Home Blog Page 175

Threat to Privacy! 61% of Organizations Suffered an Insider Attack Last Year

Insider Threats

A survey from cloud security firm Bitglass revealed the state of enterprise security related to insider threats. In its “2020 Insider Threat Report,” Bitglass stated that negligent or careless employees can pose severe security risks to organizations. Mitigating insider attacks is challenging for an organization’s IT or cybersecurity team since access to legitimate credentials can put the entire enterprise network in danger.

With businesses undergoing rapid migrations and working remotely due to the ongoing pandemic, securing against insider threats has become a challenge for many organizations. Nearly 61% of respondents reported at least one insider attack in the last 12 months. Several organizations admitted that they cannot detect insider threats from personal devices (82%) or the cloud (50%), and 81% of them find it difficult to assess the impact of insider attacks. While 49% of respondents stated that one week typically goes by before insider attacks are detected, 44% said that another week usually passes before the organization recovers from the attack.

The survey also highlighted that 73% of organizations’ security budgets are decreasing or staying flat over the next year. “Few respondents have a single platform that delivers complete, unified visibility and control for any interaction. When dealing with multiple disjointed tools that provide disparate levels of protection, security professionals spend an inordinate amount of time managing each of the solutions individually,” the report stated.

Anurag Kahol, CTO of Bitglass, said, “Enterprises report that loss of critical data and disruption to business operations are the biggest repercussions of insider attacks. Along with brand damage, remediation costs, legal liabilities, and loss of revenue, these are serious ramifications that must be prevented. Enterprises need a multi-faceted security platform that is designed to monitor user behavior, secure personal devices, deliver maximum uptime and cost savings, and prevent leakage on any interaction. Only then can they defend against insider threats.”

The survey findings are based on the responses from security professionals to understand how their businesses balance budgetary and data protection concerns while defending against insider threats.

Insider Threats on Rise

Several industry experts stressed that insider threats are the primary concern for every security leader, as many organizations fail to address the insiders within their own company. As a result, numerous data breaches happen due to employee negligence or unintentional actions like responding to a phishing email with sensitive information or downloading malicious content. A recent survey report “2020 Cost of Insider Threats: Global Report” from the Ponemon Institute revealed that insider threats increased by 47% from 3,200 in 2018 to 4,716 in 2020. It also revealed that the cost of insider threat incidents also surged by 31% from $8.76 million in 2018 to $11.45 million in 2020.

Data Security Alert! American Payroll Association Suffers Web Skimming Attack

New Programming Language

The American Payroll Association (APA) disclosed it was a victim of a data breach on July 13, 2020, which affected its employees and customers’ information. The hackers injected a web skimmer on the company’s website login and checkout pages. In a security alert, APA stated that the threat actors extracted personal data by exploiting a vulnerability in the association’s content management system (CMS).

Information Accessed in the Data Breach

The attackers gained access to users’ login information like usernames, passwords, payment card information like credit card numbers, and personal information like names, dates of birth, email address, job titles and roles; primary job function, addresses, employee industry, and type of payroll software used. In addition, they also obtained profile photos and social media username data associated with some accounts.

APA notified the users affected in the incident and offered 12 months of free credit monitoring and $1,000,000 in identity theft insurance.

“Since discovering the cyberattack, APA has installed the latest security patches from our content management system to prevent any further exploitation of their website. APA technicians also reviewed all code changes made to the APA website since January; installed additional antivirus software on our servers; and increased the frequency of security patch implementation,” the Association said.

Magecart Attack, Again?

The attack that APA suffered is known as the Magecart attack (also called web skimming or e-skimming attacks) in which attackers inject malicious JavaScript code on e-commerce websites after exploiting a CMS vulnerability. Multiple security incidents have been reported on Magecart hackers earlier. Recently, researchers from threat intelligence firm RiskIQ uncovered a new Magecart campaign dubbed as “Magecart Group 7” that compromised over 19 e-commerce websites to steal customers’ payment card data. The researchers discovered a software skimmer “MakeFrame,” which injects HTML iframes into the targeted websites to obtain payment information.

