Home Blog Page 50

91.5% of Undetected Malware Landed Over Encrypted Connections

BotenaGo, malware over encrypted connections

IT administrators are having sleepless nights as threat perimeters are perpetually trending north and vectors getting guileful and evading detection. In its Q2 2021 Internet Security Report, WatchGuard Technologies detailed the trend observed around network security and malware getting shiftier in evading detection. The report revealed that 91.5% of malware arrived over HTTPS encrypted connections.

The report shares insights on the staggering rise across fileless malware threats, growth in ransomware, and the significant surge in network attacks. As per the report in Q2, total perimeter malware detection decreased to 16.6 million at 4%, despite a small 1% increase in the Fireboxes reporting in threat intelligence data.

Key Findings

  • Malware variants XML.JSLoader and AMSI.Disable.A, constituted over 90% of malware detections over secure web connections and 12% of Gateway AntiVirus detections. This malware family uses PowerShell tools to exploit vulnerabilities in Windows.
  • There was a 9-point dip in Zero-day malware from an all-time high in the last quarter. In spite of the dip, it continued to represent 64.1% of the detected malware attack.
  • 2 million network exploits were detected by Fireboxes Intrusion Prevention Service (IPS) in Q2, a 22.3% increase over past quarters.
  • Geographically, North and South America (AMER) were most attacked, averaging 1,744 IPS hits per Firebox. Europe, the Middle East and Africa (EMEA) followed with 764 hits per device, and the Asia Pacific (APAC) recorded 316 hits per device.

Protective Action  

The report recommends a few strategies for a protective approach and curtail the attacks in the next quarter.

  • Deploy an Endpoint Detection & Response (EDR) Safety Net
  • Shore Up the Holes in Your Remote Access
  • Create, Update, or Test your BC/DR Plan

As more reports emerge about innovative techniques being deployed by threat actors to go undetected and to evade malware analysis, this has been causing visible unrest among IT heads and administrators. A well-defined approach is needed to tackle the menace at hand, as there is a long winding path before there is some sense of normalcy and security in work patterns at organizations.

How to Be CyberSmart This Cybersecurity Awareness Month

CyberSmart

The cybersecurity landscape continues to evolve, with threat actors leveraging new hacking techniques to penetrate and exploit critical infrastructure. While organizations are worried about misconfigurations and poor security practices, human errors remain a major cause of cyberattacks and data breaches.

By Rudra Srinivas, Feature Writer, CISO MAG

The Cost of Human Error   

According to a study “Psychology of Human Error” by Stanford University Professor Jeff Hancock and security firm Tessian, 88% of data breaches are caused by employees’ mistakes. The study highlighted that nearly 43% said they’re sure they have made a mistake at work that had security repercussions for themselves or their company. Several organizations claim that human error was the primary factor with a year-over-year increase in several security incidents. Almost 93% are concerned about human error causing accidental exposure of their cloud data.

Cybersecurity awareness among employees is important as negligent actions could lead to severe security repercussions.

Four Ways to be CyberSmart

1. Think Twice

Whether it’s an attachment or link, don’t rush to open/download it as it could be malicious. Threat actors often distribute malware via email attachments or URLs. Once clicked or downloaded, these URLs/attachments automatically download the malware on the victim’s device or redirect the victim to a hacker-operated website that steals users’ login credentials.

2. Protect Your Passwords

Having strong passwords is not sufficient. Users must protect their passwords online with robust password protections like multi-factor authentication (MFA). Never allow websites and applications to remember your passwords, as Magecart hackers often compromise websites to pilfer users’ payments and other sensitive details. Use only reputed password management services.

3. Verify the Requester

Always be cautious when someone asks for your personal details like login credentials. Cybercriminals use various phishing and social engineering lures to make victims perform activities impersonating to be someone you know. Always verify the identity of the requester asking for your personal details, even if it is somebody you know.

