Home Blog Page 207

Not a Hoax! REvil Ransomware Operators Launch Auction Website

ransomware

The operators of REvil ransomware, better known as Sodinokibi, have launched an auction website on the dark web, Happy Blog, to sell stolen data from victims who have denied paying ransom.

By Pooja Tikekar, Feature Writer at CISO MAG

REvil is auctioning the stolen data of a U.S. food distributor and a Canadian agricultural company, for a starting price of $100,000 and $50,000 respectively. However, bidders are expected to agree to the following rules:

  • To bid on an auction, you must register for each auction separately.
  • After registration, you will need to make a deposit of 10% of the starting price. At the end of the auction the amount will be refunded (except for blockchain commission).
  • If you have not paid your bid on the winning auction, you will lose your deposit. This is to ensure that none of the bidders make fake bids.
  • All computational operations are performed in the cryptocurrency Monero (XMR).
  • By clicking Continue you confirm that you agree to the terms above. You will be given a username/password and details of deposit payment.

In their auction website announcement, the REvil operators hinted that other auctions are coming soon.

REvil has made dozens of high-profile victims, including healthcare facilities and local governments. Furthermore, its distributors’ toolkit has expanded way beyond leveraging unpatched software flaws to gain a foothold in computer networks. It follows a Ransomware-as-a-Service (RaaS) model and the ransoms raked in by the crooks reportedly reach hundreds of thousands of dollars per compromised organization.

REvil’s Online Auction Threats

REvil operators recently carried out a cyberattack on New York-based law firm Grubman Shire Meiselas & Sacks. In the attack, the cybercriminals claimed to have stolen nearly 756 GB data of several high-profile celebrities like Lady Gaga, Elton John, Robert DeNiro, and Madonna. Grubman Shire Meiselas & Sacks is a premier entertainment and media law firm handling the legal profiles of Hollywood A-listers. They also threatened to hold an online auction of pop sensation Maddona’s stolen data at a reserve price of $1 million.

REvil Amid COVID-19

The operators also targeted California-based biotechnology company 10x Genomics to steal sensitive information, as the firm is part of an international alliance sequencing cells from patients who have recovered from the Coronavirus.


About the Author

Pooja Tikekar is a Feature Writer, and part of the editorial team at CISO MAG. She writes news and feature stories on cybersecurity trends.

More from the author.

 

 

Hackers Selling Stolen YouTube Credentials on Dark Web: Report

Hackers Selling Stolen YouTube Credentials on Dark Web: Report

Security researchers from cyber intelligence firm IntSights revealed that they have noticed a surge in demand for stolen YouTube account credentials on several darknet forums. Researchers also stated that threat actors may use these account credentials to spread malware, launch fraud scams against viewers, or even use these it to blackmail the account owners.

“Over the past few weeks, IntSights researchers have observed yet another new trend in black markets and cybercrime forums that has rapidly growing demand: stolen credentials for prominent YouTube accounts. It should come as no surprise that global reliance on the internet has skyrocketed during quarantine, with surges in internet usage and streaming services in particular,” said Etay Maor, CSO at IntSights.

According to researchers, cybercriminals use multiple attack vectors to target YouTube channel owners. It is found that most recent accounts were stolen from databases containing Google credentials as well as from malware-infected computers.

Maor also highlighted that underground hacking forums run a quick poll to find if this is of interest to other forum members. One such poll revealed that 80% of the forum members wanted to see more YouTube credentials to be put up on sale. Researchers also found a seller auctioning over 680 accounts for a starting price of $400, some of which had over 40,000 subscribers.

Image Courtesy: IntSights

“YouTube accounts from compromised computers or from logs of credentials can be of high value. While smaller channels may not be as lucrative as larger ones, YouTubers rely on them as revenue streams and might be willing to pay money to attackers to get their content and access to their channels back. Below is an example of such a case from a Google support thread,” Maor added.

