Home Blog Page 131

2021 Cybersecurity Predictions: From the Rise of Ransomware to Remote Working, it is Time to Shore Up Tour Defenses

cyber-tech trends (1)

As we say goodbye to 2020, here are some 2021 cybersecurity predictions on ransomware, synthetic media, hacking for hire, and remote working for organizations worldwide.

By James Muir, Threat Intelligence Research Lead, BAE Systems Applied Intelligence

1. Ransomware continues its march; policy complexities follow

The surge of ransomware attacks against organizations was *the* central cyberthreat theme of 2020. We have seen more and more groups adopting the ‘double extortion’ model based on data theft and public victim blogs. A ‘perfect storm’ of factors has contributed to the success of this criminal enterprise. We expect criminal groups to continue in this vein, evolving their tools and finding ways to collaborate. This will result in a greater number of effective attacks. We also anticipate increased use of ransomware-like attacks by unscrupulous state actors, both for financial gain, as well as for disruptive attacks under a false flag. Recent advisories by U.S. Treasury bodies are the first sign of policy complexities to come, with legislation around ransom payment likely to emerge in several countries. Financial institutions, especially those offering cyber insurance, will need to watch this space closely in 2021. Whether policy measures are sufficient to stop the scourge of ransomware attacks remains to be seen; collaborative defensive and increased pursuit of the criminals is also likely required.

2. Synthetic media goes mainstream, and threat actors capitalize

Technological developments in synthetic media (AI-generated faces, voices, etc.) have boomed in 2020 and will continue to do so in 2021. The benefits of this could be many-fold. For example, NVIDIA has proposed an AI-based mechanism to minimize bandwidth use in videoconferencing, with impressive results. However, time has told us that threat actors are always quick to exploit technological advances to support their goals. The immediate use of ‘deepfakes’ for disinformation will be in the interests of several different threat actor groups with political or subversive goals. Synthetic media will also be increasingly used for new twists on social engineering – e.g., AI-generated faces on social media profiles, fictitious personnel at spoofed/front companies, etc., and an array of potential uses of this technology for cybercrime and fraud are likely to be seen in the wild. A scenario in which ‘your CEO’ requests over Zoom that a wire transfer is made, when in reality it is a real-time deepfake video overlay and audio from a cyber-criminal, is increasingly a possibility.

3. Hacking-for-hire becomes a booming industry and intrigue abounds into the ‘hirers.’

2020 has seen a massive increase in disclosure of threat activity constituting ‘hacking for hire.’ Often referred to as corporate or industrial espionage or ‘mercenary’ activity, an increasing number of threat groups and corresponding companies have been implicated in this. We predict that further to the apparent nexuses for these companies in India and Russia, more groups and centers will appear. To date, organizations and individuals in legal, financial services, and government sectors have been heavily targeted, but the ultimate ‘hirers’ of this activity remain unclear. We expect more investigative effort will shine a light on this eco-system in 2021.

4. The implications of remote working become clearer

Much has been written about the potential implications of increased remote working on organizational security, with particular attention to increased attack surface through additional devices and different connectivity mechanisms. Survey data has suggested that a lack of awareness around security best practices has led to an increased rate of data breaches. There have been reports of ‘WFH compromise’ leading to ‘organizational compromise’ – although it is unclear whether these would have occurred from the office anyway. Definitive trends in whether remote working has led to increased prevalence of specific attack paths are currently unclear. However, we expect further attention from both attackers and defenders in 2021. As a global movement to work from home has shifted the enterprise’ last mile’ to include consumer network-enabled technology, 2021 shapes up to be the beginning of a new revolution in adversary tactics, tools, and strategy.

5. Organisations go back to basics to shore up defenses

“Doing the basics right” has been a mantra of many cybersecurity standards bodies for many years. Continuing a trend we saw in 2020, we expect an additional emphasis on this in 2021 as organizations realize that implementation of patching regimes and appropriate authentication controls are a pre-requisite for good security – and those complex technical solutions are rarely the answer in and of themselves. This has particular relevance for preventing ransomware attacks, where board recognition of the threat and preparedness for the attack – both in response and ensuring that backups are functioning and resilient to attack – are vital. The transition to the cloud has been undoubtedly accelerated by the COVID pandemic, further shifting monitoring away from the enterprise for early warning. The Verizon DBIR 2020 highlighted the rise of breaches due to cloud misconfigurations (pre-pandemic) – this is likely to feature heavily next year, too but is a ‘basic’ that should receive increased emphasis.


About the Author

James MuirJames Muir leads on thematic and technology threat research at BAE Systems Applied Intelligence. His current research interests are in the ransomware threat, hackers-for-hire, and threats to operational technology. Muir is a secondee with the U.K. government’s National Cyber Security Centre’s Industry 100 scheme. Muir also holds a Ph.D. in Neuroscience from University College London.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.


Related stories: 

Seven Impactful Cyber-Tech Trends of 2020 and What it Means for 2021

2021 Predictions: Holistic, Centralized, Software-Defined, and Automated Security that is Everywhere

Cybersecurity Startup Corellium Wins the Copyright Suit Against Apple

apple loses copyright infringement lawsuit, Apple, Corellium, cybersecurity, cybersecurity startup, Federal judge verdict, iPhone, iPad, copyright infringement, Apple copyright infringement, Corellium copyright lawsuit, copyright lawsuit,

The David vs Goliath

The “Goliath” Apple had taken on the “David” Corellium in August last year when the former filed a lawsuit against the cybersecurity startup regarding a copyright infringement of its iPhone software. The tech giant claimed that Corellium had made a virtual copy of its iPhone on the computer, which Corellium was offering to ethical hackers for finding vulnerabilities in the iOS. However, a federal judge on Tuesday has finally dismissed this copyright infringement lawsuit against cybersecurity startup Corellium.

