Home Blog Page 264

Researcher Finds 5 Malicious Adware Apps on Play Store

Adware

Does that tiny Ad pop-up on the screen annoy you? Yes, we are talking about the same pop-up that no matter which app you open follows you like a shadow. Well, that’s an Adware. Tatyana Shishkova, an Android Malware Analyst from Kaspersky discovered a few similar malicious Adware apps on Google’s Play Store.

Adware is a type of malware (malicious software) which displays unwanted advertisements on the user’s device. These ads are generally in the form of a pop-up and at times without a “Close Popup” option. This form of a malware is less serious than others but has a ton of nuisance value to it. Adware implementers can sell your browsing history and behavior to interested clients which they could in turn use to target you with more such ads customized as per your likes and dislikes.

In a similar finding earlier in the week, Tatyana also found three hidden Ad apps on the Play Store which had close to 12,000 installs. Digital adverts are no longer just used to pursue the user to only buy products, but this set of information is also used to earn profits by selling it to interested third-party clients.

Google advises against downloading unknown third-party apps. Do a thorough research before downloading any app. Reading the app information, reviews, ratings and app permissions will certainly help. Turn on the “Scan device for security threats” in Google Play Store’s Play Protect. Additionally, Google also recommends purchasing and downloading an anti-malware app like Malwarebytes to add an added layer of security against such malicious Adware apps.

Earlier last year, a malware developed using the Kotlin programming language was a cause of concern for the Google Play Store. It was found that Kotlin could be used to develop nasty apps, which were difficult to detect. Trend Micro, a cyber-defense and security firm, discovered a malicious app posing as Swift Cleaner for optimizing Android devices. The Kotlin-developed app was capable of information theft and click ad fraud amongst its other noted damages.

APAC Service Providers Must Scale-Up and Scale-Out Security Infrastructure

Nearly Half of Global Consumers Affected by Data Breaches

A new report from Juniper Networks, a provider of AI-driven networks, revealed that Asia-Pacific (APAC) service providers are concerned over their security infrastructure as they readying themselves toward the adoption of new technologies like distributed clouds, IoT, and 5G.

According to the findings, only one-quarter of service providers surveyed stated they are satisfied with the existing security infrastructure, while the majority are planning heavy investment into cybersecurity over the next two years.

The findings are based on the responses of IT decision-makers from service providers across APAC. The report also highlighted that increased adoption of new technologies like distributed clouds, IoT, and 5G are forcing service providers to scale up and scale-out their security infrastructure to remain relevant and secure.

Report Highlights:

  • Only 29 percent are very satisfied with their current firewall
  • 65 percent will upgrade their firewall within the next year
  • 61 percent plan to increase spending on firewall products and services over the next two years

Almost 96 percent of the APAC service providers surveyed stated that they’re planning to use 5G technology in the next two years. According to the report’s findings, the top areas of focus were with respect toward better intrusion detection solutions (88 percent), upgrading security gateway, GI-firewall and roaming firewall (86 percent), and greater cloud security (84 percent).

“Network deployments have changed significantly over the past few years. Service providers are rapidly moving to the cloud and adopting new technologies, such as IoT and 5G, which will redefine the way we live, work and play. All of these are heavily dependent on the network, and enterprises are increasing spending on security to protect new and existing infrastructure,” said Ang Thiam Guan, VP & GM, APAC, Juniper Networks. “As this transformation occurs, we need to encourage a more all-encompassing view of security, rather than focus on the perimeter. The network itself should be the first line of defense, especially as the scale, demands and usage patterns on infrastructure continue to evolve and grow.”

Cybersecurity Market in India Rise to US$3.05 Bn by 2022: Study

Acronis Cyber Readiness Report, cyberattacks in India, cybercrime in India, India’s Private Sector

According to a joint study by PwC India and Data Security Council of India (DSCI), the cybersecurity market in India will grow from US$1.97 billion in 2019 to US$3.05 billion by 2022, at a compound annual growth rate (CAGR) of 15.3 percent. It’s believed that the growth in the Indian cybersecurity market is around 1.5X of the global security market.

The study also stated that Banking, Financial Services and Insurance (BFSI), IT, and government are the top three sectors with the largest market share in cybersecurity expenditure in the country.

“The BFSI sector accounts for 26 percent of the total expenditure in the cybersecurity market and is expected to increase its expenditure to US$810 million from the existing US$518 million by 2022, at a CAGR of 16.1 percent,” the report stated.

