Home Blog Page 126

Google Delists 164 “CopyCatz Apps” for Spreading Malicious Ads

Mobile Apps Security, mobile apps

With people becoming more dependent on the app ecosystem, threat actors targeting unwitting users with fake mobile apps to compromise their accounts or steal sensitive data have become rampant. Despite multiple security checks and scans, many counterfeits and malicious apps remain undetected and make their way to the app markets. Recently, Google removed 164 malicious applications for spreading disruptive ads, these apps were downloaded over 10 million times from the Play Store.

Hundreds of CopyCatz Apps!

Security experts from the WhiteOps Satori Threat Intelligence Team stated that they found a large number of fake mobile apps, dubbed “CopyCatz” on Google’s Play Store that were mimicking apps of popular brands to get downloads and then trick the users into seeing unwanted ads.

How the Apps Infect the Device

Scammers Victimized Popular Brands

The researchers claimed that these fake apps contain a malicious code that displays out-of-context ads under the com.tdc.adservice package. It was found that these apps were controlled by a command-and-control JSON hosted on Dropbox, which was also a victim of CopyCatz operation. For instance, attackers used Assistive Touch 2020, which was a copy of the legitimate app – Assistive Touch, to trigger out-of-context ads on users’ devices.

“The URL of the JSON differs from app to app, but the structure is very similar, indicating the frequency of the ads and the Publisher ID to be used. Interestingly, the apps didn’t really try to cover their tracks. All of them have the open-source Evernote job scheduler embedded inside used as a persistence mechanism,” the researchers said.

Related Story: How to Spot Malicious or Fake Apps

A 21st Century Solution to Our Cybersecurity Skills Shortfall

cybersecurity-budget

As both a CSO and CIO, I am often asked – what keeps you up at night? Undoubtedly, I, like many of my peers, have insomnia caused by the real and growing challenge facing not just my organization, but the entire global cybersecurity community: the increasingly daunting task of identifying, recruiting, and retaining top talent to fill widening demand. While the problem is pervasive in all areas of IT, cybersecurity is particularly severe.

By Jason Albuquerque, CIO & CISO, Carousel Industries, Inc.

The forecasts are big, scary, and truly staggering. (ISC)² estimates the current cybersecurity workforce is now 2.8 million professionals but more than four million professionals are needed to close the skills gap. The data indicates a necessary cybersecurity workforce increase of 145%. In the U.S. market, the current cybersecurity workforce estimate is 804,700 and the shortage of skilled professionals is 498,480, requiring an increase of just 62% to better defend U.S. organizations.

So, what is being done — or what must be done — to reverse this trend and better equip our global workforce and the organizations it services to close this gap?

As a CSO, CIO, and former member of the U.S. military, I think I bring a unique perspective on the importance of continuous training and advanced certifications. I’ve seen the tremendous advantages they deliver to IT and security professionals at every stage of their careers. I also had the good fortune of taking a slightly different path to the corporate workforce – one that gave me real on-the-job training while attending college. It is this background that shapes my beliefs and thoughts on addressing this critical need for our cyber workforce development.

Here’s my five-point plan for developing a 21st-century solution to our cybersecurity skills shortfall.

1. Build New Alliances

Throughout history, tough adversaries have been defeated when one or more organizations join forces to deliver a combined set of strengths and resources, which can deliver value and results far more powerful than if those organizations remained siloed or operated unilaterally.

Today, our nation’s higher education system and the for-profit tech industry share a somewhat curious relationship. They have common interests – the education, preparation, and utilization of our future and current tech-focused workforce – yet the somewhat harsh reality is that, with few exceptions, successful partnerships involving these two seemingly philosophically aligned entities, remain rare.

We need to change this and develop new programs that incentivize activity in research and training like those being driven by Facebook. While not having been a beacon for personal privacy and security, Facebook still understood the dire need for security talent and has invested accordingly. Through its Cyber Security University Program, Facebook is collaborating with several colleges and universities to offer cybersecurity courses and provide access to hands-on training, mentoring, and industry events. Texas A&M University-San Antonio, one of the participants, won a National Science Foundation grant to help recruit students for these positions and connect graduates with jobs. It also opened a $63 million science and technology building to house its Center for Information Technology and Cyber Security.

Facebook also launched a cyber skills development program specifically for Veterans, which I fully support and hope is replicated elsewhere. I applaud these efforts but urge more tech and IT services companies, as well as colleges and universities – especially at the state and local level – to look to follow suit.
Similarly, Fortinet, a global leader in broad, integrated, and automated cybersecurity solutions, has launched it’s Fortinet Network Security Academy (FNSA) and the Fortinet Veterans (FortiVet) program which applies training and education programs to help close the cybersecurity skills gap and address the talent shortage.

FNSA aims to shape the next generation of cybersecurity professionals by providing industry-recognized Fortinet training and certification opportunities to secondary and university students, as well as to individuals working with participating non-profit organizations. By collaborating with the FNSA program, academic institutions and nonprofit organizations gain access to Fortinet’s NSE certification curricula – ensuring that participants gain the knowledge required to become part of an elite group of skilled security professionals.

The FNSA program provides cybersecurity training and certification opportunities that were once exclusive to Fortinet customers, employees, and partners to students. With more than 200 participating academies located in more than 60 different countries, the FNSA ensures that participants from across the world graduate from this program with the skills they need to defend networks against ever-evolving cyberthreats.

2. Overhaul Cyber-Education Approaches

Despite the best efforts by colleges and universities, my experience has shown that students today are simply not learning modern skills. Surprisingly, relatively few colleges offer undergraduate or graduate cybersecurity degrees that ensure graduates have the skills that will make them successful. I am hopeful, however, that change is coming. Related to the point above, colleges are partnering with the private sector to design new programs and curricula that meet workforce needs and, in some cases, helps shoulder the cost of expensive training and simulation facilities such as cyber ranges. These schools include Augusta University, Regent University, Texas A&M, the University of Michigan, and Virginia Tech.

