Home Blog Page 281

Hackers Using Steganography in WAV Audio Files to Hide Malware

Steganography attack

Steganography, an ancient practice of hiding secret content and text messages inside non-suspicious messages, is being increasingly used by cybercriminals to attack businesses around the world.

Security researchers found a new malware campaign using WAV audio files to hide their malware. It’s said the attackers are using Steganography to embed the malicious code within the WAV audio files. According to BlackBerry threat researchers’ analysis, each WAV file contains a loader component to decode and execute malicious content embedded in audio files.

Attackers use Steganography as a technique to hide malicious code within the image/audio/text file that is mainly employed by exploiting kits to hide their malvertising traffic.

The researchers also revealed that some of the WAV files contain crypto miner script “XMRig Monero CPU” miner and “Metasploit” code to establish a reverse shell, which is used to gain remote access over the victim networks.

“Attackers deploy CPU miners to steal processing resources and generate revenue from mining cryptocurrency. Cryptocurrency miners are a popular malware payload since they provide financial benefits and aim to operate in the background without the user’s knowledge. An effective cryptocurrency botnet can yield thousands of dollars per month for an attacker,” Blackberry said in a statement.

“This approach allows the attacker to execute code from an otherwise benign file format. These techniques demonstrate that executable content could theoretically be hidden within any file type, provided the attacker does not corrupt the structure and processing of the container format. Adopting this strategy introduces an additional layer of obfuscation because the underlying code is only revealed in memory, making detection more challenging,” the statement added.

Cybercriminals are continuously using innovative methods to execute their malicious activities. Recently, Trend Micro stated that cybercriminals are using steganography to infect the targeted systems. It’s believed that the Powload campaign activity was distributing malicious codes since 2018 through fileless methods, steganography techniques, and hijacking email accounts to deliver the information-stealing malware such as Emotet, Bebloh, and Ursnif.

In a similar research, Matthew Rowen, a security researcher from Bromium, discovered ransomware embedded into a downloadable Super Mario image using steganography method. The attackers send emails with an attached spreadsheet that has an embedded malware and a macro. The attachment prompts the user to click on and enable a content link to deploy the malware.

A Four-Step Approach to Communicate Cybersecurity

Board meeting, mitigate risks from Log4j

By V3 Cybersecurity

Since the times of ancient Egypt, visualization has played a prominent role in how we communicate.  As leaders, we often look to the past for inspiration and think of new ways to apply the teachings of history.  Why should cybersecurity be any different?  Unfortunately, in our attempts to prove our technical knowledge and forward-thinking, oftentimes we diminish our ability to be effective.  Albert Einstein is quoted as saying, “If you can’t explain it simply, you do not understand it enough.”  As cybersecurity leaders, our largest challenge is not controls or compliance but is how we communicate.

The cybersecurity leaders of tomorrow will follow a simple four-step method in their approach to cybersecurity.  This approach will take the place of the current model in which we ask resources to sew a patchwork quilt with Third-Party Assessments, GRC tools, and Self Assessments.  Even if you are good enough to figure out how to consistently deliver the message, this approach has inherent flaws.

Let’s begin with third-party assessments.  Unless you have timed the assessment to coincide with your board meeting or event, you are working with old data.  Even if timed well, you are plagued with interviewer bias and response distance which drives the quality of data issues into your reporting.  Lastly, I call it captivity.  In today’s consulting model the only way for you to gain the needed visibility is to pay for another assessment.  With these never-ending assessments, no wonder they are willing to take us for a good meal.

Secondly, we will focus on our favorite GRC tools.  There is no doubt that these tools can play a role in an effective security program, but what was sold is not necessarily what is delivered.  What we were sold was business context and reduction of risk, but what was delivered was a compliance-driven workflow tool that is operational in nature.  This is good if you subscribe to the failed communication approach of “More content is better!”  This approach leaves Boards and C-suite peers asking themselves, “So what?”