Enterprise Security Challenges Surge with Spike in Work from Home: Study

remote work, Remote workforce security

There has been a sudden surge in enterprise security challenges owing to the spike in work from home. According to the newest study by Juniper Networks, sudden changes in priorities, poor network visibility, and lack of time were cited as key issues for security professionals struggling to cope with new norms. The study commissioned by Juniper and conducted by Vanson Bourne explored the attitudes, perspectives, and concerns of 1,000 senior IT networking and security professionals from various industry sectors across the globe.

The traditional approaches toward securing enterprise networks have been amplifying newer challenges due to budget constraints and an increase in remote workforce. According to the study, 97% of respondents admitted that they were specifically experiencing ongoing enterprise security challenges when attempting to secure their organization’s network effectively. These were IT challenges that were present even before lockdowns and work from home formats were established. The peril was only heightened by prolific and highly motivated bad actors who have been taking advantage of every opportunity to thrive and remain undetected.

Other highlights of the study include:

  • 86% of respondents felt that they need to improve network reliability and performance.
  • 87% of respondents pursued a security solution to give better visibility across existing apps, reducing false positives, and improving threat response times.
  • 63% of respondents stated that their organization positions IT security as a cost center rather than as a value-driving asset.
  • 97% stated that they had been obliged to spend money on breach mitigation in the last twelve months, with the average cost being more than $276,000.
  • 95% of respondents stated that they have been working with multiple vendors in pursuit of their overall security deployment goals.

“There is a clear narrative among senior IT and security professionals that is overwhelmingly confirmed in this survey. Put simply, they know network security is hugely important, with failure increasingly carrying significant risk for their organization. For me, the most compelling statistic is that ninety-nine percent (99%) agree that a threat-aware network would bring benefits to their organization,” said Samantha Madrid, VP of Security Business & Strategy, Juniper Networks.

She continued, “As workers become more distributed and threats become more sophisticated, security professionals are faced with new and emerging challenges that put enterprises at even greater risk than before. Companies need threat-aware networks that bring speed and agility to enterprise security, coupled with a Connected Security strategy that allows all network elements to work together for increased visibility and action where it matters most. The old way of thinking about security will no longer suffice for those companies battling a new norm.”

Evil Internet Minute: 1.5 Cyberattacks on Computers with an Internet Connection

Evil Internet Minute: 1.5 cyberattacks on Computers with an Internet Connection

Research from threat intelligence firm RiskIQ disclosed the growing volume of malicious activities on the internet. In its report “Evil Internet Minute,” RiskIQ revealed that cyberattacks cost organizations $24.7, with a year-on-year increase of more than $2 every minute. The research also estimated that it will have a per-minute global cost of $11.4 million by 2021, a 100% increase over 2015. Cybercriminals are using sophisticated attack techniques by leveraging the ongoing pandemic, accounting for a 30% increase in Magecart attacks since the outbreak began.

Key Findings

  • 1.5 cyberattacks on computers with an internet connection per minute
  • 16,172 records compromised per minute
  • 1 vulnerability disclosed every 24 minutes
  • Organizations face 375 new cyberthreats per minute
  • 5.5 domain infringements detected per minute
  • 1 Magecart attack every 16 minutes
  • 1 COVID-19 blacklisted domain every 15 minutes
  • 35 COVID-19 spam emails analyzed per minute

Tactics Used

According to the research, attackers are using a variety of hacking techniques such as phishing, domain infringement, and supply chain attacks for monetary gain and cause large-scale reputational damage, political motivations, and espionage.

RiskIQ CEO Lou Manousos, said, “The sheer scale of today’s threat activity is driven by a variety of factors, including that cybercrime is easier than ever to participate in, and better threat technology makes cybercriminals more effective and wealthier than in the past. The OSINT and RiskIQ threat intelligence in the ‘Evil Internet Minute’ paint a vivid picture of the cybercrime RiskIQ and our industry colleagues are tackling in 2020.”

“These stats show threat activity is widespread, but also show the power of threat intelligence in defending the enterprise. More knowledge, greater awareness, and an increased effort to implement necessary security controls make a huge difference in stopping these threat actors in their tracks,” Manousos added.

Data Governance in the Age of the Home Office

Unprotected Server Exposes Facebook Scraped Data of 12 Mn Users in Vietnam

The COVID-19 pandemic took many businesses by surprise. Companies that were vehemently opposed to remote work because of security and compliance concerns have found themselves forced to reconsider their stance at an alarmingly quick rate. This means that remote work policies were put together hastily to ensure company operations continued as lockdown measures swept the world.

