Home Blog Page 33

Pakistani APT Group ‘SideCopy’ Targets Officials in India and Afghanistan

Lone Wolf, SideCopy APT

Several threat actor groups have targeted public and private organizations in India lately, affecting critical infrastructures in the country. Recently, security experts from Malwarebytes revealed that a Pakistani APT group SideCopy has been targeting ministries in India and Afghanistan to pilfer Google, Twitter, and Facebook credentials and obtain access to confidential government networks, banking details, and password-protected documents.

SideCopy APT in Brief

Active since 2019, the SideCopy APT group has been targeting South Asian countries, particularly India and Afghanistan. Researchers stated the group is leveraging new initial infection vectors such as Microsoft Publisher documents and Trojanized applications to trick the users via spear-phishing campaigns. It was also observed that attackers used a new data stealer tracked as AuTo stealer.

AuTo stealer is written in C++ language and is used by attackers to deploy and load an executable (credbiz.exe) that side loads the stealer. The researchers found two variants of AuTo stealer – the HTTP version and the TCP version.

Also Read: CDSL Data Breach Exposes Sensitive Details of 44 Mn Indian Investors

Specific Targets

The lures used by SideCopy APT are usually archived files embedded with files like – Lnk, Microsoft Publisher, or Trojanized Applications, which are specially crafted and designed to target government or military officials.

So far, the SideCopy APT targeted:

  • Administration Office of the President (AOP) of Afghanistan personnel: The attackers have performed spear phishing attacks on members of AOP and were able to gain access to ten of them and steal their credentials from different government services such as mis.aop.gov.af, internal service, bank services (Maiwand Bank) and personal accounts such as Google, Twitter, and Facebook.
  • Ministry of Foreign affairs, Afghanistan: The actors infected one of the members of the Ministry of External affairs, but it seems they were not able to collect any data from this victim.
  • Ministry of Finance, Afghanistan: The actor infected two members of MOF, but mostly they were able to collect personal accounts such as Google and Facebook and Bank accounts (worldbankgroup.csod.com). They also exfiltrated documents that are password protected.
  • Afghanistan’s National Procurement Authority (NPA): The actor infected one person in NPA and was able to steal personal credentials, including Twitter, Facebook, Instagram, Pinterest, Google, and the mis.aop.gov.af account.
  • A shared computer, India: The attackers obtained access to a shared machine and collected a lot of credentials from government and education services. It seems this machine has been infected using one of the generic lures.

“The SideCopy APT was able to steal several Office documents and databases associated with the Government of Afghanistan. As an example, the threat actor exfiltrated Diplomatic Visa and Diplomatic ID cards from the Ministry of Foreign Affairs of Afghanistan database and the Asset Registration and Verification Authority database belonging to the General Director of Administrative Affairs Government of Afghanistan. They also were able to exfiltrate the ID cards of several Afghani government officials,” the researchers said.

Operation SideCopy

In September 2020, cybersecurity solutions provider Quick Heal revealed evidence related to SideCopy’s cyberespionage campaign. Tracked as “Operation SideCopy,” the campaign targeted Indian Army personnel in 2019 to pilfer sensitive information. Researchers observed three infection chain processes in which attackers exploited equation editor vulnerability (CVE-2017-11882) as the initial infection vector. Read More Here

Cyber Insurance for Health Care Organizations

Health care data breaches

Cyberattacks are dangerous for any organization. Health care organizations can be particularly vulnerable, however, because breaches often reveal sensitive patient information and may result in fines, loss of reputation, and lost revenue, and in some cases can affect patient care.

By Vikas Khosla, Chief Digital Health Officer of Intraprise Health

According to the Government Accountability Office (GAO) the number and severity of cybersecurity attacks continue to increase, as has the cost to recover from them. According to the HIPAA August  2021 Healthcare Data Breach Report, while the number of breaches in August 2021, was less than those reported in July 2021, 5,120,289 health care records were breached, “which is well above the 12-month average of 3.94 million breached record in a month.”

Ransomware was responsible for several of the August breaches, the report says, including attacks on the University Medical Center Southern Nevada and the St. Joseph’s/Candler Health System; those breaches resulted in a combined 2.7 million patients being affected. Class action lawsuits have already been filed on behalf of those patients.

The breaches are also costly. IBM Security’s, Cost of a Data Breach Report 2021 reports that between 2020 and 2021, data breach costs increased from $3.86 million to 4.24 million, representing the largest single-year cost increase in the last seven years. The report notes that remote working and digital transformation due to the COVID-19 pandemic contributed to the increase.

To protect themselves against such attacks, businesses are increasingly securing cyber insurance. The number of businesses that purchased cyber insurance increased 60 percent from 2016 to 2020.

Cyber insurance protects your organization against losses related to cyber-risks, such as data theft/loss, business interruption caused by a computer malfunction or virus, and fines or lost income because of system downtime, network intrusion, and/or information security breaches.

Cyber insurance can include first-party coverage for the health care organization that covers such things as data breaches where patient information is stolen, protection if your computer systems are hacked, and can also cover ransom payments and professional help if your network, data, or website are being threatened.

Third-party coverage can include coverage of legal costs if your organization is found liable for a data breach or cyber-attack. It provides defense and settlement costs if you did not secure your systems and your patients or customers suffered damages and can protect against digital media claims that can include copyright infringement and violation of privacy. But this type of coverage comes at a price that can be quite steep if your security program isn’t comprehensive and holistic.

According to Intraprise Health’s Chief Operating Officer, Neal Pason, “Based upon what our clients have told us, the total cost to address a single breach can be in the millions of dollars. Many of our clients have either obtained or plan to get a cyber insurance policy.”

