Home Blog Page 219

52% of Americans Avoid Using Certain Services Over Privacy Concerns: Survey

personal data collection, Personal data. Data Privacy

Most American adults are concerned about how the government and private organizations use their personal information, an online survey by the Pew Research Center revealed. More than half (52%) of adults in the U.S. stated that they feel their personal data is less secure and decided not to use a product or service over privacy and security concerns. Some are also worried about how much personal information would be collected about them when they make purchases.

The survey which was conducted between June 3 – 17, 2019, also found the role of education and income as factors in determining consumer privacy concerns. Nearly 55% of college graduates and adults with some college education stated they have decided not to use a product or service due to privacy concerns, compared with 45% of those with high school education. And 54% of adults with an annual income of $75,000 or more annually shared this concern, compared with 48% of those who make $30,000 or less.

It was also found that people who had fallen victim to a data breach in the last 12 months were much more inclined to take security steps to keep their personal information secure.

The survey included a set of questions for the respondents, such as a recent situation where they decided to not use a product or service over privacy concerns.-  One-in-five Americans (21%) said they decided not to use particular websites as they felt it unsecure.

Image Courtesy: pewresearch.org

Around 11% said they decided not to use certain electronics. And some stated they avoided social media or specific services such as DNA ancestry kits, financial tools or health care.

  Image Courtesy: pewresearch.org

Apart from these, the most mentioned concern was that they must share personal information (15%) in order to get access to the product or service. The second largest concern was that the product or service is untrustworthy (9%). And 8% cited surveillance as one of the many concerns such as giving payment information, potential third-party involvement, and the risk of scams.

Zaha Hadid Architects Suffers a Ransomware Attack

Ransomware, supply chain and ransomware

As per a report in the Architects’ Journal, Zaha Hadid Architects (ZHA) – an architectural firm in the U.K., has reportedly suffered a ransomware attack on April 21, 2020. This malicious activity has disrupted the remote operations of its 348 London-based employees who are working from home amid the national lockdown. Zaha Hadid Architects detected the ransomware attack when they found messages left on its server stating that the internal company data has been hacked and encrypted and would only be released on negotiating a ransom settlement with the cybercriminal(s).

ZHA immediately alerted the police and took the help of the cyber forensics team to investigate the extent of the data breach. As per sources, server encryption does not pose a serious problem, as ZHA’s data was backed up. However, the uncertainty factor is how much information has been stolen. To this, ZHA believes that no project data was stolen or interfered with during the ransomware attack.

It also noted that although its employees were locked out of the server and were forced to perform a mandatory password reset, the attack has not seriously affected the firm’s daily operations. Initially, the clients were not alerted of the security breach, as the company was not sure if its communications system were secure enough post the attack.

However, it later told Architects’ Journal that, “Data protection and privacy is extremely important to us and this is why we regretfully have to announce that on 21 April we experienced a security breach and theft of data in a ransomware attack. We immediately worked to secure our network and reported the incident to the authorities. With minimal disruption to the work of our teams, we continue to investigate any criminal theft of data with cyber specialists.”

Earlier in the month, information technology services provider Cognizant admitted of falling prey to a ransomware attack. In an official statement, the IT giant stated that it was hit by Maze ransomware that caused service disruptions for some of its clients. Cognizant notified its clients and users about the ransomware incident and engaged with required law enforcement authorities to investigate the attack. They provided their clients Indicators of Compromise (IOCs) and other technical information of defensive nature, to help tackle the crisis efficiently.

66% of Remote Workers in the U.K. Lack Cybersecurity Training: Research

4 in 10 Organizations Struggle with SOC Staff Shortages: Report

The surge in remote work has brought a new wave of cyberattacks targeting remote workers. Several industry experts stated that the lack of cybersecurity training may increase cyber risks.

A new research from cybersecurity firm Promon found that 66% of remote workers in the U.K. haven’t been trained on cybersecurity in the past 12 months,  whereas 77% said that they aren’t worried about the security while working remotely. Around 61% said they are using personal devices when working from home. This is adding further security concerns as many of these are likely to be less secure than corporate-issued ones.

