Home Blog Page 157

Cybersecurity Awareness – Act Now!

The month of October is commemorated as National Cyber Security Awareness Month in the U.S. While it has been a norm to mark-up a day of the year for significant causes and furthering solutions, it is rare for an entire month to be commemorated for a cause. In fact, Cybersecurity Awareness is the only cause, that I am aware of, for which an entire month has been marked-up. More than anything, this is an indicator of both the significance as well as the urgency in accomplishing this monumental task. Delays or failure to reach desired levels of consistent cybersecurity awareness could have a dramatic impact on individuals, societies, as well as entire nations. The recent incident in Germany where a hospital could not care for patients resulting in death as well as inadequate medical care to the community is a stark reminder of potential consequences.

By Ravi Ivaturi, Sr. Vice President – Digital Security Architecture at Citi

It is clear that the time to act is now! For Cybersecurity leaders and professionals, the month of October and the rest of the quarter is an excellent opportunity to further the awareness and initiate conversations. These conversations should be beyond a simple ‘FYI-note’; rather these should be messages with a call for action. The requested action(s) must be tailored to the target audience and their impact measurable. Let’s look at some common stakeholders and awareness topics that could accrue immediate benefits:

Individual Customers and Employees

This segment of stakeholders is the most targeted by attackers and yet, has been least included in the cybersecurity solution-ing.  Looking at the Verizon Data Breach Investigation Report (DBIR) makes it immediately evident that Phishing and Credential Validation are the top-two attacks in 2019. In fact, these two attacks have been in the top three list consistently over the past five years. Both these attacks rely on user behavior and their inadequate cybersecurity awareness levels.  Of course, there are technology-based controls to protect against these attacks, but their effectiveness has been limited. This implies a successful defense against two top threats and hinges on promoting individuals’ cybersecurity awareness. So, in your message to this segment, consider encouraging your employees and individual customers to:

  1. Change the password for their accounts on your applications, if they have used the same password elsewhere.
  2. Attend training on detecting potential phishing/vishing/smishing attacks; even better send along a brief video or an online interactive lesson.

Both these activities can be measured to determine engagement, follow-on actions, and an overall reduction in attack surface. Apart from enhancing the overall security posture of your business, this effort could help the business be seen as a responsible and trustworthy partner.

Technology Teams

Businesses are becoming more and more technology-centric, so much so that they seem like technology companies.  The technology teams are pivotal to building new capabilities as well as enabling operations. This makes the technology teams a key stakeholder to reach out to about cybersecurity awareness. And, what could we ask of this tech-savvy group?

The key message to this segment of stakeholders is to consider cybersecurity as a springboard for their professional growth. Be it a technologist in an operations role or in a development role, a solid understanding of cybersecurity requirements, identifying solutions, and influence outcomes will greatly help the individual stand out from the rest. More importantly, the individual would have demonstrated a grasp of the business expectations and change-leader – both capabilities are a must for taking on leading roles. Follow this message with a call for action to take up specific training courses or wholehearted support for security initiatives you need traction for.

Leadership Teams

This is perhaps the smallest segment by number and yet, it will be the most impactful in your endeavors. Leadership teams further the business goals and realize the set objectives. This essentially translates into the need to partner with growth-enablers. Cybersecurity has often been looked at as a growth-balancer, rather unduly so. Use the cybersecurity awareness month and the rest of the year to balance this narrative. One analogy I have seen to be effective is as follows:

Brakes on automobiles are often seen as devices meant to slow down the vehicle. Now, imagine driving a vehicle with no brakes at 60mph. Would you do that? In effect, brakes are tools that enable us to drive our vehicles at the speeds we do (with the confidence that we can slow down or apply the brakes anytime). Similarly, cybersecurity enables a business to accomplish rapid growth that can be sustained by technology.

