Home Blog Page 231

Finastra Hit by Ransomware Attack, Shuts Down Servers

ransomware, fonix, fonix ransomware, Cybereason Partners with Intel for Hardware-Enabled Ransomware Prevention, Kronos

Finastra, a fintech firm that provides technology solutions to banks globally, announced that it shut down its key systems due to a security breach discovered on March 20, 2020. In an official notice to its customers, the London-based company stated that it detected an unknown hacker group attempting to induce malware into its network through a ransomware attack. Finastra provides financial technology services to 90 top-rated banks across 130 countries globally.

The incident came to light when Finastra’s threat intelligence team discovered an unusual activity on their network systems. The team immediately took down the servers offline and reported the issue to the data privacy authorities for further investigation. The company also notified its customers who may have been affected in the incident.

According to Finastra’s Chief Operating Officer Tom Kilroy, there is no sign of customer or employee data misuse, nor were the clients’ networks impacted. “The Finastra risk and security services team has detected anomalous activity on our systems. In order to safeguard our customers and employees, we have made the decision to take a number of our servers offline while we investigate. This, of course, has an impact on some of our customers and we are in touch directly with those who may be affected,” said Kilroy.

Commenting on how the situation was taken care of, Kilroy stressed, “Our approach has been to temporarily disconnect from the internet the affected servers, both in the USA and elsewhere, while we work closely with our cybersecurity experts to inspect and ensure the integrity of each server in turn. Using this ‘isolation, investigation and containment’ approach will allow us to bring the servers back online as quickly as possible, with minimum disruption to service, however we are anticipating some disruption to certain services, particularly in North America, whilst we undertake this task. Our priority is ensuring the integrity of the servers before we bring them back online and protecting our customers and their data at this time.”

Fintech Firms Vulnerable to Security Incidents

A survey revealed that around 70% of financial firms in the U.K. reported security incidents last year, in which half of the incidents occurred due to internal errors. The research, which surveyed 100 senior business decision-makers from financial organizations in the U.K., highlighted that most of the attacks have originated due to employees who failed to follow proper data protection policies. Apart from employees’ errors, the survey also revealed other reasons, that led to attacks, including downloads of malware or viruses from third-party devices like USBs, and file transfers to unsecured sources. 

IoT Devices Market is Estimated to Increase between 2020 to 2025

IoT attacks

The number and purpose of connected devices is rapidly increasing as IoT evolves beyond the state of limited applications, a latest research revealed. According to the research report named, “The Connected Device Market for Consumer, Enterprise, and Industrial IoT Devices by Use Case, Device Type, Application, Region, and Country 2020 – 2025″, IoT applications will become increasingly interconnected in the next five years (from 2020 to 2025).

This report assesses the connected device market segment–including consumer, enterprise, and industrial devices–with associated connected device market sizing from 2020 to 2025. It also assessed applications and solutions in each market segment including agriculture, advertising and media, automobiles, security management, energy management, healthcare, manufacturing, oil & gas, public safety, and telecommunications.

According to the research findings, the global market for IoT devices in the energy sector (temperature controllers, smart lighting, smart windows, smart home, etc.) will reach to around US$6 billion by 2024. The global market size of government security and monitoring equipment (CCTV, Cameras, etc.) and connected health monitoring devices will reach US$5.1 billion by 2025.The smart hospital equipment (monitoring and diagnostic equipment, surgical tools, pathology and laboratory equipment, etc.) will reach US$1.4 billion by 2024, while consumer appliances (TV, refrigerators, washing machines, dish washers, microwaves, cooking appliances, coffee machine, etc.) will reach $1.7B by 2025.

As enterprises embraced mobility and always-on connectivity for employees, the lines have blurred between company-owned and privately-owned devices, and between the workplace and the home. Security experts opined that the sudden increase in connected devices emerged as a security threat to enterprises’ security posture.

A similar survey from security firm, Extreme Networks, revealed that organizations remain highly vulnerable to IoT-based attacks. The research, which surveyed 540 security professionals across organizations in North America, Europe, and the Asia Pacific, found that 84% of organizations have IoT devices on their corporate networks. It also stated that more than 50% of the organizations don’t maintain necessary security measures beyond default passwords.

