Home Blog Page 243

Toll Faces Customer Fallout After Cyberattack

Toll Australia, ransomware

Toll Group, the Australian freight delivery service provider, is struggling to restore its services completely after being hit by the recent “Mailto” ransomware attack on its infrastructure. The incident compromised around 1,000 systems that affected local and global deliveries across the country, and forced Toll to take down many of its delivery and tracking systems. The officials at Toll stated that they have rolled out a cautious approach to restore its systems. The company removed over 500 applications that supported its international operations in 25 countries. Toll stated that its internal networks and user access are currently operational, and the company is continuing to resume the operations of its international air and ocean freight shipments.

Toll declined to reveal the ransom that was demanded. However, the company clarified that it’s not paying or has paid any ransom. Earlier, Toll said that it was working with the Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) to identify the virus and how to respond. It has also been working with the Federal Police since the attack.

Toll received severe criticism over the time taken to investigate the incident and start restoring services back online. Toll is facing complaints from its customers and clients including Unilever, Adidas, Nike, Telstra, Optus, Footlocker, and Officeworks due to indefinite delays over deliveries.

“From the outset, we’ve prioritized customer-facing and other critical systems. We now have many of our customers back online and operating essentially as normal, including through large parts of our global cargo-forwarding network and across our logistics warehouse operations around the world. And, we’re progressively reactivating full services on the MyToll parcels booking and tracking portal,” a spokesperson from the Toll Group said in a media statement.

The statement also highlighted, “Core systems including email, phones and end-user devices have been tested, restored and are operating as normal. For all of that, we know that some of our customers continue to be affected. We’re working with them and we’re doing everything in our power to get them moving as a matter of priority and, importantly, when it’s safe to do so.”

How Mailto Ransomware Affected Toll Group

On January 31, 2020, post the attack discovery, Toll promptly shut down several systems across multiple sites and business units in Australia to stop the spread of ransomware. The incident resulted in Toll reverting to manual processes for clearing the backlog of undelivered local and international parcels across Australia. It continued to function its regular pickup, process and dispatch services, but at a slow pace due to manual processing.

Personal Information Belonging to 144,000 Canadians Breached

Canada Revenue Agency Shut Down Services after Cyberattacks

Several government departments in Canada have compromised the personal information of 144,000 individuals across 7,992 data breaches that occurred over the past two years, according to a report from the Canadian Broadcasting Corporation (CBC). The Canadian government stated that the information breached while answering to an order paper question filed by Conservative MP Dean Allison last month.

According to report findings, the Canada Revenue Agency (CRA) suffered a greater number of cyberattacks with 3,005 data breaches which affected 60,000 Canadians’ information. The CRA blamed the breaches on security issues, misdirected mail, and employee misconduct. Health Canada reported the second-highest number of data breaches with 122 breaches, affecting 23,894 individuals. The report also revealed that the Public Health Agency of Canada (PHAC) was responsible for seven breaches that affected 3,725 individuals.

Etienne Biram, CRA spokesperson, said, “We consider a single privacy breach to be one too many. Two-thirds of the total individuals affected were as a result of three unfortunate but isolated incidents.”

The other government entities that reported data breaches include the Public Services and Procurement, which experienced 164 breaches, with 5,149 affected; Employment and Social Development Canada suffered 1,421 breaches, affecting 3,586 individuals; Department of National Defence (DND) was responsible for 170 breaches, with 2,273 individuals affected; Immigration saw 3,005 breaches, affecting 4,268 individuals.

“As it stands, federal departments only have to alert affected individuals in the event of material breaches–cases involving sensitive personal information, which reasonably could be expected to cause serious injury or harm to an individual, or ones affecting large numbers of people,” CBC stated.

 Data Breaches Increased in Canada

 Earlier, the office of the Privacy Commissioner of Canada revealed that around 680 security breaches were reported in 2019, which is six times the volume received during the same period in 2018. It’s said that the number of Canadians affected by a data breach is more than 28 million, in which 58 percent of reported breaches involved unauthorized access.