The growth in cybersecurity expenditure is due to several factors like tightened norms from regulators, data localization, utility payments, e-commerce, and online insurance marketplaces. Also, the revolution in payments technology using AI, blockchain, IoT, and the introduction of mobile point of sale (POS) devices has brought a host of financial solutions in the country, according to the report.

The report also highlighted that the average cost of a data breach in India has gone up to INR 11.9 Cr (US$ 16M), which is an increase of 8 percent from 2017.

Cybersecurity Products in India

The study anticipates that cybersecurity products in India will grow at a higher rate. It is believed that data protection and endpoint security tools will grow at a CAGR of 22.2 percent and 19.1 percent respectively over three years.

“Artificial intelligence and machine learning applications are being embedded into the cyber suite of offerings—especially in security intelligence, detection and response (IDR), endpoint security and security testing. The key use cases stem from the ability to use predictive analytics and heuristics in drawing quick statistical inferences, thereby helping in detecting and lessening threats with an optimized number of resources and savings. A natural outcome of such developments is the emergence of products and platforms specializing in these areas,” the report added.

DSCI also mentioned that global regulations like General Data Protection Regulation (GDPR), Health Insurance Portability and Accountability Act (HIPAA), and Health Information Trust Alliance (HITRUST) will continue to have an impact on the Indian cybersecurity market.

SBI warns: Public Charging Stations Can be Used for Juice Jacking

State Bank of India

Is your mobile phone running out of juice?  Need a quick charge? Ah, there is a public charging station! Wait, is it safe? May not be, says SBI. Beware, you can be a victim of Juice Jacking.

One of India’s largest and premier government controlled banking institution, the State Bank of India has publicly issued a warning of ‘Juice Jacking’ through its twitter handle. In a country like India where digital economy is still in its nascent stage, this social and digital awareness campaign is welcomed by many. The bank in its tweet advised its customers and general public to “think twice before plugging-in their phone at (pubic) charging stations, as hackers can maliciously infect their smartphone with a malware.”

What is Juice Jacking?

In simple words, Juice Jacking is an attack carried out by hackers through a USB charging cable. When a user plugs in the charging cable in his mobile’s charging port, and connects it to any of the rigged charging stations installed at public spaces such as airports, train stations, hotels, cafes etc – it gives a back-door entry to hackers into the compromised device. The charging port which is also used for data transfer over the USB, is pointed as the main cause of concern over here. Installing malware, cleaning user data, asking ransom in exchange for access to personal data on the phone, personal and financial account hijacking are just some of the many nefarious things that a hacker can do with this unrestricted access.

Steps to Mitigate the Risks

In order to guard your phone against Juice Jacking, take these precautionary measures:

  • Avoid using public charging stations. These are soft targets for hackers as they are often kept unguarded and without any surveillance. Even while using them, go behind the charging station and check the power source of the USB ports.
  • Always use your own AC charging adapter and cable for charging the device. And be sure to plug it into the AC wall socket, and not the USB socket on the wall.
  • Stay guarded against a stranger’s device and laptop. Do not connect with an unknown person’s laptop or PC for charging your electronic devices and vice-versa.
  • For emergency situations, buy and carry a certified power bank with enough capacity to take care of your device’s emergency power backup needs.
  • It may be difficult to find, but try to use a cable that can be used only as a charging cable and not a data cable. This can be a task as almost all mobile devices come with a charger that is capable of charging as well as data transfer.
  • Frequent travelers should use a USB blocker. It is a small device that blocks the data connection on the USB cable by blocking its data pins.

In a similar warning earlier, the Los Angeles District Attorney urged travelers to avoid public USB power charging stations in hotels, airports, and other public locations. The Attorney’s warning described many attack vectors that cybercriminals use to abuse USB wall chargers. And the most common way is via “pluggable” USB wall chargers that can be plugged into an AC socket by attackers to leave malware at public charging stations.

Thief Stole Payroll Data of 29,000 Facebook Employees

Facebook Data leak, Facebook bans cyber mercenary

Some tens of thousands of current and former Facebook employees are impacted after a thief stole corporate hard drives from an employee’s car. According to Bloomberg, banking information of 29,000 Facebook employees in the U.S. was compromised.

The hard drives, which were unencrypted, contained payroll data like employee names, bank account numbers, social security numbers, salary details, bonus amounts, and equity details. However, Facebook clarified that the stolen drives didn’t include Facebook users’ data.

“We worked with law enforcement as they investigated a recent car break-in and theft of an employee’s bag containing company equipment with employee payroll information stored on it. We have seen no evidence of abuse and believe this was a smash and grab crime rather than an attempt to steal employee information,” Facebook said in a statement.

