Home Blog Page 306

‘Silence’ hits Bangladesh’s Dutch Bangla Bank to steal $3 million

Bank hack

Security researchers discovered that a group of hackers breached multiple banks in 25 plus countries worldwide, including Bangladesh, India, Sri Lanka, and Kyrgyzstan.

According to the research firm Group-IB, a hacker group named Silence is likely behind the recent cyber-attack on the Dutch Bangla Bank Limited in Bangladesh. The attackers apparently scooped more than $3 million in an ATM cash-out attack that occurred in May 2019, the ZDNet reported.

Group-IB stated the Silence group has been active since 2016 and previously attacked banks in Russia, former Soviet states, and Eastern Europe. It’s said that the hacker group appears to have deployed a malicious code, named Silence malware, on the bank’s network to run malicious commands on hosts and allegedly used the access to orchestrate fund withdrawals from the bank’s ATMs, according to the security researcher Rustam Mirkasymov at Group-IB.

“Group-IB has the ability to actively track cybercriminals’ infrastructure of this and other financially motivated cybercriminal groups. This all gives us visibility to indefinitely confirm that an infected machine inside the bank’s network was communicating with Silence’ infrastructure,” said Mirkasymov. “In this case, we discovered that Dutch Bangla Bank’s hosts with external IPs 103.11.138.47 and 103.11.138.198 were communicating with Silence’s C&C (185.20.187.89) since at least February 2019.”

Describing the hacker group Dmitry Volkov, the Chief Technology Officer and Head of Threat Intelligence at Group-IB, said, “It appears that the cybercriminals responsible for these crimes were at some point active in the security community. Either as penetration testers or reverse engineers. They carefully study the attacks conducted by other cybercriminal groups and analyze antivirus and Threat Intelligence reports. Many of Silence’s tools are legitimate, others they developed themselves and learn from other gangs. The Internet, particularly the underground web, favors this kind of transformation; it is now far easier to become a cybercriminal than 5–7 years ago.”

Multiple banks and other financial companies in several West African countries have suffered from different hacking attacks, which are underway since mid-2017. According to a report published by Symantec, financial institutions in Cameroon, Congo (DR), Equatorial Guinea, Ghana, and the Ivory Coast have been hit by multiple cyber-attacks in 2017 and 2018. Symantec stated the intruders who are behind these attacks were unknown.

Symantec stated that it has detected four distinct hacking campaigns targeted against financial firms in Africa. The first attack started in mid-2017 and has infected computers with a malware known as NanoCore (Trojan.Nancrat). The second type of attack began in late 2017, in which cybercriminals used malicious PowerShell scripts and credential-stealing tool Mimikatz (Hacktool.Mimikatz) to exploit their targets.

The third attack was targeted at banks in Ivory Coast using a malware called Remote Manipulator System RAT (Backdoor.Gussdoor), alongside Mimikatz and two custom Remote Desktop Protocol (RDP) tools. The fourth attack started in December 2018. The intruders used a malware known as Imminent Monitor RAT (Infostealer.Hawket) to attack banks in Ivory Coast. Symantec stated that all the four attacks were discovered through alerts generated by its Targeted Attack Analytics (TAA), which uses artificial intelligence to analyze and spot targeted attacks.

US Military discovers flaw in Outlook, warns users to update

Outlook

The U.S. Cyber Command has issued a public warning to users, companies, and government agencies stating that it is has discovered an “active malicious use” of a vulnerability in Microsoft Outlook that seems to be linked to Iran-backed attackers. The agency stated the attackers might exploit the flaw in the Outlook mail client to turn off security features and gain access to users’ credentials.

“USCYBERCOM has discovered active malicious use of CVE-2017-11774 and recommends immediate patching,” the agency said in a Twitter post.

The Cyber Command suggested the users update their unpatched Outlook versions to prevent potential cyber-attacks. The warning comes after the recent reports that Iran and the U.S. are involving in offensive cyber campaigns.

Recently, the Military cyber forces of the United States launched a cyber-attack against Iranian Military computer systems in response to Iran’s shootdown of $240 million worth U.S. surveillance drone. The attack was performed with the approval from the President Donald Trump.