Lastly, the grueling task of self-assessments.  In speaking with persons given this charge, they are overwhelmed and find themselves chasing the organization to participate.  While this task is important, they have signed up to be in the field of security and not in a perpetual world of baby-sitting.  Needless to say, once they have done the hard work of getting the organization to participate, they then have to aggregate the data which is prone to human error.

Enough with discussing today’s reality.  Our ability to communicate effectively and unlock performance can be achieved in a four-step method.  The steps are as follows:

  1. Leverage the industry
  2. Leverage the organization
  3. Leverage technology
  4. Leverage each other

Step 1: Leverage the industry

Our industry has evolved so quickly that many organizations still utilize controls that are uniquely defined.  We must understand that in doing so, we isolate our organization from our peers and limit our effectiveness.  While you might be able to justify needing unique controls, you are creating your own language.  With adoption of so many common frameworks and standards such as ISO and NIST, there is no reason to isolate your organization.  Start by selecting a control framework that is best aligned with your organization and join the community.

Step 2: Leverage the organization

Accountability and clarity go a long way in obtaining the results you need to effectively communicate the status of your security program.  We must clearly define control owners and ensure that those closest to the control are the ones answering for us.  We often see organizations providing input that is not aligned with their actual maturity or control posture.  This typically happens as a result of the response distance.  As the response distance increases, there is a reduction in data quality.  Equally, while a number of controls are typically centralized in execution, we must do our best to gain visibility across the organization and that means integrating our response owners with our neighbors (Application Development, Infrastructure, Security, etc.).

Step 3: Leverage technology

In today’s digital world, we need to leverage technology to ensure that we are aggregating our responses effectively thus allowing our security resources to drive value in their management of the resulting data, and not in the administrative action of compiling spreadsheets.  The ability to consistently produce results in a common language will not only help drive a consistent message but will help train our colleagues.  Using a common language will drive higher organizational awareness and enhance business continuity.

Step 4: Leverage each other

The days of going to the annual convention to find out what our peers are doing is not enough.  After we have executed on the first three steps, we need a vehicle to provide insight into our results. This fourth step is where the true impact on your organization is demonstrable.  Once we have meaningful views into our peers, we will unlock a new dimension of security leadership.  Dynamic visibility into our security program will reduce the liability to our board members regarding their responsibility of compliance oversight.  Our ability to leverage each other is the key to establishing due care on behalf of the organization.  Equally, with this visibility, we will establish a self-advancing model for security programs as each member works to improve in their areas of weakness and in doing so, increase the baseline for establishing due care.

Companies like V3 Cybersecurity, Inc are tackling these very questions and providing solutions that will change the way that Cybersecurity leaders communicate.  “Communication for cybersecurity leaders is evolving into a conversation about business risk.  Business risk is a common language that transcends organizational boundaries.  Our ability to communicate business risk through visualization is key to unlocking organizational performance,” says Jorge Conde-Berrocal, CEO of V3 Cybersecurity, Inc.  “Helping our community solve these long-standing challenges is our mission!” he concluded.

Knowledge is power, but wisdom is empowering!

CISO MAG did not evaluate the advertised/mentioned product, service, or company, nor does it endorse any of the claims made by the advertisement/writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

“Cozy Bear” Strikes Again! Targets Foreign Ministries in Europe

Cybercrimes in COVID-19 Pandemic

Security experts revealed that the Russian-based hacking group “Cozy Bear”, the group behind the 2016 U.S. Presidential election hack, has been working under the radar to attack the Foreign Ministries in Europe.

Cozy Bear, also known as APT29, is believed to be linked to the Russian intelligence service and Russian military hacking group Fancy Bear, which was involved in high profile attacks between 2014 and 2017.

According to cybersecurity analysts from IT security firm ESET, the hacking group, which ESET refer to as Dukes, have continued their campaign “Operation Ghost” from 2013 to 2019.