Hackers Flood Dark Web with Stolen Data

In recent security discovery, researchers found and reported a massive data breach, in which the members of the “Shiny Hunters” hacking group compromised 73.2 million user records from over 11 companies and kept them on the darknet for sale. The hackers are from the same group who are behind the Tokopedia data breach, in which 91 million user records were compromised and kept on sale on the hacking forums for $5,000. Later, the group breached India-based online learning platform Unacademy, which exposed details of 22 million users and kept the records for sale on the darknet forums for $2,000.

Several incidents have been reported in recent times on hackers selling stolen information on the darknet markets. According to Cyble, attackers were also selling over 267 million Facebook records for £500 (US$623) on dark websites and hacker forums.  The records contain information that could allow attackers to perform spear phishing or SMS attacks to steal credentials.

 

8Belts Exposes PII of e-learners in a Data Breach: Report

Data breach

Researchers from cybersecurity firm vpnMentor discovered a data breach related to a popular Spanish e-Learning platform 8Belts, exposing personal data of over 100,000s of e-learners across the globe.

In its primary investigation report, the researchers claimed that 8Belts database was stored on a misconfigured Amazon Web Services (AWS) S3 bucket which resulted in the data leakage. “By our estimates, the breach – which originated from a misconfigured Amazon Web Services S3 bucket – affected 100,000s of people across the globe, exposing their private data, and making them vulnerable to dangerous attacks and frauds from cybercriminals. By not securing its user data, 8Belts compromised the safety and privacy of its users and the future of the company itself,” the researchers said.

According to VpnMentor, the exposed database contained different forms of Personally Identifiable Information (PII) of 8Belts users, including:

  • Full names
  • Email addresses
  • Phone numbers
  • Dates of birth
  • Country of residence
  • National ID numbers
  • Skype IDs

“All of these private data could be combined and exploited in various ways to target those exposed for fraud, theft, and online attack. While most of 8Belts’ users reside in Spanish-speaking countries, people from all over the world were exposed. Records included data from residents in almost every country on the planet, across six continents. From the U.S. to Uzbekistan, Australia to Angola, Belgium to Barbados, this data breach covered the entire globe,” researchers added.

In addition to PII data, information like students’ account details, course history, performance report, courses they had taken, account user IDs, evaluation scores, and certificates of completion were also exposed in the incident.

Data Breaches on E-Learning Platforms

Recently, India-based online learning platform Unacademy suffered a data breach that exposed details of 22 million users. It was also found that the unknown hackers kept 21,909,707 user records for sale at $2,000 on darknet forums. The compromised information included usernames, hashed passwords, date of joining, last login date, account status, email addresses, first and last names, and other account profile details. Hemesh Singh, Co-founder and CTO of Unacademy, confirmed the data breach and stated that only 11 million users were affected and no sensitive information like financial data, location or passwords were exposed.

 

Security Incidents at U.S. Federal Agencies Dropped in 2019: White House

CISA VDP platform, U.S. export ban on cybersecurity items

The White House’s Office of Management and Budget (OMB) stated that the federal agencies reported fewer cybersecurity incidents, representing an 8% decrease in 2019 compared to the previous year.

According to the annual report from the Federal Information Security Modernization Act (FISMA), released by the White House, government agencies in the U.S. reported 28,581 security incidents,  compared to the 31,107 incidents reported in FY 2018.

Image Courtesy: www.whitehouse.gov

The FISMA report also included the results of 71 security audits of High-Value Assets (HVAs), critical systems deployed in various federal agencies. It stated that several critical systems used at government entities remain susceptible to cyberthreats like spear-phishing attacks. It is also found that these systems have poor patch management, password reuse, insecure default configuration, and weak password policies.

Top Attacks Reported in 2019

Image Courtesy: www.whitehouse.gov

Agencies had not identified an attack vector for close to 25% of all security incidents. “These assessments revealed that the Federal Government continues to face challenges mitigating basic security vulnerabilities,” the report said.

