Home Blog Page 278

Office 365 Voicemail Phishing Alert!

Hackers Target Office 365 Users with SurveyMonkey Phishing Campaign

Office 365 provides users the ability to use all traditional Office Suite applications such as Word, PowerPoint, Excel, Access, Outlook, etc. on the go. This widespread usage acts as a prime reason for its popularity among varied businesses and working professionals. But this popularity has attracted a lot of attention from hackers and the dark web world.

According to a blog published by McAfee Labs Senior Security Researcher, Oliver Devane, Voicemail Phishing attacks using different phishing kits have been on a steady incline in recent weeks. While voicemail phishing technique is not alien to anyone but using multiple phishing kits to enable a voicemail phishing attack is a first of its kind.

Oliver further explains the chronology of events in this phishing attack:

  • The attack is initiated by sending a fake voicemail attachment to the user through an email. This email informs the user about a missed phone call, along with a request to login to their account to access their voicemail.

The following filenames used for attachments of phishing emails act as its indicators:

  • 10-August-2019.wav.html [Format: DD-Month-YYYY.wav.html]
  • 14-August-2019.html [Format: DD-Month-YYYY.html]
  • Voice-17-July2019wav.htm [Format: Voice- DD-MonthYYYYwav.htm]
  • Audio_Telephone_Message15-August-2019.wav.html [Format: Audio_Telephone_MessageDD-Month-YYYY.wav.html]

On accessing the attached HTML file the user is redirected to a fake phishing webpage. While redirecting an audio recording is played making the user believe the authenticity of the received voicemail message. On inspecting the source code of this audio file the following HTML code was discovered:

<audio autoplay hidden>

<source src=”http://soundbible.com/mp3/Hello-Soundbible.com-218208532.mp3” type=”audio/mp3”>

</audio>

Once the fake phishing webpage is loaded the user can see a Microsoft logo and respective email address prepopulated on the landing page replicating Microsoft’s login landing page. This screen prompts a user to enter the password stating, “Enter Password. Because you’re accessing sensitive info, you need to verify your password”.

When the password is entered, a success message is displayed on the screen and the user is further redirected to the office.com login page.

As mentioned earlier, voicemail phishing is not new to the world of cybersecurity. But this time around attackers have used not one or two, but three different phishing kits. McAfee’s report makes a mention of these three kits, namely, Voicemail Scmpage 2019, Office 365 Information Hollar, and the third one is unnamed yet, has a close resemblance to an old phishing kit used to target users in 2017. These kits are phishing users’ credentials such as email, password, IP Address, and Location.

McAfee also stated that its customers using VSE, ENS, Livesafe, WebAdvisor, and MGW are protected against these phishing campaigns as it has already taken preventive measures. McAfee has advised its users to be extra vigilant about emails and corresponding attachments received from unknown senders and requested them to use Two-Factor Authentication (2FA) instead of Single-Factor Authentication (SFA).

Hackers Plead Guilty in Uber’s 2016 Data Breach

Uber Data Breach

Two hackers, Glover and Mereacre, have pleaded guilty for their extortion scheme to steal sensitive information of 57 million Uber’s passengers and drivers.

According to the statement from the Federal Court, California, the hackers admitted stealing personal information from the ride-hailing service provider that was stored on Amazon Web Services from October 2016 to January 2017 and then demanding a ransom.

After hiding the incident for more than a year, Uber admitted, in November 2017, that two hackers gained unauthorized access to information on Github and stole Uber’s credentials for a separate cloud-services provider, where they were able to download driver and rider data.

The incident was first reported by Bloomberg on November 21, 2017. The company reportedly fired its chief security officer, Joe Sullivan, and a deputy, Craig Clark, soon after for concealing the hacking incident.

It was reported that Uber paid hackers US$ 100,000 in ransom to destroy the stolen data to hide the breach that allegedly compromised the personal information of about 57 million passengers around the world in October 2016.

