Home Blog Page 208

Hackers Sell 80K Stolen Credit Card Details on Dark Web

one million card data exposed

Cybersecurity research firm Cyble recently disclosed that threat actors kept details of 80,000 credit cards on the darknet forum for sale in exchange for cryptocurrency. It was found that the stolen credit card details include both Visa and MasterCard users from various countries, which include:

  • 33,000 credit card details from the U.S.
  • 14,000 from France
  • 5,000 from the U.K.
  • 2,000 from Canada
  • 1,200 from Singapore
  • 1,300 from India

According to Cyble, the exposed information included the name of the cardholder, CVV code, billing details, and expiration date, which were selling at $5 per card, and the money was paid in cryptocurrency. While the source of this massive stolen credit card database was unknown, the researchers stated that hackers might have stolen these details via a phishing website or by compromising an online store.

 Snapshot of the data leak of credit cards

Image Courtesy: Cyble

“We report these breaches so people could be made aware of the threats and risks using these applications, and perhaps do something about it,” the researchers said in a statement.

Hackers Flood Dark Web with Leaked Databases

The discovery comes after Cyble recently identified and reported another massive data breach, in which the members of the “Shiny Hunters” hacking group compromised 73.2 million user records from over 11 companies and kept them on the darknet for sale. The hackers are from the same group who are behind the Tokopedia data breach, in which 91 million user records were compromised and kept on sale on the hacking forums for $5,000. Later, the group breached India-based online learning platform Unacademy, which exposed details of 22 million users and kept the records for sale on the darknet forums for $2,000.

Several incidents have been reported in recent times on hackers selling stolen information on the darknet markets. According to Cyble, attackers were also selling over 267 million Facebook records for £500 (US$623) on dark websites and hacker forums.  The records contain information that could allow attackers to perform spear phishing or SMS attacks to steal credentials.

Related Stories: 

Canadians Refuse to Divulge Personal Data for Free Online Services: Survey

Canadians Refuse to Divulge Personal Data for Free Online Services: Survey

A new survey report from the Canadian Internet Registration Authority (CIRA) revealed that most Canadians refuse to provide their personal information to access free online services.

The report “2020 Canadians Deserve a Better Internet Report” disclosed that except online banking services (52%), most Canadians stated that they are unwilling to share their sensitive data for better products and services online. Only 26% of respondents admitted that they are willing to give personal information in return for better video streaming services. Around 23% of Canadians stated that they disclose personal details to use social media services and 15% are willing to share personal data for access to internet-connected devices like baby monitors.

“The survey result shows Canadians growing anxiety about cybersecurity-related issues, including a significant drop in their willingness to disclose personal information for better content and services online. In 2019, 72% of Canadians said they were willing to disclose some or a little personal information in exchange for valuable content or service. One year later, with the exception of online banking services, the vast majority of Canadians say they are unwilling to share their personal data in exchange for better online services,” the report said.

Other Key Findings from the Report Include:

  • 83% believe it is important that government data, including the personal information of Canadians, be stored, and transmitted in Canada only.
  • Seven in 10 are concerned about potential cybersecurity risks from foreign-owned network technologies.
  • 74% have privacy or security concerns related to connected-home devices like Amazon’s Alexa or Google Home.
  • 82% support a change in the Officer of the Privacy Commissioner’s legal authority that would give it powers to make orders and issue fines for companies who fail to comply with Canadian privacy law.
  • Over half of Canadians (54%) indicate that they definitely or probably came across fake news stories about Canadian politics or politicians in the lead up to, or during, the 2019 federal election.
  • 16% indicate that they have used a fax machine to send documents to a government department or agency in the past year because it would not accept scanned documents by email.

“Many Canadians worry that the dangers online outweigh the benefits – especially when it comes to privacy. COVID-19 has shown us that going off the grid is no longer an option; digital forces are knocking on the front doors of our homes through new smart, internet-enabled technologies, and digital surveillance tools. The entire sector can work together and strike the right balance that provides the assurances Canadians need to ensure the internet remains a trusted part of their everyday lives,” said Byron Holland, President and CEO, CIRA.

