Home Blog Page 129

Threat Actors Impersonate ACSC Officials to Scam Users

ProxyShell Vulnerabilities

The Australian government is warning users about an ongoing malware campaign imitating the Australian Cyber Security Centre (ACSC). The cybercriminals are claiming to be ACSC officials, calling and emailing Australians to trick them into installing malware on their personal devices. Scammers are also trying to convince the victims to install remote access software on their computer systems in order to break-in and pilfer users’ sensitive information.

“Cybercriminals are attempting to take advantage by using the ACSC name to send emails to individuals containing a malicious link requesting they download Antivirus software. If clicked on, the link downloads and installs malicious software to the individual’s computer,” ACSC said.

In addition to malicious emails, threat actors are also calling individuals from a spoofed Australian phone number asking users to download desktop access applications like “TeamViewer” or “AnyDesk” onto their devices. “The scammer then attempts to persuade recipients to take actions, such as enter a URL into a browser and access online banking services, which then compromises their computer to reveal banking information,” ACSC added.

The Australian government has asked users to reach out to 1300 292 371 (1300 CYBER 1) if they receive any suspicious email or phone calls.

With the evident surge in cyberattacks in the country, the Australian Prime Minister, Scott Morrison, recently announced that the country is spending AU$1.66 billion ($1.19 billion) over the next decade to bolster the cybersecurity defenses for enterprises. The Australian Cyber Security Centre (ACSC) has been ever since taking countermeasures and giving advisories to businesses around the country to defend themselves from cyberattacks and fortify cyberspace.

Google Rolls Out January 2021 Android Security Update

PhantomLance Targets Android App Store to Spread Malware and Spyware, message encryption for Android

Google has started rolling out security fixes with its January 2021 security updates for Android devices.  The latest security fixes will address 42 vulnerabilities in Android’s System component, 15 vulnerabilities in Framework, and over 19 vulnerabilities in Kernel, MediaTek, and Qualcomm components. Google has listed the details of all the security flaws that affect Android devices in its Android Security Bulletin and provided security patch levels of January 5, 2021, or later.

System Component Vulnerabilities

According to Google, the most severe critical security vulnerability, tracked as CVE-2021-0316, in the System component could allow a remote attacker to execute arbitrary code execution within the context of a privileged process. The other three flaws addressed in Android’s System component include two elevations of privilege issues and one information disclosure vulnerability.

“The severity assessment is based on the effect that exploiting the vulnerability would possibly have on an affected device, assuming the platform and service mitigations are turned off for development purposes or if successfully bypassed,” Google said.

Vulnerabilities in Framework

Apart from 15 severe flaws, the latest security patch level also fixed a critical denial of service (DoS) flaw, eight high-severity elevations of privilege bugs, four high-severity information disclosure issues, one high-severity DoS flaw, and one medium-severity remote code execution vulnerability in Framework components.

Vulnerabilities in Kernel, MediaTek, and Qualcomm

A total of 19 vulnerabilities in Kernel (three high-severity flaws), MediaTek (one high-severity issue), and Qualcomm components (six high-severity bugs) were fixed with the new security update.

In addition, Google also released patches to fix vulnerabilities in its Pixel devices. The Pixel Update Bulletin addressed four severe bugs, including a high-severity elevation of privilege in Framework (CVE-2020-27059), a moderate flaw (CVE-2021-0342) in Kernel components, a moderate flaw (CVE-2020-11160) in Qualcomm components, and one more flaw (CVE-2020-11161) in Qualcomm closed-source components.

Credit Card Data of 10,000 American Express Accounts Posted on Darknet Forum for Free

ICO fines American Express

As per a recent finding of Bank Security, data of 10,000 American Express credit cardholders’ accounts from Mexico has been posted by a threat actor on one of the underground forums for free. Reportedly, the same threat actor, in another post on the forum, has claimed to sell more data of Mexican banking customers of American Express, Santander, and Banamex.

What the Leaked American Express Data Contains

Based on the screenshots shared by Bank Security, the leaked data set has potentially exposed American Express account (credit card) numbers and the personally identifiable information (PII) of its customers, which includes names, phone numbers, full address (including postal code), birth dates, gender, membership reward details, etc.

credit card data sale on darknet, credit card data leak, credit card fraud, American Express, Santander, Banamex, PII exposed, Personally Identifiable Information, American Express credit cardholders,
Image Credit: Bank Security

In a statement shared with Bleeping Computers, the card company said, “American Express Card Members are not liable for any fraudulent charges on their accounts. American Express has sophisticated monitoring systems and internal safeguards in place to help detect fraudulent and suspect activity. If we see there is an unusual activity which may be fraud, we will take protective actions.”