4. Know When to Delete

Delete your sensitive data from your devices and online accounts when it’s no longer required. Regularly backup your critical files and store them separately in the cloud or encrypted USBs.

Here’s what experts have to say Acknowledging the importance of the Cybersecurity Awareness Month, Robert Prigge, CEO of Jumio, said, “The amount of large-scale cybersecurity breaches we’ve witnessed in the last year highlights just how creative cybercriminals will get to steal sensitive data and sell it on the dark web. The number of reported identity theft cases more than doubled from 2019 to 2020, while the number of reported data breaches escalated 38% from the first to the second half of 2021. With traditional online verification tools such as knowledge-based authentication and passwords, organizations will continue to place consumers’ personal information at risk of being compromised.”

“Cybersecurity Awareness Month encourages security leaders and executive decision-makers to modernize their security practices to adapt to the increased sophistication of fraudsters. In today’s cybersecurity climate, organizations must move away from outdated, obsolete authentication methods and implement more advanced identity verification solutions, like face-based biometric authentication, that confirm online users are truly who they claim to be. This month is also essential for educating consumers on safeguarding their digital identity and managing personal data consent rights online. These best practices are crucial to keep data away from the hands of malicious actors.”

Concurring with Prigge, Anurag Kahol, CTO and Cofounder of Bitglass, added, “From cloud misconfigurations exposing massive amounts of sensitive data online to ransomware attacks severely impacting critical infrastructure, this past year has underlined the inherent lack of proactive security across organizations of all sizes. As we move toward a new era of hybrid operations post-pandemic, the sophistication and frequency of cyberattacks will only continue to increase at an exponentially higher rate. Organizations must be prepared to face the evolving threat landscape to protect their employees, corporate infrastructure, and sensitive data.”

“International Cybersecurity Awareness Month serves as a reminder for enterprises to make security a strategic imperative. A vigilant security posture starts with implementing a unified cloud security platform, like secure access service edge (SASE) and security service edge (SSE), that replaces various disjointed point products and extends consistent security to all sanctioned cloud resources while following a Zero Trust framework to prevent unauthorized network access. Additionally, enforcing comprehensive cybersecurity training for all employees, hiring security experts and continuously monitoring and enhancing cybersecurity postures will ensure organizations are adequately equipped to defend their modern operations.”

Cybercriminals constantly adopt newer techniques to target internet users. Hence, becoming CyberSmart is requisite to defending against rising threats.

 

About the Author:

Rudra Srinivas

 

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

More from Rudra.

Episode #14: Ransomware Attacks and the Impact on Cyber Insurance

Ransomware and cyber insurance

The number of ransomware attacks has increased drastically. According to a report from security firm Barracuda, ransomware attacks grew 64% year-on-year between August 2020 and July 2021. The report says these attacks were carried out by a “handful of high-profile gangs,” such as Revil, Darkside and others. Ransomware attacks are making a big impact on cyber insurance.

The frequency of ransomware attacks has increased dramatically over the past year, with 93% more carried out in the first half of 2021 compared to the same period last year, according to Check Points mid-year security report.

And attackers are getting innovative too with ransomware as a service and triple-extortion ransomware techniques.

With increased ransomware attacks Insurance premiums are blowing through the roof, and clearly, it’s time to do something about it.

Dave Cole, CEO, Open Raven (Twitter: @mediafishy) and Brian Pereira, Editor-in-Chief, CISO MAG discuss ransomware payments and the impact on business and cyber insurance.

As Chief Product Officer of CrowdStrike, Dave took a nascent product line with a handful of small customers in 2013 and established it as a disruptive force in the industry that currently dominates endpoint security. He was also Chief Product Officer of Tenable where he steered the team through an aggressive growth phase, culminating in a successful initial public offering in the Summer of 2018.

In early 2019, Dave and Jack Daniel (B-Sides conference founder) started the Security Voices podcast as a sponsorless show focused on highlighting the diverse people and perspectives in cybersecurity. The podcast has released over 40 episodes and continues to publish new content monthly.

