Home Blog Page 229

Wait! Don’t Plug in That “Best Buy” USB Pen Drive!

USB

A cybercriminal gang, named as “FIN7 APT” has been found launching a social engineering attack. According to the security firm Trustwave Spider Lab, unknown attackers posed as Best Buy officials mailed letters via postal service to the targeted victims, which contained a gift card and USB drive. The matter in the letter contained a socially engineered message intended to lure the recipients to place the USB drive on their computer. It says the gift card is a thank you gesture for being a great Best Buy customer and the USB drive contains a list of products that can be purchased using the gift card.

According to the FBI, the FIN7 group mailed these letters to several businesses, via the U.S. Postal Service, targeting employees in human resources, IT, or executive management departments. In addition to the gift cards and USB, the attackers also sent teddy bears for some employees. There is nothing on the gift cards, however the USB contains malware.

The researchers at Trustwave found the USB drive was programmed to emulate a USB keyboard, as most PCs and software by default allows a USB keyboard to connect.

The Attack Process

Once the drive is inserted, a payload is injected, and a malware payload is downloaded. After that, a fake message pops up on the screen that says, “the USB device is not recognized”, which is to confuse the victim. During this time, an additional JavaScript is downloaded to register the infected device with the command-and-control (C2) server, which later sends encoded data containing the info-stealing software.

Massive Data Theft

Once the malware is downloaded successfully, it collects a huge amount of information from the infected device, which includes:

  • Username
  • Hostname
  • User’s System Privilege
  • Uses WMI query to get the:
  • Process owner
  • Domain name
  • Computer model
  • Operating system information
  • Office and Adobe acrobat installation
  • List of running Processes (including PID)
  • Whether the infected host is running in a virtualized environment

The Bad USB Drive

Trustwave stated “One of our digital forensics and incident response retainer clients brought this device to our attention. One of their business associates received this suspicious letter. Fortunately, our client and their associate did not plug the drive into any computer.”

The researchers found some inscriptions on the head of the drive on the printed circuit which says, “HW-374”, and quick search of this serial number led to a product described as “BadUSB Leonardo USB ATMEGA32U4” for sale on shopee.tw.

If the users are not vigilant, attackers use these kinds of USB controller chips, programmed for malicious use, to launch an attack and infect users’ computers without knowing them.

Mukashi Malware Exploits Zyxel NAS Device Vulnerabilities

Armor Piercer

Mirai malware that turns networked devices into remotely controlled bots has relaunched itself as Mukashi malware and has been actively exploiting Zyxel network-attached storage (NAS) devices’ vulnerability reported under CVE-2020-9054. This remote code execution vulnerability, with a CVE rating of 9.8, was marked “Critical” and made public last month. As per the findings, Zyxel NAS devices with firmware versions 5.21 or less are vulnerable to Mukashi Malware.

How Mukashi Malware Works

This vulnerability was discovered as a zero-day exploit and was soon put up for sale by its handlers. Zyxel NAS devices authenticate username parameter using the weblogin.cgi CGI executable. However, if this parameter contains specific characters, then it may allow command injection due to the privileges Zyxel device web servers possess. A setuid utility that exists in Zyxel devices can be leveraged to compromise by sending a specially crafted HTTP POST or GET request. This vulnerability exploit can eventually lead to remote code execution with root privileges of the Zyxel NAS device.

Mukashi first monitors the TCP port 23 of random hosts and attempts brute force device login using default credentials. On successful login, the Mukashi malware displays a message, “Protecting your device from further infections” and attaches itself to the TCP port 23448 so that only a single instance of the intended program is running on the compromised system.

Researchers at Palo Alto networks found that Mukashi malware is also capable of launching DDoS attacks on the compromised system when it receives the respective command from its C2 server. They said, “Mirai’s and its variants’ DDoS attack mechanics (e.g UDP, TCP, UDP bypass, and TCP bypass) have already been analyzed in-depth, and Mukashi’s DDoS capabilities are no different from these variants. The presence of DDoS defense bypass confirms our speculation from earlier that Mukashi includes certain capabilities from the dvrhelper variant — Mukashi also possesses the anti-DDoS-defense capabilities.”

