Home Blog Page 24

Experts to Convene at Ransomware Resilience Summit Series

Ransomware Resilience Summit Series

Ransomware attacks have surged 311% in the past year with a business now being attacked every 11 seconds. From crippling the Irish healthcare system and shutting down 45% of the eastern United States’ fuel supply to stopping manufacturing and production lines globally, attacks are hitting hard. Experts will gather at the two Ransomware Resilience Summits to discuss resilience and mitigation strategies.

Ransom demands have surpassed £50 million, and the average cost of recovery is around 10 times the size of the ransom demanded. The 2022 Ransomware Resilience Summit Series will bring organizations and their expert advisors together across 2 events in London and Washington to benchmark resilience and business continuity planning, share lessons learned and enable businesses to better protect themselves.

Are you fully confident in your organization’s ability to detect and defend against a ransomware attack?

Join us alongside leading cybersecurity experts from Europol, TikTok/ByteDance, Trainline, Prudential, HMRC, Wiley, Aston Martin, Microsoft and Barclays to learn how to identify cybersecurity threats and ensure strong mitigation plans; determine internal roles and responsibilities; practice cybersecurity hygiene as an organization; and apply lessons learned from past victims.


Ransomware Resilience Series

22 – 23 February | London
29 – 30 March | Washington DC


Download European Agenda
Download USA Agenda

With tickets starting at just £499, you could potentially save your business millions of pounds if you register today. Apply your exclusive discount code ‘SWCRC20’ at checkout to save an additional 20% on your ticket price. With ransomware attacks being the most prominent malware threat to businesses and ransom costs already passing $20 billion globally, can you afford not to attend?

Register now for our European Summit
Register now for our USA Summit

Pre-Event Workshop

Join us at our pre-event workshops (21 February, London | 28 March, Washington) with Linklaters and Mandiant to explore best practices and strategies for assessing incident response plans, looking at how organizations can better be equipped at building, growing, and adapting their action plans ahead of an attack.

For more information on our European Summit click here
For more information on our USA Summit click here

For sponsorship opportunities, please contact Ellis at [email protected]


SPONSORED FEATURE

BADNEWS for Hackers! Patchwork Group Expose Themselves in Malware Campaign

Patchwork BADNEWS, APT31 threat group

Not only users but cybercriminals also become victims of their mistakes sometimes. An India-based threat actor group dubbed Patchwork, which targeted users and government organizations in Pakistan, inadvertently exposed its hacking strategies online. Active since 2015, Patchwork affected various entities in Pakistan via spearphishing attacks. According to a report from Malwarebytes, the attackers exposed all the information they gathered, including their malware details, captured keystrokes, and screenshots of their systems.

Hackers Spreading Ragnatela via BADNEWS

The researchers stated that Patchwork leveraged malicious RTF files to drop a new variant of the BADNEWS Trojan dubbed Ragnatela in its recent campaign from late November to early December 2021. The group used spear phishing emails to distribute the Ragnatela RAT across the targeted network systems.

Ragnatela capabilities include:

  • Executing commands via cmd
  • Capturing screenshots
  • Logging Keystrokes
  • Collecting list of all the files in victim’s machine
  • Collecting a list of the running applications in the victim’s machine at specific periods
  • Downing addition payloads
  • Uploading files

Also Read: Pakistani APT Group ‘SideCopy’ Targets Officials in India and Afghanistan

Patchwork operators tricked victims with fake documents impersonating Pakistani authorities. The group used virtual machines and VPNs to develop and push updates to track their victims.