Cybercriminals are exploiting the current working conditions by carrying out COVID-19-related phishing campaigns and other malicious activities, the research stated. The findings are based on the responses from 2,000 remote workers in the U.K.

“Cybercriminals are taking advantage of decreased levels of security on personal devices connected to corporate networks, with successful attacks ringing alarm bells for employers whose sensitive corporate data is now at risk, along with individuals’ personal data, including banking information and login details,” the report said.

Promon CTO and Co-founder Tom Lysemose Hansen, said, “It’s concerning to find that such a large number of workers don’t have the necessary training to spot a potential cyber threat, such as a phishing email or spoofed website, as these are the main ways in which cybercriminals are executing their attacks. Organizations must ensure that staff who are working remotely are doing so in secure environments, whether that’s on personal or corporate devices, and it’s critical that they provide the necessary training and tools to ensure corporate data is protected.”

U.K. Firms Suffer Basic Cybersecurity Skills Shortage

A similar research into the U.K. cybersecurity labor market by the Department for Digital, Culture, Media & Sport (DCMS) found an increase in the basic cybersecurity skills gap in most organizations in the country. According to the research, around 653,000 organizations (48%) in the U.K. are unable to carry out basic tasks defined in the government’s Cyber Essentials Scheme like setting up firewalls, storing data, and removing malware. The report claimed that 408,000 businesses (30%) lack advanced cybersecurity skills in areas like pen testing, forensics, and security architecture.

“Threat Detection has Evolved from Static to Dynamic Behavioral Analysis to Detect-Threatening Behavior”

Debashish Sonicwall

Debasish Mukherjee is the Vice President, Regional Sales (APAC), SonicWall. He has over 18 years of experience throughout in IT industry and has worked in India & Middle East in various roles. During this time, he focused on building and motivating cross-functional teams as well as managing and driving partner and customer relationships in various organizations. Mukherjee is in the security industry since last seven years; prior to that he was with Dell as the Regional Solution Manager and with Huawei as the Regional Sales Director. He has an extensive experience in Channel Sales, Data Center Solution & IT Infrastructure solutions across verticals.

In an exclusive e-mail interview with Augustin Kurian, Senior Feature Writer of CISO MAG, Mukherjee talks about the fast-moving cryptocurrency markets and how bitcoin is helping cryptojacking to stay a relevant lucrative option for cybercriminals. He discusses some of the pressing cybersecurity issues faced by Indian telcos. Mukherjee states that unknown zero-day threats are just that — unknown. And there is no way to predict the next vulnerability avenue that will be exploited. He highlights how SonicWall’s intelligence-driven analytic service addresses zero-day attacks.

In one of your earlier interviews with CISO MAG, you said, “The rise of ransomware forced companies to improve their defenses against malware and intrusions. As a result, malware developers seek new ways to evade network security defenses.” While hackers are innovating and leveraging methods like cryptojacking, what are the steps taken by Sonic Wall to thwart malicious activities like cryptojacking and many others?

With the rising costs of mining cryptocurrencies such as Bitcoin, hackers develop and distribute malware to make victims do it for them. SonicWall prevents cryptojacking software from being downloaded and spreading throughout the network through the power of our next-generation multi-layered technology chain of security devices and services.

Cryptocurrency markets are fast-moving, where quick bull runs (often caused by price manipulation) can cause dramatic price spikes. Bitcoin ($BTC) prices also drive the value of Monero ($XMR), which is the alt coin of choice for many cybercriminals since its transactions can’t be publicly tracked like bitcoin. Halfway through 2019, bitcoin is surging again and is helping cryptojacking stay relevant as a lucrative option for cybercriminals. Cryptojacking volume hit 52.7 million registered attacks for the first six months of the year, as published in the mid-year update of the 2019 SonicWall Cyber Threat Report.

We can log hits and analyze signatures all day. But it remains difficult to align cryptojacking attacks — and criminal intentions — with cryptocurrency value.

Ultimately, it doesn’t matter what they mine. It only matters how they mine and all forms of these illegal miners — and future — damage systems and create security vulnerabilities.

