Home Blog Page 218

Researchers Uncover “Agent Tesla” Malware Abusing MS Office Vulnerabilities

Malware and Vulnerability Trends Report, Mobile malware threats

Security services provider Quick Heal Security Labs recently uncovered a password stealing malware codenamed as “Agent Tesla” being distributed via malicious campaigns. It is said that attackers are spreading the malware via COVID-19 themed phishing campaigns to steal sensitive data by capturing keystrokes, taking screenshots, and dumping browser passwords.

Quick Heal stated that hackers are currently abusing MS Office vulnerabilities, titled CVE-2017-11882 and CVE-2017-8570, as well as archives with double extension executable (ZIP, RAR etc.).

The CVE-2017-11882 vulnerability allows attackers to run an arbitrary code to deliver the Agent Tesla malware payload. Another vulnerability CVE-2017-8570 triggers the execution of scripts without user interaction. CVE-2017-8750 downloads the .NET payload which steal sensitive data, log user keys, and send data to the SMTP server.

Explaining the attack vector, the researchers at Quick Heal said, “A victim receives a phishing mail with an attachment titled as ‘COVID 19 NEW ORDER FACE MASKS.doc.rtf’. This doc is an RTF file that exploits CVE-2017-11882 which is a stack-based buffer overflow vulnerability present in the Microsoft Equation editor tool. This vulnerability allows the attacker to run arbitrary code and after successful exploitation to deliver the Agent Tesla payload. This dropped payload performs code injection in known windows process RegAsm.exe. The injected code in RegAsm.exe performs all info-stealing activity and sends it to the CnC server.”

Image Courtesy: Quick Heal

“Actors behind these campaigns are capitalizing on the global Coronavirus panic to distribute Agent Tesla malware and steal sensitive user information. Quick Heal advises users to exercise ample caution and avoid opening attachments & clicking on web links in unsolicited emails. Users should also keep their Operating System updated and have a full-fledged security solution installed on all devices,” Quick Heal added.

ExecuPharm Suffers Ransomware Attack, Hackers Published Data on Darknet

Ransomware Attacks, Graff ransomware attack

The U.S.-based pharmaceutical giant ExecuPharm admitted it became a victim of a cyberattack. In a letter to the Vermont attorney general office, ExecuPharm said it was hit by a ransomware attack on March 13, 2020, and attackers may have been accessed users’ sensitive data like social security numbers, taxpayer ID/EIN, driver’s license numbers, passport numbers, bank account numbers, credit card numbers, national insurance numbers, national ID numbers, IBAN/SWIFT numbers, and beneficiary information.

ExecuPharm stated that the unknown hackers encrypted its servers and asked ransom in exchange for decryption. This was after ExecuPharm employees were targeted in a phishing campaign.

Further investigation into the incident revealed that the attackers may have accessed and shared select personal information of ExecuPharm executives whose information were stored on ExecuPharm’s data network. ExecuPharm has notified federal and local law enforcement authorities in the U.S. and held a third-party cybersecurity firm to investigate the incident.

Meanwhile, TechCrunch reported that the hacker group have published the stolen data on a dark web site associated with the CLOP ransomware group. The site contained vast information like cache data, email addresses, financial and accounting records, user documents and database backups which are stolen from ExecuPharm’s systems.

“ExecuPharm internal teams worked diligently with forensic consultants to rebuild the impacted servers from back up servers and have now fully restored and secured the ExecuPharm systems. This included the installation of forensic tools on all systems and the isolation of impacted systems until ExecuPharm could confirm that they were secure. ExecuPharm also implemented additional countermeasures to block further ransomware emails from entering the ExecuPharm environment. ExecuPharm also upgraded its security measures to prevent future attacks, including forced password resets, multi-factor authentication for remote access, and endpoint protection, detection, and response tools,” ExecuPharm said in a statement.

