Home Blog Page 32

“Security is a Priority for Total Application Experience”

Gregg Ostrowski, Regional CTO at Cisco AppDynamics, application security

The onset of the pandemic in 2020 saw an unimaginable shift to the digital world, where millions dived into cyberspace both as users and service providers. With restrictions imposed on physical mobility across the globe, even non-tech-savvy individuals had to plunge into the digital world just to stay connected with family and friends. The frequency and the number of financial transactions being executed online presented a massive opportunity for cybercriminals.

In an interview with, Gregg Ostrowski, Executive CTO at Cisco AppDynamics, Minu Sirsalewala, Editorial Consultant, CISO MAG, discussed how ransomware attackers and cybercriminals increasingly exploit vulnerabilities caused by gaps in rapid digital transformation. And how increased use of applications, driven by the pandemic, has changed the way application security is viewed. Security sits on top of the total application experience.

Ostrowski is an Executive CTO at AppDynamics, part of Cisco. He engages with customer senior leadership to help prioritize their strategy for digital transformation. Prior to AppDynamics, Ostrowski held senior leadership positions at Samsung and Research in Motion.

Excerpts from the interview follow:

Can you explain why Application Security has gained so much importance in the past year?

In the world we live in today, applications have become critical to our daily lives; they are critical to us and companies or organizations we work with. To help attract new customers, retain customers, and keep them happy, they need to create rapid development cycles. As they needed to innovate quickly, they started introducing different cloud technologies.

With the expansion of the existing infrastructure – which typically runs on premise – it has sprawled to include additional cloud components or additional dependencies for that application. So, what you’re seeing is a sprawl of the overall application topology or the application map that makes all these things work. With all these different dependencies and the need for speed to deliver applications, going with an application security approach or application first security really helps our customers stay ahead of the game and understand what’s happening from a security perspective across all the dependencies of that application. For companies looking to build rapidly, attract new customers and ensure the desired user experience, security needs to be placed in the application first type mentality.

This enables businesses to understand the application stack from a user experience, performance, and security perspective as security affects users more than performance, and a security threat is highly detrimental to the brand.

Is there something called beyond Layer 7 security? If so, what is it?

That is a really interesting question. The OSI, as we know, has 7 layers, and the 7th layer is the Application Layer; everything underneath is a dependency for that application all the way and goes down to the physical servers (Physical Layer).

I wouldn’t necessarily consider a layer beyond seven, but security must be the critical component of every step along the way. So, each piece is going to be implementing security. Be it Denial of Service (DoS) attacks or threat detection, or intrusion detection where application security comes in, it brings all the components together and allows full visibility of the entire layer from a security perspective. I wouldn’t call it beyond Layer 7; rather it is an evolution of how security fits into the overall OSI model.

How can we use Cisco Secure Application to detect and block threats in real time?

The AppDynamics — the product overall has an agent-based model that runs in the runtime of the application. We have included the security, the Cisco secure application within the runtime of the application. This enables us to analyze and understand what’s happening, not just for performance, but also how it is being ineffective by any kind of security threats or vulnerabilities.

And we do that by being able to pull in data from public resources and some proprietary resources that run a list of the current threats and vulnerabilities. So, there is a real-time alert pop-up with tracking that shows where the security threat is happening. We did an application stack, and once a threat is found, we can simply alert and send out a notification to the security teams and the application. And as a preventive measure, we can go down and block that component of the application from becoming more detrimental to the business. This enables both teams – the application teams and the security teams – to collaborate on how to really address the threat.

For example, if there is a web server that’s running a version 2.5 and the version 2.7 happens to have a threat, it can notify the customer that an upcoming version of one of your components of the application stacks has an upcoming vulnerability, so they can address it before it hits the production servers.

Prioritizing and classifying data is key to data management. How can organizations prioritize threats by business impact?

One of the key fundamental aspects of AppDynamics is being able to present it in the business context. We can use our AI capabilities to provide the insights to stack rank on how these threats are coming in and which is the most critical to the business, thereby allowing a window for the IT teams to know which ones to go out and fix.

A good example would be a payment service that affects multiple applications, as the way apps were built, multiple tasks are performed in a shared service type model. Most of these deployed applications run in a microservice-type architecture. So here, the payment services are the most valuable piece to the business, as it is directly tied to the business revenue. Using the AI, we can prioritize the detection and fixing of the threat for the payment service application in comparison to other threats that were coming in and were picked up by Cisco security.

How beneficial is the Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) approach?

I think it is definitely beneficial. When one implements application security testing before the application goes to production, you are putting security in the process of your CI/CD pipeline. As security testing is done pre-production, the Cisco secure application monitors the application while it is running in production.

It is best to move through the scanning process while you are building the application, ensuring security is part of the CI/CD pipeline.

AppSec is a focus area for CISOs with the increasing incidents of data breach. How can DevSecOps help mitigate the security risks and enhance application security?

There is a need to start thinking and bringing teams together and collaborating amongst all aspects of the application development. I strongly believe CISOs need a seat at the table. When one goes through the development cycle, the DevSecOps model, you want to make sure that security is built into the application from the word go. The CISOs role is to look at what new advancements and capabilities need to be incorporated from the security aspect.