SonicWall Firewalls filter out cryptojacking software entering the network. Intrusion Prevention Service (IPS) stops cryptojackers like Coinhive from spreading across the network and connected devices. Eliminate phishing emails with SonicWall Email Security. Scan email attachments and embedded URLs for advanced threats. Prevent malicious uploads with SonicWall Secure Mobile Access (SMA). Roll back affected endpoints with cryptojacking software to a clean state with Capture Client. Leverage SonicWall Gateway Anti-virus to stop known forms of cryptojackers. Funnel suspicious files to SonicWall Capture ATP to discover and stop new strains of coinhive and other related attacks. Block access to cryptojacking websites with Content Filtering Service. Continuously monitor system behavior for cryptocurrency mining behavior.

SonicWall is aiming to provide managed security services to Indian telcos. What advancements have been made on that front? Also, what are the pressing cybersecurity issues faced by Indian telcos?

Risk to non-adherence to cybersecurity regulations, breach of subscriber data, DDoS intended to disrupting services, risk management and mitigation for rolling out new technologies with right security controls, stopping leakage of database by outsourced entities, minimize the magnitude of an event to recover as quickly as possible and reduce the impact on their customers.

These however have brought new avenues to telcos. They can offer cybersecurity services to enterprises, providing services on securing end customer networks, thereby using cybersecurity as an opportunity to gain upper hand in a very competitive market.

In this perspective SonicWall has developed many offerings for MSSP and in India we have started offering our services with one of the leading telcos and we are in process of launching several new services in next few months.

When it comes to malware detection and protection, several companies are relying on signature-based malware monitoring. What are the challenges in using signature-based malware monitoring? How does SonicWall differentiate itself from other vendors when it comes to malware detection and protection?

Threat detection has evolved from static to dynamic behavioral analysis to detect-threatening behavior. Comprehensive layers of defense, properly placed within the network and the endpoint, provide the best and most efficient detection and response capabilities to match today’s evolving threats.

For years, SonicWall offered endpoint protection utilizing traditional antivirus (AV) capabilities. It relied on what is known as static analysis. The word “static” is just like it sounds. Traditional antivirus used static lists of hashes, signatures, behavioral rules and heuristics to discover viruses, malware and potentially unwanted programs (PUPs). It scanned these static artifacts across the entire operating system and mounted filesystems for retroactive detection of malicious artifacts through scheduled scanning.

Traditional antivirus focuses on pre-process execution prevention. Meaning, all the scanning mechanisms are primarily designed to prevent the execution of malicious binaries. If we go back 20 years, this approach was very effective at blocking the majority of malware, and many antivirus companies capitalized on their execution prevention approaches.

SonicWall developed advanced real-time memory monitoring to detect malware designed to evade sandbox technology. Today, SonicWall uses a multitude of capabilities — coupled with patent-pending Real-Time Deep Memory Inspection (RTDMITM)—to identify and mitigate malware more effectively than competing solutions.

SonicWall Capture Client is a unified endpoint offering with multiple protection capabilities. With a next-generation malware protection engine, Capture Client applies advanced threat protection techniques, such as machine learning, network sandbox integration and system rollback. Capture Client uses automated intelligence to adapt and detect new strains of malware through advanced behavior analytics. One crucial feature of the latest Capture Client solution is the ability to record all the behaviors of an attack and the processes involved on an endpoint into an attack storyline—essential for security operations detection, triage and response efforts. SonicWall Capture Client combines multiple technologies to provide the most efficient and effective defense against threat actors. The solution should be paired with a defense-in-depth security strategy across all the key layers of transport, including email, network and endpoints.

Adoption of AI and ML is touted to be the future of cybersecurity. In that front, SonicWall has always been way ahead in the league. Briefly tell us about the upcoming products and services from SonicWall that aim to counter threats of the future.

Unknown zero-day threats are just that — unknown. You have no way (besides historical experience) to predict the next vulnerability avenue that will be exploited. The other quandary faced when tackling complex targeted zero days is the skills gap. Staffing a security operations center (SOC) with highly skilled cybersecurity professionals comes at a cost and only becomes profitable with economies of scale that a large customer base brings.

