Home Blog Page 271

Researchers Found New Banking Malware “Ginp”

BotenaGo, malware over encrypted connections

Researchers exposed a new form of banking malware named “Ginp” targeting Android users. According to specialists from ThreatFabric, attackers use Ginp malware to steal users’ bank credentials, messages, and credit/debit card details, focusing on the Spanish banks’ customers.

ThreatFabric stated the malware, which was first identified by Tatyana Shishkova from Kaspersky in October 2019, is still active with five different versions of the Trojan released in the last 5 months (June – November 2019).

It’s said that Ginp was built from scratch and included a code copied from the infamous Anubis banking Trojan.

How it works?

When the malware is injected on the device it will start by removing its icon from the app folder. It will then ask the victim for the Accessibility Service privilege. Once the user grants the requested Accessibility Service privilege, Ginp grants itself additional permissions required to send messages and make calls, without the victim knowing.

“The most recent version of Ginp has the same capabilities as most other Android banking Trojans, such as the use of overlay attacks, SMS control and contact list harvesting. Overall, it has a common feature list, but it is expected to expand in future updates. Since Ginp is already using some code from the Anubis Trojan, it is quite likely that other, more advanced features from Anubis or other malware, such as a back-connect proxy, screen-streaming and RAT will also be added in the future,” ThreatFabric said in a statement.

According to ThreatFabric, Ginp embeds a set of features, which include:

  • Overlaying: Dynamic (local overlays obtained from the C2)
  • SMS harvesting: SMS listing
  • SMS harvesting: SMS forwarding
  • Contact list collection
  • Application listing
  • Overlaying: Targets list update
  • SMS: Sending
  • Calls: Call forwarding
  • C2 Resilience: Auxiliary C2 list
  • Self-protection: Hiding the App icon
  • Self-protection: Preventing removal
  • Self-protection: Emulation-detection

Security pros opined that Ginp is an efficient banking Trojan used to trick victims into delivering sensitive information. “Ginp’s unusual target selection is not just about its focus on Spanish banks but also the wide selection of targeted apps per bank. The fact that the overlay screens are almost identical to the legitimate banking apps suggests that the actors might be very familiar with the Spanish banking applications and might even be accustomed to the language,” ThreatFabric added.

Victim of Hakbit Ransomware? Don’t Pay for it

Ransomware, supply chain and ransomware

Are your files infected by Hakbit Ransomware? Yes. But don’t worry. Emsisoft, a specialized cybersecurity company has released a decryptor for your assistance.

As per Emsisoft, Hakbit Ransomware encrypts its victims’ files using AES-256 (AES stands for Advanced Encryption Standard) and appends the encrypted files with the extension “.crypted”. AES is a symmetric key cipher. This means the same secret key is used for both encryption and decryption, and both the sender and receiver of the data need a copy of the key. The advantage of symmetric systems like AES is their speed. Because a symmetric key algorithm requires less computational power than an asymmetric one, it’s faster and more efficient to run.

Once installed, Hakbit hides itself by randomly naming its executable to one of the following: lsass.exe, svchst.exe, crcss.exe, chrome32.exe, firefox.exe, calc.exe, mysqld.exe, dllhst.exe, opera32.exe, memop.exe, spoolcv.exe, ctfmom.exe, or SkypeApp.exe.

Hakbit has a distinguishing feature that has not been seen in any ransomware until now. Once the files are encrypted, the victim’s desktop image is replaced with a ransom note that also includes a QR code, leading the victim to the bitcoin wallet address, where the ransom is to be deposited. We would like to believe that truly this is a first of its kind and the victim’s convenience has been given top priority.

Emsisoft’s Hakbit Ransomware Decryptor Tool

Although breaking AES-256 encryption is a difficult and tedious process, Emsisoft has found a solution to the Hakbit Ransomware attack. They have created a decryptor tool which is available for free on Emsisoft’s official website. Emisoft says, “Regardless of what the Hakbit ransom note might say, our decryption tool can help you recover your files for free. Support for this tool is provided by the experts at Bleeping Computer.”

