Home Blog Page 128

2021 Security Predictions: Endpoint Security is of Utmost Importance

2021 Security Predictions

2020 has been an unforgettable year – from a virus upending the world to a sudden shift to remote workforce, we have seen it all. However, our reliance on technology will be more than ever.

The following predictions offer insights into how cybersecurity will evolve in 2021:

By Jason Lee, CISO, Zoom

1. Data protection for the hybrid workforce will become increasingly complex.

  • Many companies have embraced a fully remote workforce during this challenging time. Next year, many of these same companies will need to adapt to a hybrid workforce with some employees re-entering the office, and others staying remote.
  • Security leaders will need to reevaluate their network security posture, maintain an effective data protection strategy on endpoints, and consider mobile device management (MDM). Corporate network congestion could also become a big issue for companies that have a lot of employees heading back to the office in addition to a large remote workforce.
  • Companies with many remote employees will also need to support more endpoints than ever before. Protection of the data on these endpoints will be critical. Programs like BYOD will offer those employees secure access to the tools they need to stay productive.

2. Companies will move toward personal device authentication.

As we continue to practice social distancing in 2021, companies will move away from shared/communal computers, and shift toward supporting employees on their personal devices. Security teams will also need to deploy consistent authentication practices that support both in-office employees and those staying remote. Multi-factor authentication for corporate-owned and/or BYOD-supported mobile phones will be the most popular solution. Additionally, we will see a move toward passwordless access and leveraging other factors.

3. The war for cybersecurity talent will continue to heat up.

  • This past year, many companies began hiring cybersecurity professionals remotely–no matter where they live. In 2021, cybersecurity pros will continue to be able to work from wherever they want. In particular, Zoom will continue hiring employees in the office and remotely for its cybersecurity team.
  • One of the most effective ways to increase an organization’s security capabilities is to arm its development teams with rich training. Zoo m will be significantly investing in security training for its developers. The company supports continuous learning via secure code training, “capture the flag” competitions, and other gamification techniques to train its development organization on security.

4. The Zero Trust security model will be a primary focus in 2021.

With the Zero Trust model, employees must be authenticated and validated before given access to appropriate applications and the right level of data. As companies look to support a hybrid workforce, this approach will become even more attractive for security leaders, as it provides continuous checks as to whether employees need access at that time to sensitive data. Companies will also double down on endpoint controls to ensure their rapidly growing remote workforce stays secure.


About Jason Lee

Jason Lee is the Chief Information Security Officer at Zoom with 20 years of experience in technology, with a specialization in information security and operating mission-critical services. He was recently the Senior Vice President of Security Operations at Salesforce where he was accountable for the global organization delivering critical end-to-end security operations to customers and employees including company-wide network and system security, incident response, threat intel, data protection, vulnerability management, intrusion detection, identity and access management, and the offensive security team. Before Salesforce, he held the position of Principal Director of Security Engineering for the Windows and Devices division in Microsoft.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Episode #7: CISO Culture is All About Focusing on the Negatives

Adam Palmer Tenable

In an industry focused on catching and reporting the bad guys, the good elements of a solid cybersecurity program can easily go unnoticed. CISO culture focuses so much on finding threats and identifying risks that they forget to learn from what is working successfully or how to use positive data to encourage business units that are doing well.  At the same time, finding good data can demonstrate the value and results of their program, but they may struggle to show substantive evidence. Reporting success is equally as important as reporting risk. So, how can CISOs effectively communicate the good initiatives/results to the board?

In this newest podcast episode from CISO MAG, we have Adam Palmer, Chief Cybersecurity Strategist, Tenable, who explains in-depth both the metrics for evaluating cybersecurity and how the CISO culture is based on the concept of cybersecurity Tetris.

Palmer has over 20 years of experience in cybersecurity, which includes executive positions at large cybersecurity vendors, leading the U.N. Global Program against Cybercrime, and working as the Global Director for IT & Cyber Risk at one of the largest EU banks.  His diverse global background perfectly positions him to understand and advise security leaders to be successful.

As Tenable’s Chief Cybersecurity Strategist, Palmer focuses on advising senior leaders (CISO/CIO/CTO) on cybersecurity strategy. Before joining Tenable, he was the Global Director, Cybersecurity Risk & Controls for Banco Santander – the largest bank in the EU and Latin America.  This role provided him with deep global experience with comprehension for a large, advanced cybersecurity program.