There is an overreliance upon the theory in many cybersecurity classrooms today. How do we change this? We need more cross-pollination among cyber practitioners and universities – lectures, real-world training, co-ops, hackathons. These are just a few vehicles that need to be adopted, promoted, and celebrated for their successes.

3. Adopt an Apprenticeship Model

Apprenticeships have their roots in the late Middle Ages when master craftsmen trained young men and women. Across Europe and in America, similar programs flourished at the turn of the 20th century for skilled trade workers in traditionally blue-collar areas such as electricians, plumbers, and other trades. So perhaps the term “apprenticeship” suffers from a dated perception and is in need of an overhaul or adaptation on its own. Regardless, it is hard to argue with the success of these programs in these industries and in IT and cybersecurity, we are long overdue for organizations to embrace and advance this model. It just makes so much sense – and not just for young men and women who have just graduated high school or college and are unsure of their career paths or who’ve change their minds. Apprenticeship programs can serve career changers at arguably every stage of life.

4. Incentivize New Skills Training

Whether part of a formalized apprenticeship program or not, there may be no workforce initiative of greater importance today than re-skilling or up-skilling workers. In cyber, this is happening but on a small scale so far.

In 2018, Federal Cybersecurity Reskilling Academy offered U.S. Federal employees the opportunity for hands-on training in cybersecurity. This reskilling effort was part of the Administration’s commitment to developing a Federal workforce of the 21st century, as outlined in the President’s Management Agenda and the recent Government Reform Plan. The inaugural class comprised current Federal employees not working in the IT field and was designed to help them build foundational skills in the field of Cyber Defense Analysis. The second class was open to all Federal employees. Although the academy’s future is unclear, demand was strong. Federal Chief Information Officer (CIO) Suzette Kent shared last year that the program received over 1,500 applications and over 20,000 social media impressions during a 50-day application window.

Last year, a program launched by my organization – the Certified Ethical Hackers Program – provided comprehensive cybersecurity training and certification to a group of employees seeking to expand their skillsets and knowledge. Based on the highly-regarded Certified Ethical Hacker (CEH) curriculum, the training covered the newest techniques in security, including footprinting and reconnaissance, scanning networks, vulnerability analysis, system hacking, social engineering, session hijacking, and evading IDS, firewalls, and honeypots.

Our efforts were focused on giving proven employees opportunities to learn and apply new skills to expand their value to fortify our own defenses and apply these skills directly to client engagements. The program was tremendously popular, and we intend to replicate it again in the future and are eager to open our playbook to other organizations interested in the concept.

5. Market Cyber Career Paths Downstream

Ultimately, for the cybersecurity field to have a sustainable pipeline of diverse talent, we need to be identifying aptitude for technology and cybersecurity as early as possible. To address this gap, we must capture the interest of a wider and more diverse set of students. We must reach down to the middle school levels. In order to be successful, we must work with K-12 educators to create cybersecurity curriculum for teachers. These efforts will bear fruit down the line for our industry.

These programs work because they benefit all. Talent-strapped employers can expand their recruitment pool while identifying a new crop of potential employees – likely with modest salary demands eager to learn new skills as they enter a brand-new field. Similarly, employees are given a tremendous opportunity to learn valuable and highly marketable new, real-world skills from tech professionals in proven corporations. Organizations such Bosch, Barclay’s Bank, IBM, and Amazon all currently or previously have implemented successful technology-driven apprenticeship programs. We need to learn from these organizations, celebrate their successes, and encourage many more programs of similar nature.


About The Author

Jason AlbuquerqueJason Albuquerque is responsible for Carousel’s IT Operations, Enterprise Security and Compliance, and Innovation Center of Excellence. He takes pride in leading the charge in building a culture that is secure by design for the Carousel community and its clients. Jason brings the highest levels of leadership, industry knowledge, and agility that today’s industry requires to effectively respond to the rapidly changing innovation, business, threat, and risk landscape. He is the recipient of several prestigious awards in technology and leadership, like Rhode Island’s 40 under Forty Award, Rhode Island’s Tech 10 Award, and is a seven-time National Public Technology Institute Solutions Award winner. Jason is a co-host of the Business Security Weekly Podcast and is a frequent contributor to CIO, Forbes, and several other leading IT and business publications. He currently serves on Congressman Langevin’s (D-RI) Cybersecurity Advisory Committee, Tech Collective Board of Directors, and the Rhode Island Joint Cyber Task Force.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.


This story first appeared in the July 2020 issue of CISO MAG. Get your preview here.
Get the preview of our January 2021 issue here. Subscribe now!

“The battle for the vaccine market to launch cyberattacks has already begun”

Dmitry Volkov interview

As a first-year student at Russia’s leading engineering university, the Moscow State Technical University of N.E. Bauman, Dmitry Volkov co-founded Group-IB, a cyber investigations startup back then. Seventeen years on, the company has evolved into one of the cybersecurity leaders known for its engineering innovations. Group-IB now protects banks, industrial enterprises, and eCommerce giants in 60 countries around the world, and offers solutions in Threat and Fraud Hunting, Threat Intelligence & Attribution, and Digital Risk Protection categories. The company’s services, however, continue to play an important role in feeding the Group-IB Threat Hunting ecosystem, distributed across Singapore, Amsterdam, Hanoi, Moscow, Bahrain, and other locations, with unique battlefield cyberthreat intel.

Volkov is the mastermind behind most of Group-IB’s products. From day one, he has been a prominent voice leading Group-IB toward becoming the go-to expert in threat hunting and intelligence. His team successfully conducted the first and later on the most complicated cyber investigations and DFIR engagements. They have helped identify and track the most notorious threat actors, including Cobalt, Silence, MoneyTaker, Lazarus, etc.

Volkov is a recognized visionary leader. In 2015, he was listed by Business Insider as one of the top 7 professionals behind influential security companies. Dmitry is a great believer in the idea of engineering neutrality and advocate of cyber weapon non-proliferation. In 2013, Volkov became a member of the UN Open-ended Intergovernmental Expert Group aimed at conducting a comprehensive study on the problem of global cybercrime. Since 2016 he is a member of the Europol EC3 Advisory Group on Internet Security.

