Home Blog Page 261

Securing the Hybrid Cloud Environment: A New Paradigm Using Zero Trust

Cloud Forensics

By Peter Smith, CEO and Co-founder, Edgewise

It’s clear the future of IT lies in hybrid cloud, thanks to its ability to increase an organization’s scalability, agility and cost savings. According to a recent survey from Microsoft, two-thirds of enterprises already use hybrid cloud, more than half of these just deployed in the past two years. What’s more, this growth isn’t anywhere near finished. Analysts expect spending on hybrid cloud will grow more than 300% from 2017 to 2023, topping $138 billion.

Digital transformation will help a business to discover new ways of engaging with customers, create a smarter enterprise, and define new business models. Significantly, the nature of digital technologies allows it to deliver different outcomes for different business functions. For example, the CIO gains from increased speed and agility of the IT environment, the CMO can orchestrate campaigns better and acquire more customers, the CSO can now have a scalable and predictive engine and forecast more accurately, the CFO benefits from reduced costs, increased revenues and profits, while the CHRO enjoys improved employee experience and engagement. Undoubtedly, digital technologies CIOs now see the cloud as potentially more secure than their own environments, thanks to the massive resources and expertise cloud providers are able to dedicate to cybersecurity.

While security used to be a primary concern preventing enterprises from using the cloud, that thinking has shifted dramatically.That doesn’t let the enterprise off of the security hook, however. Cloud providers secure their own infrastructure, but it’s still up to the customer to lock down access to data stores (e.g., S3 buckets) and workloads. That’s no simple task. Each cloud operates differently, so as additional environments are added, the level of management complexity increases exponentially for network and security teams. And as complexity grows, so does the likelihood of misconfigurations and other errors leaving a cloud environment vulnerable to attack. Even worse, the tools security teams use to protect their on-premises data centers aren’t well suited to the autoscaling environments of the cloud.

The best way to cut through all of the multi-cloud complexity is to adopt a security model that operates independent of the environment. And a good place to start is the data, which, let’s face it, is the asset that bad actors are almost always targeting. Here are five capabilities to make sure you have in order to secure your hybrid cloud environment from attacks.

Access controls

Preventing unauthorized access to data is clearly critical for cloud security, but it’s not sufficient. Limiting access to authorized apps and users is a necessary start, but sophisticated attacks will use stolen credentials or even piggyback on authorized communication paths to reach their target. More is required to protect data-rich applications and services inside hybrid cloud networks.

For example, software, devices, hosts and servers all require access to other network assets, but it’s easy for malware to exploit these communication pathways to propagate laterally across the network. So instead of relying on “trusted” network connections, security controls need to allow access after verifying the identity of software and services — a core tenet of zero trust networking. Additionally, prior authorization should not be used to grant new access; it must be iterative and awarded on a least-privilege basis.

One of the big advantages of basing access on identity is that it can operate independently of the underlying network. That’s especially important in autoscaling environments like the cloud, where addresses change constantly.

Asset inventory

It’s impossible to protect data or systems if your security team is unaware that they exist, and in today’s sprawling networks across multiple environments, it’s easy for even important assets to be overlooked. Security tools must have the ability to provide a current inventory of all assets and data. Doing this manually is far too time-consuming and error-prone, so tools should automatically discover and update the asset inventory.

Automation

This leads to our next capability, because discovering and mapping the environment is certainly not the only security function that’s too complex to handle manually. Automate low-level tasks to free up security teams’ time so they can focus on critical, strategic initiatives. Rote and routine processes are important, but they are best performed by algorithms, which can complete them faster and more accurately.

Segmentation/ microsegmentation

Flat networks are fast and easy to use, but these benefits don’t just apply to users — attackers take advantage of them as well. Instead, the network needs to be segmented into much smaller “secure zones” governed by policies that allow only those applications, devices and users to access them. In this way, we move security much closer to the assets we want to protect.

In a microsegmented, zero trust environment, all network traffic is assumed to be hostile and so the identities of workloads are verified before they are allowed to communicate. The traditional model of a hard shell just won’t work in a threat landscape where hundreds of thousands of new malware files emerge on a daily basis. Eventually, something will penetrate the perimeter and, if the interior isn’t hardened, malware has free rein to do as it likes, moving across the network until it can access the data it’s seeking.

