Home Blog Page 40

Microsoft November 2021 Patch Tuesday Addresses 55 Vulnerabilities

Microsoft November 2021 Patch Tuesday, Windows 10, Microsoft PrintNightmare

Microsoft has released patches for over 55 security vulnerabilities in its latest November 2021 Patch Tuesday update. Six of these vulnerabilities are rated as critical and 49 as important in terms of severity. The update has addressed security flaws in Microsoft Windows and Windows Components, 3D Viewer, Azure, Azure RTOS, Azure Sphere, Microsoft Dynamics, Microsoft Edge (Chromium-based), Exchange Server, Microsoft Office and Office Components, Windows Hyper-V, Windows Defender, and Visual Studio.

Six Critical Bugs Fixed

The tech giant also released patches for two critical vulnerabilities – CVE-2021-42321 and CVE-2021-42292 – in Microsoft Exchange Server and Microsoft Excel that are actively exploited in the wild.

CVE-2021-42321 is a Microsoft Exchange Server Remote Code Execution flaw due to improper validation of cmdlet arguments, which can be exploited only by an authenticated hacker. Whereas CVE-2021-42292 is a Microsoft Excel Security Feature Bypass bug that allows an attacker to trick users into opening a specially crafted file with an infected version of Excel.

“We are aware of limited targeted attacks in the wild using one of the vulnerabilities (CVE-2021-42321), which is a post-authentication vulnerability in Exchange 2016 and 2019. Our recommendation is to install these updates immediately to protect your environment. These vulnerabilities affect on-premises Microsoft Exchange Server, including servers used by customers in Exchange Hybrid mode. Exchange Online customers are already protected and do not need to take any action,” Microsoft said in a statement.

Other critical vulnerabilities addressed in the update include:

  • CVE-2021-38631– Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
  • CVE-2021-41371– Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
  • CVE-2021-43208– 3D Viewer Remote Code Execution Vulnerability
  • CVE-2021-43209– 3D Viewer Remote Code Execution Vulnerability

Microsoft urged organizations and users to apply the patches to prevent potential exploits. “The monthly security release includes all security fixes for vulnerabilities that affect Windows 10, in addition to non-security updates. In addition to security changes for the vulnerabilities, updates include defense-in-depth updates to help improve security-related features,” Microsoft added.

CISA Recommends

The Cybersecurity and Infrastructure Security Agency (CISA) asked users and administrators to apply Microsoft’s November 2021 patches for better protection against rising cyberthreats. The agency recently issued a Binding Operational Directive (BOD) to reduce the risk of actively exploited vulnerabilities. The new Directive, which applies to all software and hardware found on federal information systems, requires federal civilian agencies to remediate such vulnerabilities within specific timeframes.

Robinhood Hack Exposes Shortcomings of the Human Firewall in Cybersecurity

Robinhood ransomware

Robinhood, a commission-free, U.S.-based trading app, joins the list of ransomware victims. On November 3, 2021, the trading platform experienced a phishing attack in which a customer support employee fell prey to the ransomware trap. As a result, data of millions of customers was exposed and stolen.

Robinhood is a popular trading app in the U.S. due to its friendly user interface and commission-free trading. It allows trading stocks, ETFs, options, or cryptocurrency on its platform. Per Statista, the app’s users grew from half a million in 2014 to 22.5 million in 2021. The app’s net revenue stands at $91 million as of Q2 2021.

Announcing the ransomware incident in a blog, Robinhood revealed, “An unauthorized third-party obtained access to a limited amount of personal information for a portion of our customers. Based on our investigation, the ransomware attack has been contained and we believe that no Social Security numbers, bank account numbers, or debit card numbers were exposed and that there has been no financial loss to any customers because of the incident.”

See also: What is the “Cyberchology of Human Error” in Cybersecurity?

A Robinhood customer support employee was socially engineered over a phone to get access to the customer support system. The blog added, “At this time, we understand that the unauthorized party obtained a list of email addresses for approximately five million people and full names for a different group of approximately two million people. We also believe that for a more limited number of people — approximately 310 in total — additional personal information, including name, date of birth, and zip code, was exposed, with a subset of approximately 10 customers having more extensive account details revealed. We are in the process of making appropriate disclosures to affected people.”

The company did not comply with the ransom demand and has employed Mandiant, a security firm, for investigating the breach.

Robinhood’s Chief Security Officer, Caleb Sima, said, “As a Safety-First company, we owe it to our customers to be transparent and act with integrity. Following a diligent review, putting the entire Robinhood community on notice of this ransomware incident now is the right thing to do.”

Target Pattern

Ransomware news is making headlines every week. Once again, the human factor comes to play whereby we see cybercriminals leveraging the “human bait” to fulfill their motives. Humans continue to be the weak link in the cybersecurity landscape and responsible for more than 80% of reported security incidents.