AI understands the big data coming from behavioral analysis. It can adapt the discovery approach to uncover threats that try to hide and, once determined as malicious, can fingerprint the payload via signature, turning a zero day into a known threat. It is the speed of propagation of this new, known signature to the protection appliances participating in the mesh protection network that drives the efficiencies to discover more threats.

Also, it’s the size of the mesh network catchment area that allows you the largest overall service area of attaches, which helps your AI to quickly learn from the largest sample data set. SonicWall has you covered on all these fronts. With more than one million sensors deployed across 215 territories and countries, SonicWall has one of the largest global footprints of active firewalls. Plus, the cloud-based, multi-engine SonicWall Capture Advanced Threat Protection (ATP) sandbox service discovers and stops unknown, zero-day attacks, such as ransomware, at the gateway with automated remediation. Our recent introduction of the patent-pending Real-Time Deep Memory Inspection (RTDMITM) technology, which inspects memory in real time, can detect and prevent chip vulnerability attaches such as Spectre, Meltdown and Foreshadow. It’s included with every Capture ATP activation.

At SonicWall, the mantra of automated, real-time breach detection and prevention is fundamental to our security portfolio. It is how our partners drive predictable operational expenditures in the most challenging security environments. Only via connected solutions, utilizing shared intelligence, can you protect against all cyberthreat vectors.

Can you update us how SonicWall products address zero-day attacks? What is the kind of “threat intelligence” and “predictive capabilities” in your products?

SonicWall Analytics is a powerful intelligence-driven analytic service. It gives a direct line of sight into the threat intelligence of your networks and users in real time, all through a single pane of glass. With drill-down capabilities, security teams can mine various sets of contextualized firewall log and flow data to easily find and tackle security as well as network performance issues quickly.

SonicWall provides single-pane visibility and complete situational awareness of the network security environment, perform deep investigative analysis, gain deeper knowledge and understanding of potential and real risks and threats, hunt, detect and remediate risks with greater clarity, certainty and speed, reduce incident response time with real-time, actionable threat intelligence.

Analytics is available in SaaS mode via the SonicWall Capture Security Center and can also be deployed on key virtual platforms such as VMWare and Hyper-V. The flexibility to leverage this product across multiple platforms along with capex or opex-based licensing helps ease the financial and operation planning and decision processes. This gives organizations the operational and economic benefits of virtualization and cloud computing. It also enables dynamic upscaling of storage to fulfill the growing data retention requirements from virtually unlimited number of firewall nodes.

SonicWall is announcing new offerings for managed security service providers (MSSP) on April 6, 2020. The newly announced capabilities allow MSSPs to simplify oversight, visibility and management of cybersecurity ecosystems as they continue to expand.

The cyberthreat intelligence, which is available in the SonicWall Security Center, maps the behavior of cybercriminals and the tactics they employ to breach the networks of businesses and organizations across the world. Included with Capture ATP, SonicWall’s patent-pending RTDMI technology catches more malware than behavior-based sandboxing methods, with a lower false positive rate.

First announced in February 2018, RTDMI technology is used by the SonicWall Capture Cloud Platform to identify and mitigate even the most insidious cyberthreats, including memory-based attacks. RTDMI proactively detects and blocks unknown mass-market malware — including malicious PDFs and attacks leveraging Microsoft Office documents — via deep memory inspection in real time. Because of obfuscation techniques, many legacy firewalls and anti-virus solutions are unable to effectively identify and mitigate PDFs or Microsoft Office file types that contain malicious content.

Hackers Exploit Web Application Vulnerabilities to Deploy Malicious Web Shell

Compromised Email Accounts

The U.S. National Security Agency (NSA). and the Australian Signals Directorate (ASD) recently issued a joint security advisory “Cybersecurity Information Sheet” (CSI), which details threat actor activities. The security agencies stated that hackers are exploiting web application vulnerabilities to deploy the malicious web shell. The advisory contains a wide range of information for security teams who want to detect hidden web shells and to block malicious actors from deploying such tools on unpatched servers.