In a recent interview with Augustin Kurian from CISO MAG, Volkov talks about cybersecurity trends in 2021, espionage attacks, and how various scammers are discussing these topics like vaccines on the dark web.

What according to you will continue to be a cybersecurity trend even in 2021?

I’m sure that next year we will see even more ransomware operators joining Big Game Hunting, which refers to the attacks on big companies with huge assets that are more likely to pay the ransom. With large companies continuing to make some primitive errors, like failure to promptly update the software to patch vulnerabilities or the use of weak passwords, they are still an easy target for ransomware operators. The above also explains the continuous growth of the market for the sale of access to corporate networks, which, according to Group-IB forecasts, will continue increasing the following year.

Next year, in the light of rising tensions in MEA, Group-IB expects to see more sabotage campaigns by state-sponsored threat actors in the region. This might lead to dire consequences since intelligence agencies are attacking more aggressively. Their goal is now not only to spy on targets covertly but also to destroy critical infrastructure facilities.

The year 2021 is also likely to bring more attacks with the use of JS-sniffers and POS malware, intending to gather bank card data (text data and data of bank card magnetic strips) that pose a major threat to online retail, especially in the U.S. JS-sniffers, which once were a seldom-studied type of malware, has become a mainstream tool for cybercriminals who make their living selling stolen textual data from bank cards. Only from H2 2019 to H1 2020, the number of known JS-sniffer families has grown from 38 to 96, while the techniques that prevent JS-sniffers from being detected on web resources have improved greatly.

It is safe to say that the COVID-19 vaccine may take a fair share of the limelight in 2021. Do you think there would be an uptick in the number of phishing and ransomware attacks surrounding the same?

Threat actors always exploit hot topics in their attacks and the vaccine will be no exception. Therefore, we are likely to see a lot of phishing emails and scams surrounding this subject. Already, we see various scammers discussing these topics on the dark web, though, not very actively.

This year, several countries, including the U.S., admitted they were being targeted by state-sponsored espionage attacks surrounding vaccine development. With the varying success rate of different vaccines across the world, do you anticipate a surge in corporate espionage in 2021?

Espionage is always on the rise: new groups appear every year and old groups whose activities remained undetected are uncovered; tools and instruments to carry out the attacks are constantly being improved, and we see that state-sponsored attackers are only getting stronger. In the future, state-sponsored threat actors are likely to engage ordinary cybercriminals purchasing access to corporate networks from them or recruiting them for espionage activities, which will lead to an even greater increase in spying. As I’ve already mentioned, the battle for the vaccine market has already begun, and we expect espionage around vaccine-related organizations to grow further.

In your recent report on cybercrime, Group-IB stated that it identified a continuing trend where physical destruction of infrastructure is replacing espionage. It also highlighted that seven new APT groups joined the global intelligence service stand-off. Can you share more details about it? And how big of a concern is it?

It would be correct to say that the attackers’ focus has shifted from only espionage to spying with subsequent sabotage, or physical destruction of infrastructure. To sabotage effectively, one must first gain access to a target network, do reconnaissance in the victim network, and obtain desirable resources. Only advanced nation-state attackers can carry out effective sabotage operations, with such campaigns being prepared for years. Since the results of sabotage campaigns become visible immediately, attackers normally reveal themselves as a last resort and only in hot spots. It’s not worth explaining that such attacks can lead to colossal losses. Sabotage campaigns that we see today should be regarded as only a rehearsal, and judging from it, critical infrastructure facilities are not ready for a situation where such attacks become a general problem, given the constant growth of the number of state-sponsored Advanced Persistent Threat (APT) groups. It is noteworthy that sometimes cybersecurity researchers notice new APT groups only several years after it began their activity, which underlines how sophisticated these threat actors are.

By 2021, 5G will be widely available, and the floodgates will open, and both the white hats and black hats of the world will experience a swift learning curve in navigating the mass distribution and interconnectivity of 5G. What strategies should companies deploy to circumvent this impending threat landscape?

The architectural features of 5G (compared to 1/2/3/4G), such as superfast data transfers and other advantages of the new technology, are mainly implemented using software rather than hardware platforms. It means that all threats to server and software solutions are becoming relevant to 5G network operators. Such threats, including traffic manipulation and DDoS attacks, might become much more frequent and effective due to the large number of insecure devices connected and wide bandwidth. I would, therefore, highlight three main points regarding the issue by the priority. The first one is research: it is necessary to invest as much as possible in 5G security research. The second one is the inventory. Connected devices are very often vulnerable, and it is necessary to create a system to identify all new devices and monitor their status. Currently, existing solutions do not solve this problem well. The third one is protection. I would keep this issue open because this is a necessary phase, but it is unique for each organization.

From the standpoint of a zero-trust model, do you think it should be standard and by-design for the future?

This model can and must become the standard. We see more and more companies in the corporate sector building their cybersecurity in accordance with the zero-trust model, which confirms its viability.


Augustin Kurian

About the Author 

Augustin Kurian is part of the editorial team at CISO MAG and writes interviews and features.


This interview first appeared in the January 2021 issue of CISO MAG. Get your preview here.
Subscribe now!

Strengthen Your Cloud! CISA Warns Organizations Amid Rising Attacks

Misconfigured Cloud Storage Services Led to Over 200 Breaches in Past Two Years

The Cybersecurity and Infrastructure Security Agency (CISA) has advised users and organizations to strengthen their cloud security configurations after detecting multiple attacks targeting cloud services. In a security advisory, the agency stated that cybercriminals used advanced phishing and other attack vectors to exploit poorly configured cloud services.

Brute Force and Pass-the-Cookie Attacks

CISA claimed that attackers leveraged a variety of tactics and techniques, including phishing, brute force login attempts, and pass-the-cookie attacks to exploit loopholes in an organization’s cloud security practices.

In Pass-the-Cookie attack technique, the attacker compromises the cookies to gain unrestricted access to the victim’s resources. Even multi-factor authentication can be bypassed using this technique.