Tie this analogy with your call-for-action. This could be initiatives you would like to see funded, projects you’d like to prioritize, changes to employee performance measurement to include cybersecurity as a parameter, or other tasks that give you a strategic edge. Another effective call-for-action would be to have the leaders speak on this topic with their teams. Culture flows top-down in every organization. When leaders highlight cybersecurity as a priority, it will only translate into greater traction for your initiatives.

To conclude, cybersecurity awareness is pivotal for building and maintaining a robust security program in an organization. Using every opportunity to promote awareness will help significantly in the successful execution of your cybersecurity strategy. To ensure your awareness activities are effective, tailor them to the target audience, and design the activities to be measurable.


References:

1.https://www.theverge.com/2020/9/17/21443851/death-ransomware-attack-hospital-germany-cybersecurity

2.https://enterprise.verizon.com/resources/reports/dbir/2020/dbir-report/

3.https://www.digitalistmag.com/cio-knowledge/2018/12/10/every-business-is-becoming-technology-business-06194681/


About the Author

Ravi IvaturiRavi is a cybersecurity leader with deep expertise in building cybersecurity programs for emerging technologies. He enjoys authoring technology articles, engaging with cybersecurity startups, and above all, solving problems. In his current role, Ravi heads the Cloud Security Architecture function for Citi’s Consumer division, providing security leadership for financial products used by millions of individuals across 19 countries. He also serves on Citi’s apex Security Architecture Council, providing oversight to enterprise-wide security architecture. With over 15 years of cybersecurity experience in the Financial sector, Ravi brings together a well-rounded experience and thought leadership in emerging-technology risks, security assessments, compliance, and technology risk management. Ravi holds a master’s degree from New York University in Computer Science.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Hacking Alert! Footage of 50,000 Singaporean Homes Lands on the Internet

vulnerability in IoT devices

After a long tiring day at work, home is the place you want to be. It is our private and secure space, and we feel no one can breach this periphery. However, 50,000 Singaporeans have been robbed of this feeling. The very device that was installed for the homeowner’s security has been hacked. The security home cams that often help office goers to keep an eye on their kids or elders back home have been hacked. Some private and explicit footage stolen from these home cams has landed upon certain adult sites for paid viewership.

 Key Highlights 

  • Nearly 50,000 Singapore home cams were hacked and over 3TB of data was leaked.
  • A small minority of victims coming from countries like Thailand, South Korea, and Canada are also reportedly affected.
  • Cybercriminals have put up a free online demo of 700MB footage consisting of nearly 4,000 clips.
  • The duration of these clips ranges from under a minute to as long as 20 minutes.

A Singapore-based tabloid, The New Paper, first broke the story quoting that the unnamed hacker group shared these clips with over 70 members who have paid a premium of US$150 for lifetime access to the entire database. The tabloid also mentioned that the operatives of this gang have an active group on the instant messaging app Discord with nearly 1,000 members from around the globe.

Related Story

Over 100,000 Security Cameras in U.K. Are Hackable: Report

To prove credibility to their claims, the gang is said to be offering a free sample containing 700MB worth of data comprising over 4,000 clips and pictures. In all, it is believed that the videos that range from durations of less than a minute to almost 20 minutes. The stolen data has a collective size of 3TB. Although a significant number of clips appear to be from IP-based cameras in Singapore, a few minute observations in certain videos show that a small minority of victims appear to be from other countries like Thailand, South Korea, and Canada. Experts believe that the cybercriminals are exploiting a vulnerability in a specific brand of home cams that are being majorly used in Singapore.

Apart from this, the cybercriminals are incentivizing people to buy VIP membership to the content by offering free tutorials for VIP members where they would be taught to “explore, watch live, and even record” home cams after hacking. This also means that the number of private videos could grow over time.

Jake Moore, Security Specialist at ESET, said, “As worrying as it may seem, this comes as a clear reminder that when cameras are placed on the internet, they must be properly installed with security in mind. When smart devices are set up, they are still regularly placed around the home with no second thought for privacy.”