“PerSwaysion” Phishing Campaign Targets High-Ranked Professionals Across The Globe

“PerSwaysion” Phishing Campaign Targets High-Ranked Professionals Across The Globe, IKEA email reply-chain attack

Threat Intelligence team from Group-IB recently uncovered an ongoing phishing campaign targeting corporate email accounts by exploiting Microsoft file sharing services, including Sway, SharePoint, and OneNote. Codenamed as “PerSwaysion” – the phishing campaign attacked around 156 high ranking officers of various organizations across the U.S, Canada, Germany, the U.K., Netherlands, Hong Kong, Singapore, and several other countries. The group sent phishing emails to top-level executives at targeted companies to trick them into entering Office 365 credentials on fake login pages. Group-IB created a website for users to check if their email address was compromised by PerSwaysion group.

According to Group-IB, PerSwaysion has been active since 2019. It is said that PerSwaysion is a collection of targeted phishing attacks operated by multiple hackers’ groups, attacking small and medium financial services companies, law firms, and real estate groups.

The researchers also stated that the campaign adopts multiple techniques to avoid traffic detection and automated threat intelligence gathering, which include:

  • Whitewashing: Using legit file sharing sites as a jumping board; Using web application hosting from reputable vendors such as Google’s AppSpot and IBM’s MyBlueMix
  • Counter-intelligence: Randomizing malicious JS file names; Fingerprinting victim browsers and rejecting repeated visits
Image Courtesy: Group-IB

PerSwaysion Attack Methodology

  • Attackers send an email containing a clean PDF file as an email attachment to the targeted user. When the user opens the attachment, they’d be asked to click on a link to view the actual content
  • The link then redirects the users to a Microsoft Sway (newsletter service) page, where a similar file would ask the victim to click on another link
  • This will again redirect the user to a page imitating the Microsoft Outlook login page, where hackers would collect the victim’s credentials

   Phishing Site Disguised as Microsoft Sign In Page

Image Courtesy: Group-IB

Describing the PerSwaysion campaign, Feixiang He, Senior Threat Intelligence Analyst at Group-IB, said, “PerSwaysion campaign is a living example of highly specialized phishing threat actors working together to conduct effective attacks on high ranking officers in large scale. They adopt multiple tactics and techniques to avoid traffic detection and automated threat intelligence gathering, such as the use of file-sharing services and web application hosting from reputable vendors.”

“The campaign pursues non-trivial counterintelligence methods, for example, randomizing malicious JS file names and fingerprinting victim browsers and rejecting repeated visits. Such measures taken by cybercriminals seeking to garner sensitive corporate information requires non-standard approach to their detection and response,” He added.

“In the Digital Economy, Security is no longer an afterthought”

Vipin Samar, Senior Vice President of development for Oracle Database security

Vipin Samar is the Senior Vice President of development for Oracle Database security. He leads teams responsible for all aspects of database security including encryption, redaction, masking, Oracle Database Vault, Oracle Key Vault, Oracle Audit Vault, and Oracle Database Firewall.

Prior to joining Oracle, Samar worked at Sun Microsystems and was the Founder and CEO of a startup that developed enterprise application integration and mobile platforms. Since joining Oracle in 2005, he has held various positions in product development related to data security.

Samar holds a bachelor’s degree in electrical and electronics engineering from Birla Institute of Technology and Science (BITS), Pilani, India. He also holds a master’s degree in computer science from the State University of New York at Stony Brook and has 12 patents in the areas of security and information retrieval.

In an email interview with Brian Pereira of CISO MAG, Samar talks about information security in the digital economy, Oracle’s approach towards data security, and how the organization has embedded security technologies and capabilities into the Oracle Database. 

Why is there a change in attitude towards Security? Earlier, it was just the regulated industries that took security seriously.

In the digital economy, information security is industry/vertical (or for that matter organization) agnostic. If we look at the scenario, 10 years ago, it was mainly government and the banking sector that took security seriously, but now, information security has become a business prerequisite for every organization. Given the data explosion, organizations are facing an enormous challenge to safeguard their data from cyber theft.

Looking at the kind of hacks that have happened last year, these hacks were not just about the credit card data; but about everything — from your location, email, address — to healthcare records, etc. Once they got your PII (personally identifiable information), they have it forever and can access it whenever they want to. Therefore, security is no longer an afterthought especially after the introduction of regulations like GDPR. Now, almost 125 countries have passed, or are in the process of passing similar laws.

At the start of this year, CCPA was introduced in the State of California. What has been the impact so far?