“These types of attacks frequently occurred when victim organizations’ employees worked remotely and used a mixture of corporate laptops and personal devices to access their respective cloud services. Despite the use of security tools, affected organizations typically had weak cyber hygiene practices that allowed threat actors to conduct successful attacks,” CISA said.

CISA’s Observations

  • In several engagements, CISA observed threat actors collecting sensitive information by taking advantage of email forwarding rules, which users had set up to forward work emails to their personal email accounts.
  • CISA determined that the malicious actors modified an existing email rule on a user’s account—originally set by the user to forward emails sent from a certain sender to a personal account—to redirect the emails to an account controlled by the actors. The adversaries updated the rule to forward all email to their accounts.
  • Attackers also modified existing rules to search users’ email messages (subject and body) for several finance-related keywords (which contained spelling mistakes) and forward the emails to their accounts.
  • In addition to modifying existing user email rules, they created new mailbox rules that forwarded certain messages received by the users (specifically, messages with certain phishing-related keywords) to the legitimate users’ Really Simple Syndication (RSS) Feeds or RSS Subscriptions folder in a bid to prevent legitimate users from seeing the warnings.

How to Mitigate?

CISA also recommended certain security steps for organizations to strengthen their cloud security practices. These include:

  • Implement conditional access (CA) policies based upon your organization’s needs.
  • Establish a baseline for normal network activity within your environment.
  • Routinely review both Active Directory sign-in logs and unified audit logs for anomalous activity.
  • Have a mitigation plan or procedures in place; understand when, how, and why to reset passwords and to revoke session tokens.
  • Verify that all cloud-based virtual machine instances with a public IP do not have open Remote Desktop Protocol (RDP) ports. Place any system with an open RDP port behind a firewall and require users to use a VPN to access it through the firewall.
  • Focus on awareness and training. Make employees aware of the threats—such as phishing scams—and how they are delivered. Additionally, provide users training on information security principles and techniques as well as overall emerging cybersecurity risks and vulnerabilities.
  • Establish blame-free employee reporting and ensure that employees know who to contact when they see suspicious activity or when they believe they have been a victim of a cyberattack. This will ensure that the proper established mitigation strategy can be employed quickly and efficiently.

Nokia for U.S. Federal 5G Cybersecurity Project

5g security, 5G cybersecurity

Post Huawei’s ban from deploying 5G communications equipment in countries like the U.S., Australia, Taiwan, the U.K., and others, Nokia has now claimed the throne to become the main 5G solutions provider in NCCoE’s 5G Cybersecurity Project.

Someone’s Loss is Someone’s Gain

In July 2019, several researchers found evidence of Huawei’s involvement with Chinese state-sponsored attackers. The incident proved to be the last straw in its worldwide ban. Owing to the ban, Huawei had to forfeit its deals, which included providing 5G communications equipment to a majority of developed countries. The claim of malpractices on Huawei’s end further strained the relationship between the U.S. and China, which eventually culminated in the form of a trade war.

Related News:

Huawei employing China-sponsored hackers: Research

However, the incidents did not do any good to either of the parties. Scrapping the deal resulted in monetary losses to Huawei and China, as some of its equipment was already shipped to the U.S. and for the U.S., the end deal meant a huge delay in shifting from the 4G to 5G technology. But the entire fiasco was an eye-opener for the U.S. Federal agencies. They took the cybersecurity concerns of the 5G technology very seriously and have now announced a host of collaborators for their 5G Cybersecurity Project including Nokia.

The 5G Cybersecurity Project

In November 2020, the National Cybersecurity Center of Excellence (NCCoE), a sub-department of the NIST, invited technology providers and industry experts AMI, AT&T, CableLabs, Cisco, Dell Inc., Intel, Keysight, MiTAC, Nokia, Palo Alto Networks, and T-Mobile to collaborate on the 5G Cybersecurity Project. These companies will help NCCoE’s 5G team to identify 5G use case scenarios and show how 5G architecture can provide security capabilities to mitigate identified risks and meet the compliance requirements.

Related News:

5G Networks Present New Risks and Security Challenges

The scope of the project is to leverage the 5G standardized security features which are defined in 3GPP standards to provide enhanced cybersecurity capabilities built into network equipment and end-user devices. The 5G Cybersecurity Project is currently in build phase and is based out on the following building blocks:

  • 5G security
  • Adversarial machine learning
  • Applied cryptography
  • Data security
  • Derived PIV credentials
  • Internet of things (IoT)
  • Mobile device security
  • Patching the enterprise
  • Supply chain assurance
  • Trusted cloud
  • Zero trust architecture (ZTA)

The Baton is Passed to Nokia

Strengthening their trust in their collaborators, the NCCoE has announced that Nokia is their main 5G solutions provider and collaborator. Nokia will partner with NCCoE’s 5G experts and other vendors to ensure a safe and secure transition from 4G to 5G networks.

Raghav Sahgal, President, Cloud and Network Services at Nokia said, “Previous cellular technology generations have been industry-led whereas 5G development must evolve in collaboration with governments to ensure availability and access of secure trusted networks. The 5G Cybersecurity Project fills this role with a cross-section of government and industry collaborators on board. At Nokia, we embed security into every solution that we ship, and we are committed to enabling the secure shift to the cloud by working with government agencies and the industry to advance cybersecurity for 5G use cases that leverage both open and commercial components.”

For improved 5G security, Nokia is also reportedly deploying their 5G RAN software and core solution along with IP-Backhaul for the project.

Microsoft’s First Patch Tuesday of 2021 is Here! Know Which Flaws are Fixed

Microsoft November 2021 Patch Tuesday, Windows 10, Microsoft PrintNightmare

Microsoft released the official patches for over 83 newly discovered vulnerabilities as part of its Patch Tuesday security updates, marking the first of many for 2021. The technology giant stated that the latest security updates address flaws in around 11 of Microsoft’s products and services, including an actively exploited zero-day vulnerability. Out of 83 vulnerabilities, 10 were listed as critical, and 73 as important in severity.