Ransomware attacks have seen a steep rise in the recent past. Attackers have started targeting government organizations and larger companies having bigger clusters of networks and computers rather than individual machines.

Very recently, the Louisiana state government fell victim to a ransomware attack that took down its IT systems and websites. Governor John Bel Edwards confirmed the damages of the attack by tweeting,” The attack impacted the public state government’s email, website, and other online applications.”

The ransomware attacks are not just limited to the U.S. government. In another incidence, the Government of Nunavut fell victim to a sophisticated ransomware attack. “All government services requiring access to electronic information stored on the Government of Nunavut (GN) network are impacted, except Qulliq Energy Corporation,” said the Premier of Nunavut, Joe Savikataaq.

“It’s a war and the well-prepared one will win”

Ahmed Nabil has more than 17 years of experience in the field of Information Technology/Systems, Infrastructure, Project Management, Information Security, Application development/Automation, and IT management. He holds several professional IT certifications from Microsoft, Cisco, ISACA, ISC2, PMI, CWNP, PECB, and EC- Council. Ahmed is an industry expert in Information Security and Digital Transformation, a public speaker at several international conferences (Microsoft Ignite the Tour, ITCamp Cluj, CISO Africa Summit, Egypt CSCAMP, SharePoint Saturdays, CloudWeekend, etc.

Ahmed is currently the Global Senior Information Technology and Security Architect Lead at one of the top Oil & Gas companies in the world. He was awarded the Microsoft Most Valuable Professional Award (MVP) in Enterprise Security/Cloud and Data Center Management for seven years in a row from 2013 to 2020,  for his exceptional knowledge sharing and community leadership in Egypt and the Middle East Region. Ahmed received the MESA CISO 100 Award from the MESA conference held in Dubai for the top CISO executives in the Middle East and was a finalist in EC-Council CISO awards 2018 (Atlanta, U.S.). He was recently selected as a member of the EC-Council CCISO advisory board due to his Industry standing and deep experience.

 In an exclusive interaction with Augustin Kurian of CISO MAG, Ahmed talks about his journey, threats lurking around cyberspace directed at the Oil & Gas industry, and his tips for aspiring cybersecurity professionals.

You had a stint in the North Africa region before moving to the Middle East, and that makes you a cybersecurity expert in the MENA region. Can you tell us how the Middle East differentiates from North Africa with regard to cybersecurity? Also, tell us how alike are these two regions?

I think in general the MENA region is becoming more vulnerable to security threats and attacks nowadays. While most of them are for-profit or for preventing companies to achieve their goals, we can find several attacks are political in nature, and that’s what might differ between both the Middle East and North Africa.

The Middle East is moving in more digital initiatives supported by Governments and the private sector, while in North Africa, its mainly focused on the private sector. Cybersecurity will differ from one country to another depending on the economy that differs between each one. Another interesting point is that the North Africa region, and due to limited budgets, went to developing their own internal security software, which can be an added value by saving cost, driving the country economics and controlling their security posture–or might raise some other risks if it’s not mature enough.

Other differences will stem from the societal influences that drive each of these regions.

You are currently the Global Senior Information Technology and Security Architect Lead at one of the top Oil & Gas companies in the world. You are in a space that is currently at the epicenter of cyber-attacks as well as physical attacks. How many espionage attacks from both business as well as state-sponsored attacks do you handle on a month?

Oil & Gas industry is leveraging technology and adopting different transformation projects which made it prone to cyber threats. The recent cyber threats caused significant disruptions to different energy, utilities, oil & gas organizations across the globe.

Typical Operations (SOC – Security Operations Center) will receive many attacks per month depending on the organization’s name, reputation, size, and exposure. Economic and political factors play a great role as well. Many of these attacks are targeted kind of threats.

The attack number is not what is received but rather what successfully penetrated the environment, which sometimes is not known. It’s very critical nowadays to have a solid 24×7 SOC team applying the latest technological advances such as artificial intelligence and machine learning. It’s a war and the well-prepared one will win.

Has there been a shift between the way attacks have been perpetrated towards Oil & Gas companies? Tell us a bit about the new trends in this space.