Patching

Every security professional knows how important keeping devices and applications up-to-date is to an organization’s security posture. However, sometimes circumstances require delaying the deployment of a new patch. Still, even though it might not always be possible to do so immediately, the security team has to know when assets are out of date. At the very least, security can update policies to strictly limit communications to unpatched software or devices.

A Time for Change

The hybrid-cloud landscape presents some tricky challenges when it comes to security. Their autoscaling nature alone means many of the tools and methods that security teams are accustomed to using no longer apply. A new security paradigm is required that replaces the “hard shell / soft center” approach with one that moves security close to the data that needs protection by microsegmenting the environment, adopting a leastprivilege access model and basing authorization on immutable identity of the communicating workloads.

This is a tall order, and frankly, would not have been feasible even just a few years ago. But with the help of AI, machine learning and automation, cloud security is now within reach of any organization. And given how dangerous the threat environment is — and it’s getting worse all the time — this change is overdue.

Disclaimer: CISO MAG does not endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. Views expressed in this article are personal.

SmartMetric Biometric Payment Cards Now Have Over 9 years Battery Life

one million card data exposed

With security being top priority especially in the age where card skimming activities are alarmingly rising, SmartMetric Inc., a fingerprint-based biometric credit and debit cards manufacturer, said that they have now got a breakthrough in increasing the payment cards’ fingerprint scanners battery shelf life to more than nine years.

Based on the hype created a few years ago by popular mobile manufacturing companies that even day-to-day payments will only be done on smartphones, it was being said that the end of plastic credit and debit cards is near. This has of course not happened, but a rather reverse trend is observed.

As per EMVCo’s report, the world total of chip based (EMV) credit and debit cards topped at more than 8.2 billion cards for the year 2018. The highest number of cards being deployed was in the APAC (5,001 million) region, but Africa and the Middle East saw the highest EMV card adoption rate at 87.8 percent. This is a clear indication that not just the U.S. or Europe but around the globe, making payments using payment cards is not going out of fashion anytime soon.

The trend also calls for more secure features over relying on chip based EMV encrypted transactions. Fingerprint based biometric credit and debit cards might just be the answer to this.

What is SmartMetric Biometric Credit and Debit Cards?

It is a proprietary product of SmartMetric that has a fully functional fingerprint scanner integrated within the credit and debit cards. Once the authorized card user receives this card, it barely takes 5 seconds to register the personal fingerprint. Four taps on the fingerprint scanner and the card stores the user’s fingerprint within the card’s database. Next time onwards, whenever the user taps on fingerprint sensor on the card’s surface, within a quarter of a second (0.25 second) the pre-stored fingerprint is matched against the card user’s fingerprint with the help of a processor and an operating system which is also integrated within the payment card.

Earlier, during a presentation in Madrid, Chaya Hendrick, President and CEO of SmartMetric said, “Adoption of the ADVANTIS chip and operating system into our advanced biometric secured credit and debit card allows our biometric card solution to be issued by some of the World’s largest banking groups throughout the world.”

The card has underwent rigorous testing and development. Tests in July this year showed a certain shortcoming when it came to the battery life of the fingerprint scanner which were being worked upon. Finally, SmartMetric has cracked the code. It announced that its biometric credit and debit card has a battery shelf life of over nine years. The card’s biometric fingerprint sensor and internal processor powers on automatically as soon as the card holder touches the card’s fingerprint sensor on the card’s surface.

“This means the card can stay unused by a user for a long time and when they go to use the card it will power up immediately; the user simply touches the card’s sensor,” said Chaya.

The card’s internal biometric scanner is powered by a rechargeable ultra-thin wafer like battery. The battery is recharged every time the card holder uses the card in a vendor’s payment card reader or ATM or also in contactless readers used to read contactless credit and debit cards. SmartMetric has also managed to integrate contactless NFC technology used for contactless transactions. This will also be activated only when the user touches the card’s biometric sensor.

Why CMO Should Know About Cybersecurity?

