Home Blog Page 224

Apple Is Hackers’ Favorite for Brand Phishing Attacks

Apple Is Hackers’ Favorite for Brand Phishing Attacks, REvil gang threatens Apple blueprint leak

Apple was the most frequently used brand in phishing attacks during the first quarter of 2020, according to Check Point’s research. The research report “Brand Phishing Report” revealed that nearly 10% of all brand phishing attempts in 2020 so far were misusing the Apple brand.

The report stated that Apple is the primary target for cybercriminals to exploit its brand recognition, which soared from seventh place in Q4 of 2019 to the top this year in rankings. The report highlights various brands which were frequently imitated by hackers in their cyber activities to steal a victim’s sensitive information. According to the report, Netflix took the second position after Apple with 9% of all phishing attempts related to the company. The Chase Bank brand rose by 3% from Q4 2019 to the sixth position, with 5% of phishing attempts.

What is a Brand Phishing Attack?

In brand phishing attacks, attackers imitate the official website of a popular brand by creating a similar domain name or URL of the original site. The links to the fraudulent website will be sent to targeted individuals via email or SMS. Once a user clicks the link, it redirects to the fake website which often contains a form intended to steal users’ credentials, payment details or sensitive information.

Check Point stated that technology, banking, and media are the most targeted sectors in brand phishing attacks. The company also listed the top ten brands targeted in phishing attacks in Q1 2020, which include:

  1. Apple (with 10% of brand phishing attempts globally)
  2. Netflix (9%)
  3. Yahoo (6%)
  4. WhatsApp (6%)
  5. PayPal (5%)
  6. Chase (5%)
  7. Facebook (3%)
  8. Microsoft (3%)
  9. eBay (3%)
  10. Amazon (1%)

The research indicated that web phishing was reported as the most common attack vector with 59% of attempts in Q1 of 2020. While mobile phishing was second, with 23% of attempts and email phishing came in third with 18% of attempts.

Maya Horowitz, Director, Threat Intelligence & Research, Products at Check Point, said, “Cybercriminals continue to exploit users by adopting highly sophisticated phishing attempts via emails, web and mobile applications purporting to be from well-recognized brands which they know will be in high demand at the moment, whether that’s a high profile product launch or just generally tapping into behavioral changes we’ve seen during the Coronavirus pandemic. Phishing will continue to be a growing threat in the coming months, especially as criminals continue to exploit the fears and needs of people using essential services from their homes. As always, we encourage users to be vigilant and cautious when divulging personal data.”

How a Red Team Engagement Can Improve Your Security Preparedness

Red Teaming Blue Team Red Team

You may have a very mature security program for your organization with comprehensive technical and administrative security controls.  You have stopped a variety of dangerous events in the past 12 months and you can see things are going well overall. But there’s always room for improvement. The threats we can’t see and can’t plan for are still lurking. But you can check the maturity and strength of your security posture by conducting a Red Team engagement.

Contributed by Dick Wilkinson, IT Security Officer, New Mexico Judicial Information Division

Red Team engagements are a series of simulated attempts to breach your security perimeter. The concept can include physical attempts to enter secure spaces, social engineering on the phone and in person, technical attacks against your computer network or even a spear-phishing attempt at senior board and executive members. The team of people executing these attacks will be given some amount of limited knowledge about your organization and some clear boundaries on acceptable behavior.

Some considerations when planning a Red Team engagement:

  • No breaking windows to gain entry or physically damaging computer equipment to disrupt the network.
  • Capture the boundaries in your contract’s statement of work. The hope is to create a realistic dress rehearsal of attacks your organization may face.
  • Understanding your business market, the security practices of industry peers and the threats that face your industry as a whole are crucial to creating a realistic set of scenarios your security plan can defend against.
  • The previous experience of the red team will likely determine what techniques they find most useful.
  • Be open to suggestions from the team and listen to how they have helped previous clients.

This event can be a learning experience for your organization, even during the planning stages, before any offensive actions have taken place.

The Blue Team defends

The alternative to the red team engagement is the blue team. This is your team of network defenders, and they are probably already doing the job of protecting your network daily. These employees are crucial to help you define what the outcome of this special event should be. They should have the best insight to understand what the weakest parts of your security plan may be.