Poor passwords, irregular patch application of updates, or a sheer case of penetration into IoT devices, whatever the reason may be, security and privacy of smart devices should never be taken lightly as these can cause major implications in future as evidently seen in this incident.

Related Stories

Xiaomi Security Camera Bug Shows Other Homes’ Camera Feeds

Hackers take over Smart Home

Business Email Compromise Leaves Global Footprints in 50 Countries

BEC Scammers Exploit Email Auto-Forwarding Rules, FBI warns

A new investigative report from security solutions provider Agari revealed the geographic locations of business email compromise (BEC) cybercriminals. The investigation found that email fraudsters are operating globally across 50 countries with 25% of scammers in the U.S. In a BEC attack, cybercriminals first steal legitimate business email account credentials, which are later used to launch financial fraud campaigns like fraudulent email messages, requests for out-of-channel funds transfers, and deleted accounting trails.

Agari stated that its Cyber Intelligence Division (CID) identified money mule networks of cybercriminals in every state, including the District of Columbia. Hackers use money mule networks to launder and quickly move money offshore.

Key Findings:

  • Over 2,900 global money mule bank accounts were uncovered, with more than 900 identified money mules located in the U.S.
  • BEC cybercriminals demanded $64 million illicit funds in total.
  • An average of $247,000 of payments were requested to Hong Kong money mule accounts, six times higher than in the U.S.
  • BEC cybercriminals are located across 50 countries where 50% of email fraudsters located in Nigeria and 25% located in the U.S.
  • Nearly 48% of U.S.-based email scammers are located in five states: California, Georgia, Florida, Texas, and New York.
  • The five cities with the biggest volume of clusters of email scammers include Atlanta, GA, New York, NY, Los Angeles, CA, Houston, TX, and Miami, FL.

Agari Chief Identity Officer Armen Najarian, said, “A CISO I spoke to just last week explained her number-one goal is customer trust – to earn it, maintain it, and respect it. The information unveiled today as a result of our ACID team’s investigations enables CISOs to learn something new about the threat landscape they are working in and how to adapt their security controls to stay ahead of fraudsters. And ultimately those actions taken by the CISO organization earn and sustain consumer trust.”

BEC Attacks – A Remunerative Business for Cybercriminals

A similar research from the APWG (Anti-Phishing Working Group) revealed how enterprises lose their wealth to BEC attacks. In its “Phishing Activity Trends Report,” APWG highlighted that the average wire transfer loss from BEC attacks surged from $54,000 in Q1 2020 to $80,183 in Q2 2020, as cybercriminals expected high returns. Read the full story here.

Need for Cyber Training! Survey Finds Security Awareness Gaps in Indian Organizations

Acronis Cyber Readiness Report, cyberattacks in India, cybercrime in India, India’s Private Sector

A survey from Cyberbit revealed that over 61% of organizations in India do not have enough cybersecurity training modules to train their workforce. It is found that most of the companies rely upon on-the-job training for their Security Operations Center (SOC) team. Over 90% of organizations are not disclosing their security teams to the MITRE ATTCK framework, and only 32% of companies are aligning their training to MITRE. MITRE ATTCK is a globally accessible knowledge base of cybercriminals tactics on real-world observations of cyberattacks.

Nearly 89% of organizations still depend on classroom training, external certificates, and tabletop exercises, which do not provide practical skills. The survey also claimed that organizations know their employees need cybersecurity training but are not implementing any. However, 11% of organizations stated they have deployed a cyber range that exposes SOC teams to simulated cyberattacks.