A week after Uber acknowledged a massive data breach, the Washington state Attorney General Bob Ferguson sued the taxi-aggregator for failing to report the incident. On November 28, 2017, Ferguson filed a multimillion-dollar lawsuit against Uber King County Superior Court, alleging that the ride-sharing company violated the state’s revised data breach notification norm.

Ferguson charged civil penalties of up to US$ 2,000 per violation, which could result in millions of dollars if Uber loses. While asking Uber to cover the costs and fees associated with the lawsuit, Ferguson alleged that names and driver’s license numbers of at least 10,888 Uber drivers in Washington state were stolen without their being notified as state law requires.

Uber also faced a fine of £385,000 (US$ 491,284) from the United Kingdom’s Information Commissioner’s Office (ICO) for failing to protect customers’ data and not reporting the breach in a timely manner. The taxi-aggregator was also slammed by the Dutch Data Protection Authority with a fine of €600,000 (US$ 679,257) for the same reason.

The ICO stated the breach allowed hackers to illegally access personal data, including names, email addresses, and phone numbers of 2.7 million Uber customers in the U.K. and 174,000 in the Netherlands.

Mysterious Malware Infects over 45,000 Android Phones

GO SMS Pro Android App Still Vulnerable to Data Exposure

Thousands of Android users have been complaining online about a malicious app that hides itself, downloads other threats, and displays ads on the infected devices, and reinstalls itself even after users delete it from their devices.

According to a report published by Symantec, the malicious app packed with the malware, named Xhelper, has infected more than 45,000 Android devices in the last six months and is continuing to infect 2,400 devices on an average each month. Symantec stated the malicious app mainly targeting mobile users in India, U.S., and Russia.

Though Symantec didn’t find the exact source of the malicious app, it did suspect that the malicious app was pre-installed on Android devices from certain brands.

Once launched, the malware connects to its remote command-and-control server over an encrypted channel and downloads additional payloads like clickers, droppers, and rootkits on the infected Android devices.

“None of the samples we analyzed were available on the Google Play Store, and while it is possible that the Xhelper malware is downloaded by users from unknown sources, we believe that may not be the only channel of distribution,” Symantec said in its report. “From our telemetry, we have seen these apps installed more frequently on certain phone brands, which leads us to believe that the attackers may be focusing on specific brands.”

“However, we believe it to be unlikely that Xhelper comes preinstalled on devices given that these apps don’t have any indication of being system apps,” the report added.

Symantec urged Android users to take simple precautions like, keeping devices and apps up-to-date, avoiding app downloads from unfamiliar sources, paying attention to the permissions requested by apps, frequently back up data and installing a good antivirus app that protects against malware and similar threats.

A similar research from Kaspersky revealed an ongoing Android malware campaign dubbed ViceLeaker that has been active since 2016. According to Kaspersky, a hacker group has been found targeting Israel citizens and other Middle East countries with surveillance malware named Triout. The malware is designed to steal sensitive information, including call recordings, text messages, photos, videos, and location data without users’ knowledge.

Apart from spying features, the malware also has backdoor capabilities, including upload, download, delete files, record surrounding audio, takeover camera, and make calls or send messages to specific numbers, according to the researchers.

Facebook sues NSO Group for violating Computer Fraud and Abuse Act

WhatsApp and Indian governmentWhatsapp Hack

Facebook has sued the Israel-based cyber intelligence company NSO Group for violating the Computer Fraud and Abuse Act. According to the lawsuit filed in the federal court, the NSO Group deployed its custom malware on around 1,400 WhatsApp installed mobile devices in April and May 2019.

NSO Group is a developer of spyware for mobile devices. The firm is known for the development of Pegasus software that targets mobile phones to gather information and provides authorized governments with technology that helps them combat terror and crime.

In May WhatsApp, a Facebook-owned instant messaging app, revealed that it discovered a vulnerability in its network system that allowed hackers to install spyware via an infected WhatsApp voice call. It stated that the spyware can exploit the mobile device, its calls, and texts; it activates the phone’s camera, microphone, and it is able to perform other malicious activities. The malicious spyware was developed by the NSO Group, according to Facebook.