Major Security Incidents

According to the report, three major categories accounted for most of the incidents reported each year. The federal agencies witnessed a rise in brute-force attacks, security incidents executed with removable media (USB devices, external hard drives), and incidents caused by the improper use of a federal agency service or device. The three incidents include,

  • In January 2019, the Federal Emergency Management Agency (FEMA) inadvertently shared personally identifiable information (PII) of around 895,000 disaster survivors with a third-party volunteer organization without authorization
  • In June 2019, a ransomware attack impacted a license plate reader contractor used by the U.S. Customs and Border Protection (CBP) agency Attackers exfiltrated license plate images and facial images of drivers in their cars
  • In December 2019, DHS found that the FEMA continued sharing sensitive information of over 2.5 million hurricane survivors with a third-party contractor providing temporary shelter to victims, even after it was no longer necessary

Experts stated that the U.S. federal agencies improved their cybersecurity practices last year. According to the report, the agencies received over $17 billion in cybersecurity budgets, with most of the funds going to the Department of Defense (DOD) and the Department of Homeland Security (DHS).

 

Minnesota Websites Experience Outages Due to Cyberattacks

Minnesota cyberattacks

Trouble is brewing for Minnesota state even in the cyberworld. In the past few days, the state has seen massive protests and rampant destruction by protestors who are upset by the death of George Floyd in police custody. But now hackers have also started attacking the state’s digital assets. The Star Tribune reports that hackers forced the Minnesota State Senate website to go offline in a series of DoS cyberattacks targeting the state’s computer systems. Other websites also experienced outages due to cyberattacks. And many state agencies were targeted.

A denial of service (DoS) attack sends a high amount of traffic to a server, making it inaccessible and unresponsive to new requests.

The Star Tribune quoted Secretary of the Senate Cal Ludeman, who wrote an e-mail to staff that the Senate’s server was “hacked and accessed for several minutes” starting at 4:24 a.m. Tuesday.

The email said: To rectify the problem and prevent the spread of the attack Senate Information Technology employees “took down the server as a precaution” and are working with the Minnesota IT Services and the FBI to trace what was accessed.

The Senate Wi-Fi password was compromised but login information for senators and staff were not accessed. The Wi-Fi password has since been reset.

According to Ludeman, the same hacker group targeted 10 state agencies, including the governor’s office, in recent days.

City of Minneapolis websites also experienced outages due to a cyberattack early Thursday morning. A city spokeswoman said there was no evidence of a data breach and that most of the sites were back online by 9 a.m. that day.

It is yet to be determined whether these cyberattacks are directly linked to the protests fuelled by the death of George Floyd. But in a weekend news conference, Gov. Tim Walz said that “a very sophisticated denial-of-service attack on all state computers was executed” as the state readied its response to riots on Saturday.

RELATED STORY

Data Breach Affects Around 50,000 Patients at Minnesota Hospital

Hackers Using Steganography to Target Industrial Enterprises: Kaspersky

Hackers Using Steganography to Target Industrial Enterprises, IT security

Security experts from Kaspersky have warned about a series of attacks targeted at distributors of equipment and software for industrial enterprises globally to steal Windows credentials. It is found that attackers are using phishing scams and steganography methods to hide malware on legitimate image and file resources.

In its report, Kaspersky stated that it identified a series of targeted attacks on organizations located in Japan, Italy, Germany, and the U.K. from May 2020. Hackers used malicious Microsoft Office documents, PowerShell scripts, and other sophisticated techniques like steganography to escape detection. While the ultimate goal of the attackers is unknown, Kaspersky stated that hackers used Mimikatz utility to steal the authentication data of Windows accounts stored on a compromised system.

Phishing emails, used as the initial attack vector, were tailored and customized under the specific language for each specific victim. The malware used in this attack performed destructive activity only if the operating system had a localization that matched the language used in the phishing email,” researchers said.

Steganography

Steganography is an ancient practice of hiding secret content and text messages inside non-suspicious messages. Cybercriminals use this technique to hide malicious code within the image/audio/text file that is mainly employed by exploiting kits to hide their malvertising traffic. If the victim clicks the document, the script will execute and downloads the image hosted online which contains the malicious code.

Attack Chain

The phishing emails from attackers contain an urgent request to open the malicious attachment. Hackers send an Excel spreadsheet with a malicious macro or a malicious image (using Steganography technique) and ask users to enable active content, which triggers the malicious PowerShell script. The hidden malware will be executed when the user downloads the malicious excel sheet or the image.