Palmer began his career as a U.S. military officer focused on cybercrime cases.  After the military, he worked in a senior operational role by creating the .ORG top-level Internet domain cybersecurity program.  This program has been cited by leading industry groups as a major success for reducing cyber risk.  Palmer later created and led the United Nations Global Program Against Cybercrime, delivering anti-cybercrime capacity building programs to global governments.

Palmer also has significant experience as an advisor working at leading cybersecurity vendors.  In these roles, he advised both large and medium-size organizations on cybersecurity best practices.  He has published numerous articles and is regularly invited to speak about cybersecurity.

Palmer (JD, MBA, CISSP, CIPP) is originally from the U.S.  He has worked across the U.S., Asia-Pacific, Europe, and the Middle East., and is currently based in Dublin, Ireland.

Listen to our previous podcast episodes here.


Augustin Kurian

About the Host 

Augustin Kurian is part of the editorial team at CISO MAG and writes interviews and features.

 

Trump Sex Scandal is Just RAT Menace

trump backs away from working with russia on cybersecurity

The outgoing President of the United States, Donald J. Trump, has been extensively grabbing headlines for his and his supporters’ actions. With his name being one of the most trending keywords globally, cybercriminals are trying to make the best of the situation with fake threads indicating a sex tape of the departing POTUS. The Java Archive (JAR) file called “TRUMP_SEX_SCANDAL_VIDEO.jar” is a new remote-access trojan (RAT) variant that aims to lure unsuspecting users to deliver a malware package.

Researchers at Trustwave were the first to stumble upon this new thread while reviewing their spam traps. The most peculiar thing about the campaign was that, on the surface, it appeared like a typical investment scam with the subject “GOOD LOAN OFFER” but had an attachment called TRUMP_SEX_SCANDAL_VIDEO.jar— unrelated to the email theme.

Trump Sex Scandal

The RAT file is of an unusual kind. Named as “QNODE DOWNLOADER,” this a variant of earlier seen Node.Js QRAT downloaders. Once a user clicks on the attachment, a copy is created and then executed from the %temp% folder while the user is greeted with a pop-up message that reads, “remote access software and is mainly used for penetration testing”. As soon as a user clicks “Ok, I know what I am doing,” the malicious activities begin.

“Third, the string “qnodejs” which previously identified the files associated with this threat, is not in this variant,” the researchers noted. “The Node.Js installation folder is still at %userprofile%, however, the folder is not prepended with “qnodejs-“ anymore. Fourth, when downloading next stage malware, only the argument “–hub-domain” is required when communicating to the command-and-control servers (C&Cs). After setting up the Node.Js platform, a Node.Js process is created to download the next malware in the infection chain. The argument “–hub-domain” along with the C&Cs is the only data supplied to the process. The information about the QHub service subscription user we observed in the earlier variant is no longer contained in the JAR file.”

Trump Sex Scandal RAT

And in the end, JAR file downloads a file named “boot.js” and saves it at: %temp%\_qhub_node_{random}.

In comparison to the previous variant, the new one is significantly enhanced to infect the system with a QNode RAT. Several characteristics and behavior were also improved. These include downloader being split-up into different buffers inside the JAR to evade detection, names of the other files it created and downloaded being changed put into different locations, and not inside the Node.Js installation folder, among several other new features.

What is QRAT?

A Qua or Quaverse Remote Access Trojan (QRAT) is a Java-based RAT, which first made its appearance in 2015. The Trojan can be used to gain complete take over of a compromised device. It was initially advertised as a SaaS Java RAT.

Data Breach Exposes PII of Aurora Cannabis’ Present and Former Employees

Medical Cannabis Users Suffer Data Breach

Aurora Cannabis, a popular medical cannabis producer in Canada, suffered a data breach that exposed its customers’ and employees’ personal information totaling 50GB of data. The stolen data includes medical diagnoses, credit card information, government IDs, residential addresses, banking details, images of passports, cheques, driver licenses, and business documents.

Aurora Cannabis operates a range of cannabis-related medical and consumer brands like Whistler Medical Marijuana Corp., MedRelease, CanniMed, San Rafael, Daily Special, and Woodstock.

According to a report from Marijuana Business Daily, both former and current employees have received data breach notifications from Aurora Cannabis after the enterprise discovered the cyberattack on December 25, 2020.

Stolen Data Traded for One Bitcoin

Marijuana Business Daily claimed that the threat actors responsible for the Aurora Cannabis data breach are selling the stolen data on darknet forums for one bitcoin. They also advertised their posts to promote sales by leaking images of the stolen information.

