Home Blog Page 204

FBI Warns About Fake Mobile Banking Apps, Trojans

The FBI recently issued a warning about threat actors targeting users with fake banking apps to compromise bank accounts, as more people are using online banking during the coronavirus pandemic.

In an official statement, the FBI stated that online and mobile banking apps witnessed a 50% surge in usage since the beginning of 2020. Citing the U.S. financial data study, FBI stated that 36% of Americans plan to use mobile applications for various banking activities, and 20% of them plan to visit branch locations less often. “With city, state, and local governments urging or mandating social distancing, Americans have become more willing to use mobile banking as an alternative to physically visiting branch locations,” FBI said.

Fake Banking Apps and Trojans

It is expected that cybercriminals try to abuse new mobile banking customers through app-based banking trojans and fake banking apps. The FBI advised the public to be cautious while downloading banking apps, as hackers spread fake apps concealing malicious intent in them. This incident reminds us about the detection of 65,000 fake apps on major app stores in 2018, by U.S. research organizations.

“Cyber actors target banking information using banking trojans, which are malicious programs that disguise themselves as other apps, such as games or tools. When the user launches a legitimate banking app, it triggers the previously downloaded Trojan that has been lying dormant on their device. The Trojan creates a false version of the bank’s login page and overlays it on top of the legitimate app. Once the user enters their credentials into the false login page, the Trojan passes the user to the real banking app login page so they do not realize they have been compromised,” the FBI said in a statement.

Preventive Measures

The FBI recommended certain security measures to defend against banking Trojan attacks, these include:

  • Enable two-factor or multi-factor authentication on devices and accounts to protect them from malicious compromise
  • Use strong two-factor authentication if possible, via biometrics, hardware tokens, or authentication apps
  • Use multiple types of authentication for accounts if possible. Layering different authentication standards is a stronger security option
  • Monitor where your Personal Identifiable Information (PII) is stored and only share the most necessary information with financial institutions
  • Use passwords that contain upper case letters, lower case letters, and symbols.
  • Use a minimum of eight characters per password
  • Create unique passwords for banking apps
  • Use a password manager or password management service

 

June 2020 Patch Tuesday: Microsoft Fixes 129 CVEs

Microsoft September 2021 Patch Tuesday

Microsoft released its June 2020 Patch Tuesday software security update to fix a total of 129 newly discovered CVEs (Common Vulnerabilities and Exposures) affecting various versions of Windows operating systems and related software products.

The security patches apply to various Microsoft products including Microsoft Windows, Microsoft Edge, ChakraCore, Internet Explorer, Microsoft Office, Microsoft Office Services and Web Apps, Windows Defender, Microsoft Dynamics, Visual Studio, Azure DevOps, Adobe Flash Player, and Microsoft Apps for Android, according to Microsoft’s advisory.

The “June 2020 Patch Tuesday” is  Microsoft’s biggest patch Tuesday security update ever. It released  115 patches in March 2020, and 113 fixes in April 2020. Of 129 vulnerabilities, the tech giant classified 11 as critical, 109 as important, 7 as moderate, and 2 as low in risk severity.

Critical Vulnerabilities

Microsoft stated that three critical vulnerabilities exist in Microsoft Edge and VBScript engine that could allow hackers to perform remote code execution by tricking a user into visiting a maliciously crafted web site. These vulnerabilities include:

Other critical vulnerabilities would require an attacker to trick users into downloading specially designed malicious files. If abused, these vulnerabilities could allow an attacker to execute commands on the targeted device with the same privileges as the user. These include:

Satnam Narang, Staff Research Engineer at Tenable said, “Microsoft continues its streak of releasing patches for over 100 CVEs, as June 2020s Patch Tuesday release contains fixes for 129 CVEs, 11 of which are rated as critical. For the second month in a row, none of the vulnerabilities patched this month were exploited in the wild nor publicly disclosed. Most notably in this month’s release are a trio of fixes for vulnerabilities in Microsoft Server Message Block (SMB), two of which reside in SMB version 3.1.1 (SMBv3),”

Microsoft urged system administrators and users to install these updates as soon as possible to protect their devices from privilege escalation and spoofing attacks. “These updates are intended to help our customers keep their computers up-to-date. We recommend that you install all updates that apply to you,” Microsoft said.

