Home Blog Page 57

Indian Organizations Among Most Targeted for Ransomware; Most Pay Ransom

JVCKenwood, LockFile ransomware, ransomware attacks in India, Suppress ransomware payment channels

Most news on ransomware attacks is about U.S. organizations. We hear little about ransomware attacks in India, as few organizations report it. That’s not to say that Indian companies are spared. In fact, India is the fifth most attacked country in the world and the third in Asia. This is widely reported in the media. In its report titled The State of Ransomware 2021,” cybersecurity firm Sophos reveals that India tops the list of top 30 countries for ransomware attacks, with 68% of Indian organizations surveyed being hit by ransomware in the last 12 months.

Ransomware Attacks in India Decline

According to Sophos, there has been a drop in ransomware attacks this year, compared to the previous year. The Sophos survey also highlighted that 67% of Indian organizations whose data was encrypted paid a ransom to get back their data compared to last year, when 66% paid a ransom.

The Sophos report states, “In fact, Indian organizations were the most likely to pay a ransom of all countries surveyed: the global average was just under one third (32%).”

While ransomware attacks in India saw a dip this year, various research reports show that attackers are taking a more targeted and organized approach. There are new vulnerabilities; zero-day attacks are now common. Ransomware hackers have now zeroed in on blockchain, cryptocurrencies, and cryptocurrency exchanges. EC-Council’s Cyber Research cell will be releasing a report on this next month.

According to the Microsoft Security Endpoint Threat Report 2019, Asia Pacific continued to experience a higher-than-average encounter rate for malware and ransomware attacks – 1.6 and 1.7 times higher than the rest of the world, respectively.

India registered the seventh-highest malware encounter rate across the region, at 5.89% in the past year. This was 1.1 times higher than the regional average. The report also found that India recorded the third-highest ransomware encounter rate across the region, which was two times higher than the regional average.

This was despite a 35% and 29% decrease in malware and ransomware encounters, respectively, over the past year.

Cryptojacking Attacks Increasing

The Microsoft report states that crypto-hacking, malware, ransomware, and drive-by download attacks have high cybersecurity challenges in India. In fact, India recorded a cryptocurrency mining encounter rate that was 4.6 times higher and drive-by download attack volume that was three times higher than the regional and global average.

It’s a well-known fact that millions of Indians have taken to cryptocurrency trading via hundreds of exchanges around the world. And since cryptocurrency is linked with ransomware, it’s not surprising that new attack vectors like crypto-hacking, cryptojacking, and illegal cryptomining are picking up in the region.

Cryptocurrency is generated through crypto mining, which requires a lot of computing power. During cryptojacking attacks, the victims’ computers are infected with cryptocurrency mining malware, which enables criminals to leverage the computing power of victims’ computers without their knowledge, to mine cryptocurrency. Pro-Ocean, which was discovered by Palo Alto Networks, is an example of cryptocurrency mining malware.

New Vulnerabilities Found

In its Q2 Index Update, Cyber Security Works reveals new vulnerabilities in the ransomware arsenal. Its research shows that six vulnerabilities have become associated with seven ransomware strains; among them are the infamous Darkside, Conti, FiveHands, and the newly christened, Qlocker.

Ram Movva, the President and Co-founder of Cyber Security Works“With this update, the total number of vulnerabilities associated with ransomware has increased to 266. We have also noticed a 1.5% increase in the number of actively exploited vulnerabilities that are trending currently, reiterating that a risk-based approach for the remediation of vulnerabilities is the need of the hour.

One of the most compelling observations during this quarter was the exploitation of zero-day vulnerabilities even before vendors published their discovery or released patches,” said Ram Movva, Chairman and Co-founder of Cyber Security Works.

More Targeted Attacks

Another trend we observe is that the attacks are getting more targeted. Going forward you can expect to see attackers going after niche sectors rather than trying to pull off large scale attacks on everyone.

