Home Blog Page 269

6 Times Digital Currency Made Headlines in 2019

Liquid Exchange Hack

By Rudra Srinivas

Since the inception of cryptocurrency (Bitcoin) in 2009, there is a significant evolution of blockchain technology and a variety of challenges as well. Not only investors, but the unique features of cryptocurrency also attracted many eyeballs of cybercriminals.

Numerous hacks and heists were reported on cryptocurrencies, but the Mt. Gox hack claims to be the biggest cryptocurrency attack. It occurred in 2014 which resulted in a theft of around 850,000 bitcoins worth US$ 450 million. It would be a sum of around US$ 7 billion when compared at present rates.

According to a report from the blockchain forensics company CipherTrace, cryptocurrency investors lost US$ 4.4 Billion to digital currency attacks in the first nine months of 2019.

The listicle takes you to the notable cryptocurrency hacks occurred so far in 2019:

 1. Cryptopia

In what was dubbed as the first cryptocurrency hack of 2019, Cryptopia lost nearly 19,390 ETH tokens in the cyber-attack on January 13. Blockchain analytics firm Elementus tweeted that the hackers have cashed out US$ 3.2 million from the stolen tokens. “As of this morning, the hackers have liquidated US$ 3.2m in tokens, with the bulk of that going to Etherdelta,” read the tweet.

According to reports, the hackers have been sending their loot to popular crypto exchanges with Bitbox, Binance, and Huobi seeing the most withdrawal volumes. It is estimated that out of the US$16 million stolen by hackers nearly US$ 900,000 has been withdrawn.

 2. Bithumb

South Korean exchange platform Bithumb once again made it to the headlines in 2019, after discovering a cyber-attack for the third time in the past three years.

In an official statement, Bithumb stated that on March 29, 2019, at around 10:15 p.m. the company detected abnormal withdrawals of its cryptocurrencies from its hot wallets. It’s believed that attackers possibly made off with around 3 million EOS (worth US$ 13.4 million) and 20 million Ripple coins (XRP) worth US$ 6 million.

According to Bithumb, the first hack was happened in July 2017, when hackers stole US$ 7 million in Bitcoin and Ethereum, while the second incident took place in June 2018, when hackers stole 35 billion won (US$ 31 million).

3. Binance

Attackers stole over US$ 40 million worth of Bitcoin from the popular cryptocurrency exchange Binance. The Taiwanese company stated that it discovered the breach on May 7, 2019, at 17:15:24 (UTC), in which hackers illegally obtained over 7,000 Bitcoins by using a variety of attack methods, including phishing, viruses, and other attacks.

It’s said that the intruders also accessed several user API keys, 2FA codes, and other information. Following the hack, the exchange suspended all the operations temporarily and assured that it will refund the affected customers in full.

Later in July this year, a research report from the Cybersecurity and Blockchain company Confirm stated that they’ve discovered certain signs indicating a possible start of transferring stolen funds to Fiat via different cryptocurrency exchanges.

4. BITpoint

July was a terrible month for Japanese exchange Bitpoint as it discovered an unauthorized withdrawal of US$ 32 million from its hot wallet in different cryptocurrencies targeting more than 50,000 users. The exchange stopped operating for a month due to the incident and reopened for business in August.

BITpoint held five cryptocurrencies in its hot wallet: Bitcoin, Bitcoin Cash, Ethereum, Litecoin, and Ripple. However, the company clarified that its cold wallet and cash holdings were not affected in the incident.

5. Coinmama

On February 15, 2019, Coinmama notified its users that it suffered a security breach which affected around 450,000 users’ emails and hashed passwords. The company stated that unknown intruders compromised customer data and put it out for sale on a dark web registry.

The exchange revealed the compromised data belonged to users who registered until August 05, 2017. Coinmama also explained the security issue affected 30 companies and a total of 841 million user records.

6. Upbit

Upbit is the latest hacking victim in the list. The South Korean cryptocurrency exchange informed its customers that 342,000 in Ethereum (approximately US$ 49 million) had been stolen on November 27, 2019, from its hot wallet. Upbit said an abnormal transaction by intruders transferred the stolen Ethereum from its hot wallet to an unknown wallet address. The exchange suspended all its deposit and withdrawal services for two weeks.