In its initial filing, Apple had said that the “virtualization” of their iPhone was a copyright infringement of their iOS software. Although it did not require a SIM card to be placed physically in this virtual version, it still constituted replica of the software involved.

The Federal Judge, Rodney Smith, however, had a different perspective on this lawsuit. He said Apple failed to show a legal basis for protecting its entire iOS from security researchers. He added, Corellium’s service is designed to find security holes in the software, and thus, seemed like a “fair use” of the copyrighted material.

The Grounds of Dismissing

Smith, in his ruling, provided clarity by saying,

From the infancy of copyright protection, courts have recognized that some opportunity for fair use of copyrighted materials is necessary to fulfill copyright’s purpose of promoting ‘the progress of science and useful arts.’ There is evidence in the record to support Corellium’s position that its product is intended for security research and, as Apple concedes, can be used for security research. Further, Apple itself would have used the product for internal testing had it successfully acquired the company.

 

Additionally, Corellium makes several changes to iOS and incorporates its code to create a product that serves a transformative purpose. Hence, Corellium’s profit motivation does not undermine its fair use defense, particularly considering the public benefit of the product.

The Other Allegation

This, however, is only a part of the overall allegations that Apple has placed on Corellium and the court has not dismissed all of them. Apple also alleged that Corellium circumvented its authentication server and secure boot chain, among other measures, which violates the DMCA’s ban on circumventing copy protection measures. Corellium gave a fair use defense against the DMCA charges, but the judge found it insufficient to dismiss the DMCA allegations before a full trial.

The ruling, if upheld, will give a boost to security researchers who face civil or criminal penalties for reproducing copyrighted software as part of their research efforts of finding vulnerabilities.

Related News:
Apple Is Hackers’ Favorite for Brand Phishing Attacks

Kawasaki Suffers Data Breach Through Unauthorized Access

Data breach in 100 U.S. cities

Japan’s Kawasaki Heavy Industries has confirmed a security breach after unknown threat actors illicitly obtained access to its internal networks by exploiting servers located overseas. The authorities stated that some critical information may have been exposed to third-party vendors.

“The company has found no evidence of leaking information to the external network. However, due to the fact that the scope of unauthorized access spanned multiple domestic and overseas offices, it took a considerable amount of time until the company can formally announce the incident. We sincerely apologize for this delay and the inconvenience and concern to customers and other related parties,” Kawasaki said in an official statement.

What Happened?

Kawasaki discovered unauthorized parties accessing its server in Japan from its Thailand’s office on June 11, 2020. The communication between the overseas servers was immediately terminated as a precautionary measure. Kawasaki also discovered unauthorized access from overseas offices located in Indonesia, the U.S., and the Philippines. “We have therefore enhanced monitoring operations to accesses from overseas offices and tightened access restrictions to block unauthorized accesses,” Kawasaki said.

Threat Summary

June 11 Kawasaki identified unauthorized access from an overseas office in Thailand by an internal system audit of the Japan office.

June 15 – Kawasaki confirmed a possibility of a data breach to external parties.

June 16 – Confirmed unauthorized access from the overseas office in Thailand to multiple servers in the Japan data center.

June 24 – Confirmed unauthorized accesses from other overseas offices in Indonesia and the Philippines to the Japan office.

July 8 – Discovered suspicious activity from overseas office in the U.S to the Japan office.

August 3 – Kawasaki implements enhanced network communication restrictions at all overseas offices.

October 5 – Performed a thorough security soundness inspection of approximately 3,000 terminals in overseas offices network, where breaches possibly occurred.

October 30 – Confirmed by continuous network monitoring that no further unauthorized access to the Japan office occurred after August.

November 30 – Restored the network communication that was terminated between overseas offices and the Japan office.

December 21 – Continued monitoring of network traffic after resuming the connection of the restricted overseas offices.

What’s the Impact?

Kawasaki Heavy Industries is a multinational organization that produces a range of consumer products, including motorcycles, marine craft, and heavy industrial equipment for the energy, automotive, aerospace, and defense sectors. Since the company handles critical data and social infrastructure-related information, the recent data breach seems to be the top concern, as cybercriminals could exploit the sensitive data for their advantage.

Kawasaki stated that it informed the affected customers of the security incident. The company is also strengthening access control in communication networks between the overseas and domestic offices to prevent a recurrence.

2021 Predictions: Holistic, Centralized, Software-Defined, and Automated Security that is Everywhere

cybersecurity predictions 2021

The year that has been 2020 has been a cornucopia for cybercriminals who have been able to feast off an extended attack surface, a weakened edge, and networks under enormous strain. If this was the Hunger Games, it could be argued that these criminals are currently running with the advantage. Still, the truth is that 2020 has jolted a security reality that will have longstanding consequences in 2021 and beyond. A reality that could quickly turn the tables in favor of security professionals if organizations change their approaches in the following key areas.

By Tim Woods, Vice President of Technology Alliances, FireMon

Cloud, SASE, and Software-Defined Everything

Starting with the cloud is a bit like stating the obvious. Still, no one could have bet on the sudden and sharp upwards trajectory the cloud has taken, in part fueled by the swift and dramatic shift to work from home (WFH) models resulting from the global COVID-19 pandemic but also because of a changing customer service dynamic. Instead of ruminating on what to scale to the cloud, CIOs are now chewing on how they can best manage hybrid and multi-cloud environments, while CSOs are being urged to develop a plan to secure them.