Prateek Bhajanka, Senior Principal Analyst, Gartner

“Ransomware threats actors have been constantly evolving their tradecraft to increase the odds of the ransom payment. The most infamous ransomware variants such as WannaCry, NotPetya were more of opportunistic attacks than targeted. However, the ransomware incidents and attacks from 2020 and 2021 are much more focused, planned, and targeted and are becoming ‘Human-Operated’. They leverage known information such as vulnerabilities/ stolen credentials/ phishing attempts to launch initial attacks. These newer ransomware variants are also including ‘cyber extortion’ angle in the mix along with ransomware rendering the data backups/ restoration controls implemented by organizations less effective,” said Prateek Bhajanka, Sr Principal Analyst, Gartner.

He continued, “In many cases of ransomware incidents, the encryption of data may not even occur, and the threat actor would issue a ransom note saying, we have stolen your regulatory, client and other sensitive information, here is the sample, and if you don’t pay, we will also encrypt your data. The ransomware threat actors are going to various lengths to increase the odds of the payment and even resorting to launching/ threaten a DDOS attack if the organization doesn’t pay, called ‘Triple extortion attacks'”.

Bhajanka also said there will be an increase in the volume of attacks due to emergence of Ransomware as a Service (RaaS) in the dark web, which makes it much easier to target specific organizations. He said the attacks are going to be directed at specific industries.

“In 2020, Healthcare and Pharmaceutical industries were the most sought-after targets and now we are also observing increase in attacks in Retail and education sectors. Alongside, the threat actors are targeting the technology service providers such as Managed service providers (MSPs) and Managed Security Service Providers (MSSPs) to use them as a vector/pivot to large number of victim organizations,” he added.

New Zealand Banks and Postal Service Under DDoS Attack

DDoS Attacks in Russia , RDDoS attacks, DDoS attack on New Zealand Banks

It seems like New Zealand is becoming a new cyberthreat landscape with regular security incidents. Months after a cyberattack on the New Zealand reserve bank, attackers reportedly targeted several banks, financial institutions, and postal services in the country.

New Zealand’s Computer Emergency Response Team (CERT) stated that it identified a Distributed Denial of Service (DDoS) attack that temporarily affected the operations of several organizations in the country. In DDoS attacks, threat actors make a targeted system or service unavailable to its users by flooding their systems with unwanted incoming traffic from different sources.

While the criminals behind the attack are unknown, the agency stated that it is investigating the incident and working with affected parties to explore more details.

One Attack, Multiple Victims

The DDoS attack has affected multiple organizations in New Zealand, including Australia and New Zealand banking group (ANZ), New Zealand Post (NZ Post), and Kiwibank.

Also Read: New Zealand’s Reserve Bank Data System Hacked; Critical Data at Risk

ANZ has apologized its customers for the service outage. “We are experiencing an outage with our Internet Banking and goMoney app at the moment, we’re really sorry for any inconvenience that this may cause! Our tech teams are working hard to get things fixed asap,” ANZ said.

Several other victim organizations took to social media to apologize to its customers and provide update on the security incident.

“Apologies for the inconvenience while we work to fix intermittent access to our App, Internet Banking, Phone Banking, and Website,” Kiwibank said in a post.

DDoS Attacks Rise in New Zealand

This is not the first time organizations in New Zealand have sustained a DDoS attack. Recently, New Zealand stock exchange NZX Ltd. went offline for three consecutive days after a DDoS attack impacted its network connectivity systems, including NZX websites and the markets announcement platform. Read More Here…

The Increase in Scope of Cybersecurity from Software to Hardware Protection

scope of cybersecurity, Microsoft December 2021 Patch Tuesday

When we think of cybersecurity our mind automatically goes to powerful software protecting “soft” assets i.e. data that could range from massive enterprise-grade datastores to tiny files that contain sensitive data about someone.

 By Neil Okikiolu, Founder/CEO of Simius Technologies Inc. 

These “soft” assets have been given priority in the cybersecurity industry. However, hardware is surging in popularity, things like autonomous vehicles and robots are on the horizon. Knowing this, hardware companies and the cybersecurity industry will need to come together and come up with effective strategies to protect the devices they sell and deploy. 

