Home Blog Page 169

Red Teaming: Simulating Targeted Cyberattacks

red and blue teaming

When it comes to cybersecurity, no organization can be 100 percent safe. Even organizations that use advanced security technologies may face problems with such key elements as people, business processes, technologies, and associated intersection points.

There are many methods that help to evaluate the protection level: analysis of the security of systems and applications, penetration testing, assessment of personnel security awareness, etc. However, due to the constant change in the cyberthreat landscape, and the emergence of new hacking tools and criminal groups, new types of risks arise that are difficult to identify using traditional methods.

By David Balaban, Computer Security Researcher

One of the most advanced approaches to test the security level of any organization is Red Teaming — a continuous assessment of the security of information systems, as well as the preparedness of incident response specialists, and the infrastructure’s resistance to new types of attacks, including APT and targeted attacks.

By utilizing the Red Teaming approach and practicing the response to controlled attacks, the internal security teams can enhance their skills in identifying previously undetected threats and thus stop real intruders in the early stages of the attack preventing monetary and reputation damages to the business.

Red Teaming. What is it?

Red Teaming is a comprehensive and most realistic way to test an organization’s ability to resist complex cyberattacks using advanced methods and tools from the arsenal of hacker groups.

The main idea of ​​this exercise is not only to identify potential weaknesses and vulnerabilities that were not detected using standard testing methods, but also to assess the organization’s ability to prevent, detect, and respond to cyberattacks.

Red Teaming helps an organization to understand:

  • How security tools protect important assets.
  • Whether the early warning and monitoring systems are configured correctly.
  • What opportunities attackers must penetrate the internal infrastructure.

Security assessment and training should strive to be maximally realistic and close to real-life situations. The organization’s security team (Blue Team) should not be informed of the start of the project so that the Red Team can model the actions of real attackers based on specific threat analysis and try to breach the infrastructure.

“Cyber-drills” that use the Red Teaming format are most effective for companies with a mature level of information security. Such drills are not limited in time and are focused on achieving different goals, whether it is gaining access to network nodes or sensitive information by any available means. The actual scenarios of Red Teaming are unique for each organization and depend on the goals set.

Commonly used scenarios include:

  • Active Directory forest take over.
  • Getting access to top managers’ devices.
  • Imitation of theft of sensitive customer data or intellectual property.

Read Teaming vs. Penetration Testing

Despite the fact that Red Teaming and Penetration Testing use similar cyberattack tools, the goals and results of both approaches are different.

Red Teaming

The Red Teaming process simulates real targeted attacks aimed at an entire organization. The essence of this approach is the continuous probing of information systems attack resistance. Continuous deep probes provide a comprehensive understanding of how secure the infrastructure is, whether employees are aware of new threats and whether the internal processes of the organization are effective when they are exposed to a real attack.

Penetration Testing

Penetration testing specialists attempt to exploit vulnerabilities and increase their privileges in the systems in order to assess the possible risk from these rogue activities. Pentests do not test readiness to identify and respond to information security incidents.

Below are some of the differences between Red Teaming and Penetration Testing:

Red Teaming and Penetration Testing complement each other. Each approach is important and useful for the organization in its own way, since in the course of such a combined test, it is possible to evaluate both the passive security of the systems and the active security of the company.

Red Teaming in Action

Red Teaming can be divided into several successive stages. To increase efficiency, and considering the limited time, some activities within the main stages, may begin earlier or be performed in parallel with others. Therefore, in practice, the Red Teaming process is not such a clear linear sequence of steps.

More information about each stage:

1. The preparatory stage. Duration: 4 to 6 weeks.

During this stage, the current needs of an organization get assessed, and the amount of work gets calculated. Also, at this stage, the key points for conducting Red Teaming are specified and the official launch of the project is announced:

  • A working group is created consisting of representatives of the Customer and the Contractor.
  • The scope of work is determined (duration, volume, prohibited actions, etc.)
  • Interaction protocols get created.
  • The Red Team is formed according to the needs of the current project.

2. Active Red Teaming stage. Duration: 12 weeks or more.

At this stage, the Red Team:

  • Runs Threat Intelligence.
  • Develops scenarios based on crucial system functions and threat models.
  • Forms a plan and attempts to attack agreed targets (assets, systems, and services that contain one or more important business functions.)