New technologies and trends are introduced to the Industrial and Oil/Gas sectors. A lot of companies are embracing these technologies like IoT and new industrial devices.

Defending against emerging attacks, such as industrial attacks and IoT is new and sometimes unknown to traditional security professionals, and that’s why new ICS and OT security professionals are introduced in the market. Generally, corporates should have the agility in their operations to apply it in all security processes. This works hand-in-hand with a good governance process ensuring security is part of any business system or application or process.

Tell us a bit about the need for clubbing cybersecurity with physical security in an industry like Oil & Gas corporations.

The fact that we are currently witnessing low oil prices mandated most of the Oil & Gas companies to think and adopt digitization across their companies, raising up more issues for cybersecurity.

A big problem will be focusing only on new technologies and logical control while ignoring other physical problems. Remember most of Oil & Gas sites and facilities are critical infrastructure assets for their countries. We should never forget that one of the main security principles is a defense in layers.

Responses to cyber-attacks must be multilayered, this includes Physical, technical and advanced and emerging threat vectors. Security should be integrated into every facet of an organization’s daily operation to cover the overall threat landscape.

You hold certifications like MSC, Microsoft MVP (Most Valuable Professional), CISSP, CISIM, CCSP, CCSIO, CEH, CHFI, CWSP, MCSE, MCSA, CCNP, ISO 27001 LI/LA and PMP. How much have certifications helped you groom your career progress?

It really helped a lot. Certificates are not meant to be just a badge on your shoulder or social media (although it’s nice to have), but I would really think of it as an opportunity for continuous learning. That’s the beauty of Technology and Security from my point of view, is that you need to continuously learn new things. Certificates are just proof that you have learned and mastered this topic, but it should not be your end goal.

I would recommend security professionals to be diversified and try to learn different topics, platforms, and technologies.

What are your thoughts on the skill gap in cybersecurity? How can these be prevented? What are your tips for upcoming cybersecurity professionals?

Cybersecurity is an evolving industry with a prominent issue of the skill gap. According to the latest surveys, unfilled cybersecurity jobs are expected to reach 1.8 million by 2022.

The problem is that this difference between supply and demand is allowing bad malicious hackers to use this for their own good. We need to admit that the typical formal cybersecurity education is not capturing the talent pool. We need to capture such talent (new generation) in a more innovative way since Cybersecurity itself is not a standard formal career.

More focus should be placed on information security-focused courses which put the student in specific topic-related content. Competitions like “Raise the Flag” are very helpful because these focus on the actual work instead of theory.

For becoming cybersecurity professionals, I believe, passion is the most crucial thing from my point of view. You need to love what you do. Next will be the right skills which are both technical skills and logical/analytical skills.

Technical skills are very wide-ranging from entry to specialized and expert experience. Security professionals tend to be all-rounders, which means they need to have some solid foundation in networking, scripting, operating systems, web technologies, before switching to a full security job. Also, logical and analytical thinking is a must since they will face new challenging problems. Security professionals need to develop a security mindset which is being able to think out of the box, and that’s where you will be targeted.

T-Mobile Data Breach: Are You Affected?

T-Mobile data breach

The U.S. unit of T-Mobile reported of a data breach that affected only its prepaid customers. As per their statement, none of the customers financial information, social security number (SSN) and passwords were compromised.

What Happened?

T-Mobile’s cybersecurity team detected a malicious attack by hackers that gave them unauthorized access to some customer information. The incidence response team was up for the challenge. They shut-out the hackers from the database immediately post detection and restricted them from gaining extensive customer information. They further reported this data breach incidence to the concerned authorities and took appropriate legal approach.

However, T-Mobile said, “The data accessed was the information associated with the prepaid service accounts. Some personal information was exposed in this attack. This would have included name and billing address (if you provided one when you established your account), phone number, account number associated with the prepaid service, and information about your rate plan and features.”

Rate plan and features of voice calling service are “customer proprietary network information” (CPNI) under FCC (Federal Communications Commission) rules. This requires the service provider to officially issue a notice of any security/data breach incident to all the affected users personally and via a press release.