The researchers stated the group continued their malicious activities while staying under the radar. Cozy Bear recently targeted ministries of foreign affairs of three different countries in Europe, as well as the U.S. embassy of a European Union country in Washington DC.

“The Dukes (aka APT29 and Cozy Bear) have been in the spotlight after their suspected involvement in the breach of the Democratic National Committee in the run-up to the 2016 U.S. elections. Since then, except for a one-off, suspected comeback on November 2018, with a phishing campaign targeting several US-based organizations, no activity has been confidently attributed to the Dukes. This left us thinking that the group had stopped its activities,” ESET said in a statement.

“This held true until recent months when we uncovered three new malware families that we attribute to the Dukes – PolyglotDuke, RegDuke, and FatDuke. These new implants were used until very recently, with the latest observed sample being deployed in June 2019. This means the Dukes have been quite active since 2016, developing new implants and compromising high-value targets. We call these newly uncovered Dukes activities, collectively, Operation Ghost,” the statement added.

Attackers from Russia were involved in a series of espionage activities across various sectors over the years. A recent threat report from cybersecurity firm CrowdStrike revealed that hackers tied to Russian intelligence agencies are eight times faster than North Koreans, Chinese, and Iranians in hacking.

In its report titled Global Threat Report 2019: Adversary Tradecraft and the Importance of Speed,  CrowdStrike stated the Russians are the most sophisticated among the many nation-state adversaries that are regularly hacking government and private computers in the United States.

Canadian Legislation Lacks Cybersecurity Awareness: Survey

Canadians Refuse to Divulge Personal Data for Free Online Services: Survey

Cybersecurity experts have opined the Canadian government isn’t doing enough to protect businesses and consumers from data breaches.

A recent survey from Keyfactor, a provider of secure digital identity management solutions, revealed that 87 percent of surveyed cybersecurity pros think that more privacy and security legislation is required to better protect Canada’s businesses and consumers. Keyfactor provides secure digital identity management solutions that enable organizations to confirm authenticity.

According to the survey, 58 percent of respondents think regulators and the Canadian officials are not trying to regulate the security guidance on measures like data encryption. The survey also highlighted that 50 percent of respondents stated that manual and complex processes as their greatest challenge in managing Public Key Infrastructure (PKI) while 43 percent of respondents were concerned about their ability to securely adopt DevOps, cloud, and IoT.

“While the federal government continues to introduce cybersecurity consortiums and guidance, professionals on the front lines know that consortiums do little to protect their business and consumers from attacks and data loss,” said Chris Hickman, the chief security officer at Keyfactor. “The resource divide that exists across small and large enterprise, combined with standards inconsistencies, make us vulnerable to attacks.”

“As the federal election looms, Canadians should closely evaluate each party’s cybersecurity pledge and what it means to their own digital security as an online consumer. Broadly, whether large or small, Canadian businesses are struggling with IT and security resourcing. Without stronger government standardization and actionable support, businesses and consumers downstream face rising security risks,” Hickman added.

The comments come after the recent cyber-attack that impacted 201 online campus stores in Canada. A hacker group named Magecart was responsible for the recent data breach. According to Trend Micro, the attackers used a skimming script, a malicious code, designed to steal the data from 201 online stores that were catering to 176 colleges and universities in Canada. Hackers used a skimming script to compromise the card information and personal details entered on the payment page by users. Trend Micro also stated that attackers also compromised PrismWeb, an e-commerce platform designed for college stores by PrismRBS.

The Krack on Amazon’s Kindle and Echo

From creepy laughs to spy bugs, Amazon’s Echo devices have been in the limelight for more than a dozen or two reasons, and it seems like Alexa is going to hog maybe a bit more of your attention due to a “Krack” on the wall.

Reports have emerged stating that the millions of first-generation Amazon Echo devices and even the eighth generation Kindle are susceptible to a Krack WiFi vulnerability. The vulnerability allows hackers to execute a man-in-the-middle attack against a WPA2 protected the network.