 

Cyber 9-Line: The 911 for Reporting Malware Threats

National security Agency

The U.S. Cyber Command (USCYBERCOM) in collaboration with the country’s National Guard has launched a malware sharing portal, “Cyber 9-Line.” This portal is created with the intent of sharing common knowledge related to cyberthreats and attacks carried out by foreign adversaries and securing the country’s cyberspace.

How Cyber 9-Line Works

The Cyber 9-Line helps the National Guard units and USCYBERCOM to stay in sync by rendering quick communication of a cyber incident on a two-way channel. These reports are then shared with the Cyber National Mission Force (CNMF), who further diagnose the cyberattack to determine the motive and source of the adversary. Eventually, the feedback from the investigation is shared with the two agencies as well as with the state and county governments to address and restrict the cyber incident. This process is key in decreasing the latency of incident response and strengthening the cybersecurity across various verticals in the government and nation.

Cyber 9-Line, however, is not just limited to acting as a communication channel. The reporting and feedback from this system is added to the unclassified cyber Big Data Platform (BDP). This increases the critical defense capabilities and provides matching and analysis of previously known malware records to further reduce latency and deploy proactive cybersecurity measures in a shorter span.

What NSA Says…

According to the National Security Agency (NSA),  most states and territories have scheduled the Cyber 9-Line training and/or are establishing their accounts. However, 12 states have already completed the registration process and begun leveraging the resources on offer. NSA also accepted that their foremost priority at this moment is securing the 2020 Presidential elections.

U.S. Army Brig. Gen. William Hartman, who also leads the USCYBERCOM’s Election Security Group and is a CNMF Commander said, “This level of cooperation and feedback provides local, state and Department of Defense partners with a holistic view of threats occurring in the United States and abroad. Dealing with a significant cyber incident requires a whole-of-government defense; bidirectional lines of communication and data sharing.”

Thus, this is a foot in the right direction for improving cybersecurity measures in the country.

 

Ransomware Threats Surge by 25% in Q1 2020: Report

Ransomware attacks, LockBit Ransomware

A new report from specialist insurance firm Beazley reported a 25% increase in ransomware attacks in the Q1 of 2020, compared to Q4 of 2019. The “Beazley Breach Insight Report” stated that nearly all businesses reported security incidents during Q1 of 2020. The manufacturing sector reported the highest number of incidents, with a 156% increase in incidents quarter-on-quarter.  Apart from the manufacturing sector,  the most affected sectors continue to be financial services and healthcare, which together accounted to almost 50% of all ransomware attacks reported in Q1 of 2020.

Image Courtesy: www.beazley.com

According to the report, ransomware attacks against vendors and managed service providers (MSPs) continued to be a major security concern in Q1 2020. The attacks against MSPs also affected banks, credit unions, and health care providers.

The COVID-19 Impact

While threat actors focused on COVID-19 related ransomware attacks, business email compromise (BEC)  eased in Q1 2020.

Image Courtesy: www.beazley.com

“While the financial services, health care and retail sectors reported fewer BEC incidents than in Q4, this may prove to be a temporary reprieve tied to behavioral changes amid the response to COVID-19. Employees first adjusting to working from home may have been less responsive to emails generally, and organizations may have been more focused on quickly ramping up remote working capacity than on identifying and reporting BEC incidents,” the report said.

Katherine Keefe, Head of BBR Services, said: “Cybercriminals are preying on people’s heightened anxiety during this pandemic, tricking them into clicking and sharing links that steal information. Also, those working from home may have weaker IT security than corporate networks typically provide. Organizations must ensure their security systems and protocols are up to date and ensure that colleagues working from home are extra vigilant.”

The research findings are based on the number of security incidents reported to Beazley’s in-house breach response team Beazley Breach Response (BBR) Services.