All these hacks represent the massive risks that exchanges, and its users take with their cryptocurrency wallets.

And we do not know what the year 2020 will bring!

Rudra Srinivas is part of the editorial team at CISO MAG and writes on cybersecurity trends and news features. 

Data in the Cloud is Much More at Risk Than Enterprises May Think

Nanocore Netwire AsyncRAT, Cloud security, cloud computing

By Venkat Krishnapur, Vice-President of Engineering and Managing Director, McAfee India

Cloud computing has become near-ubiquitous, with India’s cloud market poised to reach over US$7 billion by 2022. The use of cloud services has empowered organizations to accelerate their businesses with more agile technology at moderate costs. Cloud is making IT more strategic than ever and companies are structuring themselves around the rapid transformation, growth and agility the cloud delivers.  However, this rapid migration is also presenting complexities and risks that few businesses are equipped to deal with, and the security of data has taken center stage. While cloud providers are enabling more security than ever before, there are aspects of Security that they do not cover, and it becomes the responsibility of the users to ensure those are mitigated.

The data dilemma

While it’s true that sensitive data can be stored safely in the cloud, this is not an inevitable conclusion. According to the McAfee 2019 Cloud Adoption and Risk Report, 21 percent of all files in the cloud contain sensitive data and sharing of sensitive data in the cloud has increased by more than 50 percent. While most of this data is stored in well-established enterprise cloud services such as Box, Salesforce, and Office365, it’s necessary to realize that none of these services guarantee 100 percent safety.

Irrespective of how robust your threat mitigation strategy is, the threat rates are too high to have a reactive approach. Access control policies must be ascertained and enforced before data ever enters or exits the cloud.

Think of it this way–just as the number of employees who require the ability to edit a document is much smaller than those who need to view it, it is likely that not everyone who needs to access certain data needs the ability to share it. Examine all permissions and access the context associated with data in the cloud environment. Control who has access. Access management requires three capabilities: the ability to identify and authenticate users, the ability to assign users’ access rights, and the ability to create and enforce access control policies for resources.

Large institutions that have a range of data, including sensitive consumer data to protect, and many cloud solutions to choose from, must balance potential benefits against risks of breaches and access integrity. What many organizations fail to realize when moving to the cloud is, to what extent they are responsible for securing their own cloud environment. Cloud providers (vendors) secure the infrastructure but securing data, and applications are all the responsibility of the cloud customer.

The Responsibility Equation

When it comes to security, CISOs are speculating if external providers can protect their sensitive data, while also ensuring compliance. There exists a misconception that the Cloud Service Provider is responsible for securing the cloud environment. This is where shared responsibility comes into play. In simple terms, this means that the organization and the vendor split responsibilities for cloud deployment. While the vendor may handle everything from physical networks, servers, and storage to operating systems, and even applications, but the organization will need to be responsible for the rest. In reality, no matter what level of service the vendor offers, the organization is ultimately responsible for the security and compliance of cloud deployment.

As it is with all aspects of cloud, responding to security incidents is also a shared responsibility. CISOs must learn to collaborate effectively with the Cloud Service Provider, to examine and respond to potential security occurrences. To collaborate effectively, they need to understand what information the vendor can share, and the limits within which they can assist.

Companies that are fulfilling their shared responsibility by securing their data are assuming substantially more benefits than those who aren’t taking data protection into their own hands. There are ways and means of mitigating security risks and the cloud is a feasible alternative for enterprises; the advantages from cloud-managed services far outweigh concerns.

Organizations need to regularly assess the security posture of their cloud environments, and that of their vendors, suppliers, partners all third parties. The Verizon breach is a fine example where the vendor’s mistake turns to be the organization’s headache. The shared security model exists for a reason. No matter who is responsible for the security of the cloud data, the organization is eventually responsible for what happens to their data.

CASB – a key enabler

Cloud access security brokers (CASBs) are on-premise or cloud-based security nodes, that sit between cloud service consumers and cloud service providers, to enforce security and compliance for cloud applications. These help organizations extend the security controls of their on-premises infrastructure to the cloud.