India Witnessed 1.45 Mn Cyberattacks

Computer Emergency and Response Team – India (CERT-In) recorded over 1.45 million cybersecurity incidents including breaches and hacks between 2015 and 2020. According to India’s Ministry of Electronics and Information Technology (MeITY), Cert-In reported 49,455, 50,362, 53,117, 208,456, 394,499 and 696,938 cybersecurity incidents during the year 2015, 2016, 2017, 2018, 2019 and 2020 (till August) respectively. The figures were out after the ministry was asked about growing cyberattacks targeting Indian citizens as well as commercial and legal entities. According to a report, released by the U.S. Internet Crime Complaint Centre of the Federal Bureau of Investigation, India stands third in the world among the top 20 countries that are victims of internet crimes. Reports also suggest that the number of internet users in India has grown six-fold between 2012-2017 with a compound annual growth rate of 44%.

October Patch Tuesday Alert! Microsoft Fixes 87 Vulnerabilities Including 11 Critical Ones

microsoft ransomware cybersecurity CISOMAG, Microsoft Patch Tuesday October 2020

Like most other tech companies, 2020 has been a tough year for the tech giant Microsoft. In the past seven consecutive months, it has released more than 100 vulnerability fixes in each of its monthly Patch Tuesday updates. If we are to believe, it is probably the support for a distributed workforce that added to the strain of fixing certain issues, which weren’t critical previously. However, this busy year seems to be finally getting better as Microsoft’s Patch Tuesday for October 2020 contained only 87 vulnerability fixes, yet 11 critical ones.

What’s Included in Microsoft Patch Tuesday October 2020

The October release exclusively consists of security fixes for the following software:

  • Microsoft Windows
  • Microsoft Office and Microsoft Office Services and Web Apps
  • Microsoft JET Database Engine
  • Azure Functions
  • Open Source Software
  • Microsoft Exchange Server
  • Visual Studio
  • PowerShellGet
  • Microsoft .NET Framework
  • Microsoft Dynamics
  • Adobe Flash Player
  • Microsoft Windows Codecs Library
Related Story

Microsoft Fixes 129 Vulnerabilities in its September Patch Tuesday

Tenable’s Staff Research Engineer, Satnam Narang, agrees with our commentary and says, “It has been an unusually busy year for Microsoft Patch Tuesday updates. This month’s Patch Tuesday includes fixes for 87 CVEs, 11 of which are rated critical. It also marks the first time since February that Microsoft patched less than 100 CVEs in a single release. These are positive signs. It means Microsoft is getting secured and much more stable adjusting to the current tech demands in the market.”

A Peep into the Vulnerabilities Fixed

Although discussing all 87 vulnerabilities is beyond the scope of this article, let’s have a look at the most critical ones below. For the complete list refer Microsoft’s Release Notes here.

 CVE-2020-16898 : Windows TCP/IP Remote Code Execution Vulnerability

Dubbed as “Bad Neighbor,” CVE-2020-16898, is a critical remote code execution (RCE) vulnerability within the Windows TCP/IP stack. The vulnerability exists due to improper handling of ICMPv6 Router Advertisement packets using Option Type 25 and an even length field. According to a blog post from McAfee, Microsoft Active Protections Program (MAPP) members were provided with a test script that successfully demonstrates exploitation of this vulnerability to cause a denial of service (DoS). While the test scenario does not provide the ability to pivot to RCE, an attacker could craft a wormable exploit to achieve RCE. While an additional bug would be required to craft an exploit, it is likely that we will see proof-of-concept (PoC) code released in near future.

 CVE-2020-16899 : Windows TCP/IP Denial of Service Vulnerability

This CVE is similar to the previous CVE and results from improper handling of ICMPv6 Router Advertisement packets. To exploit this flaw, an attacker needs to send manipulated ICMPv6 Router Advertisement packets which could cause the system to stop responding. While Microsoft does recommend applying security update to patch this flaw, a workaround is available via a PowerShell command to disable ICMPv6 RDNSS (Recursive DNS Server) in the event the patch cannot be immediately applied.

 CVE-2020-16951, CVE-2020-16952 : Microsoft SharePoint Remote Code Execution Vulnerability

These RCE vulnerabilities in Microsoft SharePoint are a result of a failure to validate an application package’s source markup. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code under the context of the SharePoint application pool and the SharePoint server farm account.