As per a survey by Black Hat, 91% of social engineering attacks are launched with a phishing email. It says, “A single human mistake can result in an attacker taking over all of the organization’s infrastructure, no matter what hardware, software, or endpoint security implementation has been done from the defensive team,” and this is exactly what resulted in the Robinhood hack.

CDSL Data Breach Exposes Sensitive Details of 44 Mn Indian Investors

Data Breach at CDSL

India’s popular securities depository services provider – the Central Depository Services Limited (CDSL) – is making headlines for an alleged data breach at its subsidiary CDSL Ventures Limited (CVL). According to a report from CyberX9, the data breach exposed the personal and financial information of over 4.39 crore (43.9 million) investors in India.

One Flaw – Two Data Breaches

CyberX9’s research team stated that it had identified a critical authorization vulnerability in a public CDSL’s KYC API exposing investors’ data online. The vulnerability was fixed after the research team reported the issue to the CDSL. However, after a few days, the CyberX9 team found a bypass for the patch that CDSL applied to the vulnerability, exposing the same sensitive data of 43.9 million investors again.

The issue was fixed after CyberX9 reported the flaw through the Government of India’s CERT-In and NCIIPC, which coordinate responsible disclosure of critical vulnerabilities in India.

Data Exposed

The data breach affected the investors who did their market securities KYC process in 2005. The exposed information included personal details like full name, PAN numbers, gender, marital status, father/spouse’s full name, birth dates, nationality, complete residential address, complete permanent address, contact numbers, email address, and occupation details. The incident also exposed sensitive financial information like the amount of annual income tax return filed, net worth (along with the date it was updated), Demat account number, broker name, and CDSL Client ID.

Potential Impact

The exposed information is highly sensitive and could lead to severe security and privacy issues if it falls into the wrong hands. Having access to CDSL KYC data, cybercriminals could have an endless supply of convincing scamming templates for calls and emails to use against investors and organizations.

Also Read: Suffered a Data Breach? Here’s the Immediate Action Plan

Online phishers and scammers could misuse the leaked information against individuals and organizations. Threat actors often leverage Business Email Compromise (BEC) scams impersonating stockbrokers, banks, and businesses to trick users into transferring funds. State-sponsored actors could also exploit this data to spread misinformation and manipulate Indian share market trends.

“This is extremely sensitive data which is usually the base information needed for many malicious attacks against individuals and organizations. There is an indefinite number of possible malicious use cases. Any malicious attacker who could’ve discovered it and stolen all the data. We strongly suspect that the data might’ve already been stolen by malicious attackers,” CyberX9 said.

Securing ‘Digital India’ With a Zero Trust Approach

User Verification Policy, zero trust approach

What are some of the biggest challenges facing countries across the globe today? Technology is transforming human societies and communities across the globe, in different ways, changing the way we live and conduct business. As its pervasiveness becomes a reality in all walks of life, right from health care to education, so do the challenges it brings with itself. Over the last year or so, cybersecurity has emerged as one of the topmost concerns as enterprises and individuals opened closely guarded networks to enable remote working, hybrid workspaces, and multi-cloud environments. With every passing day, there’s a multifold surge in cases of cybercrime, including phishing, hacking, and ransomware attacks, putting sensitive information and data of citizens at risk. The cyberwar threat is real. It’s time for India’s government and public sector to embrace a Zero Trust approach to security.

By Anil Valluri, Regional VP and MD for India and SAARC, Palo Alto Networks

India is no exception. In recent years, India has taken rapid strides to leverage technology to build the country as a global economic powerhouse. Under ‘Digital India’, the country has committed to a massive investment of 1.13 lakh crore towards building a public digital infrastructure that will drive India towards a paperless and cashless economy. However, if the past few months are anything to go by, India has a long and challenging road ahead. Just earlier this year, multiple government websites reported a large-scale data breach, and citizens’ COVID-19 lab test reports were leaked. It was later reported that the criminals were found selling the sensitive data on the dark web for a few hundred rupees, potentially compromising the sensitive health records of over a million registered citizens. This incident has only reinforced our understanding that if India were to become an economic powerhouse, it is crucial to not only invest in building a strong network of IT and technology systems but also secure all the information that flows through it.

See also: Creator of Zero-Trust Model Says Trust Did Not Exist in a Digital World

By various estimates, India continues to be among the top countries globally, hit by ransomware and cyberattacks every year, giving rise to massive reputational, financial, operational, legal, and compliance implications. A report by the Belfer Center of Harvard Kennedy School, U.S., on ‘National Cyber Power Index 2020’ that analyzed about 30 countries to examine their cyber power, reiterated this. According to the report, India lags behind at number 21, when it comes to adopting cyber strategies or lack of existing capabilities, therefore achieving policy goals. It is revealing for a country that’s placed much emphasis on growing its technology footprint to not yet have the preparedness required to thwart the ever-increasing cyberattacks. The Indian public sector, thus, needs to relook at its cybersecurity strategy to ensure safe, secure, resilient, vibrant, and trusted cyberspace and deliver on its promises of ‘maximum governance and minimum government.’ 