CISOs need to evaluate the full risk landscape in their on-premise and externally hosted cloud environments that can compromise security. Think of them this way–they act as central data authentication and encryption hubs for both cloud and on-premise applications, accessed by all endpoints, including personal devices like smartphones and tablets. CASBs are an essential element of a cloud security strategy, that helps organizations govern the use of cloud and protect sensitive data. These implement security procedures like authentication, authorization, encryption, device profiling, alerting and anomaly detection/prevention.

By using CASBs, organizations can:

  • Evaluate and select cloud services that meet security and compliance requirements
  • Identify what Shadow IT cloud services are being employed, by whom, and what are the risks they pose to data
  • Identify potential misuse of cloud services, including both activity from insiders as well as third parties like external service providers
  • Protect enterprise data in the cloud by blocking certain types of sensitive data from being uploaded, encrypting and tokenizing data
  • Enforce varying levels of data access and cloud service functions based on a user’s device, location, and OS 

Conclusion

Technology has come a long way since the dawn of computing that included conventional ways of data management. Today, cloud computing is revolutionizing the IT industry, shaking up the business landscape, and pretty much everything else it touches. Although migration to the cloud is helping CIOs in their digital transformation journeys, hastily jumping into it without the necessary maturity can throw all their efforts out of the window.

While the business advantage of cloud usage is significant, this rapid migration is also introducing complexities and risks that most organizations don’t have provisions to deal with. If properly addressed, these issues will not hinder your IT roadmap and data doesn’t have to remain anchored on-premise. The future of cloud rests upon introducing industry standards, that will help address regulatory, management and technological matters.

The stronger your cyber defenses are, the better you are at reducing the risk and the impact when something happens.

Disclaimer: CISO MAG does not endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. Views expressed in this article are personal.

RIplace – A Security Evading Ransomware Technique

ransomware, fonix, fonix ransomware, Cybereason Partners with Intel for Hardware-Enabled Ransomware Prevention, Kronos

Nyotron’s research team has discovered a new ransomware technique that goes undetected in most antivirus, anti-ransomware and Endpoint Detection and Response (EDR) solutions. The researchers have named it “RIplace”, as it bypasses latest security products by replacing all sensitive files on victim’s machine.

What’s different in RIplace Ransomware Technique?

Generally, all ransomwares follow a similar flow as shown below.

Ransomware-Flow

But the RIplace technique is different when it comes to the last step. It creates a new encrypted file and replaces both, the original and sensitive data files using the Rename request (specifically, IRP_MJ_SET_INFORMATION with FileInformationClass set to FileRenameInformation). The Rename operation is used widely by Microsoft and other security vendors to call filter drivers. If prior to calling Rename, DefineDosDevice (a legacy function that creates a symlink) function is called, then an arbitrary name can be passed as the device name, and the original file path, as the target to point on.

The RIPlace discovery team further stated that “the callback function filter driver fails to parse the destination path when using the common routine FltGetDestinationFileNameInformation. It returns an error when passing a DosDevice path (instead of returning the path, postprocessed); however, the Rename call succeeds. “

Riplace Ransomware Flow

Using this technique, it is possible to maliciously encrypt files and bypass antivirus/anti-ransomware products that do not properly handle IRP_MJ_SET_INFORMATION callback.

Nyotron Raises the Red Flag

Nyotron told BleepingComputer that they tested RIPlace technique over a dozen vendors including Microsoft, Symantec, Sophos, McAfee, Carbon Black, Kaspersky, Trend Micro, Cylance, SentinelOne, Crowdstrike, PANW Traps, and Malwarebytes. They have followed the responsible disclosure policy by informing Microsoft and other security vendors and all relevant law enforcement and regulatory authorities.

Nyotron also released a demo video of the RIPlace evasion technique with Windows Controlled Folder Access (CFA) and announced a free testing tool any organization can download to check its systems.

Singapore to Adopt New Data Protection Measures

Singtel data breach

In order to boost cybersecurity and tackle next-generation cyber threats, the Singapore government decided to adopt new data protection measures. The government also established a committee, named Public Sector Data Security Review Committee, to review its data security practices.

