Home Blog Page 203

92% of SMBs Believe They Can Recover from a Cyberattack: Report

Cyber attack

According to a new research from security firm Infrascale, most small and medium-sized businesses (SMBs) believe they are prepared for a cyberattack, but only few of them are ready to deal with the outcome of such incidents.

The research stated that around 92% of SMB executives believe their organization is ready to handle cyber threats, but more than 20% don’t have a data backup or disaster recovery solution in place. It also indicated that 16% of executives in SMBs admitted that they do not know their own Recovery Time Objectives (RTOs). While 84% of the respondents said they are aware of their organizations’ RTO, the rest stated that they were not.

An RTO is the time period between the starting point of the recovery process and to the point at which all the organization’s systems and services are back to normal. It is found that 24% of SMBs expect to recover their data in less than 10 minutes after a security incident and 29% expect to do so in an hour.

While, 8% of executives in SMBs admitted that they are not prepared to recover from a security incident, 39% of them stated that they lack the budget, 37% reported lack of time to research on solutions, 32% said they don’t have the right resources, and 27% said that they don’t have the right technology to deal with cybersecurity incidents.

Russell P. Reeder, CEO of Infrascale, said, “Having a low RTO can be achieved one of two ways: you either have redundant, highly automated infrastructure or an expensive disaster recovery solution. If you’re willing to trade just a little amount of time for cost, you can achieve a reasonable RTO with an affordable disaster recovery solution, such as Infrascale. Every industry uses technology differently to achieve their business goals, which in turn will have a different requirement around the redundancy and availability of their systems. While it may be possible to have an RTO of less than one minute if you implement redundant systems, those costs usually outweigh the benefits.”

He added, “Whether a business is dealing with a server crash or a site-wide disaster, unplanned downtime comes with serious consequences. Businesses can dramatically reduce downtime, quickly recover from ransomware attacks, and avoid paying ransoms by employing disaster recovery as a service. SMBs also can get ahead of an anticipated disaster such as a hurricane by failing over to their disaster recovery solution before the disaster is expected to hit, completely mitigating any downtime.”

One in Three SMBs Rely on Free Cybersecurity Tools or Nothing

One in three small businesses with 50 or fewer employees rely on free or consumer-grade cybersecurity tools stated a research commissioned and published by BullGuard. The research also pointed out that one in five companies do not use any endpoint security whatsoever. The research, which surveyed small businesses in the U.K. and the U.S., suggested that nearly 43% SMB owners are not prepared for a potential cyberattack or breach leaving their most sensitive financial, customer, and business data at risk.

 

Snap Your Fingers Twice, Thanos Ransomware is Here!

Thanos ransomware

Cybersecurity researchers have found a new ransomware called Thanos. This ransomware is being popularly advertised in the underground market as Ransomware-as-a-service (RaaS) tool. Another reason behind its rising popularity is that Thanos is the first ransomware family that seems to exploit the RIPlace technique in the Windows file system. This technique goes undetected in most antivirus, anti-ransomware, and Endpoint Detection and Response (EDR) solutions as it bypasses the security products by replacing all sensitive files on the victim’s machine.

Thanos was initially spotted in January on an underground forum. It has been reportedly developed by a threat actor named as “Nosophoros”. However, a lot has changed since its initial emergence and now the latest feature of RIPlace technique has been integrated and used since February.

Since Thanos ransomware follows a RaaS model, the subscribers to this service are offered two packages:

  1. Light: A monthly subscription with limited capabilities.
  2. Company: A yearly subscription including additional features such as data-stealing functionalities, RIPlace technique and lateral-movement capabilities.

The other fascinating feature of the Thanos ransomware is its lateral movement which leverages SharpExec. The SharpExec tool can be downloaded from a GitHub repository and used to execute the Thanos client on remote computers.

Threat Summary
Name Thanos
Threat type Ransomware
Files Encrypted Using AES-256 in CBC mode
Programming language used for Thanos Client C#
Features & Capabilities RIPlace technique, lateral-movement, exfiltration of all files with a specific set of extensions, an anti-analysis tool allowing the client to perform several checks to determine whether it is executing within a virtual machine environment, and two obfuscation options.