 

Threat Summary
Name Mukashi
Threat type Malware, botnet, further capable of launching DDoS attacks
Default Passwords used for credential brute-force attack t0talc0ntr0l4! and taZz@23495859
C2 server 45[.]84[.]196[.]75:4864
C2 commands supported by Mukashi PING, scanner, .udpplain, .tcp, .killallbots, killer, .udp, .udpbypass, .tcpbypass, .udprand, .udphex, .http
Affected Products NAS326 before firmware V5.21(AAZF.7)C0 NAS520 before firmware V5.21(AASZ.3)C0 NAS540 before firmware V5.21(AATB.4)C0 NAS542 before firmware V5.21(ABAG.4)C0
Firmware updates available for NAS326, NAS520, NAS540, and NAS542
Affected models with end-of-support NSA210, NSA220, NSA220+, NSA221, NSA310, NSA310S, NSA320, NSA320S, NSA325 and NSA325v2
Recommended measures
  • Update the firmware immediately as per above information.
  • The latest version of the firmware is available for download.
  • Change default login credentials and use complex or difficult login passwords for any device to avoid brute-force attacks.

Indicators of Compromise (IOCs)

File (Sha256)

8c0c4d8d727bff5e03f6b2aae125d3e3607948d9dff578b18be0add2fff3411c (arm.bot)

5f918c2b5316c52cbb564269b116ce63935691ee6debe06ce1693ad29dbb5740 (arm5.bot)

8fa54788885679e4677296fca4fe4e949ca85783a057750c658543645fb8682f (arm6.bot)

90392af3fdc7af968cc6d054fc1a99c5156de5b1834d6432076c40d548283c22 (arm7.bot)

675f4af00520905e31ff96ecef2d4dc77166481f584da89a39a798ea18ae2144 (mips.bot)

46228151b547c905de9772211ce559592498e0c8894379f14adb1ef6c44f8933 (mpsl.bot)

753914aa3549e52af2627992731ca18e702f652391c161483f532173daeb0bbd (sh4.bot)

ce793ddec5410c5104d0ea23809a40dd222473e3d984a1e531e735aebf46c9dc (x86.bot)

a059e47b4c76b6bbd70ca4db6b454fd9aa19e5a0487c8032fe54fa707b0f926d (zi)

Deception Tactics in Cybersecurity: Human Lab Rat

Cyber Deception

Deception has been a defense strategy in military and intelligence programs for hundreds of years. As cybersecurity techniques mature, we continue to borrow proven methods from more traditional security industries.

By Dick Wilkinson, IT Security Officer, New Mexico Judicial Information Division

Deception in the military setting is often as simple as setting out decoy items that create a false image of strength or create a feint to distract the enemy from the real intentions of your campaign. In the cybersecurity setting, we look to honeypots as the clear example of a deception tactic. Most people in the cyber field would say we are not using deception in a thoughtful or mature way. Honeypots are simple and usually easy to spot once you find your way into one. Creating decoys on the network seems like a waste of time and precious computing resources, so what would the benefit be to deception techniques in network defense?

Deception Experiment Through Penetration Tests

An American Federally Funded Research Lab ran an experimental series of penetration tests to study how deception or even the illusion of deception might impact a malicious actor’s methods or chance at success. I had the unlikely chance to participate in this event as a human test subject. I happened to be looking for some short-term contract work and a two-day pen test event came up in my search. The pay seemed very generous and the details very light. I had to follow through and see where this event might lead. Only upon the final contract signature did I find out the event was a human test subject experiment.

The experiment was designed to measure stress and cognitive response to a complex network environment. The room was built with private stalls with no interaction between participants. Each test subject was issued a biometric measurement watch that measured heart rate and other stress markers. Each stall had two computers, one to launch attacks against the test environment and the other for research on the external internet. All activity on both machines was recorded via screen capture. Over the course of two 8-hours sessions on consecutive days. Each person was given a vague set of instructions to penetrate the network and collect all data that could be interesting in a pen test report; demonstrate vulnerabilities, exploits and access, and then report your findings. The test hinged on one sentence in the instructions of some users but not in the instructions for others. The instruction: Look for signs of deception on the network, and if found include in your report.

