Home Blog Page 167

Iranian Expats Under Radar of ‘Rampant Kitten’ Cyber Espionage for Six Years

Log4j, Iranian Ransomware Actors, SpoofedSccholars, second-tier targets, NIOPDC

Check Point Research uncovered a cyber espionage campaign linked to an Iranian hacker group targeting expats and dissidents in Iran for almost six years. The surveillance campaign dubbed as “Rampant Kitten” targeted government dissidents including resistance group Mujahedin-e Khalq, the Azerbaijan National Resistance Organization, Iranian minorities, and other anti-regime organizations to exfiltrate sensitive information from their Windows systems, Telegram apps, and SMSes.

“The conflict of ideologies between those movements and the Iranian authorities makes them a natural target for such an attack, as they align with the political targeting of the regime,” Check Point said.

Attack Vectors

  • Check Point researchers found four variants of Windows info-stealers intended to steal the victim’s personal documents as well as access to their Telegram Desktop and KeePass account information.
  • Android backdoor that extracts two-factor authentication codes from SMS messages and records the phone’s voice surroundings.
  • Telegram phishing pages, distributed using fake Telegram service accounts.

Malware Analysis

Hackers used multiple malware payloads to obtain data from the targeted devices including:

Information Stealer: Once uploaded on the victim’s device, this malware allows the attackers to make full usage of the victim’s Telegram account. It steals information from the KeePass application, uploads any file it finds, which ends with pre-defined extensions. It also logs clipboard data and takes desktop screenshots.

Module Downloader: This malware downloads and installs several additional modules.

Unique Persistence: This malware implements a persistence mechanism based on Telegram’s internal update procedure.

“The backdoor’s functionality and the emphasis on stealing sensitive documents and accessing KeePass and Telegram accounts shows that the attackers were interested in collecting intelligence about those victims, and learning more about their activities,” Check Point added.

Attacks via Dharma Ransomware

Recently, Group-IB researchers detected attacks on multiple companies across the globe that are carried out by Iranian newbie threat actors for financial gain. These attacks have been actively orchestrated since at least June 2020. The threat actors are using Dharma ransomware along with a set of other publicly available tools to target companies specifically in Russia, Japan, China, and India. Once compromised, the gang typically demands a ransom between 1-5 Bitcoins (BTC). The threat actors seem to be naïve since they did not have a fixed plan about what to do with the compromised networks.

Cybersecurity in Times of a Pandemic [INFOGRAPHIC]

COVID-19 Cyberthreats

The COVID-19 pandemic has disrupted global health, the economy, and social systems. From emptying office spaces to dispersing the workforce, corporates have yet ensured seamless delivery of services. However, remote work environment has also led to a surge in unseen threats in the digital space. Threat actors are prying on potential victims to deploy cyberattacks on home and public networks.

Phishing emails are formulated in the name of the World Health Organization (WHO) and other regulatory bodies, using social engineering tools, to target vulnerable victims. These phishing emails contain documents with embedded links that result in ransomware attacks.

Here are myriad cyberthreats posed by the pandemic:

Ciso Mag Covid-19 info


Click here to view the infographic on a full screen!

To subscribe to the September issue of CISO MAG, click https://cisomag.com/magazine/

About the Authors

About the Authors

Pooja Tikekar is a Feature Writer, and part of the editorial team at CISO MAG. She writes news and feature stories on cybersecurity trends.

More from the author.

 

Rudra Srinivas

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.

 


 

U.S. House Passes Bipartisan IoT Security Bill to Strengthen IoT Networks

IoT attacks

The U.S. House of Representatives passed the IoT Cybersecurity Improvement Act, which is intended to improve the security of Internet of Things (IoT) devices  in the country. The bipartisan bill, which was introduced in 2017 and reintroduced in 2019, will now have to pass the Senate. As per the proposed bill, all the IoT devices purchased by the government must fulfill minimum security requirements.

The bill is supported by Reps. Will Hurd (R-Texas) and Robin Kelly (D-Ill.), and Sens. Mark Warner (D-Va.) and Cory Gardner (R-Colo), along with several cybersecurity companies including Rapid7, BSA, Mozilla, Tenable, Cloudflare, and CTIA.

