcast receiver as “com.lenovo.anyshare.app.DefaultReceiver”, receives the action “com.ushareit.package.action.install_completed” and Extra Intent then calls the startActivity() function. It was also found that the developer of the app disabled the exported attribute via android:exported=”false” and enabled the android:grantUriPermissions=”true” attribute, allowing any third-party entity to gain temporary read/write access to the content provider’s data.

“We found that SHAREit generates vdex/odex files after dex2oat when first launched. The app then loads these files directly in subsequent running. An attacker may craft a fake vdex/odex file, then replace those files via the abovementioned vulnerability to perform code execution. Also, we noticed that SHAREit has set up deep links using URLs leading to specific features in the app. These contain features that can download and install any Android Package (APK),” Trend Micro said.

No Response from the App Developer

Developed by Singapore-based Smart Media4U Technology Pte. Ltd., SHAREit allows users to transfer files between devices. The app developer has not addressed the flaws despite responsible disclosure three months ago.

“We reported these vulnerabilities to the vendor, who has not responded yet. We decided to disclose our research three months after reporting this since many users might be affected by this attack because the attacker can steal sensitive data and do anything with the apps’ permission. It is also not easily detectable,” Trend Micro added.

App security should be a top priority for users, organizations, and app developers. Users must be vigilant while installing any app on their mobiles. Regularly updating and patching mobile operating systems and apps enhance device security.

North Korea Accused by its Southern Counterpart for Cyberattack on Pfizer

Coronavirus, COVID-19

North Korea seems to be getting desperate to resolve the COVID-19 crisis even when the country has not yet officially reported any positive cases. Its southern counterpart has accused them of launching a cyberattack against COVID-19 vaccine maker, Pfizer. This is the second attack reported in the past three months; the first being against AstraZeneca.

Related News:

COVID Vaccine Frontrunner AstraZeneca Targeted by Suspected North Korean Threat Actors

North Korea Targets Pfizer

North Korea has been previously accused of targeting the then COVID-19 vaccine frontrunner, AstraZeneca, to know more about its research. The alleged threat actors used social engineering techniques and baited the employees of AstraZeneca with phishing emails containing fake job offers. They hid malicious links and attachments in these emails that led to the download of data exfiltrating malware. Although the attack was not so successful, it gave impetus to the North to try it on other vaccine makers as well. Thus, taking a cue from its previous campaigns, North Korea has now targeted another vaccine maker, Pfizer.

The accusation has been made by Ha Tae-Keung, a South Korean lawmaker and opposition party member of the parliament. After a security briefing from the National Intelligence Service (NIS), Ha told reporters,  There were attempts to steal COVID vaccine and treatment technology during cyberattacks, and Pfizer was hacked. The NIS though has remained tight-lipped and only accepted that a record of multiple security incidents was discussed in the security briefing without accepting or rejecting Ha’s claims of Pfizer being compromised. The NIS though did mention that it has successfully averted all attacks from the North directed towards its own COVID vaccine research.

As per Reuters, Pfizer’s offices in Asia and South Korea have not yet commented on Ha’s revelations. However, Ha did provide a picture of the notes he had taken during the briefing, but this is not enough to prove anything as of now, and we will have to sit tight to know more. If it is true, there are two conclusions for the motive behind the attack:

  1. North Korea wants to steal vaccine data and COVID-19 research information to develop its own indigenous vaccine.
  2. They wish to sell this information to another country or organization in exchange for a huge sum to support other activities.

Meanwhile, North Korea is set to receive around two million doses of the AstraZeneca/Oxford University vaccine later this year, via the Covax programme.

Related News:

“The battle for the vaccine market to launch cyberattacks has already begun”

Is Clubhouse App Leaking Users’ Sensitive Data to Chinese Govt?

Chinese actors target telecom

It seems like Clubhouse, a popular invite-only audio chat app, ran into serious pressure after researchers from Stanford University warned that the app is possibly leaking users’ audio data to the Chinese government. It is suspected that the backend software “Agora” used in the Clubhouse app is exposing users’ information to a third-party without users’ consent.

The Clubhouse app is based on audio-chat, which is part talkback radio and part conference call. The audio of the calls is not recorded by the app and not stored on servers; it cannot be shared. So, what is at risk here is the user ID and meta data.

Currently, Clubhouse is only available on iOS and can be accessed through joinclubhouse.com. However, users need an invitation to join a room.

Agora: The Culprit?

The Stanford Internet Observatory (SIO) stated that Agora, a Shanghai-based provider of real-time engagement software, provides back-end infrastructure to the Clubhouse app. According to SIO, Agora might have access to the user’s unique Clubhouse ID number and chatroom ID transmitted in plaintext and sending them to the Chinese government.