When an organization starts focusing on building applications that drive a high-end user experience and performance, the CISO ensures that the application is secure. Their role is not limited to ensuring the latest security technologies but also driving innovations or new user experiences along with security.

DevSecOps is a very, very strong growth trend in the industry. If organizations are not embracing it, it is highly recommended that they consider building some practice that helps with security within their DevOps.

Learnings from the Facebook outage?

This is truly an example of that anybody and everybody could be vulnerable. Though I have not been closely tied to the issue at Facebook, from what I have read and understood, there are multiple shared services and how their entire ecosystem was taken out. The sprawling IT infrastructure is causing the same level of concern for a lot of our customers, with multi dependencies and interdependence, neutropenic type environments where risk must be managed, completely or inclusively.

When you have multiple different applications running in a shared service environment, you do not know where to target first and resolve the issue. It is a combination of both performance as well as security; this incident is a validation of the efforts we need to put at viewing every single dependency of the application stack from a business and security perspective. This also includes the infrastructure that is running on-premise or cloud. Most important is to have the right tools and visibility to be able to do their jobs right.

Security recommendations or best practices?

A DevSecOps model is definitely a strong way of getting started. The second one is to ensure the CISOs seat at the table, when it comes to new innovations and new capabilities. Many organizations are working in silos and not communicating enough to focus on the same direction thereby impacting the business. You have the infrastructures team, the network team, the development team all working in silence. This delays delivery and leads to misalignment of the organization. Having everybody on the same page with a common goal for the business helps align your teams a little bit tighter for the greater good of all.


Minu

About the Interviewer

Minu Sirsalewala is an Editorial Consultant at CISO MAG. She writes news features and interviews.

More from Minu.

QNAP Warns About New Bitcoin Miner Targeting NAS Devices

Coinbase, QNAP Devices

Hardware vendor QNAP released a security advisory warning its users about a new cryptomining malware targeting its network-attached storage (NAS) devices. The Taiwan-based company urged users to take necessary security measures to prevent the ongoing malware campaign.

Once the malware infects a NAS device, the CPU usage becomes unusually high, where a process named “oom_reaper” could occupy around 50% of the total CPU usage. A NAS device is an internet-connected storage device that allows data storage and retrieval from a central location for authorized network users and clients.

“This process mimics a normal, legitimate kernel process with the same name. However, while the legitimate kernel process PID is usually below 1000, the bitcoin miner PID is usually greater than 1000,” the advisory said. While the actors behind the malware campaign are unknown, QNAP stated it is currently investigating the severity of the threat.

Also Read: Illicit Cryptomining Surges Amid Soaring Crypto Value

Mitigation

QNAP stated the infection could be removed by rebooting the affected devices. Customers also need to take proactive measures such as updating operating systems (QTS or QuTS), all QNAP add-on apps, and changing their NAS account passwords.

To protect the NAS devices from the Bitcoin mining malware, the company recommended users to:

  • Update QTS or QuTS hero to the latest version
  • Install and update Malware Remover to the latest version
  • Use stronger passwords for your administrator and other user accounts
  • Update all installed applications to their latest versions
  • Do not expose your NAS to the internet or avoid using default system port numbers 443 and 8080
  • If you suspect your NAS has been infected with the bitcoin miner, restarting the NAS may also remove the malware

Not the First Time

This is not the first that QNAP NAS devices have been under attack. Earlier, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the U.K.’ National Cyber Security Centre (NCSC) uncovered a strain of malware known as QSnatch that targeted QNAP NAS systems.

Internet Crime and Technology: Where Are We Headed?

Cybercrime, internet crime

Cybercrimes have been constantly evolving and extending across national boundaries in the 21st century. Their complexity, along with the ability of threat actors to constantly change and adapt, has now become an important security concern for businesses of all sizes (irrespective of their verticals). We all have witnessed how cybercriminals have continued to drag down organizations across the globe over the years with highly sophisticated methods and techniques, which keep progressing with the surge in remote working culture, automation, dependence on technology, and connectivity.

By Argha Bose, Head of Cybersecurity and Risk Business, Tata Advanced Systems Ltd.

We heard about the attack on the U.S. Colonial Pipeline that transports refined gasoline and jet fuel from Texas to New York. In addition, the Florida water supply security incident (earlier this year) highlighted the risk to the water treatment plants when threat actors increased the level of sodium hydroxide to an extremely dangerous level. And most recently, the world observed how hackers penetrated the defense of the popular U.S. IT company Kaseya and deployed ransomware.

These incidents demonstrated the vulnerability of IT and OT infrastructures to cyberthreats, and the complexity as well as sophistication level that cybercriminals had achieved over the years. They are now turning to advanced technologies like Artificial Intelligence (AI) to scale up their TTPs and circumvent detection.

I think we have seen a further surge in cyberattacks since the COVID-19 outbreak as the enterprises worldwide were forced to transmute and adjust so quickly that the security didn’t get ample time to reach close to the borderline.

The spike of cybercrime skyrocketed during the pandemic, and the fraudsters have leveraged the hype and fear connected with the COVID-19 to cause more damage, monetize and gain profits. With immense pressure on health systems, it has also challenged cybersecurity as more people have started working from home. I believe cybercrime has increased at both individual and organizational levels during this time.  