Image Courtesy: Kaspersky

“The data is hidden in the image using steganographic techniques and is extracted by the malware from pixels defined by the algorithm. Using steganography enables the attackers to evade some security tools, including network traffic scanners. The data extracted from the image is consecutively encoded using the Base64 algorithm, encrypted with the RSA algorithm and encoded using Base64 again,” researchers added.

Preventive Measures

Kaspersky has also listed certain preventive measures to mitigate these kinds of attacks, these include:

  • Train employees at enterprises in using email securely and, specifically, in identifying phishing messages
  • Restrict macros in Microsoft Office documents
  • Restrict PowerShell script execution
  • Pay special attention to events of launching PowerShell processes initiated by Microsoft Office applications
  • Restrict the ability of programs to gain SeDebugPrivilege privileges
  • Install antivirus software with support for centrally managing the security policy on all systems; keep the antivirus databases and program modules of security solutions up to date
  • Use accounts with domain administrator privileges only when necessary. After using such accounts, restart the system on which the authentication was performed
  • Implement a password policy with password strength and regular password change requirements
  • If it is suspected that some systems are infected, scan these systems with antivirus software and force a change of passwords for all accounts that have been used to log on to compromised systems

 

Indian Payments App BHIM Exposed to a Massive User Data Breach, NPCI Denies

Indian Payments App BHIM Exposes 7.26 Mn User Data, NPCI Denies

Security researchers from vpnMentor discovered a massive data breach (estimated 7.26 million), which exposed records connected to  India’s mobile payments app BHIM (Bharat Interface for Money). The website in question (www.cscbhim.in.) was developed by developed by a company called CSC e-Governance Services LTD. in partnership with the Indian government.

In vpnMentor’s investigation report, the researchers stated that the website is used to promote BHIM usage across India and to sign up new merchant businesses.  BHIM app was launched by the non-profit business consortium, the National Payments Corporation of India (NPCI), to increase cashless transactions in India.

The data was exposed through a misconfigured Amazon Web Services (AWS) S3 storage bucket containing 409 GB of data. The website leaked sensitive profile and financial data, including names, dates of birth, age, gender, home address, caste status, Aadhaar card details, biometric details, profile photos, fingerprint scans, photos used as proof of residence, professional certificates, PAN numbers, ID numbers for government programs and social security services.

“The scale of the exposed data is extraordinary, affecting millions of people all over India and exposing them to potentially devastating fraud, theft, and attack from hackers and cybercriminals,” the researchers said.

NPCI Denies Data Leak

In a statement, the NPCI clarified that there was no data breach through the BHIM app. “We have come across some news reports which suggest data breach at BHIM App. We would like to clarify that there has been no data compromise at BHIM App and request everyone to not fall prey to such speculations. NPCI follows high level of security and an integrated approach to protect its infrastructure and continue to provide a robust payments ecosystem,” the NPCI said.

Security Incidents on Indian Firms

Recently, India-based online learning platform Unacademy suffered a data breach that exposed details of 22 million users. It was also found that the unknown hackers kept 21,909,707 user records for sale at $2,000 on darknet forums. The compromised information included usernames, hashed passwords, date of joining, last login date, account status, email addresses, first and last names, and other account profile details. Hemesh Singh, Co-founder and CTO of Unacademy, confirmed the data breach and stated that only 11 million users were affected and no sensitive information like financial data, location or passwords were exposed.

 

Organizations with Understaffed Security Roles are Prone to Attacks: ISACA

Whistle-Blower Reports to ICO Increase by 34% in the Last Year

The new survey report from Information Systems Audit and Control Association (ISACA) states that organizations with understaffed cybersecurity roles and teams are less confident in their ability to respond to threats and are exposed to a greater number of cyberattacks.