The attack was targeted on the Iranian military computers that used to control the entire Iran missile operations. According to the Islamic Revolutionary Guard Corps, the drone was taken down when it entered Iran’s airspace near the Kouhmobarak district in the south of Hormuz.

“The downing of the American drone was a clear message to America … our borders are Iran’s red line and we will react strongly against any aggression … Iran is not seeking war with any country, but we are fully prepared to defend Iran,” the Revolutionary Guard commander, Hossein Salami, said in a media statement.

However, the U.S. Air Force denied Iran’s argument. “This was an unprovoked attack on a U.S. surveillance asset that had not violated Iranian airspace at any time during its mission,” said General Joseph Guastella. “This attack is an attempt to disrupt our ability to monitor the area following recent threats to international shipping and the free flow of commerce. The aircraft was over the Strait of Hormuz and fell into international waters.”

Recently, the cybersecurity research firm FireEye claimed that an undetected hackers’ group from Iran is allegedly stealing travel and mobile data of individuals in the Middle East region. According to FireEye, the Iranian group dubbed APT39 has targeted several people in the Middle East, especially in the Gulf region. It’s believed that the espionage group is allegedly providing information to the Iranian government. The researchers at FireEye stated that they had been tracking APT39 activities since 2014 to protect organizations from cyber incidents.

Indiana University launches Cybersecurity Clinic to train security professionals

Indiana University

With an aim to enhance the cybersecurity posture of the state, Indiana University has announced the launch of a new Cybersecurity Clinic.

The University stated the new clinic will serve as a cybersecurity hub for training and address security issues encountered by governments, businesses, and individuals. The Clinic also helps not-for-profit organizations and small businesses better manage cyber-attacks, protect intellectual property, and improve data privacy.

The new cybersecurity clinic, worth of $340,000, will work along with students from across the university, including the Kelley School of Business, the Maurer School of Law, and the School of Informatics, Computing, and Engineering.

“As Indiana continues to establish a strategic framework of cybersecurity initiatives, we’re committed to taking an all-hands-on-deck approach that combines the cyber expertise and leadership of our universities, research centers and businesses,” said Dave Roberts, chief innovation officer at the Indiana Economic Development Corp. “We’re excited to contribute to the launch of the new IU Cybersecurity Clinic, which will offer next-generation training and real-world experience for Hoosier students while assisting organizations in instilling an array of cybersecurity best practices and expanding Indiana’s cybersecurity professional workforce that will be integral to powering our economy into the 21st century.”

Three Universities in the United States have recently disclosed data breach incidents that exposed personally identifiable information of students and working staff. The three universities, Graceland University, Oregon State University, and Missouri Southern State University, stated that unknown intruders made unauthorized access to some of their employees’ email accounts.

The exposed information included, students’ full name, social security number, date of birth, address, telephone number, email address, parents/children, salary information, and financial aid information for enrollment.

The students and employees whose personal information was potentially stolen or accessed in the incident have been notified. The security professionals at the universities clarified that no evidence has been found of the impacted personal information being stolen or used in a malicious manner.

Recently, the Australian National University discovered a major data breach that affected students’ and University’s sensitive information. According to the University’s Vice-Chancellor Brian Schmidt, unknown cybercriminals attacked University’s systems and accessed personal information late in 2018, which was recently discovered by the University authorities on May 17, 2019. It’s believed that the hackers had unauthorized access to 19 years of significant amounts of information related to personal staff, students, and visitors.

Island Hopping becoming prominent technique to launch cyber-attacks: Survey

Hackers Exploiting Cisco’s ASA/FTD Software to Steal Data

Security researchers opined that ‘Island Hopping’ is an increasingly popular cyber-attack technique using by the cybercriminals in recent times. Island Hopping is an advanced attack method, where attackers intrude their target organization through small companies that work with the target company. In this attack, the hackers compromise the network system between the two companies and take advantage of the digital assets.

According to the cybersecurity firm Carbon Black, attackers are using Island Hopping method to infiltrate smaller companies like HR, marketing, and healthcare firms to allegedly access a larger target organization.