Evolving Picture of Cybercrime – Targeting the Root of Organizations

 

We have seen threat actors leveraging human vulnerability and make the most out of their fears around health and safety. In a recent study by Cybersecurity Ventures, it was found that nearly 4000 malicious COVID-related sites emerged within a few months of the first lockdown in 2020. Even if we keep the pandemic aside, the last few years have observed so many severe data security breaches at high-profile enterprises worldwide.

Cybercriminals target vulnerabilities and gaps in security, irrespective of the fact whether it is at the human level or the system level. They keep looking for new ways to trick the first line of defense, compromise networks, and exploit vulnerabilities. Social engineering and phishing are the most commonly used as successful methods. Recent industry reports have shown that around 35% of internet users in India were impacted by web-based threats in 2020, which were social engineering attacks masqueraded as COVID-19 related threats. Businesses often struggle to counter such attacks as threat actors take advantage of the trends and fears in the digital ecosystem to trick users and grab their credentials to get access to critical information.

I think that ransomware is another name that can’t be kept aside while talking about the most dominant cyberthreats, which have evolved. Initially, we have seen threat actors encrypting both user and company data and asking for ransom in exchange for the decryption key. But now, cybercriminals have adopted a double-extortion model wherein they steal and publish the data, along with encryption, on the dark marketplaces to threaten victims. At the moment, Ransomware-as-a-Service (RaaS) is termed as the “next-great cyberthreat.” It has aided even the least technically sound cybercriminals to launch attacks and target victims. Ransomware is now being offered as a service on the dark web marketplaces by different operators.

Additionally, the cloud has also expanded the attack surface for businesses across the globe since more enterprises are moving to the cloud. And, therefore cybercriminals have moved their focus in this direction. The assumption that data stored in the cloud applications is highly secured is perishing gradually. Security experts have observed a very heavy volume of attacks (utilizing the IMAP protocol) on popular SaaS applications such as G Suite and Office 365...To read the full story, subscribe to CISO MAG.

This story first appeared in the August 2021 issue of CISO MAG.


About the Author

Argha BoseAfter being associated with leading technology and security organizations for 26 years, Argha Bose is presently working with Tata Advanced Systems Ltd. as the Head – Cyber Security and Risk Business. Previously, he has worked with CA Technologies as Sr. Director, managing Global Services Delivery business. Prior to that, he has also successfully established the IAM practice at HCL Technologies.

He has been an effective professional amalgamated with several successful high-growth organizations. He is a Certified Blockchain Expert and has acquired a Masters degree in Cyber Law and Cybersecurity, as well as other certificates like CISM and CISSP to name a few.

With well-rounded experience in managing business level P&L, CXO level client relationships, handling government and enterprise clients, he is excellent in creating strategic alliances with leading OEMs. His primary focus is in cybersecurity, including Identity and Access Management and Consulting.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Google Takes Legal Action Against Glupteba Botnet

Zoho Vulnerability , Atlassian Confluence Vulnerability

Google recently disrupted the malware activities of a sophisticated botnet – Glupteba. The search engine giant claimed the Glupteba botnet has been targeting Windows systems by protecting itself using blockchain technology. Google disrupted the key command and control infrastructure of the Glupteba to dissolve its operations completely.

“Botnets are a real threat to Internet users and require the efforts of industry and law enforcement to deter them. As part of our ongoing work to protect people who use Google services via Windows and other IoT devices, our Threat Analysis Group took steps to detect and track Glupteba’s malicious activity over time. Our research and understanding of this botnet’s operations put us in a unique position to disrupt it and safeguard Internet users around the world,” Google said.

Glupteba Botnet in Brief

A botnet is a set of Internet-connected devices that carries malicious commands under the remote control of the attacker. Threat actors often use botnets to compromise a targeted network, deploy malware, and launch Distributed Denial-of-Service (DDoS) attacks.

Also Read: Meris Botnet Hits Russian Search Engine Yandex Again with 21.8 Mn RPS

Google stated that Glupteba can steal users’ credentials and data, mining cryptocurrencies on infected hosts, and set up proxies to funnel other people’s internet traffic through infected machines and routers. The botnet currently involves approximately one million compromised Windows devices worldwide and is expected to grow at a rate of thousands of new devices per day.

Legal Action Against Glupteba

While the operators behind the Glupteba botnet are unknown, Google suspects that Russian cybercriminals are involved in the campaign. Google took legal action against the Glupteba for infiltrating more than a million computers and other devices worldwide, including the theft and unauthorized use of Google users’ login and account information. Reports suggest that threat actors could leverage the Glupteba botnet to launch ransomware or DDoS attacks.

“Our litigation was filed against the operators of the botnet, who we believe are based in Russia. We filed the action in the Southern District of New York for computer fraud and abuse, trademark infringement, and other claims. We also filed a temporary restraining order to bolster our technical disruption effort. If successful, this action will create real legal liability for the operators,” Google added.

“DevOps Engineers are Constantly Being Hunted by Cybercriminals”

DevOps Security

Remote work and distributed environments have disrupted long established security models and workflows. Security architects had to re-adapt, re-architect, and rebuild security for remote workers, with the rapid de-perimeterization we witnessed over the months. A multi-layered approach had to be deployed with a mix of security solutions, ranging from identity management, privilege access management, encryption, data-level authentication, data loss prevention, network security, security protocols – and of course, zero trust architecture. In a rush to accede to business demands for cloud adoption and digital transformation, established frameworks and models like security by design and DevSecOps or DevOps security were often neglected.