The January 2021 security release consists of security updates for the following software:

  • Microsoft Windows
  • Microsoft Edge (EdgeHTML-based)
  • Microsoft Office and Microsoft Office Services and Web Apps
  • Microsoft Windows Codecs Library
  • Visual Studio
  • SQL Server
  • Microsoft Malware Protection Engine
  • .NET Core
  • .NET Repository
  • ASP .NET
  • Azure

According to the release, the Remote Code Execution (RCE) flaw in Microsoft Defender (CVE-2021-1647) is listed as the most severe bug which could enable threat actors to infect qualified units with arbitrary code.

“According to Microsoft, this vulnerability was exploited in the wild as a zero-day, though no further details have been shared. Considering how prevalent Microsoft Defender is, this flaw provides attackers with a large attack surface. Microsoft also patched CVE-2021-1648, an elevation of privilege vulnerability in the printer driver host, splwow64 due to improper validation of user-supplied data. The vulnerability is marked as publicly disclosed by researchers at Google Project Zero and through the Zero Day Initiative. While it is labelled as an elevation of privilege vulnerability, Microsoft states that it can also be used for information disclosure,” said Satnam Narang, Staff Research Engineer at Tenable.

The latest patches also fix other critical bugs like a memory corruption flaw in Microsoft Edge Browser (CVE-2021-1705), a Windows Remote Desktop Protocol Core Security feature bypass flaw (CVE-2021-1674), and five critical RCE flaws in Remote Procedure Call Runtime.

How to Install the Latest Security Updates

“It is important to install the latest servicing stack update. Updates for Windows RT 8.1 and Microsoft Office RT software are only available via Windows Update. In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features. Customers running Windows 7, Windows Server 2008 R2, or Windows Server 2008 need to purchase the Extended Security Update to continue receiving security updates,” Microsoft said in a release.

Unprotected Server Exposes Scraped Data of 214 Mn Social Media Users

106 million Thailand visitors

Socialarks, a Chinese social media management company, recently suffered a massive data breach that exposed over 400GB of users’ personally identifiable information (PII).

According to the researchers from Safety Detectives, an unsecured ElasticSearch database leaked the personal data of over 214 million social media users, globally, including celebrities and social media influencers. The database was left online without password protection, allowing anyone in possession of the server IP-address to access it.

The researchers found that the exposed data was illegally scraped from various social media profiles on Facebook, Instagram, and LinkedIn.

What Data are Exposed?

While the researchers found 318 million records in the exposed 408GB data dump, the exact number of affected users remains unknown. The leaked database contains:

  • More than 11 million Instagram user profiles, including names, phone numbers, usernames, profile pictures, email addresses, average comment count, number of followers and following count; country of location, frequently used hashtags, and locations
  • Nearly 82 million Facebook profiles including full names, contact details, email addresses, Messenger IDs, Like, Follow and Rating count; Facebook link with profile pictures, website link, profile description, and pictures
  • Around 66 million LinkedIn user profiles containing full names, email addresses, employment details, job profile including job title and seniority level, LinkedIn profile link, user tags, domain name, connected social media account login names, company name, and revenue margin

What’s the Impact?

Cybercriminals often exploit scraped or leaked content for various malicious operations.  “In some cases, scraped data can be weaponized to carry out a specific goal of extracting personal information for criminal purposes. Potential ramifications of exposing personal information include identity theft and financial fraud conducted across other platforms including online banking. Contact information can be harnessed to target people with targeted scams including sending personalized emails containing other personal information about the target, thereby gaining their trust, and setting the stage for a deeper intrusion into their privacy,” Safety Detectives said.

What is Data Scraping?

Data scraping is extracting users’ private information from a website or social media platform without their knowledge, which is against the data privacy policy.

Artificial Intelligence and Cybersecurity: A Double-Edged Sword

Artificial Intelligence

As artificial intelligence (AI) becomes a hot topic, there is also an increasing amount of misinformation and confusion about what it can do and the potential risks it presents. The cultural legacy of decades of literature and film has depicted dystopian visions of human downfall at the feet of omniscient machines. On the other hand, many people understand the beneficial potential of AI to speed up and help the evolution of our society. Although computer systems can learn, reason, and act, these behaviors are still in their early stages. Machine Learning (often abbreviated as ML) needs huge amounts of data even for just learning, translated into training or coaching depending on the function that is assigned to Artificial Intelligence. Allowing AI access to information and giving it full autonomy therefore carries serious risks that must be considered.

By Pierguido Iezzi, Cyber Security Director and co-founder of Swascan

The first risk of artificial intelligence is intrinsically linked to its creation. The human mind bears the ancestral burden of error. Accidental bias, or more simply, an error of the programmer or in the dataset, can generate a series of countless errors on the part of the AI. Incorrect design of artificial intelligence can also lead to over-or under-sizing of the computational system, with the effect of causing the machine to make unnecessarily complex decisions or bringing it to a halt. Providing for control systems such as human supervision and rigorously testing artificial intelligence systems can reduce these risks during the design stage. The decision-making capabilities of computing systems must be measured and evaluated to confirm that any biases or questionable decisions are quickly addressed and, if necessary, corrected. Although the risks described so far are based on unintentional errors and flaws in design and implementation, a different set of threats may arise if a person or an organization intentionally tries to exploit AI systems to their advantage as if they were a weapon in a crime.

Cybercrime perpetrators can ‘trick’ AI more easily than one might think, and ‘train’ it to use it to their advantage

Deceiving an AI system can be surprisingly easy. Cybercriminals can manipulate the data sets fed to the computer (data poisoning) to “train” the AI, making even minor changes to the control parameters. All in order to lead it in the desired direction. Using another approach, if the attackers are unable to access the datasets, tampering techniques could be exploited to force computational errors by the AI or to make it difficult to correctly identify the datasets. Even though checking the accuracy of data and inputs may not be feasible, if only for financial reasons, it would be desirable for professionals to make every effort to collect data from reliable and verified sources. Among the possible defensive countermeasures against possible hacking attempts, it is worth mentioning the addition of isolation functionalities of some segments or entire AI systems with automatic prevention mechanisms.

