Home Blog Page 252

Mitsubishi Electric Reveals Data Breach, Suspects Tick Hacking Group

Mitsubishi Electric Reveals Data Breach, Suspects Tick Hacking Group

Japanese electronics manufacturer Mitsubishi Electric recently confirmed that it was hit by a cyberattack in June 2019. The Tokyo-based firm released a notice detailing the data leak in the wake of two news stories published recently by Asahi Shimbun and Nikkei.

Who’s the Culprit?

The sources claimed that the Chinese hacking group tracked as Tick was likely behind the attack. It’s said that Tick has been active for a long time and is known for stealing sensitive data from the defense, aerospace, chemical, and satellite industries in Japan and China.

The unauthorized access began with compromising computer systems in Mitsubishi’s office located in China, and spread to Japan. The attackers used the compromised accounts to infiltrate into the company’s internal network and gained access to server systems that had sensitive information.

Massive Information Leak

According to the internal investigation, which began in September 2019, the security incident compromised the information of Mitsubishi’s public and private business partners, defense-related details, and data on critical social infrastructure like electricity and railways. It’s believed that intruders managed to access computers, servers, and company sites, including details on the company’s joint projects, negotiations, research documents, and data of government organizations like Defense Ministry, the Nuclear Regulation Authority, and the Agency for Natural Resources and Energy.

Past Incidents

The government entities and businesses in Japan faced multiple security incidents in recent times.

Earlier this month, the authorities of the Tokyo 2020 Summer Olympics issued a warning about an ongoing phishing campaign. It’s said that the suspicious emails were designed to look like they’re coming from the Tokyo Organizing Committee of the Olympic and Paralympic Games 2020.

The authorities stated that the phishing emails redirect the recipients to fake websites or infect their computer systems with malware if opened. The international multi-sport event is scheduled between July 24 and August 9, 2020, in Tokyo.

“We have detected emails disguised to look like they are coming from a Tokyo 2020 staff member. Although the email may look official and legitimate, if you have no reason to receive such an email or if the content is questionable, you should not click on the link or open any attached files. It is highly likely that you would be directed to a phishing site or your computer would be exposed to a virus,” the authorities said in an official statement.

FireEye Acquires Cloud Security Startup Cloudvisory

FireEye Acquires Respond Software

Cybersecurity firm FireEye has acquired cloud security startup Cloudvisory to advance its cloud-hosted security operations.

FireEye caters to enterprises and helps businesses thwart cyberattacks. With the addition of Cloudvisory, FireEye will provide customers a single operations platform to monitor multi-cloud environments, hybrid-cloud firewalls, and integrate container security.

Commenting on the acquisition, Grady Summers, Executive Vice President of Products and Customer Success at FireEye, said, “Customers need consistent visibility across their public and hybrid cloud environments, as well as containerized workloads. Cloudvisory delivers this visibility and allows FireEye to apply controls and best practices based on our frontline knowledge of how attackers operate. Security is top of mind for almost all organizations as they migrate critical workloads to the cloud. With the addition of the Cloudvisory technology, FireEye is able to offer a comprehensive, intelligence-led solution to secure today’s hybrid, multi-platform environments.”

Last year, FireEye discovered an undetected hacker group from Iran which managed to steal travel and mobile data of individuals in the Middle East region. The Iranian group dubbed APT39 targeted several people in the Middle East, especially in the Gulf region. It’s believed that the espionage group is allegedly providing information to the Iranian government. The researchers at FireEye stated that they’ve tracked APT39 activities since 2014 to protect organizations from cyber incidents.

The researchers said the group used phishing emails that target specific people and include malicious attachments or links resulting in a POWBAT infection. FireEye also observed that the group uses Persian language words in encrypting data. APT39’s activities are reportedly focused on the telecommunications sector, the travel, and the IT industry, and allegedly represent Iran’s potential global operational reach and how it collects key data.

16Shop Phishing Kit Extends Attack Portfolio to PayPal

xss vulnerability in UPS, Phishing Attack, spear phishing, phishing mails

In early January 2020, ZeroFOX’s research team, Alpha, discovered a phishing kit targeted towards PayPal customers, which had signatures of 16Shop written all over its code. Active since 2018, 16Shop is a Malware-as-a-Service (MaaS) phishing kit that is developed by a hacking group called the Indonesian Cyber Army. After targeting Apple and Amazon customers in 2019, the hacking group has now modified the kit to target PayPal and certain American Express customers as well.

