Home Blog Page 31

Hackers Compromise PM Modi’s Twitter Account To Publish a Bitcoin Post

PM Modi Twitter

Not all cybercriminal activities are intended to steal credentials. Several threat actor groups often compromise/penetrate social media accounts of public figures such as political leaders, entrepreneurs, and movie actors to show their presence and hacking capabilities. Recently, threat actors compromised the Twitter handle of Indian Prime Minister Narendra Modi and posted a message regarding Bitcoins. However, the officials immediately secured the Twitter account and reported the citizens to ignore the post.

“The Twitter handle of PM @narendramodi was very briefly compromised. The matter was escalated to Twitter, and the account has been immediately secured. In the brief period that the account was compromised, any Tweet shared must be ignored,” the Prime Minister Office (PMO) said.

Investigation Underway

Following the incident, the Indian Computer Emergency Response System (Cert-In) asked Twitter for complete details regarding the hack and probed an investigation. The officials are working on identifying the adversaries behind this act.

Twitter’s Response

The officials at Twitter stated they took all the necessary security measures to restore the affected account as soon as it became aware of the activity. The company also confirmed that PM Modi’s Twitter account was not compromised due to any breach of its internal systems.

Also Read: How to Report and Regain Access to Your Hacked Twitter Account

Not the First Time

Earlier in September 2020, threat actors illicitly obtained access to PM Modi’s profile and posted a series of tweets asking followers to donate to a relief fund through cryptocurrency.

Besides, Bitcoin scammers carried out a high-profile hack that compromised nearly 130 Twitter accounts, including verified accounts of known personalities like Jeff Bezos, Bill Gates, Elon Musk, Barack Obama, Joe Biden, and corporate accounts of Apple, Uber, and many more.  It was termed “The Greatest Twitter Hack” because multiple verified accounts were hacked simultaneously to scam people.

“We Need to Rethink How Security is Applied Throughout the Organization”

As we wind down another year and prepare for the next, business leaders and CISOs are thinking about the plans and strategies they want to execute in 2022. CISOs are thinking about security investments and the tools and technologies they want to adopt in 2022. Security strategies top their agendas.

In an exclusive video interview, Brian Pereira, Editor-in-Chief, CISO MAG and Justin Hurst, Field CTO, APJ for Nutanix discuss security strategies that leading organizations are betting on, to ensure security isn’t dictating their business growth.

Hurst says organizations face a tremendous risk as they embrace the cloud and digital transformation. The risks include loss of revenue, risk of reputation, customer churn, loss of sensitive data, and complete breach of compliance.

Security Strategies

The balance for companies is finding a way to embrace these new technologies — to embrace the agility of the public and hybrid cloud. But they should do so in a way that incorporates security posture from the foundation up.

The challenge that many companies are facing is that they want to use these new resources; they want to use the agility of the cloud, but their people and their processes are in an on-prem mode of thinking. The type of security that is used today in the private data center does not apply in the hybrid or public cloud world. So it requires rethinking how security is thought about throughout the whole organization — not just the compliance team. More so as apps are modernized and moved to the public and private cloud.


Also see:

3 Takeaways from 2020 for CISOs to Guide This Year’s Strategy


At Nutanix, Hurst is responsible for guiding and articulating technical vision across all products and platforms in the APJ region. His key focus areas are enabling digital transformation, IT modernization, and innovation  through design. He also connects Nutanix customers and partners with internal R&D to guide product direction and ensure customer success. He brings twenty years of experience in a broad range of technology roles, including IT  operations, architecture, education, and sales. He has been with Nutanix for over eight  years. Justin is a frequent keynote speaker, and has presented worldwide on transformative  technological change and embracing disruption. He is based in Tokyo, Japan.

The CISO Playbook: Storage & Backup Security Edition

security

Of the three main IT infrastructure categories — compute, network, and storage — the latter often holds the greatest value, from both security and business perspectives.

 SPONSORED CONTENT 

Security vulnerabilities and misconfigurations of storage and backup devices present a significant threat, especially as ransomware attacks have taken hold of businesses over the past few years. Yet, the security posture of most enterprise storage systems is strikingly weak.