Aurora’s spokeswoman Michelle Lefler clarified that Aurora’s patient systems and operations were unaffected in the incident. She also confirmed that the company “was subject to a cybersecurity incident on Christmas day that affected both current and former employees. The company immediately took steps to mitigate the incident, is actively consulting with security experts and cooperating with authorities.”

“I can confirm we are following all security protocols, are working with privacy councils and law enforcement and have communicated directly with any impacted current or former employee,” Lefler added.

Canada’s Cannabis Connection

Multiple security incidents have been reported earlier on Canadian medical cannabis providers. Natural Health Services, the operator of Canada’s largest referral network of medical cannabis patients, suffered a data breach that exposed customers’ personal information like medical diagnoses, referrals, encounter notes, and allergies. The Calgary-based health center stated that unknown intruders allegedly accessed personal health records between December 4, 2018, and January 7, 2019.

Mumbai Cyber Cell Busts Phishing Racket; Six Scammers Arrested

Facebook Indicts Two Developers for Scraping Users’ Data, Europol

Mumbai Cyber Cell has arrested six scammers from Bhopal and its neighboring state West Bengal, who were running a cartel of duping individuals through 123 phishing websites impersonating popular e-commerce brands. The fraud amounted to nearly ₹10Cr (approximately $13,64,825) and victimized 10,000 people.

The Modus Operandi

According to the cyber cell, the gang created spam ads, advertised them on popular social media platforms and gave lucrative deals that would be hard to resist. They even promoted these advertisements on WhatsApp and sent malicious links to those interested in it. The scammers further created identical fake/phishing websites of popular e-commerce brands and leveraged them into gaining users’ trust and personal information. The scam set up was pre-planned. Scammers operated from a small call center that was set up in Patna, India. The list of fake websites includes petrol pumps/ LPG dealership agencies, private loan providers, Reliance towers, Snapdeal, and Naaptol, among others.

Explaining the operations of scammers, and the fake websites they set up, an official said, “For example, it is a website about getting an LPG dealership, it will seek all the general information such as identity proof and all the documents for registration purposes. It will then ask to deposit a certain amount following some more steps, which is done even on an authentic website. People usually fill-up all the details and deposit the money, and then get to know of the scam, only later.”

The Bust

The incident was first brought to light on December 15, 2020, after a customer was duped for an amount of ₹3.6 lakhs. After following the trail carefully, the Mumbai cyber cell traced the scammers back to Bhopal and West Bengal. They immediately sent a team to get hold of the scammers. Six individuals, including a woman, were arrested and questioned. As per the latest reports, the gang had been operational since July 2018, and the arrested members have accepted their wrongful doings.

A few more members are involved and absconding. The officials noted that the investigation is on-going, and the search parties are looking out for the missing members.

Related News:

Operation Falcon: INTERPOL Nabs Three Nigerian BEC Scammers

After Juspay, ClickIndia, ChqBook and WedMeGood Allegedly Suffer Data Breaches

Patchwork BADNEWS, APT31 threat group

Threat actors behind the recent Juspay data breach, which compromised 35 million of its users’ credit and debit card details, are now selling databases of three more India-based enterprises – ClickIndia, ChqBook, and WedMeGood on Darknet forums. ClickIndia is an E-marketplace, ChqBook is a fintech startup, and WedMeGood is a wedding planning platform. All three companies have a significant customer base and hold a lot of sensitive information.

According to cybersecurity researcher Rajshekhar Rajaharia, threat actors that go by the name “ShinyHunters” are selling data dumps that contain 8 million records of ClickIndia (name, email, mobile and other personal details), 1 million records of ChqBook (name, email, mobile, full address, and other personal details), and 1.3 million from WedMeGood (name, email, hashed password, other sensitive personal information). Rajaharia has opined that there might be some connection between all these data breaches.

As per reports, ShinyHunters was also behind the BigBasket data breach, previously reported by the security firm Cyble in November 2020. BigBasket, an India-based grocery e-commerce platform, suffered a data breach incident that exposed personal details of over two crore customers. The stolen database was available for sale on a dark web market. Hackers sold the database for over $40,000 with the table name “member_member.” The size of the database (SQL file) was around 15 GB and contained over 20 million customers’ personal data.

North Korean APT37 Uses RokRAT Trojan to Target South Korea

Cryptocurrency Lazarus, North Korean TA406, Lazarus Group , Korea Atomic Energy Research Institute

Security researchers from Malwarebytes found that state-sponsored North Korean threat actor group APT37 is using RokRAT Trojan in a new wave of cyber operations targeted against the South Korean government. APT37, also known as ScarCruft, Reaper, and Group123, has been active since at least 2012.