Preventive Measures

T-Mobile has sent a text notification to all the affected users informing them about the breach.

T-Mobile Alert Notification

They are doing their best to reach out to their customers and aiding its users by all possible means. It said that, “We encourage you to confirm or update the personal identification number (PIN/passcode) on your T-Mobile account as additional protection. You can reach us by dialing 611 from your T-Mobile phone or by calling 1-800-T-MOBILE from any phone. We are happy to assist in adding special instructions for account handling as well.”

They also said, “like any other corporation, (T-Mobile) is unfortunately not immune to this type of criminal attack. Because of that, we are always working to improve security so we can stay ahead of malicious activity and protect our customers. We have a number of safeguards in place to protect your personal information from unauthorized access, use, or disclosure and shall continue to evolve so that such incidences are not repeated in future.”

In a similar data breach incidence last year, T-Mobile US, Inc had revealed a data breach that compromised around 2 million users’ personal information. What’s concerning is the fact that this data breach is identical to the current breach.

Twitter Now Allows Users to Disable SMS-based 2FA

PM Modi Twitter

Twitter users must be glad after the microblogging service announced that from now users can disable the SMS-based 2FA method for their accounts and use alternative methods like OTP authentication or a security key.

“We’re also making it easier to secure your account with 2FA. Starting today, you can enroll in 2FA without a phone number,” Twitter said in a post.

Earlier, users were required to register their phone numbers and enable the SMS-based 2FA method, even if they didn’t want to.

However, several users claimed that they’re unable to disable the SMS-based 2FA method, which exposes their accounts to attackers.

The downside in this SMS-based 2FA is that hackers can perform a SIM swap attack to hijack a user’s phone number, bypass 2FA, and then compromise the user’s account. Several high-profile accounts have been hacked using this attack method.

Twitter shifted on its decision to make SMS-based 2FA mandatory only after hackers used a SIM swap attack to break into its CEO Jack Dorsey’s Twitter account.

According to an official statement, a hacking group named “Chuckle Squad” used the SIM Swapping Attack technique to take over Jack’s account by exploiting the cell carrier vulnerability, which enabled them to post anti-Semitic comments in his account feed.

Describing how the account got hacked, Twitter said, “The phone number associated with the account was compromised due to a security oversight by the mobile provider. This allowed an unauthorized person to compose and send tweets via text message from the phone number. That issue is now resolved.”

Recently, a security blunder by Twitter exposed phone numbers and email addresses of its users who opted for 2FA protection. The social networking company stated that user contacts had been used for targeted advertising purposes.

In an official statement, Twitter stated that an error in its “Tailored Audiences and Partner Audiences advertising system” unintentionally used the information, provided by users, to run targeted ads.

“We recently discovered that when you provided an email address or phone number for safety or security purposes (for example, two-factor authentication) this data may have inadvertently been used for advertising purposes, specifically in our Tailored Audiences and Partner Audiences advertising system,” Twitter said in a statement.

Don’t Overlook the Security of Your Supply Chain

Supply chain

CISO MAG EDITORIAL

Not long ago, the IT Head—and we are using this as a generic term–of an organization was concerned with securing all the infrastructure behind the company firewall. In those days, threats were largely viruses, trojans and worms. The Internet was still in its early days, so interconnecting networks was rare in the corporate world, and more common in academic (Yale, Columbia, Stanford) or military networks (ARPANET). However, that paradigm has changed today. The Internet has percolated all strata of our society, the business world and governments. While we have benefitted greatly from this omnipresent interconnectivity, there is a downside to it—the attack vectors have increased multifold. Today a business’s infrastructure interconnects to partners, suppliers, developers, customers (app connectivity) and other ecosystem players. It is a borderless enterprise or the extended enterprise. Therefore, a CISO must worry about the risk profile of other networks too—on the supply chain.