According to Gartner’s recent report on Cyberstorage: ‘Although numerous solutions are available for endpoint protection, centralized storage lacks active protection against malicious attacks.’

Organizations must act immediately to better protect their storage – as well as backup systems – to ensure their data is secure against ransomware and other cyberattacks.

To help organizations gain the visibility they need to understand their storage vulnerability risk and avoid blind spots, CISO MAG partnered with Continuity to provide a practical guide for CISOs and security practitioners.

This guide provides an overview of the evolution of storage and backup technology, recent security threats, and the risks they pose. It also includes a set of recommendations for the secure configuration and protection of storage and backup systems.

securityLearn all about this and much more, by downloading the Whitepaper.

Russia Blocks Tor Web Over Privacy Concerns

Russia Bans Tor

Restrictions on internet usage and other online products are quite common in Russia. According to a report, the country banned the Tor web anonymity services and six virtual private network (VPN) operators for allowing citizens access to illegal content. The VPN services blocked included Betternet, Lantern, X-VPN, Cloudflare WARP, Tachyon VPN, and PrivateTunnel.

Russia’s privacy watchdog Roskomnadzor, also known as the Federal Service for Supervision of Communications, Information Technology and Mass Media, announced the website www.torproject.org had been prohibited based on a court decision.

Tor (The Onion Router) is a free and open-source browser that provides an anonymous communication platform online.  Tor browser’s intended use is to protect the personal privacy of its users, as well as their freedom and ability to conduct confidential communication by keeping their Internet activities unmonitored.

Also Read: DDoS Attacks in Russia Surge 2.5 Times in 2021

The latest ban on the Tor browser is evident of the fact that the Russian government continues to control the internet and prevent any attempts to avoid locally imposed restrictions on internet usage.

“The grounds for this were the placement of information on this website that enables the operation of tools that provide access to unlawful content. Today, access to the resource has been restricted,” Roskomnadzor said in a statement.

Tor Responds

Responding to the censorship, Tor stated Russia has the second largest number of Tor users, with more than 300,000 daily users or 15% of all Tor users. The company urged users to help connect users to its services via the Run a Tor Bridge campaign.

“As it seems this situation could quickly escalate to a country-wide Tor block, it’s urgent that we respond to this censorship! We need your help NOW to keep Russians connected to Tor! Last month we launched the campaign Help Censored Users, Run a Tor Bridge to motivate more volunteers to spin up more bridges. We are calling on everyone to spin up a Tor bridge! If you’ve ever considered running a bridge, now is an excellent time to get started, as your help is urgently needed,” Tor said in a statement.

Prevent Cybercriminals From Making a Run for Your Money and Personal Details

Cybercriminals

The excitement of obtaining a bargain will soon be driving retail fever with holiday deals fueling online sales across the world. India’s e-commerce festive sale season 2020 recorded INR 58,000 crore ($8.3 billion) worth of gross sales for brands and sellers, up 65% from INR 35,000 crore ($5 billion) last year. In all this excitement it is easy to forget the fundamentals of online security, making consumers and retailers easier and more profitable targets for cybercriminals.

By Ali Neil, Director of International Security Solutions, Verizon Business

Data Breach Investigations Report (2021 DBIR) recently highlighted that cybercriminal predominately targets confidential data held within retail outlets including consumer payment details (42%), personal details (41%), and credentials (33%).

If Something Looks Too Good to be True, It Probably is!

The retail industry continues to be a target for financially motivated criminals looking to cash in on the combination of payment cards and personal information which thrives in this sector. Social tactics include Pretexting and Phishing, with the former commonly resulting in fraudulent money transfers. These tactics were used in 77% of the breaches examined within the retail sector in the 2021 DBIR.

Phishing campaigns can be broken down into four distinct groups – a scam, such as an email from a relative who is trapped overseas and needs cash to get home; brand impersonation, the email poses as a bank or a trusted brand name requiring the user to confirm a payment or with a special retail bargain; extortion, designed to frighten the user into compiling and finally Business Email Compromise (BEC), this is a highly targeted attack at a business rather than an individual. All campaigns urge users to click on links, which will navigate them to false pages or send confidential information.

