Home Blog Page 120

NCIJTF Releases Ransomware Fact Sheet for Public Awareness

Ransomware attacks, ransomware, Sinclair Broadcast group

The U.S. National Cyber Investigative Joint Task Force (NCIJTF) published a new ransomware fact sheet intending to spread public awareness on the ransomware threat landscape. The fact sheet details the critical information on the current ransomware threat scenario and the government’s response to it. Besides, the sheet describes the common infection vectors, tools for attack prevention, and the contacts in the event of a ransomware attack.

The NCIJTF is responsible for coordinating, integrating, and sharing information in support of cyberthreat investigations, supporting intelligence analysis for community decision-makers, and providing value to other ongoing efforts in the fight against cyberthreats to the nation.

NCIJTF estimated that victims paid over $144.35 million in Bitcoin as ransom between 2013 and 2019.  While ransomware attacks can impact any business in any sector, the FBI is particularly concerned about attacks on the networks of police and fire departments, state, local, territorial governments, municipalities, hospitals, and other critical infrastructure. “These types of attacks can delay first responders in responding to emergencies or prevent a hospital from accessing lifesaving equipment. It is imperative these organizations be prepared in the face of the ransomware threat,” the FBI said.

Common Ransomware Attack Vectors

Though ransomware operators leverage various attack methods to spread malware, the most common attack vectors include:

  • Email Phishing Campaigns
  • Exploiting Remote Desktop Protocol (RDP) Flaws
  • Misusing Software Vulnerabilities

How to Minimize Ransomware Risks

  • Backup your data, system images, and configurations Test your backups and keep the backups offline.
  • Enable multi-factor authentication.
  • Update and patch systems.
  • Make sure your security solutions are up to date.
  • Review and exercise your incident response plan.

NCIJTF advised the victims of ransomware attacks to file a complaint with Law Enforcement Authority or report the incident to the Internet Crime Complaint Center (IC3) or the Cybersecurity and Infrastructure Security Agency (CISA).

DriveSure Suffers Data Breach, Users’ Data Leaked on “Raidforums”

zero-day vulnerabilities

Adversaries posted sensitive information of 3.2 million DriveSure users on the underground hacking forum – Raidforums. Dubbed “pompompurin,” the hacker group advertised the leaked files and user data in a post, as proof of compromise. DriveSure is a car dealership service provider focused on employee training programs, customer retention, and maintains client data in large quantity.

According to Risk Based Security, the exposed information included full names, full addresses, contact details, email address, hashed passwords, car model, VINs, records of how much they paid for service, warranty status, emails to customers, texts sent to customers, IP addresses, damage claims, survey responses, logs of edits to customers, and current status of the car.

Hackers dumped two databases that hosted sensitive data of DriveSure users. One database has over 22 GB of the company’s MySQL files, which detailed dealer and inventory information, sales data, reports, claims, and customer data. The second compromised database contained 11,474 files in 105 folders and is 5.93 GB in size in their “parserfiles” s3 bucket.

The Impact

The exposure of sensitive data may bring severe consequences to the users whose data was affected in the incident. Cybercriminals can easily misuse users’ information for personal gains.

“The information leaked in these databases is prime for exploitation by threat actors, and in particular for insurance scams. Criminals can use personally identifiable information, damage claims, extended car details, and dealer and warranty information to target insurance companies and policyholders. Moreover, user credentials are used by threat actors to break into other valuable platforms such as bank accounts, personal email accounts, and corporate systems. The diverse set of user data can also be used to guess, and crack security questions often used by companies to reset passwords. Commercial email addresses can even be targets for spear-phishing or extortion,” Risk Based Security said.

Agent Tesla RAT Upgrades Itself with New Delivery and Evasion Techniques

WhisperGate malware campaign, Flagpro malware, MosaicLoader Malware, drinik

Malware is often on the lookout for newer ways to sneak and evade security. One such malware is Agent Tesla. It is an information stealer and Remote Access Trojan (RAT) active since 2014. It remained as one of the most widespread threats to Windows users. Cybercriminals often leverage Agent Tesla malware to steal user login credentials and other sensitive information from victims via screenshots, keyboard logging techniques, and clipboard capture.

Research published by cybersecurity firm Sophos details the latest evasion techniques of how the Agent Tesla operators disable endpoint protection before they install the malware and payloads.

Agent Tesla’s New Capabilities

Sophos stated that threat actors behind Agent Tesla are using a multi-stage process where a .NET downloader takes large chunks of malware from legitimate third-party websites like pastebin and hastebin. The attackers then join, decode, and decrypt the chunks to form the loader that carries the malicious payload.