The good news is this is precisely what the Zero Trust approach is built for. Zero Trust isn’t a brand new concept. However, as new technologies emerge and mature, the approach seems to be drawing attention and acceptance, for all the right reasons.  The power of Zero Trust was first recognized in 2009, by John Kindervag, when he was still an analyst at Forrester Research. Kindervag explained it as “the critical cybersecurity strategy for protecting critical data, applications, systems, and services.” Based on the principle of ‘never trust, always verify’, it assumes that trust could translate into vulnerability at any time and as such no single user, network or device can be trusted. In short, f Zero Trust involves enforcing the least privilege everywhere and never trusting, always verifying when it comes to identity, even if previously verified.

To be sure, the government and public sector agencies, in contrast to commercial enterprises and organizations, need to deal with multiple classifications of their data and information, which naturally creates a level of categorization. This increases complexities in processes and systems due to separated network deployments, strict compliance with regulatory requirements, and increased operational burdens. Moreover, with so many workers operating remotely during the pandemic, there’s heavier dependence on digital technologies, for everything right from learning, business, and even our medical response. Employees no longer have ready access to their IT departments, and share common networks and devices with their families, while no longer enjoying benefits from their usual protections. This, in turn, has left people and systems more vulnerable.

We can no longer guarantee that a threat can’t sneak in or that there is no bad actor existing within our systems and infrastructure. As multiple incidents suggest, bad actors, both foreign and domestic, are now finding alternative ways to pass through perimeter defense- perhaps through a bug that was not fixed, a hastily developed app or a system that was misconfigured. As such, threats have escalated in number and potential damage, where adversaries can enter networks and steal secrets, data while roaming undetected. In addition to this, intruders see big opportunities from even the slightest error and are well-equipped, well-funded with much more sophisticated tools and knowledge to get the job done.  From this perspective, a zero-trust technology system offers exactly what the governments and public sector in India needs. It is a strategic approach that entails multiple solutions working together to provide the best defense.

How Can Governments Implement It?

Government agencies can’t simply flip a switch to turn on a zero-trust environment; it requires a major commitment and in-progress administration. Access and privileges are constantly changing and need constant observing. As India embraces cloud technology, digitalizes governance, and citizen services, a corresponding enhancement of government-industry cyber defense is needed.

Embracing a Zero Trust approach therefore will require verifying every attempted access through location awareness, proper device controls, user authentication controls by considering every access as a threat until verified otherwise. To move to zero trust, first and foremost, agencies should evaluate their preparedness with the current security architecture and understand where the challenges may emerge. Instead of replacing legacy systems overnight, agencies should look at opportunities for integrating them with newer solutions, thus saving precious monies. Given the rise of hybrid working models, agencies should review their most sensitive data and workflows to determine access entitlements and policies for employees working both in-offices and remotely. Additionally, policies must be often reviewed and altered to cut off non-essential access immediately.

But this sounds easier than done. A sudden attempt to modernize legacy systems and implement a Zero Trust architecture might put people and processes at risk, bringing overall productivity and effectiveness down. Government agencies, therefore, must consider investing in a robust integrated cybersecurity platform across clouds, networks, and devices that rely on Artificial Intelligence (AI) and Machine Learning (ML) and constantly evolve to keep sophisticated threats at bay. Eventually, the model can scale up and down, as organizational needs evolve. Instead of a piecemeal approach, that may still contain tiny gaps and could expose vulnerabilities, government agencies must adopt a platform-centric approach, reducing the need to integrate solutions from different security vendors. This will enable increased visibility access controls and put more balances and checks at each level.

Humanizing Security

The Zero Trust architecture does away with the notion that bad threat actors attack the target directly. Instead, it is firmly rooted in the belief that they are more likely to attack a weaker link and then roam laterally across the network. This link is often humans within the system who are prone to making mistakes, can have a lapse in judgement and misplaced trust.

Using the Zero Trust model, government agencies can tackle this and fill in the inherent cybersecurity skills gap within the organization. Government employers can put multimodal teams in place that are technically equipped and can undertake infrastructure modernization based on sound strategy and regular policy inputs. Agencies can also undertake employee awareness campaigns that can help guide, sensitize employees, partners, and other stakeholders, on the effects of cyberthreats and their role in it. While reliance on home networks and remote work practices may be unavoidable for the foreseeable future, agencies can also alert employees by keeping them abreast of internal cyber incident response protocols to adapt as and when threats arise.