Related News:

Hackers Sell 80K Stolen Credit Card Details on Dark Web

Since the leak contains full credit card information of American Express cardholders, it could be used in phishing and smishing (SMS phishing) attacks and tele-calling scams. Thus, as a precautionary measure, all American Express cardholders (not just limited to Mexico but worldwide) are advised to stay vigilant about any suspicious activities related to their credit card accounts. Ensure you personally monitor your account statements or register for a credit monitoring service.

Related News:

From Data Leak to Dark Web: What Happens to Your Stolen Credit Card Data?

Smart Home Devices Under Swatting Attacks; FBI Warns

FBI, FatPipe MPVPN zero-day

Internet of Things (IoT) has become an easy target for threat actors. The rise of connected devices in our daily lives and unpatched flaws in them have created a security blind spot. Cybercriminals can launch a Zero-day attack to break into internet-connected devices like webcams, smart TV, and other smart home gadgets. The FBI recently issued a warning notice to IoT devices users after cybercriminals targeted residents with Swatting Attacks by exploiting smart cameras and voice-capable smart devices. The agency urged users to use strong passwords and enable two-factor authentication for their connected devices to protect against increasing swatting attacks.

What is a Swatting Attack?

In swatting attacks, the offenders make fake calls to emergency services like law enforcement and the S.W.A.T. team and share false information about the victim’s location. Malicious actors often use Swatting as a form of revenge, harassment, or a prank, sometimes resulting in potentially deadly consequences.

“Offenders often use spoofing technology to anonymize their phone numbers to make it appear to first responders as if the emergency call is coming from the victim’s phone number. This enhances their credibility when communicating with dispatchers,” the FBI said.

To obtain access to connected devices, offenders misuse users’ stolen e-mail passwords or exploiting users who re-use the same passwords. Once compromised, malicious actors take control of the device features like live-stream camera and voice assistant.

How to Defend

The FBI urged users of smart home devices to be vigilant and advised to follow certain measures to maximize IoT device security. These include:

  • Because offenders are using stolen email passwords to access smart devices, users should practice good cyber hygiene by ensuring they have strong, complex passwords or passphrases for their online accounts, and should not duplicate the use of passwords between different online accounts. Users should update their passwords regularly.
  • Users should enable two-factor authentication for their online accounts and all devices accessible through an internet connection to reduce the chance a criminal could access their devices.
  • Users should also enable two-factor or multi-factor authentication with a mobile number, and not with a secondary e-mail account.

Mobile Phishing: A Growing, but Preventable Threat

phishing, Telegram bots and Google Forms used for phishing

Mobile phishing is on the rise. And while most of us know what phishing is, let’s quickly define it to make sure we’re on the same page. Phishing is the fraudulent attempt to obtain sensitive information or data, such as usernames, passwords, and credit card details, by disguising oneself as a trustworthy entity in an electronic communication. Mobile phishing a particularly insidious attack, because while people are primed to receive phishing attacks on their desktop and laptop computers, they generally feel safer when using a mobile device — even though attacks on mobile apps and devices are increasing rapidly. A 2020 study from cloud security company Lookout found that mobile phishing attacks grew 37% from Q4, 2019 – Q1, 2020, with much of this growth attributed to new attacks related to COVID-19.

By Alan Bavosa, Vice President of Security Products at Appdome

Phishing attacks rely on social engineering, where hackers target unsuspecting mobile users by tricking them to click on a link that takes them to a malicious site.

Hackers have two main goals when they conduct mobile phishing:

  • Data Harvesting: Using man-in-the-middle (MiTM) attacks (and other forms of network or session hijacking techniques), a malicious attacker can gain access to valuable data, such as usernames, passwords, secrets, API keys, and other valuable information. They either monetize this information or use it later in other attacks, such as to infiltrate the ‘backend’ systems or server.
  • Malware delivery: Sometimes, attackers trick unsuspecting users into downloading malware. For instance, the attacker may pretend to be your bank, your IT department, or some other trusted entity and ask you to download or update a mobile application that looks like the real app but is a fake copy of the real app with malware embedded inside. Once you download the app, the malware activates, usually at some later time so that you don’t suspect it.