Canada’s COVID-19 Cyber Defense Force

SecDev Group in Canada initiated a volunteer-based program wherein it called upon Canada’s top cybersecurity and IT professionals to join the COVID-19 Cyber Defense Force in order to protect the country’s key services and critical infrastructure from cyberattacks. The Group’s vision and mission include: No ransomware attack should close hospital operations; no cyberattacks should affect any patients’ treatment; and no form of essential services should be affected by any cyberattack

SecDev Group also collaborated with Zeropoint to provide VPN strategies and access control to governments and companies and help them adapt to cybersecurity monitoring to accommodate a workforce that is majorly working on distributed remote desktops from home.

 

State-sponsored attacks “from China” hindering COVID-19 vaccine development: Bryan Ware

Fireside Chat CISA

CISO MAG hosted its fourth webinar in its Fireside Chat series with Bryan Ware, Assistant Director for Cybersecurity, Cybersecurity and Infrastructure Security Agency (CISA), Department of Homeland Security (DHS). In this role, Ware leads CISA’s mission of protecting and strengthening the nation’s critical infrastructure against cyber threats. A slew of cybersecurity experts comprising of CEOs, CISOs. CIOs, Vice Presidents, and executives from countries like the U.S., U.K, Canada, Cambodia and even regions like Panama attended the webinar. The latest Fireside Chat series stressed on the impact of COVID-19 with the topic “CISA and cybersecurity in times of a Pandemic.” The Fireside Chat held on May 20, 2020, was moderated by Brian Pereira, Principal Editor of CISO MAG.

Over the past few months, malicious cyber actors have tried to exploit COVID-19 fears to deliver malicious software and steal data. CISA has relied on a well-established and trusted collaboration with private industry and government partners both in the U.S. and internationally, to reinforce, refine and resonate defensive cybersecurity technologies and capabilities for businesses, government and public. Bryan Ware started the webinar by elaborating on the role of CISA and how the key body has been convening several industries and sectors for seamless functionality. “CISA is instrumental in cross-cutting several sectors by coordinating and communicating with them across several verticals.”

He also highlighted how prioritization changes under different times and scenarios. “Earlier one of the core focus areas of CISA was aviation, but with the COVID-19 pandemic, a lot of things changed. Now cyber risks on aviation is not as important as the impact of cyber risks on the supply chain for food, PPE kits, etc. CISA always proactively engages with industries with its risk profile.”

Commenting more on the Coronavirus related attacks, he opined that there has been a shift in the attack surfaces. “From the onset of the COVID-19 pandemic, there have been several scams targeting the healthcare sector. A lot of campaigns have also exploited the pandemic but launching several phishing and ransomware attacks. But the thing that worries CISA and the FBI the most is the increasing number of state-sponsored attacks originating from China. These are attacks aimed at espionage on COVID-19 vaccine development. It is not the first time that China has been involved in corporate espionage, but these new attacks are hindering vaccine development in the U.S.”

During the webinar the audience also took part two snap polls following which Bryan later took questions from the audience: You can see the results of the snap polls here:

Ware has served as the DHS Assistant Secretary for Cyber, Infrastructure, and Resilience Policy. In this role, Ware was responsible for leading DHS policy development in support of department-wide efforts to reduce national risks with a focus on critical infrastructure cybersecurity, federal network security, countering cyber-crime, and improving the security and resilience of the global cyber ecosystem, as well as national resilience initiatives that enhance Federal, State and local government and community preparedness and response capabilities.

Following the webinar, five lucky attendees who tweeted about the webinar won a one-year subscription of CISO MAG.

The next Fireside chat on the topic “Cybersecurity in the Times of Crises” will be held on June 17, 2020, with Ajay Kumar, Director, Solutions Engineering, BeyondTrust.

Register for the next webinar at https://register.gotowebinar.com/register/5005617252476549902

Through the Fireside Chat series, CISO MAG will be partnering with industry experts and solution providers from across the world to host similar webinars thrice a month to discuss some of the pressing issues and trends in the cybersecurity. Stay tuned.