Cybercrime Will Cost the World US$6 Trillion by the End of the Year: Study

covid-19 vaccine, vaccine

The global pandemic of COVID-19 will continue to have a massive impact on cyberspace. In fact, the damages caused by cybercrime is poised to double amid the Coronavirus outbreak. According to the Official Cybercrime Report published by Cybersecurity Ventures, cybercrime will cost the world US$6 trillion annually by 2021, up from US$3 trillion in 2015. The trend also represents one of the biggest transfers of economic wealth in history.

It is estimated that cybercrime will be more profitable than the global trade of all major illegal drugs combined. The report also estimates that cybercrime damage costs could potentially double during the outbreak period not only due to phishing scams but an uptick in ransomware attacks, insecure remote access to corporate networks and employees exposing login credentials and confidential data to members at home.

“Cybercrime costs include damage and destruction of data, stolen money, lost productivity, theft of intellectual property, theft of personal and financial data, embezzlement, fraud, post-attack disruption to the normal course of business, forensic investigation, restoration and deletion of hacked data and systems, and reputational harm,” said Steve Morgan, Founder and of Cybersecurity Ventures and Editor-in-Chief at Cybercrime Magazine, in a release.

With employees being asked to work remotely to contain the global pandemic, experts are also urging organizations to beef up its security stance and spread enough cybersecurity awareness among its employees, especially around phishing scams.

“Employees from organizations of all sizes and types now have minimal cybersecurity resources, if any, compared to what is normally available to them,” added Morgan. “If remote workers don’t immediately self-educate, and if businesses don’t immediately provide their employees with security awareness training centered on the home office threat, then we could see global cybercrime damage costs as much as double by the end of this year.”

“Cybercriminals thrive on chaos, whether it’s real or perceived,” said Robert Herjavec, Founder and CEO at Herjavec Group, and a Shark on ABC’s Shark Tank. “Your team will experience an uptick in phishing attacks as a result of the global Coronavirus pandemic.”

Exploiting Coronavirus

Hackers have constantly been exploiting virus outbreak and have been launching several attacks. A research from CYFIRMA found that Korean-speaking hackers were planning to make financial gains using sophisticated phishing campaigns, loaded with sensitive data exfiltration malware and creating a new variant of EMOTET virus (EMOTET is a malware strain that was first detected in 2014 and is one of the most prevalent threats in 2019).

Attackers Launch DDoS Attack on Food Delivery Startup Liefrando

Multiple Banks and Telecoms in Hungary Affected in a DDoS Attack

Precautionary measures to mitigate the ongoing COVID-19 outbreak led to swift change in the work life of the businesses and people globally. Social distancing resulted in an increase in remote working across all business units. Amidst this pandemic phase, cybercriminals are taking advantage of the situation and targeting businesses and users online.

Hackers have launched a distributed denial-of-service (DDoS) attack on Germany-based food delivery service Takeaway.com (Liefrando.de). Attackers demanded two bitcoins (around US$11,000) in ransom to stop the attack. In DDoS attacks, hackers flood the target with useless traffic to inhibit the availability of services provided by the target.

Liefrando offers delivery services from more than 15,000 restaurants in Germany, where people under COVID-19 and other health emergency regulations hugely depend on the service. Some customers claim that the service provider accepted new orders, despite its systems being stopped and they were not being processed. However, the company informed that it’ll refund orders that had been paid online and were not delivered.

“Our systems have been attacked and are currently under maintenance to ensure the security of all data. This can lead to a delay in order processing. We apologize for the inconvenience and hope to return to normal soon,” Jitse Groen, Founder and CEO of Liefrando, shared on Twitter.

Groen also shared a note from the attackers which said, “Hi Jitse! Pizza.de is under attack. We want 2 BTC, tell me when you’re ready to pay. After payment we stop attack and help you to protect your company. We can attack another sites takeaway company. We are waiting for your answer.”

Cybercriminals Vow Not to Attack

Amid the slew of Coronavirus pandemic, cyberattacks on the business sector became an additional threat level and hurdle to organizations, especially for healthcare providers. However, on the flipside, several ransomware groups recently came forward to assure that they would hold back from attacking health organizations during the Coronavirus crisis. Lawrence Abrams from Bleeping Computers reached out to the operators of the Maze, DoppelPaymer, Ryuk, Sodinokibi/REvil, PwndLocker, and Ako Ransomware infections to find out if they would cease to target Healthcare organizations during this time of dire crises. They also stated that if any health care organization is hit by mistake; they would decrypt it for free.