What a Blue team offers:

  • Advice from this group could range from very technical input to general anecdotes about previous security incidents.
  • The historical knowledge these employees have should be built into your requirements for your red team actors. That knowledge may not define the entire plan but it will give you very clear starting points.
  • The everyday network defenders will be your blue team during the engagement as well.

Some considerations for the Blue team engagement:

  • To maintain some realism to the penetration events, keep this team out of the meetings where you go over the plan with the red team.
  • You will want the defenders to use their real-world tools and sensors and execute real responses to the red team’s offensive actions.
  • They need to have some element of surprise to act the way they would in real scenarios.
  • Details to share with the blue team should be the rules of the engagement, what is and is not allowed; the start and end date of the event; the way to call a stop to the exercise if a real-world incident begins to impact business operations.
  • The blue team does need to be informed but they should not know the script the red team may follow.

Planning a Red Team Engagement

Several factors may lead to the decision to hold a red team engagement. Your industry regulations may require some type of adversarial event to prove your security plan is well designed. Your leadership may have heard about another organization’s event and wants to try it at your company.

A red team event could be self-directed because you and the IT staff know it is time to really push the limit and prove that your ideas work. Understanding why you need to do the red team will determine what you should expect to learn from the engagement. From the beginning of planning the event, the IT staff needs to create clear objectives to cover that help you learn the most about your gaps in the security plan.

Create a list of known threats and what controls you have in place to protect against those threats; refer to your risk registry to get you started. When you discuss the need and desired learning outcomes with the team that will engage in the penetration attempts, be very clear with your expectations.

Some red team events are conducted by internal audit teams, some by third-party security vendors; this can change the expected outcomes and that should be identified early in the planning process.

Some important items to consider in the plan could include:

  • Will there be a physical perimeter breach attempt?
  • Will we allow social engineering?
  • Could there be a punitive response from HR if an employee violates company policy during the test?
  • How much detail do you share with your executives and board if they are considered “in-scope” targets of the test?
  • How will you call an emergency stop to the event and how will that be communicated to all participants, vendors and company employees?
  • What laws may dictate how we execute the event? Physical security vendors have been arrested during scripted penetration events.

Most important of all, what are we going to do when we hear bad news? As the IT leader in this engagement you will feel responsible for the outcomes of this event. This is your plan, your defenses, and your security team; a failing grade may be hard to face. Talk openly before anything ever starts about where you think you might fail. Be clear with senior leadership that this event may lead to some outcomes that cost time and money to remediate.

In the course of one or two weeks you will learn more about the effectiveness of your program than you could in one or two years of regular operations having only minor incidents. The impact that this engagement can have on moving your security posture to a new level can’t be understated.

Create the narrative that this was not a failure but an accelerator to your next level of maturity. When you speak in those terms to your leadership and employees, they will take the deficiencies found by the red team as a plan to grow from, and not a report card that says you failed.

This article has been adapted for online reading. Read the complete article in the March issue of CISO MAG here.

 

About the Author

Dick WilkinsonDick Wilkinson is the Chief Information Security Officer on staff with the Supreme Court of New Mexico. He is a recently retired Army Warrant Officer with 20 years of experience in the intelligence and cybersecurity field. He has led diverse technical missions ranging from satellite operations, combat field digital forensics, enterprise cybersecurity as well as cyber research for the Secretary of Defense.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

PII of 115 Million Pakistani Mobile Users Up for Sale on Dark Web

Dark Web

Pakistan-based cybersecurity company, Rewterz Threat Intelligence, discovered a sale advertisement of 115 million Pakistani mobile users’ data being put up on the dark web by an undisclosed hacker.

Researchers at Rewterz said that the threat actors are monetarily motivated as they have placed a minimum price tag of 300 bitcoins amounting to approximately $2.1 million for the leaked data. Researchers added that the threat actors hold a premium account on the dark web forum where it has been advertised. The uploaded data dump had been recently hacked and was still being updated as per the advertisement. However, it is still unclear if any specific telecom operator(s) or all telecom operators in Pakistan fell victim to this malicious attack, and whether the data was collected through a single data breach or over a period of time from multiple data breaches.