About CISO MAG

CISO MAG is a publication from EC-Council, which provides unbiased and useful information to the professionals working to secure critical sectors. The information security magazine includes news, comprehensive analysis, cutting-edge features, and contributions from thought leaders, that are nothing like the ordinary. Within the first year of launch, the magazine reached a global readership of over 50,000 readers. The magazine also has an Editorial Advisory Board that comprises some of the foremost innovators and thought leaders in the cybersecurity space. Apart from this, CISO MAG also presents a platform that reach out to the cybersecurity professionals across the globe through its Summits and Awards and Power List surveys.

About EC-Council

EC-Council, officially incorporated as the International Council of E-Commerce Consultants was formed to create information security training and certification programs to help the very community our connected economy would rely on to save them from a devastating Cyberattack. EC-Council rapidly gained the support of top researchers and subject matter experts around the world and launched its first Information Security Program, the Certified Ethical Hacker. With this ever-growing team of subject matter experts and InfoSec researchers, EC-Council continued to build various standards, certifications and training programs in the electronic commerce and information security space, becoming the largest cybersecurity certification body in the world.

The Role of Third-Party Management in Cybersecurity

third party and vendor risk management

It is almost impossible to monitor a cybersecurity news cycle without reading about another organization experiencing a breach caused by an exploited third-party vendor vulnerability. For example, 1 million of healthcare provider Kaiser Permanente’s health records were exposed by one of its business associates – a California-based record storage firm. There, unbeknownst to Kaiser Permanente, an unauthorized individual accessed the Kaiser’s records through an email account belonging to an executive from the record storage firm. Marriot was also forced to disclose a breach that involved an unknown third-party using two Marriott employees logins to access 5.2 million customer records.

By AJ Yawn, Cloud Security Expert

Finding a single vendor to handle all the technological and business process needs of a modern organization is not likely. Therefore, organizations continue to outsource key functions of their operations such as cloud hosting, human resources information systems, commoditized legal services, accounting, or cybersecurity managed service providers. Organizations benefit from the increased efficiency, reduced costs, and minimized operational disruption that results from outsourcing these key functions. These benefits also come with risk, the partnership between third parties and service organizations includes joining cybersecurity practices and vulnerabilities. Vulnerabilities exploited with one organization will inevitably impact the partnered organization. Therefore, vendor management should be considered an important element of a cybersecurity program.

What do today’s regulations and compliance frameworks say about vendor management?

Cybersecurity regulators and compliance frameworks reinforce the importance of vendor management in cybersecurity programs. Multiple frameworks require organizations to establish a vendor management program that includes evaluating the confidentiality, integrity and availability risks associated with a third parties’ IT system. Industry standards such as the AICPA’s Statement on Standards in Attestation Engagements (SSAE-18) Service Organization Controls 2 (SOC-2), International Standards Organization (ISO) 27001:2013, and Payment Card Industry Data Security Standard each encompass some version of assessing, managing, and mitigating data risks brought on by third-party providers. Government regulations such as the Health Insurance Portability and Accountability Act (HIPAA) Security Rule and the European Union’s well discussed General Data Protection Regulation (GDPR) impose legal obligations on organizations to implement strict third-party governance programs typically through the implementation of certain contractual language.  Few of the requirements from different compliance frameworks and regulations are listed below:

Service organizations have similar responsibilities pertaining to vendor management under each of these standards. Organizations are required to include certain contractual provisions and conduct ongoing monitoring activities in order to be compliant with their vendor management obligations. Regardless of an organizations’ industry, your vendor management processes will be evaluated in a cybersecurity or privacy compliance assessment.

Implement the basics

Establishing a third-party management program to comply with these regulations and compliance frameworks begins with three implementation steps:

  1. Document a third-party management policy. Ensure the policy outlines requirements to onboard, monitor and offboard vendors including the evaluation of the security processes in place at each third-party organization.
  2. Identify and classify all third parties that can impact your service. Classify third parties by their potential impact on your organization. For example, if your cloud hosting provider goes down, they are a critical vendor that will impact your service and your customers significantly and should be classified with an applicable high classification.
  3. Accountability & Monitoring. Ongoing monitoring is a vital component of any third-party management program. This begins with requiring your third parties to undergo compliance assessments by third-party assessment firms and providing those reports to your organization.