The use of QR codes has also risen during the pandemic, especially amongst smaller retailers and hospitality venues, as an easy ordering and payment solution. However, consumers should beware as these can also direct them to suspicious URLs to make payments, send location details as well as a link to their social media profiles – all without their knowledge, in an attempt to steal personal credential and payment information.

If a company is offering a retail bargain that is simply too good to be true – then it probably is! Don’t click on the link!

Obviously, the main advice to avoid Phishing scams is not to open the emails, however, our human nature and curiosity make this easier said than done.

Education is the best defense here. Regular employee training which highlights the tactics used by phishing campaigns and how to spot them is essential in protecting confidential data within a company as well as helping an employee in their personal e-commerce world.

Maintaining the Security Balance – The Retailer Responsibility

In the cybersecurity world, retailers live in the unenviable position of having to consider their own data security as well as that of their many customers. In an increasingly digital age, it’s important to install as many security measures as a company can, but equally important is the general awareness of what cybercriminals are after and how they’re doing it. Having an open mind to the newest technologies is an invaluable way to always be one step ahead of would-be attackers.

Our data shows us that over the last five years 35% of the 1,354 breaches which stole payment card information resulted from compromised Point of Sale (PoS) systems, as used in brick-and mortar-retail stores; whilst 38% came from compromised web applications, such as online shopping sites.

These web attacks compromise a website’s payment application and then install code into the application that will capture customers’ payment card information as they complete their purchases. These are the everyday attacks that don’t necessarily make headlines but have the same consequences. Today’s cybercriminals look for vulnerable e-commerce applications to provide an avenue for efficient and automated attacks.

Things companies can do to decrease this threat include:

  • Keeping data safe: To keep data safe, retailers must take appropriate measures to help combat cyberattacks. While there is no end-all solution, here are a few steps companies can take to mitigate risk.
  • Know the importance of integrity software: Cybercriminals who target web applications aren’t targeting data at rest. Rather, they inject code to capture customer data as it’s entered intobri web forms. To combat this method, consider adding file integrity software to your malware defenses on payments sites, in addition to patching OS, and payment application code.
  • Embrace what’s new: Continue to embrace new technologies that make it harder for criminals to use POS terminals as low-hanging fruit. Some considerations are EMV and mobile wallets, or any other method that utilizes a one-time transaction code, as opposed to PAN.

While criminals are often after payment card information, it’s not the only data variety that they consider useful. Retailers should also remember that rewards programs that leverage ‘points’ are also potential targets, as these contain valuable customer personal information.

Security is Everyone’s Responsibility

One thing is certain, the security of data no matter where it lies – in a retail organization, on a mobile device, social media account, or on a computer – is everyone’s responsibility. Consumers have a responsibility to ensure that they are diligent and aware of who they share their data with and how they interact online. Equally, retailers have the major responsibility of not only protecting their own preparatory data and brand but also the data of their shoppers who rely on and trust these brands.

For many retail organizations, especially smaller ones, implementing widespread security measures is neither affordable nor feasible. But each security step, no matter how small, can have highly beneficial impacts when it comes to detecting and deterring cybercriminals.


About the Author

Ali Neil_VerizonAlistair Neil is the Director of International Security Solutions at Verizon Enterprise Solutions. He has been associated with Verizon for over 18 years. In his role, Alistair works for the benefit of his clients to provide them with the confidence they need to grow and transform their businesses. He helps them understand their risk, protect their critical digital assets and intelligence, monitor their environments for threats, and be prepared to respond to incidents or breaches.

Alistair’s responsibility is the leadership of Verizon’s Security Sales organization across Europe, the Middle East, Africa, Asia, and Australia. Alistair is also the leader of the Security Solutions business in Europe, Asia, and Australia.

Alistair holds a bachelor’s degree from the University of Southampton.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Around 300,000 MikroTik Devices Vulnerable to Hacker Intrusions

MikroTik Devices, ASUS Routers

Threat actors often prey on vulnerable devices to break into targeted networks. With most employees working remotely, cybercriminals increased their hacking attempts targeting vulnerable commercial IoT devices like Wi-Fi routers. Recently, a security research report from Eclypsium revealed that over 300,000 IP addresses related to MikroTik devices were exposed to remotely exploitable security vulnerabilities.

