Home Blog Page 244

Group-IB Finds Half a Million Credit Cards of Indian Banks on Darknet

BLAZINGSUN: A New Breach on Joker’s Stash Dark Web

Cybersecurity firm Group-IB recently detected a database containing over 460,000 payment card records of Indian banks on the darknet for sale. The database, named “INDIA-BIG-MIX (full name: [CC] INDIA-BIG-MIX (FRESH SNIFFED CVV) INDIA/EU/WORLD MIX, HIGH VALID 80-85%, uploaded 2020-02-05 NON-REFUNDABLE BASE”, was kept on “Joker’s Stash”, a dark web marketplace for trading stolen cards data.

While the source of the database remains unknown, Group-IB has notified Indian Computer Emergency Response Team (CERT-In) about the database leak. According to Group-IB, the database contains 461,976 payment records, card numbers, expiration dates, CVV/CVC codes, cardholders’ full name, email ID’s, contact details, phone numbers, and addresses. It’s estimated that the underground market value of these cards’ data would be more than US$ 4.2 million.

Dmitry Shestakov, Head of Group-IB cybercrime research unit, said, “In the current case, we are dealing with so-called fullz — they have info on card number, expiration date, CVV/CVC, cardholder name as well as some extra personal info. Such type of data is likely to have been compromised online — with the use of phishing, malware, or JS-sniffers — while in the previous case, we dealt with card dumps (the information contained in the card magnetic stripe), which can be stolen through the compromise of offline POS terminals, for example. We have shared all the information discovered with our colleagues to CERT-In.”

This is the second major leak of payment cards related to Indian banks detected by Group-IB.  In October 2019, Group-IB’s threat intelligence team uncovered a database holding over 1.3 million credit and debit card records of Indian banks’ customers uploaded to Joker’s Stash. The underground market value of the database was estimated at more than US$130 million.

Joker’s Stash – A Hacker’s Marketplace

There were multiple incidents where hackers traded stolen cards’ data on Joker’s Stash. Recently, threat intelligence firm Gemini Advisory revealed that hackers kept payment card details of Wawa’s customers on Joker’s Stash. In an official statement, Wawa confirmed that hackers tried to sell customers’ card information that breached in the security incident occurred on December 10, 2019. The data belonged to 30 million Americans and over one million foreigners from more than 100 different countries.

6.5 Million Israelis Voter Details Exposed using “View Source”

Israel

A simple yet critical coding flaw in Israel’s current ruling party’s election management application – Electoral, has exposed an entire Israeli voter database of 6,453,255 citizens. Ran Bar-Zik, a front-end developer of Verizon Media, was first tipped-off about this vulnerability by an unknown source who sent Bar-Zik his son’s personal details as proof. The exposed database includes information such as the full names, updated address, social security number, gender, and the ballot address and number. Details such as telephone numbers, father’s name, mother’s name and family connections were also available in the database.

According to Bar-Zik’s story published in Haaretz, Israeli political parties receive the voter registry including personal details of all the registered and eligible voters. Likud, the current ruling party in Israel uploaded this voter registry to its official election management application – Elector, which has been developed by a software firm Feed-b. Elector helps in sending latest news updates related to the elections and also enables the operators to send bulk messages to all the voters in its database. Feed-b played down the exposure by deeming it as a “one-off incident, which has been immediately dealt with,” however, it is unsure about the extent of the vulnerabilities’ exploitation and its corresponding time frame.

The “View Source” Hack

Talking about the hack, Bar-Zik said, “It’s amazing. It’s very simple and very stupid hack”. On Elector’s web application, Bar-Zik right-clicked and selected the “View Source” option. This option displays the HTML code used to develop the website. A file path labeled as “get-admin-users” was written within the code. He further copy-pasted this path as an extension into the URL bar of the browser. This led to a complete list of admins that was displayed on his screen, which included their usernames and passwords. Bar-Zik used a few credentials to check the authenticity and tried logging into the admin accounts. It did work as he received full access to the entire voter registry.

Upon discovery, as per the reporting data and privacy breach guidelines of Israel, Bar-Zik reported the issue to its developer in Feed-b and The Privacy Protection Authority in the Ministry of Justice.