The power of Deepfakes

Cybercriminals can also use AI to make their attack or social engineering strategies more effective and efficient. Artificial intelligence can be provided with datasets on hacking activity in order to study which technique has proved most effective. All the strategies that cybercriminals are currently implementing could be dramatically improved by using AI. The other potential field of application of AI by criminal organizations consists of identifying new flaws in the code of software, apps, or sites. In this case, AI would provide criminal hackers with a list of potential points of attack, like a well-trained bloodhound.

And we should not forget the rising shadow of Deepfakes, maybe the next frontier of social engineering attacks. We should not forget what happened in 2019 in the U.K., where the CEO of a company was the victim of a purpose-built scam with a phone call based on an audio deepfake. Believing he was talking to his boss, the victim sent nearly $250,000 to the criminal hackers’ address without batting an eyelid. The phone call scam is, without a doubt, one of the most bizarre applications of deepfake technology.

However, as we have seen, it is one that can clearly be successfully and convincingly applied. So much so that the CEO who fell victim to the cyber-attack stated that he recognized his boss’ voice by its “slight German accent” and “melodic cadence.” As if that weren’t enough, sophisticated technology aside, the process behind building the fake audio is surprisingly simple. Criminal hackers need only modify machine learning technology to clone an individual’s voice, usually using spyware and devices that allow them to collect several hours of recordings of the victim speaking.

The more data they are able to collect — and the better the quality of the recordings — the more accurate and potentially damaging the voice cloning will be in practice. Once a voice pattern has been created, the AI goes to work “learning” to imitate the target. It will then use so-called generative adversary networks (GANs): those systems that continuously compete against each other where one creates a fake and the other tries to identify its flaws. With each new attempt, the algorithm is able to exponentially improve itself.

For high-profile targets this is not good news (think CEOs of large companies); their speeches are recorded online and shared via social media, while phone calls, interviews, and everyday conversations are relatively easy to obtain. With enough data, the level of accuracy achieved by deepfake audio files is as impressive as it is frightening, and criminals are able to make the AI say whatever they want.

The future of phishing?

Certainly, today phishing attacks remain very popular — and successful — with as many as 85% of organizations finding themselves targeted. However, one of the main reasons why deepfake audio could find the fertile ground is its ability to evade most classical security measures. On the other hand, these AI-generated calls depend solely on human error and trust… and that’s what makes them potentially so dangerous. If we add to this the fact that, even the smartphones we keep on hand at all times, are not as secure as we think, it is not hard to see a multitude of ways in which cyber attackers could bypass our defenses.

There are two main obstacles, in my opinion, to the massive spread of this technology at the moment. The first is that it hasn’t yet climbed to the top of the cost-benefit ratio: a botnet sending phishing emails is capable of sending millions of emails in a short period of time. Deepfake audio requires time to study the target and processing time. In the same time frame, classic criminal hacking methods are able to yield more. The second is that, although it is true that AI-driven cybersecurity measures capable of recognizing the patterns of a deepfake are still at an experimental stage, there is already a very analog method of defeating the threat: if you are not sure, just hang up.

Most deepfake scams are carried out with the use of a VoIP account, created to contact targets on behalf of criminal hackers. By calling back, victims should be able to tell immediately whether they were talking to a real person or not.

How to benefit from AI for corporate and personal security?

But it’s not all bad news, AI can be very effective in network monitoring and analysis. Such computational systems have proven to be surprisingly efficient in detecting ‘standard’ behavior and, consequently, in identifying possible anomalies. This capability could be employed, for example, in the analysis of server access logs or data traffic. By detecting intrusions in advance, there is a greater chance of minimizing damage. Initially, it may be useful to have AI systems report any anomalies and alert corporate IT departments for further investigation. AI continues on its path of constant improvement, and it is possible that in the near future it will have the capability to neutralize threats and prevent intrusions in real-time. Given the undeniable cybersecurity shortcomings of public and private sectors, AI can take over some of these oversight tasks, allowing qualified professionals (available in limited numbers) to focus on complex problems.

With companies constantly striving to cut costs, Artificial Intelligence is becoming more and more appealing, with the prospect of a not-too-distant replacement of “physical” cybersecurity staff. This transformation will bring undeniable benefits to businesses, in terms of results and cost-efficiency. But the most ambitious and knowledgeable operators in the industry need to plan a strategy now to reduce the potential risk of cyber-attacks using AI.


About the Author

Pierguido Iezzi Pierguido Iezzi is the Cyber Security Director and co-founder of Swascan with over 30 years of experience in the world of Cyber Security. With a degree in Information Sciences, he has had the opportunity to work nationally and internationally in large corporate contexts and in the largest multinationals as a Cyber Security representative. Author of several publications, he regularly collaborates as Author and Contributor to a number of newspapers and publications. Keynote speaker and testimonial at universities, national and international events.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

What is an RDP attack?

remote desktop protocol (rdp)

Remote Desktop Protocol (RDP) attacks are becoming a nightmare for CISOs, CIOs, CTOs, and network administrators. They are an attack vector to enterprise networks. The year 2020 saw the biggest increase in RDP attacks, targeting U.S. companies. According to Cyware, RDP brute force attack attempts increased from 200,000 a day in January 2020 to 1.4 million a day by April 2020. Kaspersky Labs revealed that RDP attacks grew a massive 242% reaching 3.3 billion in 2020 compared to 2019. Blame the increase in RDP attacks on the Coronavirus and escalating cybercrime. As employees moved workstations from their offices to their homes in a short span of time, there wasn’t much time to reconfigure home networks and endpoints to establish multi-level security that’s inherent in enterprise networks. Knowing this, hackers took advantage and attacked remote endpoints to get into enterprise networks. According to Avast, ransomware attacks via RDP are increasing and often targeted at small and medium businesses.

What RDP attacks occurred in the past?