Workload migrations to the cloud will continue to grow through 2021, which means that cyber cloud attacks are going to increase. It is a simple dynamic of supply and demand. Networks will continue coming under scrutiny, and efforts to secure the employee edge along with the intelligent edge must become a priority. The key to securing this will lie in adopting Secure Access Service Edge (SASE) solutions and a zero-trust approach to security everywhere.

Yes, Gartner is cautioning clients to beware of slideware and marketecture in the SASE market. Why? Because some vendors are rushing solutions to market that don’t reflect a true cloud-based delivery-as-a-service model. We, however, foresee that 2021 is going to see maturity in the SASE market. The promise of a security fabric woven into an SD-WAN is far too attractive to overlook. We anticipate that vendors globally are going to push R&D into ensuring improvements in this area.

A trend we anticipate continuing from 2020 and accelerating into 2021 is the purchase of SaaS-based Identity Access Management (IAM) and Identity Governance and Administration (IGA) systems.

User Monitoring to Secure Data

Data is the new “oil” for businesses, which implies it needs to be as closely guarded. We have also evidenced a surge in online retail, digital logistics capabilities, and the intelligent edge’s growth beyond just IoT. This has resulted in a data explosion, and data lakes are now being exposed to access from devices outside of the corporate network, making them a soft target.

According to Forrester VP and principal analyst Chase Cunningham, companies that do not embrace some form of user monitoring will be out of business in the next 20 years as their intellectual property is compromised and exfiltrated. Now, if we factor in that security companies have reported a massive spike in phishing attacks, some more than 600x, just since the beginning of COVID – we can assume that the expanded attack surface has made easy pickings of data.

Data security and data policies will need to become more stringent, and CSOs will have to become more aligned to HR, management levels across an organization, and risk officers to ensure these policies are enforced. Without adequate data management, the compliance compound will be breached. We anticipate that in 2021 we will witness some record penalties levied to companies who fail in this area.

Embedded Security from Container to App

The use of containers is exploding, and Global Market Insights, Inc. claims the overall market will cross a $2.4 billion valuation by 2024. This is driving demand for container-level security policies and ModelOps, where security is baked into each application at the start of development. This will add to the zero trust efforts embraced by CSOs, and when effective SASE solutions are deployed, we will start to evidence the efficiency of intrinsic and software-defined security.

Aligned to this, automation will flex its muscles as businesses facing budget constraints, the prospect of a recession, and flat markets will need to stretch each dollar. But as much as automation will move up the needs list for businesses, it will herald in new risk factors. Again, raising the need for pervasive security that is baked into processes, applications, and containers from the start.

Remote is the New Default

Remote access to the cloud, remote system management, remote monitoring, remote working – is officially the new normal. The pandemic may have driven us into our homes, but how users have embraced the change and the rapid digitalization of services and march to the cloud will see a continuation of remote working.

With this shift, security agility will be the new frontier as workforces evolve alongside the lessons learned from the pandemic. As a result, security professionals will be taking those learnings and start formalizing more stringent policies with regards to remote everything, which again lends itself to zero trust and SASE approaches being effective combative approaches.

Places of learning will also need to start looking at tighter controls for remote learners from schools, colleges, and universities. The more remote access is granted, and the number of devices accessing a network or the WiFi expands so does the attack surface and proffers additional avenues into the network. Edge devices in this new remote topology will require a heightened security focus to clamp down on the threat potential.

Finally, all the above will be put under enormous pressure from the global security skills shortage. Upskilling security professionals is a constant need on any predictions list – but it will reach peak levels in 2021 as cybercriminals make a meal of vulnerabilities using advanced technologies such as ML and AI.

There is still no certainty about the impact and long-term effects of the rapid technological changes in 2020. Yet, there is some comfort in the fact that the advancements we have seen in the security industry are coming together to finally create the view that all security must be viewed as holistic and centralized. We might not be going back to digging moats, but we will be building more impenetrable fortresses.


About the Author

Tim WoodsTim Woods is the Vice President of Technology Alliances at FireMon. A security professional with over 20 years of experience, Woods believes in raising awareness and educating people on new and emerging technologies. He is known for his leadership and building strong teams with a commitment to growth. Woods is also an ISSA member.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.


Related story: Seven Impactful Cyber-Tech Trends of 2020 and What it Means for 2021

Sparrow: CISA’s Free Anomalies Detection Tool for Azure/M365 Environment

Microsoft Azure vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) has launched a detection tool to identify any unusual or malicious activities in an Azure/Microsoft O365 environment. The agency stated the free detection tool, dubbed Sparrow, is created in response to the recent identity and authentication-based attacks targeting Azure users.

How Sparrow Works?

Sparrow is a PowerShell-based tool created by CISA’s Cloud Forensics team to help Azure administrators find compromised Azure accounts and applications. Sparrow detects unusual intrusions and anomalies by verifying the unified Azure/M365 audit log for indicators of compromise (IoCs), lists Azure AD domains, and checks Azure service principals and their Microsoft Graph API permissions.

“The tool is intended for use by incident responders and focuses on the narrow scope of user and application activity endemic to identity and authentication-based attacks seen recently in multiple sectors. It is neither comprehensive nor exhaustive of available data and is intended to narrow a larger set of available investigation modules and telemetry to those specific to recent attacks on federated identity sources and applications,” CISA said.

 Once installed, the Sparrow detection tool analyzes the machine based on multiple parameters. These include:

  • Searches for any modifications to the domain and federation settings on a tenant’s domain.
  • Searches for any modifications or credential modifications to an application.
  • Searches for any modifications or credential modifications to a service principal.
  • Searches for any app role assignments to service principals, users, and groups.
  • Searches for any OAuth or application consents.
  • Searches for SAML token usage anomaly (User Authentication Value of 16457) in the Unified Audit Logs.
  • Searches for PowerShell logins into mailboxes.
  • Searches for well-known AppID for Exchange Online PowerShell.
  • Searches for well-known AppID for PowerShell.
  • Searches for the AppID to see if it accessed mail items.
  • Searches for the AppID to see if it accessed Sharepoint or OneDrive items.
  • Searches for WinRM useragent string in the user logged in and user login failed operations.