Reality or Deception?

The idea of deception on the network was meant to lead you into a false sense of self-doubt. Do I slow down? Do I second guess every step to look for reality or deception, or do I just get on task and start collecting data? The real world does not have very many networks with deception present. Almost no pen test methodology is taught with deception in mind, we believe what we see is real and we execute accordingly. Even the idea that deception might be present is a very unusual prompt for a pen tester or hacker. I was one person with the deception present in my instructions. I sat for eight hours running down rabbit holes only to find one completely void virtual machine after another. I then sat for an hour of psychological tests asking if I felt frustrated or misled or if my confidence was in question. The next day was more of exactly the same. In this case, while I can’t truly establish my own personal baseline, I feel certain deception ruined any chance of success for me. The myriad of easy to see and useless to penetrate machines left me scratching my head.

Mixed Results

The results of this project were published with very little conclusive evidence other than that the testing method was valid and deception may impact behavior. The final note of the report was to encourage further research into enhanced deception techniques. The lesson learned for network operators and network defenders from these experiments is that deception will have mixed results and only a thoughtful plan could lead to enhanced protection. The balance of resources invested vs. results gained would be hard to prove. Creating deception for a specific type of attack method may yield some results but again, proving a negative would be a challenge.  Only the most mature security program should even consider deception techniques and it should not be at the cost of other resources.

About the Author

Dick WilkinsonDick Wilkinson is the Chief Information Security Officer on staff with the Supreme Court of New Mexico. He is a recently retired Army Warrant Officer with 20 years of experience in the intelligence and cyber security field. He has led diverse technical missions ranging from satellite operations, combat field digital forensics, enterprise cybersecurity as well as cyber research for the Secretary of Defense.

Disclaimer: CISO MAG does not endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. Views expressed in this article are personal.

 

Indian Cybercrime Officials Release a List of Potentially Dangerous Coronavirus-related Domains

99% of Websites Are Prone to Cyberattacks Via JavaScript Plug-Ins: Report

COVID-19 has affected several lives and businesses globally and is steadily increasing its spread. According to the government of India, the total number of active cases of Coronavirus in the country, as of March 30, 2020, is standing at,942and the death toll stands at  29. The government of India has been taking all the necessary precautions to contain the spread of the virus.

While the government and public are taking stringent actions against the transmission of COVID-19, opportunistic cybercriminals are taking advantage of the situation to exploit internet users. Multiple  Coronavirus-related scams, phishing websites, malicious maps, and spam messages were reported often in recent times.

Recently, the cybercrime division of New Delhi, India, warned the public to be vigilant about malicious Coronavirus-related websites. The officials also tweeted a list of fake or potentially dangerous websites, urging people not to click on them.

Following domains are listed as potentially dangerous:

  • coronavirusstatus[.]space
  • coronavirus-map[.]com
  • canalcero[.]digital
  • coronavirus[.]zone
  • coronavirus-realtime[.]com
  • coronavirus[.]app
  • coronavirusaware[.]xyz
  • coronavirusaware[.]xyz
  • corona-virus[.]healthcare
  • survivecoronavirus[.]org
  • vaccine-coronavirus[.]com
  • coronavirus[.]cc
  • bestcoronavirusprotect[.]tk
  • coronavirusupdate[.]tk

The cybercrime officials also released a report, “Cybercrime Threat in Wake of Rampant Corona Virus,” in order to educate online users on how cybercriminals are capitalizing the Coronavirus outbreak. “Fake links related to the pandemic are sent by criminals claiming to be health authorities, with the aim of tricking victims into connecting to a specific webpage and to login their real email address and password. Scammers then use their credentials to access sensitive information and potentially to steal their money,” the report stated.

Cyberattacks via Malicious Coronavirus Map

Recently, a security researcher named Shai Alfasi discovered that threat actors are spreading malware disguised as “Coronavirus Map” to steal personal information like usernames, passwords, credit card numbers, and other sensitive information that is stored on the user’s browser. Attackers designed multiple websites related to Coronavirus information to prompt users to click/download an application to keep them updated about the situation. The website displays a map representing COVID-19 spread, which then generates a malicious binary file and installs it on the victim’s devices.