By Filip Cotfas, Channel Manager, CoSoSys

The reality of remote work as the new normal has meant that all the carefully crafted data protection frameworks and data governance policies have suddenly become insufficient in the face of a completely new status quo. Mostly because, the premise they were built on, employees working together on a company network within a designated office space, ceased to exist overnight. Even businesses that allowed remote work rarely made provisions for such extreme cases as their entire staff working from home simultaneously for extended periods of time. Remote work policies were thus stretched thin or proved inadequate.

The transition to remote work sent many companies into chaos, with data security practices becoming more lax. Cyberattackers have taken advantage of the situation to prey on vulnerable employees. Malicious attacks against corporate networks and servers also saw a surge as the pandemic slowed down response teams dealing with attacks. The shift towards mass workforce mobility also leads to a similar spike in data movement, putting highly sensitive information at a higher risk of loss and theft.

An Increase in USB Drive Usage

Removable devices, and USB drives, in particular, have long been a thorn in the side of data protection strategies. Pocket-sized, easy to misplace or steal, they have been responsible for countless data leaks over the years. To make matters worse, in recent years, USBs have also become a popular malware infection tool. However, there is no denying they are practical, easy-to-use tools that are an essential part of most work environments.

USBs and removable devices are most often used by employees when leaving company premises, whether to attend business meetings and conferences or to work remotely. The reason for it is fairly simple: this is when they need to take relevant files and documents with them and it’s easier to simply copy them onto a USB, especially if the files are big, to ensure they have access to them at all times.

And while this might be an understandable practice in normal circumstances, when put in the context of the COVID-19 pandemic, it becomes highly problematic. As employees find themselves leaving familiar office spaces, they may feel the need to take confidential files and sensitive data with them to ensure they can perform their duties effectively from home. As a consequence, a large amount of sensitive data is likely to wind up either in the cloud or on vulnerable removable devices such as USBs, from where it can be easily accessed by outsiders or stolen.

A Rise in Internal Threats

Mass layoffs in many countries have led employees fearing dismissal to copy corporate files and sensitive information onto their personal devices, in the hope they may prove useful to them in case they lose their jobs. Many times, they feel entitled to take these files as they may be the result of their work over the years.

This desire to secure something for the future can be very dangerous for companies for two reasons. One is the possibility that their employees, embittered by job loss, may take sensitive data about their business operations to their competitors or use them to discredit the company.

The second is that the data copied, although never used maliciously by the employees that took it, maybe stolen or made public leading to potential fines for companies for noncompliance with data protection regulations.

Protecting Data While Working Remotely

Companies can take measures to curb the transfer of sensitive data onto removable devices through the use of tools such as Data Loss Prevention (DLP) solutions. These can block computers’ peripheral and USB ports, thus preventing connection of any such devices to company endpoints or allowing only trusted devices like encrypted company-issued removable devices to connect to them.  Data defined as sensitive can also be blocked from being transferred onto popular cloud services or file sharing websites through DLP tools.

Enforced USB encryption can help mitigate data vulnerability on removable devices. Through it, an encryption solution is deployed automatically to any trusted USB storage device connected to a company computer. Once installed, any files copied onto the USBs will be encrypted and accessible only through passwords.

Another particularly useful feature of DLP solutions is their ability to not only control but monitor sensitive data and log its movements. Admins are thus notified when an employee attempts to copy or transfer sensitive data. In this way, companies can keep a close look at important information and immediately detect any increases in data transfers whether via the internet or through portable devices.

About the Author

Filip CotfasFilip Cotfas has an impressive background in sales and project management. As a Channel Manager at CoSoSys, he is utilizing his extensive skills for the daily operating efficiency with a focus on South Asia, the Middle East, and Northern Europe markets. Filip`s main responsibility is handling the existing Customer portfolio, as well as acquiring additional revenue streams, mainly by coordinating with the existing partners or enabling new partnerships, in order to help more customers benefit from our award-winning Data Loss Prevention solution. In the past years, he has been developing sales strategies for his markets and built a successful relationship with channel partners.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Iranian Rookie Cybercriminals Target Global Corporates with Dharma Ransomware

Log4j, Iranian Ransomware Actors, SpoofedSccholars, second-tier targets, NIOPDC

Group-IB researchers have detected attacks on multiple companies across the globe that are carried out by Iranian newbie threat actors for financial gain. These attacks have been actively orchestrated since at least June 2020. The threat actors are using Dharma ransomware along with a set of other publicly available tools to target companies specifically in Russia, Japan, China, and India. Once compromised, the gang typically demands a ransom between 1-5 Bitcoins (BTC). The threat actors seem to be naïve since they did not have a fixed plan about what to do with the compromised networks.