“Malicious cyber actors have increasingly leveraged web shells to gain or maintain access on victim networks. This guidance will be useful for any network defenders responsible for maintaining web servers,” the advisory stated.

What Is Web Shell Malware?

Web shell malware is a software deployed by a hacker on a compromised internal or internet-exposed server to gain access by executing arbitrary code remotely and delivering the malicious payloads. These web shells provide hackers with a visual interface that allows them to communicate with a hacked server and its file system. The web shells enable hackers to rename, copy, delete, edit, and upload files to the server.

“Web shell malware has been a threat for years and continues to evade detection from most security tools. Malicious cyber actors are increasingly leveraging this type of malware to get consistent access to compromised networks while using communications that blend in well with legitimate traffic. This means attackers might send system commands over HTTPS or route commands to other systems, including to your internal networks, which may appear as normal network traffic,” the NSA said.

Attackers install malicious web shells on the internet-connected servers or in web applications like CMS, CMS plug-ins, CRM-systems, and corporate applications to exploit the vulnerabilities in them.

Web Application Vulnerabilities Used to Install Web Shells

The NSA and ASD provided a list of commonly exploited web application vulnerabilities in web applications. These include:

Image Courtesy: media.defense.gov

The advisory listed instructions on web shell detection, prevention, and mitigation strategies. “Web shells can play the role of tenacious backdoors or relay links to route malicious programs or scripts to other systems. Usually, hackers connect web shells on several compromised systems simply to route traffic over networks, from the internet-connected systems to internal networks,” the advisory added.

Shade Ransomware Terminates Operations; Releases 750K Decryption Keys

New Programming Language

The operators behind the infamous Shade ransomware recently announced that they have shut down their operations. The hacker group released over 750,000 decryption keys and also apologized for the damages they caused to victims. In a GitHub repository, the operators stated that they stopped distributing the ransomware and other malicious activities at the end of 2019. They also provided instructions on how to encrypt and recover files using the released keys.

Shade ransomware was considered as one of the most dangerous threat actor groups which has been active since 2014. The Shade group, also known as Troldesh and Encoder.858, attacked several organizations in Russia and Ukraine by distributing malware via spam phishing mails and malicious attachments.

“We are the team which created a trojan-encryptor mostly known as Shade, Troldesh or Encoder.858. In fact, we stopped its distribution in the end of 2019. Now we made a decision to put the last point in this story and to publish all the decryption keys we have (over 750 thousand at all). We are also publishing our decryption soft; we also hope that, having the keys, antivirus companies will issue their own more user-friendly decryption tools,” the hacker group said in a statement.

Along with 750K individual victim’s decryption keys, the repository also contained a decryptor, five master decryption keys, and the instructions on how to use them. Some security researchers also confirmed the validity of the released keys and working on creating a free decryption tool.

“All other data related to our activity (including the source codes of the trojan) was irrevocably destroyed. We apologize to all the victims of the trojan and hope that the keys we published will help them to recover their data,” the statement added.

Insider Threats Rise by 47% in Two Years: Report

Insider attacker leak data

Several industry experts stressed that insider threats are the primary concern for every security leader, as many organizations fail to address the insiders within their own company. As a result, numerous data breaches happen due to employee negligence or unintentional actions like responding to a phishing email with sensitive information or downloading malicious content. In addition, with the ongoing crisis due to the COVID-19 pandemic, companies across the globe are working remotely. This is creating new opportunities for threat actors to launch insider threats.

A recent survey report “2020 Cost of Insider Threats: Global Report” from the Ponemon Institute revealed that  insider threats increased by 47% from 3,200 in 2018 to 4,716 in 2020. It also revealed that the cost of insider threat incidents also surged by 31% from $8.76 million in 2018 to $11.45 million in 2020.

According to the survey, negligent employees create around 62% of security incidents, costing organizations an average of $307,111 per incident. The fastest-growing industries for insider threats are the retail sector (38.2% two-year increase) and the financial services sector (20.3% two-year increase). It takes 77 days for a company to contain each insider threat incident, and only 13% of the analyzed security incidents were contained in less than 30 days, the report stated.