 

Threat Actors Can Eavesdrop Using a Light Bulb’s Vibrations: Research

Threat Actors Can Eavesdrop Using a Light Bulb's Vibrations: Research

A group of cybersecurity researchers discovered a novel side-channel attacking technique that allows eavesdroppers to spy on conversations happening in a room from a nearby location by watching a light bulb hanging in that room.

In a research report, security researchers Ben Nassi, Yaron Pirutin, Adi Shamir, Yuval Elovici, and Boris Zadov from the Israeli’s Ben-Gurion University of the Negev and the Weizmann Institute of Science stated that a technique called “Lamphone Attack” works by capturing microscopic sound waves via an  electro-optical sensor focused at the bulb and using it to recover speech and recognize music.

“Any sound in the room can be recovered from the room with no requirement to hack anything and no device in the room. You just need line of sight to a hanging bulb, and this is it,” the researchers said.

Lamphone Attack

The Lamphone attack is based on detecting vibrations produced from hanging bulbs that are caused due to air pressure fluctuation occurred from sound waves.  The researchers stated that when sound waves hit surfaces in the room, it brings tiny changes in the bulb’s output and triggers small vibrations which will pick up bits of conversations and identify music.

“We analyze a hanging bulb’s response to sound via an electro-optical sensor and learn how to isolate the audio signal from the optical signal. Based on our analysis, we develop an algorithm to recover sound from the optical measurements obtained from the vibrations of a light bulb and captured by the electro-optical sensor. We evaluate Lamphone’s performance in a realistic setup and show that Lamphone can be used by eavesdroppers to recover human speech (which can be accurately identified by the Google Cloud Speech API),3 and singing from a bridge located 25 meters away from the target room containing the hanging light bulb,” researchers explained.

Attack Demonstration

For their experiment, the researchers set up a series of telescopes around 80 feet away from a target office’s light bulb, and kept each telescope’s eyepiece in front of a Thorlabs PDA100A2 electro-optical sensor. They also used an analog-to-digital converter to transform the electrical signals from that sensor to digital information.

“We assume a victim located inside a room/office that contains a hanging light bulb,” the researchers said. “We consider an eavesdropper a malicious entity that is interested in spying on the victim in order to capture the victim’s conversations and make use of the information provided in the conversation (e.g., stealing the victim’s credit card number, performing extortion based on private information revealed by the victim, etc.),” researchers explained.

​The Result

The researchers were able to reproduce a recording of the Beatles’ Let It Be and Coldplay’s Clocks. “We evaluated Lamphone’s performance in terms of its ability to recover non-speech audio. In order to do so, we decided to recover two well-known songs: “Let it Be” by the Beatles and “Clocks” by Coldplay. Experimental Setup: We played the beginning of these songs in the target office. In these experiments we used a telescope with a 20 cm lens diameter to obtain the optical signals via the electro-optical sensor (the internal gain of the sensor was set to 70 dB). We applied Algorithm 1 to the optical measurements and recovered the songs,” researchers added.

The researchers are planning to demonstrate this experiment at the Black Hat USA 2020 conference this August.

 

Over 100,000 Security Cameras in U.K. Are Hackable: Report

vulnerability in IoT devices

New research from consumer advocacy organization Which? revealed that more than 100,000 wireless security cameras installed in U.K. homes and businesses are vulnerable to cyber threats. Security cameras manufactured by HiChip that use software like CamHi app, Accfly, ieGeek, and SV3C might allow attackers to spy, steal personal data, or even change the camera’s password, according to Which?

“Many of these potentially vulnerable cameras are still on sale from online marketplaces such as Amazon, eBay and Wish.com, and more than 12,000 were activated in UK homes over the past three months alone,” Which? said in a security alert.

According to Which? investigation with Paul Marrapese, a U.S.-based security researcher, more than 3.5 million security cameras worldwide are still vulnerable to cyber risks. It is found that a majority of these cameras are located in Asia, and over 700,000 cameras are active across Europe, including more than 100,000 in the U.K.