Mobile apps need to be secured against phishing if they have messaging capabilities, but there’s not one quick fix to the problem. Like most cybersecurity defenses, mobile phishing protections need to be multi-layered, using measures such as URL whitelisting, MiTM attack prevention, certificate pinning, certificate validation, anti-tampering, and anti-reversing.

So, let’s take a deeper look at the mobile phishing problem and how mobile developers can protect their apps against this kind of attack.

The Mobile Phishing Problem

As noted above, when people think of phishing attacks, they typically think of a spoofed email that pretends to be from their IT department asking them to download a patch that’s a virus or a bogus request from the CEO to send a wire transfer that ends up going to criminals. However, these days phishing attacks are conducted through mobile channels, including social media apps, gaming apps, banking apps, short messaging services (SMS), and multimedia messaging services (MMS). Many games, especially those that involve large numbers of other human players, include chat capabilities that can act as a vector for phishing.

In short, if the app enables people to communicate with one another, a hacker can abuse it. And why not? It’s effective.

Hackers use many different attack methods to convince their victims to take actions that will move an attack along, often disgusting their presence. For instance, “URL padding” is an attack technique where the hacker uses a real and recognizably safe domain up front, but then adds hyphens or other characters to conceal the true, malicious domain. This means a domain like http://mobile.twitter.com—————-a23x.I-will-steal-your-money.com/login.html would show up as “mobile.twitter.com” in the small address bar of the mobile phone … possibly along with a few hyphens that the user won’t notice. Hackers also use tiny URLs from one of many services that create a smaller link that redirects to a much longer one, hiding the actual domain from the user.

Mobile phishing is often blended with a man-in-the-middle (MitM) attack to increase effectiveness. For example, a user might receive a message in their banking app purportedly from their financial institution asking them to log in via their browser and verify account details. The malicious link leads them to a site that looks exactly like their banks’ website.

Other times, the attacker delivers the fake login screen inside the mobile app, placing the fake screen on top of the real screen in what’s known as an “overlay attack.”

Certainly, developers of financial mobile apps understand the stakes — people’s finances are at risk. But even apps focused on entertainment such as games need anti-phishing protections. After all, mobile gaming revenue surpassed $75 billion in 2020, a 19.5% increase over 2019, according to Sensor Tower. And 43% of that gaming revenue comes from in-app purchases, according to a 2020 study from Wappier. That’s at least $32 billion passing through mobile gaming apps in 2020 alone. Hackers are working hard to siphon some of that money off for themselves.

Combatting Mobile Phishing Requires a Multi-Layered Defense

As explained above, mobile phishing attacks are far from simple, so they require several different techniques to defend against them.

Blacklisting, which blocks known dangerous URLs, is a common tactic, but it’s not very effective. Most of the sites to which phishing attacks link only remain active for a few days, at most, and new sites pop up daily. Attempting to identify them all is a never-ending game of whack-a-mole. When possible, URL whitelisting is a far more effective measure because it allows access to a specific list of sites and blocks all others.

A financial app, for example, might whitelist just a few select URLs to its website, and a game might do the same. In this way, no matter what link a phishing attack sends, the user will be unable to connect to it through the app.

Another method to combat phishing is securing the transport or communication channel to prevent MiTM attacks. For starters, apps should always enforce Transport Layer Security (TLS) versions and ensure that trusted, approved cipher suites are used. Cipher suites are sets of algorithms used to secure a TLS connection, and developers have hundreds of options to choose from, many of which may be outdated or insecure. Only approved, current and secure cipher suites should be allowed.

In addition, it’s important to validate the authenticity of the SSL/TLS certificates used in mobile connections. Certificates work on a chain of trust. “Higher” certificates validate the authenticity of “lower” certificates, all of which depend on a certificate issued by a trusted provider. When a server presents a certificate to an end-user, that’s called a “leaf” certificate, and while these certificates are not intended to be used as certificate authorities, they can be used to sign other certificates. This allows an attacker to insert a malicious, fake certificate into the mobile device without the user knowing. The attacker can then redirect the connection or even alter the content/payload.

To stop this kind of attack, developers should consider defenses such as certification validation, certificate pinning, and certificate role enforcement using “Basic-Constraints.”

