Home Blog Page 127

EMA Cyberattack Update: Data Compromised Last Month Appears on the Dark Web

healthcare cybersecurity, Nucleus:13

Earlier in December 2020, the European Medicines Agency had reported a cyberattack that was targeted towards the COVID-19 vaccination data, which was submitted to the EU drugs regulator for emergency approval. EMA stated, “A limited number of documents belonging to third parties were unlawfully accessed.” However, the investigation was ongoing and in the latest update, EMA has notified that a certain set of documents breached during the cyberattack have now been leaked online on the dark web forums, potentially for sale.

The Breach Victims – Pfizer and BioNTech

In the official statement given by the EMA, it did not mention the third parties whose data was breached in the cyberattack but said: “The concerned companies have been informed.” However, a day later, Pfizer and BioNTech, in a joint statement, stated that EMA did inform them about the breach and alerted them of an “unlawful access” to their regulatory submission documents stored on EMA’s server. Back then, the drug manufacturer had said that no personal data of the participants taking part in the vaccine trial was compromised in the cyberattack.

Related News:

COVID Vaccine Frontrunner AstraZeneca Targeted by Suspected North Korean Threat Actors

EMA Admits Data Leak

Ever since the cyberattack took place in December 2020, EMA has been on the lookout for any markers and has thoroughly been investigating the extent of the leak. But Italian cybersecurity firm, Yarix, has now broken the news that the data leaked during the cyberattack was put on sale on the dark web.

The cyber intelligence team at Yarix has found the following piece of information:

  • The post entitled “Astonishing fraud! Evil Pfffizer! Fake vaccines!” was first published on a well-known underground forum on December 30, 2020, at 7:30 pm. (This was subsequently removed by the forum directors).
  • In addition to the link to download the leaked documents (which no longer is available), the post refers to a thread posted in another forum, which is published in the Russian language.
  • Having been removed, the post was re-posted at 15:25 hrs and to date is available on the dark web forum with new links and search files.
  • The leaked files are contained in a zip folder called “EMA_LEAKS.zip.” The total data is worth 4MB and has two archives and a text file, which has the zip files extraction password.
  • The two archives individually contain confidential documents divided into five folders and 50 files. The material in these files has references of the staff from EMA, Pfizer-BioNTech, and the European Commission.
  • It has extracts of confidential conversations between EMA staff and members of the European Commission, relating to the vaccine production, validation, and marketing process.
  • Additionally, the cybercriminal who has leaked the information has provided several screenshots and PDF documents that refer to EMA’s Eudralink portal, which is used for internal secure communications.

Yarix, however, stated, “There are no certain elements that allow confirming that the data recovered is only a part of the leak or if it actually includes all the data stolen in the breach. On the other hand, the intention behind the leak by cybercriminals is certain: that of causing significant damage to the reputation and credibility of EMA and Pfizer.”

Based on these new findings, EMA also stated,

Some of the unlawfully accessed documents related to COVID-19 medicines and vaccines belonging to third parties have been leaked on the internet. Necessary action is being taken by the law enforcement authorities. The Agency continues to fully support the criminal investigation into the data breach and to notify any additional entities and individuals whose documents and personal data may have been subject to unauthorized access.

Rolling out the COVID-19 vaccine is the need of the hour. The drug regulator was quick to inform that the European medicines regulatory network remained fully functional and timelines related to the evaluation and approval of COVID-19 medicines and vaccines are not being affected.

Related News:

Dr. Reddy’s Lab Attacked Days After India Approves Russia’s COVID-19 Vaccine Trial

Beware! Fake COVID-19 Vaccines Circulating on Dark Web

Five Phishing Baits You Need to Know [INFOGRAPHIC]

Phishing Campaign on FINRA

Protecting sensitive information from threat actors is a concern for both individuals and organizations. Despite their continuous efforts to secure digital assets, cybercriminals are outsmarting the security perimeters to break into corporate networks. A thoughtless action of a single employee can cost the company a fortune.