Lessons Learnt

The entire Israeli voter details being exposed is really a big lapse and a confirmed failure in safeguarding the data privacy of its citizens, but it has surely given a few lessons for governments and organizations who are emphasizing on digital and cloud technologies.

Firstly, there was no other form of user authentication apart from the simple password authentication, not even a two-step verification procedure. Any sensitive or even basic data of users on cloud and physical drives should allow admin accounts access only with a two-step or multi-step verification process.

Secondly, Bar-Zik pointed out that he connected to the system using a VPN, which meant that the IP address was routed from outside Israel. Software companies having country-specific targets and users should restrict access of IPs and limit it to the home country only (i.e. Israel in this case).

Personal Data Protection Commission Fines Multiple Firms on Data Breaches

American Cybersecurity Literacy Act

The Personal Data Protection Commission (PDPC) of Singapore found seven organizations that violated the Personal Data Protection Act and has fined them a total of S$66,000 (approximately US$47,514). According to an official release, the penalties were issued to Singtel, SCAL Academy, SPH Magazines, and Royal Caribbean Cruises for failing to protect customers’ data.

Details of Penalties

Singtel

Singtel was fined S$9,000 (US$6479) for a data breach involving its ‘My Singtel’ mobile app. The breach occurred when the firm was migrating to a new billing system back in 2018 which resulted in the exposure of personal data of 750 mobile subscribers.

SPH Magazines

SPH Magazines, owned by Singapore Press Holdings, was fined S$26,000 (US$18,718) for a data leak of its forum site HardwareZone. According to a source, a hacker gained access to the system in 2017 and hacked in a senior moderator’s account and accessed information of 704,764 profiles.

Royal Caribbean Cruises

The cruise company was fined S$16,000 (US$11,518) for a ransomware attack on its vendor’s system that exposed personal data of 6,000 of its customers, including the personal data of its 25 employees. The incident occurred when hackers broke into the database of the receipt system and left a ransom note demanding a payment of 0.08 bitcoin for the data.

SCAL Academy

PDPC charged SCAL Academy with a fine S$15,000 (US$10798) for failing to protect the personal data of 3,628 people who had attended its programs. It’s claimed that the Academy failed to secure the scanned registration documents that held personal data like name, race, nationality, date of birth, identity card number, address, and company name of its attendees.

Besides imposing penalties, PDPC also imposed directives on Henry Park Primary School Parents’ Association for breaching the Protection and Accountability Obligations of the PDPA. Also, a warning was issued to NTUC Income and AXA Insurance for failing to maintain the necessary security requirements to prevent unauthorized disclosure of personal data they held.

New Bill Grants US$400 Million to Address Cybersecurity Risks in the U.S.

CISA VDP platform, U.S. export ban on cybersecurity items

A new federal legislation was introduced recently to address cybersecurity threats to information systems of state, local, and territorial governments in the U.S. The legislation, “the State and Local Cybersecurity Improvement Act”, will create a grant program worth US$400 million to finance cybersecurity improvement attempts in communities across the country. The legislation was introduced by a group of bipartisan representatives, Rep. Cedric Richmond, Rep. John Katko, Rep. Derek Kilmer, Rep. Michael McCaul, Rep. Dutch Ruppersberger, Rep. Bennie G. Thompson, and Rep. Mike Rogers, who are associated with the House Committee on Homeland Security.

According to an official statement, the funds will be provided to eligible communities by the Department of Homeland Security to assist in areas like vulnerability scanning and testing, cyber workforce development, and intelligence sharing.

Apart from cybersecurity funding, the bill requires DHS’ Cybersecurity and Infrastructure Security Agency (CISA) to develop strategies to improve the cybersecurity posture of the communities. It also establishes a state and local cybersecurity resiliency committee, giving state and local communities a venue to report their security needs to CISA.

Commenting on the newly released legislation, Congressman Cedric Richmond, Chairman of the Homeland Security Committee’s Cybersecurity, Infrastructure Protection, said, “The State and Local Cybersecurity Improvement Act is a critically important piece of legislation that provides state and local governments the tools they need to significantly invest in their cybersecurity infrastructure. Louisiana has long been vulnerable to cyber-attacks, and this bill offers the resources needed to ensure protection against potential threats. I’m proud to introduce this comprehensive measure to give Louisiana and other states across the country the proper framework they need to implement vital cybersecurity plans.”