In addition, the malware alters the code in Microsoft’s Anti-Malware Software Interface (AMSI) to disable endpoint security protection and install the malware without being blocked. AMSI service enables applications and services to integrate with installed security products.

Sean Gallagher, senior threat researcher at Sophos, said, “Agent Tesla malware has been among the top malware families distributed via email in 2020. In December, Agent Tesla payloads accounted for around 20% of malicious email attachment attacks intercepted by Sophos scanners. The most widespread delivery method for Agent Tesla is malicious spam.”

Remediation Measures

  • Install an intelligent, security solution that can screen, detect, and block suspicious emails and their attachments before they reach users.
  • Implement the recognized authentication standards to verify emails as what they claim to be.
  • Educate employees to spot the warning signs of suspicious emails and what to do if they encounter one.
  • Advise users to double-check the emails that come from the address and the person they claim to be.
  • Advise users to never open attachments or click on links in emails from unknown senders.

“Sophos believes that cybercriminals will continue to update the malware and modify it to evade endpoint and email protection tools. The email accounts used to spread Agent Tesla are often legitimate accounts that have been compromised. Organizations and individuals should, as always, treat email attachments from unknown senders with caution, and verify all attachments before opening them,” Gallagher added.

Airtel Data Leak: Close to 2.5 Mn Indian Users Likely Affected

India, cybercriminals, Airtel, Bharti Airtel, Airtel data leak, data leak, data breach, Aadhar, Aadhar data leak, identity theft, India Today, India Today Tech, data on sale,

India has been tiptoeing on finalizing its Personal Data Protection (PDP) Bill for a long time now. A month ago, it made 89 amendments and added one new clause to this long-standing bill, which has been debated in the parliament since its introduction in 2019. However, this needs to speed up, now more than ever, for the bill to become an Act/law. We are saying this because cybercriminals are polishing their ways of getting away, and the end-users are suffering, which is quite evident from the latest instance where a likely data leak has hit Indian telco giant Airtel, exposing the personally identifiable (PII) of millions of users. If this were to happen in the EU, the said company would face steep fines, as per the GDPR.

Airtel Data Leak

According to a report from a national publication house, India Today, nearly 2.5 million (25 lakh) subscribers of Airtel (registered under Bharti Airtel Ltd.) have likely fallen prey to a data leak that included their PII data. Airtel is India’s largest telecom service provider. Security researcher Rajshekhar Rajaharia made the discovery of this alleged data leak public through a tweet.

Reports suggest that the leaked information included the following:

  • Telephone number
  • Address
  • City
  • Aadhaar card number
  • Gender details

Related News:

Zhenhua Data Leak: Is China Spying and Collecting Data on Indians?

Was Airtel Aware?

Rajaharia shared another tweet where he revealed that Airtel’s security teams knew about the alleged leak and were in constant contact with the cybercriminals going by the name “Red Rabbit Team.”

According to the email trail presented in the video, the cybercriminals first reached out to the Airtel security team on December 12, 2020. They asked for a payout of $3,500 worth of Bitcoins in exchange for the leaked data. However, Airtel’s security team kept pushing them to allow extra time for negotiation. Eventually, out of infuriation, the Red Rabbit team posted the leaked data on the open web, which included a sample data set of 2.5 million subscribers as proof.

Rajaharia noted that the website containing the sample data set was taken down a few days ago and contained data majorly of Airtel’s subscribers in the Jammu and Kashmir region. However, if the leaked data was just a subset of the original data set, it could well mean that this is one of the biggest data leaks in India because Airtel has a subscriber base of nearly 327 million in the country.

An Earlier Instance

Around a year or two back, Airtel had accepted a security flaw in its mobile app’s API that allowed potential threat actors to fetch sensitive user information of any Airtel subscriber. Although Airtel quoted,  “We’ve fixed it,” could this have led to the current data leak situation?

Related News:

Airtel Accepts Security Flaw, Says, “We’ve Fixed it”

Ransomware – A Pandemic Plaguing the Digital World

ransomware

The world faced a growing spate of ransomware attacks in 2020. While malware was planted on systems throughout the year, it was detected only at the end of the year. According to a recent report,  more than 500 successful ransomware attacks were officially reported in over 45 countries in the past year (H2 2019 to H1 2020). The financial damages accounted for over $1 billion ($1,005,186,000) and a future forecast predicts this number to rise 20 times to $20 billion by 2021. Experts believe this number could double-up or even rise fivefold if all attacks are reported.

Ransomware operators targeted health care institutes, banks, government agencies, and universities. Unsettled employees — many of whom were working from home — and a distributed and depleted workforce, meant an increased likelihood of an incident happening, and it did.