These three steps will jumpstart a vendor management program that aligns with the requirements set forth in common cybersecurity and privacy compliance frameworks. Most importantly, these steps will help organizations reduce the risk associated with third-party partnerships.

An organization’s cybersecurity posture is dependent on understanding the risks that threaten them. Third parties are a threat vector that includes access to sensitive data and critical systems. Organizations that do not have a vendor management program in place are flying blind and missing potential threats to their systems’ and customer’s data. A complete cybersecurity program includes third-party management that mitigates the risks associated with interconnected business relationships.

About the Author

AJ Yawn, Cloud securityAJ Yawn is a cloud security subject matter expert that possesses over nine years of senior information security experience and has extensive experience managing a wide range of compliance assessments (SOC, ISO 27001, HIPAA, etc.) for a variety of SaaS, IaaS, and PaaS providers. He has earned several industry-recognized certifications, including the CISSP, AWS Certified Security Specialty, AWS Certified Solutions Architect-Associate, and PMP. AJ is involved with the AWS training and certification department, volunteering with the AWS Certification Examination subject matter expert program.

Disclaimer 

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

70 Mn Records Exposed After AFL Fan Website Leaks Users’ Data

70 Mn Records Exposed After AFL Fan Website Leaks Users’ Data

Australia’s AFL fan website is the latest victim of a security breach where private data of 70 million users’ were compromised. Researchers from SafetyDetectives stated that they found around 132GB of data from a leaky Elasticsearch database including private user data and technical information relating to the company’s website BigFooty.com.

SafetyDetectives notified the incident to the BigFooty authorities and also reported to the Australian Cybersecurity Centre. The database is secured now. BigFooty.com is an Australian web and mobile application focused on Australian football rules. The site allows users to interact with each other on a range of topics with football being the prime focus for most users.

“Private messages are fully exposed in the leak and can be traced back to specific users. This includes some high-profile users such as Australian police officers and government employees. Private information belonging to such individuals, including chat transcripts and email addresses, were found on the database which thereby creates a significant vulnerability in terms of potential blackmail and other reputational damage that could be caused,” the researchers said.

According to SafetyDetectives, the exposed information includes:

  • Users’ private messages
  • Usernames used to access Big.Footy.com
  • Passwords to live streams
  • Data relating to ad spammers
  • Email addresses
  • Relationships between users
  • Phone numbers
  • Users’ comments including personal threats and racist material
  • Personal information relating to real-world activities, intentions, and behavior
  • Data related to site’s internal workings, server information, operating system information, internal resource details, browser information, error logs, access logs, IP addresses, and location data.

Cybercriminals Target Australians

Australia witnessed a sudden surge in cyberattacks amid Coronavirus pandemic which led the Australian Cybersecurity Centre (ACSC) to release a new threat report exposing how cybercriminals are exploiting the situation for their own gain through phishing schemes and malicious activities. The report is intended at raising awareness about the increasing COVID-19-related malicious cyberthreats and also provide real-time cybersecurity advice to organizations and individuals.

 

Almost Half of U.K.’s Population Fears Abuse of NHSX COVID-19 Tracing App

COVID-19

The U.K.’s National Health Service (NHS) is all set to launch an NHSX contact-tracing app based on similar implementations in China and India. However, like the concerns raised in these countries, 48% of the U.K.’s citizens showed distrust in the government’s latest technological adoption. As per a survey conducted by Censuswide on behalf of Anomali,  the citizens fear that their personal data might be at risk as cybercriminals may take advantage of it.

Due to the coronavirus pandemic, the app has been developed in very compressed timelines and like every development, compromises were made in the name of timeliness.

The NHS started the NHSX app trials on May 4, 2020, and subsequently released the beta application code for review. The NHS said, “Due to the coronavirus pandemic, the app has been developed in very compressed timelines and like every development, compromises were made in the name of timeliness. Hence, the intent of being open before a national launch was to show what and how the app will do, and to get some peer review from security and privacy researchers.”

Thus, a stringent timeline and overlooked issues made citizens fear the consequences. However, the NHS clarified that the contact-tracing app is designed to slow the spread of Coronavirus whilst protecting users’ privacy. It will not ask or collect any personal information such as name or email address. As an additional security perimeter, the NHS states that all users are assigned a random and unique installation ID. It will securely store only the first part of the postal code, your installation ID, and the registered mobile phone’s make and model.