The SIO claimed that Agora is allegedly sending users’ metadata over the internet in plaintext unencrypted, allowing any third-party with access to a user’s network traffic to exploit.

“In this manner, an eavesdropper might learn whether two users are talking to each other, for instance, by detecting whether those users are joining the same channel. It is also likely possible to connect Clubhouse IDs with user profiles,” SIO researchers said.

“Although last week Clubhouse had not yet been blocked by the Great Firewall, some mainland users worried the government could eavesdrop on the conversation, leading to reprisals. Clubhouse app’s audio messages, unlike Twitter posts, leave no public record after speech occurs, potentially complicating Chinese government monitoring efforts,” SIO researchers added.

Ironically, the Chinese government recently blocked the Clubhouse app citing that it involves Chinese users in cross-border discussions on political and human rights subjects.

The Sudden Rise of Clubhouse

Developed by entrepreneur Paul Davison and ex-Google employee Rohan Seth, the Clubhouse app took social media by storm recently. Clubhouse received huge attention when Elon Musk tweeted about his chat with rapper Kanye West on Clubhouse.

Things got more interesting when Musk invited Russian President Vladimir Putin.

What Clubhouse says…

Responding to the allegations, Clubhouse said, “With the help of researchers at the Stanford Internet Observatory, we have identified a few areas where we can further strengthen our data protection. Over the next 72 hours, we are rolling out changes to add additional encryption, and blocks to prevent Clubhouse clients from ever transmitting pings to Chinese servers. We also plan to engage an external data security firm to review and validate these changes.”

Did Remote Working Make Cybercriminals’ Lives Easy?

New Programming Language

With remote work becoming the new normal, organizations globally are getting used to secure the work devices virtually. While the entire working community fit into the new working conditions, cybercriminals also ditched their old tactics and attempted innovative hacking techniques to target the remote workforce.

Adversaries are leveraging specially crafted malware or spyware to infect end-user devices like laptops, smartphones, and Internet of Things (IoT) devices, to pilfer sensitive corporate data. Research from Malwarebytes found a major change in the devices targeted and strategies deployed by threat actors. The 2021 State of Malware Report revealed that the use of tracking applications rose by 565% in 2020, while spyware app detections increased across the same period by 1,055%.

While regular culprits like Adware, Trojans, and cryptocurrency miners declined in 2020, there has been a huge spike in HackTools, Spyware, and other malware designed to compromise and harvest users’ sensitive information.

“In tandem with exploiting fear, cybercriminals sought to gather intelligence about targets. That meant deploying various information-gathering tools through malicious phishing attacks. During this time, threat actors leaned heavily on information stealers, Spyware, and tools that collected information about victims’ systems,” Malwarebytes said.

According to the report, during 2020 cybercriminals focused on:

  • Exploiting public fear on the COVID-19 pandemic.
  • Gather intelligence through phishing attacks, information stealers, and spyware.
  • Upgrading existing malicious tools like Trickbot and brute force attacks.

Key Takeaways

  • Malware detections on Windows business computers decreased by 24% overall, but detections for HackTools and Spyware on Windows increased dramatically — by 147% and 24%, respectively.
  • Mac detections decreased by 38%, though Mac detections for businesses increased by 31%.
  • Malware accounted for just 1.5% of all Mac detections in 2020 — the rest can be attributed to Potentially Unwanted Programs (PUPs) and Adware.
  • Among the top five threats for both businesses and consumers were the Microsoft Office software cracker KMS, the banking malware Dridex, and Bitcoin Miners; business detections for KMS and Dridex rose by 2,251% and 973%, respectively.
  • Detections for the most notorious business threats Emotet and Trickbot fell this year by 89% and 68% respectively, although the operators behind these threats still pulled off several big attacks in 2020.
  • New ransomware called Egregor came onto the scene in late 2020, deployed in attacks against Ubisoft, K-Mart, Crytek, and Barnes & Noble.

“Malicious actors no longer need to be experts at crafting the whole chain of their attacks. The process can be broken up into chunks and these can be refined and perfected. This leaves malware authors to concentrate on making more effective malware, while malware distributors work to improve their networks, all while still making a profit and running their businesses,” Malwarebytes added.