It is crucial to note that Zero Trust is no magic wand. It’s a journey that involves many milestones and each deployment will expand as new needs emerge and processes are assessed. If governments and agencies enter Zero Trust with the right resources and expectations in place, it will go a long way to protecting the government’s most sensitive assets from assault, spying, hacking, and exploitation.

Earlier this year, when U.S. President Joe Biden passed an executive order to implement a strong cybersecurity framework, it validated and reaffirmed the relevance of ‘Zero Trust’ in a post-COVID-19 world. Government leaders and public officials in India must closely monitor the developments with the White House executive order, which could serve as a model for how to incorporate Zero Trust into government operations at all levels.

All said and done, most of the country’s critical infrastructure is linked to information highways and is interdependent. Cyber threats are now a national security threat and securing it is more important now than ever. Protecting it is vital to India’s national security and global positioning as it is intrinsically connected to people’s economic and social wellbeing.


About the Author

Anil ValluriAnil Valluri is the regional vice president for the India and SAARC region at Palo Alto Networks. In this role, Valluri focuses on driving profitable growth and accelerating the technology footprint across customer segments, creating strategic go-to-market alliances, and scaling the partner ecosystems, while building talent within the organization’s ranks in the region.

Anil is an alumnus of Stanford University Graduate School of Business and is an avid single-digit golfer, analog audiophile, and DIYer.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

How to Uproot Rootkit Threats

Rootkits

Threat actors leverage Trojans, malware, and ransomware to break into victims’ systems and cause maximum damage. We explain a different kind of malware threat that impacts users’ data privacy and security – Rootkits. Cybercriminals often utilize rootkits to spy or steal critical information from the targeted network systems.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

What is a Rootkit?

Rootkits are malicious software or software tools designed to run in stealth mode on a targeted computer or device. A rootkit allows a remote attacker to obtain and maintain privileged access to the operating system on the infected machine. Threat actors could monitor and steal sensitive information leveraging rootkits.

The word rootkit is derived from two words – root and kit. The term root represents privileged administrator-level access in a UNIX system. And the word kit indicates a set of software applications that form the tool.

Rootkit Capabilities

Once installed on a targeted system, rootkits can:

  • Run without any limitations on the victim’s device
  • Evade security detections
  • Harvest sensitive data such as credentials and other remote access privileges
  • Hide its presence from anti-virus software and security admins

Types of Rootkits

  1. Application or User Mode Rootkits – These types of rootkits are designed to infect applications and standard files in a targeted computer. However, the infected programs and applications usually run, making it difficult to find the rootkit.
  2. Hardware/Firmware Rootkits – These infect hardware or firmware like hard drives, routers, network cards, and computer’s basic input operating software (BIOS).
  3. Bootloader Rootkits – A bootloader, also known as a boot manager and bootstrap loader, is a computer program responsible for booting a system. The bootloader rootkit infects as soon as a computer turns on by replacing the original bootloader.
  4. Memory Rootkits – These hide and infect the computer’s random-access memory (RAM).
  5. Kernel Mode Rootkits – These affect the operating system by deploying malware. Once infected, Kernel Mode rootkits allow an attacker unrestricted access and can alter data structures.

How Cybercriminals Install Rootkits 

Threat actors typically inject rootkits on targeted computers via phishing or social-engineering attacks. This happens when an unsuspected user downloads the rootkit received via a malicious URL or link. Attackers could also exploit an unpatched vulnerability in software or an operating system. Rootkits can also be distributed via weaponized PDFs, malicious apps, and other media.

Detection and Prevention

It’s a challenge for security admins and software to detect rootkits as they disguise themselves on the system. While there are no standard measures to discover rootkits, certain security actions can help protect endpoints from rootkit infections. These include:

  • Download computer programs and drivers only from authenticated sources
  • Always validate before downloading any email attachment received from unknown sources
  • Update the operating system, browser, and system software regularly
  • Regularly scan for security flaws and patch known vulnerabilities
  • Configure your systems according to prescribed guidelines
  • Deploy security firewalls to check for any suspicious activities on the system

About the Author

Rudra Srinivas

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.

More from Rudra

 

Chinese Cyber Espionage Campaign Found Exploiting Zoho Vulnerability

Zoho Vulnerability , Atlassian Confluence Vulnerability

Critical infrastructure and technology vendors become a frequent target for state-sponsored adversaries. A security research team from Palo Alto Networks’ Unit 42 uncovered an ongoing cyberespionage campaign that has already targeted nine organizations belonging to critical global sectors, including education, defense, health care, energy, and technology. With contributions from the National Security Agency (NSA), the research report revealed that the campaign is focused on stealing critical information from U.S. defense contractors.