In the U.S., every state is passing its own laws. Specific to CCPA, this is the first year of its introduction, so we’ll have to wait and see.

And what do you observe in India, regarding companies being compliant to security standards?

There are a bunch of processes to be followed which are audited regularly, with technical controls in place. Many of our customers in the banking and financial services sector are all compliant with the GDPR guidelines and it is quite amazing to see the adoption of different standards, for encryption, auditing, and access control.

Once the proposed Personal Data Protection Act comes into force, a lot of things will change. In India, the volume of data is so high (like China). With data privacy concerns on the rise and stringent regulatory requirements coming into force, organizations have no choice but to redefine the way they approach data management. A good first step would be to put in place a cohesive IT architecture, with systems and applications built to work as an integrated unit. The data can then be organized in such a way that it’s easier to change, transfer, find, erase and comply with regulatory requirements. Security and proper access processes are critical – assess, prevent and detect should be the key mantras.

What is Oracle’s approach to data security? How is it embedding security in its products? 

Oracle’s approach to security is in protecting the world’s most mission-critical systems and data. Our Gen 2 Cloud has put the security of critical workloads at the forefront of its cloud design. For customers running security-sensitive workloads such as financial applications or citizen data accessibility, Oracle Cloud Infrastructure (OCI) has built a cloud with technology to reduce risk by isolating customers from the parts of the cloud-controlled by other tenants and even Oracle personnel. The security-first design approach led to innovations like isolated network virtualization and pristine physical host deployment, which give customers a higher level of security than first-generation clouds. Simply put, security is not bolted on, whether it is encryption, access control, auditing – all this is built inside. That is what gives us scale and performance. We are moving towards “always-on” security, and you can’t turn it off on the cloud. We have to move towards this space of “business-on” by default. There is no “off” switch.

For example, Oracle Autonomous Database is a generational innovation that redefines data management. It automatically encrypts all data whether it’s at rest or in flight. It also prevents any administrators from snooping on sensitive application data. From a security perspective, with self-securing capabilities, Oracle Autonomous Database ensures the automatic application of the latest security updates with no downtime, eliminating cyberattack vulnerabilities. It also offers protection from all types of downtime, including system failures, maintenance, user errors, and changes to the application data model.

Can you tell us about some of Oracle’s data security innovations?  

An organization’s success and failure depend on how it uses and secures its data. Organizations need to be a step ahead of hackers, who are ready to exploit any weakness, whether in databases, or applications or the infrastructure.

That is the reason, we have multiple security technologies for protecting data at the source – within the database. We have focused on all pillars of security: evaluating the risk posture, minimizing the attack surface, preventing the attacks, and detecting and alerting any malicious behavior in databases.

We have embedded security technologies and capabilities into the Oracle Database to enable our customers to deploy and maintain a highly secure database environment all by themselves. With Oracle Data Safe, critical functionalities for securing databases in the cloud are now under a simple click-and-secure interface. The most common security tasks can be completed without requiring any deep security expertise. Data Safe helps all customers, big or small, keep their data safe and has made security an enabler for many organizations to move to the cloud.

Oracle takes a multi-layered approach to security. Can you explain that?

There isn’t a single thing you can do to make your database secure. You have to think from the perspective of the hackers, who are attacking from all sides: network, infrastructure, database, applications. They could attack the weakest link and there isn’t a single solution. So, businesses need different solutions to protect all this. Therefore, we need to embed security as close to the data as possible and keep it secure.

Oracle Advanced Security provides two preventive controls to protect sensitive data at the source: encryption and redaction. Together, these two controls form the foundation of Oracle’s defense-in-depth, multi-layered database security solution. Multi-layered security includes controls to evaluate risks, prevent unauthorized data disclosure, detect and report on database activities, and enforce data access controls in the database with data-driven security. Capabilities such as online and off-line tablespace migration options provide flexibility while deploying encryption, while database privilege analysis helps reduce an application’s attack surface.

How is Oracle helping organizations with compliance and regulation? Do you have a product or service specifically for that?