The latest move comes after a series of cyber-attacks on public and private organizations in the country.

As per the reports, the newly established committee inspected around 336 network systems across 94 government agencies and observed international data security practices in the financial and healthcare sectors.

The committee, which is chaired by the Minister-in-charge of Public Sector Data Governance, Teo Chee Hean, suggested five recommendations to better protect citizens’ data. 

The five recommendations from the committee include:

  1. The need to enhance technology and processes to safeguard data against threats.
  2. Building data security competencies and training all public officers on data security.
  3. Improving the Government’s expertise in data security technology.
  4. Amending the Personal Data Protection Act to cover third-party vendors handling Government data.
  5. Improving the accountability and transparency of the public sector data security regime.

The government has accepted the committee’s proposals and aims to implement them by the end of 2021.

In his response to the Committee, Prime Minister Lee Hsien Loong said, “The Government accepts all the recommendations by the Public Sector Data Security Review Committee to secure and use data and digital solutions to deliver better services and policies for Singaporeans.”

PM Lee also said, “Data is the lifeblood of the digital economy and a digital government. We need to use and share data as fully as possible to provide better public services. In doing so, we must also protect the security of the data and preserve the privacy of individuals, and yet not stifle digital innovation. This is especially so in healthcare, but it is true of every other field of government too.”

Recently, Singapore and the United Kingdom joined hands to promote user “Security by Default” in both countries. According to the official report, the Chief Executive of the UK’s National Cyber Security Centre, Ciaran Martin, and Chief Executive of Singapore’s Cyber Security Agency, David Koh, signed a joint statement on cooperation between Singapore and the United Kingdom on the Internet of Things.

Both countries agreed to work together on areas of common interest, including alignment, cooperation, and coordination to support the cause “secure by default.” The Singapore-UK strategic alliance is intended to drive improvements in the security of smart consumer devices.  The agreement also accelerates the IoT industry to grow and innovate.

Statinko Botnet Uses YouTube as a Gateway for Cryptomining

Hackers Selling Stolen YouTube Credentials on Dark Web: Report

Statinko Botnet has been around since 2012 and has kept evolving. The latest addition to its wide portfolio of malicious activities like click fraud, ad injection, social network fraud and password-stealing attacks, is Cryptomining. According to the researchers at Slovakian software security firm, ESET, Statinko is capable of installing crypto malware on victims’ devices using YouTube.

Stantinko’s Cryptomining Module

Researchers found that Stantinko’s cryptomining module, exhausts most of the resources of the compromised machine by mining cryptocurrency using a highly modified version of the xmr-stak, an open-source cryptominer. Also, all unnecessary strings and whole functionalities are removed in attempts to evade detection.

Use of YouTube in Cryptomining

As mentioned earlier, Stantinko is constantly developing and improving its existing custom modules. This is evident from the fact that CoinMiner.Stantinko doesn’t communicate directly with its mining pool but uses proxies whose IP addresses are acquired from the description text of YouTube videos.

The description of such a video consists of a string composed of mining proxy IP addresses in hexadecimal or enclosed in “!!!!” format. This simplifies the process of parsing and prevents possible changes in the HTML structure of the YouTube video turning the parser, dysfunctional.

YouTube has now taken down all the channels containing these videos after the ESET researchers informed the video-sharing platform of the abuse.

Statinko Botnet’s Cryptomining Prowess

ESET has briefly described the cryptomining abilities of Statinko Botnet. It said, “The main part performs the actual cryptomining; the other parts of the module are responsible for additional functions such as:

  • Suspending other (i.e. competing) cryptomining applications.
  • Detecting security software.
  • Suspending the cryptomining function if the PC is on battery power or when a task manager is detected, to prevent being revealed by the user.”

Stantinko botnet has typically targeted users in the Soviet countries of – Russia, Ukraine, Belarus and Kazakhstan. It is still active, and, with the wide outreach of YouTube, this botnet has the capability of spreading like wildfire in other parts of the globe.