In an interview, Brian Pereira, Editor-in-Chief, CISO MAG, and Jeffrey Kok, Vice President of Solution Engineers, Asia Pacific and Japan at CyberArk, exchange notes on current challenges posed to organizations for DevOps security, adopting security by design, and in integrating security into the CI/CD pipeline. Kok reveals strategies employed by his organization to work around these challenges. The interview concludes with a discussion on privileged access management and how PAM secures remote work environments that have questionable security defenses.

Kok has more than 17 years of experience in the cybersecurity industry. At CyberArk, he is responsible for working with various internal teams to qualify leads, identify business issues and drivers in any particular sales opportunity, and manage the entire presales and solution process of the business cycle.

Prior to joining CyberArk, Kok was Technical Consultant Director, Asia Pacific and Japan for RSA, managing a team of senior pre-sales engineers and technicians. While in this role, he built a strong and high-performing cross-regional pre-sales practice.

During his career he served in companies and institutions, including RSA, Cisco Systems, Nera Telecommunications, and the National University of Singapore (NUS). He holds a Bachelor of Applied Science in Computer Engineering from the Nanyang Technological University and a CISSP certification.

Edited excerpts from the interview follow:

Implementing DevOps requires close collaboration between various teams. But with most teams and people working from different locations during the pandemic, has this posed a challenge to the development process?

During the initial onset of the pandemic, development teams working in different locations were affected as many organizations, especially those in the Asia Pacific, were not prepared to work in remote settings. Most organizations needed time to adapt to this new change as, prior to the pandemic, developers would gather in a physical room and discuss ideas using a large whiteboard with colourful post-its. Now, organizations would need to provide access for remote workers to ensure the same level of collaboration.

Within a couple of months, most organizations successfully adapted. This is evident from the development of new apps and updates during the pandemic. For instance, the Singapore government made significant progress throughout the pandemic on its contact-tracing application, Trace Together, having released numerous updates and added functions to improve the user experience, as well as to reflect the latest vaccination status.

There has been much talk about “security by design.” But not many organizations are following this practice. Your comments please. 

I believe that the challenges with adopting security by design are global. The concept requires additional time and effort, which all adds to the cost for companies.

This is a common issue, especially for start-ups that tend to skirt around security needs in exchange for speed. These companies tend to introduce security during the later stage of the development to gain the competitive edge of launching solutions or updates before their competitors.

On the other hand, larger and more mature organizations tend to adopt security by design at the outset, as they understand the importance of securing their applications. For instance, the public sector and banks tend to put a big focus on this approach.

As for organizations that have been operating with legacy applications and systems designed decades ago, it does require an enormous amount of effort (and sometimes it is impossible) to re-architect and rebuild with an added layer of security. Companies looking for a refresh often adopt and partner with a proper security platform that can help them implement modern security practices. In this way, they have something that equates to security by design.

What is the biggest challenge with DevOps security? Is this challenge seen only in APAC or elsewhere in the world too?

Recurring low-level phishing and impersonation attacks set up by cybercriminals target developers who have high levels of access to credentials. Developers are preyed-on as they build critical software and are frequently given administrative privileges, which provide a valuable entry point to the rest of the organization, if compromised. Cyberattackers know this, and they aim to misappropriate admin privileges that could jeopardize the whole application environment. While enabling organizations to become more efficient and faster, the growth of DevOps has significantly expanded the attack surface.

CyberArk’s CISO View research shows that high-level DevOps engineers are constantly being hunted by cybercriminals due to having access to sensitive company assets. This illustrates that the credentials that DevOps teams use must be managed and secured in a centralized and controlled way.

When attackers are able to access privileged credentials, unrestricted access to DevOps pipelines, sensitive databases, and cloud systems become targets for abuse. This can result in data breaches and intellectual property theft.

What would be the way to get round this challenge? And how?

Firstly, the development team should start with securing the DevOps pipeline. If the pipeline is not secured, this means that companies have not put the correct security building blocks in place. On the other hand, if companies have security-as-code alongside infrastructure code — as part of the entire pipeline — they have a strong foundation.

Secondly, do not leave hardcoded credentials everywhere. Always make it dynamic, so that it reduces the risk of someone in the DevOps team stumbling onto an SSH key somewhere, effectively allowing them the keys to the kingdom.

Finally, use existing industry best practices, which are talked about frequently in conferences and events around the world. 

There is also a challenge of integrating security into the CI/CD pipeline. Security teams are slow to secure every part of the code and cannot keep up with the pace of DevOps. And this raises security risks during the integration stage. How are organizations getting past this challenge?

For companies with a CI/CD pipeline, it makes it easier for them to embed security best practices into their pipeline. Think of the pipeline as a train.  If this train is being created, and this train goes through different stations, a company can break down problems into many parts and address the security aspect in each of those stages of the pipeline, or each of those train stations. Companies should follow best practices on securing codes and validate them against the automated validation of the codes. Security must be integrated into CI/CD pipeline before DevOps move on to their operations.