By Aditya S

Apart from configuring cybersecurity measures, the Chief Marketing Officer (CMO) needs to be responsible for taking up cybersecurity practices within their organization. Cybersecurity breaches often coincide with the fact that the CMO is not well-prepared or aware of the whole functionality of cybersecurity. It is important to stay current on cybersecurity trends and threats. There is a hacker attack every 39 seconds; in the year 2018, there were about half a billion data breaches recorded. Government, retail, and technology are the top three cyber hacks breached in the year 2016; there was about 95 percent of records manhandled.

Knowledge about cybersecurity

Many business sectors are undergoing a digital transformation; it has become quite evident that the emerging technological advancements have precisely developed human behavior down the years. Cyber breaches and security hacks are now kept on top priority. Since CMOs are often completely unaware of the practices of cybersecurity measures, they find themselves in a hard position at the time of crisis management.

  • About 22 percent of consumer product companies have CMOs, and most of them are getting engaged in the field of the cyber risk management team. There are many IP which can be stolen and can impact brand equity and its future. Vendors’ security is one of the most critical programs. CMO must not, in any case, leave a loophole.
  • CMOs must examine all touchpoints within their consumer acquisition. Every marketing process deals with very sensitive data that must be stored with prior responsibility. CMOs must coordinate with the chief information security officer to ensure that there is no weakness at any stage of the marketing process. The CMOs should have excellent communicative skills with the IT department to check the security from time to time.
  • CMOs should be champion in the creation and ongoing development of an integrated policy that ensures the latest security protocols implementation. They play an integral part in ensuring employees are well aware and educated on the best security practices of their company.
  • If by any chance, an attacker manages to bypass necessary protection the company has implemented, CMOs’ first action will be to inform the IT department. CMOs are likely to instantly inform its customers about the situation while guiding them on how they will improve security shortly.
  • A security breach can massively hamper the brand identity if a breach takes place; the trustworthiness of that brand diminishes and impacts the brand image. CMO provides a pivotal role in ensuring all the investors and trusted consumers by emphasizing them through word of mouth.
  • Education is the key to protect your brand. Companies that have been victims of malicious cyber-attack must learn from previous experiences. CMO can hire a security consultant to provide specialized knowledge that can save money as well as the brand reputation.

Ways to prevent a cybersecurity breach

  • Secure network

CMOs must be aware of every single connection between them and the rest of the wider web. By re-examining network services, CMOs must be able to cut down the risk factors dramatically. Instead, concentrating on efforts to keep data stored, one should ensure that all the networks are fully protected.

  • Educate users

Educating other employees about cyber attackers is a better option to opt for. CMOs should provide their teammates with regular educational material and training to keep them conscious of cybersecurity.

  • Malware protection

Malicious software refers to content that could harm the computer. Every time a document is uploaded or downloaded, CMOs must check if it’s picking up any malware and data breach. CMO’s must ensure that proper anti-virus software is installed across the company’s technology.

  • Remote access

When CMOs are allowing their employees to access from a remote location, make sure risk-based policies are also taken into account. Keep those users aware of how they can use their devices safely and securely preventing any cyber-attacks and data breaches

  • Monitoring the systems

Proper monitoring is hence an integral part of any cybersecurity plan. CMOs must keep a close eye on the status of every monitor; this may help to catch any attempted or actual attack fast and efficiently. In many cases, it becomes necessary to stay in touch with legal and regulatory requirements as well.

  • Curbing out risk management

Having a clear risk management system across the entire company can become significant. Creating an easily understandable list of policies and good practices will make it easier for the rest of the employees in the organization. Everyone, including staff, contractors, suppliers who work closely with the company, needs to be clear on a risk management system to avoid unnecessary risk with company data.

  • Configuration commitment

A systematic configuration across the company can bring a boost. Any functionality which is not to be used must be removed permanently and should take steps to resolve any known vulnerabilities.

Statistics

  • Cyber attacks are mainly targeted to small scale business firms with about 43 percent penetration
  • By 2020 cost of a data breach may count to $150 million
  • Healthcare industry is affected by malware over more than 75 percent last year
  • $6 trillion is expected to be spent on cybersecurity globally by 2021
  • About 95 percent of cybersecurity breaches happen due to human error
  • Most companies take tenure of 6 months to detect a data breach
  • 27 percent share prices fall on an average due to cybersecurity

After understanding the cybersecurity breaches and role of CMO in handling these issues, it must draw points that well-connected communication within the organization is a necessary factor that can curb out silly mistakes which employees often commit. CMO plays an important card to handle all the risk management, in today’s date it becomes mandatory for any CMO to understand the basic integrities of cybersecurity because building a brand and maintaining its reputation both go hand in hand.