Anti-Tampering and Code Obfuscation

Finally, it’s important to protect apps against tampering, reversing, and debugging. The more a hacker knows about your app, the better prepared they will be to launch effective attacks. It’s harder for a cybercriminal to create an app overlay without first taking the app apart to understand how it works.

Code obfuscation prevents reverse engineering techniques that rely on disassembling or decompiling an app’s code via static or dynamic analysis tools, but it needs to be implemented carefully because the app can break if the wrong process is obfuscated. Additionally, obfuscation must be updated line-by-line with every new release of the app. Finally, third-party components such as software development kits (SDKs) can’t be obfuscated unless developers have access to the source code, which is rare.

Anti-tampering and reverse engineering protection stop hackers from adding modifications to apps or even create fake versions of apps. And in the case where hackers can modify an app’s code, developers should ensure that the bogus app won’t function. Checksum verification does exactly this by analyzing the binary to generate a unique hash function. Any changes to the binary will result in a different checksum value from the one the genuine app will generate, which should cause the app to close.

Mobile App Security Implementation Challenges

Implementing all of these protections presents a daunting challenge to mobile development and security teams. Not only are some of these measures such as obfuscation extremely difficult to manually code, but the mobile security skills required are also in short supply. And even if a development team has the skills in house, manually implementing security is expensive and time-consuming, ballooning budgets and delaying release dates. Thankfully, there are ways to implement these features without having to do so manually.

Software development kits (SDKs) can be incorporated into apps to provide security, though they do require some manual coding and bring significant limitations when it comes to obfuscation. Another option is a no-code platform that can embed security capabilities into an app binary without requiring changes to source code. By obfuscating at the binary level, even SDKs and third-party libraries may be obfuscated.

Mobile phishing is a growing threat, but app developers are not helpless to defend against it. By taking a multi-faceted approach, app developers can protect their customers and end-users from being compromised.


About the author

Alan Bavosa is VP of Security Products at Appdome. A long-time security product exec, Alan has previously served as chief of product for Palerra (acquired by Oracle) and Arcsight (acquired by HP).

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.


Related news story: Large Scale Phishing Operation: 615,000+ User Credentials Stolen Using Facebook Ads

5 Reasons to Focus on Health Data Security

Only 44% of Health Care Providers Meet National Standards on Cybersecurity, OpenEMR vulnerabilities

Over the past decade, the medical care structure has been turning to total digitalization and utilizing technology to strengthen the quality and effectiveness of medical treatment and health care delivery. Patients can contact their doctors from anywhere using their gadgets. Doctors can examine their patients and check their blood pressure and heartbeat rate in real-time. Although technology made health care services very comfortable, sensitive personal health data is revealed to cyberspace and becomes very attractive to hackers. According to Cybersecurity Ventures, ransomware strikes will rise five-fold by 2021. Also, Cybersecurity Ventures professionals indicate that the health care cybersecurity field will expand by 15% a year and will grow to $125 billion by 2025. Today, cybersecurity has become a major issue and crucial strategic advantage that every structure, particularly the health care industry, must focus on critically.

By Roman Zhidkov, CTO at DDI development

What is health data?

Before we talk about health data security and the reasons why this kind of data must be safe, we should discuss what health data actually is. Health data is every type of information about a health condition, medical treatment, personal preferences of the patient, all reports about health status, and patient’s medical history. Moreover, health data includes information about the patient’s socioeconomic status, security number, policy number, and even credit card numbers. Health data covers:

  • Data generated by doctors and other medical professionals (health records, prescriptions, test results, and other details).
  • Data generated by patients (illnesses monitoring, wearable devices utilizing, media medical posts reacting, and others).

Top 5 reasons to secure health data

Hacking and cyber strikes are the main matters of concern and increasing difficulties for the health care industry. Here we are going to reveal why.

1. Health data boom

The value of the technological health market is rising at an extremely rapid speed. But not just the value only, the volume of health data that is produced and collected globally is swelling incredibly. Health data is expected to grow from 153 exabytes in 2013 to 2,314 exabytes in 2020. Now you can imagine that with poor quality and outdated health care security level, this very sensitive and personal information becomes a perfect object for cybercriminals all over the world. With these files open, hackers get a patient’s name, date of birth, account numbers, details about the family, address, property tax account, or even voting report. Criminals can create a fake identity to purchase medical equipment or drugs, prescribe medicines, or get medical services, not mentioning the possibility to blackmail public figures or ordinary people. The worst part is that health data cannot be changed when the attack was detected. You cannot block it the same way as you block your credit card. When medical data is stolen the damage is irreversible.