Can you give us some recommendations for DevOps security?

Automatic rotations for secrets, passwords, keys, and certificates hinder cybercriminals from accessing DevOps tools and access keys. Moreover, this automation reactively informs security teams if and when a breach happens. Taking a proactive method to protection, using automation and programmability, will encourage collaboration throughout teams, accelerating innovation amidst companies’ evolving needs.

Here are some tips for DevOps security:

  • Tightly working with Software Engineering and IT/DevOps will be beneficial for developers to protect their applications. Supporting the idea and understanding the importance of security should be the priority, and instilled early into Software Architects, Developers, and DevOps/IT Operations. Acknowledging that the extra process is not to decelerate the development work, rather it is to accelerate via simple integration points. Identifying security breaches before it becomes critical requires security teams to focus early in the development cycle.
  • Remove all hard-coded secrets in code, DevOps tools, configuration files and scripts. It’s also important to never use default passwords. For example, some tools establish a developer default user to create projects.
  • To bring most value, Privileged Access Management and secrets management for DevOps infrastructure should be integrated cohesively; one system to centralize all privileged accounts, secrets, and other credentials.
  • The development, security, and operations teams could utilize security-policy-as-code for efficient and unambiguous communication. Security tests and scans are integrated in the CI/CD pipeline to routinely and continuously identify potential risks and security gaps. Thus, organizations can improve their security posture, at the same time maintaining DevOps velocity and scalability.
  • Securing credentials used in DevOps tools and processes is not always straightforward, but one aspect that is a must is to automate this effort. Minimal human hands-on and manual work allows administrative overhead reduction and a reduction in errors.

How does PAM help in securing remote environments, with workers at home using personal devices?

With the rise in remote work, securing employee workstations is more important than ever. Employees are working from home offices with insecure “BYOD” devices on insecure home networks. Every single endpoint (laptop, smartphone, tablet, desktop, server, etc.) contains privilege by default. Built-in administrator accounts enable IT teams to fix issues locally, but they also introduce great risk. Attackers can exploit admin accounts, then jump from workstation to workstation, steal additional credentials, elevate privileges, and move laterally through the network until they reach what they’re looking for. Thus, companies need to adopt privileged access management (PAM) as privileged accounts, credentials and secrets exist across the remote workforce and need to be secured. Privileged access is the gateway to an organization’s most valuable assets and is at the core of nearly every major data breach.

Privileged access management solutions can also offer insider threat protection, helping to ensure activities occurring across the distributed network aren’t malicious and, if they are, enable security operations teams to take quick action. From internal privileged users abusing their level of access, or external cyber attackers targeting and stealing privileges from users to operate stealthily as “privileged insiders,” humans are almost always the weakest link in the cybersecurity chain. PAM helps organizations make sure that people have only the necessary levels of access to do their jobs and enables security teams to identify malicious activities linked to privilege abuse and take swift action to remediate risk.

A proactive PAM program could account for the comprehensive removal of local administrative rights on workstations to reduce risk. Implementing a comprehensive privileged access management program will allow organizations to effectively monitor where privileged access exists at every layer, understand which users (both human and non-human) have access to what, detect and alert on malicious or high-risk activity, and enhance overall cybersecurity.

——————————————————————-

About the Interviewer

Brian PereiraBrian Pereira is the Editor-in-Chief of CISO MAG. He has been writing on business technology concepts for the past 27 years and has achieved basic certifications in cloud computing (IBM) and cybersecurity (EC-Council).

More stories from Brian

Microsoft Disrupts Chinese Threat Actor Group Nickel

Nickel, Hackers, Twitch source code

Microsoft announced that it had disrupted the operations of a Chinese cyberespionage group targeting organizations in the U.S. and 28 other countries. Tracked as Nickel, the advanced persistent threat (APT) group has been linked to various cyberattacks across the globe since 2012, under different names including APT15, Bronze Palace, Ke3Chang, Mirage, Playful Dragon, and Vixen Panda.

Nickel’s criminal activities included compromising confidential information from government agencies, think tanks, and human rights organizations. Microsoft also dissolved the group’s access to its victims and prevented the websites from executing attacks.

“Obtaining control of the malicious websites and redirecting traffic from those sites to Microsoft’s secure servers will help us protect existing and future victims while learning more about Nickel’s activities. Our disruption will not prevent Nickel from continuing other hacking activities, but we do believe we have removed a key piece of the infrastructure the group has been relying on for this latest wave of attacks,” Microsoft said.

Nickel’s Cyberespionage

Microsoft researchers observed the Nickel group using advanced and a variety of techniques to deploy specially crafted hard-to-detect malware that facilitates intrusion, surveillance, and data theft activities. The group also leveraged compromised third-party virtual private network (VPN) suppliers or stolen credentials from spear phishing campaigns to exploit the targets. Nickel has targeted organizations in both the private and public sectors, including diplomatic organizations and ministries of foreign affairs in North America, Central America, South America, the Caribbean, Europe, and Africa.