The survey “The State of Cybersecurity 2020 Survey Report” revealed that only 21% of significantly understaffed respondents admitted that they are confident in their organization’s ability to respond to threats, while  respondents who indicated that their enterprise was appropriately staffed to face threats have 50% confidence level . The survey also revealed that enterprises are struggling to fill security roles due to the time it takes to hire,  leaving a majority of organizations (62%) understaffed.  Around 35% of enterperises that take three months to hire security personnel reported an increase in attacks and 38% from those taking six months or more.  In addition, 42% of organizations that are unable to fill open security positions are experiencing more attacks.

Most Reported Attack Types

According to the survey findings, most respondents believe that their organization will be hit by a cyberattack soon, with 53% thinking it is likely they will experience one in the next 12 months. Cyberattacks are also continuing to increase, with 32% of respondents reporting an increase in the number of attacks relative to a year ago.

The survey also listed the top attack types, which include social engineering (15%), advanced persistent threat (10%) and ransomware and unpatched systems (9%). It also stated that a majority of respondents believe that cybercrime remains underreported, with 62% of security professionals believing that enterprises are failing to report cybercrimes, even when they have a legal or contractual obligation to do so.

Only 30% of those surveyed use artificial intelligence and machine learning solutions as a direct part of their security operations for fighting the cyberattacks.

“These survey results confirm what many cybersecurity professionals have known for some time and in particular during this health crisis—that attacks have been increasing and are likely to impact their enterprise in the near term. It also reveals some hard truths our profession needs to face around the need for greater transparency and communication around these attacks,” said Ed Moyle, lead writer of the report.

“Security controls come down to three things—people, process and technology—and this research spotlights just how essential people are to a cybersecurity team. It is evident that cybersecurity hiring, and retention can have a very real impact on the security of enterprises. Cybersecurity teams need to think differently about talent, including seeking non-traditional candidates with diverse educational levels and experience,” said Sandy Silk, CISSP, Director of IT Security Education & Consulting, Harvard University, and ISACA cybersecurity expert.

 

 

StrandHogg 2.0 Impersonates Real Android Apps to Steal User Data

StrandHogg 2.0 Vulnerability

Researchers at Promon, a cybersecurity firm better known for its in-app security protection, had earlier discovered a vulnerability in the Android operating system named “StrandHogg”. This vulnerability enabled cybercriminals to hijack legitimate apps and perform malicious operations. But having learned from its shortfalls, the StrandHogg 2.0 vulnerability now enables cybercriminals to hijack nearly any app running on Android 9.0 devices and below.

StrandHogg 2.0 Vulnerability

The Promon researchers found a new elevation of privilege vulnerability classified as “critical severity” (CVE-2020-0096) by Google. One of the reasons for its severity being termed as “critical” is because it allows cybercriminals to gain access to almost all apps. The earlier version of StrandHogg exploited the Android control setting ‘TaskAffinity’, which hijacked Android’s multitasking feature and, as a result, left behind traceable markers. However, this was worked around in StrandHogg 2.0 as it does not exploit the Android control setting ‘TaskAffinity’ and thus difficult to detect.

StranHogg 2.0 Vulnerability
Image Source: Promon
The StrandHogg 2.0 vulnerability allows potential cybercriminals to take app controls and:
  • Listen and record user and phone call conversations through the microphone
  • Unknowingly take camera controls and click photos
  • Read and send SMSs
  • Exfiltrate users’ login credentials used in different mobile apps and accounts
  • Access and exfiltrate data files and photos from the device
  • Track device location and gain GPS information
  • Access the contacts list on the device
  • Access phone logs

StrandHogg 2.0 vulnerability is a severe threat as it could be exploited without gaining root access, however, it has not yet been exploited in the wild. Meanwhile, Android has already rolled out security patches for its Android ecosystem partners in April 2020 and was expected to apply the same to the current Android versions 8.0, 8.1, and 9.0 soon after.

The Underbelly of COVID-19: Malware and Ransomware Ramp Up

covid-19 malware ransomware, netwalker ransomware

Cybercriminals are known to leverage global phenomena for personal gain, be it the elections or the Olympic Games. And COVID-19 is no different. Scammers are using the pandemic to capitalize on a public scare that is already dire.