In its 2020 Predictions report, Trend Micro states that organizations will face a growing risk from their cloud and the supply chain. The reliance on open source and third-party software—and the introduction of modern workplace practices all present immense risks. Organizations are increasingly allowing employees to work from home (remote workers). Financial institutions are working with startups. Third-party software could have vulnerabilities. The report states: “Cloud and DevOps environments will continue to drive business agility while exposing organizations, from enterprises to manufacturers, to third-party risk.”

As more organizations opt for Managed Services, the onus and responsibility of security shifts to Managed Service Providers (MSPs). The Trend Micro report states: “Managed service providers (MSPs) will be targeted in 2020 as an avenue for compromising multiple organizations via a single target. They will not only be looking to steal valuable corporate and customer data but also install malware to sabotage smart factories and extort money via ransomware.”

Key message: The security of the supply chain is as crucial as the security of the company network. And this should be intrinsic–built into contracts, SLAs, legal documentation. Ensure the security of not just your enterprise IT infrastructure but also that of your supply chain.

CISO MAG study: 1 in 3 CISOs feel biggest challenge of endpoint solution is its complexity

1 in 3 CISOs feel biggest challenge of endpoint solution is its complexity

November 21, 2019: Today, the typical organization has hundreds if not thousands of endpoints: desktops, workstations, laptops, mobile phones, tablets, access points, printers, IP-cams, USB devices, credit card readers, POS devices, servers, cloud VMs, and virtual desktops. The addition of IoT devices will increase the number of endpoints even more. Traditional anti-malware, signature-based, and file-scanning solutions will not be able to keep up and manage all those endpoints. This raised concerns with organizations delving into endpoint security.

CISO MAG, an information security news website and publication from EC-Council conducted a multiple-choice survey, in the month of October 2019 to present new research on the usage of endpoint security solutions.

3 key takeaways

The three prominent findings that stand out in the survey are:

1. The best of both: Half of all companies (53.19%) that participated in this survey are using both EPP and EDR solutions.

2. Endpoint visibility: Almost half of the respondents (46.38%) want real-time endpoint and application visibility.

3. Managed services: Two-thirds (62.55%) said their endpoint solution included managed endpoint detection services.

Some vendors are sweetening their offerings by bundling endpoint monitoring and management services. These services offer in-depth or advanced threat hunting, forensics, and remediation services.

Another key trend is that endpoint protection is now moving to the cloud, with SaaS-based services for monitoring endpoints. The demand for endpoint security services has increased as cloud security has improved. Traditionally, endpoints were centrally managed from an on-premise server communicating with agents on the endpoints. This shifts the responsibility of managing endpoints out of the enterprise and into the hands of managed security services providers (MSSPs).

Here are some key findings of the survey, indicating that many organizations still need to complete their endpoint security deployments.

Key Findings

  • More than half the respondents (62.98%) have been using an endpoint security solution for some time.
  • It is surprising to note that 14.89% are not using any endpoint security solution.
  • The rest of the respondents (22.13%) are either in the process of evaluating a solution, implementing a solution, or conducting pilot trials.
  • Almost half the respondents (46.38%) agree that an endpoint security solution offers better or real-time endpoint and application visibility.
  • A quarter of the respondents (25.11%) said there was increased usage of mobile devices and endpoints in their organizations.
  • A fifth (20.85%) agreed there was increased volume and complexity of breaches.
  • More than half (53.19%) are using a combination of EPP and EDR solutions while the rest are using one or the other.
  • Two-thirds (62.55%) said their endpoint solution included managed endpoint detection services while a little over one-third (37.45%) said they were not using such services.
  • More than half the respondents (52.34%) said the main factor in deciding the type of endpoint solution they want is the technical capability of the solution.
  • A third of the respondents (32.77%) said the biggest challenge is the complexity of deploying, managing, and using the endpoint solution.

Methodology

The online survey was conducted by CISO MAG readers from EC-Council’s database. The respondents represent a cross-section of organizations from over 42 countries. Responses were received from those living in the U.S., U.K., UAE, Singapore, Egypt, and The Netherlands. Entries were also received from islands in the Caribbean Sea, such as St. Vincent & The Grenadines, and Trinidad & Tobago.

The survey was prepared in consultation with security experts and industry analysts.