Also Read: Microsoft Identifies Six Iranian State Actor Groups Deploying Ransomware

“Nation-state attacks continue to proliferate in number and sophistication. Our goal in this case, as in our previous disruptions that targeted Barium, operating from China, Strontium, operating from Russia, Phosphorus, operating from Iran, and Thallium, operating from North Korea, is to take down malicious infrastructure, better understand actor tactics, protect our customers, and inform the broader debate on acceptable norms in cyberspace. We will remain relentless in our efforts to improve the security of the ecosystem, and we will continue to share an activity we see, regardless of where it originates,” Microsoft added.

Cyberespionage on the Rise

A security research team from Palo Alto Networks’ Unit 42 uncovered an ongoing cyberespionage campaign by a Chinese group that has already targeted nine organizations belonging to critical global sectors, including education, defense, health care, energy, and technology. The campaign is reportedly focused on stealing critical information from U.S. defense contractors. It is believed the techniques used in the campaign are similar to those of the Chinese threat group Emissary Panda, also known as TG-3390 and APT27.

Nobelium’s Phishing Campaign Targets French Entities

Nobelium

In a report, the ANSSI (French National Cybersecurity Agency) revealed that it has observed several phishing campaigns directed against French entities since February 2021. These compromised email accounts of French organizations were used to spread the malware and send malicious emails to foreign institutions and they have been ascribed to the Nobelium set.

Per the report, the French entities have also been recipients of malicious emails sent from compromised foreign institutions. The agency has attributed these attacks to the Nobelium intrusion set. The Russian-backed Nobelium hacking group is also responsible for last year’s SolarWinds attack.

According to Microsoft, Nobelium was active in October 2021. The intrusion set was possibly used during attack campaigns that target Active Directory Federation Services servers to compromise government bodies, think tanks, and private firms in the U.S. and Europe.

“The Microsoft Threat Intelligence Center (MSTIC) observed NOBELIUM attempting to compromise systems through an HTML file attached to a spear-phishing email. When opened by the targeted user, a JavaScript within the HTML wrote an ISO file to disc and encouraged the target to open it, resulting in the ISO file being mounted much like an external or network drive. From here, a shortcut file (LNK) would execute an accompanying DLL, which would result in Cobalt Strike Beacon executing on the system,” Microsoft added.

Recommendations

1. Restrict the execution of file attachments

Given the chain of compromise, which relies on the opening of a malicious file attachment as part of a phishing campaign, it is recommended that suspicious files are not executed.

2. Tightening Active Directory security

The intrusion set tends to focus on Active Directory (AD) servers in particular. Tighter security measures should be applied. ANSSI has produced a guide containing recommendations for security hardening, which can be found on the CERT-FR website.

The Nobelium Attacks 

  • Pentagon (August 2015)
  • Democratic National Committee (2016)
  • US think tanks and NGOs (2016)
  • Norwegian government (2017)
  • Dutch ministries (2017)
  • Operation Ghost
  • COVID-19 vaccine data (2020)
  • SUNBURST malware supply chain attack (2020)
  • Republican National Committee (2021)

Mandiant, which has been tracking the Russian threat actor closely since the SolarWinds supply chain attack has shared a few observations in its report.

  • Compromise of multiple technology solutions, services, and reseller companies since 2020.
  • Use of credentials likely obtained from an info-stealer malware campaign by a third-party actor to gain initial access to organizations.
  • Use of accounts with Application Impersonation privileges to harvest sensitive mail data since Q1 2021.
  • Use of both residential IP proxy services and newly provisioned geo located infrastructure to communicate with compromised victims.
  • Use of novel TTPs to bypass security restrictions within environments including but not limited to the extraction of virtual machines to determine internal routing configurations.
  • Use of a new bespoke downloader called CEELOADER.
  • Abuse of multi-factor authentication leveraging “push” notifications on smartphones.

“In most instances, post compromise activity included theft of data relevant to Russian interests. In some instances, the data theft appears to be obtained primarily to create new routes to access other victim environments. The threat actors continue to innovate and identify new techniques and tradecraft to maintain persistent access to victim environments, hinder detection, and confuse attribution efforts,” Mandiant said.

This reflects what has been reported in the French organizations’ case where the compromised emails are further used to launch attacks on foreign institutions – creating routes to access other victim environments.

How Cybercriminals Use Phishing Kits

Phishing Kits, Cost of Phishing Attacks

Cybercriminals are creating new phishing strategies and malware variants to make their attacks more intense and successful. They even rely on phishing kits, which are readily available on darknet forums, to exploit their targeted systems.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

What is a Phishing Kit?

A phishing kit is a collection of various software tools, services, and other components such as archive files, HTML pages, images, and codes that enable threat actors to launch phishing or social engineering attacks. Phishing kits provide readymade phishing pages, email IDs, and malware codes to target victims. Even with little or no knowledge of phishing attacks, a person can create various kinds of phishing lures using a phishing kit.

A typical phishing kit includes:

  • Website development software
  • Email templates
  • Sample malicious scripts or codes
  • Automation software for malware distribution
  • Compromised email ids or phone numbers
  • Evasion mechanisms like HTML character encoding

Phishing kits facilitate adversaries to instantly create undetectable phishing pages, impersonate brands, and harvest users login credentials through it.

Also Read: How To Find a Phishing Email

Types of Phishing Kits  

The complexity and capability of a phishing kit depends on its price on the dark web. While a simple phishing kit contains only a few components, advanced kits include built-in botnets and other evasion techniques.