 CVE-2020-16947 : Microsoft Outlook Remote Code Execution Vulnerability

This RCE flaw in Microsoft Outlook occurs due to the improper handling of objects in memory. An attacker can exploit this vulnerability using a crafted email file sent to a user using a vulnerable version of Microsoft Outlook. Because Outlook’s Preview Pane is affected by this flaw, a user does not have to open the message for the vulnerability to be exploited. As Outlook is widely used as an enterprise email solution, it is highly recommended to prioritize the patching of this CVE.

 CVE-2020-16929, CVE-2020-16930, CVE-2020-16931, CVE-2020-16932 : Microsoft Excel Remote Code Execution Vulnerability

To exploit these vulnerabilities, an attacker must create a malicious Excel file and prompt its victim to open the file using a vulnerable version of Microsoft Excel, either by attaching the file to an email or hosting it on a website. Successful exploitation would allow an attacker to gain arbitrary code execution on the vulnerable system with the same rights as the current user. The exploitation of this vulnerability can become critical if the current user has administrative privileges, which could grant the attacker the ability to perform a complete takeover of the vulnerable system.

A Fresh Take on Cybersecurity Awareness

Every year in October we remind our employees that it is time to think about cybersecurity. The cybersecurity awareness campaign has often become an afterthought for the security team and the employees are even less excited. We run the same or a slightly updated training and hang up some new posters in the break room. You might email out a slide presentation and ask everyone to read it and respond “yes I read it”. The annual requirement to check the block on security awareness has lost the value and effect we hope to achieve. Even blending the concept of training and awareness is to some degree misplaced effort. Do we want to teach our staff how to be secure computer users, or do we want them to understand the threats our organization faces and how your team works to defeat them? Those are two very different things and I would like to encourage CISOs, this October, to choose the latter.

By Dick Wilkinson, Chief Technology Officer, New Mexico Judicial Information Division

Security efforts often go unnoticed. The staff and the work they do is a mystery to employees outside of the IT department and even many IT staff are not focused on the security effort. The security team is busy and they are always either improving your defenses or thwarting the next probe or attack. They may not be very engaged with the rest of the organization and don’t get much credit for the hard work they do. The security professionals work behind the scenes and know that their work may be a secret to control sensitive information about your own weaknesses or recent incident responses. This is for a good reason, we don’t want to advertise everything our security team does. The more you talk about the real-world threats and how you respond, the more information you give away about how you defend your system and that could lead to a compromise in the future. I challenge you to place that extreme secrecy aside and let some people peek behind the security curtain just a little bit.

A New Approach to Awareness

This October, take a different approach to cybersecurity awareness, internalize the awareness campaign. Instead of spending all of your time giving training and news snippets that don’t relate to your staff, take the time to show people what your team does and just how well they do it. The following are a few suggestions on how to showcase your team and their efforts while also making your general staff smarter about the threats you face.

Present awards: If you have a big enough security team to highlight some exceptional efforts or individual growth, make October the time you recognize those people. If you can put together a presentation to showcase these people, even better, invite the entire company. Putting your security employees themselves in the spotlight helps people see that they are a part of the larger team and the security professionals are just as motivated as they are to grow and achieve new professional success. Recognize things like new degrees or certifications earned in the last year. Recognize people that were promoted in the last year and describe what that new level of responsibility means. The organization seeing your team and the personal effort they bring to the table will make them more approachable and integrated with the rest of the company. This makes the staff aware that your team is focused on growth.