The victims of Ragnatela Trojan include:

  • Ministry of Defense- Government of Pakistan
  • National Defense University of Islam Abad
  • Faculty of Bio-Science, UVAS University, Lahore, Pakistan
  • International center for chemical and biological sciences
  • HEJ Research Institute of Chemistry, International center for chemical and biological sciences, University of Karachi
  • SHU University, Molecular medicine

Indicators of Compromise (IoC)

Lure

  • karachidha[.]org/docs/EOIForm.rtf
    5b5b1608e6736c7759b1ecf61e756794cf9ef3bb4752c315527bcc675480b6c6

RAT

  • dll
    3d3598d32a75fd80c9ba965f000639024e4ea1363188f44c5d3d6d6718aaa1a3

C2

  • bgre[.]kozow[.]com

“While Patchwork uses the same lures and RAT, the group has shown interest in a new kind of target. Indeed this is the first time we have observed Patchwork targeting molecular medicine and biological science researchers. Thanks to data captured by the threat actor’s own malware, we were able to get a better understanding of who sits behind the keyboard,” the researchers said.

Focus On Protecting Critical Infrastructure and Supply Chains

Cybersecurity Predictions

In 2021, we saw many attacks on critical infrastructure and supply chains, and these attacks are likely to continue in 2022. I’ve identified this as one of the top trends for 2022.

By Chuck Brooks, President, Brooks Consulting

Critical Infrastructure (CI) and supply chain will be targeted more in 2022 (state-sponsored, cybercriminal gangs) with ransomware and malware attacks. CI is a high-profile target for both geopolitical and economic considerations for hackers. This critical infrastructure includes defense, oil and gas, electric power grids, health care, utilities, communications, transportation, education, banking, and finance. Protecting critical infrastructure Industrial Control Systems (ICS), Operational Technology (OT), and IT systems from cybersecurity threats is a difficult endeavor. They all have unique operational frameworks, access points, and a variety of legacy systems and emerging technologies. Protecting the critical infrastructure supply chain in IT and OT systems will be a public and private sector priority. A special concern for the supply chain is third-party risk and their partners’ visibility in the chain. Investment and risk strategies will expand in conducting vulnerability assessments and filling operational gaps with cybersecurity tools. Tools include Data Loss Prevention (DLP), encryption, identity and access management solutions, log management, and SIEM platforms. 

Despite efforts to attract workers to security and tech jobs, the qualified cybersecurity worker shortage will continue to pose major operational challenges. The public and private sectors are currently facing challenges from a cybersecurity talent shortage. A report from the firm Cybersecurity Ventures estimates there are 3.5 million unfilled cybersecurity jobs in 2021. And 2022 is not showing any signs of improvement in hiring.  

The Internet of Things (IoT) will pose a growing cybersecurity risk. IoT’s exponential connectivity is an ever-expanding mesh of networks and devices. IoT incorporates physical objects communicating with each other, including machine-to-machine and machine-to-people. It encompasses everything from edge computing devices to home appliances, from wearable technology to cars. IoT represents the melding of the physical world and the digital world.  They differ from conventional computers as they are highly specialized and usually small, both in physical size and computing capacity. A cybersecurity challenge of IoT is the lack of visibility and the lack of ability to determine if a device has been compromised and not performing as intended. The increased integration of endpoints combined with a rapidly growing and poorly controlled attack surface poses a significant threat to the Internet of Things. Protecting such an enormous attack surface is no easy task, especially when there are so many varying types and security standards on the devices. It will only worsen in 2022 as connectivity grows.


About the Author

Chuck_BrooksChuck Brooks is the President of Brooks Consulting International and Adjunct Faculty at Georgetown University.He is a Technology Evangelist, Corporate Executive, Speaker, Writer, and a Government Relations, Business Development, and Marketing Executive. With over 74,000 followers on LinkedIn, 16,000 followers on Twitter, and 5,000 followers on Facebook, Chuck has built a sizeable community on social media, where he regularly shares the latest happenings and updates from the cybersecurity industry. He was named The Top 5 Tech People to Follow on LinkedIn. He’s among the world’s 10 Best Cyber Security and Technology Experts, by Best Rated; in the Top 50 Global Influencer in Risk, Compliance, by Thomson Reuters; the Best of The Word in Security, by CISO Platform, and IFSEC’s #2 Global Cybersecurity Influencer. Chuck was featured in the 2020 and 2021 Onalytica Who’s Who in Cybersecurity as one of the top Influencers for cybersecurity issues and risk management. He was also named one of the Top 5 Executives to Follow on Cybersecurity by Executive Mosaic; the Top Leader in Cybersecurity and Emerging Technologies by Thinkers360, and Top Global Top 50 Marketer by Oncon in 2019. Chuck has an MA in International Relations from the University of Chicago, a BA in Political Science from DePauw University, and a Certificate in International Law from The Hague Academy of International Law.