2. Smartphone penetration and the rise of IoT

Smartphones continue to conquer the world. In 2020 global smartphone penetration has beaten the mark of 40% and reached 41.5% with the U.S., the UK, and Germany topping the list of countries in terms of smartphone users. Together with the incredibly rapid growing popularity of smartphones, very mobile and demanding users are not satisfied with having one device only. Currently, they can utilize a smartphone, tablet, wearable device, and laptop. But the rise of the Internet of Things (IoT) means that connected devices are constantly communicating with no human involvement. By the end of 2020, the amount of IoT devices in homes will grow to 12.86 billion. About 40% of IoT devices will be utilized in business and manufacturing. The health care sector is not an exception. By the end of 2020, 40% of health care IoT devices will be used for patient’s health status monitoring, health data management, video conferencing, etc. However, security statistics claim that 84% of companies that have embraced IoT have undergone some kind of security violation. It means that IoT can provide a side door entry to any network; in terms of the health care sector, health data will be at risk.

3. Costly data breaches

When attacked, industries spend millions of dollars to recover and pick up the pieces. Canadian financial services cooperative Desjardins Group spent $53 million to heal after a massive cyber breach in 2019. British Airways and Marriott International added $100 million apiece to the final cheques after their accidents.

As reported by Ponemon Institute, data breaches cost $3.86 million per breach on average in 2020. To make things worse, health care is the sector that has the maximum data breach cost of all industries. This year it is $7.1 million on average. Health care organizations top the list of the highest data breach costs for the 10th consecutive year because costs are skyrocketing for unprepared organizations. The more costly and damaging the data breaches, the more likely businesses are to shut down. That is why the health care industry is severely impacted. In addition, there is a little chance that this unfortunate tendency will decrease in the near future. With that in mind, medical organizations should work on a security plan to detect, prevent, and respond to future data breaches.

4. Health care staff’s negligence

While the world is discussing the risk of cyberattacks, a recent study proved that more than half of the data breaches in health care happened due to the negligence of hospital staff. According to the research presented by Michigan State University and Johns Hopkins University, 53% of health care breaches happened because of insiders’ negligence. The researchers reviewed 1,150 cases that influenced more than 164 million hospital patients and found that cybercriminals are responsible for less than half of them. The rest of the data leaks would never have happened if health care employees were following the strict protocols and procedures set by their respective organizations. If there are no protocols and procedures, we suggest adopting some internal policies and procedures that will reduce negligent personal data leaks. The procedures are for keeping medical records in safe storage, implementing encryption, and to utilize reliable health care mobile apps — or to create a telemedicine platform that will keep sensitive patient data safe and help monitor employees.

5. Medical records misuse

When medical records are not secured properly to protect sensitive health data, they can be misused. Here are some cases that happened a couple of years ago. A man providing financial audit services for a health care organization found out that a girl had an abortion there. And the girl happened to be his niece. So, the man told the girl’s parents about the abortion because they were religious people. Elizabeth Dove was upset to discover that confidential information about her suspected depression was shared with the local council. Although Elizabeth never gave permission to share her medical records and she never had trouble with the police, her right to privacy and confidentiality was violated. If we speak about public figures, let’s recall an unfortunate incident that happened to Britney Spears when her medical records were revealed to the whole world. As you see, medical records misuse is a serious matter and can be as damaging as hacking.

Bottom Line

To sum up, health data security is an even more important issue to focus on than financial data security. Because pretty often it is much harder, frustrating, costly, and time-consuming to correct and restore health data. Medical records, when breached, cannot be changed or cleaned at the touch of a button – the damage is irreversible. For health care organizations, a health data breach can be financially and reputationally destructive and lead to shut down. That is why health care organizations should keep sensitive and valuable data safe and secure.


About the Author

Roman Zhidkov Roman Zhidkov is a CTO at DDI development. He is a professional with an advanced degree in Cybersecurity, and 7 years of experience in building a cybersecurity strategy for all the company’s projects. He has a deep understanding of network security, compliance, and operational security.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Over 100,000 Zyxel Devices Vulnerable to Secret Backdoor

Zyxel Devices Vulnerable to Secret Backdoor

Researchers from EYE discovered a hardcoded credential vulnerability in Zyxel’s firewalls, VPN gateways, and access point controllers that could allow attackers root access to devices through the SSH interface or the web administration panel. According to EYE’s security researcher Niels Teusink, over 100,000 Zyxel devices are potentially vulnerable to the flaw. DDoS botnet operators, state-sponsored hackers, or other cybercriminals could abuse this backdoor account to access vulnerable devices and break into internal networks.