Industry specialists say that while cyber insurance is relatively new, they notice a trend: As the number of cyberattacks against health care organizations increases, so too, do cyber insurance premiums. In some cases, insurance providers will refuse to cover some organizations, considering them too much of a risk. Commercial property-casualty insurance prices in the U.S. rose an average of 14% in the third quarter, driven by a 96% average price hike for cyber coverage, according to Commercial Insurance broker Marsh’s latest Global Insurance Market Index. The 96% jump for cyber insurance coverage is 40 percentage points higher than in Q2, the highest average increase since 2015. Prices rose even higher in some months, with a 112% increase in August.

So how can a health care organization position itself to enjoy comprehensive cyber insurance coverage at a better premium? One way is to ensure it has a rigorous, comprehensive security program that is based on industry-accepted standards such as a cybersecurity framework. The coverage is even stronger if it covers its third-party vendors or those individuals or organizations that provide contract services to the health care organization. A framework serves as a system of standards, guidelines, and best practices to manage risks that can arise in health care. A cybersecurity framework prioritizes a flexible, repeatable, and cost-effective approach to promote the protection and resilience of your business.

A cybersecurity framework both protects your organization and helps it grow. Using a framework to align controls like local, offline, and cloud backups will improve resilience from any attack or reliance on hardware. The NIST Cybersecurity Framework and HITRUST CSF are the two leading frameworks utilized in health care.

“Insurers are in the business of mitigating risk,” Intraprise Health COO Pason says. “So they take a number of factors into consideration when evaluating a health care organization’s security. If they don’t have confidence the organization’s security is sound and uses best practices, they could decide not to insure the organization or to charge higher rates than they would charge a company with a comprehensive security program.


About the Author

Vikas Khosla is the Chief Digital Health Officer of Intraprise Health. Vikas works with the leadership team and partners to develop strategies and market differentiation for the advancement of security risk management programs across the health care industry.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Cloud is Booming and It Is Going to Get Better in 2025 and Beyond

Cloud Security

COVID-19 era has brought a major revolution in the IT domain where cloud services are expected to be the backbone of almost all organizations by the year 2025. COVID-19 pandemic has accelerated the adoption of cloud services and highlighted the importance of cloud security as most offices had to operate their businesses from various remote locations. Cloud storage ensures the stored data can be edited or shared from anywhere with an internet connection. It provides better accessibility and is cost-effective as it eliminates the need to purchase physical storage. The cloud service providers offer improved security to the data on the cloud by setting up layered security parameters allowing only authorized users to access information on the cloud.

By Michael Messuri, Cyber Forensics Engineer, Praetorian Standard Inc

However, everything comes with its own pros and cons, the increased use of the cloud has irked the attention of malicious attackers who are coming up with ways to take advantage of the vulnerable situation, such as the hassle of moving businesses online without establishing proper security parameters. Additionally, the number of data breaches and phishing attacks associated with cloud services is on the increase, resulting in attackers infecting the cloud with malware to cause disruption and earn ransom. Therefore, it is necessary to draw preventive measures and guidelines to ensure cloud security for those services.

According to the report by MarketsandMarkets, “Cloud Security Market worth $68.5 billion by 2025” statistics indicate that the cloud security market is not only expected to grow significantly with an estimate of around 15% compound annual growth rate (CAGR), but double its expenditure rate by 2025, and increase its projected net worth to around $800 billion.

The stats itself shows how organizations from every industry should realize the benefits of cloud computing, such as the increased flexibility of storing data on the cloud, carrying out seamless transactions, and availing services that eradicate the need for a separate infrastructure to utilize technology, such as Blockchain-as-a-Service (BaaS). Therefore, this blog will try to bring an insight into how advanced technologies such as AI, quantum computing, and more will enhance and accelerate the cloud domain in the coming years.

Artificial Intelligence: Breaking Barriers in Cloud Security

Cloud computing is boosting businesses forward, but it is also constantly evolving.  In its initial form, cloud computing was represented by Platforms as a service (PaaS), with this quickly being followed by both the cloud’s ability to collect, store, and analyze data coming next, and Infrastructure as a service (IaaS).

The next big step for cloud computing is its integration with artificial intelligence (AI).  As this fusion between AI and the cloud begins to solidify, Cloud providers will begin to ensure that developers have adequate resources and services by assisting them with different AI tools that cover image recognition, analyzing big data for insights, etc.  All this will in turn increase the overall efficiency and operations of cloud computing while simultaneously bestowing upon its users a wide range of appealing advantages, such as:

  • Making AI more accessible by democratizing it.
  • Fostering AI-powered transformation for businesses by cutting adoption costs and encouraging co-creation and innovation.
  • Adoption of continuously improving algorithms and techniques to strengthen cloud security for future years to come

Artificial Intelligence can be a beneficial aspect for cloud security by ensuring robust data controls by combining AI technology with network security. It provides endpoint protection and avails authorized authentications for administrators to secure systems to prevent data theft and potential cyberattacks. AI can also help monitor suspicious activities, due to which organizations can react to the threat before it causes any disruption. AI can discover vulnerabilities and loopholes by enabling real-time monitoring to identify potential problems which can later be patched up. Automation techniques by AI can automatically control the situation and deploy preventive measures when suspicious activities occur.

Migrating to Cloud – 2020 and Beyond

2020 is a year where we are witnessing a major overhaul in the way businesses and industries work. If the past few months have taught us anything, it is that the pandemic is unpredictable. Businesses who are keeping up are accelerating their digital transformation and this means faster migration to the cloud. The following is a list of the top cloud technology and migration trends for 2020 and beyond.

1. Endpoint Security and Management

Endpoint security protects the network and access points connecting internal data to devices like laptops, mobile phones, and smart devices. In cybersecurity, it is recognized as the frontline solution for securing a variety of cloud networks. As the use of bring-your-own-device (BYOD) policies becomes more popular, the market is likely to grow. Endpoint solutions require cloud computing, artificial intelligence (AI), IoT, linked devices, and modern technologies. For almost a year and a half now, organizations worldwide operate remotely; endpoint security will ensure that the data, devices, and operations are carried out securely and seamlessly. The endpoint security market will potentially rise from $13.99 billion in 2021 to $24.58 billion in 2028.

2. The Emerging Trend of Zero Trust

Zero Trust refers to trusting nothing inside or outside the organization’s infrastructure and verifying and authenticating everything to achieve maximum security in the cloud infrastructure and network parameters. Organizations are looking to adopt the zero-trust paradigm in the light of increased cyberattacks post the outbreak of Coronavirus and the new normal of working remotely.

To implement Zero Trust in an enterprise network, the organization must monitor and control the network. It develops and enforces access restrictions to protect critical applications, such as those in on-premises data centers, against unauthorized access and lateral movement.

Hosting an application on cloud services can prove cost-effective compared to hosting it on a data center. According to IDG, over 73% of businesses today utilize cloud-based apps or infrastructure because these cloud environments, which cloud service providers and SaaS suppliers run, are not connected to an organization’s network; the usual network restrictions do not apply. The current statistics assume that 80 percent of the newly established digital business applications opened to ecosystem partners will be accessed through ZTNA to avoid disruptions and ensure security. Therefore, the majority of organizations are more likely to shift towards adopting Zero Trust Network in the coming years as opposed to the traditional Virtual Private Network (VPN).

3. Increased Use of Multi-cloud

Multi-cloud is an infrastructure where two or more cloud computing platforms and storage services operate under one ecosystem primarily to remove the need to rely on a single cloud service provider.  A multi-cloud infrastructure can contain public, private, or hybrid cloud services according to the enterprise’s requirements. The strategic distribution of the cloud can help in managing data and operations while achieving scalability and resilience. For instance, a company can employ multiple clouds for services such as infrastructure, platform, blockchain to divide the workload over different cloud providers or to operate efficiently with geographical barriers, among various other reasons. Organizations can establish a multi-cloud architecture to distribute computational resources, thereby limiting downtime and data damage. It also helps mitigate cyberattacks or data breaches since the enterprise’s data is not allocated at one point but is spread across various cloud service providers.

Hybrid clouds give greater control over public cloud services and provide ease of data management. The industry is estimated to be valued at USD 173.33 billion by 2025 and grow at a CAGR of 22.25% every year from 2021.

Hybrid cloud computing models will optimize efficiency, cut down storage costs, and make organizations more Agile by offering greater mobility and flexibility when it comes to migrating data between infrastructures.  As businesses continue to upgrade their offline workspaces and remote network architectures, this segment is expected to take off and evolve with the technological landscape.

4. The Rise of Confidential Computing

Confidential computing is a cloud computing solution that encrypts sensitive data and processes it in a secure CPU enclave. Only approved programming code has access to the enclave’s contents, including the processed data and the techniques used to handle it. Everything else, including the cloud provider, is invisible and unknowable. Confidential computing safeguards data during processing and, when combined with storage and network encryption, provides end-to-end data security in the cloud with exclusive ownership of encryption keys. Organizations can use confidential computing to execute sensitive workloads in the cloud, avoid malicious access, and construct cross-cloud data applications from different partners. Post pandemic organizations have leaned towards confidential computing as it uploads encrypted data to the cloud. The results are encrypted, ensuring data privacy which is a tremendous advantage during the rise of cyberattacks.

Where Quantum Computing Meets Cloud and The Future

Quantum Computing on the Cloud is disrupting the technological landscape and paving the way for rapid innovation in the 21st century. Researchers are beginning to demonstrate the power of this technology by encoding problems, visualizing business data models in real-time, breaking encryption keys, and computing multiple variables from different sources at once. Cloud developers in Microsoft Quantum and Amazon Bracket are working on getting new users up to speed with use cases and their different applications.

Quantum mechanics is a platform that is used to provide faster processing of large datasets and provide efficient results over ordinary computers.

The agility of quantum computing allows quantum computers to create multi-dimensional spaces to represent substantial problems. The users can work with specific algorithms to translate complex issues into understandable information, deriving solutions in the designed multi-dimensional space.

Major Cloud providers are focusing their efforts in the education sector with classrooms leveraging quantum cloud solutions to process qbits.

The biggest drawback with using this technology is the user base. IT teams and users need specialized skills in order to access its benefits and Quantum Cloud has a steep learning curve for those who are not well-versed with the technology currently. Cloud vendors will be working providing Quantum Cloud as a Service and rolling out the latest software deployments with emerging technology trends and requirements in mind.

The global cloud computing market is estimated to be valued at $945 million by 2025. There will be a surge in quantum computing jobs and more vacancies popping up as these solutions will be used to solve increasingly complex computing issues. AI in quantum computing can leverage large datasets and learn from huge volumes of data, further adding to its potential. In the future, we can expect Quantum Cloud to simulate real-world problems, eliminate cognitive biases, and work on a subatomic level, with Quantum tunneling drastically cutting down power consumption for devices by up to 100-1000x without sacrificing performance.

Over 5 companies have already made Cloud computing chips, namely – Google, IBM, Intel, Rigetti, and D-Wave. IBM experience expanded from 5 to 20 bits of processing power after launching Q bit. The Quantum Artificial Intelligence Lab, which is run by NASA released Bristlecone, a 72-bit qbit processor which features a robust Cloud environment and ODI native integration. It empowered organizations to transform their traditional enterprise-grade infrastructures into state-of-the-art Cloud deployments and AI analytics with these solutions are transforming companies at the supply chain level.

Future Quantum Computers would be able to crack AES encryptions in seconds and the best supercomputers today would take millions of years to perform the same tasks. The scope is high and with the integration of the Cloud, quantum computing technology will be causing massive disruptions in the healthcare, finance, and various industries. Being able to double or QUADRUPLE quantum volume is no longer a mere possibility but becoming a reality for many global tech leaders across the world. Disease control, cryptography, weather forecasting, and financial modeling – these are just a few of the many applications we are witnessing in recent times.

Cloud: The Answer to Lowering Carbon Footprint by up to 80% in India

Carbon footprint can be defined as the emission of greenhouse gas (GHG) which includes carbon dioxide as well. Global warming has been one of the serious concerns across the world, and one of the major reasons for global warming is an exponential increase in the carbon footprint. Individuals, organizations, and environmentalists across the globe are figuring out methods to reduce the carbon footprint. It is estimated that around 1.6 billion tons of greenhouse gas are emitted by manufacturing processes and running digital technologies. Researches have determined that shifting to a complete cloud-based ecosystem can reduce the carbon footprint proving the cloud to be a sustainable and effective alternative to decrease environmental issues. As per a recent statement by Amazon Web Services (AWS), if Indian companies and public sector organizations migrate to on-premises data centers to the cloud-based ecosystem, it could reduce the carbon footprint by 80%.

The report proves that the cloud is a technical advancement and an aid that benefits all organizations and protects the environment. The estimation derives that if only 1,200 of the largest publicly traded Indian businesses were to shift one megawatt (MW) of their computation workload to the cloud, it would save one year’s worth of emissions from 160,000 Indian households. Migrating to the cloud ensures decarbonizing and promotes renewable energy resources, progressing towards a better world.

Post-pandemic Growth: The Spending on Public Cloud Services is Expected to Hit $124 Billion by 2025 

With companies latching to cloud infrastructure and utilizing public cloud services, the market is expected to reach $124 billion in the next four years, i.e., 2025. The global pandemic has played a massive role in shifting on-premises services and data storage to cloud services and boosting the cloud infrastructure-as-a-service ecosystem. To continue achieving secure and efficient work operations, data transmissions, storing vast amounts of information, and economic transactions, organizations, started relying on cloud services amid remote working culture. The post-pandemic work culture is still incorporating cloud services, and many organizations are even looking for more ways to utilize the benefits of the cloud. Industries realizing the scope of the cloud in data transactions and even in business development without downtime is one of the significant reasons cloud infrastructure-as-a-service is predicted to grow by 32.7% in 2021. Since the cloud provides high security and assures complete backup, among many other advantages, industries such as banking and healthcare are investing majorly into setting up a cloud ecosystem. Enterprises in the Asia Pacific, excluding Japan (APEJ), recognize the increasing growth of the cloud market and the exponential integration of cloud in businesses.

Conclusion

Cloud computing is the future and it’s undoubtedly becoming a popular technology choice for those trying to deploy services in a scalable, Agile, and efficient way. As long as an individual has access to the World Wide Web, they can transfer data and connect with others on the cloud. Security aspects of platforms are currently undergoing development which means vendors are getting busy addressing the pitfalls and challenges which emerge with the release of new services. The ever-changing needs of businesses, increased demands of consumers, huge volumes of data, and urgency to automate core business processes are some of the primary factors driving the evolution and growth of this technology.  Most cloud platforms offer a free to try subscription which users can upgrade later and what sets the cloud apart is its customizable features, flexible storage, and ability to adapt to different enterprise requirements. Top hyper scalers in the industry like Amazon, Tencent, Google, SalesForce, and RackSpace are already leveraging its benefits and it’s not surprising to see others follow suit.  Cloud is the future and with the advent of other technologies like AI, ML, Robotic Process Automation, and Internet of Things (IoT), it’s about to get a whole lot better as we speak.

References:

  1. https://www.livemint.com/technology/tech-news/moving-to-cloud-can-reduce-carbon-emissions-of-indian-companies-by-80-11628056238017.html
  2. https://www.cbinsights.com/research/report/quantum-computing/
  3. https://community.connection.com/4-ways-ai-is-improving-cloud-computing/
  4. https://fortanix.com/products/confidential-computing-manager/what-is-confidential-computing/
  5. https://www.cloudflare.com/en-in/learning/cloud/what-is-multicloud/
  6. https://www.checkpoint.com/cyber-hub/network-security/what-is-zero-trust-network-access-ztna/
  7. https://www.gartner.com/teamsiteanalytics/servePDF?g=/imagesrv/media-products/pdf/Qi-An-Xin/Qi-An-Xin-1-1OKONUN2.pdf

About the Author

Michael MessuriMichael Messuri has over 25 years of reverse engineering skills while his development skills include assembly language, C language, Python, firmware device drivers, and limited applications. He uses the experience gained in previous obstacles and collaborates his skills to overcome problems he faces along the way. He expresses an interest in hunting, fishing along with digital forensics, penetration testing, and malware analysis.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

FBI and CISA Warn About Actively Exploited Vulnerability in Zoho

Zoho Vulnerability , Atlassian Confluence Vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) and FBI warned about the ongoing exploitation of the recently addressed vulnerability in Zoho’s ManageEngine ServiceDesk Plus product. Tracked as CVE-2021-44077, the unauthenticated remote code execution vulnerability affects all ServiceDesk Plus versions up to and including version 11305.

Successful exploitation of this flaw could allow an attacker to upload executable files and place web shells that enable post-exploitation activities like compromising administrator credentials, conducting lateral movement, and exfiltrating registry hives and Active Directory files. While there is no information about the attackers behind this exploitation, the FBI and CISA suspect that advanced persistent threat (APT) actors are among those exploiting the vulnerability.

Also Read: CISA, FBI Ask Critical Infrastructure Partners to be Vigilant This Festive Season

While Zoho released the patch for this vulnerability on September 16, 2021, the FBI and CISA stated threat actors have been exploiting the CVE-2021-44077 flaw since October 2021.

The agencies also identified attackers using various tactics, techniques, and procedures (TTPs), including:

  • Writing web shells to disk for initial persistence
  • Obfuscating and Deobfuscating/Decoding Files or Information
  • Conducting further operations to dump user credentials
  • Living off the land by only using signed Windows binaries for follow-on actions
  • Adding/deleting user accounts as needed
  • Stealing copies of the Active Directory database (NTDS.dit) or registry hives
  • Using Windows Management Instrumentation (WMI) for remote execution
  • Deleting files to remove indicators from the host
  • Discovering domain accounts with the net Windows command
  • Using Windows utilities to collect and archive files for exfiltration
  • Using custom symmetric encryption for command and control (C2)

Required Actions

The agencies urged organizations to report if they find the existence of any of the following scenarios:

  • Identification of indicators of compromise as outlined above.
  • Presence of webshell code on compromised ServiceDesk Plus servers.
  • Unauthorized access to or use of accounts.
  • Evidence of lateral movement by malicious actors with access to compromised systems.
  • Other indicators of unauthorized access or compromise.

CISA and FBI urged organizations to be vigilant and patch their vulnerable networks with the recent updates.

NHS U.K. Warns About Fake Omicron PCR Test Alerts

Omicron_News

Just when the world is trying to come to terms with the challenges unleashed by the COVID-19 virus, we have another variant, Omicron.  Threat actors are already eyeing the new variant to trick victims into phishing.

The National Health Service (NHS) U.K. has issued a warning through its Twitter handle requesting the citizens to not fall prey to an email warranting “PCR testing” for the Omicron variant.

The residents of the U.K. have been receiving fake emails, pretending to be from NHS, asking individuals to order their PCR test. The malicious link, if accessed, also steers the individual to a fake NHS website. The user is asked to fill in all the personal details and bank details to purchase the test. All the credentials get saved, and the criminals sit on a goldmine.

Since November and December are festive seasons across the globe, people are a tad less vigilant and become easy targets for threat actors. Since last year, we have been inundated with news related to scams and frauds in the name of COVID-19. What followed was a significant change in the threat landscape, and the health sector continues to be amongst the most targeted by cybercriminals.

The COVID-19 related scams and fraud took a back seat in the second half of 2021, as malware and ransomware attacks made their presence felt in the consumer sector and critical infrastructure industries.

However, Omicron as offered renewed opportunity for scamsters.

From the U.K. to the World

It is not far when similar attacks will be reported from other parts of the world. Numerous government and health care authorities have been issuing alerts to safeguard individuals from COVID-19 related scams, and the number of victims falling prey continues to move northwards.

The U.S. Department of Health and Human Services Office of Inspector General has alerted the public and shared measures to protect themselves from these fraudulent offers and schemes:

  • Do not buy fake vaccine cards, do not make your own vaccine cards, and do not fill-in blank vaccination record cards with false information.
  • As volunteers go door-to-door to inform communities across the country about COVID-19 vaccines, be sure to protect yourself from criminals who are seeking to commit fraud. Do not provide personal, medical, or financial details to anyone in exchange for vaccine information and obtain vaccinations from trusted providers.
  • Offers to purchase COVID-19 vaccination cards are scams. Valid proof of COVID-19 vaccination can only be provided to individuals by legitimate providers administering vaccines.
  • Be cautious of COVID-19 survey scams. Do not give your personal, medical, or financial information to anyone claiming to offer money or gifts in exchange for your participation in a COVID-19 vaccine survey.
  • Be mindful of how you dispose of COVID-19 materials such as syringes, vials, vial container boxes, vaccination record cards, and shipment or tracking records. Improper disposal of these items could be used by bad actors to commit fraud.
  • Photos of COVID-19 vaccination cards should not be shared on social media. Posting content that includes your date of birth, health care details or other personally identifiable information can be used to steal your identity.
  • Beneficiaries should be cautious of unsolicited requests for their personal, medical, and financial information. Medicare will not call beneficiaries to offer COVID-19 related products, services, or benefit review.
  • Be suspicious of any unexpected calls or visitors offering COVID-19 tests or supplies. If you receive a suspicious call, hang up immediately.
  • Do not respond to, or open hyperlinks in, text messages about COVID-19 from unknown individuals.
  • Ignore offers or advertisements for COVID-19 testing or treatments on social media sites. If you make an appointment for a COVID-19 test online, make sure the location is an official testing site.
  • Do not give your personal or financial information to anyone claiming to offer HHS grants related to COVID-19.
  • Be aware of scammers pretending to be COVID-19 contact tracers. Legitimate contact tracers will never ask for your Medicare number, financial information, or attempt to set up a COVID-19 test for you and collect payment information for the test.
  • If you suspect COVID-19 health care fraud, report it immediately online or call your local authorities.

These measures hold true not only for existing COVID-19 related frauds but to any new variant or rules that apply to COVID-related issues.

If technology has been a boon, we need to bear the brunt. With the barrage of virtual attacks on health care, education, critical services, banking and finance, e-commerce, one ponders if we are making progress or regressing into the dark world.

Finland Warns About ‘Flubot’ Malware Spread Via SMS

WhisperGate malware campaign, FluBot malware

FluBot – an infamous banking malware that affected thousands of users across Australia and the U.K. – is now active in Finland.

In an official alert, Finland’s National Cyber Security Centre (NCSC-FI) warned about a massive FluBot malware campaign targeting Android users in the country since June 2021. The Finnish Transport and Communications Agency has reportedly received multiple reports about dozens of messages sent to spread the FluBot malware.

What is FluBot?  

FluBot is a sophisticated malware targeting Android users via malicious messages or pop-ups.  The messages that carry FluBot usually alert the victims that they have a new voicemail or missed call from an unknown number.  The message contains a link, which, once clicked, redirects the user to a malicious website impersonating a legitimate website. The malware is then deployed on the targeted device.

How FluBot Infects

The officials stated the FluBot campaign sent fraudulent text messages to Android device users. FluBot malware can steal sensitive information from the compromised device and infect other banking apps installed on the device.

“Clicking on the link does not yet install the malware. Users will be requested to allow the installation. The malware may steal data from the device and send malware-spreading scam messages. The messages are often written without Scandinavian letters (å, ä and ö) and may contain the characters +, /, &, % and @ in random and illogical places in the text,” the alert said.

The NCSC-FI urged organizations to be vigilant and inform about the FluBot campaign to their personnel. Users are recommended not to click on any links from unknown sources and not download files or attachments shared via links or messages.

“Preparedness is important, and organizations should inform their personnel about FluBot to ensure that their employees do not install the malware on their phones. It is important for organizations to know what information and data phones contain and assess the risks of a potential data leak because FluBot steals information from phones,” the alert added.

Mitigation

NCSC-FI offered certain mitigation measures for the affected users:

  • Perform a factory reset on the device. If you restore your settings from a backup, make sure you restore from a backup created before the malware was installed.
  • Contact your bank if you used a banking application or handled credit card information on the infected device.
  • Report any financial losses to the police.
  • Reset your passwords on any services you have used with the device. The malware might have stolen your password if you logged in after installing the malware.
  • Contact your operator because your subscription may have been used to send text messages subject to a charge. The currently active malware for Android devices spread by sending text messages from infected devices.

Commenting on the latest malware campaign, Aino-Maria Väyrynen, Information Security Adviser at the NCSC-FI, said, “According to our current estimate, tens of thousands of messages have been sent to people in Finland during one day. We expect the amount to increase in the coming days and weeks. We managed to almost completely eliminate FluBot from Finland at the end of summer thanks to cooperation among the authorities and telecommunications operators. The currently active malware campaign is a new one because the previously implemented control measures are not effective.”

Episode #18: Building a C-SCRM Program

C-SCRM Program

This year organizations and their customers were impacted by supply chain attacks such as SolarWinds and Kaseya. Then we heard about Lazarus, a notorious APT group using MATA malware and backdoors to target supply chains, particularly in the defense sector. These ripples were felt around the world, and in the Asia Pacific region too. According to a Barracuda survey,  46% of APAC respondents identified software supply chain attacks as their top application security challenge. That’s why it is important to have a Cyber Supply Chain Risk Management (C-SCRM).

Now, organization outsource to vendors and contractors to save costs, and to focus on core competencies, innovation, and core competencies. But vendors and solution providers could be the weak link in the chain. And since you are entrusting them with your customer data and giving them the keys to your infrastructure, albeit in a controlled manner, that increases your risk quotient.

According to the Poneman Institute’s Cost of Data Breach Report 2020, data breaches caused by third parties increase the cost of a data breach by an average of $207,411.

Since you depend on the nth vendor, you need to be assured that their environments are as secure as yours – to assure your customers that their data is safe. That also mitigates the risk for your own infrastructure.

And that’s where Cyber Supply Chain Risk Management (C-SCRM) comes in.

 

Mani Keerthi Nagothu is a cybersecurity professional with work experience starting in India, London, Bermuda, and Canada. She worked with consulting firms before her current role as Security Lead at Ballard Power Systems. She is also an expert on C-SCRM.

Her experience comprises building cybersecurity strategies, developing security initiatives, Cyber incident response, and risk assessments.

She was a recent speaker at (ISC)2 security congress 2021, Cloud Security Alliance SECtember 2021, Day of Shecurity 2021, Bsides (Vancouver, Calgary, Edmonton) 2021.

She recently started a podcast on LinkedIn named: “A Thought in Cyber” season 1. The podcast focuses on specific topics related to Cybersecurity including leadership, Emerging Technology, and Emotional Intelligence.

We recommend: 3 Steps Businesses Can Take to Protect Themselves From Software Supply Chain Attacks

Threat Actors Leverage Smishing to Target Iran Citizens

Smishing attacks

Security researchers from Check Point found ongoing malware campaigns targeting Iran citizens. The campaign reportedly uses socially engineered SMS messages to infect tens of thousands of victims’ devices.

The researchers stated that attackers leveraged specially crafted messages to impersonate officials from the Iranian government to trick victims into downloading malicious Android applications that steal credit card data, personal messages, and two-factor authentication codes. Once attackers get hold of the data, they make unauthorized money withdrawals and turn each infected device into a bot to spread the malware to other devices.

Attackers Used Smishing

The threat actors used the Smishing technique to distribute the malware. In Smishing attacks, fraudsters send a specially crafted message (SMS), provoking the user to click on a malicious URL hidden in the text. Besides, the attackers used multiple Telegram channels to promote and sell their malicious tools.

“For $50-$150, the threat actors provide a full ‘Android Campaign Kit’ including the malicious application and underlying infrastructure, with a control panel that can be easily managed by any unskilled attacker via a simple Telegram bot interface,” the researchers said.

The Android backdoor used in this campaign is capable of:

  • SMS stealing
  • Hiding to maintain persistence
  • Bypass 2FA:
  • Botnet Capabilities
  • Wormability

Also Read: How to Find a Phishing Email

How the Campaign Works

  • The malware distribution begins with a phishing SMS. In many cases, it’s a message from an electronic judicial notification system that notifies the victim that a new complaint has been opened against them. The SMS message contains the link to a web page to follow up on the complaint.
  • The webpage lures the user to download a malicious Android application and enter credit card data under the pretense of a small service fee.
  • Once installed, the malicious Android application steals all the SMS messages from the infected device, allowing the attackers to use the credit card with access to 2FA SMS sent by credit card companies.
  • The malicious application checks the attacker-controlled C&C server for new commands to execute periodically. Most notable is the command to spread additional phishing SMS messages to a list of new phone numbers.

Thefts of Iranian Rials in Billions

Check Point suspects that the campaign has compromised and installed malware on tens of thousands of Android devices, resulting in the theft of billions of Iranian Rials from victims, with estimates of $1,000 to $2,000 per victim.

Alexandra Gofman, Threat Intelligence Team Leader at Check Point Software, said, “The general population of Iran is in a growing situation where cyberattacks significantly impact day-to-day lives. These attacks began with the railways, which we traced to a group called Indra. The attacks continued with gas stations and then the national aviation company. Now, we’re seeing yet another cyberattack that shows how even pure cybercrime can make headlines and chaos, hurting many in Iran. Although we do not see a direct connection between these latest cyberattacks and the aforementioned major attacks, our latest insights show how even unsophisticated cyberattacks significantly damage Iran’s general population. We believe these recent cyberattacks to be financially motivated and a form of pure cybercrime. We suspect the threat actors involved are likely from Iran itself.”

India in the Top 5 Countries for Access to Corporate Networks: Report

Acronis Cyber Readiness Report, cyberattacks in India, cybercrime in India, India’s Private Sector

Group-IB, a global cybersecurity leader based in Singapore, presented its research into global cyberthreats titled “Hi-Tech Crime Trends 2021/2022” at its annual threat hunting and intelligence CyberCrimeCon’21 conference. As part of the report, which explores cybercrime developments in H2 2020 — H1 2021, Group-IB researchers analyze the increasing complexity of the global threat landscape and particularly highlight the growing role of alliances between threat actors. The trend manifests itself in partnerships between ransomware operators and initial access brokers under the Ransomware-as-a-Service model. Scammers too band together in clans to automate and streamline fraudulent operations. Notably, individual cybercrimes, such as carding, is in decline for the first time in a while.

For the 10th consecutive year, the Hi-Tech Crime Trends report analyzes the various aspects of the cybercriminal industry’s operations, examines attacks, and provides forecasts for the threat landscape for various economy sectors. The report was for the first time divided into five major volumes with different focuses — ransomware, the sale of access to corporate networks, cyberwarfare, the financial sector threats, and phishing and scam. Forecasts and recommendations outlined in Hi-TechCrime Trends 2020-2021 seek to prevent damage and downtimes for companies around the world.

Sales of Access to Corporate Networks: Companies in APAC are Trending

In H2 2020 – H1 2021, the market for the sale of access to corporate networks continued to flourish and reached $7,165,387 globally, which is a 16% increase compared to the corresponding period a year earlier. It should be noted that some of the sellers do not specify costs for the lots they offer, which creates certain obstacles to evaluating the actual size of this market.

In APAC alone, the total cost of all the accesses to the region’s companies available in the underground totaled $3,307,210 in the review period, which is nearly a 7-fold increase year-on-year. Most of the accesses on the sale belonged to organizations from Australia (36%), India (23%), and China (14%).

Australia and India have even made it to the global top 5 countries, access to whose companies is most frequently found in the underground, with a 4% and 3% share, respectively. They are preceded by the U.K. (4%), France (5%), and the U.S. (30%).

The majority of companies affected belonged to production, education, financial services, healthcare, and commerce. In the review period, the number of industries exploited by initial access brokers surged by 75% from 20 to 35, which indicates that cybercriminals had just started to realize the variety of potential victims. This is also reflected in the fact that the number of countries affected by the sellers of access to corporate networks rose by 62% from 42 to 68. In APAC alone, the number of attacked countries grew by 50% from 10 to 15, having added Singapore, Indonesia, Malaysia, and South Korea.

The number of initial access brokers continues growing as well, with the number of access sellers having amounted to 262 in H2 2020-H1 2021. At least 229 out of them are newbies to the market. To compare, over the previous review period, the number of active sellers totaled 86. The total number of accesses offered for sale reached 1,099, compared to 362 a year earlier.

Cybercriminals who buy access to corporate networks frequently monetize it with the help of ransomware-as-a-service affiliate programs. Group-IB analysts expect the growing demand for ransomware to contribute to the emergence of new initial access brokers and the general increase in the number of access offers.

Corporansom: Instruments to Pressure Victims and RaaS

Over the review period, Group-IB analysts recorded 21 new Ransomware-as-a-Service (RaaS) programs, which is a 19% increase compared to the previous period. During the review period, the cybercriminals have mastered the use of Data Leak Sites (DLS), web resources that are used as an additional source of pressure on their victims to make them pay the ransom under the threat of leaking their data in public. However, in practice, even if the ransom is paid, the victim can find its data available in public. The number of new DLS resources more than doubled during the review period and reached 28, compared to 13 in H2 2019 – H1 2020. In total, the data on 2,371 companies were released on DLS websites over time. This is an increase of an unprecedented 935% compared to the previous review period when data on 229 victims was made public.

It is noteworthy that in the first three quarters of this year, ransomware operators released 47% more data on the attacked companies than in the entire 2020. Taking into account that cybercriminals release the data on only about 10% of their victims, the actual number of ransomware attack victims is dozens more. The number of companies that opt for paying the ransom is estimated at 30%.

According to the data from DLS resources, the APAC region ranked third in terms of the number of attacked companies in 2020 and 2021, preceded by Europe and North America. In the first three quarters of this year, the Asia-Pacific’s share in the regional distribution grew from 6.1% to 9.1%. In the current year, the majority of publicly known ransomware attack victims in APAC originated from Australia (41), India (24), Japan (16), Taiwan (16), and Indonesia (12).

Globally, the majority of companies targeted by ransomware operators in the current year originated from the United States (49.2%), Canada (5.6%), and France (5.2%), while the majority of organizations affected belonged to manufacturing (9.6%), real estate (9.5%) and transportation (8.2%).

Having analyzed ransomware DLS in 2021, Group-IB analysts concluded that Conti became the most aggressive ransomware group, which made public information about 361 victims (16.5% of all victim-companies whose data was released on DLS), followed by Lockbit (251), Avaddon (164), REvil (155), and Pysa (118). Last year’s Top 5 was as follows: Maze (259), Egregor (204), Conti (173), REvil (141), and Pysa (123).

Holding Back Carding

Over the review period, the carding market dropped by 26% from $1.9 billion to $1.4 billion compared to the previous period. Such a decrease is explained by the lower number of dumps (the data stored on the bank card magnetic stripe) offered for sale: the number of offers shrank by 17% from 70 million records to 58 million in light of the shutdown of the largest card shop Joker’s Stash. Meanwhile, the average price of a bank card dump fell from $21.88 to $13.84, while the maximum price surged from $500 to $750.

An opposite trend was recorded on the market for the sale of bank card text data (bank card numbers, expiration dates, names of owners, addresses, CVV): their number soared by 36% from 28 million records to 38 million, which can among other things be explained by the increased number of phishing web resources mimicking famous brands amid the pandemic. The average price for the text data climbed from $12.78 to $15.2, while the maximum one skyrocketed 7-fold from $150 to an unprecedented $1,000.

In APAC specifically, the carding market dropped from $328.7 million to $291.5 million in the review period. This was accompanied by the increase in the average price of text card data from $14.23 to $20.26 and a dramatic drop in the price of a dump from $75.17 to $39.57.

Phishing and Scam Partner Programs

Another cohort of cybercriminals actively forging partnerships over the review period were scammers. In the last few years, phishing and scam affiliate programs became highly popular. The research conducted by Group-IB shows that there are more than 70 phishing and scam affiliate programs. Participants aim to steal money, as well as personal and payment data. In the reporting period, the threat actors who took part in such schemes pocketed at least $10 million in total. The average amount stolen by a scam affiliate program member is estimated at $83.

The affiliate programs involve large numbers of participants, have a strict hierarchy, and use complex technical infrastructures to automate fraudulent activities. This helps scale phishing campaigns and customize them for banks, popular email services, marketplaces, logistics companies, and other organizations. Phishing and scam affiliate programs initially focused on Russia and other CIS countries, recently started their online migration to Europe, America, Asia, and the Middle East. This is exemplified by Classiscam. Group-IB is aware of at least 71 brands from 36 countries, impersonated by the affiliate program members.

Over 4 Mn Payment Card Details Hawked on Dark Web

one million card data exposed

Financial information like credit/debit card and bank account numbers continue to be peddled on underground dark web markets. Threat actor groups and other cybercriminal affiliates often rely on the darknet markets to obtain sensitive financial data and exploit it later. A new analysis from NordVPN found over 4 million (4,481,379) payment card details, belonging to users across 140 countries, being traded on the dark web. The hackers were found selling payment cards information for $10 on average per card. The highest number of card details found for sale were from the U.S., Australia, and Hong Kong.

Card Numbers are Brute-forced

NordVPN found that most of the sensitive financial information traded on the dark web was harvested via brute-forcing. Brute-force technique is often used to guess passwords and penetrate targeted accounts. The passwords are guessed using dictionaries or common word combinations.

“Increasingly, the card numbers sold on the dark web are brute-forced. Brute-forcing is a bit like guessing. Think of a computer trying to guess your password. First, it tries 000000, then 000001, then 000002, and so on until it gets it right. Being a computer, it can make thousands of guesses a second. After all, criminals don’t target specific individuals or specific cards. It’s all about guessing any viable card details that work to sell,” said Marijus Briedis, CTO at NordVPN.

Key Findings  

  • The independent researchers found 1,561,739 sets of card details for sale on the dark web from the U.S. during their research. This was far more than from anywhere else.
  • 1,561,739 out of 4,481,379 payment card details found by researchers for sale belonged to Americans.
  • More than half of all the discovered payment cards coming from the U.S. were Visa, followed by Mastercard (406,851) and American Express (143,836).
  • The second most affected nation was Australia, with 419,806 card data researchers discovered for sale on the dark web. And 399,537 hacked payment cards belonged to people from Hong Kong.
  • Comparing the number of credit and debit cards, overall, the difference wasn’t very big, with 52.05% of the discovered cards being debit and 47.95% being credit cards.
  • Debit cards were more common than credit cards in the markets the independent researchers surveyed. Hacked debit cards put their victims at greater risk because there tend to be fewer protections in place for debit.

Also Read: 3 Digital Assets That Are High in Demand on Dark Web Forums

Mitigation

Threat actors often obtain confidential financial data to make fraudulent purchases or trade across underground forums. Users need to be extra vigilant while giving their financial information online. Maintaining strong password hygiene with multi-factor authentication procedures is recommended.

Briedis added, “Review your monthly statement for suspicious activity and respond quickly and seriously to any notice from your bank that your card may have been used in an unauthorized manner. Another recommendation is to have a separate bank account for different purposes and only keep small amounts of money on the one your payment cards are connected to. Some banks also offer temporary virtual cards you can use if you don’t feel safe while shopping online.”

Experts Say…

Troy HuntIn an exclusive quote to CISO MAG, Troy Adam Hunt, Information Security Author and Instructor at Pluralsight and Founder of Have I Been Pwned, said, “This research shows that now more than ever, as our lives are increasingly digitized, we face ongoing threats to our privacy, finances and general wellbeing. Particularly striking in this report is the indiscriminate nature of brute-forcing credit card numbers; you don’t have to be personally targeted, you’re literally just a number that a computer can guess and that can have a major impact on your financial posture.”