Krack, a jazzy abbreviation of Key Reinstallation Attack was first revealed by researchers Mathy Vanhoef and Frank Piessens in 2017. The vulnerability existed in the four-way handshake of the WPA2 protocol, which secured almost all modern Wi-Fi networks at that time.

According to researchers, attackers could have easily exploited the vulnerability by using key reinstallation attack if the victim was within the network. The attack would enable access to details like passwords, email, photos, and even financial data like credit card numbers were among several other personal and sensitive data that was vulnerable.

After the vulnerability was discovered, Amazon had released a patch for affected devices early this year after researchers from ESET informed the Amazon about the vulnerability. But “Krack” has cracked its way open to the surface, and researchers from ESET have discovered and again confirmed that the first-generation Amazon Echo and the eighth generation of Kindle are still affected by “Krack” vulnerability.

“The Echo 1st  generation and Amazon Kindle 8th generation devices were found to be vulnerable to two KRACK vulnerabilities”, ESET researchers stated in their report. “Using Vanhoef’s scripts, we were able to replicate the reinstallation of the pairwise encryption key (PTK-TK) in the four-way handshake (CVE-2017-13077) and reinstallation of the group key (GTK) in the four-way handshake (CVE-2017-13078).”

Even though Amazon had patched the vulnerability, the reason why Krack still looms in the air is that several users may not have updated their devices and ESET has urged users to go to the setting of these devices to make sure they are running the latest firmware.

Vulnerabilities in Amazon Echo devices are not a new thing and it has echoed even before. In the last edition of DEFCON security conference researchers Wu HuiYu and Qian Wenxiang gave a live demonstration on how to hack a smart speaker. The team used Amazon Echo smart speakers to present their attack program.

The researchers hacked the speaker by adding a malicious device embedded with an attack program.  “After several months of research, we successfully break the Amazon Echo by using multiple vulnerabilities in the Amazon Echo system, and achieve remote eavesdropping,” the researchers said in a media report. “When the attack succeeds, we can control Amazon Echo for eavesdropping and send the voice data through a network to the attacker.”

Recruitment Sites Exposes 250,000 Resumes Online

recruitment sites data leak

Around 250,000 American and British-based job seekers’ personal information has been exposed after two recruiting sites misconfigured their databases. The exposed information included candidates’ names, addresses, contact information, and work experience.

The data leak occurred when recruitment sites Authentic Jobs and Sonic Jobs failed to set their cloud storage as private. The companies stored the candidates’ profiles in cloud storage folders known as buckets, which were provided by Amazon Web Services (AWS).

Both companies set their privacy settings options to public instead of private, which allowed the users to view the details of someone who applied for a job and also downloaded by anyone who knew the location of the buckets.

The data breach was discovered by security researcher Gareth Llewellyn and reported to Sky News in the U.K.

“By finding and closing these buckets we can protect people who placed their trust in these businesses and, hopefully, start drawing attention to the dangers of storing personal data in a woefully insecure manner,” Gareth Llewellyn said. “Just because they leveraged a service like AWS, or even outsourced to a third-party entirely, doesn’t preclude them from ensuring the data entrusted to them is safe.”

According to the official reports, the U.S.-based job portal Authentic Jobs, whose client list includes EY and The New York Times, exposed over 221,130 resumes online. A further 29,202 resumes were exposed by the UK-based retail and restaurant jobs app Sonic Jobs, which is used by the Marriott and InterContinental hotel chains for recruitment.

After being warned of the exposure, the companies restored their databases and changed their bucket settings to private. “We take security and privacy very seriously and are looking into how this happened,” Authentic Jobs said in a statement.

“With limited resources, as a small business, we are confident that we take reasonable and proportionate measures to protect the confidentiality, integrity, and availability of our business data and the personal data we hold,” Sonic Jobs said.