Installation Requirements:

There are no extra steps required to install Sparrow. However, CISA said, “The function, Check-PSModules, will check to see if the three required PowerShell modules are installed on the system and if not, it will use the default PowerShell repository on the system to reach out and install. If the modules are present but not imported, the script will also import the missing modules so that they are ready for use.”

The required PowerShell modules include:

  • CloudConnect
  • AzureAD
  • MSOnline

CISA strongly recommended all Azure and Microsoft O365 admins to learn how to spot suspicious activities using the Sparrow detection tool.

Text Messaging Scams Rise Amid the Holiday Season: FTC

Text Messaging Scam on the Rise, text messaging scam, mobile scam, phishing scam, cybersecurity, holiday scam, smishing scam, spam text messages, smishing, UPS, FedEx, fake delivery partners scam,

In a topsy-turvy year where everyone wished to just hit the skip button and roll on to the next year, the holiday season comes as a pleasant change. After a very long time, marketing and sales pundits are reporting positive shopping and buying sentiments. Since many countries, including Germany, Spain, France, and the U.K., are again going back under a forced lockdown, the physical shopping spree is not possible this season; however, digital sales are certainly seeing an uptick. Many of us are still expecting our gifts to arrive, and reports suggest that cybercriminals are using this to their advantage.

The U.S. Federal Trade Commission’s (FTC) advisory that was released earlier this month suggests that amid the much-anticipated holiday season this year, cybercriminals are prying on users’ shopping trends and targeting them through text messaging scams, also known as SMS phishing or Smishing.

The FTC said that, during the holiday season, people do expect their gifts to be delivered by packaging and delivery partners like FedEx, UPS, and other postal or logistics services. Cybercriminals use this opportunity to carry out text messaging scams by simply writing call to action statements that seem to require immediate action in a stipulated time frame to create a sense of urgency and thus, entice the reader into clicking on a malicious link. One such example is shown in the image below.

Text Messaging Scam
Image Credit: FTC

The malicious link redirects the user to a form, asking them to fill in their personal details, which are then exfiltrated and used in other online frauds or sold over the darknet for monetary gains.

To avoid these scams, FTC suggests its consumers do the following:

  • Check the hyperlink/URL for typos or spelling errors.
  • Verify messages with the courier over a call on its hotline number for legitimacy.
  • Install a mobile device antivirus and keep your OS updated.
  • In case of any suspicious activity, report to the FTC at ftc.gov/complaint.

Related News

Barracuda Alerts APAC Holiday Shoppers of Possible Bot Attacks

URL Hijacking on the Sprawl, Holiday Shoppers Beware

How NTT Ltd. in India is Protecting WFH Employees from BEC Attacks During the Pandemic

Threat Alert! Attackers Use Malicious Email Accounts to Launch BEC Attacks

NTT Ltd. Global Threat Intelligence Center (GTIC) publishes a Monthly Threat Report based on its observations and research. Its October 2020 report featured an article on the OZIE Team – a Nigerian business email compromise (BEC) threat actor group. The OZIE Team has targeted 852,541 domains since it became active in 2017. It is targeting businesses around the world working in the manufacturing, health care, automotive, and food distribution industries. GTIC has been tracking the OZIE Team Team since August 2019. CISO MAG spoke to Murtaza Bhatia, Head – Vertical Solutions, NTT Ltd. in India. to learn about the modus operandi of this gang and what NTT Ltd. did to protect its customers and employees from BEC attacks during the pandemic.

By Brian Pereira, Principal Editor, CISO MAG

According to the GTIC report, the OZIE Team relies on commodity malware sold through sites like HackForums.net and private discord groups. To purchase the commodity malware, the OZIE Team uses Bitcoin and Bitcoin Cash, or internet payment systems like Perfect Money.

Murtaza Bhatia, Head - Vertical Solutions, NTT Ltd. in India
Murtaza Bhatia, Head – Vertical Solutions, NTT Ltd. in India

“They use off-the-shelf tools to do this compromise, rather than creating new variants or new malicious codes. They compromise communication channels, people’s information on their laptops and desktops via their email accounts. So, the whole idea is to hack via email as a channel. They send bulk emails to different targeted industries, groups of people that they select, which leads people to click links in the mail or open attachments in the mail. Those links or attachments are malicious, with malicious codes built into the attached files. And that malicious code once executed will start logging keystrokes and send these back to a central server, which collects information over a period of time. And that is how they get passwords and other user information,” explained Bhatia.

The OZIE Team performs massive reconnaissance spam campaigns against a variety of industries looking for victims. After the reconnaissance campaigns, the OZIE Team will analyze the results and focus on an industry based on the results of their reconnaissance campaigns.

This year, the OZIE Team turned its attention to work from home employees, with pandemic-themed BEC attacks.

“The group took advantage of the fact that people are working from home using unsecured systems such as their personal devices, which lack enterprise-grade security tools,” said Bhatia.

To protect its customers who had work-from-home employees, NTT Ltd. launched an emergency response program in March called Care Program.

“Through the Care Program, we went to all our clients and helped them in terms of setting up secure remote connectivity, giving them secure access to business applications on personal and corporate-owned assets from home. We gave them the ability to measure and monitor the productivity of their employees working from home by providing the appropriate collaboration tools. The combination of these solutions will create a secure environment around the user,” said Bhatia.