Survey Respondent Profile

  • IT Manager/ICT Manager
  • Head of IT/VP IT
  • MIS Manager
  • IT Security Manager
  • Information Security Manager
  • Manager/Head of Network Security
  • Director of Information Security
  • ISO/Information Security Officer
  • Security Operations Officer/Operation Security Manager
  • VP/CISO
  • CIO
  • Security Consultant
  • Cybersecurity/Security Analyst
  • Cybersecurity Architect
  • Cybersecurity Engineer
  • Head of IS and SOC
  • ICT Security, Risk & Compliance Coordinator
  • Head IT, Risk & Security

Read the full survey report and the latest issue of CISO MAG here.

About CISO MAG

CISO MAG is a publication from EC-Council which provides unbiased and useful information to the professionals working to secure critical sectors. The information security magazine includes news, comprehensive analysis, cutting-edge features, and contributions from thought leaders, that are nothing like the ordinary. Within the first year of launch, the magazine reached a global readership of over 50,000 readers. The magazine also has an Editorial Advisory Board that comprises some of the foremost innovators and thought leaders in the cybersecurity space. Apart from this, CISO MAG also presents a platform that reaches out to cybersecurity professionals across the globe through its Summits and Awards and Power List surveys.

About EC-Council

EC-Council, officially incorporated as the International Council of E-Commerce Consultants was formed to create information security training and certification programs to help the very community our connected economy would rely on to save them from a devastating Cyber Attack. EC-Council rapidly gained the support of top researchers and subject matter experts around the world and launched its first Information Security Program, the Certified Ethical Hacker. With this ever-growing team of subject matter experts and InfoSec researchers, EC-Council continued to build various standards, certifications and training programs in the electronic commerce and information security space, thereby becoming the largest cybersecurity certification body in the world.

Google Updates its Political Ads Policy

Google Announced US$1 Million for its “Be Internet Awesome” Initiative

In order to increase voters’ confidence in political ads, Google recently announced that it is making a few changes in handling political ads on its platform globally.

The updated ad policy will come into effect within a week in the United Kingdom due to its upcoming general election. Also, the policy will be introduced in the European Union before the end of the year, and rest of the world from January 6, 2019.

The search engine giant also stated that it’s committed to helping protect election campaigns from foreign interference and surface authoritative election news. It’s believed that these changes will enhance trust in digital political advertising and faith in electoral processes.

According to the new ad policy, Google is limiting election ads audience based on three categories: Age, Gender, and Location.

“Whether you’re running for office or selling office furniture, we apply the same ads policies to everyone; there are no carve-outs. It’s against our policies for any advertiser to make a false claim—whether it’s a claim about the price of a chair or a claim that you can vote by text message, that election day is postponed, or that a candidate has died,” Google said in a statement.

“To make this more explicit, we’re clarifying our ads policies and adding examples to show how our policies prohibit things like “deep fakes” (doctored and manipulated media), misleading claims about the census process, and ads or destinations making demonstrably false claims that could significantly undermine participation or trust in an electoral or democratic process,” Google added.

Earlier, Google provided anti-hacking technology “Project Shield” to political organizations in Europe during Union elections in May 2019. The technology used in Project Shield will safeguard websites from DDoS attacks by using a technique called Reverse Proxy. This technique monitors the website traffic and scans it for malicious content.

In a related development, Facebook stated that it is tightening its security for the 2020 U.S. elections after fresh signs of Russia meddling. The social media giant stated that it’s taking down accounts involved in illicit activities and stepping up searching state-controlled media trying to manipulate American voters.

Facebook pledged to use a variety of security measures, including artificial intelligence, to counter Russian attackers or other online intruders who use misleading strategies and false information to meddle in the 2020 U.S. elections.

Trend Micro’s 2020 Predictions – Escalating Cloud and Supply Chain Risk

trend micro's 2020 predictions

Trend Micro Incorporated today announced its 2020 predictions report, which states that organizations will face a growing risk from their cloud and the supply chain. According to Trend Micro’s 2020 predictions, the growing popularity of cloud and DevOps environments will continue to drive business agility while exposing organizations, from enterprises to manufacturers, to third-party risk.