In a similar data breach incident, an unprotected MongoDB server exposed a database that contains resumes of 202 million Chinese people online.

Security researcher Bob Diachenko discovered that the unsecured server was left visible online without a password, thus exposing the resumes that contained personal details such as mobile phone number, email, marital status, driver license, literacy level, salary expectations, skills, and work experience. The leaky server was secured soon after Diachenko publicized the issue via a Twitter post.

Samsung Admits Galaxy S10 Fingerprint Reader Vulnerability, says “Will Fix it Soon”

Galaxy S10 fingerprint reader vulnerability

Samsung, a premium smartphone manufacturer, in a statement given to the press, has admitted to being “aware of the case of S10’s malfunctioning fingerprint recognition and will soon issue a software patch.” This statement comes soon after a British user reported an issue with her Samsung Galaxy S10 fingerprint reader.

According to her story, she bought a new $3.50 screen protector for her Galaxy S10 device and then registered her fingerprint for its on-screen fingerprint recognition security feature. Her excitement about the device’s fingerprint recognition feature was cut short when surprisingly, her husband was able to unlock her phone even without registering his fingerprint with the mobile phone’s fingerprint reader. To double-check this flaw she asked her sister to unlock the phone using her fingerprint and to her surprise, this worked as well.

Samsung reportedly uses the same fingerprint reader in its recently launched model, Samsung Galaxy Note 10. Since the Galaxy S10 news surfaced, one of the twitter users shared a video on the social media handle exposing the same vulnerability on the Galaxy Note 10 smartphone.

It is a known fact that smartphone biometric security features are not as secure as they claim to be, but fooling the Samsung Galaxy S10 device with a mere $3.50 screen protector is difficult to digest. This is not the first time that Samsung has faced issues with its biometric security features. Previously, Samsung’s other flagship smartphone, the Galaxy S8, was laced with facial and iris recognition biometric security feature issues.

In a separate comment given to TechCrunch by Samsung related to fingerprint reader vulnerability, it stated, “We are investigating this issue and will be deploying a software patch soon. We encourage any customers with questions or those who need support downloading the latest software to contact us directly at 1-800-SAMSUNG.”

Attackers used “Cutlet Maker” Malware in Jackpotting Attacks on ATMs in Germany

BotenaGo, malware over encrypted connections

Cybersecurity experts found a new trace of an ATM Jackpotting Attack via infamous ATM malware named Cutlet Maker. The researchers opined that the usage of this malware by attackers is now rapidly growing across the globe.

Cutlet Maker malware was designed in 2017 to spit the cash from ATMs in Germany. In ATM jackpotting, attackers use malware like Cutlet Maker to trick the ATM, by exploiting its vulnerability, to eject the cash.

A joint investigation by Motherboard and the German broadcaster Bayerischer Rundfunk revealed some new details about a series of Jackpotting Attacks. The malware was used to attack multiple ATMs in Germany to steal around US$ 1.5 million during 2017. It’s said that a total of 10 different jackpotting incidents had taken place between February and November 2017, involving Cutlet Maker malware.

According to the investigation findings, the attacked regions include the U.S., Latin America, and Southeast Asia. The Spanish Commercial Bank Santander is one of the highly impacted banks in the 2017 attacks, as it used outdated Windows systems.

“Protecting our customers’ information and the integrity of our physical network is at the core of what we do. Our experts are involved in every stage of product development and operations to protect customers and the bank from fraud and cyber-threats. This focus on protecting our data and operations prevents us from commenting on specific security issues,” a Santander spokesperson said in a statement.

In January 2018, National Cash Register (NCR) Corporation and Diebold Nixdorf, two leading financial self-service providers in the United States, issued warnings against Jackpotting Attacks that make ATMs gush out cash incessantly. The self-service kiosk makers accepted to have informed their clients about the vulnerability. Although there is no available data on the losses due to these incidents, the ATM manufacturers have admitted to the rising cases of jackpotting across the world.