The threat actors have organized the data neatly in a CSV file. It contains personally identifiable information (PII) of all its users including name, address, phone numbers as well as their CNIC and NTN numbers.

The Dark Web Ad says…

PM (personal message) offers and Questions

Database is freshly hacked this week. That data was still being updated as I took the data down. Beautifully organized in a CSV with headers for your pleasure.

Headers: ID, MSISDN, ACT_DATE, STATUS, L_DATE, NAME, CNIC, TAX_NO, ADDRESS, PHONE1, PHONE2, CITY, REGION

Starting Cost: 300BTC (Bitcoins)

Rewterz researchers said, “It might be possible that these (compromised) telecoms companies have failed to disclose the data breach because they aren’t aware of the hack or have intentionally opted not to reveal it. Either ways, it’s concerning for customers whose information has been published.”

Freedom Mobile Users’ Data Leak

Earlier, Freedom Mobile, a Canada-based mobile network company, suffered a data breach that exposed the personal information of around 1.5 million of its customers. According to the security researchers Noam Rotem and Ran Locar from the security firm vpnMentor, a technical glitch in an Elasticsearch server exposed five million logs that contained Freedom Mobile customers’ data. The researchers stated the server was left online without password protection, allowing anyone to access the data.

Freedom Mobile stated the unprotected server revealed its users’ sensitive information, including customer names, email addresses, phone numbers, postal addresses, dates of birth, customer types, Freedom Mobile account numbers, and credit card information.

Experts Predict High Demand for Cybersecurity in India Post COVID-19

SideCopy Malware Campaign

With organizations working remotely, cybersecurity works as a core technology to keep companies secure. The Indian cybersecurity market will witness an increase in the demand for cybersecurity and privacy post the COVID-19 pandemic, according to IANS.

Experts opined that, once the pandemic settles, organizations will focus on digitization, including traditional sectors like education and hospitals. Since companies struggle to integrate cybersecurity in the initial stages, there will be an increase in the demand for cybersecurity professionals in the country.

According to Ajay Sawhney, Secretary, Ministry of Electronics and Information Technology (MeitY), the Indian government has collaborated with DSCI (the Data Security Council of India) to establish a National Center of Excellence that will accelerate innovation in the Indian cybersecurity market.

“Currently, all focus lies on COVID-19 management and innovation challenges are running to help us tackle the pandemic but all this will possibly transform into something larger, and we should never waste a crisis but take it as an opportunity,” Sawhney stated.

Rama Vedashree, CEO of DSCI, said, “As India gears up to become a hub for cybersecurity, investment becomes the game-changer to nurture startups. We have seen an uptick in cybersecurity patent filing and grants in India which proves the growing innovation ecosystem in our country. As Big Data, AI, Cloud and other deep tech emerges, cybersecurity serves as a foundational tech across all technologies and for that, we need a spurt in innovation and investment.” 

Growth in the Indian Cybersecurity Market

According to a joint study by PwC India and DSCI, the cybersecurity market in India will grow from $1.97 billion in 2019 to $3.05 billion by 2022, at a compound annual growth rate (CAGR) of 15.3%. The study also stated that Banking, Financial Services and Insurance (BFSI), IT, and government are the top three sectors with the largest market share in cybersecurity expenditure in the country.

The study highlighted that cybersecurity products in India will grow at a higher rate. It is believed that data protection and endpoint security tools will grow at a CAGR of 22.2% and 19.1% respectively over three years. DSCI also mentioned that global regulations like GDPR, Health Insurance Portability and Accountability Act (HIPAA), and Health Information Trust Alliance (HITRUST) will continue to have an impact on the Indian cybersecurity market.

Stay Operational Regardless of What Tomorrow’s Headlines May Bring

Global Cybersecurity Outlook 2022,Cybersecurity, CEO, CISO

Introduction

Whether for ensuring business continuity or enhancing workforce retention and productivity, more organizations are embracing mobility, work-at-home and flex-time for their employees. To achieve business goals with a mobile and remote workforce, having a robust and reliable access security service has never been more critical. A key element of ensuring reliable mobile access is maintaining security updates, but maintenance can disrupt service and performance. Organizations need to maintain a flexible work environment without losing availability, but deploying a highly available service can be complex, costly and time consuming.