Energy Sector Pathfinder

Recently, the U.S. Departments of Defense (DoD), Department of Energy (DoE), and Department of Homeland Security (DHS) joined hands to work on a new initiative “Energy Sector Pathfinder”, which was intended to protect the U.S. Energy Critical Infrastructure and bolster cybersecurity partnerships in the sector. The three federal departments signed a Memorandum of Understanding (MOU) to partner on the new initiative, which is aimed to improve training and education to understand cyber risks, advance information sharing, and develop joint operational preparedness and response activities to cybersecurity threats.

CryptoAG: The Swiss Spying Machine

Network Encryption, DSCI Whitepaper on Encryption

According to The Washington Post and German broadcaster ZDF, encryption device provider Crypto AG has been deemed as “The Swiss Spying Machine”, since for half a century it sold technology to nearly 120 countries while it was secretly controlled by the CIA and German intelligence services.

History of Crypto AG

The Swiss company, which was established during the World War II, manufactured encryption devices and machines that were sold to countries in the Latin American region including Brazil and Argentina, Asian rivals India and Pakistan, Iran , African countries of Egypt, Algeria, Libya, Morocco, Tunisia, Ethiopia, Ivory Coast, Nigeria, Tanzania, South Africa and even the Vatican.

Boris Hagelin, the founder of Crypto who had fled to U.S during the beginning of the Word War II, previously worked with the CIA and National Security Agency  (NSA). While nearing retirement, Hagelin put the company on sale. CIA and Germany’s spy agency BND, in a bid to keep their upper hand in the encryption technology and in order to decode other countries’ secrets during the rising geopolitical tensions of the Cold War, showed keen interest in buying the company’s stakes.

Thus, CryptoAG was secretly bought by a Liechtenstein front company (in future known as the SIEMENS group) that was owned 50-50 by the CIA and Germany’s BND for US$8.5 million. The two nations agreed to let the Swiss spies know this little secret, while only a few from the top Crypto AG management knew about it. Both U.S. and Germany asked for an intentional weakening of its encryption products sold to other nations, this meant that whenever required, they could break the encryption algorithms and intersect secret communications of these countries.

The Suspicious Success of the Swiss Spying Machine

One such example is when U.S. and Germany were able to intersect the communication where the Libyan officials were heard celebrating after terrorists exploded a bomb in a Berlin nightclub in 1984. As this ownership of CIA was a top secret, even the then President of the U.S., Ronald Reagan had no idea about it as he was publicly quoted suspecting the Crypto AG’s involvement in this incident. But these suspicions were never confirmed.

However, Crypto AG’s products are still in use in at least a dozen countries around the world, which means secrets of these nations could still be monitored. But the company was dismembered in 2018 and liquidated by its shareholders whose identities have been permanently protected under the byzantine laws of Liechtenstein, a tiny European nation with a reputation of high financial secrecy.

Deep Instinct Raises US$43 Million in Late-Stage Funding

Startup funding

New York-based cybersecurity firm Deep Instinct, with offices in Tel Aviv and Sydney, raised US$43 million in late-stage funding. The funding round was led by Millennium New Horizons, with participation from online trading and technology firms Unbound, LG, and Nvidia. With the current funding, the company has seen an investment of US$100 million.

The company plans on going on an expansion spree with the new funding. Deep Instinct now counts the largest technology companies in the world among its investors. These include LG, Nvidia, and even HP and Samsung, who had participated in previous financing rounds of the company.

“This significant round of new funding highlights the importance of prevention for every enterprise. The economic impact of repairing a breach is too high to ignore the need to prevent threats before they occur. The message to the market is that to fight today’s cyber threats, true prevention will become more critical than detection and response.” said Lane Bess, Deep Instinct’s Chairman, in a release.

The company has a patented technology that disrupts traditional security solutions. Unlike traditional solutions, which guard enterprises against known threats in operating systems (OS) and help identify the attack after it has been breached, Deep Instinct leverages its patented deep learning platform trained to identify and prevent first-seen, sophisticated and advanced cyberthreats. The company affirms that threats are prevented anywhere within the enterprise from any type of file-based or file-less cyberattacks in zero-time, with unmatched accuracy and speed.