According to sources, the incident occurred on November 17. Facebook started notifying the affected employees from December 13 after realizing the issue on November 20.

The employee who was robbed is a member of Facebook’s payroll department. Facebook stated that it has taken disciplinary action against the employee, as it is unethical to carry the company’s sensitive information outside the office.

Facebook authorities stated that it’s working with law enforcement to recover the information. The social networking giant also offered affected employees a two-year subscription to an identity theft monitoring service.

Data breach woes for Facebook don’t seem to be ending. Facebook and its subsidiaries like WhatsApp and Instagram faced several security instances in recent years for exposing personal data of its users.

Recently, Facebook admitted a data breach involving 100 third-party app developers who had improper data access. In a blog post, Facebook’s Konstantinos Papamiltiadis, Director of Platform Partnerships revealed that app developers had access to user data such as group member names and profile pictures through the Group API.

Prior to April 2018, app developers had unrestricted access to group members’ information. But with changes made in Group API posts in April 2018, this has changed. The app developers now only have limited access to group information such as group name, number of users, and the content in group posts.

According to Facebook’s new framework designed on the guidelines of their agreement with the Federal Trade Commission (FTC), Facebook is required to conduct timely and scheduled audits of all its products and services for factors such as data breach, privacy adherence, etc.

Google Chrome Introduces Improved Password & Phishing Protection

Google

In a recent update, Google has rolled-out Chrome 79 stable version for its users. This version of Chrome consists of two very important browser security features – Improved password protection and real-time phishing protection.

Malware attacks, data breaches, phishing attacks, are all real-world problems. Fake websites and URL hijacking scams are at their peak especially during the holiday season and convince users to enter their passwords and other sensitive information. With all due diligence, data security is now top priority for the platforms which provide them. Google Chrome has always stressed on built-in safety protections, and now they’re expanding those boundaries.

Compromised Password Warning

Google first introduced password breach warnings as a Password Checkup extension early in the year. Password Checkup compares passwords and usernames of users with Google’s very own database consisting of more than 4 billion compromised credentials known to Google.

According to Google this is how it works:

  • Whenever Google discovers a username and password exposed by another company’s data breach, a hashed and encrypted copy of this data is saved on its servers with a secret key known only to Google.
  • When a user signs into a website, Chrome sends a hashed copy of the entered username and password to Google, encrypted with a secret key only known to Chrome. Absolutely no one, including Google, can derive username or password from this encrypted copy.
  • In order to determine if the username and password has appeared in any breach, Google uses a technique called private set intersection. It involves multiple layers of encryption and compares the encrypted username and password (received from Chrome) with all the encrypted breached usernames and passwords (in Google’s database), without revealing the username and password. Chrome sends a 3-byte SHA256 hash prefix of username to reduce the scale of the data joined from 4 billion records down to 250 records, while still ensuring the anonymity of username.
  • If the username and password have been compromised, Chrome notifies this to the respective user only. Users are strongly recommended to change their password.

Real-time Phishing Protection

Google’s Safe Browsing keeps track of the malicious and potentially harmful sites on the web and shares this information with other browsers, to keep the internet more secure. The refresh rate of this list is 30 minutes. It protects close to 4 billion devices on a daily basis against all kinds of security threats, including phishing.

However, some phishing sites dodge the 30-minute window, either by continuous domain switching or by hiding from Google crawlers. But real-time phishing will now inspect the URLs of pages visited by users with Safe Browsing’s servers in real-time. On visiting a website, Chrome checks it against a list stored in the user’s computer that are known to be safe. If the website is not on this safe-list, Chrome then checks the same URL with Google’s database (after dropping any username or password embedded in the URL) to find out whether the site is malicious or not. Google’s analysis has shown that this results in a 30 percent increase in protections by warning users on malicious sites that are brand new.

Additionally, if this check determines that the site is indeed suspicious or malicious, Chrome immediately shows a warning to change your compromised password. In case the Google Account password was used for Google Chrome login and the same was phished, then Chrome also offers to notify Google as an added layer of protection to ensure user account isn’t compromised.

TrapX Security Appoints Ori Bach as Chief Executive Officer

Cybersecurity firm TrapX Security recently announced that it has named Ori Bach as its new Chief Executive Officer.  Mr. Bach who previously served as TrapX’s Chief Product Officer and EMEA General Manager comes to his new role with more than two decades of senior cybersecurity and high-tech experience in companies such as IBM-Security, Trusteer and NICE-Actimize.