This stage can be divided into two sub-stages: cyber intelligence and scenario development, as well as testing/attacking in the Red Teaming format.

3. The final stage. Duration: 2 to 4 weeks.

All penetration activities get completed once all the planned steps have been successfully completed, or the time allotted for work has expired.

At this stage:

  • The Red Team prepares a report describing its work, prepares conclusions and observations on the company’s ability to detect and respond to threats.
  • The Blue Team prepares its own report describing the actions taken based on the chronology of the report of the Red Team.
  • All participants exchange results, analyze them, and plan further steps to improve the organization’s cyber protection.

Parties involved in the Red Teaming process are:

  • The White Team, which consists of a manager, representatives of the Customer’s business units, and the required number of security experts who will know about the project.
  • The Blue Team – Customer’s security department responsible for the detection and response to information security incidents.
  • The Red Team, which consists of a manager and several security experts simulating targeted attacks.

Methodology

To simulate attacks on a specific target, Red Teams should use proven methodologies that include best practices and adapt them to a specific Customer’s cyber landscape.

The life cycle of security assessment utilizing the Red Teaming format follows the model of The Cyber ​​Kill Chain and has the following general steps: reconnaissance, weaponization, delivery, exploitation, installation, obtaining control, and performing actions in relation to the target.

The Real-life Red Teaming Case

Accessing Active Directory

The Customer was a group of companies operating in the heavy equipment production segment. The goal is to gain administrative access to the Active Directory domain controller at the company’s headquarters.

In the course of the project, it was found that the Customer uses multi-factor authentication (smart cards) for all types of access, including remote and external web services. The use of social engineering was prohibited.

The Red Team actions and results

Security experts conducted a thorough reconnaissance and determined that this organization acquired 12 companies and reorganized them into its subsidiaries right at the time of the Red Teaming operations.

The Red Team managed to get permission to conduct an attack on all the new companies in this group. One of the subsidiaries had very weak cyber-protections. Domain controllers – branchoffice1.domain.com were “hacked” and a VPN was discovered connecting the branch office local networks (Full-Mesh site-to-site VPN.)

The network connection was well protected but trust mechanisms between Active Directory forest domains did not work for controllers on the branchoffice1.domain.com so it was possible to spread the attack and breach the branchoffice2.domain.com, gaining administrator rights there.

Using the Kerberos “golden ticket” attack, the Red Team bypassed the smart cards protection at a “low level” due to the implementation features/failures of the Kerberos protocol. By exploiting the trust mechanism between Active Directory domains, the Red Team managed to obtain administrative rights at the head office. Thus, the domain controllers at headquarters were successfully hacked and experts achieved the goal of the Red Teaming project.

Conclusion

By conducting Red Teaming and practicing the response to controlled attacks, the internal security team can improve its skills in identifying previously undetected threats and stop real attackers in the early stages of the intrusion.

Security training that utilizes the Red Teaming approach gives the organization an idea of ​​the strengths and weaknesses of its cybersecurity posture and allows to define an improvement plan for the continuity of business processes and the protection of valuable data.

By adding Red Teaming as part of its security strategy, a company can measure security improvements over time. Such measurable results can be used for the economic feasibility of additional information security projects and the introduction of new technical means of protection.

About the Author

David BalabanDavid Balaban is a computer security researcher with over 15 years of experience in malware analysis and antivirus software evaluation. David runs the Privacy-PC.com project which presents expert opinions on contemporary information security matters, including social engineering, penetration testing, threat intelligence, online privacy, and white hat hacking. As part of his work at Privacy-PC, Mr. Balaban has interviewed such security celebrities as Dave Kennedy, Jay Jacobs and Robert David Steele to get firsthand perspectives on hot InfoSec issues. David has a strong malware troubleshooting background, with the recent focus on ransomware countermeasures.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Netlogon Vulnerability: Patch Before Hackers Become Your Admin

Microsoft November 2021 Patch Tuesday, Windows 10, Microsoft PrintNightmare

A recent vulnerability on Netlogon patched in the Microsoft August Patch Tuesday was a nightmare, reaching a CVSSv3 score of 10.0. The vulnerability dubbed as ‘Zerologon,’ also identified as CVE-2020-1472, could allow attackers to hijack the Windows domain controller. All an attacker requires is local network access, which is also why it cannot be performed directly over the internet. However, if an attacker sets their foothold in the target environment, they can change the administrator password on any Windows Domain Controller they can reach.