“Traditional cybersecurity is broken,” said Guy Caspi, co-founder and CEO of Deep Instinct. “Current solutions based on ‘assume breach’ are simply insufficient for the highly sophisticated attack landscape we all face. Deep Instinct takes an entirely new approach, preventing attacks before they are executed.”

“There is no shortage of cybersecurity software providers, yet no company aside from Deep Instinct has figured out how to apply deep learning to automate malware analysis,” said Ray Cheng, Partner at Millennium New Horizons. “What excites us most about Deep Instinct is its proven ability to use its proprietary neural network to effectively detect viruses and malware no other software can catch. That genuine protection in an age of escalating threats, without the need of exorbitantly expensive or complicated systems, is a paradigm change.”

Fake Dating Apps Bring Majority of Malware Attacks in South Africa

Dating Apps

South Africa is one of the most malware attacked countries via fake dating applications, a research from Kaspersky revealed. According to research findings, 7,734 attacks were detected on 2,548 users in 2019. The country saw a circulation of 1,486 malware threats disguised as over 20 popular dating apps. It’s said that South Africa is the most targeted country by fake dating apps accounting to 58 percent, while Kenya reported 10 percent and Nigeria 4 percent.

The research highlighted that hackers used popular dating apps like Tinder, Bumble, and Zoosk as bait to spread malware and access personal data. Cybercriminals used the Tinder app to cover their malware files, with 493 files detected only in South Africa. Once infected, the malware brings a variety of issues.

“The danger these malicious files bring varies from file to file, ranging from Trojans that can download other malware to ones that send an expensive SMS, to adware, making it likely that every ping a user gets is some sort of annoying ad notification rather than a message from a potential date,” the researchers explained.

Kaspersky also recommended a few guidelines to avoid threats from fake apps:

  • Always check application permissions to see what your installed apps are allowed to do
  • Do not install applications from untrusted sources, even if they are actively advertised, and block the installation of programs from unknown sources in your smartphone’s settings
  • Find more information about the dating website you are planning to visit, look into its reputation on the internet and try to find user feedback
  • Use a reliable security software that delivers advanced protection

Vladimir Kuskov, head of advanced threat research at Kaspersky, advised users to download only legal versions of applications from official application stores. Kuskov also stressed, “Online dating has made our lives easier and yet uncovered new risks on the path to love. We advise users to stay attentive and use legal versions of applications that are available in official application stores. And, of course, we wish you best of luck finding the perfect date for this special day.”

Security Incidents from Dating Apps  

Dating apps were used to infiltrate smartphones used by military personnel. Earlier, Hackers honeytrapped the U.K.’s Royal Air Force (RAF) personnel by hijacking an RAF airwoman’s Tinder profile and reaching out to another RAF serviceman to get details of the F-35 stealth fighter from him. The source of the hack remains unknown but comes amid concerns of China and Russia staging state-sponsored attacks.

In a similar incident, Palestinian Sunni-Islamist fundamentalist organization Hamas was accused by the Israel army’s intelligence directorate for building fake dating and FIFA World Cup 2018 applications to entice soldiers into downloading malware on to their mobile phones, with intentions to gather sensitive information about the military activities around Gaza strip.

Cybersecurity Startup spiderSilk Secures US$500,000 in Seed Funding

Axonius Raises US$58 Million to Accelerate its Security Management Tool

spiderSilk, a Dubai-based cybersecurity startup specialized in helping organizations design their cybersecurity defenses by providing offensive cyberattack simulations, raised US$500,000 in its seed funding round. The seed round was led by a UAE-based venture capital firm Global Ventures and included a few other co-investors like Magnus Olsson, co-founder of Careem, FutureTech and Xische Ventures.

Co-founded in 2019 by Mossab Hussein, an ex-product manager at Careem, and Rami El Malak, spiderSilk was founded with the aim of protecting organizations against constant cyberthreats, especially in the currently tensed geopolitical environment. The company focuses on finding vulnerabilities and loopholes in applications within the public as well as private infrastructure domains. spiderSilk simulates cyberattacks and then sends reports to its clients based on this simulation to safeguard their business networks and systems.