 

Advancing Your Cybersecurity Program Past the Crisis

Harness Your System, Free Decryptor, federal government, cybersecurity

COVID-19 forced enterprises to transition to a distributed, remote workforce almost overnight. As employees brought their offices home, cybersecurity teams had to suddenly adjust their practices and priorities. The security architecture you may have scrambled to build within an unreasonable timeline includes desirable properties you likely were planning to implement anyway. Once you have a chance to strategize, you will be able to use them to advance your cybersecurity program for the long term.

By Lenny Zeltser, CISO at Axonius

The shift from security paradigm grounded in a traditional network perimeter began years ago, driven in part by the popularity of SaaS products, which were easier to deploy and use than the applications that enterprises needed to manage themselves. Cloud computing made it possible to run code away from the local environment and enabled businesses to spend less and move more swiftly. Also, organizations started warming up to the idea of at least some employees working remotely.

So, even before the pandemic, cybersecurity teams needed to start accommodating:

  • Sensitive connections traversing untrusted networks
  • Transactions originating from potentially unmanaged computers
  • Business logic running on infrastructure managed by others
  • Web-based applications provided as a service by third parties

The ruthless fervor of the COVID-19 pandemic did not impose many new cybersecurity requirements. Instead, the sudden dispersal of the employees dramatically accelerated pre-existing trends. That is why many of the security measures you may have rushed to implement will serve you well in the long term.

The challenge is that when rushing to support a suddenly distributed workforce, you may have had to make in-the-moment decisions related to a variety of risks that usually would take months if not years to address:

  • When you cannot trust the network, how can you protect the data from being intercepted or modified?
  • When there is no network perimeter, how can you defend and safely manage your endpoints?
  • When you rely on someone else’s apps and infrastructure, how can you live up to SLAs and track security metrics?
  • When you lack centralized visibility into major aspects of your IT operations, how can you oversee their security and respond to incidents?

Fortunately, there is a security model that offers guidance for addressing such risks. It is called Zero Trust. John Kindervag, who coined this term back in 2010, explains that this paradigm “examines information about the device, its current state, and who is using it” when making security decisions. As described in the recent Zero Trust Architecture document by NIST, the idea is to narrow the sphere of trust from large networks protected by a perimeter to components, such as endpoints and users.

Zero Trust, as NIST puts it, “is a response to enterprise trends that include remote users and cloud-based assets.” This is the very configuration you are supporting due to the pandemic, so even if you weren’t sure how to begin your journey toward Zero Trust, COVID-19 forced you to advance down this path even.

When you get a chance to shift focus from tactical to the strategic planning of your security program, look at Zero Trust guidelines from the sources and people you trust. You will discover that your Zero Trust journey will likely include:

  • Centralizing identity management using a provider that can integrate cloud, SaaS, and on-premise applications.
  • Minimizing reliance on VPNs, so having access to a particular (once-trusted) network doesn’t give the user special privileges.
  • Strengthening your endpoints’ security posture with the help of modern systems management, Mobile Device Management (MDM), and anti-malware tools.
  • Implementing Single Sign-On (SSO) in a way that allows you to make access decisions based on multiple factors, such as the state of the user’s device.
  • Automating user provisioning and de-provisioning based on people’s business needs in a way that incorporates the principle of least privilege.
  • Gathering IT asset data from all components of your heterogeneous environment to maintain asset inventory and identify security gaps.

The business requirements of your organization today–remote workforce, distributed endpoints, heavy reliance on SaaS and cloud services–likely represent the ongoing needs of the enterprise. Take a look at the current state of your crisis-induced cybersecurity program. Decide which aspects of it you want to keep and which you will need to change once you are no longer in crisis mode. Consider using Zero Trust principles as guidelines. You might find that the work you have already done has advanced your program farther than you were expecting.