1. Basic Phishing Kit

A Basic phishing kit is a simple and small archive file containing a few HTML files and JavaScript codes.

2. Dynamic Phishing Kit

Dynamic phishing kits have specially created phishing lures such as fake banking login pages and compromised email addresses.

3. Puppeteer Phishing Kit

Puppeteer phishing kits are specifically designed to phish for online banking credentials. It allows phishers to prompt the victims for sensitive information from their online banking provider. Puppeteer phishing kits are often used to bypass OTPs and security phone calls.

4. Commercial Phishing Kit

With the increase in the usage of phishing kits, several adversaries are offering customized phishing kits online (like 16Shop and FreakzBrothers), where users can log in, purchase, configure, and download the phishing kits they like.

Also Read: Five Phishing Baits You Need to Know

Phishing Kits For Sale 

Threat actors sell phishing kits as phishing-as-a-service across various dark web forums, inviting other cybercriminal affiliates in their phishing campaigns. Research revealed that phishing kits have gained the “Bestseller” tag in the underground market, with the number of ads and their sellers having doubled in 2019 compared to 2018. The growing demand for phishing kits is also reflected in its price that skyrocketed last year by 149% and exceeded $300 per item.

How to Prevent Phishing Kit Scams 

Phishing lures (like emails and messages) are not perfect. A phishing email or message can be detected via paying attention to small details like:

  • Poor grammar or phrasing in messages and emails
  • False sense of urgency that trick users to take action
  • Hidden URLs/short-links like Bit.ly, which conceals links to phishing websites
  • Spelling errors in the email address

Conclusion 

While phishers across the globe invest more in phishing kits to expand their phishing activities, users need to be vigilant to detect and prevent evolving phishing lures proactively.

About the Author

Rudra Srinivas

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

More from the Rudra.

 

Hackers Steal Cryptocurrency Worth $150 Mn From BitMart Exchange

Sardonic, BitMart

The evolution of cryptocurrencies has attracted cybercriminal groups globally.  Cryptocurrency exchanges and hot wallets continue to become a primary target for threat actors.  The recent victim to join the bandwagon of crypto hacks is the cryptocurrency trading platform BitMart.

In an official statement, the company stated that it had sustained a large-scale security breach that affected its hot wallets on the Ethereum (ETH) blockchain and the Binance smart chain (BSC). The attackers reportedly stole cryptocurrencies worth over $150 million. Hot wallets are connected to the internet and allow crypto owners to store, send, and receive tokens. Crypto hackers often exploit hot wallets to pilfer crypto coins.

Also Read: Scammers Force Victims to Use Crypto ATMs

“The affected ETH hot wallet and BSC hot wallet carry a small percentage of assets on BitMart, and all of our other wallets are secure and unharmed. We are now conducting a thorough security review, and we will post updates as we progress. At this moment, we are temporarily suspending withdrawals until further notice. We beg for your kind understanding and patience in this situation,” the statement said.

Estimated Loss of 200 Million

Blockchain security and data analytics firm PeckShield claimed that the estimated loss would be around $200 million.

Affected Users Will be Compensated

BitMart’s Chief Executive Sheldon Xia stated they have completed the initial security checks and identified affected assets. The breach was a result of a stolen private key that had two of its hot wallets compromised. The company has enhanced its platform’s security to mitigate further losses. The company stated that it would compensate the affected users.

“BitMart will use our own funding to cover the incident and compensate affected users. We are also talking to multiple project teams to confirm the most reasonable solutions, such as token swaps. No user assets will be harmed. We are now doing our best to retrieve security set-ups and our operation. We need time to make proper arrangements, and your kind understanding during this period will be highly appreciated. In terms of asset deposits and withdrawals, we are confident that deposit and withdrawal functions will gradually begin on December 7, 2021. The detailed timelines will be announced very soon,” Xia said in a series of tweets.

Cuba Ransomware Infringed 49 Critical Infrastructure Entities

DeadBolt, Shutterfly ransomware, Cuba ransomware

In a flash alert, the Federal Bureau of Investigation (FBI), in coordination with DHS/CISA, identified that since early November 2021, Cuba ransomware had infiltrated around 49 entities; from the critical infrastructure sector such as financial, government, healthcare, manufacturing, and information technology in the country.

Per the flash alert, Cuba ransomware actors use “.cuba” extension for the encryption of the target files and infiltrate the network. The ransomware gang has supposedly demanded at least $74 million and received at least $43.9 million in ransom payments.

Cuba Ransomware Deployed by Hancitor

The Group-IB Threat Intelligence and Attribution team discovered that the threat actors actively use Hancitor to deploy Cuba ransomware. According to the team, Cuba ransomware has been active since at least January 2020. Its operators have a DLS site, where they post exfiltrated data from their victims who refused to pay the ransom. It added that the Hancitor downloader has been active since at least 2016 for dropping Pony and Vawtrak. As a loader, it has been used to download other malware families, such as Ficker stealer and NetSupport RAT, to compromised hosts. The Hancitor malware actors use phishing emails, Microsoft Exchange vulnerabilities, compromised credentials, or legitimate Remote Desktop Protocol (RDP) tools to gain initial access to a victim’s network. Subsequently, Cuba ransomware actors use legitimate Windows services — such as PowerShell, PsExec, and other unspecified services — and then leverage Windows Admin privileges to execute their ransomware and other processes remotely.