The number of reported data breaches in Canada increased by six times after the country implemented a breach-reporting regulation. The new regulation, the Personal Information Protection and Electronic Documents Act (PIPEDA), went into effect on November 01, 2018. As per the regulation, Canadian companies are required to report all the details of data breaches that occurred within the organization. They also need to notify affected individuals and keep records of all data breaches.

PhotoSquared App Exposes 100,000+ Customer Photos

DEO data breach

The known cybersecurity research duo Noam Rotem and Ran Locar, from vpnMentor, discovered a data breach in the U.S.-based photo printing app, PhotoSquared. The exposed database potentially compromised personalized data of more than 100,000 PhotoSquared customers including their photos, print labels and order details such as delivery address, invoice amount and more.

PhotoSquared app is available on the iOS and Android platforms where users can upload photos in the app which can then be printed onto lightweight photo tiles. These decorative tiles are further mailed back to the users as per the delivery details mentioned at the time of checkout. It’s a very basic yet popular app having a customer database of over 100,000.

The research duo found that the database in question was hosted on Amazon Web Services (AWS), using an S3 bucket. The company’s name was mentioned in the database URL. Customer data found in the unprotected database totaled to 94.7GB and dates from November 2016 to January 2020. The researchers said that, “It’s important to note that open, publicly viewable S3 buckets are not a flaw of AWS. They’re usually the result of an error by the owner of the bucket. Amazon provides detailed instructions to AWS users to help them secure S3 buckets and keep them private, but owners at times fail to implement basic security protocols.”

Risk Mitigation Steps

AWS provides a detailed list of instructions to its users for guiding them to secure S3 buckets and to keep them private, including:

  • Turn the bucket settings to private and add authentication protocols.
  • Implement best practices of AWS access and authentication.
  • Add additional layers of protection to their S3 bucket to further restrict who can access it from every point.

The same research duo Noam Rotem and Ran Locar, had earlier found an unprotected AWS S3 database containing personal and private information of British citizens that included passport scans, tax documents, job applications, background checks, expense forms, scanned contracts complete with signatures, salary information, emails and more.

Researchers came across this data while working on a web-mapping project that scans for data leaks. Rotem said, “We’re scanning large parts of the internet and trying to find data that is lying around within open databases that don’t require any hacking.”

U.S. CISA, DHS, and FBI Discover North Korean Malware

Konni Malware, North Korean threat actors target AstraZeneca

The U.S. Department of Homeland Security, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), and the FBI recently exposed a new hacking activity that is apparently originated from North Korea. According to the Cyber National Mission Force (CNMF), state-sponsored hackers from North Korea distributed six different malware variants through a phishing campaign. It’s said that the malware provided the attackers with remote access to infected systems to steal funds which are later transferred to North Korea.

Six Malwares used in the Hacking Activity

The CNMF published the details on the six new malware samples which are under the federal authority’s radar.

  • BISTROMATH – detailed as a full-featured RAT
  • SLICKSHOES – described as a malware dropper (loader)
  • CROWDEDFLOUNDER – detailed as a 32-bit Windows executable, which is designed to unpack and execute a RAT binary in memory
  • HOTCROISSANT – a full-featured beaconing implant used for performing system surveys, file upload/download, process and command execution, and performing screen captures
  • ARTFULPIE – described as an implant that performs downloading and in-memory loading and execution of a DLL from a hardcoded URL
  • BUFFETLINE – described as a full-featured beaconing implant, which downloads, uploads, deletes, and executes files

North Korea was accused multiple times earlier for stealing valuable information and cryptocurrencies. Through the years, North Korea has been linked to a series of cyberattacks, either to display its cyber prowess or just to fund their activities.

CISA Relates Malware to Lazarus Group

CISA related the malware activity to a North Korean government-backed hacking group tracked as “Hidden Cobra”, which is a part of the notorious threat actor unit “Lazarus Group”. The Lazarus Group was involved in various cyberattacks that were reported earlier. Recently, security pros from K7 Labs discovered that hackers of Lazarus Group distributed malware that targeted MacOS users to create fake cryptocurrency trading applications.