Every regulation has multiple aspects like encryption, auditing, access control, security assessment, etc. For example, if we talk about GDPR, it talks about data anonymization, data masking, etc. We map our solutions to every regulation, like GDPR for instance. Oracle security includes a full set of hybrid cloud solutions, from the chip to applications that help prevent, predict, detect and respond to security threats.

What is the industry sentiment towards cloud security? How is Oracle responding?

Cloud has changed the rules of the game. Earlier, many were hesitant to move to the cloud because they were concerned about weak security. Now they move to the cloud because it is more secure than traditional/legacy on-premise setups.

In the digital era, hacks are increasing in complexity, variety and impact, so CISOs can’t afford to let their guard down even for one second – because the attack surface has expanded unimaginably spanning multiple threat vectors. Add to this the shortage of top-quality cyber-talent and increasing regulatory/compliance requirements – you have the CISOs literally in the hot seat at any given point in time. We do not see enough professionals with security as their focus area. At the same time, the organizations depending more on humans will face immense challenges as hackers are getting tech savvier every day. Hence, we feel that businesses need to gather and strike a fine balance between the deployment of machines and humans to counter security threats. As the future war for security will be a machine vs machine combat.

We’ve purpose-built our second-generation cloud from the ground up to meet the requirements of large enterprises and complicated workloads. Oracle is opening more regions across the world, including India to comply with data residency mandates and data sovereignty requirements.

For Oracle, simplicity is a pre-requisite for any solution and that’s why we created Data Safe. It takes the responsibility of the user component of that whole equation and automates that completely. So, this is about simplicity and not about requiring security expertise. So, we have made security simple and easy to use.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article

 

“PhantomLance” Targets Android App Store to Spread Malware and Spyware

Fleeceware Applications

Security researchers from Kaspersky Lab found threat actors exploiting Google Play Store for years to distribute advanced android malware to steal a wide range of sensitive data from users. According to the researchers, a malicious campaign named “PhantomLance” has been targeting android devices with malware and spyware payloads embedded in applications delivered via multiple platforms including Google’s Play Store and other android app stores like APKpure and APKCombo.

“The campaign has been active since at least 2015 and is still ongoing, featuring multiple versions of a complex spyware – software created to gather victims’ data – and smart distribution tactics, including distribution via dozens of applications on the Google Play official market,” Kaspersky said.

Evading Google Security Checks

The researchers found that attackers behind the campaign used sophisticated techniques to constantly bypass the vetting process that Google uses to detect malicious apps. Hackers initially submit a benign version of an app and include the backdoor after the app is accepted by Google.

Kaspersky observed over 300 infection attacks on users of android devices in India, Vietnam, Bangladesh, and Indonesia since 2016. There were also several threat detections noticed in Nepal, Myanmar, and Malaysia. Below is a cartographic representation of countries with top attempted attacks.

Data Source: Kaspersky Labs

Apart from the android applications containing PhantomLance malware, Kaspersky also provided a list of apps that were distributed and later removed from the Play Store by Google in November 2019.

Image Courtesy: Kaspersky Labs

“During our extensive investigation, we spotted a certain tactic often used by the threat actors for distributing their malware. The initial versions of applications uploaded to app marketplaces did not contain any malicious payloads or code for dropping a payload. These versions were accepted because they contained nothing suspicious, but follow-up versions were updated with both malicious payloads and code to drop and execute these payloads. We were able to confirm this behavior in all of the samples, and we were able to find two versions of the applications, with and without a payload,” Kaspersky added.

Official reCAPTCHA Walls Protect Phishing Campaigns

phishing campaign, Smishing attacks

Researchers at Barracuda Networks have reported an increase in phishing attacks using official reCAPTCHA walls to avoid detection from email security solutions. This technique of phishing hides the malicious content and tricks unsuspecting naive users.

Purpose of reCAPTCHA

reCAPTCHA walls are typically used to verify and differentiate between human users and bots. Once the human intervention is verified only then access to web content is allowed. It is also commonly used as one of the MFA (multi-factor authentication) techniques, which helps legitimate companies restrict bots from scraping and hijacking their content.

Ultimately no security solution will catch everything. The ability of the users to spot suspicious emails and websites is the key.