NTT’s strategy to protect WFH employees 

CISO MAG asked Bhatia about NTT’s strategy and the steps it took to protect WFH employees. Bhatia told us that they considered the visibility of the corporate assets at remote locations. They also looked at the reconfiguration of security tools that are already deployed on those assets or devices.

“We need to first understand what kind of asset the home user has. Is it a corporate-owned laptop with security tools already installed and deployed? Can I reconfigure those security tools, because now these tools have gone out of the corporate network and the device will be connected to home Wi-Fi broadband, which is an unprotected network? So, configuration checking policies on these tools had to be considered. These configurations have to be reset or changed for a different scenario because the connectivity has changed. And when the connectivity and environment have changed you need to understand what applications a user is authorized to access. And this depends on the security profile of the user as well as the sensitivity of the application they are using,” added Bhatia.

NTT Ltd. had to assist its customers in changing the policy frameworks for all employees. It was a laborious and time-consuming process.

“We had to change those policy frameworks so that the users had access to applications and data on a need-to-have or need-to-know basis. We could then configure the toolsets available on their devices to prevent them from doing a copy-paste or accidentally leaking the data. So, there are tools and solutions which will help you to do that. We saw that most organizations opted for virtual desktop solutions where the desktop is running in the data center and is streamed to the client device,” said Bhatia.

NTT Ltd. offered its customers data encryption solutions and helped them with policies for sharing and storing data. Customers raised questions about compliance and regulation when discussing cloud storage. However, the government relaxed certain rules about allowing call center employees to operate from home, and that took away some anxiety.

“Everybody said it is OK to use the cloud. But some industries were bound by regulation and were not allowed to use the public cloud. But the DoT later said our contact center agents can work from home. They relaxed the rules in terms of connecting and doing calls from agents sitting at home in the ITeS / BPO sector. The relaxation in rules changed the boundaries of security,” said Bhatia.

Bhatia opines that it is the thought process that matters more than reconfigurations or anything else.

“Reconfiguration is about allowing access and also about securing. It is about how do you allow access with minimum or no risk. And this was possible because of the additional tools and cloud solutions that we deployed, such as multi-factor authentication. We could not ship reconfigured devices to remote locations because of issues with logistics. However, we could deploy and configure security tools to remote devices over the cloud. This helped us in reconfiguring security tools and policies,” concluded Bhatia.

Read the December edition of the GTIC Monthly Threat Report here.


RELATED STORY

Operation Falcon: INTERPOL Nabs Three Nigerian BEC Scammers


 

About the Author

Brian PereiraBrian Pereira is the Principal Editor of CISO MAG. He has been writing on business technology concepts for the past 26 years and has achieved basic certifications in cloud computing (IBM) and cybersecurity (EC-Council).

 

Conti Ransomware Gang Takes Down Sangoma Technologies

Hive Ransomware

On Christmas eve, Sangoma Technologies, a provider of Unified Communications as a Service (UCaaS), disclosed a data breach that compromised one of the company’s internal servers. The compromise took place during a targeted ransomware attack by the infamous Conti ransomware gang.

 Key Findings 

  • Sangoma Technologies disclosed the data breach event on December 24, 2020.
  • Researchers suggest Conti Ransomware Gang was responsible for the attack.
  • The Conti ransomware gang posted 26GB worth of data on their data leak website a day before the data breach disclosure.
  • Confidential data, including the company’s financials, accounting, acquisitions, employee salary and benefits information, and legal documents, were leaked in the attack.

It is reported that the attackers published nearly 26GB worth of data on their respective data leak website hosted in the underground forum. Sangoma accepted that a certain amount of confidential data, including the company’s financials, accounting, acquisitions, employee salary and benefits, and legal documents, were leaked in the attack; however, there is no evidence of customers’ data being compromised.

Sangoma Technologies has hired third-party cybersecurity experts who are closely investigating the whereabouts of the attack and determining the actual extent of the data breach. As per the latest updates, the researchers have confirmed traces of the Conti ransomware gang, which closely shares code with another infamous threat actor – the Ryuk ransomware gang.

Related News:
Suit Up! Ransomware Task Force is Here

Operations of the Conti ransomware gang first emerged in December 2019 and only gained momentum in June 2020. Conti ransomware is distributed as a payload using TrickBot malware and moves laterally until it breaks through the domain admin credentials, making it easier to infect and encrypt critical data.

Bill Wignall, President and CEO of Sangoma, said,

We are working as quickly as we can to complete our investigation. As this work progresses, we plan to provide updates of factual, accurate information as it becomes available.

Sangoma has asked its customers to reach out at [email protected] for any queries about the data breach. Additionally, it asked all its customers to change their passwords as a precautionary measure.

Related News:
Ransomware Attacks in 2020! These are 4 Most Affected Sectors

Seven Impactful Cyber-Tech Trends of 2020 and What it Means for 2021

cyber-tech trends

Every year I like to research and commentate on the most impactful security technology and business happenings from the prior year. This year is unique since the pandemic is partly the catalyst for most of these trends in conjunction with it being a presidential election year like no other. All these trends are likely to significantly impact small businesses, government, education, high tech, and large enterprise in big and small ways.

By Jeremy Swenson, Security Entrepreneur and Senior Management Tech Risk Consultant

Stock Mashup, 2020

1. Disinformation Efforts Accelerate Challenging Data and Culture

Advancements in communications technologies, the growth of large social media networks, and the “appification” of everything increases the ease and capability of disinformation. Disinformation is defined as incorrect information intended to mislead or disrupt, especially propaganda issued by a government organization to a rival power or the media. For example, governments creating digital hate mobs to smear key activists or journalists, suppress dissent, undermine political opponents, spread lies, and control public opinion (Shelly Banjo, Bloomberg, 05/18/2019). Today’s disinformation war is largely digital via platforms like Facebook, Twitter, iTunes, WhatsApp, Yelp, and Instagram. Yet even state-sponsored and private news organizations are increasingly the weapon of choice creating a false sense of validity. Undeniably, the battlefield is wherever many followers reside.