According to Satnam Narang, Staff Research Engineer Security Response, Tenable, “This scenario [attacker exploiting a vulnerability to reset the password of the domain administrator on an organization’s domain controller] is a game over situation for any organization.”

“The impact of the flaw is limited to an attacker who has already gained a foothold inside an organization’s network. Despite this limitation, an attacker could leverage any number of existing unpatched vulnerabilities to breach its target network before pivoting to compromise the vulnerable domain controller. Additionally, we foresee this flaw being a compelling addition to the toolkit of ransomware gangs, who have already wreaked havoc on private organizations, educational institutions, and governments over the last few years,” Narang said.

The Second Wave, Only Deadlier

The vulnerability was discovered by Secura’s security expert Tom Tervoort, who had also discovered the Netlogon vulnerability last year. In comparison to the current one, the earlier vulnerability was less severe. A blog by Secura also noted that Tervoort, after forging an authentication token for specific Netlogon functionality, was able to call a function to set the computer password of the Domain Controller to a known value.

According to Secura, “The vulnerability stems from a flaw in a cryptographic authentication scheme used by the Netlogon Remote Protocol, which among other things can be used to update computer passwords. This flaw allows attackers to impersonate any computer, including the domain controller itself, and execute remote procedure calls on their behalf.”

Exploit Scripts are Already Available on GitHub

Everybody is urged to install the patch on all their domain controllers as soon as possible. “As we’ve already seen, several exploit scripts for this vulnerability are published to GitHub, which provides a blueprint for defenders and attackers; we strongly encourage organizations to apply the patches provided by Microsoft immediately. If your domain controllers are running unsupported versions that are no longer receiving security updates from Microsoft, it is imperative to upgrade those as soon as possible.” Narang added.

Under Attack! 2000 Magento Stores Hacked in a Magecart Campaign

e-skimming attacks , Chinese e-commerce scammers

Security pros from cybersecurity firm Sansec discovered a massive Magecart campaign in which over 2000 Magento online stores were hacked. Magento is an e-commerce platform that allows websites to create their own online store. The researchers stated that most of the compromised sites were running on the Magento 1 version, which reached the end of support in June 2020.  Tens of thousands of customers’ personal information may have been compromised in the incident.

In Magecart attacks (also called web skimming or e-skimming attacks) attackers inject malicious JavaScript code on e-commerce websites after exploiting its CMS vulnerability.

Largest Magecart Attack

Researchers stated that this is the largest automated Magecart campaign observed till date since 2015. Attackers injected malicious code on the website checkout pages to exfiltrate payment information. Sansec detected nearly 1904 distinct Magento stores with a unique keylogger (skimmer) on the checkout page. Hackers infected 10 stores on Friday, 1058 on Saturday, 603 on Sunday, and 233 on Monday.

According to the researchers, threat actors may have used a new exploit code to compromise the stores which was offered on a hacking forum for $5,000 by a Russian seller named z3r0day.

“This automated campaign is by far the largest one that Sansec has identified since it started monitoring in 2015. The massive scope of this weekend’s incident illustrates increased sophistication and profitability of web skimming. Criminals have been increasingly automating their hacking operations to run web skimming schemes on as a many stores as possible,” researchers said.

Magecart Attacks on Rise

Multiple security incidents have been reported on Magecart hackers in the past. In the most recent one, researchers from threat intelligence firm RiskIQ uncovered a Magecart campaign dubbed as “Magecart Group 7” which compromised over 19 e-commerce websites and stole customers’ payment card data.

Facebook Seeks Judicial Review Against Irish Data Regulator’s Ruling

Facebook Takes Down Hundreds of Fake Accounts Under Coordinated Inauthentic Behavior

Ireland reportedly ordered Facebook to stop transfers of EU users’ data back to the U.S., which was carried out under the Standard Contractual Clauses (SCC) provision rendered by the ECJ in its July 2016 ruling. In response to the preliminary order sent to Facebook by Ireland’s Data Protection Commission (IDPC), the social media giant is seeking a judicial review stating it is a “premature” thought process on the part of the IDPC to reach a preliminary conclusion at this stage.

 Key Highlights 

  • Facebook applied for a judicial review towards the approach adopted by Ireland’s Data Protection Commission (IDPC) to reach its decision.
  • The IDPC reportedly sent Facebook a preliminary order to stop transferring user data from the European Union to the U.S.
  • Facebook argued that it is “premature” for the IDPC to have reached a preliminary conclusion at this stage.