Aditya S is a Growth Assistant at AirTractThe article has been curated by AirTract 

Disclaimer: The article has been edited in accordance with the guidelines of CISO MAG. CISO MAG does not endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. Views expressed in this article are personal.

FBIs IDLE Program Offers Live Bait for Hackers

FBI, FatPipe MPVPN zero-day

The U.S. Federal Law enforcement agency – FBI has quite literally decided to hang the carrot (read fake data) as bait for cyber criminals. The FBI’s exclusive Illicit Data Loss Exploitation (IDLE) program, lures hackers to attack a network in order to trace their identity.

Trusted sources from the FBI say that the agency started the IDLE program with a view of providing security to top companies’ data and network needs. Not much of official information is available on the IDLE program but experts say that the program is designed to place honeypots in servers. Companies will store irrelevant data as a decoy in their servers and use this data as honeypots to lure and trap hackers who try to steal valuable or critical information. The primary motive of the program is to keep track of insider as well as external threat actors.

This is one of the many initiatives of the FBI that is directed toward prevention of cyber and corporate espionage. The FBI also offers training for Chief Information Security Officers (CISOs) of corporate companies called CISO Academy”.

Long T. Chu, acting assistant section chief for the FBI’s Cyber Engagement and Intelligence Section, told Ars. Technica that the FBI is “taking more of a holistic approach these days. Instead of reacting to specific events or criminal actors,” he said, “we’re looking at cybercrime from a key services aspect — aka, what are the things that cybercriminals target? and how that affects the entire cybercriminal ecosystem. What are the centers of gravity, what are the key services that play into that?” That’s precisely where IDLE program comes in.

Earlier in the year, the FBI came up with a new surveillance proposal to monitor social media platforms for potential threats. As per the proposal, the FBI was asking third-party vendors to provide monitoring services, which might bring up possible conflicts with Facebook and other social media companies over privacy policies. Security experts had opined that the FBI’s proposal would violate the companies’ ban against using their data for monitoring purposes.

Thefts and Break-Ins Contribute to 31 Percent Automotive Cyber-Attacks

Automotive cybersecurity

Upstream Security, a provider of cloud-based automotive cybersecurity solutions, released its 2020 Automotive Cybersecurity Report. The report shares in-depth insights and statistics gleaned from analyzing 367 publicly reported automotive cyber incidents spanning from the past decade onward, while highlighting vulnerabilities and insights identified during 2019.

The company also announced the availability of AutoThreat Intelligence, its automotive threat intelligence subscription service which provides comprehensive and actionable insights to threats on automotive and smart mobility services.

Upstream’s 2020 Automotive Cybersecurity Report introduces some of the key findings of the AutoThreat Intelligence research team for 2019 as well as solutions used by the industry going forward:

Connected vehicles are already taking over: 330 million vehicles are already connected, and top car brands in the U.S. market have stated that only connected vehicles will be sold by 2020. This fact alone exponentially increases the potential damage of each attack. A wide-scale attack could potentially disrupt an entire city and even lead to catastrophic loss of lives.

The number of automotive cybersecurity incidents has increased dramatically: Since 2016, the number of annual incidents has increased by 605 percent, with incidents more than doubling in the last year alone.

Most incidents are carried out by criminals: Around 57 percent of incidents in 2019 were carried out by cybercriminals (black hat) to disrupt businesses, steal property, and demanding ransom. Only 38 percent were the result of researchers (white hat) with the goal of warning companies and consumers of discovered vulnerabilities.

A third of incidents resulted in car theft and break-ins: The top three impacts of incidents over the past ten years were car thefts/break-ins (31 percent), control over car systems (27 percent), and data/privacy breaches (23 percent).

Awareness is increasing: More automotive vulnerabilities are being listed, with 66 CVEs (common vulnerabilities and exposures) listed to date. The use of bug bounty programs, which has been popular in enterprise infosec, is on the rise as more automotive companies adopt it to discover vulnerabilities.