France’s CNIL Fines Facebook and Google Over Privacy Violations

France Fines Facebook and Google,Russia fines Google, Meta heavily New York City Law Department Hit by a Cyberattack

France’s data privacy watchdog, the Commission Nationale de l’informatique et des libertés (CNIL), fined Google €150 million ($170 million) and Facebook (now Meta Platforms) €60 million ($68 million) for violating E.U. data privacy laws. The regulator stated the companies failed to provide an easy option for users to reject cookie tracking technology.

In an official release, CNIL stated that facebook.com, google.fr, and youtube.com provided a button allowing users to accept cookies without giving them an option to refuse them. The regulator stated the companies violated Article 82 of the French Data Protection Act. “They do not provide an equivalent solution (button or other) enabling the Internet user to easily refuse the deposit of these cookies. Several clicks are required to refuse all cookies, against a single one to accept them,” CNIL said.

What are Cookies? 

Cookies, also known as HTTP cookies, are small pieces of information created when browsing a website. The cookies help technology firms to track and store users’ online activities across the internet. Several internet firms leverage cookies’ data to understand users’ online behavior and implement appropriate marketing strategies.

Also Read: Russian Court Slams Google And Meta with Hefty Fines

Google and Facebook Violated Data laws

In addition to penalties, CNIL ordered Google and Facebook to provide users in France with a feature to refuse cookies within three months. The companies are ordered to pay a penalty of 100,000 euros per day if they fail to do so.

“These two decisions are part of the global compliance strategy initiated by the CNIL over the past two years with French and foreign actors publishing websites with many visits and having practices contrary to the legislation on cookies. Since March 31, 2021, when the deadline set for websites and mobile applications to comply with the new rules on cookies expired, the CNIL has adopted nearly 100 corrective measures (orders and sanctions) related to non-compliance with the legislation on cookies,” CNIL added.

Hefty Fines From Russia 

It seems that Google and Meta started the New Year on a bitter note after receiving hefty penalities from the Russian government. A Russian court reportedly penalized Google, 7.2 billion rubles (around $98.4 Mn), and Meta, 2 billion rubles ($27.2 Mn) for not removing banned content from its platforms. The Tagansky District Court judged that Google repetitively neglected to delete content banned by local law. Read More Here

FBI Warns About Hackers Targeting U.S. Organizations in BadUSB Attacks

BadUSB attack

The FBI is warning organizations in the U.S. about a new social-engineering attack from the infamous cybercriminal group FIN7. The group reportedly targeted the U.S. defense sector with a package of malicious USB flash drives to deploy ransomware and launch BadUSB attacks. According to a report, the FIN7 group sent several packs of USB devices, using the U.S. Postal Service and U.S. Parcel Service, to organizations in the transportation, insurance, and defense sectors.

The attackers sent the malicious USB drives via two packages— one is imitating (U.S. Department of Health and Human Services) HHS referencing COVID-19 guidelines. Another is mimicking a gift box from Amazon containing a fake gift card and a USB. The hackers used LilyGO-branded USB devices in this campaign.

Hackers Executing BadUSB Attack

The FBI claim that the malicious USB drives are designed to launch a BadUSB attack on the targeted devices. In BadUSB attacks, threat actors leverage USB devices programmed with malicious software.

Also Read: FIN7 is Running a New Fake Company Called ‘Bastion Secure’ for Ransomware Attacks

Once a victim plugs the USB drives into their systems, the USB device registers itself as a keyboard and sends a series of preconfigured automated keystrokes to the victim’s computer. The keystrokes then run PowerShell commands that automatically install the final malware payload  acting as the backdoor for the attacker’s campaign. FBI stated the group illicitly obtained administrative privilege access and moved laterally to compromise local systems in the targeted network.