A McAfee Labs Threats Report revealed that the cybercriminals were generating 480 new threats per minute. It also highlighted that the IoT malware had increased to 73 percent, while the cryptocurrency mining malware was up to 71 percent in the third quarter of 2018.

“The variety of endpoints presents great challenges at many levels”

Rajesh Ganesan, Vice President, ManageEngine

Rajesh Ganesan, Vice President, ManageEngine has been associated with Zoho Corporation for over 22 years and is currently is the Vice President for ManageEngine, the IT management division of Zoho Corporation. He brings in more than two decades of experience in building products in the areas of telecommunication, enterprise IT management, and enterprise IT security. At ManageEngine, he is responsible for all business operations for Products – Defining, Developing, Delivering, Marketing, and Selling software products for identified viable markets.

In an exclusive email interaction with Brian Pereira of CISO MAG, Rajesh talks about the security challenges in managing endpoints and the right strategies to counter these challenges.

What is the challenge that CISOs and CIOs face today when it comes to managing endpoints? Is the challenge primarily about the visibility of the endpoints? How can they counter the challenges?

The variety of endpoints that the businesses have at their disposal to bring about productivity benefits presents great challenges at many levels. First, as the endpoints freely move across the corporate-governed network boundary, they become a primary vector for external attacks that are targeting access to critical internal resources. An endpoint used by a privileged but unassuming user can get infected with malware, which could then become the vector for external attacks when the users get back into the company network. Attackers can then execute command and control attacks leveraging the privileges of the user.

Second, is the case of dealing with the far greater menace of insider attacks, as endpoints tend to be the easiest medium to leak critical data. An attack like data exfiltration can be camouflaged as a normal activity, by leaking small amounts of information through multiple endpoints and assembling them later to get the entire data set. Or it could be simple cases of doing a print screen of sensitive data or downloading an attachment into a cloud service.

While the IT and IS leadership must build multiple layers of protection for securing endpoints, a common thread across many security incidents is how the privileges are defined and handled. This is strictly defining, enforcing, and monitoring the privileges for users to access the endpoints and the resources within, and also for the applications that run on those endpoints. For example, the privileges of a user could dynamically change depending on their location. They could have the highest privileges while in the office, moderate privileges while working from home, fewer privileges within the city of work, and minimum privilege outside the user’s usual region. Hence, privileged access management, which is “governing who has what kind of access to what resources for what reason and who approved the access” is fast becoming a top priority area for IT and Infosec leaders.

How does the PAM360 solution address this challenge?

Securing endpoints has to be done at many layers and PAM360 focusses on the privileged access management part. This is basically providing a holistic way for governing and managing “who has access to what endpoints for doing what operations, and who approved the access, and what do they do with the access.” While this sounds simple at the surface level, a lot goes inside to implement and run an effective privileged access management program. Each aspect mentioned needs a thoughtful definition of policies, processes, procedures, and controls implemented through a tool.

For example, to ascertain all the information access a user has, there must be a defined list, which includes systems and applications, types of roles, types of access, duration of access, and mechanisms to grant and revoke access. The same goes for controlling what actions a user can perform after getting access.

And speaking of users, they are not just employees within the organization. They could also be customers, partners, contractors, temporary workers, or others whose access to information needs to be managed. A contractor may not even need full-time access to all systems but just for a period of 30 minutes to get her job done. Yet, that access needs to be managed and monitored. Different tools exist to focus on specific aspects of privileged access, but PAM360 unified them all and provides one complete solution with which enterprises can implement a holistic program, regardless of the type of the endpoints.

What are the risks faced today, with regard to privileged accounts?

A primary risk with privileged accounts is they come with very high privileges but very little accountability. Most privileged accounts are system defaults like “administrator” and “root” without any explicit association with a human user. This leads to privileged accounts getting shared with whoever requires privileges for a certain period of time, but that poses a risk of anyone getting hold of the credentials to immediately inherit the privileges.

Because they are system defaults and are shared, often the credentials are not randomized periodically. This presents a huge risk of brute force attacks succeeding against these accounts and breaking one could open the floodgates.