Zyxel is a popular manufacturer of networking devices. Its Unified Security Gateway (USG) products are mostly used as a firewall or VPN gateway.

“When doing some research (rooting) on my Zyxel USG40, I was surprised to find a user account ‘zyfwp’ with a password hash in the latest firmware version (4.60 patch 0). The plaintext password was visible in one of the binaries on the system. I was even more surprised that this account seemed to work on both the SSH and web interface,” Teusink explained.

Affected Devices

The vulnerability, tracked as CVE-2020-29583 with CVSS score 7.8, affected several of Zyxel’s products that are deployed across private and government enterprise networks. These include:

  • ZyWALL (anti- virus, anti-spam, and intrusion detection services provider)
  • The Advanced Threat Protection (ATP) series (firewall protection service)
  • The Unified Security Gateway (USG) series (a hybrid firewall and VPN gateway)
  • The USG FLEX series (a hybrid firewall and VPN gateway)
  • The VPN series (VPN gateways)
  • The NXC series (a WLAN access point controller)

Patches Released!

Zyxel immediately released firmware patches to address the critical vulnerability. These include:

Firewall Patches

 

Affected product series

 

Patch available in
ATP series running firmware ZLD V4.60 ZLD V4.60 Patch1 in Dec. 2020
USG series running firmware ZLD V4.60 ZLD V4.60 Patch1 in Dec. 2020
USG FLEX series running firmware ZLD V4.60 ZLD V4.60 Patch1 in Dec. 2020
VPN series running firmware ZLD V4.60 ZLD V4.60 Patch1 in Dec. 2020

 

AP Controller Patches

NXC5500 running firmware V6.00 through V6.10 V6.10 Patch1 on Jan. 8, 2021
NXC2500 running firmware V6.00 through V6.10 V6.10 Patch1 on Jan. 8, 2021

Zyxel urged users and system administrators to immediately install the applicable updates for further protection and to avoid any security incidents in the future.

Juspay Data Breach Puts Amazon, Swiggy and Many Others in a Fix

Panasonic network breach

Juspay, a Bengaluru-based startup, is a payment partner for many Indian online platforms, including Amazon, Swiggy, and Makemytrip. It has been in business for the past eight years, and every Indian feels safe about online transactions while using Juspay. This is the brand confidence that Juspay built over the years. But a minor hiccup has now shaken this confidence a bit. Juspay has confirmed that a data breach compromised 35 million of its users’ credit and debit card details. However, the company said there was no cause for concern as the leaked data only included the masked card data.

Details of the Juspay Data Breach

Rajashekhar Rajaharia, an independent cybersecurity researcher from India, on January 03, 2021, first revealed his findings of the data breach over his Twitter handle. The compromised information of 10 crore (100 million) Indian cardholders was up for sale on the dark web. While analyzing this data dump, Rajashekhar noticed that the leaked information was from a Juspay data server and required immediate attention.

Acknowledging Rajashekhar’s findings, Juspay in a post on Medium, confirmed the data breach. However, the company was quick to correct multiple media reports stating that only 35 million records were compromised, as opposed to the claims of 100 million, which was “grossly inaccurate.” To clear the air and give more clarity on the incident, Juspay gave the following timeline of the entire episode:

  • During the early hours of Aug 18, 2020, Juspay’s engineers noticed an unauthorized activity in one of the data stores.
  • An automatic system alert was triggered due to a sudden increase in the usage of the system resources on the data store.
  • Juspay’s incident response team immediately sprang into action traced the intrusion and stopped it. The server used in the cyberattack was terminated and the entry point for this intrusion was sealed.
  • On investigating it further, the root cause of the unauthorized access that led to the Juspay data breach was found to be an unrecycled access key that was exploited.
  • A system audit was initiated on the same day to make sure the entire category of such issues was prevented.
  • Juspay then informed all its merchant partners of the cyberattack and worked with them to take various precautionary measures.
  • Over the next few days, a thorough analysis of the audit trails was undertaken to assess the impact of the cyberattack.