The cover story in the February issue of CISO MAG includes a list of the top ransomware attacks and related incidents that sent aftershocks through the business world in 2020. It also compares the different generations of ransomware, to show how this threat became more deadly over the years. Our editors dug deep to discover some scary facts and they write about what the next generation of ransomware could do, and how it would come knocking at your doors (networks).

Our editors also spoke to industry experts and curated their opinions and insights, to validate our beliefs.

We discovered new trends and changing attack vectors. For instance, attackers are now going after NAS devices, because these are backup repositories. Attention CISOs! Even your backups will be encrypted and locked. Another trend is ransomware-as-a-service. The bad guys are keeping up with trends and now offering services on the dark web.

Experts that we spoke to are already talking about new security measures like hardware-based encryption (Intel and Cybereason) and off-line storage (remember DLT magnetic tape storage?).

But the industry is not taking all this lying down. Efforts are on to fight ransomware and you can expect more news on this front in 2021. The Institute for Security and Technology launched the Ransomware Task Force in partnership with experts from multiple domains like the industry, government, law enforcement, nonprofits, cybersecurity insurance, and international organizations.

Read more about all this (and other stories about Ransomware) in our February issue.

Subscribe and download CISO MAG here.

 

 

 

 

 

Ransomware Operators Exploit 2 CVEs in VMWare ESXi

ransomware, ryuk ransomware, cox media

Ransomware gangs are evolving every day. The latest trend suggests that they are after the backup servers or machines that contain backed up data. Why? Because once these are compromised, their victims have no option but to pay the ransom. With a purview of this trend, ransomware operators are said to be exploiting two previously known vulnerabilities in VMWare ESXi logged under CVE-2019-5544 and CVE-2020-3992 to target their victims’ virtual hard disks.

The Two VMWare ESXi Vulnerabilities

In October 2020, a Reddit user reported a ransomware attack that encrypted nearly 200 virtual machines (VMs) at the datastore level in which a ransom note was found at the root of the datastores. The user further stated that since the VMWare ESXi management was not segregated from the VMs, and hence the attackers successfully encrypted the VMs.

Related News:

VMware Adds New Edge to its SASE Capabilities

Fast forward to January 2020. Another Reddit user found astounding evidence of Brazil’s Superior Justice Tribunal (SJT) being hit by a similar ransomware attack encrypting nearly 1,000 VMs with the exact ransom note. The sophistication of the attack was such that the attackers even went after disk backups. However, some old school tape backups remained untouched and saved the day for many.

On analyzing these attacks, researchers observed that in both the instances, the attackers used CVE-2019-5544 and CVE-2020-3992 vulnerabilities in VMware ESXi. ESXi is a solution that allows multiple virtual machines to share the same hard drive storage.

Dissecting the ESXi Ransomware Attack

The chronology of the ESXi ransomware attack:

  1. The attackers sent phishing emails to the target organization’s employees/users, of which three unknowingly fell prey by clicking and installing a Trojan.
  2. The attackers then escalated the privileges using CVE-2020-1472. The workstations had anti-virus protection, which at the time did not have this Trojan’s signature (it was released a few days later).
  3. The attackers gained access to hosts that had access to ESXi’s management subnet, as they already had Active Directory (AD) admin privileges.
  4. Without having to compromise vCenter, they were able to run arbitrary code on the ESXi hosts using CVE-2019-5544  or CVE-2020-3992.
  5. This led to the creation of an executable file (written in Python language) on ESXi hosts, which encrypted all the VMs.

Kaspersky, which named it as RansomEXX Trojan, gave a proof-of-concept of how this Trojan works. Click here for more info.

Remedial Measures

Researchers have found the following MD5 signatures in the attacks carried out, which all security teams need to note:

MD5 (svc-new/svc-new) = 4bb2f87100fca40bfbb102e48ef43e65MD5 (notepad.exe) = 80cfb7904e934182d512daa4fe0abbfbSHA1 (svc-new/svc-new) = 3bf79cc3ed82edd6bfe1950b7612a20853e28b0SHA1 (notepad.exe) = 9df15f471083698b818575c381e49c914dee69de

P.S.: svc-new/svc-new, a python script, was found inside the ESXi hosts, and the notepad.exe was found on the encrypted Windows servers.