The agency also stated that FIN7 actors leveraged a variety of malware and ransomware variants, including Metasploit, PowerShell scripts, Carbanak, GRIFFON, Cobalt Strike, DICELOADER, TIRION, BlackMatter, and REvil.

FIN7 Hackers on the Rise

Since 2015, FIN7 attackers have engaged in various malware campaigns that targeted more than 100 U.S. companies.The group recently targeted companies under the guise of a cybersecurity services firm, Bastion Secure. The group reportedly recruited IT specialists to conduct pen testing and carry out ransomware attacks through this phony company.. Researchers from the Gemini Advisory group posed as IT professionals and applied for the role of IT executives. They were asked to analyze tools and network files. The company appears legitimate as it has closely replicated other service companies in its recruitment process. Read More Here

Take a Unified Approach to Security Solution Stacks

Cybersecurity Predictions

Pandemic-induced disruptions have resulted in digital becoming synonymous with business transformation. This digital pervasiveness has also brought risks and vulnerabilities, amplifying the need for cybersecurity solutions to go beyond traditional security perimeters. Progressive enterprises must take a unified approach to security.

By Chandan Pani, Chief Information Security Officer, Mindtree

Here are some security trends that will play out in the months ahead.

Security will take a unified approach. Given the ever-evolving nature of businesses and threat actors and their tactics, progressive enterprises will take a unified approach to their security solution stacks. This will call for an architecture where every component of the stack speaks with each other, sieving signals from noise regardless of their origin — cloud or data center, IT or IIoT, endpoints or mobile devices. Security silos resulting from isolated legacy solutions can readily become a formidable risk within themselves.

Demand for cybersecurity skills will spike. The demand for cybersecurity professionals adept at technology and risk management continues to grow as more enterprises embrace technology like never before. However, the scarcity of these professionals presents a significant challenge in the war against cyber threats. While advanced qualifications and security certifications will continue to be critical, organizations will need to look deeper to ensure that the cybersecurity talent of tomorrow comes with real skills and motivations required to identify, prevent and manage cyber risks across complex networks.

Hypergrowth in the cloud will make security a shared responsibility. The rapid transition to the cloud has brought with it new security challenges. As cloud computing services are available online, anyone with the right credentials can access them. At the broader level, cloud environments experience nearly the same critical threats as traditional data center environments. There is, however, a key difference:  The responsibility to mitigate risks resulting from vulnerabilities in cloud environments lies not just with the cloud service provider but also with the cloud consumer. Therefore, a shared responsibility model for security will become even more crucial with a clearer division and tighter oversight of responsibilities and accountabilities between cloud service providers and consumers.

The technical, financial, commercial, compliance, and legal ramifications of security are growing in complexity. Consequently, the way forward will be to build comprehensive and unified security frameworks that provide end-to-end visibility into the threat landscape and prevent things from falling through the cracks.


About the Author

Chandan-PaniChandan Pani is the Chief Information Security Officer for Mindtree, where he is leading Mindtree’s global and diverse information security and cyber risk strategy. He has managed several projects on penetration testing, threat modeling, vulnerability management, security risk assessments in pre & post-production environments and Information Risk management for large IT/ITES projects. Along with Certifications like CISSP, CISA and CRISC, he has over 18 years of IT and Information security leadership experience across business domains. Following cyber security industry is his passion and that keeps him busy in current pandemic. Otherwise, he loves going on long jogs for unwinding.

FBI Issues Warning About Google Voice Authentication Service Scamming Users

Google Voice Authentication

Cybercriminals are always on the hunt for users’ information online. Adversaries often exploit users’ data to launch various kinds of cyberattacks and scams. The officials at the FBI are warning U.S. citizens to be vigilant while posting personal information online. The federal agency stated that Google Voice authentication scams target people who share their contact details. Fraudsters reportedly targeted users who post their phone numbers while selling goods in online marketplaces or social media platforms.