Upgraded Ukrainian Blackout Malware Sold on the Dark Web

Rootkits, Mobile Malware in Asia

Ukrainian Blackout Malware operated by the state-sponsored BlackEnergy gang, first made news in December 2015, when it took down the entire power grid of the Ivano-Frankivsk region in Ukraine. This malware specifically targets the SSH (Secure Shell) keys, which is used to build secure communication lines between two or more machines. However, researchers at cybersecurity firm Venafi, have now seen a surge in its spread owing to its sale on the Dark Web in the form of Malware-as-a-Service (MaaS).

Upgradation of Blackout Malware

An SSH key acts as a login credential in SSH protocol-based communication. It is like having usernames and passwords, but these keys are primarily used for automated processes and for implementing single sign-on by system administrators. Thus, a compromise of even a single SSH key can give attackers unrestricted root access to critical systems, which further gives a backdoor entry into spreading malware or sabotaging the processes.

A recent upgrade in the Blackout Malware now adds attackers’ SSH keys to the victims’ machine in a list of authorized key files which then trusts the attackers’ key for carrying out secure communication. Other techniques include applying brute force on weak SSH authentication to gain access and move laterally across networks. Venafi said that, over the past year, these techniques have been observed and verified by TrickBot, cryptomining campaign CryptoSink, Linux Worm and Skidmap.

Yana Blachman, a threat intelligence specialist at Venafi, said, “SSH keys can be potent weapons in the wrong hands. But until recently, only the most sophisticated, well-financed hacking groups had this kind of capability. Now, we’re seeing a ‘trickle-down’ effect, where SSH capabilities are becoming commoditized. What makes this commoditization so worrying is that if an attacker is able to backdoor a potentially interesting target, they may monetize this access and sell it through dedicated channels to more sophisticated and sponsored attackers, such as nation-state threats for the purpose of cyber espionage or cyber warfare.”

In order to combat such threats, organizations need to have cyber analytics and threat intelligence in place to plug these holes in the organization’s infrastructure. Additionally, provide utmost protection to all authorized SSH keys in the organization and prevent them from being targeted by attackers.

Google Announced US$1 Million for its “Be Internet Awesome” Initiative

Google Announced US$1 Million for its “Be Internet Awesome” Initiative

Google recently announced that it’s going to spend US$1 million to bring awareness on data privacy and internet security across the sub-Saharan Africa region. The search engine giant also launched its child online safety program “Be Internet Awesome” in South Africa, the Netherlands, and Nigeria.

“Be Internet Awesome” initiative helps minors explore the internet confidently and securely. The initiative teaches kids and minor students skills for surfing the internet, how to recognize potential online scams, secure valuable information, how to identify and refrain from cyberbullying. Google stated that it partnered with the South African Film and Publications Board (FPB) to implement the program locally.

Commenting on the initiative, Abongile Mashele, acting Chief Executive Officer at FPB, said, “The FPB has a responsibility to protect children from exposure to harmful content, thus the organization needs to play a leading role in creating awareness around the dangers of the internet, as much as it is incumbent on us to also encourage the use of the digital space as an empowering tool.”

Fortune Mgwili-Sibanda, Head of Public Policy and Government Relations at Google Africa, said, “Google is committed to a safe internet for children. We are also passionate about the empowerment of organizations that share this commitment. The fund will be administered by a third-party partner on behalf of Google.org, and we will be sharing details on application criteria and deadlines soon.”

Mgwili-Sibanda also highlighted that “Children are being exposed to the internet at their most vulnerable age so it’s important for us, at Google, to ensure that they do so as safely as possible. At the same time, teachers and parents can use these resources in order to support and guide children as they navigate the Web.”