Apart from sending malicious email attachments, tricking users to click on fraudulent URLs, or making them enter login credentials in a fake form, adversaries are utilizing different phishing techniques to target unwitting users.

While threat actors are using advanced techniques in their phishing campaigns, individuals or employees must know about various other phishing scams and attack procedures.


About the Author

 

Rudra Srinivas is a Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.

Deepfakes: A Growing Cybersecurity Concern

Cybercriminals Abuse AI and ML for Launching Sophisticated Cyberattacks

In tandem with developments in cybersecurity technology, cybercriminals have started getting more innovative with their attacking techniques. Threat actors are leveraging advanced technologies like Artificial Intelligence (AI) and Machine Learning (ML) to launch Deepfake attacks.

What is a Deepfake?

Deepfakes are specially crafted images, audio, and video content using AI and ML technologies to look like legitimate content. With Deepfake technology, threat actors can replace the voice/image of a particular person’s speech to manipulate information. Deepfakes confuse and spread disinformation campaigns, targeting popular personalities.

In addition to spreading disinformation, Deepfake technology is often misused for malicious purposes, including scams, election manipulation, social-engineering attacks, identity theft, and financial frauds.

Deepfake Attack – A Growing Cybersecurity Threat

According to security researchers from CyberCube, the spread of deep fake video and audio content could become a major security threat to businesses globally within the next two years. It is also anticipated that the increased dependence of organizations on video-based communication could motivate cybercriminals to focus on Deepfake attacks.

“As the availability of personal information increases online, criminals are investing in technology to exploit this trend. New and emerging social engineering techniques like deep fake video and audio will fundamentally change the cyber threat landscape and are becoming both technically feasible and economically viable for criminal organizations of all sizes,” said Darren Thomson, CyberCube’s Head of cybersecurity strategy.

“There is no silver bullet that will translate into zero losses. However, underwriters should still try to understand how a given risk stacks up to information security frameworks. Training employees to be prepared for deep fake attacks will also be important,” Darren added.

WhatsApp vs Signal vs Telegram: Which is More Viable and Secure?

WhatsApp vs Signal vs Telegram, WhatsApp alternatives

WhatsApp recently introduced an updated privacy policy, which mandates all users to share their data with its parent company Facebook. As per the ominous-sounding notification, users failing to accept the updated privacy policy will no longer be allowed to enjoy the services of the platform from February 8, 2021. In simpler words, they will be forced to uninstall the app if they fail to accept the policy changes.

Experts, including privacy pundits and governments, have raised concerns with WhatsApp’s stubbornness towards the new privacy policy.

WhatsApp vs Signal vs Telegram

It is a known fact that “one person’s loss is another person’s gain,” and this seems to be completely true in the current scenario. WhatsApp has nearly 200 million users that span across the globe. However, its latest move has forced most of them to rethink whether sharing data with Facebook is necessary. Confused and perplexed, users are seeking alternatives for WhatsApp. Given the number of options available on Android’s Google Play and Apple’s App Store, the competition is tough. But this race has two frontrunners fighting it out for the top spot: Signal and Telegram.

Let us have a look at the best possible alternatives for a secured messaging application.

The Winner: Experts Recommend Signal

Currently touted as the best WhatsApp alternative, Signal has been ordained by the experts for its polished security features. It is run by a non-profit led by Moxie Marlinspike, an American cryptographer and the current CEO of the company. The app was developed by the Signal Foundation and Signal Messenger, whose co-founder, Brian Acton, also happens to be the former WhatsApp co-founder.

 Security Features 
  • Developed by Marlinspike, Signal has end-to-end (e2e) encryption based on the Signal protocol. Thus, no third-party or even Signal’s developers can read its users’ messages.
  • It has an open-source protocol, which means there is transparency.
  • It does not support third-party backups like storing in Google Drive or iCloud storage. All data is stored locally on the device itself. Your chat history is lost if you lose and/or change your device.

Signal also supports other basic security features like screen lock, fingerprint unlock, and an incognito keyboard option that does not store your typed words in the auto-suggest.