Founded in 2012, TrapX Security is the pioneer in Cyber Deception Technology. The company claims that its DeceptionGrid solution quickly detects, deceives, and defeats advanced cyber-attacks and human attackers in real-time.

Mr. Bach will lead TrapX’s executive management team in scaling the business, expanding its global footprint and accelerating technology innovation designed to help its customers stay ahead of an increasingly complex cyber threat landscape.

“Deception technology has become a cornerstone of achieving cyber-resiliency. TrapX is leading the Deception market with its patented emulation technology. I am looking forward to working with the amazing talent at TrapX as we revolutionize the way that security teams tackle advanced threats,” Bach said.

In July this year, TrapX completed US$ 18 million financing round led by Ibex Investors along with the participation from the existing investors, BRM, Opus Capital, Intel Capital, Liberty Technology Venture Capital, and Strategic Cyber Ventures. The San Jose-based company stated the new proceedings will help to expand the company’s reach globally.

Microsoft Reveals Smart Phishing Techniques of 2019

Phishing, phishing attacks

Security experts said cybercriminals are customizing their Phishing attack methods to trick companies and their users. According to Microsoft, phishing campaigns grew from 0.2 percent in January 2018 to 0.6 percent in October 2019.

In its recently released 2019 Cybersecurity Trends report, Microsoft highlighted that phishing was one of the attack vectors that was rising over the past two years. “In 2019, we saw phishing attacks reach new levels of creativity and sophistication,” Microsoft said.

The tech giant reviewed three of the intelligent phishing attacks it had seen in 2019, which include:

Hijacking Search Results

In this technique, attackers make use of URLs that point to a legitimate source but route to compromised websites that eventually lead to phishing.

How it works

  • Attackers redirect web traffic that was hijacked from legitimate sites to their websites
  • Once the domains became the top Google search result, they send emails to victims linking the Google search result
  • If the victim clicks the Google link, they’ll be taken to an attacker-controlled website, which eventually redirects the user to a phishing site

“Using this technique, phishers were able to send phishing emails that contained only legitimate URLs (i.e., link to search results), and a trusted domain,” Microsoft stated.

Customized 404 Not Found Pages

In this technique, attackers use a custom 404 NOT Found page that’s designed to look like a legitimate Microsoft account sign-in page.

Phishers include URL links that pointed to non-existent pages. When a user accessed the URL, the phishing site redirects them to a phishing page instead of the server’s standard 404 error page.

Detailing the technique, Microsoft said, “A phishing campaign targeting Microsoft uses such a technique, giving phishers virtually unlimited phishing URLs. When Microsoft’s security systems would scan the link, they’d receive a 404-error back (because the link didn’t exist), and Microsoft would deem the link safe.”

Man-in-the-Middle Phishing

 In the Man-in-the-Middle (MitM) technique, users could be tricked by a legitimately looking login page.

“One particular phishing campaign in 2019 took impersonation to the next level. Instead of attackers copying elements from the spoofed legitimate website, a man-in-the-middle component captured company-specific information like logos, banners, text, and background images from Microsoft’s rendering site. The result was the exact same experience as the legitimate sign-page, which could significantly reduce suspicion,” Microsoft explained.

Also, a recent investigation by the Microsoft threat research team revealed that 44 million users were reusing their usernames and passwords. The tech-giant stated it scanned all the company’s user accounts between January 2019, and March 2019. The scanning was performed on a database of around 3 billion leaked credentials, which was obtained from multiple sources like public databases and law enforcement, Microsoft said.

New Ransomware “Zeppelin” Targets High Profiles in Canada and Europe

ransomware, fonix, fonix ransomware, Cybereason Partners with Intel for Hardware-Enabled Ransomware Prevention, Kronos

Security researchers stated that cybercriminals have created a new ransomware variant titled “Zeppelin” to target healthcare and IT companies in the U.S., Canada, and Europe. It’s said that Zeppelin ransomware is reportedly a new variant of the VegaLocker/Buran ransomware.

Background of the Ransomware

According to the BlackBerry Cylance Threat Research team, Zeppelin is the newest member of the Delphi-based Ransomware-as-a-Service (RaaS) family based on the same code and features with its predecessors VegaLocker.

Beginning its journey as VegaLocker, the ransomware was developed on Russian hacker forums under the name Buran, in May 2019. VegaLocker samples were first discovered in a malvertising operation on Yandex.Direct, a Russian online advertising network.