Cybercrimes in Africa

A research report from the information security firm Dataprotect revealed that the estimated cost of cybercrimes in Africa is €3.5 billion (approximately US$3.87 billion), compared to €528 billion (US$585 billion) worldwide. However, Africa still falls short in handling cybersecurity challenges. The analysis highlighted that the lack of skilled and qualified workforce and lesser investments in cybersecurity made West African banks vulnerable to cyberattacks including bank card fraud, phishing, and intrusions, etc.

NSO Group Acquires Convexum to Add New Product Segment to its Business

Kaspersky and SAFCSP Sign an MoU for Cybersecurity Training in Saudi Arabia

Israel’s cyber intelligence and surveillance company NSO Group recently acquired drone technology startup Convexum in a cash deal of US$60 million. Based in Tel-Aviv, Convexum develops counter-drone technologies to combat malicious drones and land them safely. Founded by IDF Intelligence Unit 8200 veterans Gilad Sahar and Niv Magen, Convexum also offers security solutions to mitigate drone threats. With the latest acquisition, the NSO Group decided to increase its product line in the drone sector.  The company stated that it will offer its comprehensive security solutions to government and public enterprises.

Founded in 2009, NSO Group is a developer of spyware for mobile devices. The firm is well-known for the development of Pegasus software that targets mobile phones to gather information and provides authorized governments with technology that helps them combat terror and crime. Due to its controversial spyware inventions, NSO encountered multiple security and legal issues in the past.

NSO’s Product Controversies

Last year, the NSO Group was sued by Facebook for violating the Computer Fraud and Abuse Act. Facebook revealed that it discovered a vulnerability in its network system that allowed hackers to install spyware via an infected WhatsApp voice call. According to the lawsuit filed in the federal court, the NSO Group deployed its custom malware on around 1,400 WhatsApp installed mobile devices in April and May 2019. It stated that the attackers used servers and Internet-hosting services that related to NSO Group. Nearly a hundred human rights advocates, journalists, and members of civil society across the world were targeted in the attack, according to Facebook.

Samsung Extends Partnership with McAfee for Data Security

CynergisTek Partners with Awake Security to Boost Cybersecurity in Health Care

Device-to-cloud cybersecurity company McAfee announced the extension of its partnership with Samsung to protect consumers’ personal data from online threats. The partnership enables Samsung smartphones to come up with pre-installed anti-malware protection powered by McAfee. In addition, the alliance offers data protection to Samsung PCs and laptops. Samsung stated that their PCs and laptops will come pre-installed with McAfee LiveSafe software, which provides protection against viruses, online threats, and ransomware with online and offline protection.

With attackers using sophisticated technologies to break into victims’ devices, it’s important for enterprises to maintain robust security measures. According to McAfee, 504 threats are discovered every minute, which represents the severity of cyber risks.

Terry Hicks, Executive Vice President at McAfee, said, “Consumers are connected more than ever, and McAfee is dedicated to protecting them online when they shop, bank, share and journey across the internet. Our partnership with Samsung continues our mission to give consumers peace of mind that their personal data, as well as their families and friends, won’t be jeopardized online.”

“There are now roughly four billion consumers connected online for an average of over six hours a day, from sharing photos to socializing with friends to completing bank transactions. Consumers expect to be able to do what they desire online- whenever and wherever they want- without worrying about the potential risks that might be lurking online,” Hicks added.

Earlier, McAfee partnered with Amazon Web Services (AWS) to offer cloud-based security solutions. McAfee stated its new security product delivers real-time visibility into all database activities and offers monitoring services to prevent sophisticated attacks. The new alliance allows the users to benefit from real-time protection for database workloads migrated to Amazon RDS while monitoring databases.

New Rogue Cryptomining Techniques and Cases

Cryptocurrency

It’s common knowledge that new cryptocurrency units come into existence through mining, a process of complex computation relying on CPU or GPU power. Unfortunately, this routine isn’t always done in an ethical way. Cybercriminals have masterminded numerous techniques to parasitize other people’s PCs and servers for generating coins surreptitiously.