On further analysis, researchers found that the latest versions of 16Shop phishing kit contained three anti-bot and anti-indexing features that worked as an anti-detection mechanism. The first is a simple blacklist file blacklist.dat. The second mechanism uses an open-source anti-crawling library called CrawlerDetect. Finally, the third one employs an integration with antibot.pw.

Depending on the target company (like Apple, Amazon, PayPal, American Express) 16Shop provides attackers options to choose from. Every phishing kit is target specific and different from the other. Each kit comes with a deployment quota for every customer. It is controlled from the 16Shop’s Digital Rights Management (DRM) system. On reaching the optimum number of deployments, 16Shop shuts shop. It operates only when the attacker (operator) pays for additional deployments.

16Shop also has a very user-friendly, intuitive and real-time updating dashboard that allows the user to see the login credentials, email addresses, credit card details, bots or clicks, collected by the phishing kit deployments.  The research also noted that stolen information is exfiltrated via an SMTP to an attacker-controlled email inbox. 16Shop phishing kits extract as much data possible inclusive of country-specific PII data.

Earlier, McAfee had discovered the first version of 16Shop phishing kit in July 2019 targeted at Amazon just before its Prime Day sale. The victims received an email with a pdf file attachment that looked like an original email alert from Apple, Amazon, or any other tech company. Once the user clicked on the link in the attached pdf file, they were redirected to a fake site where user was asked to enter sensitive information like bank account number, debit, and credit card details which were further used for financial frauds.

Cyberattacks on Downtrend in Malaysia in Q4 2019: Kaspersky

Cyberattacks on Downtrend in Malaysia in Q4 2019: Kaspersky

Kaspersky unveiled that cyberattacks in Malaysia came down in the fourth quarter of 2019.

In its security bulletin, Kaspersky stated that it detected 11,544,340 potential threats on the systems of Kaspersky Security Network (KSN) participants in Malaysia, from October to December 2019. The threat incidents decreased to 5,658,973 from 9,840,870 compared to 2018.

The bulletin highlighted that nearly 31.9 percent of  Malaysian systems were infected by malware, which was distributed via removable USB drives, CDs and DVDs, and other offline methods.

Describing the scenario, Yeo Siang Tiong, Kaspersky GM for South-East Asia, said, “It is important that everyone works together to bolster our defenses against common threats. No one knows when the next threat will appear. Keep your system intelligent and up to date with the latest cyber-security trends so that you are ready and prepared for sophisticated cyberattacks. Cybersecurity is not a boring subject to discuss with your employees, friends and families, because simple habits can greatly boost your enterprise and personal defenses against potential cyber threats.”

In order to prevent evolving threats, Kaspersky urged organizations to conduct cybersecurity training to its employees, including good password habits at workplace and running up-to-date anti-malware programs.

“Set up tiered levels of access, giving permission only to those who need it on each level and incorporate global threat feeds into their systems which can provide in-depth visibility into cyber threats targeting organizations,” Kaspersky said.

Earlier, in similar research, Kaspersky revealed that the number of Distributed Denial of Service (DDoS) attacks increased by 84 percent in the Q1 of 2019, compared to Q4 of 2018. In its research report, it stated that cybercriminals turned to DDoS attacks after a sustained time period.

The report also revealed that Kaspersky discovered a considerable growth in the number of attacks that lasted more than an hour. According to the research findings, China reported the highest number of DDoS attacks (67 percent) while the U.S. reported the second-largest attacks (17.17 percent), and Hong Kong stood third (4.81 percent).

Kroll Acquires RP Digital Security, Fortifies Asia Pacific Operations

Acquisition

In one of the most strategic acquisitions in the Asia Pacific (APAC) region, Kroll, a global risk solutions provider based in New York, has acquired a Singapore-headquartered cybersecurity firm, RP Digital Security (RP-DS). This is a strategic move from Kroll’s viewpoint since RP-DS has offices and clientele in Singapore, Hong Kong, and Indonesia. The latest acquisition would strengthen Kroll’s foothold in the APAC region. RP Digital Security’s founder Rob Phillips would take over as an Associate Managing Director (AMD) of Kroll’s APAC Cyber Risk team.

Kroll, a division of Duff & Phelps, is a global solutions provider in investigations, risk mitigation, cybersecurity, incident response, and compliance solutions. It has a strong workforce of more than 3,500 employees based in 70 locations across the globe. Kroll mainly provided solutions in the U.S. and U.K. markets, however, a sudden rise in cyberattacks in Asia lead the company to venture into the APAC region.

RP Digital Security was founded in Singapore back in 2004. Its clientele has some of the biggest law firms, financial institutions and insurance companies located in and around Singapore, Hong Kong, and Indonesia. The company provides cybersecurity and computer forensic expertise for data breach, ransomware, email scams, and insider threat investigations.