The industry is adopting a multilayered security approach: This involves new regulations and standards, security by design, in-vehicle and cloud-based automotive cybersecurity solutions and expanding SOCs to VSOCs (Vehicle Security Operations Centers) for early detection and rapid remediation.

Greta Thunberg Fans Beware, Emotet on The Hunt

Android Trojan, Trojan, ReverseRat, Numando Banking Trojan

Researchers have spotted an Emotet trojan email campaign leveraging environmental activist Greta Thunberg’s popularity to infect computers in in Europe and Asia. The trojan campaign uses climate activist’s name to target domains with .com and .edu (as Greta is really popular among students) extensions. Attackers are also geotargeting their attack making Europe and Asian countries top the charts followed by Australia and the U.S.

According to researchers at Proofpoint and ExecuteMalware, the emails that are making rounds looks like just another invite from Greta for a climate change summit or demonstration with email subjects carrying enticing text like “Demonstration 2019” or “I invite you”. The emails also encourage readers to forward and spread the message to their family and friends.

So, what’s malicious in such a mail? The email body as such does not have any malicious code, but it is the MS-Word attachment in this email that is malicious in nature. Researchers say that the malicious Word document attached is often named “Support Greta Thunberg.doc”. Once the recipient opens the attachment, a prompt to “Enable editing” and then “Enable content” to view the demonstration information is displayed to the recipient. On clicking “Enable Content” a PowerShell command executes Emotet trojan installation. Emotet, a Banking trojan has been around since 2014 but has recently become more common. On successful installation, Emotet runs un-noticed in the background downloading more pieces of malware onto the computer and spreading it to other computers on the network.

A few days ago, Germany’s federal cybersecurity agency BSI also warned of an active malware spam campaign that aims at distributing the Emotet banking Trojan. The messages from the campaign appears to be sent by German Federal Authority, but they are not. A security alert published by the BSI stated, “Currently, increasing number of spams – mails have been sent to several federal agencies with malicious attachments or links in their names. The Federal Office for Information Security (BSI) calls for special caution and warns against opening these emails and links. Several confirmed Emotet infections in federal administration authorities have been reported to the BSI in the past few days.”

For staying alert and aware from Emotet infestation BSI recommended, to check the sender name carefully before opening any attachment. If in doubt, clarify over the telephone with the alleged sender whether an email was actually sent by them. In addition, the execution of macros when opening Office documents should be avoided and at best prevented centrally.

Palo Alto Networks Acquires Aporeto

CynergisTek Partners with Awake Security to Boost Cybersecurity in Health Care

Cybersecurity firm Palo Alto Networks recently announced that it has completed the acquisition of Aporeto Inc., a machine identity-based micro-segmentation company. The acquisition will further strengthen the Palo Alto Networks Cloud-Native Security Platform delivered by Prisma Cloud.

Palo Alto Networks covers several segments like firewalls, cloud-monitoring and compliance, endpoint protection, and threat detection services. The Santa Clara-based company stated the latest acquisition deal will bring it closer to using AI and machine learning to help further automate significant parts of the company’s customer security operations.

Founded in 2016, Aporeto uses identity-based access control to secure workloads across all infrastructures. The California-based company claims that its technology strengthens Palo Alto’s cloud security suite Prisma. As per the acquisition deal, Aporeto co-founders Dimitri Stiliadis and Satyam Sinha are going to join Palo Alto Networks.

“We are excited to officially welcome Aporeto to Palo Alto Networks,” said Nikesh Arora, chairman, and CEO of Palo Alto Networks. “Aporeto is a great fit for our company, and its micro-segmentation technology will further expand our cloud security capabilities and enhance our Prisma Cloud offerings.”

Palo Alto Networks provides the most complete cloud security suite in the industry, with a broad set of capabilities in all critical areas of cloud security. With the addition of Aporeto, Palo Alto Networks will add the ability to identify workloads and apply micro-segmentation across all infrastructures, helping customers secure their applications at scale.

As per the acquisition deal, Aporeto co-founders Dimitri Stiliadis and Satyam Sinha will join Palo Alto Networks.