DDoS Attacks Rose 180% in 2019 Compared to 2018

DDoS Attacks

Neustar, a global information and technology provider company, revealed that it found 168% increase in distributed denial-of-service (DDoS) attacks in Q4 2019, compared with Q4 2018, and a 180% increase overall in 2019 compared to 2018. In its “Cyberthreats and Trends Report”, Neustar revealed that it discovered DDoS attacks across all size categories increase in 2019, with attacks sized 5 Gbps and below seeing the largest growth.

According to the report, the maximum DDoS attack intensity observed in 2019 is at 587 GB per second which was 31% larger than the largest attack of 2018, which is 343 million packets per second. The longest single, uninterrupted attack experienced in 2019 lasted three days, 13 hours and eight minutes, the report revealed.

Earlier, a similar research from Kaspersky Lab revealed that the number of DDoS attacks increased by 84% in the first quarter of 2019 compared to Q4 of 2018. In its research report dubbed “DDoS Attacks in Q1 2019”, Kaspersky stated that it discovered a considerable growth in the number of attacks that lasted more than an hour. According to the research findings, China reported the highest number of DDoS attacks (67%) while the U.S. reported the second largest attacks (17.17%) and Hong Kong stood third (4.81%).

Weaponizing Documents for DDoS Attacks

Many industry experts stressed that DDoS attacks have evolved into weaponized instruments used to disseminate ransomware, as well as launch disruptive attacks against their targets. Attack vectors targeted for weaponization include mobile devices, documents, browsers, with the current favorite being IoT devices.

Researchers from Sophos discovered a weaponized document serving the dual purpose of delivering ransomware to the system, as well as exploiting it for potential DDoS attacks. The weaponized document was sent as a spear fishing email which upon opening launched Microsoft Word and initiated embedded macros, which enabled elevated privileges for the malicious document to execute an encoded VBscript. The binary made changes to the screensaver via registry and also appeared to be carrying out a DDoS attack by flooding the subnet with network traffic using UDP packets on port 6892. The spoofed source address could direct response traffic from the subnet to interrupt host operations.

Deepwatch Partners with Tevora for Advanced Cybersecurity Services

96% of Cybersecurity Professionals are Happy With Their Roles

Security services provider Deepwatch announced a partnership with cybersecurity management consultancy firm Tevora to extend its ability to offer advanced managed security services to customers. With the new partnership, the customers of both companies will benefit from the addition of advanced security solutions and enhanced consultative services portfolio. The companies stated that they’ll collaborate with their customers regularly to ensure transparency, deep customer business process understanding, and tailored service delivery.

Deepwatch offers intelligence-driven managed security services to enterprises with advanced cybersecurity team and SecOps platform. The company delivers the differentiated security services to cybersecurity leaders, including exclusive maturity models, cloud SecOps platform, data-centric deployment models, named delivery squads, real-time collaboration, and portability and access. Tevora is specialized in providing management consulting services focused on cybersecurity, risk, and compliance.

Commenting on the partnership, Steve Stumpfl, Tevora’s Executive Vice President, said, “We believe that our partnership with Deepwatch will enable us to offer end-to-end security services to our customers. We deploy security technologies, ensure compliance, and test and manage our customers’ security posture. Deepwatch is the ideal partner to provide ongoing Managed Detection & Response, Endpoint Protection & Response, and Vulnerability Management services to our customers. If there ever is a security event or incident that needs to be managed, we are very confident that the combination of Tevora’s incident response services and Deepwatch will enable us to reduce risk and harm to our customers’ businesses and reputation.”

Earlier, Deepwatch raised US$23 million in a Series A funding round led by ABS Capital Partners.  The startup utilized the new proceeds to accelerate research and development for its machine learning security analytics platform and market expansion. As per the investment deal, Michael Avon, a venture partner with ABS Capital, joined the Deepwatch board of directors.

Hackers Attack Database of India’s COVID-19 Patients and Potential Suspects

Acronis Cyber Readiness Report, cyberattacks in India, cybercrime in India, India’s Private Sector

Kerala, one of the worst-hit states in India’s COVID-19 crisis, reported five positive cases from Aythala in Ranni-Pazhavangady panchayat. The database of all the active patients, and those who came in direct contact with them, was maintained on the district administrator’s office computers. The data included information on other people coming into the district from abroad and those kept in self-quarantine, their recent travel history, residential addresses and contact details, etc. District Collector P. B. Nooh admitted that this COVID-19 database has been hacked and has since sought an investigation into the incident.