Irresponsible employee behavior and reduced vigilance of organizations can allow any malicious insiders to further exploit their administrative privileges to disrupt an organization’s operations. Amid the rapid change in work conditions, many companies are struggling to cover security gaps while also dealing with the variety of COVID-19-related threats.

65% of Employees Access Documents Unrelated to Their Jobs

A similar survey on insider threats conducted by unified security and risk analytics firm Gurucul, revealed that nearly 65% of cybersecurity professionals have accessed documents that are not related to their job profiles. It also found that 40% of respondents who had negative performance reviews, also admitted to abusing their privileged access. According to the survey responses, about 58% of security professionals in the finance sector admitted that they have emailed company documents to their personal accounts. While 78% of them in the manufacturing sector accessed documents unrelated to their job profiles. In retail, 86% of security professionals said they’ve clicked on links from unknown sources.

Moscow Police Detains Two Individuals for Fake Digital Pass Scam

Russia, Moscow, fake digital passes

Together with the Moscow Department of Information Technology, Group-IB a Singapore-based cybersecurity company, helped Moscow police to identify and detain two individuals for running a fraudulent online service. The alleged operators were selling fake digital passes to the residents of Moscow, St. Petersburg, and Krasnodar that would help them to move around the various cities amidst the ongoing nationwide COVID-19 lockdown. The detainees have confessed to the fraud and as a result, criminal charges have been pressed against them in accordance with the Russian Criminal Code (Article 159).

The danger is that by purchasing fake lockdown passes the victims may lose their money, payment data, and sensitive personal information.

The Fake Digital Pass Epidemic

Researchers at Group-IB discovered the first traces of fake digital passes sale in late March, when the government authorities in Moscow clamped down on travel around the city and stressed on self-isolation. The fraudsters, who passed themselves off as law enforcers, pledged to help their “clients” with the issuance of passes on the public services portal Gosuslugi.ru, based on a “semi-legal” scheme, as they said. Fraudsters further asked the potential victims to send the passport details and the license plate number if they needed a relevant permit for their vehicle as well. The cost of their services ranged between $38 – $45 per digital pass.

The investigators found a total of 126 fraudulent online resources including 25 websites, 35 groups and accounts in social media, and 66 channels on the Telegram messenger, to be fraudulently selling these fake digital passes and certificates. Over a half of them (78) have already been blocked. However, since April 13, a huge flux in the growth of fraudulent services’ registration — websites, Telegram channels, and accounts on the VK (Russian social media network) and Instagram — was observed.

fake digital passes
Image Source: Group-IB

Official Channels for Digital Passes

Owing to the rising number of fake digital pass channels, a Moscow mayor decree has stated three official ways to get the digital passes for free:

  • Through the mos.ru website,
  • By calling +7 (495) 777-77-77 phone number, or
  • By sending an SMS to 7377.

Sergey Lupanin, head of cyber investigations at Group-IB said, “The danger is that by purchasing fake lockdown passes the victims may not only lose their money and payment data, but also sensitive personal information. For example, by obtaining the victim’s ID number fraudsters can apply for a loan on their behalf.”

Governments See Cybersecurity as an Opportunity to Develop Hi-tech Ecosystems

Israel cybersecurity startup

Israel’s startup era was a result of a geographically small country that had limited trade with its neighbors. From the early days of what we now call cybersecurity, Israel’s government has invested in its people to develop leading technologies that focus on keeping its citizens safe.

Israeli entrepreneurs used these initiatives, turning inward to developed technologies aimed at addressing various industry pain points in the defense, communications, and health care sectors. The non-stop breakthroughs which came out of Israel caught the attention of global headlines and of venture capital firms.

By Zohar Rozenberg, Chief Security Officer at Elron

During these earlier years, I was involved in the formalization of Israel’s National Cyber Strategy and saw firsthand the power governments hold in inspiring and enabling its citizens to come together under the umbrella of innovation. Today, along a strip spanning 15 Km by 3 Km between Tel Aviv and Herzliya, one can find 348 Investors all thriving, thanks to those private and public partnerships from years ago. This beachfront strip barely developed just 100 years ago, has boomed into a Middle East oasis of investors, developers, and entrepreneurs that has become the epicenter of today’s digital revolution.