Once the bill is signed into a law by the president, the IoT Cybersecurity Improvement Act would address various cyber risks from the incursion of insecure IoT devices, which threaten user or national security. The specific requirements of the bill include:

  • The National Institute of Standards and Technology (NIST) is required to publish standards and guidelines on the use and management of IoT devices by the federal government, including minimum information security requirements for managing cybersecurity risks associated with IoT devices.
  • Direct the Office of Management and Budget (OMB) to review federal government information security policies and make any necessary changes to ensure they are consistent with NIST’s recommendations.
  • The NIST and OMB are required to update IoT security standards, guidelines, and policies at least every five years.
  • Prohibit the procurement or use by federal agencies of IoT devices that do not comply with these security requirements, subject to a waiver process for devices necessary for national security, needed for research or that are secured using alternative and effective methods.
  • The NIST is required to publish guidelines for reporting security vulnerabilities relating to federal agency information systems, including IoT devices.
  • Direct the OMB to develop and implement policies that are necessary to address security vulnerabilities relating to federal agency information systems, including IoT devices, consistent with NIST’s published guidelines.
  • Contractors providing IoT devices to the U.S. government are required to adopt coordinated vulnerability disclosure policies, so that if a vulnerability is uncovered, that information is disseminated.

Commenting on the new development, Will Hurd said, “Securing the Internet of Things is a key vulnerability Congress must address. While IoT devices improve and enhance nearly every aspect of our society, economy and everyday lives, these devices must be secure to protect Americans’ personal data. The IoT Cybersecurity Improvement Act would ensure that taxpayers’ dollars are only being used to purchase IoT devices that meet basic, minimum security requirements. This would ensure that we adequately mitigate vulnerabilities these devices might create on federal networks.”

“The Internet of Things grows every single day, and, by the end of next year, it will include more than 20 billion devices. The result is an astounding, unimaginable amount of data, 90% of the data in the entire world was created in the last two years. America needs to keep up with this incredible trend, and that means ensuring proper security and protections—the IoT Cybersecurity Improvement Act is a step in that direction,” Hurd added.

Game Over! Chinese and Malaysian Hackers Charged for Computer Intrusion Campaigns

Chinese actors target telecom

The U.S. Department of Justice (DoJ) charged five Chinese and two Malaysian hackers for their involvement in multiple computer intrusion campaigns from early 2014 until August 2020, affecting more than 100 enterprises globally. According to the DoJ notice, the five Chinese hackers are identified as Zhang Haoran, Tan Dailin, Jiang Lizhi, Qian Chuan, and Fu Qiang. The two Malaysian hackers are identified as Wong Ong Hua and Ling Yang Ching

The hackers were indicted for stealing sensitive software data and business intelligence from companies globally, including software development firms, non-profit organizations, universities, think-tanks, social media companies, and even politicians in Hong Kong.

The cyber activities of the attackers, which are tracked as APT41, Barium, Winnti, Wicked Panda, and Wicked Spider, were intended to pilfer software code signing certificates, customer account data, and valuable business information.  In addition, they were also involved in other criminal schemes like ransomware attacks and crypto jacking.

The Chinese hackers are indicted on counts of multiple conspiracies including computer fraud, wire fraud, and intentional damage to a protected computer, and obtaining digital items of value.

The indictment against the two Malaysian hackers is changed on 23 counts of racketeering, conspiracy, identity theft, aggravated identity theft, access device fraud, money laundering, violations of the CFAA, and falsely registering domain names. They are also alleged of stealing business secrets and gaming artifacts from multiple video gaming firms across the U.S., France, Japan, Singapore, and South Korea.

Deputy Attorney General Jeffrey A. Rosen said, “The Department of Justice has used every tool available to disrupt the illegal computer intrusions and cyberattacks by these Chinese citizens. Regrettably, the Chinese communist party has chosen a different path of making China safe for cybercriminals so long as they attack computers outside China and steal intellectual property helpful to China.”

The FBI Deputy Director David Bowdich, commented, “Today’s announcement demonstrates the ramifications faced by the hackers in China but it is also a reminder to those who continue to deploy malicious cyber tactics that we will utilize every tool we have to administer justice. The arrests in Malaysia are a direct result of partnership, cooperation, and collaboration. As the cyber threat continues to evolve larger than any one agency can address, the FBI remains committed to being an indispensable partner to our federal, international and private sector partners to stop rampant cybercrime and hold those carrying out these kind of actions accountable.”