The list of confirmed and quarantined patients in the district was handed over to the police and the district health administration to help them in continuous monitoring of respective individuals. However, the same list started appearing locally on various social media groups and forums. This is a severe breach of personal data as proposed in India’s Personal Data Protection Bill 2019.

Nooh said, “We have found that data about people in isolation at home has been leaked or hacked. The police are already investigating the matter. Since it is confidential information, anyone who shares it will also be treated with strict actions. So please don’t share it anymore and those of you who already have the list, please kindly delete it.”

According to District Police Chief K. G. Simon, who is leading the investigation, the cause of hacking or data leak is uncertain; however the list doesn’t seem to be widely circulated. A cyber cell team  is investigating the data breach to track down the hackers and all the people who have shared this database.

Cyberattack on Kerala State Health Department’s eHealth Portal

Earlier, in a separate incident on March 8, 2020, the State Health Department’s eHealth portal was attacked by a hacker group known as ‘GhostSquadHackers’. The hacking attempt was recorded and observed by the Health Department’s IT team, which almost immediately summoned cybersecurity experts to further investigate the incidence. They blocked the portal and took adequate remedial measures. Health Minister K. K. Shailaja later confirmed that no data had been breached or exfiltrated from the eHealth web portal by the hackers.

Businesses in U.K. Become More Resilient to Cyberattacks: Report

Businesses in U.K. Become More Resilient to Cyberattacks: Report

With an increase in the number of cyberattacks, cybersecurity has emerged as a primary investment priority for organizations in the U.K. Businesses there have increased their budget allocation to enhance their cybersecurity capabilities. This resulted in U.K. firms becoming more resilient to data breaches and cyberattacks, according to a survey by the U.K. government.

The survey, “Cybersecurity Breaches Survey 2020,” reported a continuous rise in the overall volume of cyberattacks. Nearly 46% of businesses and 26% of charities suffered security breaches in the last 12 months. Among 46% of businesses that identified attacks, one in five (19%) have experienced losing money or data and two in five (39%) were negatively impacted. And, among 26% of charities that reported attacks, a quarter (25%) had material outcomes and over half (56%) were negatively impacted. However, the security incidents on charities increased from 19% in 2018 and 22% in 2019 and then to 26% by 2020. The report stated that 46% of businesses are experiencing security issues at least once a week in 2020.

It’s said that, since 2017, the proportion of organizations reporting any negative outcome has fallen by 19% and the proportion being negatively impacted has fallen by 18%.

The report also highlighted that the nature of attacks has changed since 2017. Over this period, there has been a rise in businesses suffering from phishing attacks (from 72% to 86%), and a fall in viruses or other malware attacks (from 33% to 16%).

Organizations Become Resilient

Though the attacks increased, organizations have become more resilient towards cyberattacks. This may mean that businesses are becoming better at identifying breaches than before. The companies are less likely to report negative outcomes or impacts from attacks.

“Over the last five years, there has been greater board engagement in cybersecurity and increased action to identify and manage cyber risks. These improvements may underpin the fact that organizations have become more resilient,” the report stated.

U.K. Cybersecurity Industry Worth £8.3 Billion

In a similar report by the U.K.’s Department for Digital, Culture, Media, and Sport (DCMS), the number of active cybersecurity firms in the country increased by 44%, up from 846 firms in 2017 to over 1,200 in 2019, indicating a growth in the cybersecurity industry.

In its report, “The U.K. Cybersecurity Sectoral Analysis 2020”, DCMS stated the security industry in the U.K. has seen a significant surge in security investments, annual revenue, and employment. It also highlighted that around 43,000 full-time employees are currently working in the industry. The annual revenue in the cybersecurity sector rose by 46% to an estimated worth of £8.3 billion (approximately US$10.8 billion). The sector received more than £348 million (approximately US$452.4 million) of investment last year.