When there is no proper monitoring of who has access to the credentials, there is a huge risk of the enterprise never being able to reconcile who performed a particular operation, especially malicious ones. And even when the access is controlled and monitored, unless the privileged actions performed are continuously monitored, malicious users can plant malware or logic bombs in software that manifest much later, obscuring all association of that particular user.

In the age of cloud and DevOps and IoT, many system and software components talk to each other and invoke actions across the network, and this access needs credentials. Often, the credentials are loosely stored or hardcoded in scripts and programs, leaving them open to anyone with access.

Why are legacy solutions inadequate to address today’s risks?

An effective privileged access management solution is not standalone but one that integrates with every component in the infrastructure. Legacy solutions often lack this support, especially when it comes to cloud, DevOps, RPA, and IoT. When it comes to cloud for instance, the requirements are elasticity and scalability as the number of managed endpoints could be large and dynamically changing. For DevOps, the requirements would be agile and velocity, in terms of how many operations per second the solution can perform. The rapidly changing requirements present lots of challenges, and the legacy solutions simply are not architected for today’s technologies and infrastructure.

Brian Pereira is the Principal Editor of CISO MAG. Apart from his editorial responsibilities, he enjoys writing features, interviews and technical articles.

Adobe Discloses Data Breach that Impacted Magento Marketplace Users

Panasonic network breach

Adobe, a provider of multimedia and creativity software products, recently disclosed a security breach that impacted users of its Magento Marketplace.

Magento Marketplace is an online portal for buying, selling, and downloading themes and plugins for Magento-based online stores.

In a notification sent to its customers, the company stated that a security vulnerability in Magento’s website allowed unknown intruders to access registered users’ account information. It’s unclear when the attackers exploited the vulnerability, but the company’s security team said they discovered the intrusion on November 21, 2019.

The exposed information included usernames, email addresses, store usernames (MageID), billing and shopping addresses, phone number, and limited commercial information. However, the company clarified that account passwords and financial data were not exposed in the incident.

“On November 21, we became aware of a vulnerability related to Magento Marketplace. We temporarily took down the Magento Marketplace in order to address the issue. The Marketplace is back online. This issue did not affect the operation of any Magento core products or services,” the company said in a statement.

“We have notified impacted Magento Marketplace account holders directly. We take these issues seriously and are committed to helping ensure our platforms are secure. We are reviewing our processes to help prevent these types of events from occurring in the future,” the statement added.

In a recent security incident, Adobe mistakenly exposed around 7.5 million user account details. This vulnerability was brought to light by Security Researcher and Consultant Bob Diachenko and reported in the press by Paul Bischoff Tech Journalist, Privacy Advocate and VPN Expert from Comparitech.

As per Adobe’s whitepaper, most components of Creative Cloud are hosted on Amazon Web Services (AWS) which include Amazon Elastic Compute Cloud (Amazon EC2) and Amazon Simple Storage Service (Amazon S3). The Elasticsearch database is used to store, search, and analyze large volumes of data in near real-time. Diachenko’s analysis spotted that this Elasticsearch database was left exposed as there was no password protection provided for it.

China Closes 173 Cryptocurrency Exchanges and Token-Issuing Platforms

Chinese Government Shuts 173 Cryptocurrency Exchanges

The Chinese government has reportedly shut down almost all the cryptocurrency exchanges and token issuing platforms that are operating within the country. The move was taken in order to tighten its grip over the financial industry in the country.

The shocking news came to light after the Chinese blockchain outlet CnLedger stated that “the 173 Chinese virtual-currency trading and token issuing platforms have all exited without risk,” referring to the People’s Bank of China (PBoC) Financial Stability Report (2019).

According to the PBoC’s Financial Stability Report, the country is going to eliminate “Unlicensed payment” businesses, which include online lending institutions and other financial companies.

“Some long-term accumulated deep-seated contradictions in the Chinese economy are gradually exposed, financial risks are prone to occur, and economic growth is facing more difficulties. From an international perspective, the possibility of “peaking down” in world economic growth has increased, and unilateralism and protectionist sentiment have increased worldwide, financial markets are highly sensitive to the trade situation, and uncertainty about global liquidity conditions has increased,” the report stated.