Chinese Hackers Target COVID-19 Research

In a recent indictment, the DoJ charged two Chinese nationals, Li Xiaoyu and Dong Jiazhi, for their alleged involvement in attempts of hacking and targeting companies that are testing and developing the COVID-19 vaccines. As per the allegations, the duo has been active for the past 11 years and have since been carrying out targeted cyberattacks against countries like the U.S., Australia, Belgium, the Netherlands, Spain, South Korea, Sweden, and the U.K.

Embarking on a Cloud Journey: Understanding the Strategy and Expectations

Misconfigured Cloud Storage Services Led to Over 200 Breaches in Past Two Years

A spate of digital technologies such as Big Data, Internet of Things, Cloud, Artificial Intelligence, and Blockchain have energized enterprises to set audacious goals for their businesses and catapult them from the brick-and-mortar age into the digital age. Driven by business compulsions such as handling disruption of existing models, pressure for more growth and improved margins, and need to engage more intimately with the customer, enterprises have embraced the digital wave.

By Narsimha Rao Mannepalli, Executive Vice President and Head, Cloud & Infrastructure Solutions Service, Infosys

Digital transformation will help a business to discover new ways of engaging with customers, create a smarter enterprise, and define new business models. Significantly, the nature of digital technologies allows it to deliver different outcomes for different business functions. For example, the CIO gains from increased speed and agility of the IT environment, the CMO can orchestrate campaigns better and acquire more customers, the CSO can now have a scalable and predictive engine and forecast more accurately, the CFO benefits from reduced costs, increased revenues and profits, while the CHRO enjoys improved employee experience and engagement. Undoubtedly, digital technologies will have an irreversible and long-lasting impact on the way business is conducted.

Cloud computing is a crucial enabler for digital transformation. It has rightfully received significant attention in recent years as many enterprises embarked on the journey to take advantage of the opportunities it offers and stay competitive. Cloud adoption has been on the rise continuously, and industry analyst Gartner states that investments in cloud computing infrastructure and applications (over USD 200 billion) will account for most of the enterprise software spends in 2019.

Cloud computing is an inevitable and integral part of the IT modernization agenda, which enterprises, both large and small, must undergo to launch their digital journey. The cloud offers a plethora of benefits over the traditional on-premise model such as increased business agility and growth, better customer experience, decreased overall IT costs, standardized IT environment, improved scalability, and availability of systems. Further, another key benefit it offers is its ability to harmoniously exist with other digital technologies, including the provision of better defense against cybersecurity threats.

However, many enterprises struggle to derive the full value from a cloud transformation undertaking. Often, they confuse the transition with a simple lift-and-shift of applications, data, or processes to the cloud and end up with modest outcomes.

An appropriate strategy makes a difference

The cloud transformation involves crafting a strategy that aligns with business objectives combined with careful planning and execution. Enterprises need to clearly state their goals, identify who will drive the transformation internally, and articulate expected behaviors. Procuring management buy-ins and preparing for change are the other factors to consider. Often the change management involves not just transforming IT assets but also refactoring human capital.

Having a well-thought cloud strategy that is aligned with the overall digital transformation path will make the difference between success and failure. With enterprises viewing cloud as a must-have catalyst to establish a next generational IT platform, an effective transformation implies a better chance of much higher levels of business performance.

What differentiates the enterprises that have expertly navigated the cloud journey and are enjoying the transformational benefits from the ones that are still grappling with the what, why, and how of cloud transformation?

Successful firms are the ones that have a clear vision of the cloud journey and can map their drivers, concerns, and expected outcomes with the right course of action. They understand which cloud approach to adopt based on the advantages it provides and are ready to shoulder significant internal changes to gear up for the cloud transition. In short, they invest efforts in getting a comprehensive picture of the cloud journey and are, hence, better prepared to handle the bumps along the way.