Canada’s Cyber Defense and World CTI League Fight Against COVID-19 Cyberattacks

coronavirus, covid-19

Amidst the rising concerns over COVID-19 spread and the amount of distress it is causing to the Healthcare industry, certain hacking groups have had a heart and decided against launching cyberattacks targeted at critical healthcare infrastructures. However, there are a few others who think otherwise, as was the case when a certain cyberattack prior to March 16, 2020, disrupted operations of the U.S. Health and Human Services Department (HHS). Cybersecurity professionals around the globe are now joining hands to tackle the COVID-19 themed cyberattacks..

No Social Distancing to Fight COVID-19-related Cyberattacks

The attack on U.S. HHS was not a one-off incident. Cybersecurity researchers and computer and network security vendors worldwide have observed a sharp spike in phishing and other forms of hacking techniques disguised as COVID-19 themed help and guidelines. Although the COVID-19’s basic mitigation step suggests social distancing, the world cybersecurity fraternity joined hands to fight and defend critical infrastructure from cyberattacks launched amid the pandemic crisis.

Canada’s COVID-19 Cyber Defence Force

SecDev Group in Canada has initiated a volunteer-based program wherein it has called upon Canada’s top cybersecurity and IT professionals to join the COVID-19 Cyber Defence Force in order to protect their country’s key services and critical infrastructure from cyberattacks. The group’s vision and mission are crystal clear:

  • No ransomware attack should close hospital operations.
  • No cyberattacks should affect any patients’ treatment; and
  • No form of essential services should be affected by any cyberattack.

SecDev group has also collaborated with Zeropoint to provide VPN strategies and access control to governments and companies and help them adapt to cybersecurity monitoring to accommodate a workforce that is majorly working on distributed remote desktops from home.

The COVID-19 CTI League

Justice League, a Hollywood movie from 2017 had a tagline, “You Can’t Save the World Alone.” That’s exactly what cybersecurity professionals from 40 countries thought and came together on March 25, 2020, to form a COVID-19 CTI (Cyber Threat Intelligence) League. The CTI League is an international group of cybersecurity individuals numbering close to 400 that includes senior-level professionals from known companies like Microsoft and Amazon.

Marc Rogers, Head of Security at Def Con and Vice President of Okta., said that creating a blanket against cyberattacks aimed at healthcare facilities and frontline responders including doctors, nurses, laboratories, etc. is going to be the highest priority of the CTI league. Rogers stresses that he has never seen so high volumes of phishing earlier and has literally documented phishing messages in every known language to man.

Insider Breaches on the Rise in Legal Sector: Report

Insider attacker leak data

A research report from Egress, a provider of human layer security solutions, revealed that 96% of security leaders opined insider data breaches as a major concern. The report named as “Insider Data Breach Survey” uncovered that 77% of employees put personal data at risk accidentally in the past 12 months and 78% think employees have put data at risk intentionally.

The survey findings are based on the responses from more than 500 security decision makers and 5,000 IT professionals surveyed across the U.K., the U.S., and Benelux regions. Respondents from legal sector admitted that their employees intentionally and accidentally broke company’s policy while sharing data. Around 57% of them said they had intentionally broken company policy while 56% said they had done it accidentally. 44% of security leaders from the legal sector say it is likely employees will put data at risk in the future.

Egress CEO Tony Pepper said, “Given the sensitivity of the information they handle, the legal industry is one of the most at-risk sectors from both accidental and intentional insider data breaches. While they acknowledge the sustained risk, bizarrely IT leaders have not adopted new strategies or technologies to mitigate the threat. They are also relying far too heavily on their staff to self-report incidents, something our analysis suggests is totally ineffective. In essence, they are adopting a risk posture in which at least 44% of employees putting data at risk is deemed acceptable.”

Misused and Phishing emails are Major Concern of Insider Breaches

Nearly 55% of legal sector employees who had accidentally leaked data stated that the incidents occurred due to phishing emails. And 31% of them said they sent information to a wrong person.  “Incidents of people accidentally sending data to incorrect recipients have existed for as long as they’ve had access to email. As a fundamental communication tool, organizations have weighed the advantages of efficiency against data security considerations, and frequently compromise on the latter,” Pepper added.