The Technical View

The FBI explained the technical working of the malicious ransomware. It stated, “Cuba ransomware, upon compromise, installs and executes a CobaltStrike beacon as a service on the victim’s network via PowerShell. Once installed, the ransomware downloads two executable files, which include “pones.exe” for password acquisition and “krots.exe,” also known as KPOT, enabling the Cuba ransomware actors to write to the compromised system’s temporary (TMP) file. Once the TMP file is uploaded, the “krots.exe” file is deleted and the TMP file is executed in the compromised network. The TMP file includes Application Programming Interface (API) calls related to memory injection that, once executed, deletes itself from the system. Upon deletion of the TMP file, the compromised network begins communicating with a reported malware repository located at Montenegro-based Uniform Resource Locator (URL) teoresp.com.”

Mitigations

Following mitigations have been suggested to ease the risk of compromise by Cuba ransomware:

  • Require all accounts with password logins (e.g., service account, admin accounts, and domain admin accounts) to have strong, unique passwords. Passwords should not be reused across multiple accounts or stored on the system where an adversary may have access.
  • Require multi-factor authentication for all services to the extent possible, particularly for webmail, virtual private networks, and accounts that access critical systems.
  • Keep all operating systems and software up to date. Timely patching is one of the most efficient and cost-effective steps an organization can take to minimize its exposure to cybersecurity threats.
  • Remove unnecessary access to administrative shares, restrict privileges to only the necessary service or user accounts and perform continuous monitoring for anomalous activity.
  • Use a host-based firewall to only allow connections to administrative shares via server message block (SMB) from a limited set of administrator machines.
  • Segment networks to prevent the spread of ransomware. Network segmentation can help prevent the spread of ransomware by controlling traffic flows between — and access to — various subnetworks and by restricting adversary lateral movement.
  • Identify, detect, and investigate abnormal activity and potential traversal of the indicated ransomware with a networking monitoring tool. To aid in detecting the ransomware, implement a tool that logs and reports all network traffic, including lateral movement activity on a network. Endpoint detection and response (EDR) tools are particularly useful for detecting lateral connections as they have insight into common and uncommon network connections for each host.
  • Implement time-based access for accounts set at the admin level and higher. This is a process where a network-wide policy is set in place to automatically disable admin accounts at the AD level when the account is not in direct need. When the account is needed, individual users submit their requests through an automated process that enables access to a system, but only for a set timeframe to support task completion.
  • Disable command-line and scripting activities and permissions. Privilege escalation and lateral movement often depend on software utilities that run from the command line. If threat actors are not able to run these tools, they will have difficulty escalating privileges and/or moving laterally.
  • Maintain offline backups of data, and regularly maintain backup and restoration. This practice will ensure the organization will not be severely interrupted, have irretrievable data.
  • Ensure all backup data is encrypted, immutable (i.e., cannot be altered or deleted), and covers the entire organization’s data infrastructure.

As the festive season witnesses a significant spike in premediated cybercrimes, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the FBI remind all organizations – big or small – and critical infrastructure partners that malicious actor groups are proactively launching premeditated cyberattacks.

The authorities had issued advisories for organizations, especially critical infrastructure and services, to assess the current security posture and implement best practices and mitigations to attenuate the threat posed by cyberattacks.

Despite the alerts, we continue to see a rise in the number of ransomware attack victims. Many organizations give in to these demands to safeguard their reputation, critical information, data, and financial status.

Satya Gupta, Cofounder and CTO, VirsecSatya Gupta, Cofounder and CTO, Virsec, opined, “Critical infrastructure will remain a highly lucrative target. There is a subtle but massive change in attacker tactics that is taking place and we are at risk of being totally blindsided. Attackers are increasingly burrowing their attacks deep in the software runtime by exploiting vulnerabilities. Being deeper in the software’s runtime helps attackers evade early discovery as evidenced by this group’s method.”

“While many vulnerability disclosures are accompanied by a software patch, the most sophisticated attackers often leverage undisclosed vulnerabilities. In a recent interview, CISA Director Jen Easterly remarked that more than ‘90 percent of vulnerabilities exploited by ransomware have patches associated with them.’  What is left unsaid is that 10% attacks are vulnerabilities for which patches are not available. Irrespective, patching is not a successful security strategy. This is because even if a patch were available, many entities will drag their heels in deploying the patch.”

Government authorities have also prioritized ransomware attacks and are pressurizing ransomware groups to cease operations to address the growing menace.

See also: Biden Administration and Tech Giants Come Together to Raise Bar on Cybersecurity

Organizations need to be on a constant alert and review their security posture at a micro-level as threat actors are actively scouting for the smallest vulnerability and launching their vicious attack.

Gupta expressed, “The only way organizations can truly protect themselves is by deploying runtime security controls that take away the attacker’s ability to successfully exploit vulnerabilities. These controls will stop attackers, in milliseconds, from successfully exploiting vulnerabilities. This type of protection is not only possible, but mandatory if we want to prevent further successful ransomware attacks.”