Related Stories:

Over 1,000 Hands Wrote 4,032 Lines of Code to Execute the SolarWinds Cyberattack

Trickbot Malware

Ever since its discovery in December 2020, the SolarWinds hack has been the talk of the town. Experts have analyzed, dissected, and unearthed many vectors behind this stealthy attack. Even heavy-weight tech giants like Malwarebytes, FireEye, and Microsoft have reported being affected by this devastatingly malicious act. In fact, Microsoft even accepted that SolarWinds attackers had accessed their “Source Code.” And in a recent interview with the U.S. news magazine program 60 Minutes, Brad Smith, President of Microsoft, went on to label the SolarWinds hack as “the largest and most sophisticated attack the world has ever seen.”

Microsoft’s Analysis of the SolarWinds Hack

While answering questions related to the hack, Smith said that Microsoft was carrying out a thorough internal investigation on the breach and had assigned a team of nearly 500 engineers to do so. Smith added that looking at the sophistication of the attack the engineers started hunting for signatures that would lead them to the perpetrators. However, in doing so they discovered that this was not a job of a small group of threat actors, instead, the engineers estimated that 1,000+ developers had worked on developing the malicious code in the first place. This implied that the attack was not just widespread but was developed and executed by a larger group, possibly a state-sponsored entity.

Related News:

SolarWinds Hackers Accessed Source Code: Microsoft

The analysis also pointed that the SolarWinds Orion software comprises millions of lines of computer code. And thus, it was easy for the threat actors to craftily re-write 4,032 lines of malicious code and hide it in plain sight from the SolarWinds developers.

An Alert FireEye Employee Opens the Eyes

The same interview panel of 60 seconds had Kevin Mandia, CEO of FireEye – the cybersecurity company that first discovered the attack on their systems. Mandia gave the credit of this discovery to an alert security employee who first raised the flag on discovering two mobile numbers being registered in the name of a single employee.

Due to the pandemic, for remote login purposes, FireEye had devised a two-factor authentication (2FA) for all its employees on their registered mobile numbers. Mandia said that for 2FA only one phone number is accepted, but it was in this data table at the backend that the whistleblower saw the additional entry. The security employee immediately called the employee in question and asked, “Hey, did you actually register a second device on our network?” and the employee reverted, “No. It wasn’t, it wasn’t me.” This was where it all started.

The security team at FireEye hunted and analyzed all its tools to know the vulnerability that was the reason for the compromise. But the attackers were highly sophisticated and in Mandia’s words, “left no evidence of how they broke in – no phishing expeditions, no malware.”

But perseverance and expertise of being in the cybersecurity domain eventually paid off for FireEye. Their security team investigated every machine possible and all fingers were being pointed to their third-party management software – SolarWinds Orion.

At the end of the discussion, Smith was asked whether the attack was still on-going? To which he replied, “Almost certainly, these attacks are continuing.” We hope the security teams of all organizations are listening to this!

Related News:

Decoding the SolarWinds Hack

U.K’s Crypto Exchange EXMO Halted Operations After DDoS Attack

DDoS Attacks

The high net-worth of cryptocurrencies attracts both investors and cybercriminals. As a result, numerous hacks and heists have been reported on cryptocurrency exchanges. EXMO, a popular cryptocurrency exchange in the U.K., recently suffered a Distributed Denial-of-Service (DDoS) attack that affected the platform’s servers to go offline.

How did it happen?

EXMO claimed that threat actors targeted the exchange with $75 million in trading volume by overloading the system with numerous unwanted traffic from multiple malicious servers. The incident affected the servers of the exchange, which are now temporarily unavailable. The volume on the exchange platform has fallen 4.9% after the attack.

The attack comes two months after EXMO reported that unknown attackers stole $10.5 million in Bitcoin, Ether, Bitcoin Cash, Tether, and Zcash cryptocurrencies.

DDoS Attacks Turn Weaponized

In DDoS attacks, cybercriminals make a targeted system or service unavailable to its users by flooding with unwanted incoming traffic from different sources. They leverage various compromised computer systems and connected sources like IoT devices as sources of attack traffic.

Several industry experts stressed that DDoS attacks have evolved into weaponized instruments used to disseminate ransomware, as well as to launch disruptive attacks against their targets.

Recently, the New Zealand stock exchange NZX Ltd. went offline for three days in a row due to a blow of successive cyberattacks. In a security alert, the bourse operator said that initially it had been hit by a DDoS attack on August 25, 2020, from offshore, via its network service provider. The attack impacted the exchange’s network connectivity systems, including NZX websites and the markets announcement platform.

How DarkSide Ransomware Attack Led Canadian Car Rental Agency to Temporarily Shut Operations

Ransomware attacks, ransomware, Sinclair Broadcast group

Canada-based car and truck rental services provider Discount Car and Truck Rentals has been hit by DarkSide ransomware. The attackers claimed to have stolen 120 GB of users’ personal information. The threat actors have threatened to publish the compromised data online if the company doesn’t pay the ransom. Discount Car and Truck Rentals is a popular car and truck rental company with 300 locations across Canada.