The Carbon Black stated the Island Hopping method has seen a rise in usage over the past few years, with 50 percent attacks were launched using the same. In its report, Carbon Black’s Quarterly Incident Threat Report, the company revealed that the industries most affected by island hopping are financial (42 percent), manufacturing (32 percent), and retail (32 percent).

“At this point, [island hopping] has become part and parcel of a cybercrime conspiracy,” said Tom Kellerman, Carbon Black’s chief cybersecurity officer. “They’re using their victim’s brand against customers and partners of that company. They’re not just, say, invading your house – they’re setting up shop there, so they can invade your neighbours’ houses too.”

A similar survey from Carbon Black stated the rate of cyber-attacks on healthcare industry appear to be increasing exponentially. In its survey report Healthcare Cyber Heists in 2019, Carbon Black has disclosed what is happening to the Personal Health Information (PHI) that was stolen by cybercriminals.

The survey, which involved 20 of the healthcare industry’s Chief Information Security Officers (CISOs), found the healthcare sector being targeted because of how lucrative PHI is when compared to other personal data like credit card numbers. It’s said that personal health information is worth three times more than other personal information since the health information never changes and can be used by cybercriminal groups for extortion or compromise.

The survey revealed that around 83% of surveyed healthcare organizations stated they’ve seen an increase in cyber-attacks over the past year and over 66% surveyed said that cyber-attacks have become more sophisticated over the past year.

Phishing and Ransomware are the top attacks on Financial Firms: Survey

phishing campaign, Smishing attacks

Security researchers stated that Phishing and Ransomware attacks are the most reported types of cyber-attacks on financial services firms. According to the Audit and Consulting firm RSM International in the United Kingdom, around 819 cyber incidents were reported by Financial services firms to the Financial Conduct Authority (FCA) last year.

RSM said that Retail Banks were the most frequently affected by cyber-attacks (486 security incidents) followed by wholesale financial markets (115 attacks), and retail investment firms (53 incidents). In 2018, financial firms reported around 93 cyber-attacks, in which half of these (48 attacks) were phishing attacks while 20 percent (19 attacks) were ransomware attacks.

RSM said the sudden increase in the companies reporting security incidents was due to the introduction of the European Union’s General Data Protection Regulation (GDPR) laws that took effect last May.

“Overall, there remain serious vulnerabilities across some financial services businesses when it comes to the effectiveness of their cyber controls,” said RSM technology risk assurance partner Steve Snaith. “More needs to be done to embed a cyber resilient culture and ensure effective incident reporting processes are in place.”

A recent study revealed that the introduction of the GDPR has resulted in a significant decrease in data leaks and thefts. The study dubbed Data Privacy Benchmark Study from networking company Cisco Systems stated that nearly three-quarter of GDPR-ready companies suffered fewer data breaches in the last year than organizations that have not been GDPR compliant.

The survey report, which is prepared based on data from more than 3,200 security professionals in 18 countries and across all major industries worldwide, also found that approximately 60 percent of companies have met most of the GDPR requirements, with nearly 30 percent more expected to do so within a year.

Country wise, the research stated the level of GDPR-readiness increased from 42 percent to 76 percent, stating that the European countries (Spain, Italy, UK, France, and Germany) were on the higher end of the range. Data security, internal training, evolving regulations, and Privacy by Design requirements were the major challenges faced by organizations while getting ready for GDPR, the research stated.

Cyber Deception Technology startup TrapX raises $18 million

Cyber Deception

Cybersecurity firm TrapX Security recently announced that it has completed an $18 million financing round led by Ibex Investors along with the participation from the existing investors, BRM, Opus Capital, Intel Capital, Liberty Technology Venture Capital, and Strategic Cyber Ventures. The San Jose-based company stated the new proceedings will help to expand the company’s reach globally.

Founded in 2012, TrapX Security is the pioneer in Cyber Deception Technology. The company claims that its DeceptionGrid solution quickly detects, deceives, and defeats advanced cyber-attacks and human attackers in real-time.