 Our Verdict 

Signal has been recommended by privacy experts, known personalities like Elon Musk and, by well-known whistleblower Edward Snowden, mainly because of three reasons:

  1. End-to-end encryption.
  2. No third-party and cloud storage of backups.
  3. Complete user privacy. As per the privacy header of Signal in the App store, it does not collect any user data.

Telegram – An Older Yet Unique War Horse

Telegram is another app that has been around for quite some time now. Learning from WhatsApp’s mistakes, it has bettered itself over time and has slowly gained popularity providing certain features that even WhatsApp lacks. With Telegram, users can send large files up to 1.5GB, add up to 200,000 users in a single group, and so on.

 Security Features 
  • Telegram also has end-to-end (e2e) encryption, but it is available only for “Secret Chats” and all types of Calls (voice, video, and group).
  • Instead of e2e encryption, it has distributed cross-jurisdictional encrypted cloud storage, which the Telegram CEO, Pavel Durov says, “is much more protected.”
  • Chat Backups are synced only with Telegram Cloud.

Although it has a host of security features, there is a downside to Telegram. It collects users’ data, including name, phone number, contacts, and user ID. It is tagged under PII and could be a problem in case of a future breach.

 Our Verdict 

Telegram is popular among the masses mainly because of its ability to accommodate 200,000 users in a single group at a given time. Apart from that, it surprisingly provides e2e encryption for one-on-one and group video calls, which is a rarity. However, it does collect users’ PII, and thus, if you are ready for a trade-off in exchange for the additional feature that it provides, nothing like it.

Closing Notes

Amid the chaos surrounding the WhatsApp data privacy policy and data sharing with Facebook, the former has issued another notification on Twitter to clear the air.

The issuance clearly states that neither WhatsApp nor Facebook can “see your private messages or hear your calls,” but how true could this be? Would users be convinced?  Will this be a start to the end of WhatsApp? Or will the tech giant pull through this crisis and emerge yet again? All we can do is sit back and wait; maybe better answers are waiting to be found. If not, then as experts suggested, we always have something to fall back on: Signal and Telegram.

Related News:

WhatsApp Discloses Six Bugs in its First Security Advisory

WhatsApp rolls out Biometric Security Lock for Android Devices


CISO MAG Writer - Mihir Bagwe
 About the Author 
Mihir Bagwe is a Tech Writer and part of the editorial team at CISO MAG. He writes news features, technical blogs, and conducts interviews on latest cybersecurity technologies.

 

UN Data Breach Exposes Over 100,000 UN Employees’ Details

Data breach

A group of cybersecurity researchers from Sakura Samurai accessed around 100,000 personal records and login credentials of United Nations’ (UN) employees that were exposed in a data breach. Sakura Samurai is an ethical hacking and security research group appointed to report security flaws to the UN under its vulnerability disclosure program and a Hall of Fame.

During the vulnerability discovery, the research team found an open subdomain for the UN body, the International Labor Organization (ilo.org), which gave them access to Git credentials. The researchers then exfiltrated the Git credentials tool, git-dumper, to take over a legacy MySQL database and a survey management platform. Sakura Samurai group also discovered an exposed subdomain of the UN Environment Program (UNEP), which was also exposing Git credentials.

Exposed Personal Data

According to researcher John Jackson, a massive amount of Personally Identifiable Information (PII) was exposed, including:

Two documents containing more than 102,000 travel records, including employee IDs, numbers, names, employee groups, travel justification, start and end dates, length of stay, approval status, and destinations.

Two documents that contain more than 7,000 records related to HR Nationality Demographics, including employee name, ID numbers, person’s nationality, Gender, employee pay grade, organization work unit Identification number and unit text tags.

One document of Generalized Employee Records (contained more than 1,000 records)

Project and Funding Source Records (more than 4,000 records)

Evaluation Reports (contained details of 283 projects)

Data Breach Impact

The Sakura Samurai team claimed they were able to download a lot of private password-protected GitHub projects and found multiple sets of database and application credentials for the UNEP production environment. In total, they found seven additional credential-pairs, which could have resulted in unauthorized access to multiple databases.