Bots and botnets are often behind the spread of disinformation, complicating efforts to trace it and to stop it. Further complicating this phenomenon is the number of app-to-app permissions. For example, the CNN and Twitter app having permission to post to Facebook and then Facebook having permission to post to WordPress and then WordPress posting on Reddit, or any combination like this. Not only does this make it hard to identify the chain of custody and source, but it also weakens privacy and security due to the many authentication permissions.

We all know that false news spreads faster than real news most of the time, largely because it is sensationalized. Since disinformation draws in viewers, which drives clicks and ad revenues; it is a money-making machine. If you can control what’s trending in the news and/or social media, it impacts how many people will believe it, which in turn impacts how many people will act on that belief, good or bad. This is exacerbated when combined with human bias or irrational emotion. For example, in late 2020 there were many cases of fake COVID-19 vaccines being offered in response to human fear (FDA, 12/22/2020). This negatively impacts culture by setting a misguided example of what is acceptable.

There were several widely reported cases of political disinformation in 2020 including misleading texts, e-mails, mailers, and robocalls designed to confuse American voters amid the already stressful pandemic. Like a narcissist’s triangulation trap these disinformation bursts riled political opponents on both sides in all states creating miscommunication, ad hominin attacks, and even derailed careers (PBS, The Hinkley Report, 11/24/20). Moreover, huge swaths of confused voters aligned more with speculation and emotion/hype than unbiased facts. This dirtied the data in terms of the election process and only begs the question of which parts of the election information process are broken. This normalizes petty policy fights, emotional reasoning, lack of unbiased intellectualism – negatively impacting western culture. All to the threat actor’s delight. Increased public to private partnerships, more educational rigor, and enhanced privacy protections for election and voter data are needed to combat said disinformation.

2. Stalkerware Grows and Evolves Reducing Mobile Privacy

The increased use of mobile devices in conjunction with the pandemic induced work from home (WFH) growth has produced more stalkerware. According to one report, there was a 51% increase in Android spyware and stalkerware from March through June, vs the first two months of the year (Avast, Security Boulevard, 12/02/20); and this is likely to be above a 100% increase when all data is tabulated for the end of 2020. Inspired by covert law enforcement investigation tactics, this malware variant can be secretly installed on a victim’s phone hiding as a seemingly harmless app. It is not that different from employee monitoring software. However, unlike employee monitoring software, which can easily be confused with this malware; stalkerware is typically installed by fake friends, jealous spouses and partners, ex-partners, and even concerned relatives. If successfully installed, it relays private information back to the attacker including the victim’s photos, location, texts, web browsing history, call records, and more. This is where the privacy violation and abuse and or fraud can start yet it is hard to identify in the blur of too many mobile apps.

3. Identity & Access Management (IAM) Scrutiny Drives Zero Trust

The pandemic has pushed most organizations to amass WFH posture. Generally, this improves productivity making it likely to become the new norm, albeit with new rules and controls. To support this, 51% of business leaders are speeding up the deployment of Zero Trust capabilities (Andrew Conway, Microsoft, 08/19/20). Zero trust moving to need to know only access mindset with inherent deny rules, all the while assuming you are compromised. This infers single sign-on at the personal device level and improved multifactor authentication. It also infers better role-based access controls (RBAC), improved need to know policies, group membership reviews, and state of the art PAM tools for the next year.

4. Security Perimeter is Now More Defined by Data Analytics than Physical/Digital Boundaries

This increased WFH posture blurs the security perimeter both physically and digitally. New IP addresses, internet volume, routing, geolocation, and virtual machines (VMs) exacerbate this blur. This raises the criticality of good data analytics and dashboarding to define the digital boundaries in real-time. Therefore, prior audits, security controls, and policies may be ineffective. For instance, empty corporate offices are the physical byproduct of mass WFH, requiring organizations to set the default to disable badge access. Extra security in or near server rooms is also required. The pandemic has also made vendor interactions more digital, so digital vendor connection points should be reduced and monitored in real-time, and the related exception policies should be revaluated.

5. Data Governance Gets Sloppy Amid Agility

Mass WFH has increased agility and driven sloppy data governance. For example, one week after the CARES Act was passed banks were asked to accept the Paycheck Protection Program (PPP) loan applications. Many banks were unprepared to deal with the flood of data from digital applications, financial histories, and related docs, and were not able to process them in an efficient way. Moreover, the easing of regulatory red tape at hospitals/clinics, although well-intentioned to make emergency response faster. It created sloppy data governance, as well. The irony of this is that regulators are unlikely to give either of these industries a break, nor will civil attorneys hungry for any hangnail claim.

6. The Divide Between Good and Bad Cloud Security Grows

The pandemic has reminded us that there are two camps with cloud security. Those who have a planned option for bigger cloud-scale and those that are burning their feet in a hasty rush to get there. In the first option, the infrastructure is preconfigured and hardened, rates are locked, and there is less complexity, all of which improves compliance and gives tech risk leaders more peace of mind. In the latter, the infrastructure is less clear, rates are not predetermined, compliance and integration are confusing at best, and costs run high – all of which could set such poorly configured cloud infrastructures up for future disasters.