Phishing Campaigns Using reCAPTCHA Walls

It seems that cybercriminals, however, have now started using reCAPTCHA walls service for preventing automated URL analysis systems from accessing the malicious content and code on the phishing pages. Researchers said that these phishing sites look more credible to the human-eye than those used in other campaigns.

Researchers added that one of the phishing campaigns sent out 128,000 emails to several organizations and its employees using reCAPTCHA walls to disguise fake Microsoft log-in pages. This sophisticated campaign used a voicemail receipt to fool users into solving the reCAPTCHA wall before being redirected to the malicious page. All the login credentials entered thereafter were sent straight to the cybercriminals.

Steps to Protect

Jonathon Tanner, Senior Security Researcher at Barracuda Networks said in the blog, “The most important step in protecting against malicious reCAPTCHA walls is to educate users about the threat so they know how to be cautious instead of assuming reCAPTCHA is a sign that a page is safe. Users should exercise scrutiny when seeing reCAPTCHA walls, especially in unexpected places where legitimate walls have not been encountered in the past.

As with any email-based phishing, checking for suspicious senders, URLs, and attachments will help users spot this attack before they get to the reCAPTCHA. The email itself is a phishing attack and may be detected by email protection solutions. However, ultimately no security solution will catch everything, and the ability of the users to spot suspicious emails and websites is key.”

Almost Every Antivirus Software Program Can Be Exploited, Researchers Say

Hackers Exploiting Cisco’s ASA/FTD Software to Steal Data

A vulnerability in almost all antivirus software platforms could have been exploited to disable anti-malware protection and turned into destructive tools, security researchers from RACK911 Labs revealed. RACK911 Labs has found a unique method of using directory junctions (in Windows) and symlinks (in macOS and Linux) to turn antivirus software products into self-destructive tools. However, it was reported that most of the antivirus companies have now fixed the vulnerability in their products.

How the bugs are exploited

Researchers stated that an attacker must be highly time-sensitive and should know when to exploit the directory junction or symlink vulnerabilities. “What most antivirus software fail to take into consideration is the small window of time between the initial file scan that detects the malicious file and the cleanup operation that takes place immediately after. A malicious local user or malware author is often able to perform a race condition via a directory junction (Windows) or a symlink (Linux & macOS) that leverages the privileged file operations to disable the antivirus software or interfere with the operating system to render it useless,” the researchers explained.

Researchers used their proof-of-concept (PoC) to exploit Norton Internet Security for macOS and downloaded the EICAR test-string from Pastebin to evade protection that prevents the antivirus to download the test-string from the Norton official website. They also attempted the antivirus exploitation process against McAfee Endpoint Security for Windows using the same POC and were able to delete the EpSecApiLib.dll file.

Affected Antivirus Software

The researchers also listed all the vulnerable antivirus software products, which include:

Image Courtesy: rack911labs

RACK911 Labs stated that it notified all the antivirus vendors about the security vulnerabilities affecting their platform. It also clarified that most of the antivirus vendors have fixed the vulnerabilities in their antivirus products.

“Whether it’s Windows, macOS or Linux, it’s extremely important that file operations happen with the lowest level of authority to prevent attacks from taking place. One must always assume the user is malicious and by performing privileged file operations within reach of the user, it’s opening the door to a wide range of security vulnerabilities,” RACK911 Labs concluded.

Darknet Markets Make Malware Buying Easy: Research

From Data Breach to Darknet

One of the main reasons for the constant surge in cybercrimes is because of the availability of malware and malicious tools on darknet marketplaces at low cost, a new study from research organization CyberNews.com revealed. The study found that threat actors can easily buy and own malware and ransomware via underground message boards and dark web market networks at a surprisingly low cost, ranging from free of cost to $50.

According to the study, you don’t have to be a technical person to buy the malware. Anyone with a digital wallet loaded with bitcoins can do it. There is a customer support service available for free updates and troubleshooting services to the malware tools that you buy.

“As it turns out, you don’t have to be a programmer or even have any specialized technical knowledge to buy or create malware. In fact, the entry bar is set so low that practically anyone can do it – all you need is an online wallet loaded with some Bitcoin,” the researchers said in the report.

CyberNews’ researchers conducted their research on 10 darknet marketplaces to analyze the availability of malware programs for sale, the cost of the malware tools on offer, and the availability of customer support for said tools.