Exploiting a Vulnerability in Zoho

The researchers found that cybercriminals penetrated international critical network systems by exploiting a recently addressed vulnerability CVE-2021-40539 in Zoho’s ManageEngine product ADSelfService Plus, an identity, and access management tool. The flaw allowed the attackers to REST API authentication bypass with resultant remote code execution. After exploiting the flaw, the threat actors deployed two malware backdoors – Godzilla webshell and NGLite payload on the targeted systems. The Godzilla webshell can parse inbound HTTP POST requests and decrypt sensitive data.

After obtaining complete access to the domain controllers, the attackers deployed KdcSponge – a novel credential-stealing tool deployed against domain controllers to steal credentials. The researchers said, “KdcSponge injects itself into the Local Security Authority Subsystem Service (LSASS) process and will hook specific functions to gather usernames and passwords from accounts attempting to authenticate to the domain via Kerberos. The malicious code writes stolen credentials to a file but is reliant on other capabilities for exfiltration.”

Researchers also claimed that both Godzilla and NGLite were developed with Chinese instructions and are publicly available for download on GitHub.

The Impact

Over 370 U.S. organizations were included in broad scanning to identify vulnerable Zoho servers. The campaign shows connections between malicious servers and U.S. organizations, including Department of Defense agencies, defense contractors, educational institutions, and health care organizations. According to Palo Alto’s Cortex Xpanse platform scans, more than 11,000 internet-exposed systems around the globe are running the affected Zoho software. The scans did not indicate what percent of those systems have already been patched.

The Director of cybersecurity for the U.S. National Security Agency Rob Joyce asked users and organizations to review the Unit 42 findings for indicators of compromise of the ongoing malware campaign.

Early Warning

Reports suggest that the campaign began on September 17, a day after CISA warned about the active exploitation of Zoho vulnerabilities, including CVE-2021-40539. The agency stated the exploitation of ManageEngine ADSelfService Plus poses a severe risk to critical infrastructure companies, U.S.-cleared defense contractors, academic institutions, and other entities that use the software.

The agency recently issued a Binding Operational Directive (BOD) to reduce the risk of actively exploited vulnerabilities. The new Directive, which applies to all software and hardware found on federal information systems, requires federal civilian agencies to remediate such vulnerabilities within specific timeframes.

Involvement of Chinese Actors

While the threat actors behind the campaign are still unknown, Unit 42 researchers believe the techniques used in the campaign are similar to those of the Chinese threat group Emissary Panda, also known as TG-3390 and APT27.

“We can see that TG-3390 similarly used web exploitation and another popular Chinese webshell called ChinaChopper for their initial footholds before leveraging legitimate stolen credentials for lateral movement and attacks on a domain controller. While the webshells and exploits differ, once the actors achieved access into the environment, we noted an overlap in some of their exfiltration tooling,” the researchers added.

ManageEngine Responds

Responding to an email from CISO MAG, ManageEngine’s spokesperson said, “We have addressed an authentication bypass vulnerability in ManageEngine’s ADSelfService Plus. The vulnerability affects REST API URLS and could result in Remote Code Execution. We released a patch and notified all our customers about the bug. They are requested to update the software to the latest version (build 6114) as soon as possible. A public advisory, detailing the steps to be taken by customers if they are affected, has been issued. Please refer to this link. We are also taking steps to apply the lessons from this incident and to introduce additional security control measures wherever required.”

Expert Opinion

Sean DucaExplaining on how organizations can reduce the significant risk of known exploited vulnerabilities to CISO MAG, Sean Duca, Vice President and Regional Chief Security Officer – Asia Pacific & Japan, Palo Alto Networks, said, “Thanks to the pandemic, businesses worldwide have been forced to accelerate their digital transformation journey. As a result, we have seen a rise in both the frequency and sophistication of cyber threats. Therefore, organizations must evaluate and update their vulnerability management approaches and security architectures regularly to combat an ever-evolving adversary. In addition, there is an increased need to look at how we can secure applications, users, and devices across the cloud. As incidents are inevitable, how organizations react to a breach is of equal importance – prompt remediation can aid in the protection of IT infrastructure while significantly reducing costs that could be financial, reputational, or both. Furthermore, organizations should put security measures in place to combat any known threats and ensure preventive controls are in place to identify, evaluate and mitigate any unknown threats.

Duca added, “The same can apply to the maintenance of the critical infrastructures of a country that are more likely to rely on outdated legacy setups, as evidenced by this espionage campaign. Public and private collaborations can go a long way in enabling the development of strong cybersecurity policies, processes, and risk management frameworks to secure critical infrastructure and respond to threats in real-time.”

Conclusion

Organizations of all sizes need to respond promptly to critical vulnerability disclosures and adopt necessary security precautions to prevent potential exploits. This is crucial for companies in critical sectors that are constantly being targeted by ransomware operators probing for vulnerabilities.

Vulnerabilities need to be disclosed to vendor organizations in a timely manner so that corrective action can be taken in a prompt manner. Vulnerability Disclosure programs offer guidelines on how to submit security vulnerabilities to organizations. They help organizations mitigate the risk by supporting and enabling the disclosure and remediation of vulnerabilities before they are exploited (Source: Bugcrowd).

What Does Good IT Security Look Like?

Hackers Using Steganography to Target Industrial Enterprises, IT security

Cyber intrusion activity globally jumped 125% in the first half of 2021 compared to the previous year, according to Accenture, with ransomware and extortion operations one of the major contributors behind this increase. According to the FBI, there was a 62% increase in ransomware incidents in the U.S. in the same period that followed an increase of 20% for the full year 2020.

By Thomas Kang, North American Head of Cyber, Tech & Media at Allianz Global Corporate & Specialty

In a new risk report, cyber insurer Allianz Global Corporate & Specialty (AGCS) analyzed the latest risk developments around ransomware and found that business interruption and restoration costs are the biggest drivers behind cyber losses such as ransomware attacks, according to its claims analysis. They account for over 50% of the value of close to 3,000 insurance industry cyber claims worth around €750 million ($885 million) it has been involved in since 2016.

In 2020, AGCS was involved in over a thousand cyber claims, up from around 80 in 2016; the number of ransomware claims (90) rose by 50% compared to 2019 (60). In general, losses resulting from external cyber incidents such as ransomware or Distributed Denial of Service (DDoS) attacks account for most of the value of all cyber claims analyzed by AGCS over the past six years.

The average total cost of recovery and downtime – on average 23 days – from a ransomware attack more than doubled over the past year, increasing from $761,106 to $1.85 million in 2021.

The surge in ransomware attacks in recent years has triggered a major shift in the cyber insurance market. Cyber insurance rates have been rising, according to broker Marsh, while capacity has tightened. Underwriters are placing increasing scrutiny on the cybersecurity controls employed by companies. AGCS estimates that three out of four companies do not meet its requirements for cybersecurity.

Taking steps to harden cybersecurity can help companies defend against the majority of ransomware attacks, but what does good IT security look like? AGCS developed a checklist for companies to review to shore up their IT defenses against a ransomware incident:

Ransomware identification:

  • Are anti‑ransomware toolsets deployed throughout the organization?
  • What proactive measures are in place for the identification of ransomware threats?
  • Are policies, procedures, access controls methods, and communication channels updated frequently to address ransomware threats?
  • Are in-house capabilities or external arrangements in place to identify ransomware strains?

Business continuity planning/incident response plan:

  • Are ransomware-specific incident response processes in place?
  • Have there been any previous ransomware incidents? If so, what lessons have been learned?
  • Are pre‑agreed IT forensic firm or anti‑ransomware service provider arrangements in place?

Anti-phishing exercises and user awareness training:

  • Is regular user training and awareness conducted on information security, phishing, phone scams, and impersonation calls, and social engineering attacks?
  • Are social engineering or phishing simulation exercises conducted on an ongoing basis?

Backups:

  • Are regular backups performed, including frequent backups for critical systems to minimize the impact of the disruption? Are offline backups maintained as well?
  • Are backups encrypted? Are backups replicated and stored at multiple offsite locations?
  • Are processes in place for successful restoration and recovery of key assets within the Recovery Time Objective (RTO)?
  • Are backups periodically retrieved compared to the original data to ensure backup integrity?

Endpoints:

  • Are endpoint protection (EPP) products and endpoint detection and response (EDR) solutions utilized across the organization on mobile devices, tablets, laptops, desktops, etc.?
  • Are Local Administrator Password Solutions (LAPS) implemented on endpoints?

Email, web, office documents security:

  • Is Sender Policy Framework strictly enforced?
  • Are email gateways configured to look for potentially malicious links and programs?
  • Is web content filtering enforced with restricting access to social media platforms?

Segmentation:

  • Are physical, logical segregations maintained within the network, including the cloud environment?
  • Are micro-segmentation and zero-trust frameworks in place to reduce the overall attack surface

Monitoring patching and vulnerability management policies:

  • Are automated scans run to detect vulnerabilities? Are third-party penetration tests performed on a regular basis?
  • Does the organization ensure appropriate access policies, enforcement of multi‑factor authentication for critical data access, remote network connections, and privileged user access?
  • Is continuous monitoring in place for detecting unusual account behavior, new domain accounts, and any account privilege escalations (administrator level), new service additions, and unusual chain of commands being run during a short time period?

Mergers and acquisitions:

  • What due diligence and risk management activities are performed prior to M&A?
  • Are regular security audits conducted on newly‑integrated entities to ensure evaluation of security controls?

About the Author

Thomas Kang

As the Head of Cyber, Technology and Media for North America at Allianz Global Corporate & Specialty (AGCS), Thomas is responsible for developing and executing a strategic vision for the line of business across all market segments in the U.S and in Canada.