“These devices are both powerful, [and] often highly vulnerable. This has made MikroTik devices a favorite among threat actors who have commandeered the devices for everything from DDoS attacks, command-and-control (C2), traffic tunneling, and more. An attacker could use well-known techniques and tools to potentially capture sensitive information, such as stealing MFA credentials from a remote user using SMS over Wi-Fi. As with previous attacks, enterprise traffic could be tunneled to another location or malicious content injected into valid traffic,” the researchers added,” the report said.

Based in Europe, MikroTik is a popular provider of routers, wireless ISP systems, hardware, and software for Internet connectivity worldwide.

Vulnerabilities in MikroTik Devices  

MikroTik routers are an enticing target as more than two million devices are deployed globally, becoming a lucrative opportunity for attackers. According to the report, the most affected MikroTik devices are located in Russia, China, Brazil, Indonesia, Italy, Indonesia, and the U.S.

Also Read: BotenaGo – A New Malware Targeting Millions of IoT Devices

The flaws in MikroTik devices could expose users and enterprises to a wide variety of security risks. They can allow remote access to hackers to exploit and penetrate the network. The discovered security flaws include:

  • CVE-2019-3977– MikroTik RouterOS insufficient validation of upgrade package origin, allowing a reset of all usernames and passwords
  • CVE-2019-3978– MikroTik RouterOS insufficient protections of a critical resource, leading to cache poisoning
  • CVE-2018-14847– MikroTik RouterOS directory traversal vulnerability in the WinBox interface
  • CVE-2018-7445– MikroTik RouterOS SMB buffer overflow vulnerability

Besides, the researchers found 20,000 exposed MikroTik devices that injected cryptocurrency mining scripts into web pages that users visited. The ability for compromised routers to inject malicious content, tunnel, copy, or reroute traffic can be used in various highly damaging ways. DNS poisoning could redirect a remote worker’s connection to a malicious website or introduce a machine-in-the-middle,” the researchers added.

How to Protect MikroTik Devices Against Exploitation

MikroTik has listed measures to secure the devices.These include:

  • Keep your MikroTik device up to date with regular upgrades.
  • Do not open access to your device from the internet site to everyone. If you need remote access, only open a secure VPN service, like IPsec.
  • Use a strong password, and even if you do, change it now!
  • Do not assume your local network can be trusted. Malware can attempt to connect to your router if you have a weak password or no password.
  • Inspect your RouterOS configuration for unknown settings, including:
    • System -> Scheduler rules that execute a Fetch script. Remove these.
    • IP -> Socks proxy. If you don’t use this feature or don’t know what it does, it must be disabled.
    • L2TP client named “lvpn” or any L2TP client that you don’t recognize.
    • Input firewall rule that allows access for port 5678.
  • Block domains and tunnel endpoints associated with the Meris botnet.

Spam Attacks: How Not to Get Hooked On Phishing Mails

xss vulnerability in UPS, Phishing Attack, spear phishing, phishing mails

As more criminals turn to online scams to steal your confidential data, phishing prevention has become critical. We now know what spam emails are and have learned to ignore them, but phishing emails can appear to be legitimate. They are sometimes tailored to individual needs.

By Hardik Panchal- General Manager, Networking Services & Operations at Rahi

Phishing emails have become more common over time, especially during the holiday season, when the numbers spike. Despite the fact that it has been around for more than two decades, phishing remains a successful assault strategy among scammers. One reason for its high success rate is its capacity to develop social engineering abilities that prey on human emotions and trust.

A recent survey by Proofpoint found out that 74% of U.S. organizations surveyed reported experiencing a successful phishing attack. To avert data breaches, businesses conduct regular training and educate staff on the various forms of cyber assaults.

Even if your organization has a strong grasp on cybersecurity, data security compliant systems, and end-user security awareness programs, unintentionally downloaded malware or clicking on a link sent through a phishing email; can infect your organization with ransomware, or you will experience a data breach due to a business email compromise (BEC) or email account compromise (EAC).