83% of Healthcare Devices at Security Risk Due to COVID-19 Outbreak

Healthcare Data Breaches, Premier Diagnostics data exposed

Most healthcare organizations in the U.S. are running their medical devices on outdated software and operating systems, leaving them vulnerable to cyberattacks. According to a research from Atlas VPN, 83% of healthcare providers in the U.S. are running on outdated software. Based on cybersecurity firm Palo Alto Networks’ survey of 1.2 million IoT devices used in thousands of healthcare organizations across the U.S., 56% of devices were still running on the Windows 7 operating system, for which Microsoft discontinued support in January 2020.

More than 40% of healthcare providers stated that they were planning to enhance their cybersecurity measures this year. The research also revealed that 27% of medical devices are still running Windows XP or old versions of Linux OS. Nearly 16% of imaging systems are at 51% risk of getting hacked, according to the research.  Due to the severity of the Coronavirus threat, the healthcare sector leaves many connected medical devices vulnerable to potential cyberthreats.

“Due to the COVID-19 outbreak, hospitals are using patient monitoring devices more than ever. Research shows that 1 in 4 such devices have security issues. Based on these numbers, Atlas VPN estimates that cybercriminals will be focusing on the healthcare sector in 2020,” Atlas VPN said in a statement.

Abuse of Coronavirus in Cyberspace

Cybercriminals never leave an opportunity to exploit any vulnerability or situation to prey on users online. For instance, attackers created fake Coronavirus Maps to trick people into downloading malware onto their devices.  CYFIRMA Research also found that Korean-speaking hackers were planning to make financial gains using sophisticated phishing campaigns, loaded with sensitive data exfiltration malware and creating a new variant of EMOTET virus (EMOTET is a malware strain that was first detected in 2014 and is one of the most prevalent threats in 2019). The phishing email had the Korean language title “Coronavirus Correspondence”, tricking recipients into opening them and launching malware into machines and networks.

65% of Security Professionals Access Documents Unrelated to Their Jobs: Research

Security

A survey on insider threats conducted by unified security and risk analytics firm Gurucul, revealed that nearly 65% of cybersecurity professionals have accessed documents that are not related to their job profiles. It also found that 40% of respondents who had negative performance reviews, also admitted to abusing their privileged access.

According to the survey responses, about 58% of security professionals in the finance sector admitted that they have emailed company documents to their personal accounts. While 78% of them in the manufacturing sector accessed documents unrelated to their job profiles. In retail, 86% of security professionals said they’ve clicked on links from unknown sources. The survey findings are based on the responses from 300 cybersecurity professionals across the world from the small, medium, and large organizations of various sectors.

Commenting on the survey findings, Saryu Nayyar, CEO of Gurucul, said, “We knew insider privilege abuse was rampant in most enterprises, but these survey results demonstrate that the info security department is not immune to this practice. Detecting impermissible access to resources by authorized users, whether it is malicious or not, is virtually impossible with traditional monitoring tools. That’s why many organizations are turning to security and risk analytics that look at both employee and entity behaviors to identify anomalies indicative of insider threats.”

Several industry experts stressed that insider threats are the primary concern for every security leader, as many organizations fail to address the insiders within their own company. As a result, several data breaches happen due to employee negligence or unintentional actions like responding to a phishing email with sensitive information or downloading malicious content.

Human Element in Security Breaches

According to Ponemon Institute’s Cost of Data Breach study, 47% of the organizations stated that the root cause of the security breaches they suffered was malware or cyberattack. It’s also revealed that there is a human element in every single security breach. Sometimes, it’s a malicious actor with an intent to harm the company and ensure that they benefit; other times, it’s an employee who accidentally clicks on a phishing email, for example, and unexpectedly exposes the organization to malware.

Nefilim Ransomware: The GenNext of Nemty Ransomware

Ransomware Attacks, Graff ransomware attack

A new ransomware named as Nefilim, surfaced and began spreading at the end of February 2020. As per Bleeping Computer, its code has signatures that suggest Nefilim ransomware is an upgraded version of Nemty 2.5 ransomware. Although the two have similarities in the code used for its development, a very important component from Nemty, that is, Ransomware-as-a-Service has been removed in Nefilim ransomware. It now completely relies on email communications with its victims for ransom payments rather than using Tor payment sites.