Other findings of the survey include:
  • Around 43% of respondents feared that cybercriminals would take this opportunity to send smishing messages or phishing emails.
  • Yet, only half (52%) of them felt they could differentiate between a legit email or text message and a phishing/smishing message.
  • 33% of the respondents also fear that the government could use this app to track their movements.
  • While 36% believe that the government could secretly collect data on them through this app.

The general consensus is that although all the privacy and security perimeters are in place, cybercriminals will most likely target the contact-tracing app and also exploit and manipulate Bluetooth vulnerabilities since the app uses a  Bluetooth signal to keep track of any possible COVID-19 patients in the immediate vicinity by transmitting an anonymous ID. These worries can be understood due to the surge in the  COVID-19 pandemic-themed cyberattacks and phishing emails posing as health advisories and government notices.

How to Detect Suspicious Email Attachments During the COVID-19 Pandemic

How to Detect Suspicious Email Attachments During the COVID-19 Pandemic

Most organizations depend on e-mail correspondence as a primary means of communication when it comes to sharing confidential data like customer account numbers, employee credentials, and other classified information. Organizations may suffer data breaches inadvertently if one of their employees unintentionally open/download a weaponized email attachment or malicious link in the email.

By Rudra Srinivas, Feature Writer, CISO MAG

With cybercriminals taking advantage of the Coronavirus pandemic, we continue to see several phishing attacks tricking people into opening malicious links and attachments. Attackers use fake email attachments in disguise aiming to compromise targeted user devices or networks. The attachments might contain Trojans and viruses, which, if downloaded, cause enormous security issues.

We need to be constantly vigilant when it comes to downloading email attachments. Here we tell you how to spot a suspicious attachment:

1. Looking at the File Extension

The file name extensions help in determining the file type of the attachment. For example, if the file name ends with .jpg extension it is an image file and if it ends with .avi it is a video file. The extension that you should avoid is .exe, which, if downloaded, executes an installation of malware into the device. Attackers use these executable files to spread malicious e-mail attachments, fake setups, updates, or other types of fake programs with the malicious code built in. These file extensions are also programmed to skip antivirus detection and e-mail attachment protection software.

Threat actors also use some Microsoft office files like .Doc, .Docx, and .Docm to infect devices. These file extensions  use malicious macros, which is a series of instructions that will execute a task. If the file name ends with an m, it has macros, these include .docm. pptm, and .xlsm. Some other file extensions to avoid include .jar, .cpl, .com, .bat, .msi, .js, and, .wsf. The rule of thumb here is to avoid extensions that look odd or suspicious.

2. Crosschecking the Sender

Verify the email sender by hovering over the display name and email address. Attackers usually spoof display names to look like it is coming from a legitimate person, but it can be determined by checking the display name for authenticity. It is OK to open an email attachment if it is coming from someone you often communicate with. However, even someone you know could be compromised themselves, and the hacker will send you a malicious file under that person’s name to build trust. It is advisable to call and confirm, if you receive a macro file attachment or any suspicious attachment from someone you know.

 3. Email Content

Go through the email content before opening its attachment, read the subject line, check for typos and other errors. If the sender appears legitimate, but the contents in the email do not seem like something they would send, it could be suspicious.  Such emails are used in phishing attacks to trick people into clicking/downloading malicious attachments/links or asking them to enter personal details.

In a recent phishing attack, a hacker group targeted the World Health Organization (WHO) via a sophisticated phishing scam, which involved an email hosted on a phishing domain that tried to trick the employees into entering their credentials.

4. Is it an Encrypted Archive?

Archive files help in compressing multiple files into one folder. However, they can be used by hackers to avoid virus scans as they may hide malware in it. If you receive an email with an archive extension like .7z, .rar, or .zip, and it asks to enter a password to open, it may be suspicious. So, we never know whether the encrypted archive contains sensitive information or a hidden virus. Just make sure it comes from a trusted source before opening it. When users click/download the attachment, they will be prompted to “Enable Content” to view the protected document. This allows malicious macros to be executed by themselves to download a malware executable to the computer.