“As we enter a new decade, organizations of all industries and sizes will increasingly rely on third-party software, open-source, and modern working practices to drive the digital innovation and growth they crave,” said Nilesh Jain, Vice President, Southeast Asia and India, Trend Micro. “Our threat experts predict that this fast growth and change will bring new risks of supply chain attacks. From the cloud layer all the way down to the home network, IT security leaders will need to reassess their cyber risk and protection strategy in 2020.”

Trend Micro’s 2020 predictions

Attackers will increasingly go after corporate data stored in the cloud via code injection attacks such as deserialization bugs, cross-site scripting and SQL injection. They will either target cloud providers directly or compromise third-party libraries to do this.

In fact, the increasing use of third-party code by organizations employing a DevOps culture will increase business risk in 2020 and beyond. Compromised container components and libraries used in serverless and microservices architectures will further broaden the enterprise attack surface, as traditional security practices struggle to keep up.

Managed service providers (MSPs) will be targeted in 2020 as an avenue for compromising multiple organizations via a single target. They will not only be looking to steal valuable corporate and customer data, but also install malware to sabotage smart factories and extort money via ransomware.

The new year will also see a relatively new kind of supply chain risk, as remote workers introduce threats to the corporate network via weak Wi-Fi security. Additionally, vulnerabilities in connected home devices can serve as a point of entry into the corporate network.

Amidst this ever-volatile threat landscape, Trend Micro recommends organizations:

  • Improve due diligence of cloud providers and MSPs
  • Conduct regular vulnerability and risk assessments on third parties
  • Invest in security tools to scan for vulnerabilities and malware in third-party components
  • Consider Cloud Security Posture Management (CSPM) tools to help minimize the risk of misconfigurations
  • Revisit security policies regarding home and remote workers 

To read the full report on Trend Micro’s 2020 predictions, The New Norm: Trend Micro Security Predictions for 2020, please visit: https://www.trendmicro.com/vinfo/us/security/research-and-analysis/predictions/2020.

Microsoft Declines Rumors about “Teams” used in Ransomware Attacks

Brand Phishing Attacks

Microsoft has declined rumors about its communication platform Teams being used by cybercriminals to install ransomware on company networks.

The speculations from unknown sources are circulating online in early November after many companies in Spain affected by the “DoppelPaymer” ransomware.

Besides rejecting rumors, Simon Pope, Director of Incident Response at the Microsoft Security Response Center (MSRC), also addressed the second set of rumors that claimed attackers might have used the BlueKeep RDP vulnerability to install the DoppelPaymer ransomware.

Microsoft has been investigating recent attacks by malicious actors using the DopplePaymer ransomware. There is misleading information circulating about Microsoft Teams, along with references to RDP (BlueKeep), as ways in which this malware spreads. Our security research teams have investigated and found no evidence to support these claims,” Simon Pope said in a post.

“In our investigations, we found that the malware relies on remote human operators using existing Domain Admin credentials to spread across an enterprise network,” Pope added.

Microsoft stated that protection from Dopplepaymer and other malware is available for customers using Windows Defender. The company stated that it’s committed to helping businesses and governments across the globe to prevent cyber threats and continue to enhance its security services to identify new emerging threats.

A couple of months ago, Microsoft revealed that it discovered two new security flaws in its Windows Desktop Services package. Security officials at Microsoft stated that the two vulnerabilities, dubbed CVE-2019-1181 and CVE-2019-1182, can be exploited by attackers to launch “Wormable Attacks” that spread across different network systems without a user’s knowledge. Microsoft also stated the present flaws are like the vulnerability known as BlueKeep (CVE-2019-0708), which was patched in May 2019.

According to Microsoft, the infected versions of Windows due to the flaws included, Windows 7 SP1, Windows 8.1, Windows Server 2008 R2 SP1, Windows Server 2012, Windows Server 2012 R2, and other versions of Windows 10. However, Windows Server 2003, Windows XP and Windows Server 2008 are not affected due to the flaws.