These ATM cyberattacks took off in 2015 in Asia, Europe and Mexico, however, now their new target is the U.S, raising concerns for the U.S. Secret Service, which has advised financial institutions to be cautious. “This should be treated by all ATM deployers as a call to action to take appropriate steps to protect their ATMs against these forms of attack,” NCR cautioned.

Gigamon ThreatINSIGHT’s “Time is Everything” Mantra for Network Detection and Threat Response

Evil Internet Minute: 1.5 cyberattacks on Computers with an Internet Connection

Gigamon a leader in network detection and response (NDR) solutions, recently announced the latest version of ThreatINSIGHT, a widely used and trusted product for network detection and response. This enhanced version has placed ThreatINSIGHT in the forefront of the cloud-native network detection and response solution providers race.

Speaking about the latest developments, Josh Carlson, Vice President and INSIGHT General Manager, Gigamon said, “Time is everything for threat response and responders. With that principle in mind, we have enhanced ThreatINSIGHT with a series of detection and management features that takes an organization’s security posture to a new level, allowing our customers to focus on threat hunting and resolution, not maintaining their threat-hunting infrastructure.”

The new features of ThreatINSIGHT, which take it ahead in the market include:

  • Machine Learning (ML) combined with Applied Threat Research (ATR) provides faster network detection and response.
  • Enables responders to quickly identify potential network threats by curating clusters of network events simultaneously
  • OmniSearch provides contextual correlation of events that accelerates investigation time.
  • Power to leverage the Gigamon INSIGHT Cloud Data Warehouse which delivers access to all current and historical network activity metadata needed for comprehensive forensics and investigative efforts.

According to an earlier research report “Managed Detection and Response Market by Security Type (Endpoint, Network, Application, Cloud), Deployment (On-Premises, Hosted), Organization Size (SMEs, and Large Enterprises), Industry Vertical, and Region – Global Forecast to 2022”, published by MarketsandMarkets, the market size is expected to grow from US$419.7 million in 2017 to US$1,658.0 million by 2022, at a Compound Annual Growth Rate (CAGR) of 31.6 percent during the forecast period.

MyGate Secures US$ 56 Million to Enhance Security in Gated Communities

Firedome Funding

MyGate, a security solutions provider for gated premises, recently raised US$ 56 million in a Series B funding round led by Chinese internet giant Tencent Holdings, US-based JS Capital LLC, and Tiger Global Management along with the participation from the existing investor Prime Venture Partners. The India-based startup stated the investment will help accelerate the business growth and expansion.

Founded in 2016, MyGate is a technology-forward app that helps people simplify their daily lives. MyGate provides comprehensive security solutions for gated communities to manage their operations digitally. With MyGate technology, the authentication procedures are performed digitally, with the implementation of artificial intelligence.

MyGate also offers other innovative services like e-intercom (automatic visitor authentication), child safety alerts, infrastructure-free vehicle management, staff management, touchless resident identification, clubhouse access management, and admin dashboards. The startup claims that its software platform is operating over a million homes in 11 cities across the country and planning to expand its services to other cities.

Speaking on the new investment, Vijay Arisetty, the CEO & Co-founder of MyGate, said, “We started MyGate to solve for the real problem of security and inconvenience faced by households every day. We are thankful to our customers and investors who believed in our solution, gave feedback and guided us in our journey. Our mission of simplifying urban living has just started and we’re delighted to welcome marquee investors and business partners in Tencent, Tiger, and JSoros to be part of our journey.”

“Right from the first time I experienced MyGate as a customer just two years ago, it’s been great to see a fledgling startup execute consistently and holistically, and grow into a category-creating market-leader. We’re delighted by the progress of MyGate and welcome these marquee investors, as the company prepares for the next wave of growth,” said Sanjay Swamy, Managing Partner, Prime Venture Partners.