LabCorp (Laboratory Corp. of America) was hit by ransomware through an RDP attack in 2018. The ransomware infected thousands of PCs and almost 2,000 servers of this major medical testing facility. According to the Wall Street Journal report, the company was hit with a strain of ransomware known as SamSam. The hackers demanded $6,000 in bitcoin for each machine or $52,500 to unlock all encrypted devices, according to the alert from the National Health Information Sharing and Analysis Center, which coordinates health-industry responses to cyberattacks.

And earlier in the year, the Hartsfield-Jackson Atlanta International Airport, regarded as the world’s busiest by passenger traffic, was also hit by an attack involving SamSam.

In 2018, the Internet Crime Complaint Center (IC3) along with the U.S. Department of Homeland Security released an alert stating, “Remote administration tools, such as Remote Desktop Protocol (RDP), as an attack vector has been on the rise since mid-late 2016 with the rise of dark markets selling RDP Access.”

How do RDP attacks happen?

Microsoft software is used in over 90% of the world’s computers, and naturally, these have been widely targeted by hackers. We saw that with Internet Explorer, the Windows Operating systems released over the years, Windows Server software – and these days with Microsoft 365.

Microsoft introduced the Remote Desktop Protocol in 1996. Every Windows system since Windows XP uses RDP for remote connection. As employees became mobile and worked from different locations, there was a need to access corporate servers and workstations from remote locations. Two technologies emerged: VPN and RDP. But RDP is the more popular choice among users as it is built into Windows and offers more control of the host. An RDP client running on the user’s laptop or desktop (client) communicates with the RDP component on the server (host). And the communication between the two is encrypted (see illustration).

How does an RDP attack happen?

Ever since RDP was introduced, cybercriminals have been trying to hack into machines via this protocol – effectively launching a Windows RDP attack. RDP attacks continue to impact organizations worldwide to this day. Today, hackers are using RDP attacks to deploy ransomware and to lock up systems, severely crippling businesses – as in the LabCorp incident. These types of RDP attacks are becoming more common since they are lucrative.

RDP attacks occur through open RDP ports.

What is an RDP port?

A computer has hardware and software ports for communicating with other devices and services. Hardware ports are easier to understand as they are physical. Look at the sides of your laptop and you will see different hardware ports for connecting devices – USB ports, HDMI ports, the legacy VGA and Firewire (Apple);  Ethernet (network) port, display port, lightning connector (Apple), Thunderbolt (Apple), the power port, etc.

Software ports are logical channels to services on networks. For instance, websites are accessed through port 8080 (http), file transfer is port 20 or 21, and send email is port 25 (SMTP). These are defined by communication protocols that are followed by the industry – http, FTP, TCP/IP, and SMTP are protocols.

Here is an analogy. Cable TV offers hundreds of channels coming down to us on a single wire. But all these channels have separate communication paths in that wire. Those are like ports. Think of ports as communication channels.

There are thousands of services to access on networks – printing, FTP/file transfer, file sharing, remote access, etc. A port (and a unique port number) is designated for service.

You have ports for Remote Access as well, and often, these ports are unsecured and open for anyone to use. Hackers scan connected devices for open ports, and once they find these, they can access the endpoints. The endpoints are connected to the corporate network via TCP/IP and other protocols. So once the hacker gets into your connected endpoint (laptop, tablet, phone) – they can easily get into the corresponding network and deploy malware like ransomware.

Why use Remote Access?

The most common example of remote access today is your IT engineer logging into your laptop from a remote location to fix an issue. They would use remote connectivity software like AnyDesk or TeamViewer to do that. This is through RDP.

Another example is a traveling employee who may want to access some files stored on his office computer, which is thousands of miles away. The employee could use either VPN or RDP to do that.

How do you block an RDP attack?

Ports have default numbers. If you keep the RDP port to 3389 (default), then it is a security threat, since hackers know about this port. So, if you plan to open up RDP ports for Internet access, the first thing to do is change the default port number from 3389 to a number above 10000. Or, if you want to keep using port 3389, make sure the port is closed down after a remote access session.

Hackers use port scanning software to determine which ports are open on the targetted system. You can use this software to see all the open ports on your system — and close these ports. But the first thing to do is to change the default port number for RDP.

 Change the default port number

Follow these steps to change the RDP port:

  1. In Windows, go to Run –> Type: regedit to open the Registry Editor.
  2. Locate the following key:

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp\

3. In the right-hand pane, double-click on PortNumber.

4. Change the value to Decimal and specify the new port number between 1001 to 254535.

5. Click OK.

6. Close the registry editor and restart your computer.

Warning: Do not try this if you are unfamiliar with the Window Registry and registry editing. Get your system administrator to do this for you.

Check if port 3389 is open and listening

You may open port 3389 to connect to a computer remotely and may forget to close it after the session. Or another user may have done this on a shared device.

Here’s how you can check if the port is open and listening:

  1. Open PowerShell by going to Run –> powershell
  2. Run the following command: tnc 192.168.1.2 -port 3389
  3. In this command, replace the IP address 192.168.1.2 with your computer’s IP. Replace it with your router’s public IP if you have allowed public access to your computer through the router. The resulting value of TcpTestSucceeded should be True.

You can also check the port using the command prompt or CLI (command line interface), but we will not discuss this here, as it is beyond the scope of this article.

Alternately, use a port scanning or vulnerability scanning tool like CurrPorts (NirSoft) that will scan all ports and list which ones are open.

Close port 3389 (if open)

This can be done either through the command line or through a utility like CurrPorts (NirSoft).

RANSOMWARE

Exploiting RDP ports to deploy ransomware

If a hacker comprises your system via an open RDP Port 3389, to deploy malware or ransomware, they could do the following:

  • Install a process that starts encrypting all docs, pdf, jpg, and several other file formats into a secure RAR archive form. After that, they could delete the originals.
  • Install a Group Policy script that enables the Guest account, set an unknown password on it, and give it complete access to all administrative functions, including RDP.  The script can be set to run on any user’s login (all profiles), so disabling the Guest account would only hold until the next session when the admin logs in.
  • Lock the login screen for all users on the server with a ransomware scare tactic screen claiming to be from an authority like the FBI.  The ransom fee, an email address, and the mode of payment will be shown on that screen.
  • Uninstalled anti-virus and other security products.
  • Delete all backups online or on the system.
  • Disabled the F8 startup key to prevent booting into safe mode.
  • Turn off Shadow Copies on all shares – and delete the historical stored revisions of files.
  • Change other system configuration settings to make the system more vulnerable to attacks.