Hardware is Eating the World 

A famous software entrepreneur once said “software is eating the world” but in recent years, hardware is biting back in a big way. The GSM Association estimates that by 2025 there will be almost 25 billion IoT devices deployed in the world. That is approximately 3 devices for every human being on the planet. 

It is no surprise why. The ability to automate tasks that require a physical activity to be performed is something that business leaders have dreamed of since they had workers. This physical automation is very desirable especially in cases where the work is either extremely repetitive or very dangerous for humans to undertake. 

Even for the general consumer too, there are large benefits such as being able to save money when it comes to energy consumption by using smart thermostats or being able to monitor the state of their entire house through their smartphone. 

However, with this rush towards the future, some things have been forgotten. The most important of these is device cybersecurity. 

The Stakes are Increased with Hardware 

So why is device cybersecurity so important? There are many reasons but we will describe the two most important ones. 

Firstly, hardware is tangible when compared to software. What does this mean? Well, say for example someone were to target your company’s website. The hacker was able to send commands to drop the main database. Seeing as how you are an astute CIO/CISO, you have data backup policies in place that allow your organization to restore its database with minimal downtime. 

However in the case of hardware, due to the nature of how software is run on it. A hacker can cause permanent damage to the device. Which is very costly for the entity that operates said device.  

The second reason is hardware control. Future IoT is not passive, we are going to have active systems. Which means devices that can alter the state of their physical environment. An example is an autonomous robot that performs agriculture tasks. 

The implication is that if someone were to take over an active device, they could have the power to negatively impact the environment they are in. To continue with the robot example, if someone were to take it over, they could drive it to another location where the robot could be taken away and sold for parts. 

Strategies for the Future 

Cybersecurity at the Design Stage 

All hardware must be designed with updatability in mind. Threats evolve and so must the hardware defending those threats. 

Traditionally, hardware has been developed using the waterfall model and for good reasons too (the system requirements are fixed, obviously you can’t patch more ram into the device). 

Luckily, there is a place where we can inject a continuous product process and that is in the embedded software development stage. 

In this stage of development, a cybersecurity-focused scrum process can be applied. The CIO/CISO can provide security guidance to engineers while allowing them to rapidly develop and improve the software being built. 

This cybersecurity-focused scrum process is already being implemented in the United States Space Command and Control.  

The other important piece regarding updatability is securely delivering and installing new firmware updates on your hardware. 

Some aspects of this process are: 

  • Firmware verification, which involves using a digital signature to verify the file being received is from the correct source. 
  • Firmware error checking, as sometimes your devices may be installed in places with low network availability, and as such your device must be able to verify the integrity of any received file 
  • Support for various encryption methods e.g. AES, DES, etc. 
  • Adding secure key storage can be accomplished by using things like a One-Time Programmable Array. 

 Keep in mind, the previous list is not exhaustive, it just provides a starting point when it comes to designing a piece of hardware with cybersecurity in mind.

Data Access Controls – We need more than Keys 

Imagine this scenario, a man walks to the gate of a factory. At this gate, he is presented with a card reader. He swipes the keycard he has on his person and the gate swings open.  

What is the problem with the scenario that was presented? Well, most of you reading this are CIOs or CISOs and you will realize that no industrial or professional building relies on only keys for access controls. There are security guards, cameras, and even members of the building standing there who can make sure that the person using the security card (or other access methods) is legitimate. 

Now, why was this story presented? 

The reason was to illuminate the fact that we have all implemented multilayered physical access controls. However, when it comes to data access controls, we usually rely on a sort of “key” which grants access to an account, which grants access to data and permissions that account has. 

These keys, for the most part, can be duplicated with ease. So why do we trust the key itself? We have assumed that just because an entity possesses the appropriate credentials, they must be allowed to access whatever the key allows them to access. 