About the Author

Lenny ZeltserLenny Zeltser is the Chief Information Security Officer at Axonius, a cybersecurity asset management company, tackling foundational IT asset management challenges to dramatically improve organizations’ cybersecurity posture. Previously serving as VP of Product, Zeltser now focuses on protecting the company’s information assets, expanding its security architecture, and advocating a strong security culture to help enable the business. He previously led security product management at Minerva Labs and NCR.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

60% of Organizations Believe to Likely Suffer Email Borne Attacks

BEC Scammers Exploit Email Auto-Forwarding Rules, FBI warns

A survey from email and data security firm Mimecast revealed that nearly 60% of organizations believe that they will likely suffer from an email-borne attack in the coming year. And 77% of respondents stated that they are introducing a cyber resilience strategy, with 31% of respondents citing data loss; 31% of them stated a decrease in employee productivity, and 29% reported business downtime due to lack of cyber resilience preparedness.

According to the report, “State of Email Security 2020 Report,” domain-spoofing and email-spoofing have become mainstream attack vectors, and 49% reported that they are expecting an increase in web or email spoofing and brand exploitation in the next 12 months. While 84% of respondents feel concerned about an email domain, web domain, brand exploitation, or site spoofing attack.

Old Threats Continue to be a Major Concern

The study also stated that impersonation attacks, phishing attempts, and ransomware continue to be major security concerns, and 72% of respondents reported phishing attacks remained flat or increased in the last 12 months; 74% reported the same about impersonation attacks. “Ransomware also continues to wreak havoc, as just over half of respondents (51%) said ransomware attacks impacted their organization, citing data loss, downtime, financial loss and loss of reputation or trust among customers,” the report said.

Need for Strong Security Awareness

The report highlighted that there is a strong need for a more cyber aware workforce, with 97% of organizations stating that they offer security awareness training to their employees. However, 60% of them reported they have been hit by malicious activity spread from employee to employee.

Joshua Douglas, Vice President of threat intelligence at Mimecast, said, “We are seeing the same threats that organizations have faced for years playing out with tactics matched to world events to evade detection. The increases in remote working due to the global pandemic have only amplified the risks businesses face from these threats, making the need for effective cyber resilience essential. It is likely that cyber resilience strategies are lacking key elements, or do not have any at all, depending on the organization’s maturity in cybersecurity.

“Security leaders need to invest in a strategy that builds resilience moving at the same pace as digital transformation. This means organizations must apply a layered approach to email security, one that consists of attack prevention, security awareness training, roaming web security tied to email efficacy, brand exploitation protection, threat remediation and business continuity,” Douglas added.

The survey report is based on the views of 1,025 global IT decision makers on the present state of cybersecurity.

Dark Basin Hack-For-Hire Group Exposed for Targeting Organizations Globally

Compromised Email Accounts

A hack-for-hire campaign has targeted thousands of users and hundreds of organizations across six continents over the past several years, according to a report from Citizen Lab, a laboratory-based at the Munk School of Global Affairs and Public Policy of the University of Toronto.

Dubbed as “Dark Basin,” Citizen Lab linked the hacker group to an Indian technology firm BellTroX InfoTech Services and related entities. It is found that the group spied on American nonprofits, senior politicians, government prosecutors, CEOs, journalists, and human rights defenders.

Based on its investigation that started in 2017, Citizen Lab discovered around 28,000 shortened URLs containing e-mail addresses of targets.  Dark Basin was Initially suspected as a state-sponsored campaign but was later identified as a hack-for-hire operation. The group is likely behind the commercial espionage on high-profile public events, criminal cases, financial transactions, news stories, advocacy groups,  hedge funds, and multiple industries.

“Over the course of our multi-year investigation, we found that Dark Basin likely conducted commercial espionage on behalf of their clients against opponents involved in high profile public events, criminal cases, financial transactions, news stories, and advocacy,” Citizen Lab said.

Links to Indian Firm

Citizen Lab stressed this cyber-espionage is the work of BellTroX InfoTech Services. Surprisingly, the BellTrox’s director, Sumit Gupta (also known as Sumit Vishnoi), was indicted in 2015 by the U.S. authorities for participating in a similar hack-for-hire scheme, including crimes related to a conspiracy to access the e-mail accounts, Skype accounts, and computers of clients.