Well, this might shake one up, if they did not already know this! So, what are you waiting for? Close your open RDP port now!

Security policies & Best Practices

We also suggest a few more things to secure your systems:

  1. Use a secure VPN connection instead of RDP to access desktops remotely.
  2. Enforce the use of strong passwords and password change every 60 – 90 days.
  3. Set a threshold for password tries – the system should lock out the user after three failed login attempts (failed passwords).
  4. Change the default name of your Administrator account.
  5. Check your Group Policies frequently.
  6. Install all server patches and pay attention to Microsoft Patch Tuesday (Update Tuesday) announcements (and similar advisories).

Brian Pereira, CISO MAGAbout the Author

Brian Pereira is the Editor-in-Chief of CISO MAG. He has been writing on business technology concepts for the past 26 years and has achieved basic certifications in cloud computing (IBM) and cybersecurity (EC-Council).

What the Automotive Industry Needs to Learn from Nissan’s Cybersecurity Error

Nissan data breach

Flooring the accelerator of a secure vehicle is still a pipedream for many automakers. And the newest to join the bandwagon of data breaches due to frivolous errors was Nissan North America, when multiple code repositories became public, after the company left an exposed Git server protected with default credentials (Username: admin, Password: admin).

By Augustin Kurian

The trove contained 20 gigabytes of Git data, including data from:

  • Nissan NA Mobile apps
  • Nissan ASIST diagnostics tool
  • Dealer Business Systems / Dealer Portal
  • Internal core mobile library
  • Nissan/Infiniti NCAR/ICAR services
  • Client acquisition and retention tools
  • Market research tools
  • Vehicle logistics portal
  • NissanConnect

The code was discovered by a Swiss IT consultant and developer Tillie Kottmann, who also highlighted that the data was being offered on torrent links and Telegram groups.

Following the Tweets, Nissan acknowledged the exposure and said that an investigation was underway. “Nissan conducted an immediate investigation regarding improper access to proprietary company source code,” the company said. “We take this matter seriously and are confident that no personal data from consumers, dealers or employees were accessible with this security incident. The affected system has been secured, and we are confident that there is no information in the exposed source code that would put consumers or their vehicles at risk.” Nissan also stated that it took down the Git server, though certain reports indicated otherwise.

For the most part, the entire incident was an embarrassing security failure. And it is not just the fault of Nissan. Tillie Kottmann had earlier found a vulnerability with Mercedes when he could download more than 580 Git repositories containing the source code of onboard logic units (OLUs) installed in Mercedes vans. That’s not it. Earlier this year, a data breach affected 384,319 BMW customers in the U.K. The stolen database contained over 500,000 customer records dated between 2016 and 2018, affecting U.K. owners of other car manufacturers, including Honda, Mercedes, SEAT, and Hyundai in the U.K. The exposed information included surnames, email IDs, vehicle registration numbers, residential address, dealer names, car registration information, names of dealerships.

Habitual Offence for Automakers

Most of these incidents, and several others that haven’t been mentioned here, highlight the dire straits of cybersecurity among automakers. “Carmakers have sacrificed the security of scores of modern cars for the sake of convenience. And, with other methods of car theft also rife and the number of cars being stolen on the rise, manufacturers must do more to make their cars more secure,” suggests an earlier CISO MAG report.

Several manufacturers are desensitized toward cybersecurity. What several of them fail to understand is that cybersecurity is essential in the road ahead. Cyber hacks might cost the auto industry $24 billion within five years.

According to a study by Ponemon, nearly 30% of companies in the automotive segment do not have a proper cybersecurity team to handle their technology and security infrastructure, let alone secure smart cars. The state is so dire that many do not even engage a third-party vendor to secure the software in the connected cars.

“As more connected vehicles hit the roads, software vulnerabilities are becoming accessible to malicious hackers using cellular networks, Wi-Fi, and physical connections to exploit them,” data protection research group the Ponemon Institute said in the report. “Failure to address these risks might be a costly mistake, including the impact they may have on consumer confidence, personal privacy, and brand reputation.”

The study also pointed out that nearly 63% of all vehicle manufacturers do not even test half of their software, hardware, and other technology deployed in their vehicles. The study sampled 15,900 IT security practitioners and engineers in the automotive industry.

Connected Cars: An Insider Threat

In a time where cars are predicted to generate 25 gigabytes of data per hour, enterprises may need to consider connected cars as an insider threat due to their vulnerability to data theft. Cars come with connected features to pair your personal device for several purposes like hands-free driving, access to infotainment, GPS, and maps. Pairing devices like smartphones that carry sensitive data to a car’s network may pose a serious threat. The data under threat can be personal or belong to an enterprise because of COVID-19 and several employees accessing official emails on personal devices.

And often, information security heads are oblivious to the number of cloud apps in employee’s personal devices. In fact, according to a 2017 Symantec report, when most CISO/CIOs assumed employees in their organizations use up to 40 cloud apps on their devices (smartphones, tablets, laptops), in reality, the number neared 1,000. The volume of exposed data is massive. CISOs need to be more vigilant; else, they may see a shift in the ways data breaches occur. To ensure the prevention of data theft from insider threats through connected cars, organizations can do the following:

  • Train employees on safe pairing techniques of devices and cars.
  • Encourage employees to charge mobile devices through cigarette lighter and not the USB.
  • Encourage employees to implement various security measures like installing firewall, antivirus, and encryption software on employees’ devices.
  • Company-owned devices should be issued with mobile device management (MDM) software.
  • In case the device is lost, there should be a way to locate and lock the device, and if necessary, the device should be implanted with a kill switch.

Augustin Kurian

About the Author 

Augustin Kurian is part of the editorial team at CISO MAG and writes interviews and features.