As per Terranova Security Gone Phishing Tournament, more than 20% of employees are likely to click on phishing email links, and an astounding 67.5 percent of them visit a phishing website and enter their credentials. Microsoft files and PDFs were the most preferred delivery vehicles of attackers, as these documents are widely trusted across the business environment, as per Sonic Walls cyber threat report.

Phishing emails employ different themes as enticement and are sent from top-level domains that instill trust in the minds of the recipients. The email contains attachments hosted on Microsoft Sharepoint or links to websites or landing pages. The documents attached are named ‘Pricing changes’ or ‘Employee bonus information’, however, visiting the link would redirect viewers to a page made for the sole purpose of phishing. Users will be prompted to input their credentials in order to sign in, bypassing a number of sandboxes at various levels.

The use of Microsoft and Google cloud infrastructure is one of many techniques phishers employ to circumvent email security systems and gateways. Some phishing emails will be blocked in user email accounts handled by desktop applications such as email client software. However, in order to totally eradicate the problem, businesses should consider teaching and training personnel in a simulated environment.

Purchase a URL for your phishing emails and send them out at regular intervals with a variety of topics such as requesting network passwords, Diwali gifts, password reset requests, and so on. The click and open rates can be tracked, and the compromised URL can go to a blank page, error 404, or you can take it further to a payment gateway or mine their credentials, just as in a phishing attack.

The practice can be beneficial when it results in lower open and click rates, but what’s more essential is the reporting to the IT desk; this is what organizations want from their workforce. With multiple simulated phishing attempts, IT reporting will rise as employees become more aware of various phishing methods and are less likely to fall when a real attack happens.

See also: How Cybercriminals Use Phishing Kits

Protection from phishing starts with your mindset towards potential red flags. Following precautions need to be taken with your emails all the time –

  1. Alarming messages shouldn’t be trusted – Organizations will never ask about your account details or personal information on an email. In the case of retail companies, when a customer asks for payments and the amount is unusual or item quantity is huge, immediately raise a red flag and report it to your IT department.
  2. Attachments are vehicles of vulnerability – Attachments especially, word, excel, PDFs, and powerpoints in phishing mail might compromise your system security. If an email looks suspicious, do not download the attachment.
  3. Check the website before sharing sensitive information – Before filling a form or handing over your personal information, copy the link and open it in your browser to verify if the website is real or a landing page created to steal your credentials.
  4. Embedded links can seed malware – Embedded links in emails should be avoided as they can install malware on your device or redirect you to another web page where your credentials can be compromised. Enter the correct URL into your browser and review the website’s security report before filling in any time details.
  5. Impersonators can phish you without hacking – When dealing with vendors and customers, there may be times when a phisher will send you an email impersonating the client with whom you are dealing. Before responding to the email or taking any further action, double-check the email and domain name. In most cases, phishing emails have fake domain names that differ slightly from the real ones. For example, if the actual domain name is ‘xyz.com’ a phisher will use ‘xyztech.com’ with other details remaining the same. Thus while doing financial transactions take one extra step and verify the domain name of the company.

The best defense is a trustworthy endpoint security solution that filters out spam and phishing emails. Your best offense will be to educate and raise awareness among employees using a simulated phishing environment that provides a learning opportunity and is a cost-effective way to implement cyber security into your organization.


About the Author

Hardik-Panchal-RahiHardik Panchal is the General Manager, Networking Services & Operations at Rahi. He is a network engineer with a hands-on approach and technological mindset for designing and implementing Enterprise IT and Data Center architecture, including configuration, optimization, and supporting network management systems. He conducts network modeling and analysis to construct a reliable, high-performance integrated network. Panchal also designs, recommends, and implements new solutions to improve the resilience of network operations. He specializes In-Network/Data Center/Security/Wireless & Cloud Technologies.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Organizations Losing Trust in Security Vendors Amid Rising Cyberattacks

supply chain attacks

Organizations that use services of mainstream software providers continue to face trust issues amid the increase in supply chain and ransomware attacks, a recent report from CrowdStrike revealed.

The 2021 CrowdStrike Global Security Attitude Survey report stated that nearly 63% of respondents lost trust in mainstream software suppliers due to security issues connected with products and services from those vendors. Around 45% of respondents had already sustained a supply chain attack last year.