7. Phishing Attacks Grow Exponentially and Get Craftier

The pandemic has caused a hurricane of phishing emails that have been hard to keep up with. According to KnowBe4 and Security Magazine, there has been a 6,000% increase in phishing e-mails since the start of the pandemic (Stu Sjouwerman, KnowBe4, 07/13/20 & Security Magazine, 07/22/20). Many of these e-mails have improved their approach and design, appearing more professional and appealing to our emotions by using tags concerning COVID relief, data, and vaccines. Ransomware increased 72% year over year (Security Magazine, 07/22/20). With many new complexities in the mobile ecosystem and exponential app growth, it is not surprising that mobile vulnerabilities also increased by 50% (Security Magazine, 07/22/20).

Take-Aways

COVID-19 is the catalyst for digital transformation in tech automation, IAM, big data, collaboration tools, and AI. We no longer have the same office and thus less badge access is needed. Single sign-on (SSO) will expand to personal devices and smartphones/watches. Geolocation based authentication is here to stay with double biometrics likely. The security perimeter is now more defined by data analytics than physical/digital boundaries, and we should to dashboard this with machine learning and AI tools.

Education and awareness around the review and removal of non-essential mobile apps is a top priority. Especially for mobile devices used separately or jointly for work purposes. This requires a better understanding of geolocation, QR code scanning, couponing, digital signage, in-text ads, micropayments, Bluetooth, geofencing, e-readers, HTML5, etc. A bring your own device (BYOD) policy needs to be written, followed and updated often – embracing need to know and role-based access (RBAC) principles. Organizations should consider forming a mobile ecosystem security committee to make sure this unique risk is not overlooked or overly merged with traditional web/IT risk. Mapping the mobile ecosystem components in detail is a must.

Cloud infra will continue to grow fast creating perimeter and compliance complexity/fog. Organizations should preconfigure cloud-scale options and spend more on cloud trained staff. They should also make sure that they are selecting more than two or three cloud providers, all separate from one another. This helps staff get cross-trained on different cloud platforms and add-ons. It also mitigates risk and makes vendors bid more competitively.

IT and security professionals need to realize that alleviating disinformation is about security before politics. We should not be afraid to talk about it because if we are then our organizations will stay weak and insecure and we will be plied by the same political bias that we fear confronting. As security professionals, we are patriots and defenders of wherever we live and work. We need to know what our social media baseline is across platforms. More social media training is needed as many security professionals still think it is mostly an external marketing thing. Public-to-private partnerships need to improve and app to app permissions need to be scrutinized. Enhanced privacy protections for election and voter data are needed. Everyone does not need to be a journalist, but everyone can have the common sense to identify malware inspired fake news. We must report undue bias in big tech from an IT, compliance, media, and security perspective.


About the Author

Jeremy SwensonJeremy Swenson is a disruptive thinking security entrepreneur and senior management tech risk consultant. Over 15 years he has held progressive roles at many banks, insurance companies, retailers, healthcare organizations, and even governments. Organizations relish in his ability to bridge gaps and flesh out hidden risk management solutions while at the same time improving processes. He is also a frequent speaker, published writer, and even does some pro bono consulting in these areas. He holds an MBA from St Mary’s University of MN and MSST (Master of Science in Security Technologies) degree from the University of Minnesota.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

A Look Back at the Top 9 Data Breaches of 2020

data breaches, top 9 data breaches, top data breaches in 2020, data breaches in 2020, data breach 2020, top data breaches, twitter hack, twitter data breach, Zoom data breach, Unacademy data breach, BigBasket data breach, Nintendo data breach, Marriot data breach, EasyJet data breach, SolarWinds hack, SolarWinds hacking, SolarWinds data breach,

At the beginning of the year, people celebrated the turn of the decade and readied themselves to strike off the “Things-to-Do” from their bucket list. The year looked promising in the first two months, but little did anyone anticipate they would spend the rest of the year confined within their homes and end up extending their list furthermore. The COVID-19 pandemic made 2020 rather bleak.

The forced lockdown saw a greater shift towards remote working and the uptake of technologies that facilitated this framework. Adoption of cloud and collaboration platforms skyrocketed and gave impetus to rapid digital transformation. However, every coin has two sides, and the flip side was worse. The expanded threat landscape made the already fragile cybersecurity aspect of several businesses cave-in, resulting in greater hacks and data breaches. In fact, a recent report from Risk Based Security revealed that 36 billion records were exposed in data breaches in 2020.

By Mihir Bagwe, Technical Writer, CISO MAG

So, as this eventful year draws to an end, let us sit back and have a look at the top nine data breaches that made it to the headlines and taught us a lesson or two.

1. The Twitter Data Breach

PM Modi Twitter

Impact of Data Breach: 130 accounts

The Twitter data breach grabbed alarming attention not because of the number of accounts hacked but for the prominent names that were targeted, this is why it makes the cut in our list of the top data breaches of 2020. The micro-blogging platform was left red-faced in July 2020, with an account hacking incident that compromised nearly 130 accounts including handles of global celebrities like Kanye West (Rapper) and wife Kim Kardashian (T.V. Celebrity), Jeff Bezos (Amazon CEO), Bill Gates (Microsoft Co-Founder), Barack Obama (the former U.S. President), and a few of the Twitter’s top employees.

The FBI later tracked down three individuals involved in the “Greatest Twitter Hack” and pressed felony charges against the trio on several counts, which involved computer intrusion, wire fraud conspiracy, and money laundering conspiracy, among others.

2. MGM Resorts Data Breach

MGM Resorts

Impact of Data Breach: 142 Million guest accounts for sale on the dark web

The MGM Resorts, in February 2020, reported a data breach that affected nearly 10.6 million of its guests. The company sought help from two cybersecurity firms to probe the incident and correspondingly beefed-up the security lines to avoid such breaches in the future. However, in July, it was discovered that a cybercriminal was selling details of 142,479,937 MGM Resorts’ guests, which might have been originally leaked during the first MGM Resorts data breach that took place in the summer of 2019. The offer price of this data on the dark web was placed at $2,939.76.