Contributed by David Balaban

The boom of rogue cryptomining (or cryptojacking) at the expense of unsuspecting users’ machines co-occurred with Bitcoin price reaching its peak in late 2017. Although the subsequent dramatic decline in its value brought many of these malicious campaigns to a halt, the predictions of the epidemic’s prompt end were premature.

New waves of cryptojacking have surfaced since the prices of popular cryptocurrencies started to gradually climb back up in 2019. To top it off, crooks are now utilizing novel techniques to masquerade their malware and monetize it. Their overhauled repertoire ranges from infecting airports and Docker hosts – to distributing booby-trapped WAV audio files and fake CMS plugins targeting different operating systems. Below are a few recent incidents that gave security analysts a heads-up.

Stealth Monero Miner Detected in an International Airport’s Systems

In mid-October 2019, researchers from security firm Cyberbit made an unsettling discovery when deploying their Endpoint Detection and Response solution in a European international airport. They found that more than half of the airport’s workstations were contaminated with a malicious variant of the XMRig Monero mining program. The infection had slipped below the radar of the antivirus tool running on the facility’s machines, but the behavioral analytics module built into the new protection software was able to identify the anomalous activity.

Although this malware lineage has been around for over a year, the experts realized they were dealing with its offshoot that underwent several tweaks to evade detection by traditional AV applications. Another new feature of the miner is that it uses PAExec, a tool based on Microsoft’s better-known PSExec service that allows threat actors to execute arbitrary processes on hosts remotely. The malicious operators leveraged this utility to gain a foothold within the network and run the harmful app with maximum privileges.

The malefactors also took advantage of the so-called Reflective DLL Injection technique to ensure fileless execution of the offending code, which means it runs entirely in memory and isn’t deposited onto the hard drives. This adds another layer of obfuscation to the attack. The original payload most likely arrived with a phishing email or drive-by download. The good news is that the malware impact was restricted to abusing the hosts’ CPU capacities to mine cryptocurrency and wasn’t aimed at disrupting the normal operation of the unnamed airport.

Unique Cryptojacking Worm Targeting Docker Hosts

For the record, Docker is a virtualization service used for hosting software and data in isolated repositories called containers. These frameworks are run by a single-engine and can have different configurations and structures while, technically, constituting the same software ecosystem.

Palo Alto Networks’ Unit 42 analysts recently came across an attack vector used to inject a cryptominer into thousands of vulnerable Docker containers. This exploitation technique stands out from the crowd because the offending code, dubbed Graboid, has worm characteristics, which is a new thing in this segment of cybercrime.

The operators of this campaign identify unsecured Docker hosts by running a scan with Shodan or a similar search engine. Having accessed a target, they install and execute a malware-riddled Docker image. This entity mines for Monero cryptocurrency and reaches out to its Command & Control server occasionally to retrieve an updated list of other unprotected Docker services. The malware randomly selects the next victim and spreads itself to the new target via the Docker client utility that supports communication with other hosts.

Graboid behaves in a somewhat haphazard way. It pauses its cryptomining job on some compromised hosts while starting it on others. Therefore, each miner is up and running about 65 percent of the time, and the mining session lasts four minutes on average. This inconsistency allows malicious actors to hide the attack in plain sight. Another thing, thwarting detection is that traditional security software doesn’t check for sketchy activity inside Docker containers.

Audio Files Carrying a Cryptomining Payload

Researchers at cybersecurity firm BlackBerry Cylance unearthed a highly evasive method of delivering cryptomining malware in October 2019. It uses benign-looking WAV files to spread a Monero miner without conspicuously raising any red flags.

The wicked architects of this campaign have found a way to pollute the data structure of regular audio tracks with the toxic payload. A victim may not notice any issues with the sound quality at all. Meanwhile, the embedded loader element decodes and launches a PE (Portable Executable) file in the background.

The resulting code is a variant of the XMRig Monero miner that siphons off the host’s CPU power. In many cases, the second-stage payload is a combo of the miner and penetration testing code called Metasploit. The latter can be used to access the compromised system remotely by establishing a reverse shell. Another serious concern is that such a mechanism of concealing harmful code inside any file format complicates detection as the underlying code manifests itself in memory only.