Now, after its investigation, Facebook revealed that the attack was linked to the NSO Group. It stated the attackers used servers and Internet-hosting services that related to NSO. According to WhatsApp’s findings, nearly a hundred human rights advocates, journalists, and members of civil society across the world were targeted in the attack.

“Between and around April 2019 and May 2019, Defendants used WhatsApp servers, located in the United States and elsewhere, to send malware to approximately 1,400 mobile phones and devices. Defendants’ malware was designed to infect the Target Devices for the purpose of conducting surveillance of specific WhatsApp users. Unable to break WhatsApp’s end-to-end encryption, Defendants developed their malware in order to access messages and other communications after they were decrypted on Target Devices. Defendants’ actions were not authorized by the Plaintiffs and were in violation of WhatsApp’s Terms of Service. In May 2019, the Plaintiffs detected and stopped Defendants’ unauthorized access and abuse of the WhatsApp Service and computers,” a statement from the lawsuit read.

China Passes New Cryptography Law

Chinese actors target telecom

In an attempt to ensure the security of cyberspace and information, the Chinese government recently passed a new law on cryptography. This paves the way for the country to release its own digital currency, which is aimed at cutting costs of circulating  paper money and to help policymakers control the money supply

The new cryptography law, which comes to effect on January 1, 2020, is designed to assist the development of the cryptography business and enhancing the security of cryptocurrency.

In 2014, China’s Central Bank set up a research team to work on its digital currency to cut the costs of traditional paper money and to control the money supply. The new digital currency can be used across major payment platforms like WeChat and Alipay, according to the Central Bank.

Previously, a wide range of uncoordinated laws and regulations governed the Internet in China. The Chinese government implemented a contentious new law in 2017, which allegedly imposes strict requirements on data storage and scrutiny. The proposed law, which was approved in November 2016 by China’s National People’s Congress, prohibits service providers from recording and selling the personal information of Internet users. In the case of these prohibitions being violated, it also gives users greater information security rights, including requirements that their data be wiped clean.

International trade organizations opposed the new Chinese regulations, at a minimum pushing for a delay in implementation, arguing that the new rules would hamper business activities on the Internet in China.

In an attempt to prevent any damage to global trade services, the U.S. asked China not to implement its stringent cybersecurity law. In a two-page document submitted for debate at the World Trade Organisation (WTO) Services Council, the U.S. claimed that China’s new cybersecurity norms can have a huge impact on cross border services supplied through a commercial presence abroad.

Strontium Hacker Group Targets 2020 Tokyo Olympics

Tokyo Olympics 2020

Microsoft recently warned about a new wave of targeted cyberattacks by a group of state-sponsored Russian hackers.  According to Microsoft’s Threat Intelligence Center report,  attackers targeted nearly sixteen International Sporting and Anti-Doping organizations ahead of the 2020 Summer Olympics in Tokyo.

Microsoft stated the attacks are linked to a Russian hacking group “Strontium,” also known as Fancy Bear or APT28, which is believed to be linked to Russian military intelligence agency GRU and has been active since 2007.

The tech giant revealed that the methods used in recent attacks are similar to those previously used by Strontium to target government organizations, think tanks, militaries, law firms, human rights organizations, and financial firms across the world. It’s said that the Strontium group launched a variety of attacks, including spear-phishing, exploiting internet-connected devices, and password spraying.

According to Microsoft, the attacks have occurred in September 2019, after the World Anti-Doping Agency (WADA) announced a ban of all Russian athletes from all upcoming world championships and Olympics sporting events.

“At least 16 national and international sporting and anti-doping organizations across three continents were targeted in these attacks which began September 16th, just before news reports about new potential action being taken by the World Anti-Doping Agency. Some of these attacks were successful, but the majority were not. Microsoft has notified all customers targeted in these attacks and has worked with those who have sought our help to secure compromised accounts or systems,” Microsoft said in a statement.

In order to avoid any kind of cyber threats during the 2020 Olympic and Paralympic Games, the Japanese government introduced a new cybersecurity strategy in 2018. As a part of the strategy, the government plans to create a new body to ensure effective coordination among government agencies, the Olympic organizing committee, municipalities, and business operators to respond to cyber threats.