“We decided to stop and report this vulnerability once we were able to access PII that was exposed via Database backups that were in the private projects,” Sakura Samurai said.

Bitdefender Takes Victims of DarkSide Ransomware Towards Light

Harness Your System, Free Decryptor, federal government, cybersecurity

Encryption and decryption are two sides of the same coin. And ransomware operators often use encryption to take users to the dark side; however, Bitdefender is taking users towards the light. The cybersecurity firm has released a decryption tool that allows organizations to recover files encrypted by DarkSide ransomware operators without paying any ransom. The free decryptor tool automatically scans the systems for encrypted files and decrypts them.

A Light into the DarkSide Ransomware

Active since August 2020, DarkSide is a ransomware-as-a-service (RaaS) group that made millions in ransom payouts by encrypting critical files on compromised systems. According to Digital Shadows, the group earned over one million dollars via their hacking operations. The DarkSide group also made headlines for donating $10,000 in Bitcoin to charities from their profits.

Traits of DarkSide

  • Uses a highly targeted approach to attack their victims.
  • Custom ransomware executables are carefully prepared for each target.
  • Corporate-like method of communication throughout their attacks.

How to Download the Decryptor Tool

Bitdefender made the free decryption tool available for download on its official site. To install:

Bitdefender Free Decryption Tool

“If you have checked the backup option, you will see both the encrypted and decrypted files. You can also find a log of the decryption process in the %temp%\BDRemovalTool folder. To remove the encrypted files left behind, you should search for files matching the extension and mass-remove them. We do not encourage you to do this until you made sure that your files can be opened safely and there is no damage to the decrypted files,” Bitdefender explained.

Biden to Appoint Cybersecurity Veteran Anne Neuberger to NSC

Anne Neuberger

If diversity were a feather, Joe Biden’s pick for staffers would look like a bird. The incoming President of the U.S. has plans of appointing Anne Neuberger to the newly formed National Security Council (NSC). According to reports from Politico, Neuberger will be departing from her role as the director of cybersecurity of NSA and will take on a senior position at the NSC. Neuberger is a decedent from a Jewish Orthodox community-based in Baltimore.

Prior to her role as the director of cybersecurity at the NSA, she led NSA’s Election Security effort and served as Assistant Deputy Director of NSA’s Operations Directorate, where she led NSA’s foreign intelligence and cybersecurity operations.

Her previous roles also include NSA’s first Chief Risk Officer; Director of NSA’s Commercial Solutions Center; the Navy’s Deputy Chief Management Officer; and a White House Fellow, working for Secretary of Defense Robert Gates. Prior to joining government service, Anne was Senior Vice President of Operations at American Stock Transfer & Trust Company (AST), where she was responsible for directing operations, including dividend distributions, complex mergers, and acquisition processing for approximately 2,000 publicly traded companies. In 2017, Anne was awarded a Presidential Rank Award for her service at the National Security Agency.

The appointment also highlights the President-elect’s posture on cybersecurity. Earlier, the outgoing president Donald J. Trump had eliminated the role of cybersecurity coordinator in 2018. With this new appointment, it can be safely said that cybersecurity might be re-elevated as a national security priority in the coming years.

“The National Security Council plays a critical role in keeping our nation safe and secure. These crisis-tested, deeply experienced public servants will work tirelessly to protect the American people and restore America’s leadership in the world. They will ensure that the needs of working Americans are front and center in our national security policymaking, and our country will be better for it,” said President-elect Joe Biden.