Facebook’s Long Fight Continues

Facebook has been fighting the data transfer battle in Europe ever since Maximillian Schrems, an Austrian activist, filed a complaint with Ireland’s Data Protection Commission (IDPC) against the social media giant in 2011. During the long dispute, Facebook took a hit as the European Court of Justice (ECJ) found Facebook falling short on several counts. However, the final nail in the coffin was struck when the ECJ invalidated the “EU-U.S. Privacy Shield,” which acted as a transatlantic data transfer framework for many tech giants including Facebook and Google.

Facebook took the blow on the chin and reverted to the SCC as per the ECJs recommendation. But it seems that the Irish data protection watchdog is still not confident about the data transfer framework adopted by Facebook and has thus sent a preliminary order against it. Facebook also pleaded for a judicial review on the grounds that the agency’s ruling was premature. In a statement, Facebook said, “A lack of safe, secure and legal international data transfers would have damaging consequences for the European economy. We urge regulators to adopt a pragmatic and proportionate approach until a sustainable long-term solution can be reached.”

Annulment of the EU-U.S. Privacy Shield

With a view of creating a safe passage for personal data transfer between the European and the U.S. companies, the U.S. Department of Commerce and the European Commission had established the EU-U.S. Privacy Shield framework in 2016. However, in a landmark judgment, the ECJ annulled the “EU-U.S. Privacy Shield” on the grounds that the said framework did not abide by the data security rights of EU citizens as defined under the General Data Protection Regulation (GDPR). It stated that the U.S. Surveillance Law does not have strong data privacy measures to protect its citizens’ data and instead asked them to make use of the already implemented legal mechanism, the standard contractual clauses (SCCs), for the time being.

Email Marketing Company Mailfire Exposes PII of Dating Site Users

Data breach in 100 U.S. cities

An anonymous ethical hacker found an unsecured Elasticsearch server exposing private data of hundreds of thousands of users of over 70 adult dating and e-commerce websites across the globe.

The leaky database belongs to Mailfire, an email marketing firm that provides online marketing tools to all the websites affected in the data leak. vpnMentor’s researchers stated the database hosted copies of push notifications that various online sites were sending to their users via Mailfire’s push notification service. The database is now secured after vpnMentor reported the incident to the server’s owner.

Breach Summary

In total, the leaky server exposed around 320 million records over 882.1 GB in size affecting more than 100, 000 users. The exposed information included notification contents, users’ PII data, private messages, authentication tokens and links, and email content. The compromised PII data included full names, age and date of birth, gender, email addresses, locations of senders, IP addresses, profile pictures uploaded by users, and profile bio descriptions. The leaked information is vulnerable to various attacks like identity theft, phishing, blackmail, and fraud.

“Cybercriminals could use contact information like names and email addresses to target users with phishing emails, tricking them into sharing even more sensitive data, like credit card details or login credentials, or clicking links embedded with malware. A user’s personal information and account details on a particular website would make it easy for cybercriminals to imitate the website in question, establish trust with their targets, and successfully trick them,” vpnMentor stated.

Misconfigurations Increase the Risks

A similar survey, “The State of Cloud Security 2020,” revealed that inadvertent database exposure continues to be a major risk for organizations, with misconfigurations exploited in 66% of reported attacks. Besides, 33% of organizations reported that attackers gained access through stolen cloud provider account credentials.  A quarter of organizations stated that managing access to cloud accounts is a primary concern to them. Nearly 96% of respondents admitted that they face issues with their current level of cloud security, while 44% of respondents reported data breaches are the top security concern. Only one in four respondents stated lack of staff expertise as a top concern.

“Locking down access is not the answer, but controlling and understanding data is”

Laurence Pitt Juniper interview

Enterprise security challenges witnessed a sudden uptick due to the spike in work from home. A recent study commissioned by Juniper and conducted by Vanson Bourne explored the attitudes, perspectives, and concerns of senior IT networking and security professionals from various industry sectors across the globe. The sudden changes in priorities, poor network visibility, and lack of time were cited as key issues for security professionals struggling to cope with new norms.