Highlight your department’s growth or transformation: Moving from the individual member to the team as a whole; this is the chance to show off your own managerial prowess. If the security team had a long project to stand up a totally new SOC tool set. Tell everyone else just how tough that was and what that work means to the company. Describe how the new system detects danger and how your people act to stop it. If you keep statistics like phishing attempts prevented or IP scans detected, now is your chance to show those to a large audience, not just the board and C-Suite. Give the employees information that is concise and easy to digest, and it should have a wow factor. Any mid-size organization sees thousands of phishing attempts in a year and your team has to be always on guard against those threats. Let the employees know that security never stops, even when they go home. Showing the staff just how diligent your team is can raise awareness of the myriad of disciplines that fall under the label security.

Training: Last but not least, training is still going to get the time it deserves. Don’t email slides or buy a training package from a website. Use your team’s expertise to conduct face to face, or virtually live training. Let the SOC analyst show a group of employees what they do when they detect a threat with real tools that they use. People think IT is magic and hackers are wizards, show them the skills you have hired and cultivated to combat that wizardry. You can really wow your company with even some basic show and tell. This will give your security employees a chance to be proud of their work and the general staff will hopefully internalize that value and try to become more connected as part of the security mission. You can take your training objectives and weave them into the show and tell or presentations from your security team. Make a comprehensive plan and then let your team decide what they feel comfortable showcasing. Coach your security team and help them realize this is not bragging about how good we are, this is teaching everyone around us how important security should be in everything they do.

Take this October to change the meaning of awareness, we all know bad actors want to harm our company. How much do we know about our coworkers and what they do to protect us? This is your chance as the CISO to answer that question and gain benefits every step of the way. You can recognize and motivate your security professionals and educate the workforce in new and interesting ways at the same time.


About the Author

Dick WilkinsonDick Wilkinson is the Chief Technology Officer on staff with the Supreme Court of New Mexico. He is a recently retired Army Warrant Officer with 20 years of experience in the intelligence and cybersecurity field. He has led diverse technical missions ranging from satellite operations, combat field digital forensics, enterprise cybersecurity as well as cyber research for the Secretary of Defense.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for them. 

 

How Pandemic Influenced Cybersecurity Budget in Australia

Cryptocurrency scams in Australia

A new research from cybersecurity firm Thycotic revealed that 66% of organizations in Australia are planning to increase their cybersecurity budgets in the next 12 months. The research titled “CISO Decisions” highlighted what motivates companies to invest in cybersecurity and the impact this has on CISO decision making.

Based on the responses from over 900 CISOs and security decision makers globally, the research states that nearly 88% of Australian respondents (77% globally) received boardroom investment for new security projects, either in response to a cyber incident at 59% of organizations (49% globally) or due to fear of audit failure at 29% (28% globally). Nearly 18% of Australian respondents (23% globally) believe that compliance or threats of fines are the most effective way to convince boards to invest in cybersecurity.

COVID-19 Boosts Security Investments

Amid growing cybersecurity risks during the pandemic and the fear of compliance audit failure, most of the CISOs stated that boards are in plan to step up their budgets for cybersecurity. 94% of CISOs in Australia (91% globally) said their board adequately supports them with investment. While two-thirds of Australian respondents (58% globally) believe that in the next financial year they will have increased security budgets due to the COVID-19 outbreak, 41% of them (37% globally) said their investments were turned down because the threat was perceived as low risk.

“Before CISOs can pursue technology innovation they must first educate their stakeholders about the value of cybersecurity. Securing Boardroom investment requires them to strike a delicate balance between innovation and compliance,” said James Legg, CEO at Thycotic.

“While boards are definitely listening and stepping up with increased budget for cybersecurity, they tend to view any investment as a cost rather than adding business value. There are encouraging signs, particularly in APAC where ROI is a leading factor in security investment decisions. However, there is still some way to go, as Boards mainly approve investments after a security incident, or through fear of regulatory penalties for non-compliance. This shows that cybersecurity investment decisions are more about insurance than about any desire to lead the field which, in the long run, limits the industry’s ability to keep pace with the cybercriminals.” said Terence Jackson, CISO at Thycotic.