Recently, Biden and Vice President-elect Kamala Harris had announced a slew of cybersecurity appointments for the NSC. These included:

  • Yohannes Abraham, Chief of Staff and Executive Secretary
  • Sasha Baker, Senior Director for Strategic Planning
  • Ariana Berengaut, Senior Advisor to the National Security Advisor
  • Tanya Bradsher, Senior Director for Partnerships and Global Engagement
  • Rebecca Brocato, Senior Director for Legislative Affairs
  • Elizabeth Cameron, Senior Director for Global Health Security and Biodefense
  • Tarun Chhabra, Senior Director for Technology and National Security
  • Caitlin Durkovich, Senior Director for Resilience and Response
  • Jon Finer, Principal Deputy National Security Advisor
  • Juan Gonzalez, Senior Director for Western Hemisphere
  • Sumona Guha, Senior Director for South Asia
  • Ryan Harper, Deputy Chief of Staff and Deputy Executive Secretary
  • Peter Harrell, Senior Director for International Economics and Competitiveness
  • Emily Horne, Senior Director for Press and NSC Spokesperson
  • Shanthi Kalathil, Coordinator for Democracy and Human Rights
  • Andrea Kendall-Taylor, Senior Director for Russia and Central Asia
  • Ella Lipin, Senior Advisor to the Principal Deputy National Security Advisor
  • Brett H. McGurk, Coordinator for the Middle East and North Africa
  • Melanie Nakagawa, Senior Director for Climate and Energy
  • Carlyn Reichel, Senior Director for Speechwriting and Strategic Initiatives
  • Amanda Sloat, Senior Director for Europe

“This outstanding team of dedicated public servants will be ready to hit the ground running on day one to address the transnational challenges facing the American people — from climate to cyber. They reflect the very best of our nation, and they have the knowledge and experience to help build our nation back better for all Americans,” said Kamala Harris.

Even during his election campaign, as the presumptive Democratic nominee for President, Biden had hired former White House cybersecurity official Chris DeRusha as the CISO for his campaign and Jacky Chang as Chief Technology Officer.

New Zealand’s Reserve Bank Data System Hacked; Critical Data at Risk

New Zealand Reserve Bank hacked

New Zealand’s top bank, the Reserve Bank, has acknowledged that a malicious actor has reportedly hacked and accessed one of its data systems, which stored sensitive information. The cybercriminal behind this breach is not yet disclosed, but the Governor informed that the investigation is underway.

New Zealand – An Emerging Threat Landscape

In a country that is known for its scenic landscape and friendlier citizens, cybercriminals are now attempting to change it into a cyberthreat landscape. It all began with a DDoS attack on the New Zealand Stock Exchange on August 25, 2020, which forced the NZX to halt operations for three consecutive days. To counter the growing menace of the looming cyberthreats, CERT-NZ proposed several steps to build cyber resilience. However, it was not enough as the attacks on the financial and banking sector have only been growing larger and more complex by the day.

In a statement issued by the Reserve Bank of New Zealand, an illegal data breach through a third-party file sharing service potentially led to the access of critical banking information. However, quick response to the incident meant that the breach was contained and taken offline almost immediately.

New Zealand’s Governor, Adrian Orr, stated that the breach incident is given the highest priority and has asked the domestic and international authorities to work on this urgently. He said, “We are working closely with domestic and international cybersecurity experts and other relevant authorities as part of our investigation and response to this malicious attack. The nature and extent of information that has been potentially accessed are still being determined, but it may include some commercially and personally sensitive information.”

Orr assured, “The system has been secured and taken offline until we have completed our initial investigations. It will take time to understand the full implications of this breach, and we are working with system users whose information may have been accessed. Our core functions remain sound and operational.”

New Zealand’s Other Cybersecurity Measures

New Zealand is taking its cybersecurity and data privacy issues very seriously with its two recent offerings – OPC’s “NotifyUs” tool and the New Privacy Act 2020 (NZ).

Related News:

Notify Data Breaches Using New Zealand OPC’s NotifyUs

Everything You Need to Know About NZ’s New Privacy Act 2020

New Year Brings New Ransomware Strain “Babuk Locker”

ransomware, fonix, fonix ransomware, Cybereason Partners with Intel for Hardware-Enabled Ransomware Prevention, Kronos

While the world is reeling from the aftereffects of the pandemic, cyberspace is getting infected with the first ransomware strain of 2021. Dubbed as Babuk Locker, the new ransomware appears to have allegedly compromised the corporate networks of some companies globally. According to security researcher Chuong Dong, Babuk Locker ransomware is encrypting victims’ sensitive information and demanding a ransom of $60,000 to $85,000 in Bitcoins.