Prior to joining AGCS, he served as the Global Cyber Product Leader at Willis Towers Watson, creating a client-centered, strategic product and services alignment across geographies.  Over the past 15 years, he has held various executive positions in cyber and E&O insurance across underwriting, product, claims, and legal with a focus on delivering innovative cyber insurance and service solutions to clients across all segments and geographies.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Scammers Force Victims to Use Crypto ATMs and QR Codes: FBI

Crypto ATMs and QR Codes

Besides leveraging various intrusion techniques, cybercriminals use different tactics to receive payments from victims and evade detection. Cryptocurrency criminals are forcing victims to use crypto ATMs and QR codes to complete their payments, the FBI warned in its latest Public Service Announcement (PSA).

The FBI has seen a rise in fraudsters maliciously using cryptocurrency ATMs and QR codes to receive payments from victims in various online scams, including impersonation schemes, romance schemes, and lottery schemes. In these scams, the attacker impersonates a legitimate entity from the government, law enforcement, a legal office, or a company and asks users to transfer the money via physical crypto ATMs and QR codes. The scammer then directs the victim to a physical cryptocurrency ATM to insert their money, purchase cryptocurrency, and use the provided QR code to auto-populate the recipient address.

In some cases, the fraudsters provide a malicious QR code linked to the attacker’s crypto wallet to the victim to use during the transaction. The scammers often maintain the communication online with the victim to provide step-by-step instructions until the payment is completed.

What is a QR Code?

A QR code is a barcode that allows a user to access information instantly by a digital device. QR codes store data as a series of pixels in a square-shaped grid and are primarily used to track details of a particular product in a supply chain.

What is a Crypto ATM?

A cryptocurrency ATM is a connected kiosk that allows users to purchase cryptocurrencies with deposited cash. The crypto ATMs rely on blockchain-based transactions that send cryptocurrencies to the user’s crypto wallets via QR codes.

Why Criminals Use Crypto ATMs and QR Codes

Receiving money illicitly via crypto wallets, transfers, and QR codes helps cybercriminals skip the security scans. Unlike bank transfers, the money sent via QR codes and crypto wallets immediately gets credited to the recipient’s account.

“Cryptocurrency’s decentralized nature creates challenges that make it difficult to recover. Once a victim makes the payment, the recipient instantly owns the cryptocurrency and often immediately transfers the funds into an account overseas. This differs from traditional bank transfers or wires, where a payment transaction can remain pending for one to two days before settlement. It can also make law enforcement’s recovery of the funds difficult and can leave many victims with a financial loss,” the PSA said.

What the FBI Suggests

While several users and businesses have legitimately used QR code payments, threat actors distributed malicious QR codes for cryptocurrency payments. The malware embedded in the QR code could automatically initiate fraudulent payments from the victim’s device by connecting to a malicious network. The FBI suggested specific security tips to prevent such payment threats, including:

  • Do not send payment to someone you have only spoken to online, even if you believe you have established a relationship with the individual.
  • Do not follow instructions from someone you have never met to scan a QR code and send payment via a physical cryptocurrency ATM.
  • Do not respond to a caller who claims to be a representative of a company, where you are an account holder, and who requests personal information or demands cryptocurrency. Contact the number listed on your card or the entity directly for verification.
  • Do not respond to a caller from an unknown telephone number who identifies as someone you know and requests cryptocurrency.
  • Practice caution when an entity states they can only accept cryptocurrency and identifies as the government, law enforcement, a legal office, or a utility company. These entities will likely not instruct you to wire funds, send checks, send money overseas, or make deposits into unknown individuals’ accounts.
  • Avoid cryptocurrency ATMs advertising anonymity and only require a phone number or e-mail. These cryptocurrency ATMs may be non-compliant with US federal regulations and may facilitate money laundering. Instructions to use cryptocurrency ATMs with these specific characteristics are a significant indicator of fraud.
  • Suppose you are using a cryptocurrency ATM and the ATM operator calls you to explain that your transactions are consistent with fraud and advises you to stop sending money. In that case, you should stop or cancel the transaction.

How U.S. Defense Contractor Electronic Warfare Associates Fell Prey to Phishing

Russian hackers, Senate Homeland Security Report, Electronic Warfare Associates

A U.S. government defense contractor, Electronic Warfare Associates (EWA), was a victim of a data breach due to an email phishing incident. Per a disclosure notification dated November 4, 2021, the defense contractor EWA was a victim of a phishing email on August 2, 2021. The incident was discovered when the hacker initiated a wire fraud, and the theft was detected. The defense contractor believes it was not an attack to purloin personal information but a direct financial theft attempt. But as discovered, the attack exposed certain personal information and files, including Social Security Number and driver’s license.

In a letter to its clients, EWA detailed the incident, what followed as investigation (third party forensics), the impact of the breach, and the steps taken as incident response. In response to the incident, EWA has offered a free fraud detection and identity theft protection through Equifax’s Complete Premier services at no charge for two years.

EWA’s customer list includes the Department of Defense (DOD) – Office of the Secretary of Defense (OSD), Defense Advanced Research Projects Agency (DARPA), Department of the Navy (USN), Department of the Army (USA), Department of the Air Force (USAF), Unified Military Commands, Department of Homeland Security (DHS), and Department of Justice (DOJ).

Some of its services include Computer Forensic Analysis, Data Recovery, Electronic Warfare (EW) Analysis and Support, EW and RF Engineering and Systems Services among others.

A data breach of any kind does expose critical sensitive data of national importance. The company deals in highly sensitive military category systems, and any breach could have grave ramifications on national security.

Third-Party Attacks

Firms are increasingly outsourcing core and non-core systems, business processes, and data processing to third-party service providers. With the widespread adoption of software-as-a-service (SaaS) technologies, even among industries like financial services that traditionally wanted control and autonomy, build vs. buy is less of a debate than it was just five years ago. When we think of third-party relationships, we think of the direct supply chain of vendors, suppliers, and cloud providers.

In an exclusive article for CISO MAG, Alla Valente, Senior Alla ValenteResearch Analyst, Forrester, opined, “What adds to the complexity of the third-party ecosystem is that although companies have limited or no control over how third parties secure their technology infrastructure, their applications, or their data, they’re fully responsible for security, privacy, or regulatory missteps that occur during the relationship. As a result, companies are on the hook financially for fines, penalties, or revenue loss and risk their reputation when events lead to negative publicity, business disruption, or impact the customer experience. According to Ponemon Institute, third-party breaches account for over half of all data breaches in the U.S.”

It’s not surprising that breaches caused by third parties are among the most highly publicized. Some of the most notorious data breaches in recent times have occurred because of the organizations’ vendors. Unfortunately, cyberattacks caused by third parties are also among the costliest. A January 2020 Ponemon Institute report indicates that 53% of organizations have experienced at least one data breach caused by a third party in the last two years. And that, on average, the data breach costs $7.5 million to remediate.

 

U.S. State Department Announces $10 Mn Bounty for Info on DarkSide Ransomware Group

bounty for DarkSide Ransomware Group, Microsoft Offers $100,000 Bounty

The U.S. government is determined to eliminate the growing cyberattacks and cybercrime affiliates in the country. The U.S. Department of State recently announced a $10 million bounty for information on the activities or location of the DarkSide ransomware group or any of its associates. The Department also declared a reward of $5 million for tipoffs or clues leading to the arrest of any participants in a DarkSide group’s activities.

The proposed reward is provided under the Department of State’s Transnational Organized Crime Rewards Program (TOCRP), which aims to dismantle transnational organized criminal groups. More than 75 transnational criminals and major narcotics traffickers have been brought to justice under the TOCRP and the Narcotics Rewards Program (NRP) since 1986. The Department has paid more than $135 million in rewards to date.

“In offering this reward, the United States demonstrates its commitment to protecting ransomware victims around the world from exploitation by cybercriminals. The U.S. looks to nations who harbor ransomware criminals that are willing to bring justice for those victim businesses and organizations affected by ransomware,” the Department said.

Why DarkSide Ransomware Group?

The DarkSide ransomware operators are responsible for the infamous cyberattack on Colonial Pipeline in May 2021, which disrupted the company’s pipeline operations that carry over 45% of the fuel to the East Coast of the U.S.

The DarkSide attackers have extended their reach globally by targeting companies in various sectors. The group is suspected to be involved in the recent ransomware attack on the Japanese tech giant Toshiba. Experts found that the malware variants used in this attack are similar to those used in the Colonial pipeline hack. The DarkSide group reportedly infected nearly 99 organizations with the DarkSide malware, with an average ransom payment of $1.9 million. The group extracted over $90 million in ransom in Bitcoin from 47 victims.

Exit > Rebrand > Re-enter 

The latest announcement from the State Department also applies to DarkSide rebrands, including the most recent BlackMatter group. Once identified, cybercriminal groups often cease their operations and return with different names and ransomware variants. After the attack on Colonial, the DarkSide group encountered severe scrutiny from international law enforcement authorities. However, reports suggest that DarkSide group continued its operations by rebranding itself as BlackMatter.

The BlackMatter group also recently announced that it is shutting down operations, citing pressures from law enforcement authorities. Active since July 2021, BlackMatter offered ransomware-as-a-service (RaaS), targeting several critical infrastructures in the U.S., and demanded ransom payments ranging from $80,000 to $15,000,000 in Bitcoin and Monero. While BlackMatter operators have not revealed much about their shutdown, the cybersecurity community opined that the recent cybersecurity initiatives from the Biden Administration may have forced the group to shut shop.