To address the surge in malware, phishing, and DDoS attacks, EC Council’s CISO MAG has planned a crisp half day virtual engagement, The Australia CISO Confluence, to create more awareness on the need for cybersecurity and its related implications in these testing times. Register here.

 

Insider Threats in Health Care: More Concerning Than Ever Before

Insider attacker leak data

A recent survey from cybersecurity firm Netwrix revealed that majority of the health care organizations are now concerned about insider threats than before the pandemic. In its 2020 Cyber Threats Report, Netwrix highlighted that over 71% of health care providers are worried about the risks of data theft due to the negligence or mistakes of their employees and IT admins. Earlier, organizations in health care sector were mostly concerned about employees accidentally sharing sensitive data (88%) and rogue admins (80%), but now they are worried about phishing (87%), admin mistakes (71%), and data theft by employees (71%).

“Their perceptions of risk are both founded and unfounded. They are correct to be concerned about phishing and IT staff errors, since those types of incidents were experienced by 37% and 39% of respondents, respectively, during the first few months of the pandemic. However, even though 37% suffered improper data sharing, concern about this risk plummeted by 32% points since the pandemic began,” the report stated.

Key Findings

  • Every third health care organization surveyed (32%) experienced a ransomware attack, which is the highest result among all verticals studied.
  • 26% of health care organizations reported data theft by employees; 49% of them were unaware of the incident for weeks or months.
  • Concern about supply chain compromise dropped by a record 50 percentage points from the pre-pandemic level; now, only 25% say it is a top security threat.
  • No respondents were able to discover improper data sharing in minutes. 26% needed hours and 74% had to spend days, weeks, or months to flag the incident.
  • 8 out of 10 health care organizations regularly report on the state on cybersecurity to executive leadership, and 47% are convinced it takes too much time and effort.

“With 39% of health care organizations experiencing incidents due to errors by IT staff, this industry should pay particular attention to the activities of privileged users. Even one mistake can bring the entire organization to a standstill, leaving it unable to take care of patients. To mitigate the risk of admin mistakes, it is essential to rigorously enforce the least privilege principle through regular privilege attestation. To ensure quick detection of unauthorized modifications, health care organizations are advised to automate both monitoring of changes and checking of all system configurations against a healthy baseline,” said Ilia Sotnikov, VP of Product Management at Netwrix.

ACSC Issues a Red Alert for a New Wave of Emotet Malware Campaign

Remote Access Scams

The Australian Cyber Security Centre (ACSC) has issued a high alert warning for a new wave of Emotet malware campaigns specifically targeting Australia’s critical infrastructure and other government agencies. Back in 2019, the ACSC had issued a similar red alert for the Emotet malware campaign but over the due course of the pandemic, the number remained below alert levels. However, the ACSC noted that the Emotet campaigns are further used to deploy ransomware attacks and network compromises, and even a small spike in its number of attacks at this moment is unaffordable.

The Observations

Emotet malware is generally spread through malicious emails (phishing/spear-phishing attacks) containing either MS-Office or PDF file attachments. These attachments contain macros or malicious links, which when enabled or clicked downloads the Emotet malware.

In its latest campaign targeting the Australian services, Emotet operators seem to be using email thread hijacking to spread its vicious circle. The ACSC says, “This technique involves the malware stealing an infected victim’s email contacts and recent email threads and exfiltrating this information to an actor-controlled Command and Control (C2) server. The actor then sends further phishing emails containing a malicious Emotet attachment, leveraging existing email threads with uninfected contacts, and spoofing the infected victim’s email address.”

On successful compromise, Emotet tries to move laterally by using brute force attacks over user credentials and by manipulating the shared drives on the network. Additionally, Emotet is also known to drop secondary payloads such as TrickBot malware/botnet. Trickbot allows an attacker to further harvest emails and credentials and save it to another C2 server. It then moves laterally within a network using exploits to compromise other systems on the infected network.Australia CISO Confluence

Related Story

Australia to Spend $1.19 Bn to Boost Cybersecurity

The Recommendations

ACSC’s researchers stated, “Emotet download domains are extremely fast-cycling, and it is impossible to maintain an accurate, up-to-date list of indicators of compromise. While domain and IP address blocking may be effective temporarily, this is unlikely to provide long term protection.”