Security Issues with Unsecure Cameras

Security flaws that exist in the design of the cameras’ software allow an attacker to:

  • Access the video stream of the camera to spy on homes
  • Talk to people in homes if the camera has a microphone
  • Steal or change passwords
  • Find the exact location of a home
  • Target other devices connected to a home network
  • Add one’s camera to an online botnet

The Experiment

Which? stated that they made an experiment on five wireless security cameras namely – Accfly, Genbolt, Elite Security, SV3C, and ieGeek. The researchers claimed that they were able to compromise the devices remotely. It is estimated that around 47 camera brands globally could potentially have this security flaw, including 32 brands sold in the U.K.

According to Which?, the camera brands with potential vulnerabilities include Dericam, Alptop, Luowice, Besdersec, CPVAN, Ctronics, COOAU, Jennov, LEFTEK, QZT, and Tenvis. Which? also claimed that any wireless camera that uses the CamHi app could be compromised. It also advised users with a camera working on the CamHi app to remove from their network.

 How to Protect your Security Cameras

Which? also suggested some protective measures to safeguard security cameras against potential risk. These include:

  • Change passwords. Many wireless cameras have weak default passwords, such as “admin.” Set a secure password connecting three random words that you’ll be able to remember
  • Keep your camera software updated. Not only does this keep your devices secure, but it often adds new features and other improvements
  • If in doubt, disconnect it. If you don’t use the feature that lets you remotely access the camera from your phone or tablet, it’s recommended that you disable it.

3 Critical Cybersecurity Gaps Enterprises Face with Collaboration Apps and How to Close Them

Zoom, video conferencing, webinar, zoom two-factor authentication, top data breaches of 2020

With millions of Americans and their employers adapting to government-mandated stay at home orders and social distancing advisories, it’s no surprise that we’ve seen a huge surge in the popularity of collaboration tools that allow businesses and consumers to stay connected with the outside world. Apps like Zoom, Slack, Microsoft Teams and WebEx have seen their user numbers skyrocket since businesses started to enforce work-from-home decrees to flatten the curve. In fact, Zoom added more active users (2.2M) in January and February alone than it did in the entirety of 2019. However, this rapid ascension has also spotlighted severe security vulnerabilities that adversaries have started to pick up on.

By Andrew Homer, VP of Security Strategy at Morphisec

Why? Most adversaries operate on a business model that will be familiar to those in the corporate world; they spend their time building exploits for tools that are widely used to maximize their return on investment and thus their profits. Now that collaboration tools like Zoom, Slack and WebEx are increasing in popularity, threat actors have started to focus on them. This is particularly concerning because collaboration app software providers often are not organized around quickly patching zero-days and hardening their software, largely because they have not needed to be before now. And it shows.

No less than Google, SpaceX, and even NASA, recently banned their remote employees from using Zoom. Shifts from such prominent organizations have shined a spotlight on the widely popular video conferencing tool’s security flaws. While “ZoomBombing” trolls can certainly be embarrassing, those are more pranksters than serious threat actors. What those news stories do, however, is highlight Zoom’s vulnerabilities in the face of sophisticated ransomware, zero-day attacks, and malware targeting their current weaknesses.

Just a couple of weeks ago, Morphisec Labs researchers presented a discovery that the Zoom app itself can be used as a delivery tool for recording and stealing information. A sophisticated attack using a trusted collaboration application like Zoom is particularly alarming because it is trusted, signed, and perhaps even whitelisted in some cases. As a result, an attack via Zoom likely will not flag any alarms on detection logic that might be thrown with other recording software. Traditional antivirus software would have no remedy for defending against this type of breach.  This is just one example. Another is that Zoom is vulnerable to a classic Windows  ‘UNC path injection’ revealed by a former NSA hacker, which was exploited to allow remote attackers to steal victims’ Windows login credentials or take control of the computer to run commands.

Three Critical Cybersecurity Gaps

Although Zoom is the video conferencing app most often in the news right now, its security weaknesses are not unique amongst collaboration apps. If anything, the only reason Zoom is in the news for exploits is because of its exponential user growth; threat actors see the higher user counts and likely decided to focus on building exploits to cash in. With that in mind, let’s go through what three of the biggest cybersecurity gaps are right now with collaboration tools like Zoom.

1. Collaboration Apps Cannot Patch Vulnerabilities Fast Enough

For the past 20 years, Microsoft Word and Adobe Flash have been two of the most targeted applications for cybercriminals. The reason is that these two pieces of software are ubiquitous, which appeal to financially-motivated cybercriminals looking to get the best ROI for their efforts. As a result, Microsoft and Adobe both have armies of security experts on staff to plug vulnerabilities as they appear.