Keys and other access mechanisms are methods, they are not proofs of identity. We cannot blindly trust the keyholder. This is security backward. The keyholder must be vetted as well. 

Think about it, if someone walked up to your house and unlocked the door, you would not just welcome them in while rationalizing that they must be a member of the household since they possess the correct key. 

So what do we do? 

User vetting and verification must be added to the user authentication pipeline. A straightforward method of user verification is fingerprinting. A good thing about human beings is, we are very good at displaying minute unique imperceptible actions which can be used to create a digital fingerprint. Some actions are, how we move our mouse, how we type (our cadence for instance), how long it takes to enter a key etc.  

Using our current knowledge and understanding of Artificial Intelligence, we can implement systems to distinguish between people using data points that will be almost impossible to replicate. 

And if these fingerprinting systems get advanced enough, we could truly eliminate the use of passwords (the bane of every security professional). 

Keep in mind that this is only one method of guaranteeing a user’s identity in addition, there are definite privacy concerns with this method. It is left up to the organization to determine what methods of identity verification suit them and those who they serve. 

The Importance of CIOs/CISOs 

This was touched upon briefly in this article and will be expanded here. 

CIOs and CISOs are quickly becoming one of the most important corporate officers in technology today. Just as the CTO rose to prominence 2 decades ago, when companies realized digital technology was a core competency. So are CIOs and CISOs because security is now one of the most important competitive advantages. 

A bad security posture can cost companies millions, if not hundreds of millions of dollars in either lost revenue or loss from lawsuits and heavy lines.


About the Author 

Neil Okikiolu is a Computer Scientist, Roboticist, and the founder of Simius (https://simius.ai) a consumer-focused IoT cybersecurity company. 

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.


References:

  1. GSMA – The Mobile Economy 2020 
  2. KPMG – Turning Cybersecurity into a Growth Driver 
  3. Home router security report 2020, 2020-06-26, Peter Weidenbach and Johannes vom Dorp, Fraunhofer Institute for Communication; Information Processing and Ergonomics 
  4. Gupta, Udit. (2015). Secure management of logs in internet of things. International Journal of Advanced Networking and Applications. 7. 2636-2639. 
  5. CPrime – Agile Processes for Hardware Development. 
  6. SolarWinds and Cybersecurity: Using Scrum To Improve National Security 
  7. Kvarda, Lukas & Hnyk, Pavel & Vojtech, Lukas & Lokaj, Zdenek & Neruda, M. & Zitta, Tomas. (2016). Software Implementation of a Secure Firmware Update Solution in an IOT Context. Advances in Electrical and Electronic Engineering. 14. 10.15598/aeee.v14i4.1858. 

This is How Ransomware Gangs Select their Victims

Ransomware gangs

Not all ransomware gangs break into targeted networks. They often purchase access to victims’ networks from other cybercriminal groups and initial access brokers (IABs) on dark web forums.  IABs are cybercriminal affiliates who breach a corporate network via brute-force or phishing attacks and then sell that access to other threat actor groups.

Ransomware operators advertise their requirements, based on which the affiliates offer a variety of products and services such as malware backdoors, compromised credentials, and access to corporate systems. After analyzing various advertisements of ransomware gangs on the dark web, threat intelligence firm KELA listed the criteria that ransomware operators look at before selecting a victim.

“In July 2021, KELA observed threat actors creating multiple threads where they claimed they are ready to buy accesses and described their conditions. Some of them appear to use access for deploying info-stealing malware and carrying out other malicious activities. Others aim to plant ransomware and steal data. KELA explored what is valuable for threat actors buying accesses, especially ransomware attackers, and built a profile of an ideal ransomware victim,” KELA said.

Attackers select their ideal victim based on:

Geography – According to KELA, 47% of attackers mentioned the desired location of victims as the U.S., followed by Canada (37%), Australia (37%), and European countries (31%).

Revenue – The average minimum revenue desired/demanded by ransomware attackers is 100 million dollars.

Sectors – Nearly 47% of ransomware attackers refused to buy access to companies from the health care and education sectors. Around 37% prohibited compromising the government sector, and 26% claimed they would not purchase access related to non-profit organizations.

Access Type – Most ransomware operators are ready to buy all kinds of network accesses, with RDP and VPN being the most basic requirement. The other most common products enabling network access include Citrix, Palo Alto Networks, VMware, Fortinet, and Cisco.

Other Key Findings

  • KELA found 48 active threads where actors claimed they are looking to buy different kinds of accesses. 46% of them were created in that month, illustrating the demand for access listings.
  • 40% of the actors looking to buy accesses were identified as active participants in the ransomware-as-a-service (RaaS) supply chain – operators, affiliates, or middlemen.
  • Ransomware attackers are ready to pay for access, starting from $100 and ending with $100,000. The average minimum and maximum prices for access are $1600–$56,250. In addition, 32% of ransomware attackers are ready to pay a share of a ransom.

“Demand for access listings on cybercrime forums is growing, with more actors advertising, they are ready to buy entry points to networks, sites, storage, and more. This is another proof of continuing servitization of cybercrime, especially ransomware-as-a-service (RaaS) operations that rely on different specialists to perform their attacks. However, it is crucial to remember that access to a company in the wrong hands may be exploited not only for deploying ransomware and stealing data but also for other malicious campaigns,” KELA added.

How to Stay Safe Online: Six Security Tips for Kids

security tips for kids

Though the Internet is a good resource for endless knowledge, it also has its share of risks. Unlike adults, most kids and teens are not aware of the security hazards while surfing online.  The Internet has become a part of life, and parents must ensure their children are aware of online safety measures and ways to protect their privacy and personal information.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

Internet @Risk

While kids are busy making new friends and sharing their personal lives online, cybercriminals are preying on their personal information. A recent survey revealed a surge in toxicity on the Internet, with a staggering 70% increase in hate between kids and teens during online chats and a 40% increase in toxicity on several gaming platforms.

“Our children are growing up in a world where the internet is a basic essential of life. They do not view the online world as new technology like some of us do – to children. It has always existed. Therefore, they don’t approach their interaction online with the caution that we might. They only see a screen that reacts to their button taps, innocently unaware of the invisible risks at play,” said Luis Corrons, security evangelist at Avast.

How To Stay Safe Online

Kids and teens do not fancy constant parental monitoring. However, parents need to communicate and encourage their children to follow online security since they carry a smartphone all the time. Some of the security tips are:

1. Limit Your Personal Data

Sharing too much personal information online, especially on social media platforms, is risky. Limit the information you share online to avoid its misuse. Make all your online accounts private and secure by enabling privacy settings. Never share your private details such as phone number, address, or live location as a security precaution.

2. Stranger is Danger

Social media platforms or fan forums offer a virtual environment to make new friends and explore and share interests. However, threat actors often have multiple identities online. Never trust anyone blindly unless you meet them offline. Never share your images and other personal identities with a stranger.

3. No Password Sharing

It’s a bad idea to share your password with your friends only to make them realize how strong it is. Your passwords could be misused to exploit your online accounts. Always use complex and unique passwords and never share them with anyone.

Note: It is important for kids to understand that password sharing is invasion of privacy, and therefore a breach.

4. Always Double-check

You come across several pieces of fake news and hate speeches online. Some are fake, while some grab users’ attention with catchy headlines, discounts, or offers to phish them eventually. Always verify the authenticity of information before telling/sharing it with anyone.

5. Report Cyberbullying

Cyberbullying happens when someone reveals toxic or mean content about someone else to embarrass or humiliate them online. Miscreants often leverage social media platforms, chat rooms, online forums, and online gaming communities to bully unsuspecting users. Communicate with a friend or family member if a stranger sends you offensive/embarrassing messages or impersonates your identity to harass others. Reach out to concerned authorities (police or emergency services) and report the bully to avert danger.