Conclusion

Just by looking at an email attachment, one should be able to estimate its authenticity and decide whether it is safe to download it or not. Generally, most email service providers allow previewing the attachments without downloading. Hence, it is better to go through the contents before downloading any attachments.

About the Author

 

Rudra Srinivas is part of the editorial team at CISO MAG and writes on cybersecurity trends and news features.

 

Number of IoT Devices Expected to Reach 24.1 Bn in 2030: Report

Number of IoT Devices Expected to Reach 24.1 Bn in 2030: Report

A research published by Transforma Insights revealed that the number of active IoT devices globally is expected to grow from 7.6 billion in 2019 to 24.1 billion in 2030, thereby generating revenue of more than $1.5 trillion, at 11% CAGR. North America, China, and Europe will dominate the IoT market in 2030, with 26%, 24% and 23% respectively of the total value.

The research stated that technologies like Wi-Fi, Bluetooth, and Zigbee will dominate connections, accounting for 72% in 2030. Public networks will grow from 1.2 billion connections to 4.7 billion in 2030, with increasing market share from 16% to 20%. While private networks account for the balance of connections, 10% in 2019 and 8% in 2030. It also found that the consumer sector is expected to dominate in terms of connected devices, accounting for 65% of all connections, up from 62% in 2019.

Within the enterprise segment in 2030, around 34% of connected devices will be accounted for cross-vertical use cases like generic track-and-trace, office equipment and fleet vehicles; 31% by utilities; most prominently smart meters; 5% by transport and logistics; 4% by the government; 4% for agriculture, and 3% each for financial services and retail/wholesale. While in the smart grid sector, connected devices like smart meters represent 14% of connections. And the smart automation sector, which is dominated by connected cars, is the third biggest category, representing 7% of the global installed base.

Image source: Transforma Insights

“In financial terms, the biggest vertical sector is consumer, generating $652 billion in revenue, or 43% of the total market value. Cross-vertical applications account for 24%. The remaining 33% is sector-specific applications across sectors such as energy, transport, retail, and healthcare,” the report said.

Growing IoT Networks Bring New Security Concerns

A similar research, “The Internet of Things: Consumer, Industrial & Public Services 2020-2024,” from Juniper Networks found that with the number and purpose of connected devices increasing rapidly, the concerns over security threats also increase. The research stressed that IoT networks must implement steps to maximize security in all layers of the IoT ecosystem, including devices and connectivity. The research advised enterprises to implement necessary security measures to defend from cyberattacks. It suggested two key areas of focus — the use of network segmentation to mitigate cyber risks and to ensure that the lifecycle management of network assets is properly maintained.

70% of Organizations Suffer IoT Attacks

According to a survey from the security firm Extreme Networks, organizations remain highly vulnerable to IoT-based attacks. The survey, which surveyed 540 security professionals across organizations in North America, Europe, and the Asia Pacific, found that 84% of organizations have IoT devices on their corporate networks. It also stated that more than 50% of the organizations do not maintain necessary security measures beyond default passwords.

 

94% of Security Pros are Concerned About Cybersecurity After the COVID-19 Outbreak

cybersecurity

A joint research from security firm Tripwire and Dimensional Research revealed that around 94% of security and IT professionals globally are concerned about their organization’s cybersecurity after the outbreak of the Coronavirus pandemic.

The research “Remote Work And COVID-19 Cybersecurity Impact Report” revealed that organizations are struggling to mitigate the risks of increased COVID-19-related attacks, with 58% of security issues revolving  around remote workers. “For most organizations, this pandemic has acted as a major stress test on cybersecurity controls and policies. The resulting surge in remote work complexifies the attack surface and brings up many new questions for security teams,” the report said.

According to the research, the topmost areas of increased concerns include employee home network security, increased ransomware, phishing, social engineering attacks, keeping remote systems configured securely, and keeping remote systems compliant.

Nearly 89% of respondents said remote work has made it difficult to secure the devices connecting various locations. Around 49% said that they cannot effectively secure remote employees’ devices. 41% find it more challenging to manage which devices connect to the corporate network, while 37% believe it is hard to collaborate and communicate as a security team. The research stated that 45% of security professionals fear increased ransomware, phishing, and social engineering attacks, while 38% of respondents admitted they find it more challenging to keep remote systems compliant and secure traffic coming through VPNs.