With spending on collaboration applications predicted to exceed $48 billion by 2024, it’s no wonder that cybercriminals see dollar signs in this segment. Unfortunately, collaboration apps are not structured to quickly patch security flaws. The reason is simple: they haven’t been targets until now because their user numbers weren’t high enough to attract threat actors. The other problem facing collaboration app vendors is that there is a severe shortage of security experts worldwide and there are not enough tools to quickly and efficiently find flaws in these tools.

Exploiting collaboration apps can lead to remote code execution, which allows the adversary to run their malicious code on the infected machine. For example, Slack recently experienced an exploit that allowed the adversary to completely exfiltrate messages, contact lists, and every other form of data tied to the messaging application. Zoom has also recently reported several zero-day attacks, including the UNC path exploit and one that enabled attackers to install malware on targeted machines.

With unknown zero-days making up 80% of successful attacks, these widely used tools and their users are relegated to a helpless position.

2. Higher Risk of Browser-Based Attacks

Coupled with risky patching processes is a much higher risk of browser-based attacks, especially for applications like WebEx, Go to Meeting and Zoom that are accessible via a browser. This vulnerability exists because video conferencing and collaboration tools require their own code to be loaded into the browser to support their functionality. As a result, the risk of attack remains high since these vendors do not yet heavily invest in secure coding. This can lead to an attacker abusing the loaded code to eventually remotely execute code on behalf of the browser.

While sandboxing within some browsers may make this method better than relying on the applications, a recent report from Positive Technologies found that in nine times out of 10, hackers are able to easily attack website visitors and a whopping 82% of web application vulnerabilities lie in the web application’s source code.

This high risk of vulnerability via the web browser should give any IT security professional pause. Browser attacks such as drive-by downloads and browser-based phishing are at high risk with collaboration apps. This is especially true today given how exposed many of these applications are to threat actors and the rise in WFH employees.

3. Increased Risk of Successful Social Engineering Attacks

Phishing emails are the most used malware delivery mechanism today. In fact, internal data from Morphisec illustrates phishing campaigns are skyrocketing as malicious parties look to take advantage of a captive audience of work-from-home employees. Between March 8 and April 12, Morphisec saw phishing and adware attacks soar from just 2,000 dt per week to more than 90,000 dt per week.

Collaboration apps, in particular messaging tools like Slack and Microsoft Teams, provide new avenues for these bad actors to deliver phishing attacks and act upon them, while video conferencing apps especially run the risk of being used for social engineering. A successful attack in this context could result in credential-stealing on a remote employee’s machine and, if the user is an admin, the attacker could further their goals in a more streamlined manner.

Of course, adding fuel to the fire is the almost 2,000 domains containing the word ‘Zoom’ that have been created so far this year — even though Zoom isn’t the only target. Enterprises need to be wary of a magnitude of new phishing websites that have been developed to exploit vulnerable WFH employees and even parents homeschooling their children.

Attackers can use phishing tactics on remote employees to have them install a remote desktop tool, which can then be leveraged to deliver a payload. Just a few short months ago, it was discovered that ConnectWise Control was being abused to deliver the Zeppelin ransomware. So as business operations become virtual, safe browsing behavior becomes more important than ever.

How to Close Collaboration Apps’ Gaps and Counter Higher Security Risk

The world is in the middle of the greatest work-from-home experiment of all time as a result of COVID-19, and collaboration applications will only grow in importance as many enterprises recognize the financial benefits of remote working. This presages a corresponding increase in security risk, which CISOs and other security executives need to account for. To close the security gaps in collaboration apps, companies should:

  • Implement basic security hygiene measures such as two-factor authentication for password protection where possible. Also, make sure to standardize on a single video collaboration tool and set it as a hard-line policy among employees. This will help prioritize patching efforts, as well as how to plan for upgrading legacy systems and applications. This is often only a minor inconvenience for employees and goes a long way to prevent breaches.
  • Deploy more proactive defense mechanisms that can protect against malicious use of collaboration applications, unlike traditional antivirus protection. Moving target defense is one example of this type of solution, which morphs application memory and protects collaboration apps from cyberattacks by changing the structure of the application on the endpoint. This changes the targeted application from a known to an unknown, complicating the job of the hacker as suddenly they are unable to identify the target application. This also instantly protects collaboration apps against the in-memory exploits, new zero-days, fileless attacks and evasive malware that we expect to proliferate in the coming month.
  • Harden endpoints in a deterministic and automatic way to ensure full business continuity against an attack. This is a core feature of moving target defense, enabling security teams to protect applications without human intervention. This makes it easier for remote workers to access the collaboration tools they need when they need them.