For governments who are thinking of how to build and harbor a notable cyber ecosystem, collaboration is a necessity. Domestic collaboration begins by acknowledging how much the public and private sectors are natural partners. When governments provide grants for academic research, startups, and innovation centers, there will be a continuous flow of new technologies that will act as the lifeblood of their ecosystems. Collaboration also needs to occur between foreign governments. Cross-border partnerships make for better-secured infrastructure and invites global tech companies to develop global R&D centers leading to the sharing of expert knowledge.

Governments not only hold the power to energize private entities but hold the ability to prepare today’s youth for future contributions across the ecosystem. Incorporating cyber education into school curriculums will create a mindset of online responsibility from the moment students begin navigating the web on their own. This engrained online vigilance will make them more desirable to cyber firms and harbor an ability to better contribute to every aspect of the ecosystem in the future.

A slogan of ‘stronger together’ needs to be at the forefront of any government that is serious about developing its cyber ecosystem. For governments who are looking to grow their cyber ecosystem, education, collaboration, sponsored events, and conferences show that your doors are open for business, actively promoting economic growth, and ready to work with businesses who want to secure our cyber technologies.

RELATED STORY

Cyber Startup Hub in Israel Declines as Global Competition Rises: Elron VP

About the Author

Zohar Rozenberg, Chief Security Officer at Elron. Hi-tech Cyber EcosystemsZohar Rozenberg (Col. Ret.) is the Chief Security Officer at Elron, an Israeli holding company dedicated to building technology companies, actively investing in startup companies. He is also acting as Member of the Board for several cyber companies. Zohar was also involved in the establishment of the National cyber bureau and the formalization of the Israeli national cyber strategy.

Disclaimer 

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

How a Malicious GIF Made Microsoft Teams Platform Vulnerable

How a Malicious GIF Made Microsoft Teams Platform Vulnerable

Microsoft recently fixed a “Subdomain Takeover” vulnerability in its office communications platform Teams that could have allowed hackers to take control of the organization’s entire list of Teams accounts simply by sending a malicious image or GIF. The vulnerability, that affected both desktop and web versions of the Teams app, was discovered and disclosed by security researchers at CyberArk on March 23, 2020.

The researchers stated that hackers could access all the information from the organization’s Teams accounts, including, competitive data, secrets, passwords, private information, meetings and calendar information, business plans, and other confidential information.

Subdomain Takeover Vulnerability

According to CyberArk, the vulnerability stems from the way Microsoft Teams handles authentication to image and GIF resources. The researchers found that they were able to obtain a cookie (called “authtoken”) that grants access to a resource server, which gives them  permissions to send messages, read messages, create groups, add new users or remove users from groups, and change permissions in groups via the Teams API.

The researchers also found two subdomains (aadsync-test.teams.microsoft.com and data-dev.teams.microsoft.com) that were vulnerable to attacks. “If an attacker can somehow force a user to visit the subdomains that have been taken over, the victim’s browser will send this cookie to the attacker’s server, and the attacker (after receiving the authtoken) can create a skype token. After doing all of this, the attacker can steal the victim’s Team’s account data,” the researchers said.

How the Attack Works?

The attack involves tricking the targeted Teams user into viewing a malicious GIF image. Using the compromised subdomains, attackers exploit the flaw by just sending a malicious image or a GIF to the targeted member or a group. When the recipient opens the message, the browser tries to load the image, but not before sending the authtoken cookies to the compromised sub-domain.

In a proof-of-concept (PoC) video, CyberArk described how an attacker can use this authtoken cookie to create a skype token and access all the victim’s data.

“Even if an attacker does not gather much information from a Teams’ account, they could still use the account to traverse throughout an organization (just like a worm).  They could also exploit this vulnerability to send false information to employees – impersonating a company’s most trusted leadership – leading to financial damage, confusion, direct data leakage, and more,” CyberArk concluded.