A wide range of uncoordinated laws and regulations governed the Internet in China.

Recently, China passed a new law on cryptography to ensure the security of cyberspace and information in the country. This paves the way for the country to release its own digital currency, which is aimed at cutting costs of circulating paper money and to help policymakers control the money supply.

The new cryptography law, which comes to effect on January 1, 2020, is designed to assist the development of the cryptography business and enhancing the security of cryptocurrency.

In 2014, China’s Central Bank set up a research team to work on its digital currency to cut the costs of traditional paper money and to control the money supply. The new digital currency can be used across major payment platforms like WeChat and Alipay, according to the Central Bank.

Firefox 72 to Block Fingerprinters by Default

Mozilla-Firefox

Mozilla is all set to launch its Firefox 72 nightly (beta) version in the first week of December followed by Firefox 72 stable release on January 7, 2020. In a bid to improve its Enhanced Tracking Protection feature and provide more control to its users, Firefox is now planning to, by default block the Fingerprinters in this version.

What is Fingerprinters?

Human fingerprints are unique and the same implies to fingerprints in the virtual world. A digital fingerprint is a unique set of information that can be used to detect software, network protocols, operating systems or hardware devices of a certain user.

Fingerprinting is an art of using this information to correlate with data sets and identify high probability—network services, operating system number and versions, software applications, databases, configurations and more. Unlike cookies, Fingerprinters collect data without user consent. A penetration tester with apt amount of fingerprinting data can define an exploit strategy against the target. Fingerprinting can also be misused for data mining, as seen in the case of Cambridge Analytica. Thus, this leads to the question, “Can we protect our user’s digital privacy?” Firefox says, “Yes. We can, through Enhanced Tracking Protection.”

Firefox’s Enhanced Tracking Protection

Enhanced Tracking Protection in a literal sense acts as a shield for the users. It helps in protecting them from ad and analytics, cryptomining and fingerprinting trackers. Earlier, with the release of Firefox 70, a provision was made for users to block the Fingerprinters manually under Custom Content Blocking section on its Privacy & Security tab. Once enabled, Firefox blocks any scripts that have been identified by Disconnect to participate in cryptomining or fingerprinting.

Firefox’s “Strict” and “Custom” presets already included protection against Fingerprinters ever since. But now it plans to make Fingerprinters blocking a default feature in “Standard” preset as well. When Enhanced Tracking Protection is active, a shield icon appears in the address bar. Its color indicates whether a site has active trackers such as:

  • Blue shield: the site has trackers that are being blocked.
  • Black shield: protection is on but there are no trackers present on the site.
  • Cross-out shield: protection is off for a specific site.
  • No shield: protection is off across all sites.

Although enabling Fingerprinters restricts user data mining, it could also cause issues like erroneous page display, trouble interacting with the website utilizing them, and so on.

In a recent news, Mozilla announced that it has doubled the rewards for its bug bounty program. It said: “To celebrate the 15 years of the 1.0 release of Firefox, we are making significant enhancements to the web bug bounty program. We are doubling all web payouts for critical, core and other Mozilla sites as per the Web and Services Bug Bounty Program page”

This Tool Predicts Cybercriminal Activity Even Before It Happens

Group-IB’s Graph Network Analysis tool

Group-IB, an international cybersecurity company that specializes in preventing cyberattacks, has launched a new tool for clients, which helps to predict and attribute attacks, even before they can occur. The Singapore-based company has granted its clients access to its internal tool for graph network analysis, which is capable of identifying links between scattered data, attributing an attack to a specific hacker group in seconds, as well as examine and predict possible threats that are relevant to a particular organization or industry.

Group-IB’s patented graph network analysis technologies are integrated in the company’s products, namely Threat Intelligence, Threat Detection System, Secure Bank, and Brand Protection Service. The company’s decision to make its internal tool available to clients aims to help SOC and CERT analysts, threat intelligence experts and forensic researchers explore the tactics and infrastructure of the attackers, while at the same time improving their own cybersecurity systems and boosting their threat hunting skills.