Organizations can approach the cloud in many ways

Today, many firms look for predictability, efficiency, and performance and emphasize tactical outcomes such as standardized technology environment, better collaboration, and faster response to the market. Enterprises who look at the cloud through the operational lens are more likely to adopt a lift-and-shift approach by migrating assets to the cloud in an opportunistic manner inclining to opt for quick wins.

Recognizing early on the objectives is critical as it influences the behavior of the organization profoundly. Those focused on lowering costs will look at initiatives such as optimizing the IT footprint and improving license management. However, those aiming to better experiences will look at re-architecting and transforming applications and enhancing user experience (UX). So, enterprises must take different actions based on the objective.

When aiming for a total cloud transformation, enterprises must be prepared to embark on a large-scale initiative that requires a revamp of existing systems, processes, and infrastructure. Such efforts demand persistence and diligence in addition to a comprehensive strategy and robust execution, but the outcomes provide exponential benefits to the company.

The enterprises that are certain to succeed are the ones with a long-term view towards prioritizing business growth and customer-centricity over operational goals. While operational goals are salient, however, they must not be the prime focus.

No initiative is free from concerns

Enterprises have a set of implementation-related concerns such as the ability of the team and availability of skills, stakeholder support, aligning with business goals, managing operational aspects, and organizational readiness for such a venture.

Determining the right cloud model (public, private, hybrid) to adopt is an important decision for the enterprise. Despite a vast amount of information available to help select the appropriate cloud model, enterprises are intimidated by this decision since the consequences of choosing the wrong model causes concern. Second, such a high-visibility initiative needs the support of executive leaders through the journey. For this to happen, the cloud program must demonstrate returns at regular intervals. Getting the stamp of approval from the leaders while running the already complex initiative will demand massive efforts. Third, the availability of the right talent to see the program through is a big concern given the inadequate levels of required skills and resources.

In conclusion, companies have a host of factors that must be weaved into the strategy when considering cloud transformation. Undertaking such a complicated endeavor requires concerted efforts bolstered by solid understanding and a skilled team. However, a successful cloud journey can be the catalyst to create an advanced IT environment and take on digital transformation to be able to support business goals deftly.

About the author

The author is the Executive Vice President and Head, Cloud & Infrastructure Solutions Service, Infosys. 

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Attackers Target Govt. Computers at the National Informatics Centre

Thales

More than 100 computer systems of the National Informatics Centre (NIC) in India were compromised in a suspected malware attack. The NIC is part of the Ministry of Electronics and Information Technology (MeitY) and responsible for securing critical cyber infrastructure in the country. It helps in implementing government projects and provides consultancy to government departments.

The attackers distributed the malware via phishing emails sent across to the employees of the Ministry of Electronics and Information Technology (MEIY) of India. The systems were infected after an employee downloaded the malicious email attachment.

The incident affected the computers of both the NIC and the MeitY that contain sensitive information about national security, citizens, and critical important government functionaries, including the prime minister, national security advisor, the home minister, and other officials. According to sources in Delhi Police’s Special Cell, the primary investigation revealed that the malicious email was sent via a proxy server from the U.S. with an IP Address traced to an Indian-based IT company based in Bengaluru.

Involvement of China Actors?

The security incident comes on the heels of reports claiming that a Chinese firm Zhenhua Data Information Technology has been collecting data on millions of people worldwide. It is found that the Chinese tech company has reported links with the country’s military and intelligence networks, and thus, this action could be an act of espionage, according to Internet 2.0, an Australia-based cybersecurity consultancy that discovered this hidden data trove. This dataset consists of the personal information of nearly 250,000 people worldwide, including 10,000 Indians that consists of prominent personalities like Indian Prime Minister Narendra Modi, Indian President Ramnath Kovind, industrialist Ratan Tata, cricketer Sachin Tendulkar, etc. The majority of the discovered dataset contains the personal information of 52,000 Americans, 36,000 Australians, 10,000 each of Britain and India, and nearly 800 New Zealand nationals.

70% of the U.S. Population Affected by Health Care Data Breaches

Cyberattack on Ireland's Health care

Health care providers have been the primary targets of cyberattacks, with several data breaches and ransomware attacks making headlines in the last few years. Health care organizations have suffered the highest number of cyberattacks than any other sector in the U.S.