6. Beware of Online Scams

Internet is not a safe place unless you’re equipped with safety measures. Several threat actor groups and adversaries rely on the Internet to steal users’ personally identifiable information (PII) or banking details to monetize it on darknet forums. The stolen data could also be misused to launch different kinds of financial frauds, identity thefts, phishing, and credential stuffing attacks. Don’t click/download suspicious files and attachments from unknown sources; they could be malicious.

Wrap-Up

Online safety precautions should be an ongoing conversation among kids, parents, and teachers. Parents must monitor their children’s online behavior and other aspects of their digital life to watch what they see or hear on the internet and guide them with right awareness. Right cyber awareness among kids today can reap responsible netizens tomorrow.

About the Author:

Rudra Srinivas

 

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

More from Rudra.

 

Sniffing Attacks and How to Defend Against Them

sniffing attacks

Sniffing attacks are gaining prominence among cybercriminals today to steal customer data and compromise network security. Sniffing attacks, a significant security risk, enable common network threat types such as man-in-the-middle attacks, insider threats etc.

They pose a crucial challenge to client-server computing today. Detecting and preventing common network adversaries is one of the most important steps in preventing common network attacks. Hence, the protection of your digital assets is pivotal in the digitalization era.

While the pandemic-induced lockdown ushered in the work-from-home culture, it also highlighted the rapidly evolving security risks. Working out of the office comes with greater risks as employees need to ensure they work from a secure network to protect sensitive information and client data. Furthermore, failure to do so can result in a massive loss of data and escalate the risk further.

In order to understand the context of sniffing in networking, this article explains the basics of packet sniffing attacks, their types, and how one can prevent them.

What are Sniffing Attacks?

Monitoring and intercepting data packets passing through a network with the help of specialized tools called packet sniffers is called “sniffing.” Data packets carry a wealth of information and facilitate the process of incoming and outgoing traffic. A sniffing attack involves the illegal extraction of unencrypted data by capturing network traffic through packet sniffers.

Legal and Illegal Use of Sniffing Tools

IT professionals and network administrators use packet sniffers to monitor network traffic, assemble information for security analysis, and identify and troubleshoot network issues from an information security context. These are examples of legal usage of packet sniffing to optimize network security.

However, these tools can also be misused for malicious purposes.

Today, it’s common to see black hat hackers using sniffing techniques. Cybercriminals use packet sniffers to steal data and sensitive information from email or web traffic over an unsecured network.

Sniffing tools are illegally used to steal critical information such as client data, passwords, banking data, or to commit identity theft. Hackers can further their nefarious activities by using stolen data in fraudulent transactions with the help of sniffing attack tools such as Wireshark, BetterCAP, WinDump, Ettercap etc.

Most people may fall prey to such sniffing attacks when they use an unsecured Wi-Fi network. Packet sniffing tools can serve as the launchpad for DDoS (Distributed Denial of Service) attacks or man-in-the-middle attacks, also known as spoofing. Consequently, these attacks can compromise the data integrity of your business.

Spoofing and Sniffing are different

Often people confuse spoofing with a sniffing attack. The terms sniffing and spoofing are frequently used interchangeably. However, sniffing is different from spoofing attacks. Sniffing includes the attacker’s direct involvement with the target. They intercept network traffic to listen for and read unencrypted data actively. On the other hand, spoofing attacks are man-in-the-middle attacks in which the attacker impersonates another person. They intercept data passing between the targets and the network to gain access to sensitive information.

Types of Sniffing 

Detecting packet sniffing takes experience and requires learning the basic concepts. So, it is essential to know the types of sniffing attacks to identify them. Two types of sniffing attacks are quite common – active and passive sniffing. The major difference between active and passive sniffing lies in the manner they operate. Let us understand them further.

Active sniffing

In active sniffing, attackers seize data packets by manipulating switch-based networks. Most networks today use a switch, which is a device connecting two network endpoints. They use the switches to forward data to a specified port using the port’s media access control (MAC) address. Attackers exploit this by injecting traffic into the LAN (Local Area Network) to enable sniffing. Common examples of active sniffing include MAC flooding, DNS (Domain Name Servers) spoofing, ARP (address resolution protocol) spoofing etc.