To dive deeper into the study and to understand the impact COVID-19 and work from home formats has had to the realm of cybersecurity, Augustin Kurian, Senior Feature Writer from CISO MAG, engaged in an interaction with Laurence Pitt, Global Security Strategy Director at Juniper Networks. Laurence is a passionate cybersecurity professional with a career spanning over 20 years. He understands the security concerns businesses face today and brings insight into the challenges they will face tomorrow. Laurence joined Juniper Networks in 2016 and is the senior security specialist in EMEA.

Excerpts from the interview:

How do you think the insider threat landscape has changed post the COVID-19 outbreak and employees switching to work from home mode? What are the alarming trends that you have witnessed in the last few months after the lockdowns began? Has there been a shift in the method of cyberattacks? What did the internet in India look like in the past?

The most significant change to the landscape with COVID-19 has been in respect of visibility for the security and network team. Put simply, threats that would be visible on a corporate network have now become invisible as they are on a home network. The definition of ‘insider threat’ has shifted. Previously the insider would typically be a disgruntled, coerced, or inadequately trained user, either sharing data, exporting data, or providing access by responding to a phishing attack. With people working from home, the user’s network now has the potential to act as an insider on the corporate network, perhaps because someone in the household has downloaded ransomware or the home-worker uses a corporate device to access personal email and gets ‘phished.’ In a recent survey we commissioned among CISOs and other senior IT professionals across nine countries, it was highlighted that 73% of organizations are struggling with the demands of the pandemic on their network and security. Therefore, we expect to see a growth in attackers taking full advantage of what they see as an opportunity.

An earlier EC-Council’s survey pointed out that 1 in 3 employees don’t use VPN to connect to the company network while working from home, escalating vulnerabilities emerging from insider threats to sharp levels. Why do you think there is such a trend even after increased knowledge about cybersecurity globally?

There is one reason that people avoid using a VPN on their device: performance. Whether it is slow to connect or slows down the network connection once running, either is frustrating. However, the reason employees use a VPN is to access resources that would not be available outside of the corporate network. In other words, they use a VPN because they must. For any resource where VPN is not required, users at home will tend to disconnect. With the growth in SaaS services such as Office 365, Salesforce, SSO applications, and CASBE, the need for a VPN to access resources has reduced overall.

COVID-19 saw mass layoffs across several companies across the world. Several of these may have been employees with privileged access. It is also true that often disgruntled employees are the biggest reasons for insider attacks. In such a situation, can you explain how HR can be leveraged in preventing insider attacks? What role can a CISO perform here?

Losing employees with privileged access is not a problem if there are processes in place to understand who is accessing what, when, and from where. When someone leaves, it is simple to de-provision their access immediately and have a record that this has occurred. It is the role of the CISO to make sure that these policies and processes are in place, rigorously enforced, regularly reviewed, and updated as new systems are deployed across the corporate network.

HR also carries responsibility for system access when an employee leaves and this is often underrated. When a new employee starts, systems will put their user ID into relevant groups for them to have zero-day access to applications and devices which they need for their role. Over time, this list will grow as the user role changes. The same HR systems should be capable of auditing these changes per user and reporting on privileges when required. If correctly implemented, this process would mean that when a user leaves, it is simple to activate a zero-day stop on their account, immediately de-provisioning access to systems on the day their role is terminated.

How do you think MSMEs are handling cybersecurity post-COVID-19? There have been several malware distributions campaigns with COVID-19 as bait or targeting their supply chain. How badly are MSMEs affected by the pandemic?

MSMEs are doing the best they can but having to account for a suddenly expanded network to manage employees who will be using a mix of home and corporate devices for their role. They must rely more upon the security awareness of users to prevent the spread of malware, but this is a challenge. In the survey we conducted recently with security specialists globally, almost 40% of them saw an increased challenge from threats due to the security of home networks. Add this to the 31% of remote workers who also use their own devices to access corporate information and we are in a time of high-risk. Employees are only trying to do their best to maintain productivity and do what’s right. Unfortunately, many organizations simply did not have the right level of a plan in place to deal with the pandemic and global lockdown.

Many a time, recruiters are unable to recruit knowledgeable or skilled personnel to deploy their security automation tools. This is a major hindrance to a good cybersecurity posture. Do you think there is enough stress on the need for security automation programs?