Babuk Locker Traits

Chuong Dong claimed that Babuk Locker uses new techniques like multi-threading encryption and abuses the Windows Restart Manager. The ransomware implements SHA256 hashing, ChaCha8 encryption, and Elliptic-curve Diffie–Hellman (ECDH) key generation for encrypting scheme. It also can spread its encryption via available networks and uses an exchange algorithm to safeguard its keys and encrypt files from detection.

“Similar to Conti or REvil ransomware, Babuk utilizes the Windows Restart Manager to terminate any process that is using files. This ensures that nothing prevents it from opening and encrypting the files. This is accomplished through the calls RmStartSession, RmRegisterResources, and RmGetList to get a list of processes that are using a specified file. If the process is not explorer.exe or a critical process, then Babuk will call TerminateProcess to kill it,” Dong said.

How Babuk Locker Encryption Works?

For encryption, Babuk Locker ransomware uses two ChaCha8 keys generated from the ECDH shared secret’s SHA256 hash and the first 12 bytes of the shared secret as encryption keys.

Babuk’s file encryption is of two different types — Small File Encryption and Large File Encryption. Small files (around 41 MB) are mapped entirely and encrypted with ChaCha8 two times. Whereas, the encryption process is different in large files. They are divided into three equally large regions, and for each of these regions, only the first 10 MB is encrypted.

Ransom Note 

Image Courtesy: chuongdong.com

Other Findings

  • Despite the amateur coding practices used, Babuk’s strong encryption scheme utilizes the Elliptic-curve Diffie–Hellman algorithm, which has proven effective in attacking a lot of companies so far.
  • Because the malware authors are using one private key for each Babuk sample, it’s clear that their main target is large corporations instead of normal computer users.
  • As per the website embedded in the ransom note and the leaks on Raidforums, they have successfully compromised five different companies in the world.

Indicators of Compromise

MD5: e10713a4a5f635767dcd54d609bed977

SHA256: 8203c2f00ecd3ae960cb3247a7d7bfb35e55c38939607c85dbdb5c92f0495fa9

Babuk ransomware comes in the form of a 32-bit .exe file.

Ryuk Ransomware Gang Made More Than $150 Mn in Ransom

BlackMatter Group, Volvo Cars ransomware attack

Ransomware attacks were the most observed security incidents in 2020. Multiple attacks and new ransomware variants were reported. Recently, a series of Ryuk ransomware attacks targeted multiple hospitals in the U.S. Cybercriminals compromised critical network systems across six hospitals in a single day. Joint research from threat intelligence company Advanced Intelligence (AdvIntel) and security firm HYAS claimed that the Ryuk ransomware operators earned more than $150 million worth of Bitcoins from ransom payments after their cyber intrusions globally. Research found that the payments to 61 Bitcoin addresses were attributed and linked to Ryuk ransomware attacks.

The companies stated that ransomware operators transferred their ransom payments to money laundering services, distributed in hacking forums, or cashed out in cryptocurrency exchanges.

“Ryuk receives a significant amount of their ransom payments from a well-known broker that makes payments on behalf of the ransomware victims. These payments sometimes amount to millions of dollars and typically run in the hundreds of thousands range,” AdvIntel and HYAS said in a statement.

Ryuk’s Bitcoin Circuit

AdvIntel and HYAS claimed that Ryuk operators converted their Bitcoins into currency by using fake accounts on two cryptocurrency portals – Binance and Huobi. One of the largest transactions involving a Ryuk wallet found during this investigation was above $5 million (365 Bitcoins).

“In addition to Huobi and Binance, which are large and well-established exchanges, there are significant flows of crypto currency to a collection of addresses that are too small to be an established exchange and probably represent a crime service that exchanges the cryptocurrency for local currency or another digital currency,” AdvIntel and HYAS added.

Ryuk ransomware has been active for two years targeting various organizations globally, focused mostly on the health care sector. The ransomware operators succeeded in economic terms and made their disruptive impact on many industries.