Nefilim Ransomware’s Modus Operandi

  • Researchers are unsure how the ransomware is being distributed but deem an exposed Remote Desktop Service as a probable cause.
  • Once the operators launch the attack, Nefilim ransomware uses a combination of AES-128 and RSA-2048 algorithms to encrypt the victims’ files. First the files are encrypted using AES-128 encryption and AES encryption key is further encrypted using the RSA-2048 public key. This key is then embedded in the executable file of the ransomware.
  • The file extension name .NEFILIM is appended at the end of each encrypted file name along with a NEFILIM file marker for all encrypted files. This is how the ransomware gets its name.
  • On successfully encrypting all files, the ransomware plants a ransom note ‘NEFILIM-DECRYPT.txt’ that instructs the victim on how to recover their files.
  • The ransom note contains different contact emails for contacting its operators. It also includes a line that warns victims of leaking their data if the ransom is not paid within seven days.

Nefilim Ransomware Note says…

All of your files have been encrypted with military grade algorithms. We ensure that the only way to retrieve your data is with our software. We will make sure that you receive your data swiftly and securely when our demands are met. Restoration of your data requires a private key which only we possess. A large amount of your private files have been extracted and is kept in a secure location. If you do not contact us in seven working days of the breach we will start leaking the data. After you contact us we will provide you proof that your files has been extracted. To confirm that our decryption software works email to us two files from random computers. You will receive further instructions after you send us the test files.

Threat Summary
Name NEFILIM
Threat type Ransomware, Files locker
Encrypted files extension .NEFILIM
File name of ransom note NEFILIM-DECRYPT.txt
Contact details for ransomware decryption [email protected], [email protected], and [email protected]
Indicators of attack Unable to open previously accessible stored files on the computer. The file extension name is appended with “.NEFILIM” (for example, xyz.doc.NEFILIM). A ransom demand message is displayed on the desktop or in the encrypted drive or directory.
Damages caused All files are encrypted and cannot be opened without paying a ransom. Additional password-stealing trojans and malware infections can be installed together with ransomware infection.

 

Cybercriminals Vow Not to Attack Healthcare Amid COVID-19

Cyberattack on Ireland's Health care

Amid the slew of panic due to the global COVID-19 pandemic, cyberattacks on the Healthcare sector became an additional threat level and hurdle to overburdened hospitals, clinics, and research facilities. The attacks on the sector was so overwhelming that several leaders and companies in cybersecurity had come together to combat the cyberattacks, with the C5 Alliance being one of them.  But even criminals can have a heart in trying times; several ransomware groups are coming forward to assure that they would hold back from attacking health organizations during the Coronavirus crisis.

Lawrence Abrams from Bleeping Computers reached out to the operators of the Maze, DoppelPaymer, Ryuk, Sodinokibi/REvil, PwndLocker, and Ako Ransomware infections to find out if they would cease to target Healthcare organizations during this time of dire crises.

Among the first ones to respond was DoppelPaymer Ransomware, an infamous human-operated ransomware cybercrime group who stated that they usually avoid attacking hospitals and nursing homes, while also stressing that if they attack governments, they also don’t touch 911 even though emergency communications are hit due to network misconfigurations. They also stated that if any Healthcare organization is hit by mistake, they would decrypt it for free.

Maze ransomware authors also responded stating that, “We also stop all activity versus all kinds of medical organizations until the stabilization of the situation with the virus.” At the time of writing, no other cyber criminals issued any statements.

On the background, according to the UN health agency, criminals were attempting to pose as WHO representatives in an effort to carry out a variety of scams, from account takeovers to phony donation requests, and the spread of malware. KrebsonSecurity also reported that an interactive dashboard of Coronavirus infections and deaths produced by Johns Hopkins University is being used in malicious websites to spread malware.

The United States Computer Emergency Readiness Team (US-CERT) sent out alerts on scams tricking people into revealing personal information or donating to fraudulent charities, all under the pretext of helping to contain and manage the coronavirus. The Federal Trade Commission also warned about similar scams.

Unprotected Elasticsearch Server Leaks 5 Billion Records

Data breach in 100 U.S. cities

There have been multiple Elasticsearch database breaches, but this is unusual and one of the biggest to date. Around 5,088,635,374 records (more than five billion) were exposed after a U.K.-based security firm inadvertently exposed its “Data breach Database”, which stored huge information related security incidents from 2012 to 2019, without password protection.