The ransomware operators compromised sensitive unencrypted data, including marketing, finance, account, banking, and franchisee details. They also advertised various folder listings of alleged Discount Car and Truck Rentals as proof of compromise.

While there is no information about the amount demanded in ransom, the company temporarily shut down its online operations at discount.com following the attack.

“Discount Car and Truck Rentals was subject to a ransomware attack that impacted the Discount headquarters office. A fully dedicated team isolated and contained the attack quickly. The team is working to investigate and restore service as quickly and safely as possible,” the company said in a media statement.

How DarkSide Ransomware Operators Execute Attacks  

  • They use a highly targeted approach to attack their victims.
  • Custom ransomware executables are carefully prepared for each target.
  • They use a corporate-like method of communication throughout their attacks.

 Flip Side of the DarkSide Attackers

In a rather unexpected act, the DarkSide group donated $20K from their ransom kitty to two nonprofits charities in October 2020. The threat actors claimed that they are planning to make more donations like this in the future. The hacker group posted payment receipts for $10,000 in Bitcoin donations to charities: Children International and The Water Project.

Bitdefender’s Decryption Tool for Darkside Ransomware  

Cybersecurity firm Bitdefender recently released a decryption tool that allows organizations to recover files that are encrypted by DarkSide ransomware operators without paying any ransom. The free decryptor tool automatically scans the systems for encrypted files and decrypts them. Read the full story here…

Here’s Why You Are More Likely to Be Targeted with a Phishing Email

“PerSwaysion” Phishing Campaign Targets High-Ranked Professionals Across The Globe, IKEA email reply-chain attack

Threat actors constantly innovate and adopt new techniques to perform their phishing activities successfully. They often leverage compromised email IDs, login credentials, and other personal data that is exposed in data breaches, or data available on darknet forums. Users who had their private information exposed in cyberattacks earlier are more prone to phishing attacks.

To determine why some users are more likely targeted by phishing scams, Google teamed up with security researchers at Stanford University to study the intentions of malicious actors. “We measure over 1.2 billion email-based phishing and malware attacks against Gmail users to understand what factors place a person at heightened risk of attack,” Google said. 

Google Blocks 99.9% Phishing Mails

Google stated that it blocks more than 100 million spam and malicious emails from reaching Gmail users. The search engine giant observed over 18 million COVID-19-related malware and phishing emails daily during the pandemic, in addition to more than 240 million COVID-19-related spam messages. Google’s machine learning models understand and filter more than 99.9% of spam, phishing, and malware from reaching its users.

U.S. Gmail Users are Most Targeted

Based on its five-month-long investigation, Google discovered that users in the U.S. were the most popular targets for phishing attacks (42%), followed by the U.K. (10%), and Japan (5%). The study also found that the attackers pre-plan their phishing campaigns by leveraging botnets and malicious attachments.

Who are at High Risk?

  • Users who have exposed their email or other personal details in a third-party data breach are likely targeted by phishing or malware by 5X.
  • User location matters. Where you live also affects risk. In Australia, users faced 2X the odds of attack compared to the U.S., despite the U.S. being the most popular target by volume.
  • With respect to demographics, the odds of experiencing an attack was 1.64X higher for 55- to 64-year-olds, compared to 18- to 24-year-olds.
  • Mobile-only users experienced lower odds of attack – 0.80X compared to multi-device users.

Other Findings

  • Most attackers don’t localize their efforts, using the same English email template for users in multiple countries.
  • There is, however, some evidence of regional attackers. Nearly 78% of the attacks targeting users in Japan occurred in Japanese, while 66% of attacks targeting Brazilian users occurred in Portuguese.
  • Threat actors rely on fast-churning campaigns. A similar email based on a template is sent to 100–1,000 targets on average.
  • The campaigns are brief, lasting just one to three days on average.
  • In a single week, these small-scale campaigns accounted for over 100 million phishing and malware emails in aggregate, targeting Gmail users around the globe.

Preventive Measures

Though Gmail’s phishing and malware protections are turned on by default, Google recommended certain security tips to avoid any phishing risks. These include:

  • Complete a Security Checkup for personalized and actionable security advice.
  • If appropriate, consider enrolling in Google’s Advanced Protection Program, which provides Google’s strongest security to users at increased risk of targeted online attacks.
  • Enable Enhanced Safe Browsing Protectionin Google Chrome to substantially increase your defenses against dangerous websites and downloads on the web.

Related Stories: