Home Blog Page 37

‘SharkBot’ Android Trojan Found Targeting Banking Apps and Crypto Exchanges

SharkBot

A new botnet, dubbed “SharkBot,” is targeting Italy, the U.K., and the U.S., including banking applications and cryptocurrency exchanges.

The Cleafy TIR team discovered the Android banking Trojan in October 2021. The botnet uses the ATS (Automatic Transfer System) technique to initiate money transfer from infected devices and evade multi-factor authentication.

“Once SharkBot is successfully installed in the victim’s device, attackers can obtain sensitive banking information through the abuse of Accessibility Services, such as credentials, personal information, current balance, etc., but also to perform gestures on the infected device,” the researchers at Cleafy said.

SharkBot has a very low detection rate due to the implementation of string obfuscation routine, emulator detection, and a domain generation algorithm (DGA) for its network communication. It executes an Overlay attack to filch login credentials and credit card information. The Trojan also has the potential to intercept legitimate banking communications sent through SMS.

The malware for SharkBot has been written from scratch and is anticipated to be at an early stage of development.

SharkBot Explained

Per Cleafy, the ATS technique has recently been noticed in other banking Trojans, such as Gustuff, which enables attackers to auto-fill fields in legitimate mobile banking apps and initiate money transfers from compromised devices.

“Contrary to TeaBot and Oscorp/UBEL where a live operator is required to insert and authorize a money transfer, with ATS technique threat actors can scale up their operations with minimum user intervention. We assume that SharkBot is trying to bypass behavioral detection countermeasures (e.g., biometrics) put in place by multiple banks and financial services with the abuse of Android Accessibility Services, also bypassing the need of a “new device enrollment,” said Cleafy.

SharkBot’s Features

  • Perform classic Overlay Attacks against multiple applications to steal login credentials and credit card information
  • Intercept/hide SMS messages
  • Enable key-logging functionalities
  • Obtain full remote control of an Android device (via Accessibility Services)

The malicious app is installed on the user’s device using the side-loading technique and social engineering schemes. The application also apes icons and commonly used app names of banking applications. After a successful installation, the Trojan activates fake pop-ups like “Allow Media Player” to take complete control of the device.

How SharkBot Evades Detection

  • Strings obfuscation: To slow down the static analysis and “hide” all the commands and important information used by the malware.
  • Anti-Emulator: When the malicious application is installed on the device, it checks if the device is an emulator or a real phone. This technique is usually used to bypass sandboxes or common emulators used by researchers during the dynamic analysis.
  • External ATS module: Once installed, the malware downloads an additional module from the C2. The external module is a “.jar” file that contains all the functionality used to perform the ATS attacks.
  • Hide the icon app: Once installed, SharkBot hides the icon of the app from the device screen.
  • Anti-delete: Like other malware, SharkBot uses Accessibility Services to avoid that the user uninstalling the malicious application from the settings options.
  • Encrypted communication: All the communication between the malware and C2 is encrypted and encoded with Base64. In addition to this, SharkBot uses a Domain Generator Algorithm (DGA).

Automatic Transfer System

Recently Emotet, a banking-trojan-turned-botnet, was in the news for resurfacing after a hiatus of 10 months. Another version which was spotted in 2014, also used the ATS technique to rob victims’ bank accounts. The version then had a modular structure, including an installation module, banking module, spam bot module, a module for stealing address books from Microsoft Outlook, and a module for organizing distributed denial-of-service (DDoS) attacks. Due to its harvesting capability, the technique is popular as it initiates direct financial transfers rather than stealing credentials and then using the stolen data to pilfer.

How CISOs Can Communicate the Need for Both IT and OT Cybersecurity

Apple Notarization, operational technology

When it comes to cybersecurity, 2021 was a wake-up call for most industrial sectors. Cyber vulnerabilities in operational technology (OT) were exposed and we learned that critical American infrastructure can be crippled with the click of a button. Attacks were present in the news monthly, with the most highly publicized including the shutdown of one of the nation’s largest pipelines, Colonial Pipeline. The recent surge of cyber incidents and the correlating effect on operations highlights the fact that threat actors have moved beyond traditional information technology (IT) targets, where their main goal is to obtain important information and data, to OT, where their primary mission is to cause physical disruptions or harm.

By Ryan Moody, President and CEO at ABS Group

As the end of the year approaches and we begin making organizational plans for 2022, CISOs within industrial sectors must take time to reflect on this year’s unprecedented events and how they should shape their priorities.

First, CISOs need to reassess their cybersecurity programs to properly address the current threat landscape. We now know that cybercriminals have set their sights on making an impact in OT environments; therefore, CISOs must completely shift their focus. The traditional solutions implemented in an IT environment do not address the unique needs and circumstances of OT.

To build out an entirely new cybersecurity program that addresses IT and OT cyber environments independently, CISOs must educate and garner buy-in from their board of directors. This crucial task will not be quick or easy to accomplish, but if done correctly, it can result in greater resources that will enable organizations to keep their digital and physical assets secure and preserve their reputation.

Educating the Board: Dispel Myths and Misconceptions

Although many boards know their organizations need to act on cybersecurity following the barrage of incidents in 2021, the biggest obstacle standing in the way is education. Most of the public – including board members – do not understand the differences between IT and OT networks and the challenges of protecting the less mature OT networks from threat actors. The media coverage and conversations on the topic are filled with myths and misinformation. There is also no real clear understanding of the distinction between IT and OT cybersecurity, which presents a significant risk to organizations.

CISOs should begin their discussions with their boards by educating the members on common myths about cybersecurity versus the realities. They should be prepared to explain:

  • IT Cybersecurity Solutions Do Not Work in OT Environments: It’s a common misconception that IT and OT are the same. CISOs need to debunk this myth by clearly communicating the differences between IT and OT with tangible examples. In an IT environment, a click on a computer screen sends an email. That same click in an OT network could open a valve or stop an engine, leading to a catastrophic event. The primary goal in an IT attack is data; an OT attack targets the lifeblood of a business: your operations. Technologies used to monitor IT networks for cyber-attacks such as agents and active scanning are mostly incompatible with and will disrupt OT systems. OT security requires highly specialized domain expertise along with cyber expertise. A cyber-attack in an OT environment might look like a simple maintenance failure – you need expertise that can understand the difference.
  • Compliant Does Not Equal Secure: Government regulations can only go so far; cybercriminals are constantly adapting, and compliance-driven rules can’t keep up with their pace. Most organizations do not realize that even if you are complying with all the latest regulations, you still won’t be secure. While government regulations have their place and provide frameworks for action, they will never be the sole answer to the problem. There is much more work to be done outside of regulatory requirements.
  • Stopping One Attack Does Not Prevent the Next: Attackers can adapt far more quickly than cybersecurity can evolve. CISOs need to address the myth that solving the last attack will make their organizations safe. Because attackers are constantly evolving and learning, implementing a solution that would have prevented the last attack, does not prevent the next or the one after that. They must be proactive with training, policies and monitoring to plan for, defend against and respond to all future attacks.

Generating Buy-In from the Board: Focus on Business Risk and Impact

Companies won’t spontaneously invest in cybersecurity. CISOs are often challenged by the board to explain what the real impact will be should a cybersecurity event occur. And since many board members don’t fully understand cybersecurity, let alone the key differences between IT and OT, CISOs must focus on what will resonate most. The need to emphasize the impact of cyber-attacks on market valuations, competitive advantages, ability to bid, and key financial performance indicators.

CISOs should also explain why managing cyber risk for both IT and OT environments is a business imperative. Their discussions should offer examples of how previous cyber-attacks in IT and OT have impacted the business performance and operations of those that have been a victim of these types of attacks. For example, the Colonial Pipeline cyber incident caused an entire shutdown of the pipeline operations that supplied 45% of fuel to the East Coast, cost the company millions in ransom, and had a substantial impact on the supply chain.

Rising to the Challenge of Communicating with Boards

Communicating cybersecurity, and more specifically the different approaches to managing IT and OT cyber risks, to the board will not be an easy task for CISOs as they map out their needs and priorities for 2022. However, they must remember that education is key and that an attack on OT systems can significantly impact people, property, and the environment. Cyber attackers will not stop; they will only increase their activity and become more intelligent as they leverage the weakness of organizations. Boards of directors must grasp this concept, and act now (not later) if they wish to keep their organizations truly secure. 2021 opened pandora’s box, and it will take focused effort and investment to close it.


About the Author

Ryan MoodyRyan Moody is President and CEO of ABS Group of Companies, Inc. (ABS Group). He previously served as Vice President of Strategic Development for the American Bureau of Shipping (ABS), where he was responsible for guiding and supporting ABS’ and ABS Group’s strategic activities and corporate growth globally. He brings 18 years of experience primarily in the oil and gas sector. Prior to ABS, he held leadership positions at Siemens Government Technologies, Siemens Energy, and FMC Technologies. His experience includes engineering, business segment management, product management, cybersecurity strategy, and corporate strategy. Moody holds a B.S. in Mechanical Engineering from Texas A&M University and an MBA from the University of Houston.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Beyond Supply Chain Attacks and Ransomware

Ransomware, supply chain and ransomware

This past year has been one of victory – for cybercriminals. The first nine months of 2021 saw 40% more cyberattacks than the same period in 2020, according to data from Check Point Software Technologies Ltd. And next year, things look to get even more challenging, with new and more comprehensive types of attacks, especially by state-level actors. Here is a look at what 2021 has brought, and what we can expect in 2022:

By Shmulik Yehezkel, Chief Critical Cyber Operations Officer at CYE

The Year of the Supply Chain Attack

Supply chain attacks were up more than sixfold in the first nine months of the year alone, according to a report from software supply chain management company Sonatype. These attacks, including the high-profile SolarWinds incident of late 2020 whose fallout continues to expand, are extremely dangerous because once a hacker gains access to a significant software supplier, they can also sometimes reach the data and code of their subscribers and customers. This provides multiple routes to new targets, including those that were once considered well-protected. Another advantage for attackers is deniability, as they can use the supply-chain company as a proxy for another target.

Attackers’ Deniability Has Grown

As cyberattacks grew increasingly severe in 2021, they also became harder to trace back to the parties carrying them out. Ironically, this is because we have seen that more hackers–including state-backed bad actors – use open-source tools that are publicly available – from what we at CYE have seen, mainly on GitHub. This helps cover their tracks, providing them a wide range of deniability, and making it more difficult to target them with counterattacks or other forms of retaliation. The anonymous nature of the attacks also allows those who carry them out to avoid dealing with the fallout, like being seen as responsible for causing financial damage or human death or injury.

Reliance on Publicly-available Attack Tools Increased

Although it may sound surprising, most of the cyberattacks we have seen during the past year were not highly technically sophisticated; this is true for both simple cybercriminals and state-level actors. Time and again, we saw them using publicly-available tools to take advantage of known vulnerabilities; as this not only saves them time and money but allows them the cover of deniability. In addition, as much as we do see growing usage of the much-feared zero-day attacks, these are still mainly limited to high-level state actors and superpowers.

On the horizon: The Increased Use of the “Hub” Attack

Going into the next year, we expect the continued growth of supply chain attacks, mainly with commercially-available tools. But hackers will also take things to the next level with what we are calling attacks on “hub-companies.” Hub companies are those with extensive digital connections to suppliers as well as customers. These companies can be average-seeming organizations, as well as insurance companies, credit clearing companies, and SaaS providers. These companies provide links to potentially more valuable suppliers and large customers. In addition to directly getting into the networks of these higher-value targets, like banks or weapons companies, hackers can find in the hub company valuable intelligence and information, like how a supplier interacts with a vendor, for creating effective phishing campaigns. This emerging hub attack is on track to become a preferred method of attack, simply because it is an efficient way to carry out attacks with far-reaching consequences, and provides easier avenues to bigger more well-protected targets.

The Emergence of “CN-All”

We also see change on the horizon for nation-state-backed attacks. These attacks have been on the rise in their number and in their success rates over the last year. But going forward, they will become more ambitious.

Today, the industry classifies attacks into categories: CNE, for computer network exploitation or espionage, CNI, for computer network influence, and CNA for computer network attack; this upcoming year, we are going to see more and more state-level actors carrying out what we call CN-ALL attacks. In this type of attack, state-level actors will combine all of the cyber warfare elements–espionage, influence, and disabling systems. These attacks will be particularly challenging because they require response simultaneously on several fronts. CISOs need to be prepared to deal with the technical aspects of recovering data and accessing backup systems, while also dealing with law-enforcement and legal teams, addressing the media, and, when needed, informing regulatory officials.

In addition, as we saw with the attack last December on Israeli insurance firm Shirbit, widely attributed to Iran, not all the consequences are clear at once. CN-ALL attacks will be about the attacker choosing when, where, and why to execute each phase of the attack. The consequence is that CISOs will have to keep in mind that even when an attack has been found, mitigated, and foiled, it might not be the end of it. In the Shirbit example, the initial part of the attack was the hackers demanding ransom and shutting down the company’s systems, making it unable to renew or issue policies and severely cutting into its business revenue.  But later, it emerged that the attackers then actually sold customer data online, and, some experts say, had an overall goal of humiliating Israel and ruining its reputation as a technology powerhouse. This mix of financial and political goals, or disguising political motives as financial ones, is something we will, unfortunately, see more of this coming year.

No One is Immune

The growth in these types of attacks will require companies to rely on cybersecurity teams made up of professionals with hands-on experience in cyber warfare at the state level, in places like the government, military, and intelligence services, who really understand and have experienced interactions with state-backed hacking groups. We call them ACTs – Advanced Cyber Talents. On a more boring note, because the stakes of attacks are getting bigger, it remains more important than ever to make sure all employees understand the value of strong passwords, learn how to recognize phishing attempts, and use multi-factor authentication. While sloppiness in these areas has long allowed bad actors to reach sensitive and valuable data, now, with the growth of hub and CN-All attacks, this human factor can also result not only in severe damage to their organization but potentially to thousands of others. In addition, from now on, every company, regardless of size, domain, or region of activity, should be aware that it might be a potential target for cybercrime, as well as state-level cyberattacks with a variety of purposes and goals. No one is immune.


About the Author

Shmulik YehezkelAfter more than 25 years in the military and the Israeli defense special forces, Shmulik joined the CYE team as Chief Critical Cyber Operations Officer & CISO. Shmulik leads the Critical Cyber Operation division (C2OPS). The C2OPS division is responsible for CYE operative operations and is composed of four main centers: data forensics and incident response (DFIR), threat hunting & computer threat intelligence (CTI), advanced cyber architecture & engineering, and the VIP security center. Shmulik is a software engineer and cyber security professional with extensive strategic and hands-on experience. Shmulik brings years’ worth of experience leading cyber operations, cyber R&D, information security, and risk management in the Israel Defense Forces, the Ministry of Defense, and the Office of the Prime Minister of Israel.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Researchers Uncover North Korean Threat Actor Group TA406 Targeting Diplomats

Cryptocurrency Lazarus, North Korean TA406, Lazarus Group , Korea Atomic Energy Research Institute

Security researchers uncovered a cyberespionage campaign linked to North Korean actors, targeting foreign policy experts, journalists, and nongovernmental organizations (NGOs). According to a cyberthreat research report from Proofpoint, the North Korean actors mostly target individuals from North America, Russia, and China. Tracked as Threat Actor 406 (TA406), the campaign reportedly stole users’ credentials and sensitive financial data from high-level officials, law enforcement officers, and experts in economics and finance.

The attackers have targeted the victims by masquerading as Russian diplomats and academics, representatives of the Ministry of Foreign Affairs of the Russian Federation, human rights officials, or Korean individuals. TA406 has also targeted individuals and organizations related to cryptocurrency for financial gain.

TA406 in Brief

  • The North Korea-aligned threat actor TA406 conducted frequent credential theft campaigns targeting research, education, government, media, and other organizations in 2021
  • Proofpoint considers TA406 as one of several actors that make up the activity publicly tracked as Kimsuky, Thallium, and Konni Group.
  • TA406 doesn’t usually employ malware in campaigns. However, two notable 2021 campaigns attributed to this group attempted to distribute malware that could be used for information gathering.

One Name – Three Groups

Proofpoint stated that TA406 campaigns have targeted users since 2018 and increased their threat activities from January 2021. It’s found that TA406 is also associated with the Kimsuky threat actor group. TA406 usually operates as three separate threat actors—TA406, TA408, and TA427 employing malware and credential harvesting in espionage and information-gathering campaigns. TA406 and TA427 operators are responsible for conducting phishing campaigns.

“TA406 uses its own registered and controlled infrastructure to host credential capture web pages and malicious documents and a limited number of legitimate, compromised websites as infrastructure. TA406 uses Gmail, Yandex, and Mail[.]ru email accounts masquerading as legitimate government or nonprofit entities to distribute lures. TA406 also uses custom message-sending tools such as Star and a PHP-based PHPMailer tool. TA406 uses URLs in phishing emails linking to the SendGrid email delivery service that redirects to an attacker-controlled domain hosting the malicious payload or a credential-harvesting page. SendGrid is an email marketing platform used for legitimate business purposes and is often allowed to bypass email security filters; many threat actors use this type of redirect behavior to appear legitimate,” Proofpoint said.

North Korean Actors Continue to Evolve

State-sponsored actors from North Korea continue to target critical organizations worldwide. Recently, security experts from Kaspersky uncovered two latest supply-chain attack campaigns from the North Korean hacking group – Lazarus. The attackers obtained access to a South Korean security software vendor’s network to exploit the corporate software and a Latvia-based IT asset-monitoring product vendor by deploying Blindingcan and Copperhedge backdoors.

FBI Alerts About Zero-Day Vulnerability in the FatPipe MPVPN device software

FBI, FatPipe MPVPN zero-day

FBI issued an alert revealing exploitation of zero-day vulnerability in the FatPipe MPVPN device software. FatPipe MPVPN zero-day vulnerability exploitation by APT actors allows access to an unrestricted file upload function to drop a webshell for malicious activity with root access, leading to elevated privileges and potential follow-on activity. According to the FBI statement, the vulnerability is not yet identified with a CVE number but can be located with the FatPipe Security Advisory number FPSA006. All versions of FatPipe WARP, MPVPN, and IPVPN device software prior to the updated releases, are affected by the vulnerability.

Report

FBI has requested users to report the existence of any of the following immediately:

  • Identification of indicators of compromise.
  • Presence of webshell code on compromised FatPipe WARP, MPVPN, and IPVPN appliances.
  • Unauthorized access to or use of accounts.
  • Evidence of lateral movement by malicious actors with access to compromised systems.
  • Malicious IPs identified through the conducted log file searches and session activity.
  • Suspicious or malicious .bash_history contents.
  • Other indicators of unauthorized access or compromise.

Users must share any other information related to the vulnerability with the authorities.

Suggested Mitigations

Immediate action is suggested regarding the discovered FatPipe MPVPN zero-day compromise within the networks.

FatPipe released a patch and security advisory, FPSA006, on November 16, 2021, that fixes the vulnerability.

All FatPipe WARP, MPVPN, and IPVPN device software previous to releases 10.1.2r60p93 and 10.2.2r44p1 are at risk. The security advisory and additional details are available at the following URL: https://fatpipeinc.com/support/cve-list.php.

FBI strongly urges system administrators to upgrade their devices immediately and follow other FatPipe security recommendations, such as disabling UI and SSH access from the WAN interface (externally facing) when not actively using it.

Zero-day Exploits Rising Popularity

A recently published  CISO Mag article discussed how several cybercriminal groups are found buying zero-day vulnerabilities such as the zero day vulnerability in FatPipe MPVPN and leasing exploit-as-a-service models on dark web forums.

Per a report from Digital Shadows, several cybercriminal groups and state-sponsored actors are increasingly willing to purchase information on vulnerabilities and exploits from various cybercrime affiliates on the dark web. The market for zero-day vulnerabilities is reportedly high, as many ransomware operators are interested in buying them. Digital Shadows claim that the price range of zero-day flaws could go up to $10 million.

Microsoft Identifies Six Iranian State Actor Groups Deploying Ransomware

Log4j, Iranian Ransomware Actors, SpoofedSccholars, second-tier targets, NIOPDC

It’s not just stealing confidential data. Cybercriminal activities from state-sponsored actors have evolved, targeting critical infrastructures and demanding ransom from high-net-worth companies. Various threat actor groups are increasingly turning to ransomware as a revenue model by sabotaging the targets.

Microsoft Threat Intelligence Center (MSTIC) recently identified six Iranian hacking groups deploying ransomware and compromising targeted network systems. “Since September 2020, MSTIC has observed six Iranian threat groups deploying ransomware to achieve their strategic objectives. These ransomware deployments were launched in waves every six to eight weeks on average,” MSTIC said.

The six Iranian threat actor groups include:

  • DEV-0146
  • DEV- 0227
  • PHOSPHORUS
  • DEV-0198
  • RUBIDIUM
  • DEV-0500

The MSTIC team claimed that they’d observed a steady evolution of the tools, techniques, and procedures of malicious network operators based in Iran. The team recently presented their analysis on Iranian nation-state actor activity at the CyberWarCon 2021.

Notable trends in Iranian nation-state sponsored actors according to MSTIC:

  • They are increasingly utilizing ransomware to either collect funds or disrupt their targets.
  • They are more patient and persistent while engaging with their targets.
  • While Iranian operators are more patient and persistent with their social engineering campaigns, they continue to employ aggressive brute force attacks on their targets.

 Iranian operators can:

  • Deploy ransomware
  • Deploy disk wipers
  • Deploy mobile malware
  • Conduct phishing attacks
  • Conduct password spray attacks
  • Conduct mass exploitation attacks
  • Conduct supply chain attacks
  • Cloak C2 communications behind legitimate cloud services

The operators have targeted several international organizations by exploiting unpatched vulnerabilities and performing widespread scanning and ransomed targeted systems through a five-step process: Scan, Exploit, Review, Stage, Ransom.

“As with any observed nation-state actor activity, Microsoft has directly notified customers that have been targeted or compromised, providing them with the information they need to help secure their accounts. Microsoft uses DEV-#### designations as a temporary name given to an unknown, emerging, or a developing cluster of threat activity, allowing MSTIC to track it as a unique set of information until we reach high confidence about the origin or identity of the actor behind the activity. Once it meets the criteria, a DEV is converted to a named actor,” MSTIC added.

Threats from Iran Hackers Continue

Cyberattacks from Iran-based hackers continue to evolve. Recently, the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), the Australian Cyber Security Centre (ACSC), and the United Kingdom’s National Cyber Security Centre (NCSC) jointly released a cybersecurity advisory cautioning active exploitation of Fortinet and Microsoft Exchange ProxyShell vulnerabilities by an Iranian state-sponsored advanced persistent threat (APT) group.

The State of Readiness Will Always Be in Flux

Threats introduced by careless employees working from home looms large today. Studies show that 40% – 50% of employees will click on links in phishing emails or open malicious attachments – thus introducing malware threats into the corporate network. And the nature of threats will continue to evolve. So cybersecurity awareness and readiness must keep up.

In an exclusive video interview, Brian Pereira, Editor-in-Chief, CISO MAG, discusses the state of cybersecurity awareness and readiness with Dr. Imtiaz Abdul Kader, CEO, Perfected Execution.

Dr. Imtiaz, who lives in Johannesburg, says there are two core elements cybersecurity awareness and readiness. One is the training and the skills, and the other is partnerships within the industry.

He says we still have a long way to go for training and skills advancement, though initiatives have been taken to establish specialist training centers.

Cybersecurity threats keep advancing and skills need to keep up, so the state of readiness will always be in a flux, says Dr. Imtiaz.

He believes constant knowledge sharing with employees is quite important for keeping up with the latest threats. It also removes the ambiguity about what they need to do when receiving malicious emails and how to react to incidents.

The second vital thing is engagement with partners and individuals specializing in cybersecurity to acquire the knowledge and the skills. This is a good approach to establishing a cybersecurity response environment.

Dr. Imtiaz is an avid researcher in the field of advanced technology integration to enable business growth. He is also the co-founder and CEO of Perfected Execution, a technology and strategy research start-up. In addition, he also practices as a Technology and Strategy Execution Executive in the Banking Industry, with 23 years of experience in executing large-scale organization transformations. He holds a Ph.D. and M.Eng degrees from the University of the Witwatersrand and published the book #Throw Away the Box.


About the Interviewer

Brian Pereira

Brian Pereira is the Editor-in-Chief of CISO MAG. He has been writing on business technology concepts for the past 27 years and has achieved basic certifications in cloud computing (IBM) and cybersecurity (EC-Council).

 

More stories from Brian

4 in 10 Organizations Do Not Employ a CISO: Report

CISO, Cybersecurity

Organizations across the world have experienced swift changes in their business operations during the new normal. In particular, the adoption of the distributed work environment became a challenge for many companies, resulting in the rise of cyberattack risks. Several enterprises have increased their cybersecurity budgets to deal with new cybersecurity challenges. As the struggle of mitigating cyberthreats seems to surge, some organizations are wary about hiring security professionals. A recent analysis from cybersecurity solutions provider Navisite revealed that over 45% of organizations don’t employ a Chief Information Security Officer (CISO). Of this group, 58% think their company should hire a CISO.

Navisite surveyed IT and compliance professionals in the U.S. to determine their perceptions of the state of cybersecurity leadership and readiness within their organizations. Around 40% of respondents stated, their cybersecurity strategy was developed by a CISO or security team member, with 60% relying on other parts of their organization, including IT, executive leadership, and compliance.

Key Findings: 

  • 21% of respondents admit their company does not have a dedicated person or staff whose sole responsibility is cybersecurity.
  • 75% of respondents said their company experienced an increase in overall cybersecurity threat volume in the last year.
  • 80% of respondents felt their company exhibited strong cybersecurity leadership during the COVID-19 pandemic.
  • 70% of respondents expressed confidence in the effectiveness of their cybersecurity program — but that confidence dropped to 58% for companies without a CISO.
  • Nearly 47% of survey takers believe their company spends too little on cybersecurity.

Also Read: 4 Critical Responsibilities of a CISO Post COVID-19

Commenting on the survey findings, Aaron Boissonnault, Navisite CISO, said, “The survey results support what we’re seeing across the board: organizations prioritized their security efforts during COVID, but at the same time, they’re acutely aware of how much more they need to do to effectively defend against cyber threats. The data also points to an ongoing problem in the industry: a cybersecurity skills shortage that extends to the highest levels. Companies value and want cybersecurity leadership, but it is increasingly difficult to find and retain these individuals.”

CISA, NCSA, ACSC Warn of Iranian APT Actors Exploiting Microsoft and Fortinet Flaws

Avaddon ransomware, Microsoft and Fortinet flaws, apt

The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the Australian Cyber Security Centre (ACSC), and the United Kingdom’s National Cyber Security Centre (NCSC) jointly released a cybersecurity advisory cautioning about active exploitation of Fortinet and Microsoft Exchange ProxyShell vulnerabilities by state-sponsored actors.

The malicious activity is believed to be the work of an Iranian state-sponsored advanced persistent threat (APT) group. The APT actors leveraged Fortinet FortiOS vulnerabilities from March 2021 and a remote code execution flaw affecting Microsoft Exchange Servers since October 2021 to gain initial access to systems to deploy ransomware. According to the advisory, the ACSC is also aware that this APT group has used the same Microsoft Exchange vulnerability in Australia.

“The Iranian government-sponsored APT actors are actively targeting a broad range of victims across multiple U.S. critical infrastructure sectors, including the Transportation Sector and the Healthcare and Public Health Sector, as well as Australian organizations. FBI, CISA, ACSC, and NCSC assess the actors are focused on exploiting known vulnerabilities rather than targeting specific sectors. These Iranian government-sponsored APT actors can leverage this access for follow-on operations, such as data exfiltration or encryption, ransomware, and extortion,” the advisory states.

The Attack

The advisory list the malicious tools used:

Mitigations

The FBI, CISA, ACSC, and NCSC suggest the following mitigations to reduce the risk of compromise by this threat.

  • Patch and Update Systems – Immediately patch software affected by vulnerabilities: CVE-2021-34473, CVE-2018-13379, CVE-2020-12812, and CVE-2019-5591.
  • Evaluate and Update Blocklists and Allowlists
  • Implement and Enforce Backup and Restoration Policies and Procedures
  • Implement Network Segmentation
  • Secure User Accounts
  • Implement Multi-Factor Authentication
  • Use Strong Passwords
  • Secure and Monitor RDP and other Potentially Risky Services
  • Use Antivirus Programs
  • Secure Remote Access
  • Reduce Risk of Phishing

Will It Stop?

Federal authorities across regions have joined hands to create awareness and address the state-sponsored APTs targeting critical infrastructure. In October 2021, Microsoft exposed Iran-linked threat actors using password spraying techniques to break into defense technology companies in the U.S., Israel, and parts of the Middle East.

Per Quarterly Ransomware Index Spotlight Report (Q2 2021), there has been an increase in several key ransomware markers. Steady growth has been observed in the number of new APT groups using ransomware, an emergence of new ransomware families and Ransomware-as-a-Service (RaaS) offerings, and an increase of Common Weakness Enumerations (CWEs) associated with researched vulnerabilities.

International Fraud Awareness Week: 3 Common Online Frauds to Watch Out in 2022

online shopping, International Fraud Awareness Week

Like online shoppers prefer big sale days to grab deals, cybercriminals prey on e-commerce sites to trick unwitting shoppers. E-commerce websites are often a primary target for scams like web skimming or e-skimming from Magecart attackers. As we’re in the middle of the International Fraud Awareness Week (November 14-20), it’s essential to acknowledge the security measures required to defend against online fraud.

International Fraud Awareness Week 

The International Fraud Awareness Week was first organized by the Association of Certified Fraud Examiners (ACFE) in 2012 to mitigate the impact of online fraud. Since then, several organizations worldwide have partnered with the ACFE to participate in the International Fraud Awareness Week during Nov. 14-20 every year. to promote anti-fraud awareness and education.

In view of the International Fraud Awareness Week, let’s take a look at the top cyberthreats impacting e-commerce websites:

1. E-Skimming 

E-Skimming attack, also known as web skimming or Magecart attack, is a form of cybercrime where attackers plant malicious JavaScript code on online stores. In a Magecart attack, hackers gain access to a company’s online store website by compromising and hiding malicious code in it. The malicious code then collects the payment card information from users while making purchases on the infected site. Magecart hackers either sell the stolen card data on the darknet or use it to make fraudulent purchases.

Prevention 

  • Be vigilant about the information you share to complete the payment process.
  • Cancel the transaction if you feel the site is collecting additional information than required.
  • Fill out what is necessary at the checkout page and remember not to save your payment information on the site.
  • Ensure you delete your previously stored payment details from the account, as the data may fall into the wrong hands if your account gets hacked.

Also Read: Ask Yourself These 4 Questions Before Shopping Online

2. Brute Force Attacks 

Sensitive credentials like usernames and passwords are like goldmines to hackers. They often leverage stolen/leaked credentials to break into users’ online accounts to steal confidential data like payment card details or make fraudulent purchases. Hackers often rely on brute-force attacks to guess passwords to penetrate targeted accounts. The passwords are guessed using dictionaries or common word combinations.

Prevention 

Enabling robust authentication procedures like two-factor authentication (2FA), multi-factor authentication (MFA), and zero-trust models can mitigate brute-force attacks.

3. Phishing 

Phishing – the most common attack vector that scammers use to phish users and perform various malicious activities such as deploying malware, stealing users’ personal data, and harvesting credit/debit card details. Attackers create and circulate numerous fraudulent or fake online shopping sites to trick users into purchasing counterfeit/non-existing products.

Earlier, the Federal Trade Commission (FTC) claimed the number of complaints about online shopping scams has increased, and victims have lost a total of $420 million since 2015. The commission received more than 86,000 complaints related to online shopping issues in 2019. The FBI received several complaints from victims stating they had not received items they purchased and were led to fraudulent websites via ads on social media platforms or while searching for specific items on online shopping pages.

Prevention 

  • Do your research on the retailer for legitimacy – Check the website’s contact details on the “Contact Us” page, specifically the address, email, and phone number, to confirm the same.
  • Be wary of online retailers offering goods at significantly discounted/unrealistic prices.
  • Be wary of online retailers who use a free email service instead of a company email address.
  • Do not click on suspicious URLs on shopping sites; they could be malicious.

Wrap Up 

In tandem with shopping habits, cybercriminals have evolved. Adversaries leverage different techniques like social engineering to deceive and mislead online shoppers. It is our responsibility to be vigilant and practice proper cyber hygiene while shopping online.