Protecting Enterprises from the New Zero-Day Frontier

Despite their importance for enterprises, the reality is that collaboration applications are often unequipped for prime time. Slack, Zoom, Microsoft Teams, WebEx, Go to Meeting, and other tools all have their security flaws and will continue to be exploited now and in the future.

Compared to most other enterprise applications, they simply lack robust security posturing, making them particularly vulnerable to zero-day attacks and evasive malware. But they need to be protected more effectively against the worst cyberattacks. And this is what moving target defense excels at, including automatic hardening of remote endpoints that enable work from home employees to access the collaboration apps they need to be productive.

Moving target defense looks tailor-made for this moment, but the protection it provides only lasts as long as the collaboration apps remain in the company toolkit. Far from being an asset just to survive through COVID-19, MTD is — and should be — the centerpiece of an effective, enduring endpoint security strategy.

About the Author

Andrew Homer is VP of Security Strategy at Morphisec and has numerous years of hands-on experience creating strategic technology partnerships and leading teams through growth phases. Prior to Morphisec, he was Director of Business Development and Technology Alliances at RSA, where he led the company’s technology ecosystem, strategic alliances and embedded OEM partnerships. Homer has also held business development positions at Dell, EMC and VMware.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

 

 

Cybercriminals Attacked Unsecured Databases 18 Times Per Day

cyberattacks on U.S. and U.K., Barnes & Noble cyberattack, zero trust

Every minute is an opportunity for threat actors when they found a server left online unsecured. A latest security experiment by Comparitech led by cybersecurity researcher Bob Diachenko discovered that cybercriminals attacked a model of an unsecured database 18 times in a single day.

In a security alert, Comparitech explained how unauthorized third parties find, gain access, and alter exposed data without any authentication process, leaving users’ privacy at risk.

The company set up a honeypot to know how quickly the hackers would attack an Elasticsearch server with a dummy database and fake data in it. Comparitech left the exposed data from May 11 until May 22, 2020. It found 175 attacks in just eight hours after the server deployed, with the number of attacks in one day totaled to 22.

“The first attack came on May 12, just 8 hours and 35 minutes after deployment. Our honeypot averaged 18 attacks per day,” Comparitech said in a statement.

Image Courtesy: Comparitech

Comparitech also pointed out that hackers used IoT search engines like Shodan.io or BinaryEdge To find vulnerable servers online. “Within just one minute of being indexed by Shodan, two attacks took place. It’s worth noting that over three dozen attacks occurred before the database was even indexed by search engines, demonstrating how many attackers rely on their own proactive scanning tools rather than waiting on passive IoT search engines like Shodan to crawl vulnerable databases,” the statement added.

Attackers Location

The researchers found attackers’ locations based on their IP addresses. The highest numbers of attacks originated from:

  • 89 attacks came from the U.S.
  • 38 attacks came from Romania
  • 15 attacks came from China

Attack Methods Used

Researchers found that most requests were aimed at getting information about the status of the database and its settings. These include:

  • 147 attacks used the GET request method
  • 24 attacks used the POST method, which was particularly popular for attacks originating in China
  • One attack used the PUT method with the intent to change the server configuration
  • One attack used the OPTIONS method to get information about the connection
  • One attack used the HEAD method to get the headers of requests without receiving the responses

All attackers were not looking to steal data. Some targeted servers to mine cryptocurrency, steal passwords, and destroy data, Comparitech stated.