Group-IB graph network analysis was designed based on indicators of compromise found during years of cybercrime investigations, incident response operations and malware analysis by Threat Intelligence and Threat Detection System. The historical data on cybercriminals, gathered in 16 years, includes billions of records from domain names, IP addresses, server digital fingerprints, which have been used in attacks, as well as tagging them to specific hackers or groups.

“It is nearly impossible to protect oneself against attacks and prevent possible damage without knowledge of their enemies,” commented Dmitry Volkov, Group-IB CTO and Head of Threat Intelligence. “We had considered dozens of graph network analysis providers before deciding to develop our own instrument. We did not find a single solution that met all our requirements. None of the graphs had the entire scope of historical data: domains, Passive DNS, Passive SSL, DNS records, open ports, services running on ports, and files that have connections with domain names and IP addresses. We started gathering such data records ourselves, updating them on an ongoing basis, with some of them covering a period of 15 years. We also did not like the fact that other solutions provided options only for manual graph creation, therefore, we built our graph to be completely automated. To tackle the problem of irrelevant links that is common for other products, we have taught our system to identify irrelevant links based on the logic of our experts who did it previously in manual mode. The main goal of our graph is threat hunting, the most accurate attribution and the deepest analysis of adversaries. This instrument is now available in our products.”

How Graph Network Analysis helps

Group-IB’s graph network analysis leaves unverified indicators of compromise behind and focuses on the attacker examination and threat management that are relevant to a particular business area. Analysts using Group-IB graph network analysis can type a suspicious domain, an IP address, email or SSL certificate fingerprint in the search bar, after which the system automatically creates a network graph based on the search element that shows linked domains, IP addresses, digital fingerprints and etc. Despite the fact that the majority of attackers – specifically cybercriminal and APT groups – try to remain undetected online, the majority of them have paid much less attention to their anonymity and operational security and resulting have made mistakes at the beginning of their criminal journey.

Graphs help to identify not only linked elements but also common features – patterns that characterize one specific cybercriminal group to another. The knowledge of such unique features helps to identify the elements of the attackers’ infrastructure at the attack preparation stage even without evidence confirming the attack such as phishing emails or malware.

For example, in December 2018, Cobalt hacker group, which is known for targeting banks, sent out emails disguised as the National Bank of Kazakhstan. If cybersecurity experts, for example, had not found the phishing emails and did not have an opportunity to carry out the comprehensive analysis of malicious files, they could have created a graph based on the malicious domain nationalbank[.]bz, used by the cybercriminals. The created graph would have immediately shown the links to other malicious domains and Cobalt cybercriminal group, revealing what files have already been used in earlier attacks.

Group-IB’s Graph Network Analysis tool

When Group-IB investigates phishing attacks, the activities of fake or pirate web sources, the company’s experts normally create graphs to identify linked web sources and check all the found hosts for analogous content. This enables Group-IB to find both old phishing pages, which remained active but undetected, and absolutely new phishing pages, which were created for future attacks and were not utilized so far.

Moreover, the graph network analysis is indispensable in searching for backends: 99 percent of cardshops, hacker forums, numerous phishing resources and other malicious servers are hiding both behind their own proxy servers and legitimate ones. The knowledge of the real location of a malicious server helps to identify the hosting service and create links to other malicious projects of the threat actors.

About Group-IB

Group-IB is a Singapore-based provider of solutions aimed at detection and prevention of cyberattacks, online fraud, IP protection and high-profile cyber investigations. Group-IB’s Threat Intelligence system has been named one of the best in class by Gartner, Forrester, and IDC. Group-IB’s technological leadership is built on the company’s 16 years of hands-on experience in cybercrime investigations around the world and 60 000 hours of cyber security incident response accumulated in one of biggest forensic laboratory and a round-the-clock center providing a rapid response to cyber incidents—CERT-GIB. Group-IB is a partner of INTERPOL, Europol, and has been recommended by the OSCE as a cybersecurity solutions provider.

Group-IB’s experience, threat hunting & intelligence have been fused into an ecosystem of highly sophisticated software and hardware solutions designed to monitor, identify, and prevent cyber threats.