On COVID-19-related attacks, 63% of respondents stated they have suffered outside intrusions. However, 61% of IT staff declared that the attempts were unsuccessful and just 2% confirmed that their organizations were breached. While 56% of respondents said they were somewhat prepared,29% said their security plans were well in place and it was simple to adjust. Only 2% said they were not impacted by the outbreak.

The research findings are based on 345 security professionals surveyed globally between April 14 and April 21, 2020, to analyze the top areas of security concerns in the wake of COVID-19 and how they are responding to new challenges.

 

 

Fake Aarogya Setu Apps Spread Spyware, SonicWall Reports

Fake Aarogya Setu Apps Spread Spyware, SonicWall Reports

The threat research team from security firm SonicWall Labs stated that they found multiple fake Aarogya Setu apps carrying spyware components.

Aarogya Setu is a smartphone application developed by the Indian government to help people assess themselves on the risk of infecting with Coronavirus. The app determines the risk if one has been near a COVID-19 infected person (within six feet distance) by scanning through a database of known cases across India. The app detects other devices via GPS or Bluetooth range and gets information about positive cases. The app gained huge popularity in the country; however, it also became a target for cybercriminals.

The SonicWall researchers also disclosed multiple scenarios on how these malicious apps function.

Scenario 1

The researchers stated that they found several fake apps with the package name “cmf0.c3b5bm90zq.patch”. It is observed that the malware operators used the same code for a majority of fake apps, by re-branding the icon and application name.

Image Courtesy: SonicWall

In this case, the app impersonates the legitimate Aarogya Setu App. However, the copy is imperfect, the icon appears stretched and can be identified by seeing along-side the legitimate app.

“Upon execution, we do not see any activity on the screen. However, after some time, the app icon disappears from the app drawer. This contains reference to a domain – johnnj2-37916.portmap.io – in the patch_preferences.xml file. During an analysis, the malware did not try to communicate with this domain, however this domain is connected to malicious apps,” the researchers said.

Scenario 2

Like in the first scenario, several fake apps have been found with the package name “yps.eton.application”. In this case, the app has been shown as an Aarogya Setu Add-on app, which is not an official app.

Image Courtesy: SonicWall

If the user installs the app, it requests for the Device-Admin privileges and permission for installation from this source. The fake app automatically installs the legitimate Aarogya Setu App from its resource folder to look less suspicious to users.

Scenario 3

In this case, hackers successfully duplicated the official Aarogya Setu icon, making it difficult to identify whether it is legitimate or fake. “There was no network activity witnessed during our analysis session but there was a record of a domain – 204.48.26.131:29491 – within an xml file belonging to the app. This domain is related to another malicious Android app,” the researchers said.

Image Courtesy: SonicWall

The common element in all the three scenarios is the containment of spyware components, which comprise malicious codes like the Android spyware SpyNote. Once downloaded, this spyware can make phone calls, recording audio, send SMS, take pictures, and record videos from the camera, and start the spyware every time the device reboots.

How to Delete Fake Apps

If the user deletes the Aarogya Setu app from the device by simple uninstalling method (by long pressing the icon), only the genuine app is removed, while the malicious app would still be available in the background of the device. The only way to remove the malicious apps is to remove it from settings > apps > uninstall.

Debasish Mukherjee, Regional Sales – APAC at SonicWall, said, “As the Aarogya Setu App gained popularity in India, it became a target for malware creators. The outbreak of Covid-19 has created new avenues for cyber attackers to explore, innovate and strike in every malicious way. With increasing cyberthreats it appears that cybercriminals are working overtime to create dissonance among mass app users. We advise Android users to exercise maximum caution while downloading and using the Aarogya Setu App.”

The Government of India made the Aarogya Setu app open source this week. The source code for Android is now available on GitHub and the Government has said that all future app updates will be made through this dedicated repository. This was reported by The Financial Express. Researchers and cybersecurity experts will now be able to audit the Aarogya Setu app at their full discretion. But hackers may also be taking advantage of this as they have access to the source code.