Rise of Supply Chain Attacks

Recent supply chain attacks on Kaseya and Solarwinds represent the security breaches from vulnerable software resources organizations rely on. Around 84% of IT and security professionals believe supply chain attacks will be one of their most significant cybersecurity threats in the next three years.

“This clearly reinforces the need for organizations to revisit their vetting procedures as well as their recovery strategies. If software supply chain attacks increase as expected, organizations could quickly find themselves in considerable difficulty if they have not prepared for such issues. In response to the recent massive increase in supply chain attacks, businesses must change the way they operate and evaluate more stringently the suppliers they work with. Every supplier, no matter their longevity or reputation, needs to be assessed on a continual basis, and their software monitored with the same impartiality as any other,” the report said.

Ransomware – A Persistent Threat

The report also revealed that ransomware attacks remain a highly pervasive threat, costing organizations nearly $2 million on average. They continue to prove effective, with average ransomware payments increasing 62.7% in 2021, hitting organizations hard with double extortion schemes. It was found that over 96% of organizations that paid a ransom were forced to pay additional extortion fees, costing businesses on average $792,493. Nearly 66% of surveyed organizations suffered at least one ransomware attack in the past 12 months. More than half (57%) of businesses did not have a comprehensive ransomware defense strategy in place.

Commenting on the survey findings, Michael Sentonas, Chief Technology Officer at CrowdStrike, said, “The survey presents an alarming picture of the modern threat landscape, demonstrating that adversaries continue to exploit organizations around the world and circumvent outdated technologies. Today’s threat environment is costing businesses around the world millions of dollars and causing additional fallout. The evolving remote workplace is surely accentuating challenges for businesses as legacy software like Microsoft struggles to keep up in today’s accelerated digital world.

“This presents a clear clarion call that businesses need to change the way they operate and evaluate more stringently the suppliers they work with. The threat landscape continues to evolve at a frightening pace and it’s obvious that modern organizations need a cloud-native, holistic end-to-end platform approach to tackle and remediate threats in a swift manner.”

Mitigation

Explaining on how organizations can mitigate the risks from supply chain attacks, Mark Goudie, APJ services director, CrowdStrike, said, “In terms of mitigating the risk of such attacks, companies need to look internally at a number of areas that they can control. They should ensure their supply chain have the same rigorous security protocols they have themselves but in India only 43% of respondents said they had vetted all of their suppliers for security purposes in the past 12 month. That exposes a significant risk especially as supply chains are growing in size and complexity. It is also eroding trust with 63% of respondents in India saying they had lost trust in a new or existing supplier.

Today’s threat environment and the supply chain attack vector highlights the need for organisations around the world to transform their security and adopt a Zero Trust architecture in order to protect their digital assets, identities and core infrastructure as threat actors are well resourced and becoming more sophisticated. It is important to note that even if a supply chain attack does occur, the victim will be better able to prevent, detect and respond to an incident with EDR technology in place. Threat visibility is key to minimising damage from any form cyberattack no matter whether it is a supply chain or otherwise. Organisations at all levels of the supply chain must work together to ensure they do not collectively become the next victims of nation states and cybercriminals executing supply chain attacks.”

Emotet Bypassing TrickBot to Drop Cobalt Strike Beacons

Ransomware attack on Nunavut, Emotet Cobalt Strike

Mid-November 2021 saw the Emotet botnet resurface and was widely reported. The botnet had been taken down by law enforcement agencies in January 2021 and had been inactive since then.

In the latest update, it has been reported that Emotet is using the Cobalt Strike pentesting tool to launch its ransomware attacks.

Threat actors leveraging Emotet were known to use TrickBot to send spam email chains with malicious attachments and links. In the past, TrickBot originated as a banking Trojan to steal sensitive financial information via brute-force attacks or credential harvesting.

In an earlier interaction with CISO MAG, Lotem Finkelstein, Director, Threat Intelligence and Research for Check Point Software Technologies, had opined, “Emotet is responsible for the explosion of targeted ransomware we have seen over the past three years and its comeback might lead to a further increase in such attacks. It is no surprise that Trickbot and its infrastructure are being used to deploy the newly resurgent Emotet. This will not only shorten the time it would take for Emotet to build a significant enough foothold in networks around the world but it is also a sign that, like in the old days, Trickbot and Emotet are united as partners in crime.”