No, there is not yet enough stress on the need for security automation. It is an essential technology since modern threats now come in so many different forms – and the bad guys are already using this technology to develop, test, and launch their attacks. In our recent global survey of CISOs and IT professionals, we asked about the importance of centralized automation in keeping ahead of the bad guys and 97% agreed and felt that centralized automation would greatly simplify the process of securing their environment. Nonetheless, there are two barriers to adoption:

  • For an automation project to be successful, it needs sponsorship across the entire business. From HR to Finance, from Security to Networking. Unless the whole company is represented in the project, it is more likely to fail.
  • Getting the right skills to deploy automation and then retaining them is the second barrier. Finding someone who understands the tools and has experience is the easy part, but these are specialists who are in demand. They will move onto another project if they do not see the right level of sponsorship for success or if the drive for automation becomes stale and they do not feel that their skills are developing.

For security automation or any system’s automation, to succeed, the combination of these two barriers must be overcome, not just for the duration of the project but as an ongoing strategic investment for the business.

As soon as the pandemic occurred, every industry had a void and became a hunting ground for cybercriminals. And there are a lot of cases when it comes to application security and data security, where many times industries do not know what their critical data is. So, how do you think we can combat this?

Many organizations do not realize how critical their data is as a business asset. Historically, data has not been tracked or managed. It is complicated to understand why a seemingly irrelevant dataset becomes both sensitive and important (and, therefore, potentially valuable and vulnerable) when combined with a second dataset. Often following a breach, or the risk of a breach, the first action is to lockdown access to data by applying multiple layers of security. While this is valid, it is not the solution and is like ‘bolting the stable door after the horse has gone.’

Data is the most critical thing that any business handles; it is the heartbeat of the business. Without it, transactions cannot occur, products cannot be developed and interactions with customers cannot take place.

Locking down access is not the answer. But controlling and understanding data is. Look at DLP (data loss prevention) solutions to help, take time to document what information is being stored and where, and put in place controls to understand what is sensitive, what needs protecting, and how it should be protected.

Many countries now have data governance regulations in place (for example, the EU-GDPR) and these include guideline recommendations for best practices in securing data. They are an excellent place to start.

How will the world be after this COVID-19 phase? What do you expect to be different in a post-lockdown world, regarding cybersecurity and hiring? 

After COVID-19, one of the most significant changes we will likely see about cybersecurity and hiring is that location will become less important for new employees. Our recent survey suggested that on average, respondents expect 37% of their workforce to continue working from home, either full or part-time. Lockdown has clearly demonstrated that it is possible to be productive and successful in a home-working or remote environment and investments are being made for this to continue. Flexibility in employment will become a new way of hiring and working.


Augustin Kurian is part of the editorial team at CISO MAG and writes interviews and features.

U.K Govt Announces Funding to Help Healthcare Companies Improve Cybersecurity

NCSC

Marking the second anniversary of the London Office for Rapid Cybersecurity Advancement (LORCA), a government-backed cyber innovation program, Digital Infrastructure Minister Matt Warman announced that hundreds of the U.K.’s vital healthcare firms are set to benefit from government’s newest funding aimed at boosting their cybersecurity posture. The announcement comes after LORCA revealed that the companies supported by it have raised more than £150m (US$200m approx) in investment since its launch two years ago. The announcement was also part of the London Tech Week.

According to the announcement, the National Cyber Security Centre (NCSC) identified a surge in cyberattacks targeting the U.K.’s healthcare since the onset of the COVID-19 pandemic. According to the NCSC, cybercriminals and syndicates have been attempting to steal sensitive intelligence, intellectual property, and personal information from pharmaceutical companies and medical research organizations.

 “We know there is a heightened cyber threat for healthcare businesses at the moment so we are releasing new funding to help those playing a vital role in the pandemic response to remain resilient,” Warman said.

Small and medium-sized businesses, which have been struggling with cybersecurity budget constraints since early this year owing to the pandemic, are touted to be among the biggest benefactors from the new initiative. SMEs are being invited to apply for a slice of the £500,000 funding (US$644855) for the initiative, which will see all consultancy and certification costs covered by the government.

The participants will also be helped get accreditation from the U.K.’s Cyber Essentials certification and set up best practices including training to make sure all phones, tablets, laptops or computers are kept up-to-date, proper firewall usage to secure devices’ internet connections, and user access controls to manage employee access to services. Apart from this, companies can also opt to receive support from one of the program’s cyber experts who will assess the cybersecurity posture of the company, identify its risk portfolio, and help companies implement a business continuity plan.