Earlier this year, Palo Alto Networks acquired information security startup Demistro in a US$ 560 million cash and stocks deal. The acquisition deal, which is expected to be completed in the third quarter of the fiscal year, will accelerate the Palo Alto networks application framework strategy and support the company’s aim to deliver immediate threat prevention and response for security teams.

Demisto, founded in 2015, develops and markets automation tools for information security management. The company claims that its Security Orchestration Automation and Response (SOAR) Platform combines orchestration, incident management, and interactive investigation into a seamless experience. Demisto is going to jointly work with the Palo Alto Networks team to strengthen its existing integration with the Application Framework, the company said in a statement.

CISO MAG Rewind: Biggest Financial Data Breaches of 2019

Financial Sector

By Rudra Srinivas

The Banking and Financial sectors were hit with a constant stream of cyber-attacks when compared to other sectors. According to Intsights Q1 2019 report, around 25.7 percent of all malware attacks last year were targeted on banks and financial organizations.

The banks are increasing their budget allocation to enhance cybersecurity capabilities to protect against threats. Multiple banks and financial institutions reported critical data breaches, malware attacks, and other types of cyber-attacks this year, which include:

Dutch Bangla Bank Limited

Attackers scooped more than US$ 3 million from the Dutch Bangla Bank in Bangladesh by launching an ATM cash-out attack in May 2019. According to research firm Group-IB, a hacker group named “Silence” is likely behind the attack.

Group-IB stated the Silence group was active since 2016 and previously attacked banks in Russia, former Soviet states, and Eastern Europe. It’s said that the hacker group appears to have deployed a malicious code on the bank’s network to run malicious commands on hosts and allegedly used the access to orchestrate fund withdrawals from the bank’s ATMs, according to Group-IB.

 First American Financial Corp

First American Financial Corp. suffered a data breach in May 2019, that compromised nearly 885 million files related to mortgage deeds, KrebsOnSecurity revealed. Based in California, First American provides title insurance and settlement services to the real estate and mortgage industries. The exposed information included bank account numbers and statements, mortgage and tax records, social security numbers, transaction receipts, and images of drivers’ licenses.

Westpac Data Breach

Cyber-attack on Westpac Banking Corporation exposed almost 100,000 Australians’ personal data. Westpac confirmed that it detected an unauthorized use of its payment platform PayID, which allowed instant transfer of money between banks using mobile number or email address. The incident exposed users’ phone numbers, email addresses, and transaction history. However, Westpac clarified that no customer bank account numbers were compromised in the incident.

“PayID allowed anyone to punch in a phone number and search for the account registered under it, along with the account holder’s name. Authorities suspect that fraudulent PayID accounts were used to generate a series of random lookups and collect data on almost 100,000 customers,” Westpac said in a statement.

Capital One Data Breach

Capital One Financial Corporation, a bank holding company, disclosed a data breach in July which affected approximately 100 million individuals in the United States and nearly 6 million in Canada. The company stated that the attacker exploited a specific configuration vulnerability in its digital infrastructure and allegedly accessed the data.

The compromised information included names, addresses, phone numbers, and dates of birth, along with 140,000 Social Security numbers, 80,000 bank account numbers, credit scores, and transaction data. However, Capital One clarified that no credit card account numbers or log-in credentials were compromised in the incident.

The FBI charged a suspect, Paige A. Thompson, with computer fraud and abuse. Thompson, who went by the hacker name ‘erratic’, allegedly exploited a misconfigured firewall to access the Capital One cloud repository and exfiltrate the data in March 2019.

Desjardins Group Breach

Canadian Credit Union Corporation, Desjardins Group, disclosed a data breach in July 2019. The incident occurred due to unauthorized use of internal data by an unidentified employee, Desjardins said. The breach exposed sensitive information of 2.7 million members which included home addresses, names, email addresses, and social insurance numbers.

Malware Targeting Indian Banks

Security experts discovered a malware that was intended to exploit ATMs of India Banks and steal customers’ sensitive information. The malware, dubbed ATMDtrack, allowed the attackers to read and store customers’ card data when they are inserted into the infected ATMs.

According to Konstantin Zykov, a researcher at Kaspersky Labs, the attacker who created the ATMDtrack was traced to the cyber-hacking outfit Lazarus Group controlled by North Korea’s primary intelligence bureau. The scandalous Lazarus Group is a prime suspect in a series of cyber-muggings, including the cyber- attack on Sony Pictures Entertainment in 2014, and the WannaCry ransomware attack in 2017.

Rudra Srinivas is part of the editorial team at CISO MAG and writes on cybersecurity trends and news features. 

Hacker Group Uses New Custom Malware “Dudell” to Infect MS Excel Docs

Researchers have discovered a cyberespionage group called “Rancor” which has been distributing a new malware campaign “Dudell” via Microsoft Excel documents.

According to researchers at Palo Alto Networks, Rancor threat group has been active since 2017 and has been targeting government organizations until January 2019. It’s believed the group performed two rounds of attacks to install Derusbi or KHRat malware on victim systems beginning early December 2018 till the end of January 2019.

“In recent attacks, the group has persistently targeted at least one government organization in Cambodia from December 2018 through January 2019. While researching these attacks, we discovered an undocumented, custom malware family – which we’ve named Dudell. In addition, we discovered the group using Derusbi, which is a malware family believed to be unique to a small subset of Chinese cyber espionage groups,” researchers said in a statement.

How Dudell Malware Infects?

Attackers spread Dudell malware with weaponized Microsoft excel document via malspam email attachment. Once a victim opens the attachment, the malicious macro gets triggered, and it automatically downloads on to the victim’s device.

After the execution, the malware attempts to evade sandbox analysis and steals victim information like IP address, hostname, language pack, and operating system details.

According to researchers, Dudell could also perform other malicious processes including:

  • Downloading and uploading files
  • Deleting files
  • Taking screenshots
  • Terminating specific processes
  • Executing commands
  • Listing folder contents
  • Enumerate processes and storage volumes

In a similar research, security experts at Microsoft said cybercriminals are customizing their phishing attack methods to trick companies and their users. The researchers stated that phishing campaigns grew from 0.2 percent in January 2018 to 0.6 percent in October 2019.

In its recently released 2019 Cybersecurity Trends report, Microsoft highlighted that phishing was one of the attack vectors that was rising over the past two years. “In 2019, we saw phishing attacks reach new levels of creativity and sophistication,” Microsoft said.

US Navy Bans TikTok for staffers citing Security Threats

TikTok, TikTok data privacy, TikTok children's privacy

The U.S. Navy recently banned short video sharing app TikTok, citing cybersecurity concerns. The U.S. Navy has also sent out a statement stating that serving members of both the Navy and the Army, who were using government-issued mobile devices and had the app installed in it, would be blocked from the Navy-Marine Corps Intranet.

The government-controlled devices can run all kinds of commercial apps, but some apps are barred due to security threats and to protect sensitive information. It has been learnt that Senator Chuck Schumer advised the U.S. Army to ensure recruits refrain from using TikTok.

TikTok is popular among U.S. teenagers, but recently it came under scrutiny from the U.S. regulators. The government launched a national security review on ByteDance, the Beijing-based parent company of TikTok, after the company made US$ 1 billion acquisition of the U.S. social media app Musical.ly.

Another Revelation

Earlier, TikTok was also hit with a class-action lawsuit in the U.S. claiming that the company surreptitiously transferred users’ data to Chinese servers, without users’ consent. The proposed class-action lawsuit was filed in California federal court by Misty Hong, a student from Palo Alto.

In her lawsuit, Misty Hong alleged that TikTok and its parent company ByteDance failed to handle users’ data and knowingly violated the Right to Privacy act. The company was also accused of taking users’ draft videos and presented uncertain privacy policies.

According to the lawsuit, Hong installed the TikTok app in April 2019 but never created an account. But she discovered that TikTok created an account for her, without her consent. Though Hong never saved or published her videos, TikTok secretly transferred her data to Chinese servers. It’s said that TikTok collects a set of users’ data, including phone and social network contacts, email addresses, IP addresses, and location.

Claimed to have around half a billion active users worldwide, TikTok previously said it does not store user’s data on Chinese servers. The incident raised severe concerns that data culled by TikTok could be used to identify, profile, and track users.