 

Flaw in Facebook Messenger App Allows Attackers to Run Persistent Malware

Security researchers from Reason Labs disclosed a critical vulnerability in the Facebook Messenger application for Windows that could allow attackers to hijack a call within the Messenger code to inject malware. The researchers also stated that it is a persistent threat that provides hackers undetected access to the application. The flaw was discovered in Facebook Messenger version 460.16, however, it is now fixed by the social media giant with the updated version 480.5 after Reason Labs reported the issue.

According to Reason Labs, the flaw initiates a call to load Windows Powershell from the C:\python27 path, which is generated while downloading version 2.7 of Python, and does not exist in most of the Windows installations. Cybercriminals can hijack these calls to stealthily execute malware without administrator knowledge.

GIF Courtesy: Reason Labs

In order to test the bug, Reason Labs researchers created a reverse shell  with msfvenom and a listener with Metasploit.  The reverse shell was then renamed Powershell.exe and was installed into the Python directory (c:\python27). The researchers found that the vulnerable app triggered the call and executed the reverse shell, proving that potential attackers can abuse the flaw for persistent malware attacks.

GIF Courtesy: Reason Labs

It is better to be vigilant about the potential vulnerabilities in online applications for messaging and videoconferencing, and other remote working tools, as we are spending more time online since the beginning of the pandemic. Even Facebook reported a 70% rise in time spent on its apps since the outbreak and a 50% increase in messaging apps.

 

COVID-19 Cyberthreats Spike in India, Brazil, and the U.K.: Google

COVID-19 Cyberthreats Spike in India, Brazil, and the U.K.: Google

Google has warned about the emerging COVID-19 cyberthreats in India, Brazil, and the U.K. The search engine giant stated that attackers are using malware and phishing emails that imitate legitimate financial incentives to entice users to respond.

Neil Kumaran, Gmail Security Product Manager, and Sam Lugani, Lead Security PMM for G Suite and GCP, said that they have seen an increased number of email attacks, most of them COVID-19 related scams, in the targeted countries. They also mentioned that earlier Gmail blocked 18 million malware and phishing emails, and more than 240 million spam emails daily during the pandemic.

“Specifically, we’ve been seeing COVID-19-related malware, phishing, and spam emails rising in India, Brazil, and the UK. These attacks and scams use regionally relevant lures, financial incentives, and fear to create urgency and entice users to respond,” the team said in a statement.

India

In India, Google noticed potential victims being targeted with the malicious emails that appear to come from health service providers and COVID-19 tracking apps like the Aarogya Setu app. Aarogya Setu is a smartphone application developed by the Indian government to help people assess themselves on the risk of infecting with Coronavirus.

Image Courtesy: Google

“As India is opening back up and employees are getting back to their workplaces, we’re starting to see more attacks masquerading as COVID-19 symptom tracking. And with more and more people looking to buy health insurance in India, phishing scams targeting insurance companies have become more prevalent. Often these scams rely on quoting established institutions, and getting viewers to click on malicious links,” Google said.

Brazil

In Brazil, Google warned about the surge in phishing attacks targeting streaming services due to their rising popularity, claiming the recipient will be fined if they do not respond.

Image Courtesy: Google

The U.K.

In the U.K., hackers are impersonating government organizations to steal confidential and personal information.

Image Courtesy: Google

The threat actors are designing schemes and campaigns referring to the government’s Small Business Grant Fund, in turn luring citizens into downloading malicious files.

Preventive Measures

Google also listed certain safety recommendations for users to prevent such email attacks. These include:

  • Avoid downloading files that you do not recognize; instead, use Gmail’s built-in document preview
  • Check the integrity of URLs before providing login credentials or clicking a link—fake URLs generally imitate real ones and include additional words or domains
  • Report phishing emails
  • Turn on two-step verification to help prevent account takeovers, even in cases where someone obtains your password
  • Consider enrolling in Google’s Advanced Protection Program (APP)—we’ve yet to see anyone in the program be successfully phished, even if they are repeatedly targeted
  • Be thoughtful about sharing personal information such as passwords, bank account or credit card numbers, and even your birthday

Along with social distancing guidelines, it is advisable to follow cyber precautions for seamless functioning of businesses operations.