Warman also urged all organizations to sign up for the government’s Cyber Essentials program.

“Protecting healthcare has been our top priority during the Covid-19 pandemic and we have been working hard to ensure organizations can keep themselves secure,” Paul Chichester, the NCSC’s Director of Operations, said. “While we will continue to support them, signing up to initiatives such as Cyber Essentials is an excellent way for organizations to help themselves.”

Chichester added, “Those who have not already taken up this offer should do so – it will help ensure they have fundamental security protections in place, even in the most challenging of times.”

Recently, NCSC joined hands with international cybersecurity agencies from five countries to issue security guidelines that intend to help organizations globally in disclosing data breaches and handling threat actors.

New Threat Alert! CDRThief Malware Targets Linux VoIP Softswitches

WhisperGate malware campaign, Flagpro malware, MosaicLoader Malware, drinik

Security researchers from cybersecurity firm ESET uncovered a new kind of Linux malware variant targeting Voice-over-IP (VoIP) telephony softswitches. The malware dubbed as “CDRThief” is programmed to compromise specific softswitches – Linknat VOS2009 and VOS3000–and exfiltrate private data like call records that contain metadata about VoIP calls, including caller and IP addresses of call recipients, call timing, and call duration. Softswitches are software-based solutions that run on Linux servers. These are core elements in a VoIP network that provide call control, billing, and management.

How CDRThief Malware Spreads

To pilfer the call metadata, CDRThief malware queries MySQL databases used by the softswitch. The malware authors encrypt all suspicious-looking strings with XXTEA and the key fhu84ygf8643 to hide its malicious capabilities. The malware then reads credentials from Linknat VOS2009 and VOS3000 configuration files and obtains access to the data stored in the MySQL database. CDRThief also uses multiple functions to communicate with C&C servers.

“We can say that the malware’s primary focus is on collecting data from the database. Unlike other backdoors, Linux/CDRThief does not have support for shell command execution or exfiltrating specific files from the compromised softswitch’s disk. However, these functions could be introduced in an updated version. The malware can be deployed to any location on the disk under any file name. It is unknown what type of persistence is used for starting the malicious binary at each boot. However, it should be noted that once the malware is started, it attempts to launch a legitimate binary present on the Linknat VOS2009/VOS3000 platform,” the researchers said.

While the goal of this malware’s creators is unknown, the researchers stated the CDRThief malware is primarily used for cyber espionage. “Another possible goal for attackers using this malware is VoIP fraud. Since the attackers obtain information about activity of VoIP softswitches and their gateways, this information could be used to perform International Revenue Share Fraud (IRSF),” the researchers added.

Russia-based APT28 Targets Election Campaigners and Political Organizations

Russia-based APT29 Targets COVID-19 Vaccine Research

APT28, also known as the “Fancy bear” or “Strontium” threat group, is reportedly backed by the Russian military intelligence agency GRU and has been active since at least 2007. APT28 is famously known to target political entities for carrying out cyberespionage campaigns. One of the most highlighted episodes of their operations came back in 2016 when they hacked the U.S. Democratic National Committee’s (DNC) computer network, which resulted in an online leak of several confidential documents. However, back then the threat actors depended heavily on the spear-phishing attack vector to target their victims, but now they have evolved and added Office 365 password-cracking and credential-harvesting techniques to bust their adversary.

Microsoft’s Advisory

Tom Burt, Microsoft’s Corporate VP for Customer Security & Trust, in a blog said that the company detected a considerable spike in cyberattacks targeted towards people and organizations involved in the upcoming 2020 presidential election, which includes both Trump and Biden campaigns. Burt specifically made a mention of three threat actors that sound more like the elements of the periodic table – Strontium, Zirconium and Phosphorus.

Based on the chemical properties, Strontium is a highly reactive chemical, and the APT28 group resembles similar traits in the cyberspace. According to researchers at Microsoft’s Threat Intelligence Center (MSTIC), the Russia-based threat group has become hyperactive and already “attacked more than 200 organizations including political campaigns, advocacy groups, parties and political consultants.” Their most noted primary targets include:

  • U.S.-based consultants serving Republicans and Democrats.
  • Think-tanks such as the German Marshall Fund of the United States and advocacy organizations.
  • National and state party organizations in the U.S.
  • The European People’s Party and other political parties in the U.K.