“On December 7, 2020, we identified a malicious document uploaded to Virus Total, which was purporting to be a meeting request likely used to target the government of South Korea. The meeting date mentioned in the document was January 23, 2020, which aligns with the document compilation time of January 27, 2020, indicating that this attack took place almost a year ago,” Malwarebytes said.

The RokRAT Trojan

According to the researchers, the malicious document (meeting invite) contains an embedded macro that uses a VBA self-decoding procedure to decode itself within the memory spaces of Microsoft Office and then embeds a variant of the RokRat into Notepad. Earlier, APT37 exploited Hangul Office documents (hwp files) to target victims in South Korea because it is the most used software in South Korea. However, this time, the attackers used an alternative method by delivering the malware via self-decoding VBA Office files.

“We can consider this technique an unpacker stub, which is executed upon opening the document. This unpacker stub unpacks the malicious macro and writes it into the memory of Microsoft Office without being written to disk. This can easily bypass several security mechanisms. Microsoft by default disables the dynamic execution of the macro, and if an attacker needs to execute one dynamically — which is the case here — the threat actor needs to bypass the VB object model (VBOM) by modifying its registry value,” Malwarebytes added.

RokRAT’s Key Traits

  • Capture Screenshots
  • Gathers system info (Username, Computer name, BIOS)
  • Data exfiltration to cloud services
  • Stealing credentials
  • File and directory management

Once successfully injected, the RokRAT Trojan harvests sensitive data from the victim’s machine and sends it to threat actors via cloud services like Pcloud, Dropbox, Box, and Yandex.

Indicators of Compromise

Maldoc:

3c59ad7c4426e8396369f084c35a2bd3f0caa3ba1d1a91794153507210a77c90

RokRAT:

676AE680967410E0F245DF0B6163005D8799C84E2F8F87BAD6B5E30295554E08

A42844FC9CB7F80CA49726B3589700FA47BDACF787202D0461C753E7C73CFD2A

2A253C2AA1DB3F809C86F410E4BD21F680B7235D951567F24D614D8E4D041576

C7CCD2AEE0BDDAF0E6C8F68EDBA14064E4A9948981231491A87A277E0047C0CB

U.S. Federal Agencies Jointly Form Cyber Unified Coordination Group

Russian hackers, Senate Homeland Security Report, Electronic Warfare Associates

The U.S. intelligence agencies including the National Security Council (NSC), the FBI, the Cybersecurity & Infrastructure Security Agency (CISA), and the Director of National Intelligence (ODNI) have jointly established the Cyber Unified Coordination Group (UCG) to coordinate the investigation and remediation of recent cyber incidents involving federal government networks.

The UCG stated that over 18,000 public and private sector customers of SolarWinds’ Orion product and around 10 U.S. government agencies were affected in the recent string of cyberattacks. The agency said it is still working to identify and notify the non-government entities who also may be impacted.

“This work indicates that an Advanced Persistent Threat (APT) actor, likely Russian in origin, is responsible for most or all of the recently discovered, ongoing cyber compromises of both government and non-governmental networks. At this time, we believe this was, and continues to be, an intelligence-gathering effort. We are taking all necessary steps to understand the full scope of this campaign and respond accordingly,” the agencies said in a statement.

All the federal agencies are supporting the UCG by providing their intelligence, cybersecurity expertise, mitigation measures, and guidance on evaluating the scale of the recent SolarWinds cyberattacks.

  • As the lead agency for threat response, the FBI is focused on four critical lines of effort – identifying victims, collecting evidence, analyzing the evidence to determine further attribution, and sharing results with the government and private sectors.
  • As the lead for asset response, CISA is focused on sharing information immediately with the government and private sector partners as we work to understand the extent of this campaign and the level of exploitation. CISA has also created a free tool for detecting unusual and potentially malicious activity related to this incident.
  • As the lead for intelligence support and related activities, ODNI is coordinating the Intelligence Community to ensure the UCG has the most up-to-date intelligence to drive the U.S. Government mitigation and response activities.
  • The NSA is supporting the UCG by providing intelligence, cybersecurity expertise, and actionable guidance to the UCG partners, as well as National Security Systems, Department of Defense, and Defense Industrial Base system owners.

“The UCG remains focused on ensuring that victims are identified and able to remediate their systems, and that evidence is preserved and collected. Additional information, including indicators of compromise, will be made public as they become available,” the agencies added.