 

 

Fake ‘Black Lives Matter’ Campaign Spreads Trickbot Malware

cyber insurance, Axio for SolarWinds Impact

Cybersecurity experts have found a fake Black Lives Matter voting campaign leveraging the popularity and sentiments of people in the ongoing protests against racism to spread Trickbot, an information-stealing malware. The phishing campaign is being touted to be run more efficiently as the fake email claims complete anonymity of the voters registered in luring potential victims.

Leveraging ‘Black Lives Matter’ Campaign

Leveraging the popularity of ongoing movements, celebrities, and the latest buzz topics, and luring potential victims into opening phishing emails is a popular trait of cybercriminals. This has been evident from earlier instances, for example, when the Emotet malware operators used environmental activist Greta Thunberg’s popularity to infect computers in Europe and Asia. The phishing emails back then looked like any other invite from Greta for a climate change summit or demonstration with email subjects carrying enticing text like “Demonstration 2019” or “I invite you.”

Similarly, pretending to be an email from the “Country administration,” the ongoing phishing campaign also targets potential victims by using subject lines such as, “Vote anonymously about Black Lives Matter.” Like other phishing campaigns, this email also contains a malicious word file as an attachment. When a user clicks on the “Enable Content” option while opening the Word file, the macros start running and downloads the Trickbot malware. When executed, this malware can further drop other payloads to carry out malicious activities.

What Trickbot Steals?

Historically, Trickbot malware is a banking Trojan. However, with time it has evolved in nature. Some of its top traits are:

  • Lateral movement in the network for maximum damage
  • Exfiltrating user credentials from browsers
  • Exfiltrating Active Directory Services databases
  • Stealing cookies and OpenSSH keys
  • Theft of RDP, VNC, and PuTTY Credentials
  • Installing additional payloads (e.g. ransomware)

 

COVID-19 Drives 79.39% Towards SaaS: CISO MAG Market Trends Report

SaaS

As the lockdown was imposed on many countries in late March 2020, most companies were forced to resort to a distributed work environment. This also boosted cloud adoption, and the demand for the SaaS model soared. This (and other cloud adoption trends) are strongly reflected in CISO MAG’s Cloud Security survey. The complete research report on Cloud Security trends is published in the June issue of CISO MAG here: https://staging-cisomag.com/magazine/

“Decision-makers in businesses of all sizes, and across geographies confirmed that cloud security is top of mind for executives as cloud adoption accelerates. These concerns are warranted, migrating to the cloud involves several risks identified in this detailed and informative survey. However, these security risks and concerns may be a result of a lack of clarity or understanding of the shared responsibility model related to security. As well as, a misconception about the potential security services available to organizations as they migrate to the cloud,” said AJ Yawn, a cloud security expert who is also on the Board of ISC2.

Key findings

  • A multi-cloud strategy is here to stay. This is reflected in our data with 19.39% having 6 or more cloud vendors.
  • Half the respondents (49.7%) opt for hybrid cloud environments and are not ready to commit fully to public or private clouds. This is due to rigid compliance and regulatory norms.
  • In the wake of COVID-19 and a distributed work environment, more organizations (39%) are opting for SaaS based delivery models, moving away from on-premise solutions.
  • Half the respondents (52.12%) said they are not confident about the public cloud because of issues like confidentiality and privacy of data.
  • There is a lack of understanding about who is responsible for security in the cloud – the customer or the cloud service provider. 76.36% said it is the responsibility of the cloud service provider.
  • 39% said they were concerned about data ownership when choosing a cloud service provider.
  • A skills gap in the security team is a major security challenge for 45.45% of respondents.
  • 88% said it is crucial to perform a proper and comprehensive risk assessment as part of the Cloud Computing project.
  • Two-thirds (66.67%) said security, privacy, and compliance should be integrated into the Cloud Computing team from the initiation of the project.

“This survey highlights the need for companies to continue to study and refine their cloud infrastructure needs and their risk appetite surrounding these services. Our results show that security is often a critical decision point, and in many cases, may be the deciding factor to move or not move a service to the cloud,” said Dick Wilkinson, Chief Technology Officer, New Mexico Judicial Information Division.

CISO MAG conducts a Cloud Security survey annually, and the last such survey (and research report) was published in July 2019.

The next CISO MAG Market Trends Report is on Data Security, and it will be published in the September issue of CISO MAG. For participation in this issue write to [email protected] or [email protected]