Speaking on the new investment round Moshe Ben-Simon, the CEO of TrapX Security, said “This round of funding will help propel TrapX as we embark on our growth stage of the company. Global expansion and continued R&D innovation will be the catalyst for highly regulated industries and those plagued with legacy infrastructure are increasingly turning to TrapX to detect and deceive today’s cybercriminals.”

As per the investment deal, Brian Abrams, the President of Ibex Investors will join the TrapX’s board of directors. “TrapX is positioned for a phenomenal opportunity in the cybersecurity market, given its ability to provide unparalleled visibility and to operate in environments that cannot deploy other security tools because of economic or technical reasons such as highly distributed networks, IoT networks, and SCADA. We are impressed with the company’s continued focus on leading the threat detection market in innovation and cutting-edge technology,” said Abrams.

Austrian Banks well prepared to handle cyber threats: FMA

Austria cybersecurity

The Austrian Financial Market Authority (FMA), the country’s financial regulator, stated that the banks in Austrian were found to be well prepared to defend themselves from evolving cyber threats after it staged the first Cyber War Game in the country. The cybersecurity test was launched on 10 banks, their IT providers, the Austrian Computer Emergency Response Team, and the interior ministry.

The one-day Cyber War Game exercise, consisted of 170 fake attacks launched by 100 experts, is intended to test the security levels of banks, technology providers, public authorities, and other financial organizations in the country. The fake cyber-attacks included malicious software injection, Phishing attacks and attacks that targeted system software and online banking apps as well as the shutdown of ATMs and websites, according to FMA.

“The organizational designs have shown to be very diverse,” FMA co-heads Helmut Ettl and Klaus Kumpfmueller said in a media statement. “The results will now be analyzed in detail and the consequences will be implemented in supervisory and regulatory activity.”

Recently, multiple banks and other financial companies in several West African countries have suffered from different hacking attacks, which are underway since mid-2017. According to a report published by Symantec, financial institutions in Cameroon, Congo (DR), Equatorial Guinea, Ghana, and the Ivory Coast have been hit by multiple cyber-attacks in 2017 and 2018. Symantec stated the intruders who are behind these attacks were unknown.

Symantec stated that it has detected four distinct hacking campaigns targeted against financial firms in Africa. The first attack started in mid-2017 and has infected computers with a malware known as NanoCore (Trojan.Nancrat). The second type of attack began in late 2017, in which cybercriminals used malicious PowerShell scripts and credential-stealing tool Mimikatz (Hacktool.Mimikatz) to exploit their targets.

The third attack was targeted at banks in Ivory Coast using a malware called Remote Manipulator System RAT (Backdoor.Gussdoor), alongside Mimikatz and two custom Remote Desktop Protocol (RDP) tools. The fourth attack started in December 2018. The intruders used a malware known as Imminent Monitor RAT (Infostealer.Hawket) to attack banks in Ivory Coast. Symantec stated that all the four attacks were discovered through alerts generated by its Targeted Attack Analytics (TAA), which uses artificial intelligence to analyze and spot targeted attacks.

Exabeam acquires Israel startup SkyFormation for business expansion

Acquisition

Exabeam, a cybersecurity and security information event management (SIEM) company, recently announced the acquisition of SkyFormation, a leading Israel-based cloud application security provider.

Founded in 2014 by security veterans Asaf Barkan, Uri Ben-dor, and Nadav Lavy, SkyFormation help organizations protect their data by using behavioral analytics to detect the tactics and techniques of cyber attackers.

The new acquisition allows SkyFormation to consistently collect logs from over 30 cloud services into Exabeam Data Lake, Exabeam Advanced Analytics or any other SIEM. The company claims that it’s the first company to collect cloud logs from over 30 cloud services into any security information and event management (SIEM) tool.

Headquartered in the United States, Exabeam helps organizations by providing security intelligence and management solutions to strengthen their information security. The company claims that its Security Intelligence Platform leverages big data, machine learning, and analytics to detect and respond to cyber threats. It’s one among the number of security information and event management (SIEM) platforms that analyze companies’ log data sources to flag abnormal activities.