“To our knowledge, Gupta was never arrested in relation to the indictment. An aggregator of Indian corporate registration data lists Sumit Gupta as the director of BellTroX, and online postings by a ‘Sumit Vishnoi’ contain references to BellTroX,” Citizen Lab said.

Citizen Lab attributed Dark Basin operations to India as hundreds of phishing emails related to them show timestamps consistent with working hours in India’s time zone (UTC+5:30), and the same timestamps were observed in phishing kit source code that was left open online by the group. Several URL shortening services had names associated with Indian words like Holi, Rongali, and Pochanchi.

Image Courtesy: Citizen Lab

Targeting American Organizations

Dark Basin hacking group targeted American advocacy organizations working on domestic and global issues, including the climate advocacy organizations and net neutrality campaigners. “Dark Basin has a remarkable portfolio of targets, from senior government officials and candidates in multiple countries, to financial services firms such as hedge funds and banks, to pharmaceutical companies,”  Citizen Lab added.

Security pros at CitizenLab discovered a cluster of targeted individuals and organizations that were engaged in environmental issues in the U.S. In 2017, Citizen Lab contacted these organizations, which are linked to the #ExxonKnew campaign, to determine the nature and scope of the attacks.

In 2016, the campaigners of #ExxonKnew were invited to a private meeting via a secret email, which was later leaked to two newspapers. According to Citizen Lab, two recipients of the leaked email were identified as the targets of Dark Basin group. The targeting spiked in February and March 2016, and then in June and July 2017.

Image Courtesy: Citizen Lab

Some other targeted organizations include Rockefeller Family Fund, Climate Investigations Center, Greenpeace, Center for International Environmental Law, Oil Change International, Public Citizen, Conservation Law Foundation, and Union of Concerned Scientists.

“We were able to identify several BellTroX employees whose activities overlapped with Dark Basin because they used personal documents, including a CV, as bait content when testing their URL shorteners. They also made social media posts describing and taking credit for attack techniques containing screenshots of links to Dark Basin infrastructure. BellTroX and its employees appear to use euphemisms for promoting their services online, including ethical hacking and certified ethical hacker,” Citizen Lab said.

Citizen Lab notified hundreds of targeted individuals and organizations and provided with assistance in tracking and identifying the hacking campaign. It also shared its investigation findings with the U.S. Department of Justice (DOJ).

 

Double the Trouble: Nintendo Revises Data Breach Numbers to 300,000

Nintendo data breach, data breach

Japanese consumer electronics and video game giant, Nintendo, had earlier admitted that over 160,000 of its gamers’ accounts had been hacked by cybercriminals. However, further internal investigations have now confirmed that another 140,000 user accounts were compromised, taking the tally to 300,000 affected accounts.

The Nintendo Data Breach

Nintendo has a unique NNID (Nintendo Network ID) for all its users. NNID acts like a user ID, which can be linked to the Nintendo account and used optionally for login purposes. However, the cybercriminals exploited this NNID login system, and illicitly gained access into the Nintendo accounts linked to it. The cybercriminals further had access to users’ nicknames, dates of birth, countries, email addresses, and other information linked to the NNIDs which posed a severe identity theft threat. The worst nightmare, however, came true when some users started reporting suspicious activities on their accounts. One of the users reported, “Someone hacked my PayPal and spent $200 on Nintendo games.”

Even after revising the numbers, Nintendo confirmed that less than 1% of all NNIDs around the world may have been illegally logged in been fraudulently traded.

Nintendo informed its users in an official release that due to the amount of damage caused and as a foot forward in a secure direction it is “now abolishing the function to log in to a Nintendo account via NNID.” As part of additional security measures, Nintendo informed its users of a sequential password reset for all affected NNIDs and Nintendo accounts. It has also urged its users to integrate a two-step verification process and usage of different passwords for all their NNIDs and Nintendo accounts to prevent such mishaps in the future.

It is essential to find and report new threats as users can take further measures to avoid identity theft and subsequent monetary losses.