The government also decided to introduce a five-level scale to classify the severity of cyber-attacks. The severity index categorizes the cyber-attacks into five levels: the lowest level 0 indicates “No Impact” while the highest level 4 indicates “Extremely Grave Impact.” The index would be helpful for people, government, and business entities in understanding the magnitude of threats and taking necessary actions.

Insider Threats: A Problem That is Preventable

Insider Threats

By Tony Pepper, CEO & co-founder, Egress

Earlier this summer, I read a fascinating story about McAfee launching a lawsuit against three former employees. The lawsuit alleged that these employees conspired to steal trade secrets on behalf of their new employer, accusing them of moving to a competitor and exfiltrating business-sensitive documents to their personal email accounts.

The scenario in the McAfee suite is a classic case of insider risk in action: privileged users accessing sensitive internal data and intentionally leaking it to personal email addresses or file-sharing sites. These edge cases are quite difficult for traditional data loss prevention (DLP) controls to mitigate, as they operate based on pre-defined static rules. One major issue is that traditional DLP doesn’t take a proactive stance with the user because its simplistic alerts and reminders tend to be written off as “nagging.” This is why new proactive and intelligent machine learning-based approaches provoke a strong reaction from leading firms as they modernize their email security strategies. By detecting gray areas of human risk, engaging users, and providing corrective guidance, insider problems can be significantly mitigated.

The McAfee incident underscores a widespread issue continuing to face businesses in all industries. Insider threats are a major concern for IT leaders, so why hasn’t the problem been dealt with? Why do scenarios like McAfee’s remain all too common? Unfortunately, the reason the issue has been unaddressed for so long is that most solutions are not effective at analyzing email and file content, validating recipient identity, or, at a more fundamental level, understanding the difference between good behavior and bad.

Each and every leakage vector outlined in the McAfee case is detectable and preventable by systems that can learn what the normal pattern of behavior is and contrast it to potentially risky or even malicious behavior. When intelligent, pattern-based approaches are used in conjunction with powerful, user-facing DLP, it’s a potent combination. The result is a new preventative and active approach to real-time insider detection and mitigation.

And while the McAfee case is a great example of what can happen when insiders decide to intentionally leak information for personal gain, the reality is that the most insider threats are not malicious at all, but accidental. Earlier this year, Verizon’s annual Data Breach Investigations Report revealed that more than 50 percent of data breaches are caused by phishing attacks or the use of stolen credentials. While privilege abuse and data mishandling of the type that affected McAfee remain prominent within the ‘misuse’ category of attacks, accidental breaches caused by employees failing to identify and avoid phishing scams and other, similar social engineering attacks are much more common. It’s worth remembering that the person responsible for a breach isn’t always an obvious, mustache-twirling villain. Sometimes it’s just a well-meaning employee unsure which warning signs to look out for.

Fortunately, the same pattern-based approaches that have proven effective at identifying malicious behavior are also highly capable of detecting careless behavior. In this way, the system doesn’t even need to determine “good” behavior from “bad” behavior: it only needs to identify behavior outside the norm. Look at it this way: how many times have you accidentally sent an email to the wrong person? Now extrapolate that number out to an entire organization. Misdirected emails happen, but the trick is to identify those emails—especially those containing sensitive information—before they can be sent.

When this strategy is taken to the next level and feedback is provided directly to end-users as well as InfoSec ops, it’s a powerful educational, awareness, and risk prevention approach. An employee who is about to do something risky can be warned automatically, avoiding the embarrassment and cost of an investigation—not to mention the fact that the business itself will avoid a costly breach.

Traditional DLP methods have focused on post-incident monitoring and remediation; however, legal recourse (as in the McAfee case) is a substantially costlier approach to insider breaches. It can also be unpleasant for businesses to deal with post-breach fallout, fines, and negative media coverage. Adopting a prevention-focused approach to insider threats can help not only stop many breaches from occurring in the first place, but bring a greater understanding of the dangers of both malicious and accidental threats to the workforce.