 Key Highlights 

  • Iranian newbies are using Dharma ransomware, also known as Crysis, to target multiple companies in Russia, Japan, China, and India.
  • All the targeted organizations had hosts with Internet-facing RDP and weak credentials.
  • The operators typically demanded 1-5 BTC as ransom.
  • The operators used Defender Control and Your Uninstaller to disable built-in antivirus software.

The Modus Operandi

In a detailed investigation carried out by the research team at Group-IB, a threat intelligence and cybersecurity company, it was found that the source code of the Dharma ransomware has been up for sale in the underground market since March 2020 and is distributed as ransomware-as-a-service (RaaS). This is the exact code that has been used by the Persian-speaking newbie threat actors for Dharma ransomware distribution.

  • The operators first scanned ranges of IPs for hosts with Internet-facing RDP and weak credentials in countries like Russia, Japan, China, and India. They used a popular software called Masscan for doing this. Incidentally, the same technique was employed by Fxmsp, an infamous Russian underground seller who made a fortune selling access to corporate networks.
  • On identifying the vulnerable hosts, the attackers executed a brute-force attack to have their way into the system. On some instances, they also attempted elevation of privileges using the exploit for CVE-2017-0213.  On establishing an RDP connection, they decided on which tools to deploy for moving laterally. Additionally, the attackers used “Defender Control” and “Your Uninstaller” to disable built-in antivirus software.
  • They then scanned for accessible hosts in the compromised network using the publicly available tool Advanced Port Scanner. The adversary used the collected information to move laterally through the network using the RDP protocol.
  • Finally, the attackers dropped and executed a variant of Dharma ransomware and executed it manually to demand a ransom in the range of 1-5 BTC.

Oleg Skulkin, Senior DFIR Analyst at Group-IB, said, “The fact that Dharma ransomware’s source code has been made widely available has led to the increase in the number of operators deploying it. It’s surprising that Dharma landed in the hands of Iranian script kiddies who used it for financial gain, as Iran has traditionally seen a lot of state-sponsored attackers engaged in espionage and sabotage. Despite that, these cybercriminals use quite common tactics, techniques, and procedures that have been effective.”

The researchers have suggested to change or maintain a close vigil on the default RDP port 3389 as the attackers usually use this for brute-forcing into the system.

 

Notarization Fail! Apple Inadvertently Approves Malware on Macs

Apple Notarization, operational technology

Apple is known for its tight security measures to prevent malicious software from landing in its app store. However, security researchers found that Apple’s macOS app notarization process inadvertently approved a malware disguised as an Adobe Flash installer.

What is Notarization?

Apple introduced the notarization process to ensure that their apps are malware-free. In notarization, app developers are required to submit their apps to a scanning process to detect for any malicious codes or other security issues. If an app does not pass notarization, it gets blocked by the built-in security function.

A Fail in Notarization

Mac security researcher Patrick Wardle discovered samples of the Shlayer adware that are notarized by Apple. The Flash installer adware campaign, which featured a malicious code, was not blocked by the built-in security function. The installer would run and download its payload on the device if a user clicks on it.

It is stated that the code could have been modified to pass or break the detection that Apple might have had for this adware. Wardle’s discovery led Apple to revoke the notarized payload and disable the developer account to further prevent the malware from running on Mac computers.

Malware on App Store

Avast, a maker of digital security and privacy products, recently discovered and reported three fleeceware apps to Apple’s App Store, which overcharge users, do not provide the services they promote and appear to be fleeceware. The apps are available on the Apple App Store as Beetle VPN, Buckler VPN, and Hat VPN Pro, and according to data from Sensor Tower, a mobile apps marketing intelligence and insights company, the apps have been downloaded over 420K, 271K, and 96K times, respectively, between April 2019 and May 2020. A fleeceware has a characteristic of overcharging users for functionality that is widely available in free or low-cost apps.