Jason Smolanoff, Kroll’s global practice leader said, “It’s important for organizations to build resiliency against attacks, including a robust incident response plan and preparedness, ahead of a breach.”

Commenting on cyberthreats, Phillips said,  “As organizations throughout APAC see increased exposure to cyberthreats while facing stricter legal requirements around data protection, it is important for companies to have a robust system in place.”

Kroll also recently expanded its fraud and financial investigation expertise by onboarding Sherine Ebadi who joined the firm as an Associate Managing Director in the Business Intelligence and Investigations practice, based in Los Angeles. Ebadi previously served for 10 years as a special agent of the FBI. She is a decorated officer and has solved many high-profile cases involving embezzlement, public corruption, international bank fraud, money laundering, securities fraud, organized crime, and identity theft. To name a few Ebadi has also been recognized with the FBI Medal of Excellence, the FBI Excellent Performance Award and the U.S. Attorney’s Award.

Cybersecurity Startup Exits in Israel Total to US$11.3 billion: IVC Report

Israel cybersecurity startup

As per the IVC Research Center report, Israel has 436 cybersecurity companies operating across various verticals of development. IVC Research Center is a specialized entity that closely monitors the progress and development of Israel’s tech industry.

Another supporting report published in the IVC Magazine’s September 2019 issue, covers the exits of Israel’s cybersecurity startups within a timeframe of 2013 to 2019. Cybersecurity exits, in other words, means the number of merger and acquisition deals and initial public offerings of shares. This cybersecurity exit totaled to US$11.3 billion for the recorded time span. The growth in the exits in the cybersecurity industry can be gauged from the fact that there were just three exits in 2013, which accounted to US$747 million, whereas, in 2019  saw a record of 23 exits that totaled to US$3.46 billion.

The exit costing has increased exponentially and so is the funding for Israeli cybersecurity companies during the same time period. Israeli cybersecurity startups have managed to attract funding of US$6.32 billion from investors across 594 deals. In 2013, the cybersecurity companies raised a total funding of US$240 million in 52 deals, whereas the number increased nearly six times by 2019 to US$1.88 billion in 75 deals, indicating the constant growth of capital in the subsequent funding rounds. This dollar amount raised is the highest for the 2013–2019 time period.

IVC’s top three cybersecurity exits in the past five years include:

Tel Aviv has been touted as the cradle of cybersecurity startups and the scale at which the cybersecurity conference “Cybertech 2020” has been organized seconds this information. At the end of the month, Israel’s Prime Minister Benjamin Netanyahu will address the audience in this conference. Companies and the Government of Israel along with delegations from the U.S., India, Germany, Spain, the U.K. and Japan shall actively participate and exchange notes on the cybersecurity front. Cybercrimes, incident response and real-life hacking simulations across different domains such as financial, communications and medical sectors are going to be focused upon.

This will also be a good opportunity for companies and organizations, including Israel’s Mossad intelligence agency, the Israel Police, Check Point Software Technologies, CyberArk, IBM, Microsoft, FireEye and Elbit Systems, to showcase their cybersecurity services and product offerings.

Microsoft Confirms Security Flaw in Internet Explorer

Brand Phishing Attacks

Microsoft announced that it’s developing a fix for a zero-day vulnerability in Internet Explorer that was exploited by a hacking group named DarkHotel. The vulnerability, tracked as CVE-2020-0674 and defined as a memory corruption issue, impacts the scripting engine in Internet Explorer version 9, 10, and 11 when running on Windows 7, 8.1, 10, Server 2008, Server 2012, Server 2016, and Server 2019.

Microsoft stated that attackers can exploit the flaw to launch remote code execution on the targeted device by tricking a user into clicking a malicious website or a link sent via email. The tech giant released a security advisory, named ADV200001, which includes mitigations to apply in order to protect vulnerable systems from threats.

In its advisory, Microsoft explained, “A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs, view, change, delete data or create new accounts with full user rights.”

Recently, Microsoft seized 50 domains operated by North Korean hacking group called Thallium. The tech giant stated that attackers used these domains to launch cyberattacks on different locations including theU.S., Japan, and South Korea.

The news came to light when Microsoft filed a lawsuit against Thallium in the U.S. District Court for the Eastern District of Virginia. The U.S. authorities ordered Microsoft to take control of the 50 domains that Thallium was using to perform their operations, as a result, these sites can no longer be used to execute any attack.