Passive sniffing

Passive sniffing takes place through hubs or wireless networks, and attackers use MAC addresses to read the destination ports of data. They do not make any direct communication with the target, unlike active sniffing. Most packet sniffers are difficult to detect because they are passive.

How to Prevent Sniffing Attacks

Sniffing is a common hacking technique among cybercriminals to steal sensitive data or commit identity theft. However, to prevent sniffing attacks, one can deploy a few preventive measures. Let’s look at a few steps to ensure the safety of your businesses’ networks and systems.

Avoid unsecured networks

We often read news of bank data theft where attackers steal a user’s credit card or banking information to make unauthorized changes or purchases. Well, that’s because they have fallen prey to sniffing attacks. It can occur if a user exposes their device to unsecured Wi-Fi networks. Additionally, attackers use such vulnerable networks to install packet sniffers to sniff and read all data transmitted over that network.

Another way an attacker can sniff network traffic is by creating fake-free public Wi-Fi. So, the next time you see a free and unsecured public W-Fi, remember to avoid it.

Encrypt your message with a VPN

An effective way to prevent sniffing attacks is to encrypt all your incoming and outgoing communication before sharing them using a virtual private network (VPN). Encryption enhances security and makes it difficult for hackers to decrypt the packet data.

Network scanning and monitoring

Network administrators should secure their networks by scanning and monitoring their networks with the help of bandwidth monitoring or device auditing. Therefore, this is one of the important strategies to optimize your network environment and identify the presence of sniffing attacks.

No network is safe from unauthorized intrusions by cybercriminals. Even with the most sophisticated techniques and measures in place, attackers can exploit and extract data from your network. Therefore, your organization needs to have a qualified team of ethical hackers and network administrators who can penetrate the systems and implement these checks periodically to identify network contingencies. Besides, if you are planning to advance your IT career to detect sniffing attacks or want to align your team with the right skill set, the Certified Ethical Hacker (C|EH) can help you achieve your goals.

Pursue a Career as a Certified Ethical Hacker

In information security, ethical hackers also use sniffing techniques to acquire information that could help them penetrate a system. Ethical hackers or IT professionals use packet sniffers to identify and troubleshoot network bugs.

Becoming a Certified Ethical Hacker (C|EH) would put you on the front lines of detecting and mitigating these sniffing attacks, thereby keeping the network safe. Moreover, you would learn all the techniques and tools hackers use to compromise systems, then use those same tools and techniques against cyberattacks to help protect your clients.

20+ Job Roles | 10,000+ Job Openings | Avg. Salary of $93,000

Become a Certified Ethical Hacker.


FAQs

1. How is packet sniffing used for attacking?

Malicious attackers can intrude on any network using a packet sniffer and capture data packets transmitted over a network. Attackers seize data packets to extract client data or any sensitive information.

2. What is a Wi-Fi attack?

Wireless networks are far from being secure. Attackers can create an open and fake Wi-Fi to intercept user data. Wi-Fi attacks are malicious attacks against wireless networks using dubious techniques like man-in-the-middle attacks, DDoS attacks, eavesdropping etc., to steal user information.


References:

  1. https://www.tutorialspoint.com/ethical_hacking/ethical_hacking_sniffing.htm
  2. https://www.jigsawacademy.com/blogs/cyber-security/sniffing/

The Cloud is New Territory for Computer Forensics

Cloud Forensics

Volumes have been written extolling the virtues and benefits of cloud computing. The cloud enables organizations to scale up rapidly and to be more agile. There are cost-savings and efficiencies too, which can be leveraged through various cloud models. But cloud forensics presents new challenges for forensics experts, as it differs vastly from traditional computer forensics.

Today, it is common practice for an organization to adopt a hybrid, multi-cloud approach. That makes cloud security more challenging. If an organization experiences an attack or data breach, it will have to trace the source of the attack, what the damage was, the extent and impact of the attack.