By Pooja Tikekar, Feature Writer at CISO MAG

Hackers are using social engineering tools to formulate phishing emails in the name of the World Health Organization (WHO) and other regulatory bodies to target vulnerable victims. These phishing emails contain documents with embedded links that result in malware and ransomware attacks.

Here are some of the COVID-19-themed cyberthreats:

1. CovidLock

The security team at DomainTools discovered a domain (coronavirusapp[.]site), which claims to have a real-time Coronavirus Tracker. It poses as a download site for an Android app that maps the spread of the virus across the globe. However, the app has a hidden ransomware application named “CovidLock” that threatens to delete contacts, pictures and videos on the victims’ device if a ransom of $100 in Bitcoin is not paid within 48 hours.

Image source: DomainTools

2. Dharma (CrySIS)

Dharma belongs to the family of CrySIS malware and was first discovered in 2016. The malware is distributed in malicious email attachments to deliver the payload. The payload is attached as an executable file by name “1covid.exe,” which begins to encrypt files after it is downloaded. The encrypted files have an extension called “.ncov” (supposedly Novel Coronavirus). It also drops a ransom note prompting users to write an email to “[email protected]” to restore their files.

dharma ransom note
Image source: Quick Heal

3. Emotet

The Emotet malware spam (malspam) emails contain a warning note and call to action for downloading a malicious Word doc attachment, which is said to contain precautionary health measures and latest updates related to Coronavirus. On opening the attachment and enabling macros in Office 365, an obfuscated VBA macro script begins to run in the background, which further installs a Powershell script and downloads the Emotet malware. The Emotet script also downloads a few other malicious payloads to extract additional data from the targeted system.

4. Maze

Maze ransomware was discovered in 2019, however, amid the Coronavirus crisis, it is used to target health care organizations. It threatens to publish patient records online, thereby putting the health care organizations at risk of the immediate violation of the General Data Protection Regulation (GDPR). According to DataBreaches.net, the operators of Maze ransomware attacked the London-based clinical testing firm Hammersmith Medicines Research, as it has volunteered its services to the U.K.’s National Health Service (NHS) and local medical practices to help test medical frontline staff for COVID-19.

maze ransom note
Image source: Wikimedia Commons

5. REvil

Also known as Sodinokibi, the REvil ransomware operators are targeting managed service providers (MSPs) and local governments amid the pandemic. The operators scan the internet for vulnerable machines to deploy the malware payload through a Virtual Private Network (VPN). The operators targeted and infected California-based biotechnology company 10x Genomics to steal sensitive information, as the firm is part of an international alliance sequencing cells from patients who have recovered from the Coronavirus.

6. NetWalker

A variant of Mailto, the NetWalker ransomware targets home and corporate computer networks to encrypt the files it finds. It targets victims by sending phishing emails attached to execute the payload of the ransomware. Further, the file name “CORONAVIRUS_COVID-19.vbs” tricks users into executing it. Once the “vbscript” is executed, the ransomware is dropped in “C:\Users\<UserName>\AppData\Local\Temp\qeSw.exe.” The shadow copies are erased from the system, making safe file recovery difficult.

netwalker ransom note
Image source: McAfee

7. Ginp

Kaspersky researchers have discovered the Ginp Banking Trojan that takes advantage of Android users to steal credit card credentials of potential victims. Once the Ginp is downloaded on the victims’ phone, the attacker sends a special command to the Trojan to open a web page titled “Coronavirus Finder.” The Coronavirus Finder web page displays the number of people infected with the virus near the victim’s location. It then asks them to pay 0.75 Euros to see the location of the virus-infected persons. If the victims agree to pay, the Trojan redirects them to a payment page, where the payment details need to be entered. Once the details are entered, the victims are neither charged, nor do they receive any information about the location of the infected persons. Instead, the credit card details of the victims are accessed.

 Conclusion 

These are dark times and scammers are taking full advantage of the pandemic to lure ordinary people into clicking on links related to COVID-19. It is essential to be cautious because one downloaded attachment or one click on the wrong link could lead to a disaster.


About the Author

Pooja Tikekar is a Feature Writer, and part of the editorial team at CISO MAG. She writes news and feature stories on cybersecurity trends.

More from the author.