Contributed by SonicWall

Effective cybersecurity must include secure mobile access

Providing mobile access in today’s anywhere/anytime, hyper-distributed world opens an explosion of exposure points over a myriad of potentially insecure mobile endpoint devices. Human fallibility and risky online behavior mandate that employees cannot be trusted to ensure the security of their own mobile devices.

Moreover, the array of threat types is expanding, deepening and getting smarter, including targeted ransomware, never-before-seen threats, memory-based malware, side-channel attacks and encrypted threats. Ultimately, the security of your mobile network must match that of your wired network.

IT must also secure access from these mobile endpoints with limited budgets and skilled staff resources. This means streamlining deployment, availability and support to lower total cost of ownership.

Best Practices: Simple, safe and agile mobility

To be effective, cybersecurity must provide mobile employees with easy and secure 24/7 access to key business resources in an agile, easy-to-use, cost-effective and scalable way.

This requires a zero-trust posture regarding any mobile device attempting to connect with corporate resources, whether those resources be on-prem or in the cloud. Secure mobile access is a core component of a zero-trust approach to anywhere, anytime access.

IT must also secure access from these mobile endpoints with limited budgets and skilled staff resources. This means streamlining deployment, availability and support to lower total cost of ownership.

SonicWall Secure Mobile Access

The SonicWall Secure Mobile Access (SMA) solution enables anywhere, anytime access across hyper-distributed enterprises. This gives your business the agility to stay operational regardless of what tomorrow’s headlines may bring.

The SonicWall SMA 1000 Series provides distributed enterprises with comprehensive end-to-end secure remote access to corporate resources hosted across on-prem, cloud and hybrid datacenters. It applies identity based, policy enforced access controls, context-aware device authentication, and application level VPN to grant access to data, resources and applications after establishing user and device identity and trust. Flexibly deployed as a hardened Linux appliance or virtual appliance in private clouds on ESXi or Hyper-V, or in AWS or Microsoft Azure public cloud environments. It supports up to 20,000 concurrent connections with a single unit and scale upwards of hundreds of thousands of users through horizontal clustering.

SMA streamlines your company’s flex work initiatives with:

  • Always-On VPN
  • Single Sign On (SSO) using SAML Identity Provider
  • High Availability
  • Multi-Factor Authentication (MFA)
  • Capture Advanced Threat Protection (ATP) sandboxing
  • TLS 1.3 Support
  • Flexible and Scalable Deployment
  • Centralized management
  • Low TCO

Conclusion

Whether for ensuring business continuity or enhancing workforce retention and productivity, secure mobile access is a strategic business imperative. The SonicWall Secure Mobile Access (SMA) solution enables anywhere, anytime access across hyper-distributed enterprises. This gives your business the agility to stay operational regardless of what tomorrow’s headlines may bring.

Best practices for mobile security include zero-trust access control, seamless dependability and low total cost of ownership. Fortunately, there is a viable solution to help you implement all these best practices.

To learn how you can be more successful in maintaining a healthy access security environment while achieving zero downtime, write to [email protected]

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

San Francisco Airport Websites Hacked; Employee Login Credentials Compromised

93% of Global Airlines are Vulnerable to Email Fraud Risk: Report

Authorities at San Francisco International Airport revealed that unknown threat actors hacked two of its websites, in March 2020, to steal usernames and passwords of its employees and contractors.

In an official notice, the authorities confirmed that its websites SFOConnect.com, which provides updates about the airport to passengers, and SFOConstruction.com, which contains information about construction and building projects at the airport, were compromised in a cyberattack. It stated that hackers inserted malicious computer code on their websites to steal user login credentials. It’s believed that attackers could use these stolen credentials to gain authorized access to the airport’s network.

“Users possibly impacted by this attack include those accessing these websites from outside the airport network through Internet Explorer on a Windows-based personal device or a device not maintained by SFO,” according to the notice.

The compromised websites were taken down and the malicious code was removed. The officials also asked users to reset their email and network passwords. “If you visited either website outside of SFO’s managed networks and were using Internet Explorer on a Windows-based device, you should change the password you use to log in to that device. You should also consider changing any credentials that use the same username and password combination,” the notice added.