Microsoft said its Digital Crimes Unit (DCU) and the Microsoft Threat Intelligence Center (MSTIC) have been tracking Thallium for months and have been gathering information on its operations. These domains were used to send out phishing emails containing a malicious link, a method known as spear-phishing that typically tricks the victims to click and enter their details in a self-hosted page, which are then stored in a hacker database.

U.K. Invests in Revolutionary Artificial Intelligence Warships

Cyber war

With an aim to help warship crews make quick decisions and process data efficiently, the U.K.’s Ministry of Defense recently announced contracts to use AI-based (artificial intelligence) technology in warships.

According to a source, Defense and Security Accelerator (DASA) will be funding £1 million (around US$1.3 million) for AI contracts as part of its “Intelligent Ship – The Next Generation” competition, which is aimed at using innovative approaches for Human-AI and AI-AI teaming for various defense platforms like warships, aircraft, and land vehicles.

James Heappey, U.K.’s Defense Minister, said, “The astonishing pace at which global threats are evolving requires new approaches and fresh thinking to the way we develop our ideas and technology. The funding will research pioneering projects into how AI and automation can support our armed forces in their essential day-to-day work.”

DASA’s warship competition, in alliance with the Defense Science and Technology Laboratory (Dstl), is intended to enhance the designs of future defense platforms by using advances in automation, autonomy, machine learning, and AI.

Julia Tagg, technical lead from Dstl, said, “This DASA competition has the potential to lead the transformation of our defense platforms, leading to a sea change in the relationships between AI and human teams. This will ensure U.K. defense remains an effective, capable force for good in a rapidly changing technological landscape.”

“Crews are already facing information overload with thousands of sources of data, intelligence, and information. By harnessing automation, autonomy, machine learning and artificial intelligence with the real-life skill and experience of our men and women, we can revolutionize the way future fleets are put together and operate to keep the U.K. safe,” Tagg added.

Last year, the governments of the U.K. and Singapore joined hands to promote user “Security by Default” in both countries. According to an official report, the Chief Executive of the U.K.’s National Cyber Security Centre, Ciaran Martin, and Chief Executive of Singapore’s Cyber Security Agency, David Koh, signed a joint statement on cooperation between Singapore and the U.K. on Internet of Things.

Both countries have agreed to work together on areas of common interest, including alignment, cooperation, and coordination to support the cause. The Singapore-U.K. strategic alliance is intended to drive improvements in the security of smart consumer devices.  The agreement also accelerates the IoT industry to grow and innovate.

Hanna Andersson Hacked; Customer Credit Card Details Compromised

Ask Yourself These 4 Questions Before Shopping Online

U.S. kids’ wear brand Hanna Anderson’s online purchase platform was hacked during the holiday season of December 2019. The attackers stole the credit card details including customer name, payment card number, CVV code, expiration date along with billing and shipping address of its customers from the checkout and payment page of the online portal.

An email sent by Hanna Andersson to its customers stated that, on December 5, 2019, law enforcement authority informed the retail giant about credit cards used on its website being sold on the dark web. The IT department responded quickly to this intimation and assembled a cyber forensic team to investigate the breach.

The cyber forensic team’s investigation confirmed that Hanna Andersson’s “third-party eCommerce platform, Salesforce Commerce Cloud, was infected with malware that may have scraped information entered by customers into the platform during the purchase process. The earliest potential date of compromise identified by the (cyber) forensics investigators is September 16, 2019, and the malware was removed on November 11, 2019.”

However, the investigators were not able to determine the exact number of compromised details. Therefore, as a precautionary measure, Hanna Andersson decided to inform all its customers about the breach, who purchased goods from the online portal during the reported time period.

Hanna Andersson confirmed that it is fully cooperating with the law enforcement department and payment card companies in further investigating the incident. The retailer has taken required steps to re-secure the third-party online purchase platform.

This attack is similar to the Magecart attack faced by Macy’s, an American department store chain, in October 2019. The retailer stated that unknown intruders planted a card-stealing malware script on its payment site and collected customer details.

According to a press release, the attackers installed a Magecart script on the checkout page of its website and siphoned off customers’ payment card details between October 7 and October 15, 2019. “The unauthorized code was highly specific and only allowed the third-party to capture information submitted by customers on macys.com and the checkout page – if  ‘place order’  button was hit after entering the credit card data, and the wallet page was accessed through My Account. Our teams successfully removed the unauthorized code on October 15, 2019,” the statement added.

Macy’s clarified that the attack only affected its webpage users and not the users who made purchases using its mobile application. Security experts opined that the attack appears to be a Magecart operation.