Co-founder of Egress, Tony currently serves as CEO, overseeing all aspects of business growth and innovation. Prior to Egress, Tony held executive management positions at Reflex Magnetics, Pointsec Mobile Technologies, and Check Point Software Technologies.

A frequent technology and industry speaker, Tony holds a Bachelor of Politics degree, a Software Engineering Master’s and is a certified BCS Fellow. Tony sits on industry committees including Intellect’s Government Management and Defence & Security Groups.

CISO MAG did not evaluate the advertised/mentioned product, service, or company, nor does it endorse any of the claims made by the advertisement/writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Adobe’s 7.5 million Creative Cloud Accounts Exposed

Adobe Creative Cloud

Adobe, a known name in creative cloud services, has mistakenly exposed around 7.5 million user account details. This vulnerability was brought to light by Security Researcher and Consultant Bob Diachenko and reported in the press by Paul Bischoff Tech Journalist, Privacy Advocate And VPN Expert from Comparitech.

As per Adobe’s whitepaper, most components of Creative Cloud are hosted on Amazon Web Services (AWS) which include Amazon Elastic Compute Cloud (Amazon EC2) and Amazon Simple Storage Service (Amazon S3). The Elasticsearch database is used to store, search, and analyze large volumes of data in near real-time. Diachenko’s analysis spotted that this Elasticsearch database was left exposed as there was no password protection provided for it. The result – if people knew how to find this vulnerability, they could easily access the database through their browser and find details of 7.5 million Creative Cloud accounts at their fingertips. It was also found that this flaw was live and unnoticed for close to a week, but whether anyone else had unauthorized access to it is not known.

Diachenko reported this security flaw to Adobe on October 19 to which it responded immediately and also gave a formal update to its users through the Adobe Blog. It stated: “At Adobe, we believe transparency with our customers is important. As such, we wanted to share a security update.

Late last week, Adobe became aware of a vulnerability related to work on one of our prototype environments. We promptly shut down the misconfigured environment, addressing the vulnerability.

The environment contained Creative Cloud customer information, including e-mail addresses, but did not include any passwords or financial information. This issue was not connected to, nor did it affect, the operation of any Adobe core products or services.

We are reviewing our development processes to help prevent a similar issue occurring in the future.”

The good news is that the user data which was exposed did not contain payment information or passwords, but it did include info such as:

  • Email address
  • Account creation date
  • Adobe products subscribed
  • Subscription status
  • Member IDs
  • Country
  • Time since last login
  • Payment status

The only concern that Adobe now has is that if someone did lay hands on this piece of information then its users are at risk of a Phishing attack.

Aviatrix Raises US$ 40 Million to Accelerate Growth

Aviatrix Funding

Aviatrix, a provider of advanced networking and security services, recently secured US$ 40 million in a Series C funding round led by existing investor CRV along with the participation from Formation 8, Ignition Partners, and Liberty Global Ventures.

The startup stated the new investment will be used to expand its sales channel, customer support, marketing, and product development operations and help enterprises by protecting their critical applications from on-premises to the public cloud.

Founded in 2014, Aviatrix develops software products that enable enterprises to build hybrid clouds. The company is focussed on Hybrid Cloud Networking, VPC Peering, Cloud networking, AWS Direct Connect, Azure ExpressRoute, AWS Marketplace, Global Transit Network, Egress Security, and Cloudsquad. Aviatrix also allows networking for CloudOps for enterprise SaaS vendors.

Speaking on the new investment, Steve Mullaney, the CEO at Aviatrix, said, “Business and application owners demand networking and security teams provide the same level of resiliency, performance, functionality, and security in the cloud as they get on-premises. The basic constructs of AWS and the other public clouds do not give enterprises the toolset required to accomplish this, and it is causing a great deal of pain for IT moving to the cloud.”

“Aviatrix gives enterprise IT an architecture to provide a common set of networking, security, and operational services across one or more public clouds. We’re seeing unprecedented demand from some of the largest organizations, and this latest funding will enable us to extend our demonstrable market leadership even more quickly,” Mullaney added.