“You post your real phone number on some online platform. It’s common for scammers to target victims who use popular marketplace apps or websites to post items for sale. Want to get rid of that old couch? Post it on one of those popular re-sale sites, and hope someone likes your taste in style. Recently, we have also been getting reports of people who are getting targeted in other locations, including sites where you post about lost pets,” the FBI said in a statement.

Also Read: U.S. Consumers Lost $148 million to Gift Card Scams in 2021

Misuse of Google Voice

Google Voice authentication service allows users to set up a virtual phone number which is then used to make domestic and international calls or send and receive text messages. Threat actors often exploit these virtual numbers to launch various scams and frauds. Scammers could use compromised virtual phone numbers in fraudulent ads or other malicious activities to hide their real identities.

How Google Voice Scam Works

Fraudsters contact the stolen numbers via text or call showing false interest in buying the products advertised by the user. The attacker sends an authentication code from Google to the victim to confirm the authenticity. The attacker then asks the victim to provide the authentication code received. Here, the attacker is actually setting up a Google Voice account with the victim’s name using his contact number as verification. Once set up, scammers use that Google Voice account to perform various frauds against the victims and even leverage the authentication code to compromise the victim’s Gmail account.

Mitigation

The FBI recommends that victims of the Google Voice authentication scam visit Google’s support website to know how to regain control of their Google Voice account and the voice number. The agency also shared certain security measures to prevent such attacks from happening in the first place. These include:

  • Never share a Google verification code with others.
  • Only deal with buyers, sellers, and Fluffy-finders in person. If money is to exchange hands, make sure you use legitimate payment processors.
  • Do not give out your email address to buyers/sellers conducting business via phone.
  • Do not let someone rush you into a sale. If they press you to respond, they are likely trying to manipulate you into acting without thinking.

Morgan Stanley Pays $60M to Settle Data Breach Litigation

American Cybersecurity Literacy Act

The U.S. investment bank and financial services company Morgan Stanley recently agreed to pay $60 million to settle a data breach class-action lawsuit. The proposed fine results from two data leak incidents that affected personally identifiable information (PII) of over 15 million current and former clients of Morgan Stanley.

As per the lawsuit filed in a U.S. District Court for the Southern District of New York, the affected class members will be compensated up to $10,000 for out-of-pocket losses along with two years of fraud insurance coverage.

Data Breach in Brief

Plaintiffs allege that Morgan Stanley failed to delete the information of over 15 million of its current and former clients in 2016 and 2019 from its IT platform before selling it to third parties. An investigation by the Office of Comptroller of Currency (OCC) revealed that Morgan Stanley violated the data privacy laws by exposing its clients’ sensitive data to third parties.

The exposed information included customers’ date of birth, social security numbers, home and work contact information, the identity of spouses and children, and passport, banking, and credit card information.

Also Read: Morgan Stanley Jumps on the Bandwagon of Accellion Data Breaches

“Morgan Stanley first learned of the 2016 Data Security Incident in October 2017, when it was contacted by a third party who said he had bought used IT equipment from an internet vendor and had access to Morgan Stanley data. In 2020, the OCC directed Morgan Stanley to provide notice of the Data Security Incidents to its potentially affected current and former clients. Morgan Stanley began distributing notice letters in July 2020. The action by the OCC resulted in a consent order stating that Morgan Stanley failed Case 1:20-cv-05914-AT Document 81-1 Filed 12/31/21 Page 6 of 38 – 4 – to effectively assess or address the risks associated with the decommissioning of its hardware,” the lawsuit said.

Morgan Stanley and Data Breaches

Morgan Stanley has been stuck in multiple data breach incidents over the year. The global financial services provider recently reported a data breach after unknown hackers stole its customers’ private data by exploiting the bug in the Accellion File Transfer Appliance (FTA) server hosted by a third-party vendor. Morgan Stanley has a huge client base, including public and private organizations, government entities, and institutions across the globe. The data breach could impact the company in several aspects.