Impact of the Data Breach

Juspay confirmed that although 35 million credit and debit card details were leaked, it included only masked card data, meaning, six digits out of sixteen-digit card numbers were masked (hashed). Rajashekhar confirmed it but sounded skeptical saying, “what if the cybercriminals figure out the algorithm used to generate these hashes. They could then use brute force and find out what the original card numbers are.”

Apart from this, Juspay said that the only non-anonymized form of data leaked during the data breach was the plain text email ID and phone numbers. Experts expressed their concerns that this information could again possibly be used in phishing or tele calling scams and attacks. Thus, all Juspay users need to be on alert in the coming months.

Related News:

India’s E-Commerce Platform BigBasket Allegedly Suffers Massive Data Breach

Did a Cyberattack Cause Power Outage in India’s Financial Capital?

Large Scale Phishing Operation: 615,000+ User Credentials Stolen Using Facebook Ads

Adware

Researchers from security firm ThreatNix found threat actors abusing Facebook ads in a massive phishing campaign to steal users’ login credentials. They stated that cybercriminals are using Github pages to exploit Facebook ads and redirect users to phishing pages. The large-scale phishing operation targeted Facebook users in Nepal, Egypt, the Philippines, and several other countries, and may have already affected more than 615,000 users.

“Our researchers first came across the campaign through a sponsored Facebook post that was offering 3 GB mobile data from Nepal Telecom and redirecting to a phishing site hosted on GitHub pages,” ThreatNix said.

Most Affected Countries

ThreatNix investigation found user entries from more than 50 countries. The most affected countries in the phishing campaign include:

  • Nepal (27466)
  • Philippines (15506)
  • Egypt (5386)
  • Mongolia (832)
  • Norway (714)
  • Tunisia (540)
  • Iraq (321)
  • Malaysia (300)
  • Algeria (282)
  • Pakistan (1042)

The Large-scale Phishing Operation

  • Adversaries used localized Facebook posts and pages imitating legitimate entities and targeted ads for specific countries.
  • Fraudulent links in these posts redirected the users to a static Github page website that contained a fake login panel for Facebook.
  • The compromised users’ login entries were then forwarded to two endpoints – a Firestore database and a domain operated by the phishing group.

The scammers used Bitly links, which were initially presented as legitimate and modified to the phishing domain once the ad was approved. Over 500 GitHub repositories containing phishing pages linked to this phishing campaign were found in the investigation. “These repositories are created by a variety of recent accounts and some of the pages were abandoned and were no longer available on GitHub pages. The earliest these pages were created in GitHub was 5 months back but as some GitHub repositories were deleted so it is possible that similar tactics were used before that as well,” ThreatNix added.

Over 200 Mn Records of Chinese Citizens on Darknet Sale

Dark Web

Researchers from security firm Cyble stated they discovered threat actors selling more than 200 million records of Chinese Citizens on darknet forums. In a security release, the researchers stated that they found a massive amount of personal information related to the people of Gongan County (a southern Hubei province), multimedia messaging service provider Weibo, and a web portal QQ as shared by the hackers in their various ads on the dark web.

Value of the Stolen Data

Cybercriminals shared a sample data of 999 household registrations of Chinese citizens from Gongan County as proof of their act. Other findings include:

  • The exposed sample data included user IDs, names, gender, birth dates, contact details, residential addresses, and code numbers of 7.3 million citizens.
  • Attackers sold over 41.8 million records of Weibo user IDs and their mobile numbers on a Russian-speaking darknet forum.
  • Personal details of 192 million QQ users were also advertised on the dark web.

Preventive Measures

Researchers from Cyble recommended certain preventive measures to avoid data leaks. These include:

  • Never click on unverified/unidentified links
  • Never open untrusted email attachments
  • Only download media from trusted sites
  • Never use unfamiliar USBs
  • Use security software and keep it updated
  • Backup your data periodically
  • Keep passwords unique and unpredictable
  • Keep software and systems up to date
  • Train employees on Cybersecurity
  • Set up a firewall for your internet
  • Take a Cybersecurity assessment
  • Update passwords regularly

What Happens to the Stolen Data?

Cybercriminals mostly misuse the compromised data for their criminal activities such as trading it on the dark web, making fraudulent purchases online, or compromising other accounts via credential stuffing attacks. Attackers focus more on pilfering financial data like credit and debit card details, bank account numbers, and login credentials. To read the full story click here…