And now, it is the Cobalt Strike tool that is being used as the new partner in crime. It was used to facilitate ransomware attacks by threat groups, and now it is bypassing the Trojans like TrickBot and directly accelerating the attack.

Cobalt Strike Popular with Cybercriminals

Cobalt Strike is threat simulation software used by security experts and penetration testers to identify the potential risk of a data breach or cyberattack. Several security experts stated that threat actors leverage the Cobalt Strike tool for cybercriminal activities.

“Cobalt Strike, while used by security practitioners to ultimately thwart cybercrime, is now a common tool in the arsenal of cybercriminals. For now, most threat actors are relying on open-source methods for deployment and configuration, but we expect cybercriminals to begin to innovate and develop new tactics that defenders will have to adapt to. We expect these innovations particularly from those cybercriminal groups that are using the tool in targeted ransomware attacks,” a report from Intel 471 stated.

The Cobalt Strike tool is used to drop “beacons” as they execute remote surveillance on infected networks and can be used to facilitate ransomware attacks.

Beacon is Cobalt Strike’s payload to model an advanced actor. Beacon executes PowerShell scripts, logs keystrokes, takes screenshots, downloads files, and spawns other payloads.

We need to see what new actions the authorities will enforce to ensure the disruption of the Emotet botnet, before more news of these alarming ransomware attacks make it to the mainstream media.

4 Types of Insiders You Need to Know

Insiders

Despite several employee awareness programs and cybersecurity best practices, most organizations face insider threats that affect the overall security posture. Threat actors continue to target unwitting employees – the weakest link – with different social engineering and phishing lures hitting the mailboxes.

According to Egress’ Insider Data Breach Survey 2021, 94% of organizations sustained insider data breaches last year. Nearly 84% of security leaders surveyed stated that human error was the top cause of cyberattacks, while 28% of the respondents admitted that insiders’ malicious intent is their biggest fear.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

Insider Threats on Rise 

Insider threats and attacks become a burning issue for organizations globally, as a single negligent act of an employee could cost a fortune for the company’s security. Insider threats increased by 47%, from 3,200 in 2018 to 4,716 in 2020. The cost of insider threat incidents also surged by 31%, from $8.76 million in 2018 to $11.45 million in 2020. Employee negligence led to 62% of security incidents, costing global organizations an average of $307,111 per incident.

Also Read: Insider Threats: A Byproduct of the New Normal

Types of Insiders  

All insider attacks are not due to employee errors. Some attacks are the result of employees with malicious intent.

Insiders
Infographic Source: CISO MAG

1. Careless Insider

The careless/negligent insiders are the common type of insiders that most organizations face. These insiders have no ill intentions towards the company; however, their negligent acts create chaos. The common actions (harmful yet unintentional) of a careless insider includes clicking/downloading malicious attachments, responding to phishing lures, and leaving flash drives containing sensitive data unattended, etc.

2. Oblivious Insider

Oblivious insiders have access to the company’s confidential data, making them a primary target for phishers. Attackers often trick these insiders via social engineering to obtain sensitive data or deploy malware.

3. Malicious Insider

These insiders purposefully cause damage to the organization’s security by erasing/stealing sensitive corporate data or helping outsiders deploy malware or ransomware.

4. Saboteur Insider

Insiders making career shifts come under this category. Saboteurs intentionally try to harm their current company’s reputation to show their frustration. Saboteur insiders take revenge against their present company by giving hackers corporate data and vulnerability exploits.

Best Practices 

While we cannot predict insider actions, implementing certain security actions could mitigate the risks. These include:

  • Providing cybersecurity education and training to all employees to boost endpoint security
  • Encouraging all employees and third-party users to maintain cyber by choosing complex passwords (Eg.: “T1g3rudhxn!vo?LSU”)
  • Establishing physical security in work environments by inspecting everyone entering critical IT server rooms
  • Monitoring remote access from all endpoints and mobile devices
  • Creating a backup system or backup policy

Note: Do not use the passwords used as example in this article for your actual password.

About the Author

Rudra Srinivas

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

More from the Rudra.