As a long-term precautionary measure, ACSC gave the following recommendations:

  • Hardening of macro settings on all workstations using MS-Office.
  • Apply the latest patches to OS.
  • Perform a scheduled daily backup of at least critical data, if not all.
  • Use email scanning solution for added security other than apt staff training.
  • Use network segmentation to avoid spread in case of compromise.
  • Immediately alert ACSC and/or other required agencies in case of an attack.

Microsoft Downs TrickBot Operations

As said earlier, Emotet is known to drop secondary payloads such as the TrickBot botnet, and the latest data analyzed by Microsoft – through its MS Office 365 Advanced Threat Detection – suggested that Trickbot had been the most prolific malware operation using COVID-19 themed phishing emails. Owing to these high numbers, Microsoft along with a group of other tech companies including Lumen’s Black Lotus LabsESET, Financial Services Information Sharing and Analysis Center (FS-ISAC), NTT, and Broadcom’s Symantec, has collectively taken the fight against the threat actors by trying to shut them off from the backend.

That’s right! Post-approval from the U.S. District Court for the Eastern District of Virginia, the said companies analyzed over 186,000 TrickBot samples to track down the malware’s C2 server and the corresponding IP addresses along with other TTPs applied to evade detection. They have for the moment disabled these IP’s rendering the C2 servers inaccessible and therefore shutting out the operators from accessing the exfiltrated data.

Related Story

Coronavirus Propagates Emotet Malspam Campaign in Japan

APT Actors Exploit Multiple Legacy Vulnerabilities to Target SLTT and Govt. Networks

Cyber Espionage Campaign Naikon APT

The Cybersecurity and Infrastructure Security Agency (CISA) and the FBI claimed that cybercriminals obtained unauthorized access to government networks by exploiting multiple legacy vulnerabilities in VPNs and the Windows platform. In a joint security alert, the agencies stated that they observed advanced persistent threat (APT) actors targeting federal and state, local, tribal, and territorial (SLTT) government networks, and non-government networks. “CISA is aware of some instances where this activity resulted in unauthorized access to elections support systems; however, CISA has no evidence to date that integrity of elections data has been compromised,” the alert said.

The APT actors leveraged legacy network access and exploited critical Netlogon vulnerability CVE-2020-1472 to compromise all Active Directory (AD) identity services. It also found that hackers leveraged vulnerabilities in internet-facing infrastructure, External Remote Services to gain initial access into systems. “Actors have then been observed using legitimate remote access tools, such as VPN and Remote Desktop Protocol (RDP), to access the environment with the compromised credentials. Observed activity targets multiple sectors and is not limited to SLTT entities,” the alert added.

CISA urged system administrators to review their internet-facing infrastructure for these or similar vulnerabilities that could be exploited by attackers, including Juniper CVE-2020-1631, Pulse Secure CVE-2019-11510, Citrix NetScaler CVE-2019-19781, and Palo Alto Networks CVE-2020-2021.

The agencies also recommended certain protective measures to secure the organization’s VPNs. These include:

  • Update VPNs, network infrastructure devices, and devices being used to remote into work environments with the latest software patches and security configurations.
  • Implement multi-factor authentication (MFA) on all VPN connections to increase security. Physical security tokens are the most secure form of MFA, followed by authenticator app-based MFA. SMS and email-based MFA should only be used when no other forms are available.
  • Discontinue unused VPN servers. Reduce your organization’s attack surface by discontinuing unused VPN servers, which may act as a point of entry for attackers.

 ALSO READ: FBI and CISA Warn About Threat Actors Spreading Disinformation on Elections