Facebook Sues Indian Firm for Registering Impostor Domains

facebook - sue/lawsuit

Facebook filed a lawsuit in Virginia against 12 hoax domain names registered by Indian-based proxy service provider Compsys Domain Solutions Private Ltd. The malicious domains spoofed Facebook and its product names to carry out unethical activities.

The social networking giant claimed that imposter domains like facebook-verify-inc.com, instagramhjack.com, and videocall-whatsapp.com were designed to mislead people. Facebook also stressed that registrars and proxy service providers have a responsibility to take down fraudulent and malicious websites.

Christen Dubois, Facebook’s Director and Associate General Counsel of IP Litigation, said, “We regularly scan the internet for domain names and apps that infringe on our trademarks and today’s lawsuit is part of this ongoing effort to protect people from phishing, credential theft and other methods of online fraud. We filed suit after we reached out to Compsys about these domain names and did not receive any response.”

Lawsuits Filed Earlier

This is not the first time Facebook took legal action against imposter domains. Recently, it filed a similar lawsuit against Namecheap,  Arizona-based provider of domain name registrars online, for refusing to cooperate in an investigation to find malicious domains that have been registered through its services. Facebook said that Namecheap impersonated its brand name and refused to share details about the owners of the suspicious domains. Security experts at Facebook tracked down 45 suspicious Facebook lookalike domains that are registered via Namecheap.

Earlier, the Israel-based cyber intelligence firm NSO Group was sued by Facebook for violating the Computer Fraud and Abuse Act. According to the lawsuit filed in the federal court, the NSO Group deployed its custom malware on around 1,400 WhatsApp installed mobile devices in April and May 2019. WhatsApp revealed that it discovered a vulnerability in its network system that allowed hackers to install spyware via an infected WhatsApp voice call. It stated that the spyware can exploit the mobile device, its calls, and texts; it activates the phone’s camera, microphone, and also performs other malicious activities.

 

Unisys Supports Cyber4Healthcare Program to Make Cyberspace More Secure

healthcare cybersecurity, Nucleus:13

Information technology company Unisys Corp. will be supporting CyberPeace Institute’s Cyber4Healthcare initiative to ensure hospitals and health care organizations are protected against the increasing cyberattacks amid the Coronavirus outbreak. The Cyber4Healthcare program is designed to offer free cybersecurity services to health care front-line workers fighting the pandemic.

By Pooja Tikekar, Feature Writer at CISO MAG

The program also calls for a stop to cyberattacks on hospitals, health care and medical research facilities and holds attackers accountable with international law wherever possible.

Unisys will also offer pro bono online consultations to help health care organizations address grave areas of cyber defense such as:

  • How to minimize the effect of ransomware within an organization by leveraging proven strategies like Zero Trust and network architectures like micro-segmentation
  • How to safely extend cyber perimeters to include work-from-home (WFH) with better identity and encryption practices
  • A “spot check” of current cyber risk based on an individual organization’s operational goals

Tom Patterson, Chief Trust Officer, Unisys, said, “We know that adversaries can attack our most critical infrastructures through the click of a single WFH employee. That’s why Unisys will stand with government, industry and academic leaders around the world to safeguard patient data, testing information and intellectual property so that our medical workers on the frontline can focus on delivering care to patients in their hour of need.”

Ransomware Attacks Against Hospitals

INTERPOL issued a warning to hospitals and other organizations on the COVID-19 front line about the surge in ransomware attacks. INTERPOL’s Cybercrime Threat Response team detected that hackers are holding medical institutions hostage and demanding ransom in exchange for access to vital digital files.

WHO Urges Cyber Vigilance

The World Health Organization (WHO) reported a fivefold increase in cyberthreats directed at its staff and the public through email scams. In April, around 450 active WHO email addresses and passwords were leaked online, however, the leaked credentials did not impact the organization as the data was not recent. It stated that cybercriminals are formulating phishing emails in the name of WHO and other regulatory bodies, in an attempt to lure potential victims to give sensitive information, download a malicious attachment, or open a malicious link.


About the Author

Pooja Tikekar is a Feature Writer, and part of the editorial team at CISO MAG. She writes news and feature stories on cybersecurity trends.

More from the author.