The cybersecurity startup came into the limelight when it first found vulnerabilities in WeWork’s GitHub repository that was leaking confidential contracts and customer data. In the subsequent months, spiderSilk’s team also exposed a database on MoviePass’ subdomains that listed the personal details of their customers along with respective credit/debit card numbers.

spiderSilk’s proprietary machine-driven technology has without notice already had a humongous impact on humankind as it has detected threats that would have potentially impacted around 120 million people to date. Owing to this revolutionary technology, it has garnered successful collaborations and clientele, which includes the likes of Samsung, Huawei, EA Games, Navblue and WeWork.

When asked about Global Ventures’ interest in the seed funding of the cybersecurity startup, Noor Sweid, General Partner at Global Ventures, said, “The company has already onboarded a list of regional and international clients such as the Ministry of Justice in KSA, Dubai Police, the UAE Government Office,  Huawei, and a large data analytics company in the U.S., amongst others. This truly illustrates spiderSilk’s ability to scale not only regionally, but also internationally. Thus, we look forward to working closely with the founders to enable the Company to scale its true potential.”

Miami Beach Police Department Suffers Ransomware Attack

Ransomware Attack on Azusa Police

The North Miami Beach Police Department was recently attacked in a ransomware campaign that encrypted files on the police computer networks. The department immediately took down the affected computers and alerted the FBI, the U.S. Secret Service, and the Miami-Dade Police Department to investigate the issue. However, the police officials noted that there was no interruption in public safety services post the attack.

The officials stated that attackers demanded millions of dollars in ransom to restore access to their network systems. The department has not revealed any information on the identity of the attacker group and about what information was compromised in the incident.

In an official statement, the City of North Miami Beach said, “We continue to work closely with these federal partners, as well as the county police department and a third-party forensic investigator, to determine the extent and objectives of the attack and how best to address it. The City of North Miami Beach’s investigation will include an analysis to determine whether any resident’s, employee’s, or vendor’s personal information may have been subject to unauthorized access or acquisition.”

“The City of North Miami Beach takes this attack seriously, and is determined to take all steps necessary to protect itself and its citizens from those who would do them harm. No other information will be released at this time,” the statement added.

Multiple cities in the U.S. have fallen victim to ransomware attacks over the past couple of years and incurred huge data and money losses in ransom demands. Earlier, NYPD’s fingerprint database was shut down for a few hours, when an accidental ransomware infection which affected nearly 23 machines linked to the department’s LiveScan fingerprint-tracking system. The incident occurred at the Police Academy in Queens when a third-party contractor was setting up a digital display system. As soon as the contractor connected the already infected NUC mini-PC to the police network, the virus attached itself to the system.

Hackers Target Supply Chain Companies with “Kwampirs” Malware

Rootkits, Mobile Malware in Asia

The FBI recently gave a security warning to private organizations in the U.S. about an ongoing hacking campaign targeting software supply chain companies. It’s said that attackers are targeting companies with a remote access trojan (RAT) malware tracked as “Kwampirs”, according to a source.

“Software supply chain companies are believed to be targeted in order to gain access to the victim’s strategic partners and customers, including entities supporting Industrial Control Systems (ICS) for global energy generation, transmission, and distribution,” the FBI said in a media statement.

Kwampirs Malware

Apart from attacks on supply chain software providers, hackers also deployed Kwampirs malware in attacks against companies in the health care, energy, and financial sectors. The FBI alert didn’t mention the targeted software providers or any other victims of Kwampirs malware. However, it shared IOCs (indicators of compromise) and YARA rules so that companies can scan their networks for signs of the Kwampirs malware used in the recent attacks. The FBI urged organizations to scan their networks for any signs of the Kwampirs malware and report if they find any. Kwampirs malware was first discovered by Symantec in April 2018. It’s said that a hacking group named Orangeworm used Kwampirs to attack the health care, pharmaceutical, IT, manufacturing, agriculture, and logistics companies.

Updated Version of Shamoon Malware

The FBI claims that Kwampirs malware has numerous similarities with “Shamoon”, a data-wiping malware developed by the APT33 hacking group. Once injected, Shamoon malware destroys data, disrupts operations, and can lead to hijacking an organization’s network.

The agency also stated that attacks which employ Kwampirs have now targeted companies in the ICS (Industrial Control Systems) sector. The FBI said, “While the Kwampirs RAT has not been observed incorporating a wiper component, comparative forensic analysis has revealed the Kwampirs RAT as having numerous similarities with the data destruction malware Disttrack, commonly known as Shamoon.”