According to a survey from privacy website PrivacyAffairs.com, health care data breaches increased by 2,733% between 2009 and 2019 in the U.S., at an average of 1.4 breaches exposing at least 500 records per day. The survey “U.S. Healthcare Data Breach Statistics” revealed over 3,054 data breaches of health care records over the past decade.

Large Amount of Compromised Data

The survey highlighted that 70% of the U.S. population is affected by health care data breaches, with over 230,954,151 health records lost, stolen, or exposed in various security incidents. It is found that 2018 and 2019 witnessed a sharp increase in the number of individuals affected by health care data breaches, with a six-fold increase between 2017 and 2019.

Biggest Health Care Breachescription

The ten biggest health care data breaches of the past decade according to the study include:

Organization             Individuals Affected                               Year
Anthem Inc. 78,800,000.00 2015
Premera Blue Cross 11,000,000.00 2015
Laboratory Corporation of America Holdings dba LabCorp 10,251,784.00 2019
Excellus Health Plan, Inc. 10,000,000.00 2015
Community Health Systems Professional Services Corporations 6,121,158.00 2014
Science Applications International Corporation (SAIC) 4,900,000.00 2011
Excellus Health Plan, Inc. 10,000,000.00 2015
University of California, Los Angeles Health 4,500,000.00 2015
Community Health Systems Professional Services Corporation 4,500,000.00 2014
Advocate Health and Hospitals Corporation, d/b/a Advocate Medical Group 4,029,530.00 2013
Medical Informatics Engineering 3,900,000.00 2015

escription

Vulnerable Systems

Majority of the hospitals are vulnerable to cyberattacks as many of them are using outdated computers and connected medical devices. Most of the hospital security teams neglect known vulnerabilities leaving them unpatched.

“A huge number of modern medical devices rely on networking in order to relay information and work together. Like using a smartphone to control your thermostat, hospitals increasingly rely on IoT for improved patient care. Due to the vast number of connected devices in hospitals, the logistical challenge for IT teams is often too great for proper cybersecurity maintenance. Add to this that medical devices are not usually built with security baked in, and it’s easy to see why medical devices are often used as an entry point for an attacker to gain access to a healthcare provider’s network,” the survey report stated.

95% IT Pros are Confident About the Visibility of IoT Devices on Their Networks

Number of IoT Devices Expected to Reach 24.1 Bn in 2030: Report

The proliferation of the Internet of Things (IoT) devices in consumer, enterprise, and health care organizations, and their internal vulnerabilities has created a security blind spot for cybercriminals. They can launch a Zero-day attack to compromise devices like webcams, smart toys, routers, smart home, coffee machines, connected cars, and medical devices.

A survey “The Connected Enterprise: IoT Security Report 2020” from Palo Alto Networks highlighted a variety of cyberthreats due to the surge in IoT device deployment. The survey, based on the responses of 1,350 security leaders in 14 countries across Asia, Europe, the Middle East, Canada, and the U.S., revealed that the number of non-business devices connecting to corporate networks increased over the last year. The devices that regularly connect to corporate networks include smart teddy bears (34%), medical devices (44%), electric vehicles (27%), and connected kitchen appliances (43%).

IoT Risks: A Growing Concern

According to the survey, 57% of IoT devices are vulnerable to cyberattacks. Over 89% of security leaders reported seeing increased numbers of  IoT devices on their networks last year, with more than 35% of them reported a significant increase. In addition, around 95% of security decision-makers stated that they have visibility of all the IoT devices on their organizations’ networks. However, 41% of respondents said they need to make improvements to the way they approach IoT security, and 17% said a complete revamp is needed.

One in five organizations in North America admitted that they have not segmented IoT devices onto separate networks, which is a basic security measure for building safe and smart networks. Only 20% reported following best practices of using micro-segmentation to contain IoT devices to their own controlled security zones.