“We are very excited to welcome the entire SkyFormation team and its partners to Exabeam. Exabeam customers have long been able to use the SkyFormation platform as part of our solution, but this acquisition means other organizations will now be able to augment their SIEM with Cloud Connectors to modernize their security operations. I look forward to growing our new Israel office,” said Nir Polak, co-founder and CEO of Exabeam.

“This announcement is great news for the SkyFormation team, for Exabeam and for every customer that will now be able to benefit from our combined security portfolio. It’s exciting to be joining a global leader in SIEM, and to help Exabeam’s customers secure their applications as they move to the cloud,” said Asaf Barkan, co-founder and CEO of SkyFormation.

Exabeam recently partnered with the Deakin University in Australia to strengthen its security management and reinforce its distinguished cybersecurity degree program. Deakin University combines research and teachings with a focus on supporting the communities it serves. The Geelong-based university stated that it deployed Exabeam’s Advanced Analytics platform to streamline alerts, analyze behavioral patterns, and identify the critical anomalies on its network.

Also, the Enterprise Resource Planning (ERP) cybersecurity solutions provider Onapsis recently announced a technology alliance and product integration with Exabeam to give security teams access to ERP vulnerability logs in their security incident and event management (SIEM) for security monitoring.

In May 2019, Exabeam secured $75 million in a Series E funding round jointly led by new investor Sapphire Ventures and Lightspeed Venture Partners along with the participation from other existing investors. The San Mateo-based startup stated the new funds will be used for expanding sales reach and accelerate new product lines.

Indian Manufacturing Industry is vulnerable to cyber-attacks: Survey

India manufacturing

Security researchers have revealed that the Indian manufacturing industry is currently facing severe cybersecurity risks. According to a survey from cybersecurity firm Seqrite, the manufacturing sector in India accounted for more than 27 percent of the threats detected between January and March 2019. Seqrite, an enterprise arm of Quick Heal technologies, is a specialist provider of endpoint security, network security, enterprise mobility management, and data protection solutions.

In its research report, named Threat Report Q1 2019, Seqrite highlighted that many of the IoT devices used by manufacturers like sensors, barcode readers, quality control systems, inventory management solutions, etc. come with minimal security, giving an avenue to cybercriminals to attack and infiltrate the enterprise network.

The survey also stated the manufacturers with inadequate cybersecurity measures might be an easy target for attackers, causing potential risk to their intellectual properties (IP) such as new technologies, products, confidential designs and formulas.

Apart from the manufacturing industry, the other sectors which were at high risk from cyber threats are enterprises in industries such as Professional Services (22.59 percent) and Education (14.64 percent), according to the report.

“Over the years, manufacturers across India have invested heavily to secure themselves against physical intrusions and damages. However, ensuring robust digital security for their IT systems as well as the connected devices used in manufacturing processes has remained quite low on the list of priorities,” said Sanjay Katkar, Joint Managing Director and Chief Technology Officer at Quick Heal.

“Indian manufacturing sector is vulnerable to threats from cyber-criminals looking to make financial gains, corporate espionage by competitors looking to gain competitive advantage, and/or state-sponsored threat actors looking to cause widespread economic disruption,” Katkar added.

A similar research revealed that the gaming industry has become an attractive target for cybercriminals with 12 billion credential stuffing attacks reported in the past 17 months (November 2017-March 2019). According to the Cloud delivery network provider Akamai Technologies, the gaming community is among the most lucrative targets for hackers to make a quick profit. In its research report, “2019 State of the Internet/Security Web Attacks and Gaming Abuse” Akamai stated that there were 55 billion cases of credential stuffing attacks across all industries.

The report highlighted that nearly 67% of credential stuffing attacks target organizations based in the United States. It stated that Russia is the second largest source of application attacks and China is ranked as the fourth highest source country. On the other hand, the United Kingdom ranked as the second highest targeted country with Japan, Canada, Australia, and Italy are all also among the countries most targeted.

California Consumer Privacy Act: Here’s Where Most Companies Will Fall Short

California Consumer Privacy Act

By Jason Patel, CTO, Ensighten

Most enterprises have scarcely caught their breath following last year’s GDPR go-live date in Europe, and already the drumbeat of questions around a new piece of consumer privacy legislation is picking up pace: What is the California Consumer Privacy Act (CCPA)? Does it affect us? What do we need to do to be compliant when it goes live on Jan. 1, 2020?