BEC Attacks Become a Highly Remunerative Line of Business for Cybercriminals

BEC Scammers Exploit Email Auto-Forwarding Rules, FBI warns

Business Email Compromise (BEC) attacks have become a highly remunerative line of business for threat actors. A new research from the APWG (Anti-Phishing Working Group) revealed how enterprises lose their wealth to BEC attacks. In its “Phishing Activity Trends Report,” APWG highlighted that the average wire transfer loss from BEC attacks surged from $54,000 in Q1 2020 to $80,183 in Q2 2020, as cybercriminals expected high returns.

In a BEC attack, cybercriminals first steal legitimate business email account credentials, which are later used to launch financial fraud campaigns like fraudulent email messages, requests for out-of-channel funds transfers, and deleted accounting trails.

BEC- A Lucrative Attack Vector

BEC attackers demand 66% of funds in the form of gift cards, stating that the average amount of gift cards requested during Q2 of 2020 was $1,213, down from $1,453 in Q1 of 2020. In addition, the number of phishing sites detected in Q2 of 2020 was 146,994, down from the 165,772 observed in Q1 of 2020.  Phishing attacks targeting the social media industry increased in Q2 by about 20%, with the most targeted attacks against Facebook and WhatsApp.

Threat from Russian Hackers

The research also found the movement of a BEC attackers’ gang in Russia known as “Cosmic Lynx,” in addition to the West African scammers targeting organizations with BEC attacks. It is found that the average ransom demanded by the Cosmic Lynx group is about $1.27 million. “We were expecting that Russian cybercriminals would move into the world of BEC because the return on investment for basic social engineering attacks is much higher than launching more sophisticated (and more expensive) malware-based attacks,” the report said.

A Rising Concern

Recently, the FBI warned that organizations that use cloud-based email systems are at high risk to BEC attacks. The bureau advised employees about the email scams that begin with phishing kits designed to mimic two popular cloud-based email services to lure employees into compromising business email accounts and misdirecting funds transfers. The FBI stated that its Internet Crime Complaint Center (IC3) received complaints, between January 2014 and October 2019, claiming more than US$2.1 billion losses from BEC scams.

Facebook Sues App Developers for Harvesting Users’ Data Illegally

Facebook Takes Down Hundreds of Fake Accounts Under Coordinated Inauthentic Behavior

Facebook filed two separate lawsuits in the U.S. and the U.K. against app developers for exploiting its platform and harvesting users’ data illegally. According to a report, Facebook Inc. and Facebook Ireland charged MobiBurn, OakSmart Technologies and its founder Fatih Haltas in the High Court of Justice for failing to comply with the audit request. The social networking giant claimed that MobiBurn gathered users’ data from Facebook and other social media firms by paying third-party app developers to install a malware “Software Development Kit (SDK)” in their applications.

“When people installed those apps on their devices, MobiBurn collected information from the devices and requested data from Facebook, including the person’s name, time zone, email address and gender. MobiBurn did not compromise Facebook, instead they used the malicious SDK on the users’ devices to collect information,” Facebook said in a report.

MobiBurn’s behavior came to light after security researchers reported the incident in a data abuse bounty program. Facebook then took enforcement action by sending a cease-and-desist letter asking MobiBurn to participate in a security audit, to which MobiBurn denied its cooperation.

In the U.S., Facebook Inc. and Instagram LLC sued Nikolay Holper in Federal Court in San Francisco for running a fake service called “Nakrutka” to sell fake likes, views, comments, and followers on Instagram. Facebook claims that Holper used a network of bots and automation software to run his fake engagement services on Instagram.

Lawsuits Filed Earlier

This is not the first time Facebook took legal action against abusers. Recently, it filed a similar lawsuit against Namecheap, an Arizona-based provider of domain name registrars online, for refusing to cooperate in an investigation to find malicious domains that have been registered through its services. Namecheap impersonated Facebook’s brand name and refused to share details about the owners of the suspicious domains. Security experts at Facebook tracked down 45 suspicious lookalike domains that are registered via Namecheap. It also filed a lawsuit in Virginia against 12 hoax domain names registered by Indian-based proxy service provider Compsys Domain Solutions Private Ltd. The malicious domains spoofed Facebook and its product names to carry out unethical activities.