Change in Tactics

Notably, since the early days, APT28 advocated the phishing and spear-phishing technique to target its victims. However, MSTIC logged a change in tactics by the threat group in their recent campaigns. It said, “APT28 has now engaged in brute force attacks and password spray, two tactics that have likely allowed them to automate aspects of their operations. They also disguised these credential harvesting attacks in new ways, running them through more than 1,000 constantly rotating IP addresses, many associated with the Tor anonymizing service.”

In fact, deeper insights into the ongoing campaigns suggested that between August 18 and September 3, 2020, APT28 targeted 6,912 accounts belonging to 28 organizations of which none were successfully compromised. That is not all. The group has reportedly also evolved its infrastructure over time by adding and removing about 20 IPs per day to further mask its activity. This makes it even difficult to keep track of their malicious activities for a longer period.

The Other Two Elements

As per Burt’s blog, the other two threat groups Zirconium and Phosphorous are also targeting multiple institutions and enterprises worldwide.

Zirconium: This China-based threat group attacked high-profile individuals associated with the election campaign that includes people associated with Joe Biden’s presidential campaign and prominent leaders in the international affairs community.

Phosphorus: The Iran-based operating group continues to attack the personal accounts of people associated with Donald Trump’s presidential campaign.

India Reports Twice as Many Cyberattacks as any Other Country

Acronis Cyber Readiness Report, cyberattacks in India, cybercrime in India, India’s Private Sector

While organizations are trying hard to cope with the new working conditions like connecting with remote employees and securing critical data at distributed networks, opportunistic cybercriminals are targeting organizations that lack cyber readiness.

The “Acronis Cyber Readiness Report 2020,” from cybersecurity firm Acronis revealed how organizations are mitigating the effects caused by the pandemic to their business operations and security posture. The report revealed that 56% of organizations stated that their IT costs have increased significantly in the past months. India reported nearly twice as many cyberattacks as any other country, followed by the U.S. and the UAE.

Organizations are concerned about protecting corporate data and digital infrastructure against the new challenges of the remote work environment, with 92% of companies adopting new technologies to enable remote work, including workplace collaboration tools, privacy solutions, and endpoint security.

According to the report, the top three technical challenges for the remote workforce are Wi-Fi connectivity, using a VPN and other security measures, and the inability to use internal networks and applications.

Multiple Attacks Scenario

Acronis stated that threat actors are targeting remote employees with various attack vectors, in which distributed denial of service (DDoS), phishing, and videoconferencing attacks are the most common attacks reported during the pandemic. While 31% of companies said they suffered cyberattacks daily, 50% of companies reported that they are targeted at least once a week. In addition, ransomware attacks also increased in the same period.

Other Findings

  • 39% of the companies experienced a videoconferencing attack in the past three months as workers rely on apps like Zoom, Cisco Webex, and Microsoft Teams.
  • Only 2% of companies consider URL filtering when evaluating a cybersecurity solution. It was discovered that approximately 10% of users clicked on malicious websites in May, June, and July 2020.
  • 72% of organizations reported that their IT costs increased during the pandemic. In particular, 27% of companies saw a significant increase during the pandemic. Only one in five companies managed to keep their IT costs unchanged.
  • Nearly 69% of remote workers have started using workplace collaboration tools like Zoom and Webex–but only 63% of IT managers reported adopting those solutions. That means 6% of remote workers are doing their own shadow IT, which poses a security risk.
  • 92% of employees expect their companies to invest more into digital transformation tools to help adapt to new business realities.
  • Only 53% of global remote workers received clear communication when switching to working from home–the other half were left to fend for themselves. A whopping 47% did not receive enough guidance, while 16% received no guidance at all.

Need for Modern Protection

The report also highlighted that organizations need a modern cyber protection solution to prevent cyberattacks and strengthens security to support the new working conditions.

Serguei Beloussov, Founder and CEO of Acronis, said, “The cyberthreat landscape has changed dramatically during the past few years, and in the last six months in particular. Traditional stand-alone antivirus and backup solutions are unable to protect against modern cyberthreats. Organizations that modernize their stack with integrated data protection and cybersecurity not only gain greater security, they lower their costs and improve efficiencies. The automation and streamlined management of Acronis Cyber Protect 15 means any business can decrease their risk, avoid downtime, and increase their IT team’s productivity.”