Other Findings of the Research include:

  • Buying malware is incredibly easy – anyone can do it in mere minutes
  • Owning malware is cheap or even free: while the free tools are available but somewhat risky to use, advanced tools are available for as little as $50 on cybercrime forums that operate in the open
  • Customer support is usually offered with paid malware tools, including free updates and troubleshooting services

“Encrypted trojans that can remain undetected by even the most sophisticated antivirus systems? Custom-built ransomware tailored to your own specifications? It’s all there and available for would-be cybercriminals – for the right price,” the report added.

Malware for Sale

CyberNews’ researchers stated that they found various categories of malware programs for sale on the darknet. A list of malware bots, ransomware builders, data stealers, Remote Access Trojans (RATs), banking trojans, and other viruses are kept for sale with a price ranging from free to maximum of $5,000.

“As we browsed the marketplaces, we found hundreds of malware programs and services for sale. Banking trojans, made for stealing people’s online banking credentials, are offered alongside ransomware builders, state-of-the-art modular malware bots, and much more. All complete with tech support that is available for free or a modest additional fee,” the researchers said.

How to Prevent Zoom Credential Theft

Zoom, video conferencing, webinar, zoom two-factor authentication, top data breaches of 2020

There are over 500,000+ stolen Zoom logins floating around the dark web. The account information has been published, exchanged, and, in some cases, sold online without their knowledge or consent. The Zoom credentials, later, were found being sold on a hacker forum for .002 cents each.

Affected accounts included ones from colleges such as the University of Vermont, University of Colorado, Dartmouth, Lafayette, University of Florida, and even well-known companies such as Chase, Citibank, and more.

In this article, I’ll talk about how the zoom credential theft occurred, the security flaws that facilitated it, and how you can prevent it from happening to yourself.

By Robert Mardisalu, Co-founder & Editor of TheBestVPN.com

A History of Zoom’s Privacy and Security Flaws

As the COVID-19 pandemic pushed more and more people to self-isolate, Zoom found itself gaining millions and millions of users. The platform has seen daily meetings surge from 10 million in December to 300 million today. Unfortunately, this surge in popularity carried with it an increase in privacy risks.

The first of Zoom’s privacy and security flaws surfaced late last month when it was revealed that Zoom’s iOS app was sending user data to Facebook.

Soon after, reports of classroom Zoombombing involving a swastika sign led the FBI to issue a public warning about Zoom’s security issues. More bugs then started showing up.

One Windows-related bug was discovered to have exposed users to password theft. Another bug allowed bad actors to take control over a Zoom user’s microphone or webcam. One more bug allowed Zoom to gain root access on MacOS desktops — a particularly risky fact.

It was then eventually discovered that Zoom doesn’t use end-to-end encryption as promised and that it was leaking users’ email addresses and photos to strangers through their “company directory” feature.

The following days then revealed more issues like Zoom’s data-mining feature, video call records left viewable on the web, calls “mistakenly” routed through Chinese whitelisted servers, and the discovery of a link to a collection of 352 compromised Zoom accounts in the dark web.

It was just a week after this latest discovery that Cyble found more than 500,000 Zoom accounts on hacker forums.

How the Zoom Credential Theft Occurred

Cyble, a cybersecurity firm, was the first to discover the credentials being sold on hacker forums around April 1, 2020. Cyble then reported this discovery to BleepingComputer.

Apparently, Zoom accounts were being posted on the forums to gain a reputation around the hacker community. Some accounts, like the ones from various colleges, were given for free. Others were sold for $0.002 each.

The stolen credentials included email addresses, passwords, personal meeting URLs, and host keys that allowed threat actors to enter meetings and carry out Zoomboming attacks.

Upon this discovery, Cyble bought 530,000 credentials to warn their owners of the impending threat. When contacted, one exposed user said that the stolen password was an old one. This raised the likelihood that some credentials were stolen through older credential stuffing attacks.

The bad actors got the credentials from accounts leaked in older data breaches and attempted to use them to log in to Zoom. All successful logins were then compiled into the lists that were posted on hacker forums.