Although the compromised data did not involve any financial details and/or personal IDs like the SSN (social security number) or license and passport numbers, MGM Resorts advised its guests to perform a password reset and be watchful of any suspicious activities.

3. Marriot International Data Breach

Marriott International’s Data Breach Exposes Records of 5.2 Million Guests

Impact of Data Breach: 5.2 Million guest accounts breached

In March 2020, hospitality group Marriott International announced that it had been hit by a data breach that exposed the personal information of around 5.2 million of its guests. In an official release, the company stated that the breach began in mid-January 2020 and was discovered only at the end of February 2020. The incident exposed contact details, including names, addresses, birth dates, gender, email addresses, employer name, room stay preferences, and loyalty account numbers. However, Marriott clarified that passport information, payment details, and passwords were not exposed in the breach.

Investigations confirmed that the exposed data had been accessed by an unknown third-party using the login credentials of two employees at a group hotel, which was operated and franchised under Marriott’s brand. Marriott notified the incident to the relevant authorities for further investigation and informed those affected in the breach. The hospitality giant also set up a website to help the impacted guests in the incident.

4. Zoom Credentials Data Breach

Zoom, video conferencing, webinar, zoom two-factor authentication, top data breaches of 2020

 

Impact of Data Breach: 500,000+ Zoom login credentials

With millions of office workers using the Zoom video conferencing platform from home, opportunistic hackers reportedly stole 500,000+ Zoom credentials and sold them for as little as $0.002 per record on the dark web. The affected accounts were related to colleges such as the University of Vermont, University of Colorado, Dartmouth, Lafayette, University of Florida, and even well-known companies such as Chase, Citibank, and more.

The stolen credentials included email addresses, passwords, personal meeting URLs, and host keys that allowed threat actors to enter meetings and carry out Zoomboming attacks.

5. Wishbone

From Data Breach to Darknet

Impact of Data Breach: 40 Million user records

An unidentified hacker group was discovered selling Wishbone.io database on darknet forums. The leaked database contained over 40 million records of Wishbone users–a social platform that allows users to compare social content via voting poll.

The exposed database contained users’ personal data including, email addresses, names, usernames, phone numbers, geographic locations, genders, social media profiles, hashed MD5 passwords, Facebook and Twitter access tokens, gender, date of birth, and profile images, etc.

6. Unacademy

DEO data breach

Impact of Data Breach: 22 Million user records

Cybersecurity firm Cyble revealed that India-based online learning platform, Unacademy, suffered a data breach that exposed details of 22 million of its users. Cyble’s researchers found that the unknown hackers kept 21,909,707 user records for sale at $2,000 on darknet forums. The compromised information included usernames, hashed passwords, date of joining, last login date, account status, email addresses, first and last names, and other account profile details.

7. EasyJet Data Breach

EasyJet cyberattack, EasyJet hack

Impact of Data Breach: 9 Million user records

On May 19, 2020, EasyJet admitted that it had been a target of a cyberattack from a highly sophisticated source.  It first learned of the attack in January 2020 and stated that the threat actors accessed the email addresses and travel details of more than 9 million customers. However, the company clarified that out of the 9 million affected customers, only 2,200 customers’ credit card details were compromised.  EasyJet added that there was no evidence of any misuse of customer information; however, it urged its customers to change passwords, monitor their credit card accounts, and be vigilant of any phishing emails.

8. Nintendo Data Breach

Nintendo data breach, data breach

Impact of Data Breach: 300,000 affected accounts

Japanese consumer electronics and video game giant, Nintendo, had initially admitted that over 160,000 of its gamers’ accounts had been breached by cybercriminals. However, further internal investigations confirmed that another 140,000 user accounts were compromised, taking the tally to 300,000 affected accounts.

Nintendo has a unique NNID (Nintendo Network ID) for all its users. NNID acts like a user ID, which can be linked to the Nintendo account and used optionally for login purposes. However, the cybercriminals exploited this NNID login system, and illicitly gained access into the Nintendo accounts linked to it. The cybercriminals further had access to users’ nicknames, birth dates, countries, email addresses, and other information linked to the NNIDs, which posed a severe identity theft threat.

9. SolarWinds Hack

SolarWinds Orion, SolarWinds Orion Hack, SolarWinds, SolarWinds tools, SolarWinds management tools

Impact of Data Breach: 18,000 high-profile customers including multiple U.S. Government Agencies and tech companies like Microsoft, FireEye, Boeing and many more.

The last-minute entrant to our list of top data breaches for 2020 is the SolarWinds Hack. Just a few days back, the White House acknowledged that a Russian state-sponsored group known as the Cozy Bear or APT 29 carried out a targeted cyberattack on several U.S. Government agencies through a vulnerability in its IT management software called SolarWinds Orion.

The impact of the hack picked up like a raging tornado, sucking up everything and growing larger with every passing moment. SolarWinds, in its SEC filing, acknowledged that nearly 18,000 of its customers were affected in their software hack and that they were all notified about it. However, no customer names were disclosed, and it took down the client list post the disclosure of the hack. However, due to mandatory data breach disclosure procedures of the governments and data regulators, multiple agencies and companies are still coming forward, revealing they were hacked.

About the Author

CISO MAG Writer - Mihir Bagwe
Mihir Bagwe is a Tech Writer and part of the editorial team at CISO MAG. He writes news features, technical blogs, and conducts interviews on latest cybersecurity technologies and trends.