Cyberattacks on Airlines

Keeping the growing cyberattacks on the Aviation industry in mind, ResearchAndMarkets.com released a report titled Aviation Cybersecurity Market – Growth, Trends, and Forecast (2019 – 2024). According to the report, the aviation cybersecurity market is expected to register a CAGR of around 11% during the forecast period of 2019-2024.

The industry relies heavily on IT infrastructure for its ground and flight operations. The security of these airline systems directly impacts the operational safety and efficiency of the industry, and indirectly impacts the service, reputation, and financial health. The report discusses cybersecurity in the aviation sector by solution and application spanning from airline management, air cargo management, air traffic control management, and airport management.

Bisq Crypto Exchange Platform’s Security Flaw Leads to Cyber Heist

Sardonic, BitMart

Decentralized exchange (DEX) platform Bisq recently fell victim to a cyber heist in which the attacker exploited a security flaw to steal more than $250,000 in cryptocurrency, Coindesk reported.

Bisq allows users to exchange bitcoin cryptocurrencies anonymously. Initially, Bisq notified its users about a software vulnerability and halted operations temporarily. However, Bisqrealized it was under a cyberattack after users reported the theft of Bitcoins from their accounts. The DEX platform developers released a hotfix (software patch) within a few hours after the attack. Bisq stated that the attacker exploited the bug in its software and stole nearly $22,000 worth of bitcoin and $230,000 worth of monero directly from the user wallets.

According to Bisq, the attacker made changes to the default fallback address. A default fallback address is a user’s destination address or wallet to which cryptocurrency is sent to, if a transaction fails in their own wallet. The attacker pretends to be a seller and leads a trade with a buyer and waits for the time to run out. Since the destination wallet is changed, the funds are directly transferred to the hacker’s wallet with the buyer’s payment and security deposit, instead of being transferred to the legitimate owner.

Hacker Cannot be Identified

Since Bisq is a DEX platform, there is no requirement for identity verification or registration. There is nothing that can prevent hackers from attacking again as their identity remains unknown.

Cryptocurrencies have always been a primary target for cybercriminals, which have resulted in the increase of cyberattacks on cryptocurrency exchanges. In a similar cryptocurrency attack, crypto exchange Bithumb lost around three million EOS (worth $13.4 million) and 20 million Ripple coins (XRP) worth $6 million. Bithumb stated that it detected abnormal withdrawals of its cryptocurrencies from its hot wallets. Describing the incident as an “accident involving insiders,”  Bithumb stated that it secured all the cryptocurrency during the detection time and confirmed that the customer assets are safe under the protection of a cold wallet.

Danish Pump Manufacturer DESMI Reports Cyberattack on IT Systems and Operations

Denmark, Danish citizens, DESMI

DESMI, a known Danish manufacturer and supplier of domestic and industrial pumping solutions, reported a cyberattack on its IT systems on April 8, 2020. The type and the scale of damages caused by the cyberattack are yet unknown, but all its IT systems were immediately taken offline to avoid further damage.

DESMI is one of Denmark’s oldest running companies. It has a wide range of pumps and pumping solution products catering to various industries like environmental, marine, defense, and utility. It has a consumer base on six different continents and provides services to more than 100 countries. However, all its operations and services came to a grinding halt since the cyberattack on its IT systems.

DESMI was quick to report the incident to the respective authorities and the Danish Police. They have sought help from external cyber forensic and cybersecurity experts to analyze the extent of damages and to get its IT systems up and running at the earliest as it affects their entire business supply chain.

All systems have been shut down and are in process of being restored. First part of our systems will be up and running within a couple of days and the rest within a couple of weeks. Operational updates will be provided to all customers and business partners asap have been shut down and are in process of being restored. First part of our systems will be up and running within a couple of days and the rest within a couple of weeks. Operational updates will be provided to all customers and business partners asap.”

– Group CEO, Henrik Sørensen.