Episode #19: Digital Transformation and Cybersecurity

Digital Transformation and Cybersecurity

Organizations accelerated their digital transformation plans during the pandemic months. Plans that could take years to implement were executed in days and months. As a result, hurried decisions were made, and security was not thought through. It resulted in misconfigurations and careless security lapses leading to increased breaches and attacks. Hackers turned their attention to workers at home who have weak security. This led to increased phishing, ransomware and BEC attacks.

And because of this, other organizations are hesitant to embark on their digital transformation journeys or they have become prudent.

In this episode, Alpna J. Doshi, CEO, Stralynn Consulting Services, Inc. talks about the security risks and setbacks that arise out of hasty digital transformation projects.

 

Doshi says she founded her company with a vision to combine Digital Transformation and Cybersecurity, in a way that people will move ahead and embrace automation, with confidence. She says business leaders and operational heads will move ahead with digital transformation once they are convinced that cybersecurity has been adequately addressed.

Cybersecurity often needs a complete relook in failed or hung digital transformation projects, says Alpna. It is imperative to understand the complete ecosystem for the proper implementation of cybersecurity. To improve time to market, businesses fast track IT initiatives through Agile and DevOps. But security considerations are often ignored or overlooked.

According to Gartner, 60% of digital businesses would experience major service failures by 2023, due to the inability of security teams to manage the Digital Risk.  Doshi says digital with operational technology integration broadens the attack surface. To mitigate this, IT teams must connect the dots between the organization’s security and it’s ecosystem of partners and vendors. Are organizations ensuring that there is full-fledged governance for third-party cyber risk management?

Alpna J.Doshi, is a trailblazer in implementing complex transformations with 28+ years in the industry and has worked as an operating partner for Thoma Bravo, with over $80B assets in SaaS companies, and served as a respectable visionary leader for major companies such as Reliance Group, Royal Philips, and other major MNCs across the globe. Alpna is also on the Board of Mimecast, a Cybersecurity leader. She is widely recognized for her role in driving innovation, digitization, and growth while paving the way as a multi- faceted thought leader.

Stralynn Consulting Services, Inc. has been formed with a goal to be the pioneer in Digital Transformation Services with a mission to bridge the gap between the digital and legacy operational models.  Stralynn is headquartered in San Jose, California, USA, with offices in Canada and India. Its digital transformation dossier includes an array of digital business services, customized to provide multi-X EBITDA and growth agility.

North Korean Hackers Greet Russian Diplomats with Malware

Konni Malware, North Korean threat actors target AstraZeneca

Security experts uncovered a North Korean-linked cyberespionage group targeting Russian embassy diplomats with weaponized email attachments. Dubbed Konni, the threat actor group reportedly sent New Year greeting emails embedded with malware to infect the victim’s device. The Konni malware campaign has been active since December 2021, according to researchers from Cluster25.

Konni Remote Access Trojan

Cluster25 researchers claim that attackers distributing malicious ZIP files contained a Windows screensaver (.scr) file citing holiday greetings. Once the user opens the file, the Konni remote access trojan (RAT) malware automatically gets downloaded onto the device.

Also Read: Researchers Uncover North Korean Threat Actor Group TA406 Targeting Diplomats

“These emails used the New Year Eve 2022 festivity as decoy theme. Contrary to its past actions, the North Korean APT group this time did not use malicious documents as attachments; instead, they attached a .zip file type named ‘поздравление.zip’, which means ‘congratulation’ in Russian, containing an embedded executable representing the first stage of the infection,” Cluster25 said.

Attacks From North Korean Actors Continue

State-sponsored actors from North Korea continue to target critical organizations worldwide. According to a cyberthreat research report from Proofpoint, the North Korean actors mostly target individuals from North America, Russia, and China. Tracked as Threat Actor 406 (TA406), the campaign reportedly stole users’ credentials and sensitive financial data from high-level officials, law enforcement officers, and experts in economics and finance.

The attackers have targeted the victims by masquerading as Russian diplomats and academics, representatives of the Ministry of Foreign Affairs of the Russian Federation, human rights officials, or Korean individuals. TA406 has also targeted individuals and organizations related to cryptocurrency for financial gain.