Trojanized WordPress Plugin Mining Coins

Phony website plugins are nothing new. They are increasingly used for backdoor access to a compromised server, and in some cases, their purpose is to encrypt the materials on a site and hold them for ransom. Experts from Sucuri, a company providing website protection and monitoring services, have recently stumbled upon an all-new use case. They discovered a fake WordPress plugin that promotes a cryptominer codenamed Multios.

The malicious plugin is a copy of “wpframework,” a WordPress component that hasn’t been updated for eight years. Although the original entity appears to be obsolete now in 2019, it is still being run on hundreds of sites based on the CMS in question. Therefore, numerous webmasters run the risk of unwittingly downloading the wrong variant of the plugin.

The perpetrators have added harmful functionality to the prototype, turning it into an instrument for unauthorized access to the admin dashboard. It additionally launches a Linux binary that sets cryptomining activity in motion. Considering this ongoing stratagem, the researchers recommend that WordPress site owners inspect their third-party plugins for suspicious activity.

Conclusion

Rogue cryptomining isn’t over. The cases above demonstrate that cybercriminals are evidently trying to think outside the box to get around the growingly effective detection techniques. The primary focus is on obfuscation of the malicious activity through the randomness of the mining process, fileless execution of the malware, and by masquerading the payloads as legit files.

Regardless of the tactics, all these attacks share the same telltale sign of exploitation: sluggish system performance due to the high consumption of the processing power. This symptom continues to be the main giveaway, and therefore users should keep tabs on their CPU usage to identify the compromise at its early stage and stop it in its tracks.

Rogue Cryptomining

David Balaban is a computer security researcher with over 15 years of experience in malware analysis and antivirus software evaluation. David runs the Privacy-PC.com project which presents expert opinions on contemporary information security matters, including social engineering, penetration testing, threat intelligence, online privacy, and white hat hacking. As part of his work at Privacy-PC, Mr. Balaban has interviewed security celebrities as Dave Kennedy, Jay Jacobs and Robert David Steele to get firsthand perspectives on hot InfoSec issues. David has a strong malware troubleshooting background, with the recent focus on ransomware countermeasures. 

 

Views expressed in this article are personal. CISO MAG does not endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Regulations for Air Transport May Prove Ineffective: Study

Airlines

A study by Queen Mary University of London’s Cloud Legal Project has stated that the cybersecurity strategies for air transport set by the NIS Directive of European Union might be ineffective against cyber risks and do not go far enough. The 2018 NIS Regulations which implemented the NIS Directive in the U.K. ensures the safety of operators of essential services against disruptions caused by cyber risks.

The researchers found that, to comply with the regulations, operators must identify, assess, and then address the cyber risks they face which often entails a level of subjective judgement and trade-offs. They stressed that the requirements of the Directive are too vague and open to interpretation. The flipside to this is that several airports and airlines may only put in place the security measures they deem commercially beneficial to them. They also pointed out that service providers may even abuse the directives by engaging in a malpractice called paper compliance, which basically means creating a massive trove of security documentation to show regulators without making actual changes to the cybersecurity infrastructure.

Another downside was that, with the NIS directives being so vague, it is difficult for regulatory bodies to effectively check and scrutinize whether the security requirements are being met. Dave Michels, Researcher at Queen Mary’s Centre for Commercial Law Studies and co-author of the paper, said, “Regulators will need to carefully monitor airports and airlines and challenge their approaches as necessary. This will require them to hire cybersecurity experts to do this effectively.”

Ian Walden, Professor of Information and Communications Law and co-author of the study, added, “Brexit may further complicate matters due to the UK’s departure from the European Agency for Cybersecurity, which plays an important role by providing guidelines for compliance and sharing best practices.”

The researchers focused on airports like Heathrow and airlines like British Airways, which were at the epicenter of major cyberattacks in the past.