Security researcher Bob Diachenko discovered the leaky database. Describing it as “Data was very well structured”, Diachenko stated that the leaky database contains huge data of previously reported and non-reported security incidents details, which include:

  • Hashtype (the way a password was presented: MD5/hash/plaintext, etc.)
  • Leak date (year)
  • Password (hashed, encrypted or plaintext, depending on the leak)
  • Email
  • Email domain
  • Source of the leak

Diachenko also said that he was able to confirm a few of the most prominent security incidents on Adobe, Last.fm, Twitter, LinkedIn, Tumblr, VK, and others. The database has been taken offline within an hour after Diachenko immediately sent a security alert.

Cyber Risks from Database Leaks

Attackers might take advantage of the sensitive information exposed to database leaks. Hackers can launch targeted phishing attacks, engage in account takeover fraud, and even sell the stolen data on dark web.

Recurring Elasticsearch Server Leaks

Elasticsearch servers have continued to leak protected personal information of millions of people and organizations. The most recent server breach occurred when Peekaboo’s app developer, Bithouse, left the Elasticsearch database open, which contained more than 70 million log files comprising nearly 100 GB data stored from March 2019. The exposed data included detailed device data, links to photos and videos, and around 800,000 email addresses.

There has always been a security concern about Elasticsearch servers. Security experts stressed that breach occurs due to lack of built-in protections, when there are no password protections or firewalls. Even ElasticSearch provided some recommendations on how to secure their servers, which include secure authenticated sign-in, proper encryption, layered security, and audit logging.

Surge in Remote Work Increases Cybersecurity Risks adding to COVID-19 Pandemic

initial access brokers

With Coronavirus or COVID-19 pandemic, organizations across the world are restricting their employees to work from home as part of social distancing to decrease the outbreak. On the flipside, most industry experts stated that remote work increases the risks of cyberthreats like never before. According to Zurich, a specialist in cyber insurance and risk engineering capabilities, businesses in financial, healthcare, federal and state agencies that deal with sensitive data might impact due to remote working conditions.

Zurich also suggested some guidelines to employees to help thwart cyber threats:

  • Be wary of suspicious emails, downloads, USB drives or other things that could introduce malicious software onto your computer and into the network. These could include spoofing and phishing attacks from hackers pretending to be IT personnel asking for your credentials
  • Promptly install patches and updates, including to your anti-virus software, to all devices on your home network
  • Go into your Wi-Fi router’s management software to ensure it’s running the latest firmware, which can update security flaws.
  • Connect to corporate networks using a secure means (e.g., a virtual private network), and store data on available encrypted network drives to avoid loss in the event of a computer virus or other malfunction.

Nikki Ingram, a Senior Cybersecurity Risk Engineering Consultant for Zurich, said “As an employee, ensure you are complying with your company’s security standards as a remote worker. Everyone wants to get their job done, but if, for example, you’re having internet trouble at home and your service provider tells you to lower your security settings, talk to your employer’s technical support before doing that.”

How Coronavirus Impacting Cyberspace

Cybercriminals never leave an opportunity to exploit any vulnerability or situation to prey on users online. A research from CYFIRMA found that Korean-speaking hackers were planning to make financial gains using sophisticated phishing campaigns, loaded with sensitive data exfiltration malware and creating a new variant of EMOTET virus (EMOTET is a malware strain that was first detected in 2014 and is one of the most prevalent threats in 2019). These hackers were planning to target Japan, Australia, Singapore, and the U.S. the researchers also observed North Korean hackers targeting South Korean businesses. The phishing email had the Korean language title “Coronavirus Correspondence”, tricking recipients into opening them and launching malware into machines and networks.

 Malicious Coronavirus Maps

Shai Alfasi, a security researcher at Reason Labs, discovered that threat actors distributed malware disguised as “Coronavirus Map” to steal personal information like usernames, passwords, credit card numbers, and other sensitive information that is stored in the users’ browser. Attackers use the stolen information for illegal activities like gaining access to bank accounts or selling it on the deep web. Attackers designed multiple websites related to coronavirus information to prompt users to click/download an application to keep updated on the situation. The website displays a map (looks like a genuine one) representing COVID-19 spread. It generates a malicious binary file and installs it on victims’ devices.