Related Stories:

Google reCAPTCHA Can be Bypassed Using Bots

recaptcha

Google has always been at the forefront when it comes to authentication and security. And thus, with a view for the future of authentication, Google acquired reCAPTCHA in 2009. Like any other product, it had its shortcomings. But little did Google know that a vulnerability, which plagued reCAPTCHA two years ago, will resurface, showing how Google reCAPTCHA authentication can be bypassed successfully by bots.

reCAPTCHA is not Perfect

CAPTCHA enables websites to distinguish between a bot and a human, making it the first line of defense against bot attacks. However, since its implementation just over six years ago, a vulnerability was discovered in its then version reCAPTCHA v2. This exploit termed as unCAPTCHA achieved 85% accuracy in bypassing reCAPTCHA’s speech authentication technique, which was put in place for the visually impaired. This was soon rectified, and a newer version named reCAPTCHA v3 was released in October 2018.

Now, after two years of running trouble-free, another researcher, Nikolai Tschacher, has presented a proof-of-concept that the vulnerability still exists and the audio file of reCAPTCHA can be submitted to Google’s speech-to-text API by a bot for bypassing the authentication. Surprisingly, the security researcher claimed that the accuracy — which was at 85% in 2017 when the vulnerability was first discovered — has now gone up to more than 90%.

How the Google reCAPTCHA Bypass Works

The idea of the attack is simple. You grab the mp3 file of the audio reCAPTCHA and you submit it to Google’s own Speech to Text API, and voila you have the bypass.

– Nikolai Tschacher

To demonstrate the Google reCAPTCHA bypass, the bot must follow these simple steps:

  1. Navigate to the website having Google’s ReCAPTCHA.
  2. Navigate to the audio challenge of ReCAPTCHA.
  3. Hit the download link for the audio challenge.
  4. Submit the downloaded audio challenge to Google’s Speech-To-Text converter.
  5. Parse the response and type the answer in the field.
  6. And Press “Submit” to check if it was successful.

The only problem here is locating the exact mouse pointer to coordinate on the screen so that it could be fed to the bot’s code for performing the clicking action perfectly. However, a demo from the unCAPTCHA2 suggests it could be easily discovered using the shell command “xdotool getmouselocation –shell.” Once the bot locates the mouse pointer’s coordinates it is just a matter of few clicks before the bypass works.

This is a newer version of the older vulnerability and, thus, experts are hoping that Google patches it sooner before it is exploited in the wild.

Related News:

Official reCAPTCHA Walls Protect Phishing Campaigns

Threat Actors Targeting Crypto Wallets with ElectroRAT Malware Campaign

ONUS Log4j, Cryptocurrency Wallet Security

Security researchers from Intezer discovered a wide-ranging marketing campaign targeting cryptocurrency holders to pilfer their private keys and compromise their crypto wallets. Threat actors used maliciously crafted cryptocurrency-related apps, domain registrations, Trojanized applications, fake social media accounts, and a new Remote Access Tool (RAT) dubbed ElectroRAT. While the researchers discovered the ElectroRAT operation in December 2020, it is suspected that the operation may have been initiated in January 2020. 

What’s ElectroRAT? 

ElectroRAT is a new kind of malware with cross-platform functionality written in Golang (an open-source programming language) and designed to target multiple operating systems, including macOS, Linux, and Windows. “It is rather common to see various information stealers trying to collect private keys to access victims’ wallets. However, it is rare to see tools written from scratch and used to target multiple operating systems for these purposes,” Intezer’s researchers said.

How ElectroRAT Works?

ElectroRAT operators have created three different Trojanized applications, Jamm, eTrade, and DaoPoke, and hosted them on websites built especially for this campaign. The malicious applications were advertised in cryptocurrency and blockchain-related platforms like Bitcointalk and SteemCoinPan. The  ElectroRAT threat actor group tricked cryptocurrency traders to download their malicious apps by promoting them in fake online forums and social media platforms. It is estimated that ElectroRAT has infected thousands of victims so far.

“The promotional posts, published by fake users, tempted readers to browse the applications’ web pages, where they could download the application without knowing they were actually installing malware,” Intezer’s researchers added.

ElectroRAT Defense Mechanism

Intezer recommended certain preventive measures for users who suspect they are the victim of ElectroRAT malware operation. These include:

  • Kill the process and delete all files related to the malware.
  • Make sure your machine is clean and running 100% trusted code.
  • Move your funds to a new wallet.
  • Change all your passwords.

Related Stories: