Home Blog Page 262

After a Slew of Hacks OnePlus Launches its Own Bug Bounty Program

bounty for DarkSide Ransomware Group, Microsoft Offers $100,000 Bounty

After the slew of cyber-attacks that had married the Chinese smartphone manufacturer, OnePlus, it has now launched its own bug bounty program named as “OnePlus Security Response Center” (OneSCR). The company invited independent security researchers to participate and be rewarded for finding security vulnerabilities in the systems.

“The global OnePlus Security Response Center will engage academics and security professionals to responsibly discover, disclose and remediate issues that could affect the security of OnePlus’ systems, and will help us proactively counter potential external threats to user security. Security researchers around the world can proactively search for and report OnePlus-related security issues through the new bug bounty program,” OnePlus said in a statement.

According to OnePlus, the reward amount ranges from a minimum of US$ 50 to US$ 7000 based on vulnerability severity and business impact.

Special cases: up to US$ 7,000

Critical: US$ 750 – US$ 1,500

High: US$ 250 – US$ 750

Medium: US$ 100 – US$ 250

Low: US$ 50 – US$ 100

The company also stated that it’s partnering with vulnerability coordination and bug bounty platform HackerOne to check OnePlus’ systems against potential threats.

The latest move comes after OnePlus encountered multiple security breaches this year. Earlier, the security team at One Plus confirmed a data breach that exposed sensitive details from certain customers’ orders which included their contact numbers, names, and addresses. As per the FAQ page on the One Plus website, the data breach occurred due to existing vulnerability on its website. One Plus stressed that hackers found this loophole and exploited it to gain the order details of certain customers while they couldn’t gain confidential payment information and account passwords.

Ahead of that, researchers revealed that a critical security vulnerability in OnePlus device’s wallpaper application ‘Shot on OnePlus’, leaked hundreds of the user’s email address and other information. The ‘Shot on OnePlus’ is an application used to access photos uploaded by the OnePlus users.

The flaw could expose the photo details, including photo code, author, email addresses, focal-length, photo topic, uploaded location, and the uploaded time. OnePlus notified the users that the issue was fixed and made changes to its API.

Hornet Nest: Lays Not 1 but 6 Malware Variants

Armor Piercer

A new malware campaign is targeting organizations in the U.S. and Europe with an attack that delivers a six-in-one malware. It includes info-stealing trojans, a remote backdoor, crypto-stealer and a crypto-miner. Since there are multiple types of malware infested in a single go, its quantity and variety has earned it a name, “Hornet Nest”.

Researchers at Deep Instinct, a cybersecurity firm said, “Such volume and variety are uncommon in the general landscape and are highly suggestive of a dropper-for-hire campaign.” The Legion Loader (i.e. the Hornet Nest), is the primary payload dropper and is written in MS Visual C++ 8. As per observation, the Loader shows signs of active modifications and is most likely to be developed by a Russian speaker as the code shows a few traces of comments and UI written in Russian.

The mode of distribution is currently unknown but once the Legion Loader is installed, a few PowerShell commands are run which in turn download the remaining payloads. This consists of three variations of trojan malware—two crypto stealers; and one backdoor entry providing payload:

  1. Vidar Targets all sorts of personal information, including data stored in Two-Factor Authentication (2FA) software.
  2. Predator the Thief Steals data and can capture images using the victim’s webcam.
  3. Racoon Stealer – Bypass Microsoft and Symantec anti-spam messaging gateways.
  4. Crypto Stealer – A PowerShell-based cryptocurrency stealer which allows the attacker to steal from a victim’s bitcoin wallet.
  5. Crypto Miner –Exploits the victim’s computer and its processing power to help mine cryptocurrency over a longer period.
  6. RDP Backdoor – Provides the attacker entry into the victim’s compromised machine. This allows the attacker to execute additional attacks in the future.

Researchers said that, “Hornet Nest” is a classic example of how a less sophisticated malware can be a nightmare for any organization as it employs more advanced file-less techniques and delivers a bundle of follow-up malwares ranging from info-stealers and credential harvesters to crypto-miners and backdoors.

In a similar multiple trojan infection attack, researchers from Fortinet found a sample file of a dropper that was flagged suspicious. Upon research, it was found that the new malware had the capability to drop both RevengeRAT and WSHRAT on systems running Windows OS.

Want New Password? Please Queue-Up – JLU tells 38,000 Students

University

In a bizarre incident, to comply with the legal requirements imposed by the German National Research and Education Network (DFN), 38,000 students of Justus Liebig University (JLU) in Gießen, Germany, had to stand in queues to get new passwords post a massive cyber-attack which took down the University network on December 8, 2019.

The severity of the cyber-attack can be gauged from the fact that the entire IT and server infrastructure of the University had to be taken offline as soon as the attack was detected. Dr Joybrato Mukherjee, President of JLU Professors, noted that the incident was marked as “severe”.

In an open letter he stated that this incident also affected the examination administrative department. The University cannot provide its students degree certificates, transcripts or any exam certificates unless restoration of services is completed.

JLU authorities have distributed close to 1200 USB sticks loaded with anti-virus software to the professors, institutes, and departments within the University. This is the first wave of combing operations on part of JLU which scans for generic viruses. The second wave of scanning contains a search for specific type of cyber-attack which targeted the University network.

Meanwhile, the 38,000 students and staff of JLU were asked to stand in a queue with their ID cards and a personalized JLU chip card containing a photo to receive new passwords for their email accounts. This may seem a bit bizarre and old-school but JLU is a member of the German National Research and Education Network (DFN). To adhere to its regulations, the new passwords can only be issued personally as per legal guidelines of the DFN.

JLU has also formed a crisis management committee that has been working with the authorities and cybersecurity experts to establish the extent of the damage and restore online services at the earliest.

In a similar incident of cyber-attack and data breach, around 50,000 students in Australia using Get, an events-scheduling application, had their private data exposed online. The issue came into light after a user reported that he’s able to access other users’ information, including name, date of birth, email addresses, Facebook ID details, and phone numbers.

Tokyo 2020 Authority Warns Against Phishing Emails

Tokyo Olympics 2020

The authorities of the Tokyo 2020 Summer Olympics recently issued a warning about an ongoing phishing campaign. It’s said that the suspicious emails are designed to look like they’re coming from the Tokyo Organizing Committee of the Olympic and Paralympic Games 2020.

The international multi-sport event is scheduled for next year between 24 July and August 9. 2020 in Tokyo, Japan. The authorities stated that the phishing emails will redirect the recipients to fake websites or infect their computer systems with malware if opened.

“We have recently detected emails disguised to look like they are coming from a Tokyo 2020 staff member. Although the email may look official and legitimate, if you have no reason to receive such an email or if the content is questionable, you should not click on the link or open any attached files. It is highly likely that you would be directed to a phishing site or your computer would be exposed to a virus,” the authorities said in an official statement.

“If you receive a questionable email, do not click on the link or open the attached file. Please delete the email immediately,” the statement added.

“Strontium” Targets Sporting Organizations

According to Microsoft’s Threat Intelligence Center report, a group of state-sponsored Russian hackers targeted nearly sixteen International Sporting and Anti-Doping organizations ahead of the 2020 Summer Olympics in Tokyo.

Microsoft stated the attacks are linked to a Russian hacking group “Strontium,” also known as Fancy Bear or APT28, which is believed to be linked to Russian military intelligence agency GRU and has been active since 2007.

The tech giant revealed that the methods used in recent attacks are similar to those previously used by Strontium to target government organizations, think tanks, militaries, law firms, human rights organizations, and financial firms across the world. It’s said that the Strontium group launched a variety of attacks, including spear-phishing, exploiting internet-connected devices, and password spraying.

In order to avoid any kind of cyber threats during the 2020 Olympic and Paralympic Games, the Japanese government had also introduced a new cybersecurity strategy in 2018. As a part of the strategy, the government planned to create a new body to ensure effective coordination among government agencies, the Olympic organizing committee, municipalities, and business operators to respond to cyber threats.

The government had also decided to introduce a five-level scale to classify the severity of cyber-attacks. The severity index categorizes the cyber-attacks into five levels: the lowest level 0 indicates “No Impact” while the highest level 4 indicates “Extremely Grave Impact.” The index would be helpful for people, government, and business entities to understand the magnitude of threats and take necessary actions.

Massive Data Breach at Wawa Stores Affected Customers’ Data

Massive Data Breach at Wawa Stores Affected Customers’ Data

Wawa Stores, an American chain of convenience stores and gas stations, is the latest victim of a massive financial data breach.

According to Chris Gheysens, Wawa’s CEO, the company discovered a malware payload in its payment processing systems on December 10, 2019. The security team at Wawa had blocked the malware on December 12, 2019, and it’s believed that the malware no longer poses any risk to customers making payments at Wawa stores.

Gheysens said that the malware affected the customers who made payments at Wawa stores and gas stations. However, the company clarified that the store’s ATMs were unaffected.

The number of affected customers is still unknown. It’s said that the incident potentially affected 850 stores, which are located across the East Coast from Pennsylvania to Florida since March 4, 2019.

The exposed financial information includes debit and credit card numbers, expiration dates, and cardholder names. However, PINs and CVV numbers were not exposed. The company also clarified that there is no evidence of any unauthorized use of exposed payment information.

Gheysens stated that they’ve informed law enforcement and payment card companies and appointed an external forensics firm for further investigation. The company also notified the affected users and offered free credit monitoring services. “I want to reassure you that you will not be responsible for any fraudulent charges on your payment cards related to this incident,” Gheysens said.

“We encourage you to remain vigilant by reviewing your payment card account statements. If you believe there is an unauthorized charge on your payment card, please notify the relevant payment card company by calling the number on the back of the card.  Under federal law and card company rules, customers who notify their payment card company in a timely manner upon discovering fraudulent charges will not be responsible for those charges,” the company said in a statement.

Asigra Vows Defense to Canadian Non-Profit Organizations

canada

Asigra Inc., a Canadian cloud-based backup, recovery and restoration software service provider, announced a new program that focusses on defending the backup repositories and data of Canadian public/non-profit organizations against cyber-attacks.

The purpose of this program is to help users in the data recovery process, that otherwise would have been difficult in case of a malicious malware/ransomware attack, which often puts large volumes of personally identifiable information (PII) at risk. Hackers have now designed ransomware and other malwares that target the secondary storage systems (i.e. backup data), this means there will be no other option for the victim but to agree to the hacker’s ransom demands, which can be exceptionally high for public and non-profit entities.

To shoulder this burden, Asigra has decided to partially donate a large percentage of its cybersecurity-enabled backup technology to Canada’s extensive list of public and non-profit organizations. Under this program, establishments in the country (Canada) that can issue a tax-deductible receipt, can contact the company to receive its complete suite of anti-ransomware and backup software. The larger part of the cost for these services will be covered by a donation-in-kind.

“The majority of cybersecurity analysts today agree that cyberattacks are evolving from the perspective of what they target, how they impact organizations and the changing methods of attack,” said David Farajun, CEO, Asigra. “For the past year, we have seen an increasing number of cyberthreats begin to target the number one method of data recovery – the backup repository. As a specialist in this area, we have developed a very effective solution to fight against this, and now offer the technology to public and non-profit organizations we share our data with.”

Cyberattacks on public/non-profit organizations have put personal data at risk. New variants of ransomware and other forms of cyber-attacks continue to infiltrate and expose sensitive data to unknown and possibly criminal entities. In a recent attack, medical test provider LifeLabs agreed to pay ransom to the attackers in order to retrieve millions of customer records. In a statement, the organization said, “the personal information of over 15 million customers was compromised, mostly in British Columbia and Ontario, including name, address, email, login, passwords, date of birth, health card number and lab test results.”

The cloud-based data recovery platform of Asigra enables data protection and cybersecurity against malware/ransomware. This coupled with FIPS 140-2 certification means a military-grade encryption is done to the data in its cloud making user data unreadable without the proper encryption key, thus ensuring secure and reliable data recovery.

Apple Announces Official Guidelines for its Public Bug Bounty Program

Apple Is Hackers’ Favorite for Brand Phishing Attacks, REvil gang threatens Apple blueprint leak

Apple recently confirmed the relaunch of its previously closed, public bug bounty program. The company made the announcement earlier this year at the Black Hat security conference in Las Vegas.

Till now, Apple organized an invitation-based bug bounty program for selected researchers and accepted only iOS related bugs. From now, the company accepts vulnerability reports from all security researchers and for a range of products that include iPadOS, tvOS, watchOS, macOS, and iCloud.

Apple published an official announcement detailing the rules of the bug bounty program, along with a breakdown of the rewards. The company also increased its maximum reward from US$ 200,000 to US$ 1,500,000, based on the exploit complexity and severity.

“As part of Apple’s commitment to security, we reward researchers who share with us critical issues and the techniques used to exploit them. We make it a priority to resolve confirmed issues as quickly as possible in order to best protect customers. Apple offers public recognition for those who submit valid reports and will match donations of the bounty payment to qualifying charities,” Apple said in a statement.

In order to earn maximum rewards and other bonuses, researchers must submit clear bug reports, which include:

  • A detailed description of the issues being reported.
  • Any prerequisites and steps to get the system to an impacted state.
  • A reasonably reliable exploit for the issue being reported.
  • Enough information for Apple to be able to reasonably reproduce the issue.

Apple also mentioned a detailed set of bounty categories ranging from a minimum bounty of US$ 25,000 to a maximum of US$ 1,000,000.

Apple isn’t the only company to offer huge bug bounty rewards. Earlier this year, Google announced the increase in its bug bounty rewards. The company raised bounties for Chrome and Google Play related bugs. Google launched the vulnerability rewards program in 2010 and provides cash rewards to security researchers who report vulnerabilities in Google code. The company stated that they’ve received around 8,500 vulnerability reports and paid rewards over US$5 million (£4 million).

Henry County’s Malware Attack Dents Administrative Pockets

Malware

To restore parity from a malware attack and a corresponding data breach, Henry County, a county located in north-central Georgia, ended-up paying more than US$650,000 to cybersecurity experts and consultants for restoring normalcy.

What happened?

In the early hours of July 17, Henry County was attacked with a malware (ransomware) which forced the authorities to almost immediately shut down its entire network and systems primarily to protect the taxpayer information available in its database. This meant that, for the next few days the County offices had to resort to the old method of maintaining paper records. Keeping important services such as issuing building permits and business licenses up and running, was their top priority as any delay in it would have had a rolling effect on other businesses as well.

How did Henry County respond?

As most of the official County services bore the brunt of this attack, workers at Henry County offices pulled out their typewriters and carried out necessary operations manually on paper for the next three weeks. They then appointed consultants who would monitor the damage and suggest all possible ways to reinstate the entire network and systems at the earliest.

What was the cost of recovery?

Although Henry County officials have been tight lipped about the expenses, a report suggests, the County spent more than US$650,000 as of mid-December to get its network and associated systems fully operational. Most of the money—around US$578,000—went to the appointed consultants and computer security specialists for new server installation, compliance work, travel expenses and other activities. A balance of US$78,000 is still shown as outstanding for the Phase-2 of the restoration process.

Henry County is not the first city county whose government offices have come under a cyber-attack. Previously, Atlanta city witnessed a similar ransomware attack on March 22, 2018, causing disruption across the city and shutting down some of the government offices. Nearly five out of the thirteen departments of the city took the stab and had to resort to the exhaustive manual processes of filling forms and submission. Payment of bills, parking tickets, and similar services were also affected. Even the Department of Corrections had to manually carry out the paperwork for inmates.

Unprotected Database Exposed Personal Data of 267M Facebook Users

Panasonic network breach

Another one on Facebook’s cap. An unprotected public database containing over 267 million Facebook user IDs, names, and contact details were left online without password protection. The issue came to light after security firm Comparitech and researcher Bob Diachenko uncovered the leaky Elasticsearch database in a joint investigation.

According to the researcher, the incident occurred due to illegal scraping operation or Facebook API abuse by cybercriminals in Vietnam.

Diachenko stated that 267,140,436 records were exposed in the incident, which could be used by attackers to launch SMS spam and phishing campaigns. The exposed data was also posted on a hacker forum for download.

After discovering the trove on December 14, Diachenko immediately notified the internet service provider managing the IP address of the server. It is said that the database was left exposed for nearly two weeks before it was taken offline on December 19.

“When we find exposed personal data like this, we take steps to notify the owner of the database. But because we believe this data belongs to a criminal organization, Diachenko went straight to the ISP,” Camparitech said in a statement.

It’s still unclear how hackers obtained the user IDs and phone numbers. But, Diachenko said that Facebook’s API could also have a security hole that would allow intruders to access personal data even after access was restricted. One more possibility, according to Diachenko, is that the data was stolen by scraping publicly visible profile pages.

“We are looking into this issue but believe this is likely information obtained before changes we made in the past few years to better protect people’s information,” a Facebook spokesperson said in a media statement.

This is not the first time that millions of Facebook users suffered a data breach. Recently, Facebook admitted a data breach involving 100 third-party app developers who had improper data access. In a blog post, Facebook’s Konstantinos Papamiltiadis, Director of Platform Partnerships revealed that app developers had access to user data such as group member names and profile pictures through the Group API.

Attackers Using Taylor Swift Image to Hide Malware Payloads

Security researchers discovered that cryptocurrency-mining botnet operators were using pop singer Taylor Swift’s image to hide their malware payloads. The botnet, dubbed as MyKingz, was spotted by UK-based security firm Sophos. MyKingz was active since 2016 and is also known as Smominru, DarkCloud, and Hexmen.

According to Sophos, attackers behind MyKingz are targeting Windows systems to deploy various cryptocurrency-mining apps. The group identifies vulnerable hosts and gains access to infected computers to install malware payloads on the compromised systems.

Researchers stated that currently, the MyKingz group is using steganography techniques to hide malicious files inside legitimate ones. It’s discovered that the group hiding a malicious EXE inside a JPEG image of pop singer Taylor Swift.

Steganography is an ancient practice of hiding secret content and text messages inside non-suspicious messages. Cybercriminals use Steganography to hide malicious code within the image/audio/text file that is mainly employed by exploiting kits to hide their malvertising traffic.

“The components of the botnet are very much interlinked, and there are many possible infection paths, so we start our discussion with the bootkit loader, keeping in mind that it is not the initial source that will be discussed later in a separate section,” Sophos said in a statement.

According to Sophos, the top infected countries by MyKingz include China, Taiwan, Russia, Brazil, the USA, India, and Japan.

Researchers stated that the MyKingz botnet is the biggest threat to Windows computers and enterprise networks. Any unpatched systems may likely to be compromised by MyKingz group.

MyKingz is not the only hacker group to use steganography techniques.

Recently, Trend Micro stated that cybercriminals are using steganography to infect the targeted systems. It’s believed that the activity was distributing malicious codes since 2018 through fileless methods, steganography techniques, and hijacking email accounts to deliver the information-stealing malware such as Emotet, Bebloh, and Ursnif.

In similar research, Matthew Rowen, a security researcher from Bromium, discovered ransomware embedded into a downloadable Super Mario image using steganography method. The attackers send emails with an attached spreadsheet that has an embedded malware and a macro. The attachment prompts the user to click on and enable a content link to deploy the malware.