Some accounts were given for free to be used in Zoombombing pranks while others were sold in bulk at less than a penny each.

How to Avoid it?

Since these credentials were exposed through credential stuffing attacks, the best way to protect your Zoom account is to change your password. If you’ve had your Zoom account before the pandemic lockdowns started, you might need to change your password now.

This should come as old news, but it’s been ignored enough to warrant a reminder:

Use strong and unique passwords

Strong passwords should be a combination of upper- and lower -case letters, numbers, and symbols. Use a different strong password for each online account — never use the same password twice. Perhaps use a password manager app to generate and keep strong passwords for you.

You can make sure your emails or usernames have not been included in any data breach by checking on data breach-notification services like Have I Been Pwned or AmIBreached. These services will show if your username or email has been exposed and from which company they were stolen from.

In their statement to BleepingComputer, Zoom said that it’s common for bad actors to target web services that serve consumers with this type of activity (credential stuffing). “This kind of attack generally does not affect our large enterprise customers that use their own single sign-on systems” they added.

Zoom also stated that they’ve already hired multiple intelligence firms to find the password dumps and tools used to create them, as well as a firm that has shut down thousands of websites attempting to trick users into downloading malware or giving up their credentials.

Zoom is still investigating, locking compromised accounts, asking users to change their passwords to something more secure, as well as looking to implement additional tech solutions to aid in their efforts.

About the Author

Robert Mardisalu is the co-founder & editor of TheBestVPN.comRobert Mardisalu is the co-founder & editor of TheBestVPN.com, a computer security professional, privacy specialist and cybersecurity writer. He has authored many insightful blogs that help readers to think beyond the surface.

 

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article

445 Mn Cyberattacks Detected Since the Beginning of 2020: Research

Sardonic, BitMart

A new survey from Arkose Labs revealed that the highest cyberattack rate was reported in the first quarter of 2020. The report suggested that 26.5% of all transactions during this period were fraud and abuse attempts, which is a 20% increase over the previous quarter. The survey “The Arkose Labs Q2 2020 Fraud and Abuse Report” also revealed that the U.S. has emerged as the top originator of cyberattacks, with attack levels increasing 20% since the previous quarter. It also found a significant increase in attacks originating from other well-established markets like the U.K., Germany, and Canada.

“With COVID-19 restricting face-to-face interactions across the globe, consumer behavior is in flux and digital transactions are on the rise. Organized fraud operations have been quick to mobilize, targeting spikes in digital activity,” the report stated.

Affected Industries

The research stated that threat actors are shifting their focus according to consumer behavior. According to Arkose Labs, the top targeted sectors for online fraud in the COVID-19 era include:

  • Retail and Travel: The attack rate has doubled from 13% of transactions to 26%, driven by attacks on ecommerce companies as travel tailed off due to restrictions.
  • Gaming: With a 30% rise in gaming traffic, the industry was hard hit with a 23% increase in attack rates.
  • Information Technology (IT): As both personal and professional collaboration and communication shifts online, attacks on tech platforms have risen 16%. Fraudsters looking to blend in with this traffic ramped up their attacks by 25% on new account registrations.

Fraud Predictions

Based on developments from the Q1 of 2020, Arkose Labs outlined various  predictions on the ongoing effects of COVID-19 related threats, which include:

  • A continued, dramatic rise in attacks as fraudsters take advantage of economic uncertainty and new individuals are pushed into cybercrime due to high unemployment
  • Automation to drive the bulk of the increase in fraud, as low-skill fraudsters who are new to the game take advantage of online tutorials and user-friendly, inexpensive fraud toolkits
  • Wider pool of sweatshop labor available with a move away from traditional fraud hubs to a distributed model of ‘guns for hire’ across the globe
  • New attack vectors to emerge as opportunistic fraudsters widen their reach amidst the pandemic
  • Exploitation of vulnerable individuals with a spike in social engineering and phishing scams targeting new users within the digital economy

Based on the attack patterns from January to March 2020, the research analyzed number transactions spanning account registrations, logins and payments across the financial services, ecommerce, travel, social media, gaming, and entertainment sectors. The research findings are based on the mechanics of attacks originating from automated bots, humans, and sweatshops.