But what if we told you that this ransomware can be avoided in the first place. Here are some suggestions:

  • Disable the VMware CIM Server (It is enabled by default).
  • Apply least privileges on your Active Directory administration.
  • Segregate Admin and Domain admin accounts on Active Directory.
  • Establish a Group Policy Object (GPO) set to log out users on inactivity instead of disconnecting them on remote desktop servers.
  • Keep and monitor audit trails of Domain Admin accounts.
  • Review backup routines. Have a master backup if possible and make sure they are segregated from regular backup. Even better, maintain an offsite read-only backup to make sure recovery is possible.
  • Constitute an isolated network for ESXi/vCenter, which needs to have its access audited, using a jump server.
  • Maintain IP access controls vCenter and ESXi.
  • Remove vCenter Active Directory integration and maintain distinct passwords.
  • Disable SSH on all ESXi hosts as a precautionary measure.
  • Implement usage of canary files monitored by a SIEM.
  • Use 2FA wherever possible, especially on admin accounts and high-priority accounts.
  • Patch Windows Servers, workstations, ESXi servers, backup servers, vCenter frequently. Review failed patch reports and report immediately to the said service provider to assure all functions are up to date.

Related News:

VMware Adds New Edge to its SASE Capabilities

Microsoft Rolls Out Application Guard for Office

Hackers Target Office 365 Users with SurveyMonkey Phishing Campaign

Microsoft has released Application Guard for Office, a defensive technology that detains untrusted Office documents from accessing trusted resources on a user’s device. The new defensive service prevents malware or malicious files from penetrating a device’s operating system or application software, keeping the user’s perimeter secure from emerging cyberattacks. The Application Guard for Office will apply to MS Word, MS Excel, PowerPoint for Microsoft 365, and Windows 10 Enterprise.

Hardware Requirements to Install Application Guard for Office

  • CPU: 64-bit, 4 cores (physical or virtual), virtualization extensions (Intel VT-x OR AMD-V), Core i5 equivalent or higher recommended
  • Physical memory: 8-GB RAM
  • Hard disk: 10 GB of free space on the system drive (SSD recommended)

Software Requirements

  • Windows OS: Windows 10 Enterprise edition, Client Build version 2004 (20H1) build 19041 or later.
  • Office application: Office Current Channel Build version 2011 16.0.13530.10000 or later.
  • Update package: Windows 10 cumulative monthly security update KB4571756.

How to Enable Application Guard for Office?

  1. Download and install Windows 10 cumulative monthly security updates KB4571756.
  2. Select Microsoft Defender Application Guard under Windows Features and select OK. Enabling the Application Guard feature will prompt a system reboot. You can choose to reboot now or after step 3.
Image Courtesy: Microsoft Support

3. Search for Microsoft Defender Application Guard in Managed Mode, a group policy in Computer Configuration\Administrative Templates\Windows Components\Microsoft Defender Application Guard. Turn on this policy by setting the value under Options as 2 or 3, and then selecting OK or Apply.

4. Restart the system.

Application Guard for Office restricts untrusted documents to reach corporate resources, users’ intranets, identity, and arbitrary files on the computer. Microsoft said, “If a user tries to access a feature that has a dependency on such access — for example, inserting a picture from a local file on disk — the access will fail and produce a prompt like the following example. To enable an untrusted document to access trusted resources, users must remove Application Guard protection from the document.”

Related Story: Microsoft to Launch Enforcement Mode to Address Critical “Zerologon” Flaw

TeamTNT Spreads Malware with New Detection Evasion Tool “Libprocesshider”

Zero Trust, cybersecurity

Security experts at AT&T Alien Labs uncovered a new detection evasion tool leveraged by threat actor group TeamTNT. Dubbed “Libprocesshider,” the new tool is copied from open-source repositories. It helps cybercriminals hide their malware and malicious process from process information programs like “ps” and “lsof,” acting as a defense evasion technique. The purpose of Libprocesshider is to hide the TeamTNT bot from process viewer tools and remove malware traces by deleting the bash history.

“The tool implements the function readdir(), which is being used by processes such as `ps` to read the /proc directory to find running processes and to modify the return value in case there is a match between the processes found and the process needed to hide. The new tool arrives within a base64 encoded script hidden in the TeamTNT cryptominer binary or ircbot,” AT&T said.

Libprocesshider’s Capabilities

  • Modify the network DNS configuration
  • Set persistence through systemd
  • Drop and activate the new tool as a service
  • Download the latest IRC bot configuration
  • Clear evidence of activities to complicate potential defender actions

How Libprocesshider Penetrates?

  • First, Libprocesshider is dropped as a hidden tar file on disk.
  • The script decompresses it and writes it to ‘/usr/local/lib/systemhealt.so’ and adds it to preload via ‘/etc/ld.so.preload.’
  • This is then used by the system to preload the file before other system libraries, allowing the attacker to override common scanning operations.

“Through the use of Libprocesshider, TeamTNT once again expands their capabilities based on the available open-source tools. While the new functionality of Libprocesshider is to evade detection and other basic functions, it acts as an indicator to consider when hunting for malicious activity on the host level,” AT&T added.