How to Strengthen IoT Security

Palo Alto also recommended certain security steps for organizations in order to bolster their IoT security. These include:

  1. Employ device discovery for complete visibility. The first thing businesses need to do is get visibility into the exact number and types of devices on their networks, keeping a detailed, up-to-date inventory of all connected IoT assets, their risk profiles, and their trusted behaviors.
  2. Businesses should divide their networks into subsections to enable granular control over lateral movement of traffic between devices and workloads, reducing the attack surface. Virtual local area network (VLAN) configurations and next-generation firewall policies should be used to keep IoT assets and IT assets separate.
  3. Strong password security is fundamental to securing IoT devices. As soon as an IoT device is connected to the network, the IT team should change the weak default password with a secure one that aligns with the organization’s password policies.
  4. Most IoT devices are not designed to patch security flaws regularly, so it is critical that IT teams ensure devices are regularly patched for known vulnerabilities. To avoid data loss, add dedicated IoT aware file and web threat prevention as well as virtual patching capabilities via intrusion prevention.
  5. Traditional endpoint security solutions require software agents that IoT devices are not designed to take. Organizations should implement real-time monitoring to continuously analyze the behavior of all network-connected IoT endpoints by integrating existing security postures with their next-generation firewall.

Ivan Orsanic, Regional Vice President and Country Manager, Canada, at Palo Alto Networks, said, “The proliferation of IoT devices poses a major challenge for Canadian organizations. IoT devices, such as connected medical devices, lack basic security settings that make them vulnerable to being exploited. As employees continue to work remotely, it is imperative that IT teams introduce IoT security measures to shore up their defenses. It is striking that Canadian organizations say they can see the problem yet are struggling to solve it. Having visibility of IoT devices is great, but without proper network segmentation, cybercriminals could gain access into networks to do damage.”

Organizations Suffer Outbound Email Data Breaches Every 12 Working Hours

BEC Scammers Exploit Email Auto-Forwarding Rules, FBI warns

Egress, a provider of human layer data security solutions, stated that several organizations suffered data breach incidents due to outbound email errors in the last year.  In its research report, “2020 Outbound Email Data Breach,” Egress revealed that 93% of security leaders admitted that their organization had suffered data breaches via outbound emails, approximately every 12 working hours. 94% of respondents reported an increase in email data breaches since the COVID-19 outbreak, and 70% stated that remote working conditions increased the risk.

Employee: the Root Cause

According to the report, the tiredness and stress in employees were the primary reasons for email data breaches, while remote working was cited as the second common reason. When asked about the impact of data breaches, on an individual-level, employees received a formal warning in 46% of incidents, were fired in 27%, and legal action was brought against them in 28%. At an organizational-level, 33% said it had caused financial damage and led to an investigation by a data regulatory body.

Lack of Email Security Tools

The research also highlighted that 16% of respondents had no technology in place to protect data shared by outbound email. 44% said they have message level encryption and 45% said they have password protection for sensitive documents; however, employees had not used the technology provided to prevent the breach in one-third of the most serious breaches suffered.

 Key Findings

  • Organizations reported at least an average of 180 incidents per year when sensitive data was put at risk, equating to approximately one every 12 working hours.
  • The most common breach types were replying to spear-phishing emails (80%); emails sent to the wrong recipients (80%); incorrect file attachments (80%).
  • 62% rely on people-led reporting to identify outbound email data breaches.
  • 94% of surveyed organizations have seen outbound email volume increase during COVID-19. 68% say they have seen increases of between 26% and 75%.
  • 70% believe remote working raises the risk of sensitive data being put at risk from outbound email data breaches.

The findings are based on the responses of 538 senior managers responsible for IT security in the U.K. and the U.S. across vertical sectors including financial services, health care, banking, and legal.

Egress CEO Tony Pepper said, “Unfortunately, legacy email security tools and the native controls within email environments, such as Outlook for Microsoft 365, are unable to mitigate the outbound email security risks that modern organizations face today. They rely on static rules or user-led decisions and are unable to learn from individual employees’ behavior patterns. This means they can’t detect any abnormal changes that put data at risk – such as Outlook autocomplete suggesting the wrong recipient and a tired employee adding them to an email.”

Pepper added, “This problem is only going to get worse with increased remote working and higher email volumes creating prime conditions for outbound email data breaches of a type that traditional DLP tools simply cannot handle. Instead, organizations need intelligent technologies, like machine learning, to create a contextual understanding of individual users that spot errors such as wrong recipients, incorrect file attachments or responses to phishing emails, and alerts the user before they make a mistake.”