Dave is a frequent spokesperson, making appearances on NBC, CNN and elsewhere while speaking at industry events such as RSA, Black Hat and B-Sides Las Vegas. He has been a contributing author to a number of information security publications and books, including Crimeware: Understanding New Attacks and Defenses. Dave has authored a number of U.S. patents during his time at Foundstone and Symantec.

White House to Host Global Cybersecurity Meeting with 30 Countries

Cybersecurity meeting, Biden Administration and Tech Giants, Zero-Trust Model

Cybersecurity continues to be a growing concern, and ransomware attacks have emerged as a national threat to organizations, affecting critical systems and causing severe damage to users and enterprises of all sizes across the globe. Particularly organizations in the U.S. have sustained devastating ransomware attacks lately. As part of their multiple cybersecurity initiatives, the Biden administration is going to conduct a virtual meeting this month involving over 30 countries to address the expanding cyberthreat landscape.

The coordinated meeting is aimed to bring all capabilities together to disrupt cybercriminals and their activities, including managing both the risks and opportunities of emerging technologies like quantum computing and artificial intelligence.

Topics to be discussed in the meeting:

  • Combating cybercrime
  • Improving law enforcement collaboration
  • Stemming the illicit use of cryptocurrency
  • Building trusted 5G technology
  • Securing supply chains from ransomware

The Biden administration also partners with other nations, NATO allies, and G7 partners worldwide who share similar threats.

“Cyberthreats can affect every American, every business regardless of size, and every community. That’s why my administration is marshaling a whole-of-nation effort to confront cyber threats. I’m committed to strengthening our cybersecurity by hardening our critical infrastructure against cyberattacks, disrupting ransomware networks, working to establish and promote clear rules of the road for all nations in cyberspace, and making clear we will hold accountable those that threaten our security,” the White House said in a statement.

Building Better Cybersecurity Practices

Proclaiming the Cybersecurity Awareness Month, POTUS Joe Biden acknowledged how much work remains to be done to maintain strong cybersecurity practices as an ongoing practice for both users and organizations.

“The Federal government needs the partnership of every American and every American company in these efforts. We must lock our digital doors — by encrypting our data and using multifactor authentication, for example — and we must build technology securely by design, enabling consumers to understand the risks in the technologies they buy. Because people – from those who build technology to those to deploy technology – are at the heart of our success,” the statement added.

Real Cloud Security Means Less Talk, More Action

Cloud Security, 80% of Organizations Suffered a Cloud Data Breach in the Past 18 Months

Cloud security is still a major problem, despite all the conversations about it and the very clear threats enterprises face today. In fact, the 2021 Verizon Data Breach Investigation Report found that most cybersecurity incidents now involve cloud infrastructure – 73% involved external cloud assets, up from 27% the prior year. It marked the first year that cloud incidents surpassed on-premises ones.

By Vince Hwang, Senior Director – Products and Solutions, Fortinet 

Clearly, security isn’t keeping up even as cloud adoption skyrockets. And it’s going to continue to do so – Gartner predicts that global spending on public cloud services will reach $332.2 billion this year, a significant increase from $270 billion last year. What’s behind these cloud security issues and how do we tackle them? Read on.

The Madness of Misconfiguration

The likelihood of misconfiguration increases in step with increased cloud use, and it’s one of the biggest problems when it comes to cloud security. According to the Fortinet 2021 Cloud Security Report, 67% of cybersecurity professionals surveyed said that misconfiguration remains the biggest cloud security risk. Cloud misconfigurations happen when a user or team specifies settings that fail to provide adequate security for their cloud data. If an organization’s cloud doesn’t have strong security measures, attackers can exploit those misconfigurations to compromise or steal cloud data.