As with GDPR, we can expect to see a scurry within organizations in the six months leading up to CCPA’s effective date, as this complex regulation requires a number of changes when it comes to how organizations handle consumer data. But there’s a problem: Companies are not yet fully cognizant of the full spectrum of risk, when it comes to how consumer data is collected on most companies’ websites. This limited awareness amounts to blindspots, which as it stands, make it hard for organizations to knowingly, wholly comply with CCPA.

A Spotlight on Consumer Control

To understand the challenges companies will face in complying with CCPA, it’s useful to understand the overall intention of the legislation. In general, CCPA is designed to enhance privacy rights of California residents by imposing obligations on businesses that collect or share consumers’ personal data. Under CCPA:

  • Businesses that collect personal data must disclose what categories of personal data are being collected, as well as the consumers’ right and means to request deletion of their collected personal data
  • Businesses that share or sell personal data must:
    • Disclose that they do so, as well as the consumers’ right and means to opt out of sale or sharing of their personal data.
    • Upon request, disclose the information that they sold or disclosed, for what purpose, and to whom.

As you can see, CCPA requires organizations have a deep understanding of exactly how they are collecting and using consumers’ data, and that can be a challenge, especially in large enterprises. But, what’s particularly challenging is the identification of who else has access to the data collected through a company’s site—and what they’re doing with it.

Understanding Unauthorized Data Access

Under CCPA, organizations are responsible for any and all data collection that occurs via their digital properties. Internal coordination and communication typically enables organizations to get a handle on how the companies themselves are ingesting and managing consumer data. But what about third parties?

Websites rely on third-party vendors to deliver critical functionality, including payment processing, customer log-in, registration services, chat capabilities, social media functionality and customer tracking for advertising purposes. While these features are necessary for meeting customer demands in today’s digital ecosystem, each one can enable third-party exchange of consumer data—and not just with the third-party vendors themselves.

In the course of any given vendor integration, tagging comes into play and therefore risk. Without getting too specific, it’s safe to say that, dozens or even hundreds of tags may be placed on a site. Companies must be able to identify and report that data collection to avoid breaching the terms of CCPA. So, how can a company ensure it has a full view of risk factors?

Improving Transparency, Shoring Up Vulnerabilities

In the ramp up to CCPA, companies need to be putting systems in place that help them not only pull back the curtain on unauthorized data access, but also shore up points of potential data breach and leakage. Here are areas that require special attention:

  • Understanding and control of data access: Companies should seek a real-time view of third-party technologies on all digital properties. These insights need to include all third- and fourth-party points of access, both authorized and unauthorized. Companies must also be able to block access to unauthorized and undesirable parties by default, which can be achieved through the use of a whitelist.
  • Consent and enforcement: Consumers must be able to access and request deletion of their personal data and opt out of its sale at their discretion. A business must provide methods, such as posting a “do not sell my data” request link on the website, to enable consumers to opt out of sharing of their data.
  • Disclosure of data collection: Consumers must have the right to know whether their personal data is collected, sold or disclosed and to whom. Data collection includes any buying, renting, gathering, obtaining, receiving or accessing any personal information by any means, whether actively or passively. A business must provide methods such as posting a “delete my data” request link on the website to enable consumers to request deletion of their personal information. Without a full view of third-party technologies across all their digital properties, many companies will struggle to wholly comply with requests for access or deletion.

While coming into compliance with new privacy regulations can be daunting, the process also represents an opportunity for companies to bring themselves into alignment with best practices for customer data security. After all, GDPR and CCPA are just the beginning. Consumer data privacy concerns aren’t going away, and future legislation is likely to get stricter. Now is the time to put in place a foundation that not only brings a company’s data practices into alignment with current regulatory requirements, but also future-proofs the organization against future developments and potential costly data breaches and leakage.

The opinions expressed in this article are the personal opinions of the author. The facts and opinions appearing in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.