The campaign was aimed at Russian speaking users. Several new versions of VegaLocker ransomware appeared during this year, carrying a different name: Jamper, Storm, and Buran, etc. The latest variant of this ransomware is Zeppelin.

Zeppelin Ransomware

BlackBerry Cylance research team stated that Zeppelin was being used in targeted attacks against healthcare and other IT companies in the U.S., Canada, and Europe. The researchers also said the ransomware also targeted Managed Service Providers (MSPs) to infect customers via management software.

Researchers believed that threat actors have dropped the ransomware through Remote Desktop servers that are online.

“The recent campaign that utilizes the newest variant, Zeppelin, is visibly distinct. The first samples of Zeppelin–with compilation timestamps no earlier than November 6, 2019–were discovered targeting a handful of carefully chosen tech and healthcare companies in Europe and the U.S.,” researchers said.

Injection Process

Once installed, Zeppelin will check the victim’s country code to make sure it’s not running in countries like the Russian Federation, Ukraine, Belorussia, and Kazakhstan.

Depending on the options set during the building process, it will either check the machine’s default language and default country calling code or use an online service to obtain the victim’s external IP address.

The ransomware then starts terminating various processes including ones associated with the database, backup, and mail servers.

While encrypting files, Zeppelin creates ransom notes as “!!! ALL YOUR FILES ARE ENCRYPTED !!!.TXT — You are not able to decrypt it by yourself! The only method of recovering files is to purchase a unique private key. Only we can give you this key and only we can recover your files.”

The notes contain other information about what happened to the victim’s files, and how they could contact hackers for payment methods.

The Three Key Takeaways for Cybersecurity in 2020

RAT, Trojan, Remote Access Trojan

By Lux Rao, Director – Solutions & Consulting, NTT Ltd. (India)

Lux Rao, Director – Solutions & Consulting, NTT Ltd. (India)
Lux Rao, Director – Solutions & Consulting, NTT Ltd. (India)

As enterprises face a barrage of cyberattacks, and the nature of these attacks is growing in sophistication, it is becoming difficult to pinpoint the vulnerabilities. The bad actors are becoming smarter and more coordinated. It has become a very organized industry, even though it is a dark industry. So here are three key aspects that organizations must immediately address as they prepare their cybersecurity strategy for 2020.

Firstly, enterprises need to be in a state of perennial alert. That calls for a set of robust threat intel, with an early warning or an advanced information system.

Whether an enterprise can do it on their own or depend on partners is not even a question. Organizations will have to work with partners who can provide threat intel and secure all flanks for an enterprise.

Secondly, AI and ML-based systems are becoming crucial factors in the evaluation and selection of security solutions. The volume (of attacks) is large, so you need to have not just machine learning, but also a constant learning algorithm that knows what the bad actors are up to, right up to the minute. This mitigates threats or provides early warning to enterprises.

Your partner could analyze threats, and not just for one technology, but for all technologies. The bad actor can enter through any door. If you secure your front door, which is your data center with robust prevention systems, and if you have a vulnerable backdoor, a trojan horse, then even the sensors can become the attack vector.

The third one is interesting. The identity is not limited to only humans now. By 2021 there will be nearly 50 – 55 billion devices and sensors for 7.5 billion people. That’s seven sensors or devices per human being.

So, you need to be looking at identity management not just from a human perspective, but it should identify and secure humans, applications and machines. You need to have one view and you need to monitor that behavior constantly.

The Personal Data Protection Bill, 2019

India’s Personal Data Protection Bill, 2019 is also a progressive move in regulating how a user’s data is protected without compromising data sovereignty. It will represent a huge shift in the way enterprises handle data. Organizations will be expected to overcome several unique regulatory and compliance challenges to meet the requirements of the regulation. This is not seen as a big challenge for implementation as Indian organizations are already very sensitive about security. GDPR was a big movement and it made everyone take security more seriously, but only as “best practices.” There is scope for full compliance and by focusing on the principle of “data protection by design and default,” this Bill will encourage organizations to make privacy and data protection a part of core business values, instead of a casual afterthought.

Since most organisations now will collect, store and process the data within the country to avoid any complications, it will also make India a processing hub. It will also allay data privacy fears, thereby giving us (in India), as well as the global players, the added confidence to actively participate in our growing digital economy.

These are some of the key takeaways, which are very relevant in geographies like India. India’s adoption of the digital twin has been very elementary so far. It is still shaping up, but once it comes into the mainstream, we need to be looking at that as well. It could be a target for attackers.

Disclaimer:  Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.