Misconfigured cloud-based resources leave critical environments at risk, so misconfigurations may result in unexpected costs and disrupted services. Attackers can do significant harm by targeting a misconfiguration as they move laterally within an organization’s infrastructure.

See also: 3 Steps to Boost Your Enterprise Cloud Security

Adding Multi-cloud to the Scenario

Another significant trend affecting cloud security is this: very few companies are taking a one-size-fits-all approach to the cloud. Most are using more than one cloud to overcome multi-cloud security challenges, such as data backup, application resiliency disaster recovery and global coverage. In fact, according to the Fortinet report, 71% of organizations are pursuing a multi- or hybrid cloud strategy; 33% of organizations are running more than half of their workloads in the cloud today, and that figure is projected to rise to 56% in the next 12–18 months. They are doing this for reasons of scalability, integration of multiple services or business continuity. That doesn’t mean that on-premises is a thing of the past; hybrid still accounts for more than one-third of deployments. What it does mean is that organizations are now operating in a diverse and expanded digital landscape.

The problem is that it’s not so easy to manage and secure different private and public cloud workloads and environments as some may have imagined. Though it offers many benefits, multi-cloud adoption adds extra layers of management complexity, especially when cloud services are added in an ad hoc manner rather than being planned out. This complexity creates management and operational challenges and increases operational costs. Even worse, not many IT teams have the expertise to manage a mixed deployment of multiple public clouds, private cloud and on-premises environments.

Less Talk, More Strategy Needed

Overcoming all of these cloud security issues requires a cohesive approach. Multi-cloud deployment presents an opportunity to hit the pause button, shift from the point solution approach and design your cybersecurity in a holistic manner. Otherwise, you may end up adding to the chaos so typical in IT today: too many management platforms, too many products, too many vendors.

A holistic security approach excels over traditional security approaches. Rather than adopting point solutions that can lead to security gaps, a holistic security model uses open standards and protocols to integrate all security activities into a single platform. With all security routed to the same platform, organizations can more rapidly detect, investigate and respond to threats. Additionally, if a security fabric approach uses machine learning (ML), the system can become a self-healing security and networking system that protects applications, data and devices across on-premises data centers and cloud services.

A Holistic View

Unfortunately, both legitimate organizations and cybercriminals take advantage of advances in technology. As enterprises have adopted multi- and hybrid cloud strategies, malicious actors have found ways to circumvent security measures and attack corporate networks. Yet the irony is that cloud misconfigurations, created by enterprise IT teams, are the primary way that attackers can infiltrate the network.

Multi-cloud and hybrid cloud approaches add layers of management complexity, which is also difficult for most IT teams to navigate. A new cloud approach requires a new security approach – one that integrates all security activities into a single pane of glass. IT security teams then have visibility into all cloud configurations and a better chance of detecting and mitigating threats. Today’s cloud strategies require a holistic security strategy.


About the Author

Vince HwangWith over 20 years in cybersecurity leading at the forefront of many industry-firsts in the space, Vince Hwang is senior director of products & solutions at Fortinet where he leads adaptive cloud security products and solutions. He’s excited by the possibilities of enabling customers to achieve their desired digital innovations outcomes through cloud journeys. Previously, Vince has held key roles driving product strategy and execution at companies that include Cisco, Sourcefire (now part of Cisco), Symantec, and Trend Micro.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Common Web Application Attacks

MaliciousItaú Unibanco app,Web Application Security, web application attacks

Amidst the pandemic, there has been an exponential rise in the number of businesses embracing digital transformations like web applications to streamline their workload and digitally exchange data and transactions. While this has numerous benefits for users, it also highlights significant weaknesses and vulnerabilities in web browsers that lead to web application attacks. You can avoid falling prey to data breaches and other such attacks by being well-versed in mitigating the risk of web applications attacks.  

It would also help to know about the most popular web-based attacks to build a strategy to mitigate such risks.  

  1. Weak authentication is a scenario where the layers of security are weaker or incompatible with the value of protected assets. Moreover, weak authentication can also point towards a situation where the authentication process is flawed or vulnerable.  
  2. On the other hand, a Cross-Site Request Forgery or Session Riding attack can disrupt the operation between the business and the user. The attacker leverages social engineering techniques to trick the target into executing a forged request in their server. Hence, it becomes impossible for the user to distinguish between what’s legitimate and what’s not. Thus, it leads to disruptive web-based attacks.  
  3. Since access control design decisions are made by humans and not machines, the scope of errors creeping in through weak access controls is relatively high. As a result, attackers quickly make their way through a web application attack and breach the accessibility and privacy of the stored data in case of weak access controls.
  4. Further, attackers can interfere with an application’s query to its database through an SQL attack. Through this, they can access data unavailable to them in normal circumstances and risk privacy and the authenticity of the data.  

Web application attacks

To steer away from these web application attacks, you must have complete visibility of the code being run on your website and conduct regular security assessments. Web Application Hacking and Security (WAHS) Course is crafted by the same team that developed the C|EH to give you hands-on training in a lab-based environment.  

Brace yourself to fight against the topmost web-based attacks through a guided mastery course at EC-Council.  Become a Certified Web Application Security Professional today.   

Get Certified 

Conti Ransomware Group Reportedly Stole 1.5TB Of Data from JVCKenwood

JVCKenwood, LockFile ransomware, ransomware attacks in India, Suppress ransomware payment channels

Multinational electronics firm JVCKenwood admitted that it had been hit by a security incident that affected some of its operations in Europe. The company also admitted there was a possible breach of sensitive information during the cyberattack. However, there is no sign of customers data leak at present. Several security experts suspect that the Conti Ransomware group is behind the security incident.

Based in Japan, JVCKenwood is known for its brands JVC, Kenwood, and Victor, which provide equipment to automobile and health care organizations.

“JVCKenwood detected unauthorized access on September 22, 2021, to the servers operated by some of the JVCKENWOOD Group’s sales companies in Europe. It was found that there was a possibility of information leak by the third-party who made the unauthorized access,” the company said in an official statement.

Conti Ransomware Attack

While JVCKenwood is investigating the incident to find further details, multiple reports claimed that Conti ransomware attackers have compromised the critical networks and  stole over 1.7 TB of data. The attackers reportedly demanded a $7 million ransom to decrypt the critical files.

Conti is a Russian-speaking ransomware group that reportedly victimized more than 400 organizations worldwide, of which 290 are in the U.S. alone. Conti attackers infiltrate victim networks through phishing emails (malicious links or attachments) or stolen/cracked remote desktop protocol (RDP) credentials. Their average recorded dwell time in the victim’s network ranges between four days to three weeks. The highest recorded bid of the Conti ransomware gang stands at $25 million.

CISA, FBI, and NSA Warn About Conti Ransomware 

The Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the FBI alerted users and organizations about the rise of Conti ransomware attacks.

To secure organizations’ critical systems against Conti ransomware, the agencies recommended certain security mitigations such as enabling multi-factor authentication,  implementing network segmentation, and keeping operating systems and software up to date.

BloodyStealer Steals Gamers’ Account Data to Sell on Dark Web Forums

BloodyStealer

Kaspersky researchers have discovered an advanced Trojan, called the BloodyStealer, sold on darknet forums and used to harvest gamers’ accounts across widely used gaming platforms such as Steam, Epic Games Store, and EA Origin.

The Online Gaming industry is one of the driving forces behind internet penetration to the most remote locations across the world. Statista in its global video game market report projects the industry revenue from the video game market to surpass 138 billion USD by 2021. Given the might of the market, it is a constant favorite of cyberattacks.

The BloodyStealer Trojans are premeditated attack campaigns to harvest in-game goods and gaming accounts as they are in high demand on the darknet and fetch a good bounty.

According to the Kaspersky researchers, gaming logins and passwords from players across the gaming platforms like Origin, Ubisoft or EpicGames fetch 14.2 USD per thousand accounts in bulk and up to 30% of the account value if sold individually.

Popularity

The Trojan has been gaining popularity due to its ability to avoid detection and malware analysis. The Trojan can harvest a range of critical data like passwords, cookies, bank cards, sessions from apps, and logs from the memory.

The use of techniques like anti-analysis method to complicate its reverse engineering analysis, including the use of packers and anti-debugging techniques has made it a choice for cybercriminals.

“The developers behind this stealer also added capabilities, such as grabbing information related to online gaming platforms. This information can then be sold on different underground platforms or Telegram channels that are dedicated to selling access to online gaming accounts,” comments Dmitry Galov, a security researcher at Kaspersky’s Global Research and Analysis Team.

According to research from Akamai Technologies, the gaming industry sustained more than 240 million web application attacks in 2020, which is a 340% surge from 2019. The “State of the Internet/Security report, Gaming in a Pandemic” highlighted the global crises that resulted in the rise of cyberattack traffic in the gaming industry.

It was observed that SQL injection was the top web application attack in 2020, accounting for 59% of all attacks, followed by local file inclusion (LFI) attacks (24%). While cross-site scripting (XSS) attacks accounted for 8%, remote file inclusion (RFI) attacks were recorded at 7%. Threat actors leveraged different kinds of web application vectors to target gamers’ login credentials and sensitive information stored within the applications.

GriftHorse Android Trojan Scam Purloins Over 10 Million Euros

Android, Trojan, Android Banking Trojans

Zimperium zLabs recently discovered a global scam where the threat actors posing as Trojans have hidden behind malicious Android applications and stolen millions of Euros from the infected devices.

The decoy makes the malicious Android applications look harmless when viewing the Play Store description or request permissions. They operate stealthily acting as Trojans and take advantage of the user interactions for further spread.

The Trojan named “GriftHorse” has been running the scam services campaign since November 2020. It uses the infected device to subscribe to unscrupulous services at a recurrent cost and has ensured illicit cash flow of millions of Euros towards the scam.

According to Zimperium zLabs, the new malware has been embedded in hundreds of applications, which have evaded detection by app repositories. These malicious applications are widely distributed through Google Play Store and other third-party app stores.  Users are charged on a monthly basis for services subscribed to, without their knowledge and approval. These Android apps vary from puzzles, gaming, food, and entertainment. The report pointed out a popular translator malicious app was downloaded no less than 500,000 times.

Google Play Store removed the malicious applications from their store on receiving the findings from the Zimperium zLabs, however unsecured third-party app repositories are still rife with these Trojans.

The Campaign

The “GriftHorse” campaign has targeted millions of users across 70 countries. The victims are targeted through apps and malicious pages in their local language, based on their geo-location and IP address thereby circumventing suspicion. The malware goes undetected for months as they avoid using hardcoding URLs or same domains, allowing them to target different countries and subscribers.

These Trojans have been developed using the mobile application development framework named Apache Cordova. Cordova allows developers to use standard web technologies – HTML5, CSS3, and JavaScript for cross-platform mobile development. The technology was abused to host the infected code on the server and develop an application that executes it in real-time.

The zLabs threat research team has reported the “GriftHorse” campaign as the most effective, widespread cyberattack of 2021 where more than 200 Trojan apps were effectively used to pocket millions of Euros across geographies from over 10 million victims’ devices.

Purplesec’s cybersecurity statistics for 2021 reports that mobile malware is on the rise with a high number of new variants infecting devices, up by 54% in 2018. Nearly 99% of the discovered mobile actors were hosted by third-party app stores. Trojans make up 51.45% of all malware. More than 250,000 unique users were attacked by Trojan Banker.AndroidOS.Asacub malware application. And 98% of all mobile malware target Android devices.