Earlier, ISS World, a Danish workplace experience and facility management company, was hit by a malware attack on February 17, 2020, which disrupted its global operations. As per the company’s standard operating procedure (SOP), the entire global computer network of ISS World, including its website, were pulled offline to isolate the attack. In a press release, ISS World explained that this malware attack had minimal impact on the company’s daily operations as the service provider mainly delivers services on-site (i.e. on client site).

NCSC and CISA Release Joint Advisory on COVID-19 Cyberthreats and Malicious Groups

Avaddon ransomware, Microsoft and Fortinet flaws, apt

Cybersecurity officials in the U.K. National Cyber Security Centre (NCSC), the U.S. Department of Homeland Security (DHS), and the Cybersecurity and Infrastructure Agency (CISA) stated that cybercriminals and advanced persistent threat (APT) groups are targeting individuals and organizations with a variety of ransomware and malware attacks, thereby exploiting the COVID-19 outbreak for their personal gain. The security agencies have released a joint advisory describing the growing number of attackers and other malicious groups in the U.K. and the U.S.

The advisory also included a non-exhaustive list of indicators of compromise (IOCs) for cyberattacks detection and mitigation advice. It offers practical advice that individuals and organizations need to follow to mitigate the risk of being affected by cyberattacks. The IOCs provided within the accompanying .csv and .stix files of the advisory are based on analysis from CISA, NCSC, and other industry experts.

The NCSC and CISA stated that they’re working with law enforcement and industry experts to prevent  COVID-19 related cyber activities. It’s said that the NCSC and the CISA have observed hackers scanning for vulnerabilities in remote working tools and exploited the increased use of video conferencing software.

Paul Chichester, Director of Operations at the NCSC, said, “Malicious cyber actors are adjusting their tactics to exploit the COVID-19 pandemic, and the NCSC is working round the clock with its partners to respond. Our advice to the public and organizations is to remain vigilant and follow our guidance, and to only use trusted sources of information on the virus such as the U.K. Government, Public Health England or NHS websites.”

Bryan Ware, CISA Assistant Director for Cybersecurity, said, “As the COVID-19 outbreak continues to evolve, bad actors are using these difficult times to exploit and take advantage of the public and business. We urge everyone to remain vigilant to these threats, be on the lookout for suspicious emails and look to trusted sources for information and updates regarding COVID-19. We are all in this together and collectively we can help defend against these threats.”

Hackers Sell Thousands of Zoom User Account Credentials on Dark Web

Zoom, video conferencing, webinar, zoom two-factor authentication, top data breaches of 2020

With millions of office workers now using Zoom from home, opportunistic hackers are stealing their Zoom credentials and selling them on the dark web. According to a recent investigation by IntSights’ researchers, hackers have shared a database containing more than 2,300 usernames and passwords to Zoom accounts on dark web forums.

The exposed database contains usernames and passwords of personal Zoom accounts, including corporate accounts belonging to banks, consultancy companies, educational facilities, software vendors, and healthcare providers.

In addition to the credentials, some of the accounts include meeting IDs, email and passwords, names, and host keys. Researchers also highlighted that they’ve found various posts and threads of dark web forum members discussing different approaches of targeting Zoom’s conferencing services.

This will be one more blow for Zoom, as the company is already suffering severe criticism and cyberthreats globally. Recently, a cybersecurity expert Mitch@_g0dmode discovered that Zoom’s video conferencing software for Windows is vulnerable to “UNC path injection” flaw that could let hackers steal Windows passwords and execute arbitrary commands on their devices. Soon after the vulnerability was identified, the company fixed the issue by releasing a patch.

The FBI has also slammed Zoom for not maintaining proper privacy and security measures for its users. The authorities also warned that the video meeting app is prone to hacking, as it contains certain unpatched bugs.

Taiwan Government Bans Zoom

The government of Taiwan announced a ban on the official use of Zoom. In an official statement, the Executive Yuan stated that all government agencies and certain non-government organizations are restricted to hold video conferencing calls using Zoom, citing security and privacy concerns. As an alternative, the government recommended agencies to use video conferencing software offered by other companies, like Google and Microsoft.

Taiwan is not the only one to bar Zoom services. Recently, New York City officials stated that schools in the City will no longer be allowed to use Zoom for online teaching. Australia’s Defense Force and its MPs are also barred from using Zoom services.