That’s where Cloud Forensics comes in.

When infrastructure is virtualized and hosted by multiple clouds with servers in different jurisdictions, it poses a tremendous challenge to cloud forensics specialists. In fact, doing forensics on the cloud is complicated and differs vastly from traditional computer forensics. With computer forensics, investigators had to find the media that had the data or digital evidence. With the cloud, this evidence could be anywhere and is much more difficult to trace.

The cloud offers various architectures, service models, processes, and continuously changing paradigms. So, it is challenging for investigators to gain access to data and resources required for forensics – the “artifacts,” as they call it. That includes registry keys, files, timestamps, and event logs. This is digital evidence that can be used in a court of law for criminal litigation.

Cloud Forensics Survey

We wanted to determine what are the biggest challenges posed to cloud forensics today. For this, EC-Council’s Cyber Research team undertook a survey titled “Cloud Forensics in Today’s World.”  The report, which appears in the September issue of CISO MAG, uncovers some interesting findings from their investigation:

  • Both multi-tenancy-related privacy issues and distributed data location were considered equally challenging by one-fourth of the respondents.
  • More than half of the respondents believe the hybrid cloud deployment model presents the most challenges towards cloud forensics.
  • Nearly 40% of the respondents say that a lack of channels for international communication contributes significantly to the legal challenges faced by cloud forensics.
  • There is a growing demand that the SLA should mention when and what data to collect, its purpose and legal liabilities.
  • FaaS (Forensics as a Service) is the most anticipated trend towards improving the cloud forensics domain.

Since the cloud is now a shared responsibility, some have suggested that cloud service providers offer Forensics as a Service.  Yes, FaaS is being offered by third parties today. But more CSPs need to offer it.

Shared Responsibility Model

In the cover story, Karim El Chenawi, CISO at John Doe Invest, writes that the shared responsibility model for cloud computing puts the onus of cloud security on both the cloud service provider and the client. And that increases the attack surface for threat actors to exploit. So there is a need for a trustworthy cloud forensic process that overcomes the existing challenges associated with cloud computing and provides clear and actionable data towards security enforcement and incident handling. He suggests that the complete cloud forensic process should be classified into incident identification, data collection, and analysis and examination phases.

ciso mag sept issue cloud forensics
Don’t miss the September 2021 issue. We hope you enjoy reading the Cover Story, Survey Report, and other curated articles from industry experts.
Click Here to Subscribe to CISO MAG

 

 

After FIN8, Researchers Warn About FIN7 Hackers Exploiting Windows Docs

Altering certified PDF Documents, FIN7 Hackers

Attack vectors range from malicious attachments to weaponized PDFs.  These vectors have been continually evolving over the years. Recently, security experts from Anomali uncovered a malicious phishing campaign that used weaponized Windows 11 Alpha-themed Word docs with Visual Basic macros to deploy malware backdoors like JavaScript payloads. Anomali attributed the malicious attacks, suspected of occurring between June to July 2021, to the infamous threat actor group FIN7.

“While we cannot conclusively identify the attack vector for this activity, our analysis. We suggest the attack vector was an email phishing or spear-phishing campaign. We assess with moderate confidence that the financially motivated threat group FIN7 is responsible for this campaign,” Anomali said.

FIN7 Hacking Group

Active since 2015, the FIN7 is an Eastern European cybercriminal group that primarily targeted organizations across the U.S. Anomali stated that the FIN7 group is responsible for the theft of over 15 million payment card records worth one billion dollars. It’s estimated that the gang targeted around 100 organizations and compromised their networks.

“FIN7 is one of the most notorious financially motivated groups due to the large amounts of sensitive data they have stolen through numerous techniques and attack surfaces. Things have been turbulent for the threat group over the past few years, as with success and notoriety comes the ever-watchful eye of the authorities. Despite high-profile arrests and sentencing, including alleged higher-ranking members, the group continues to be as active as ever,” Anomali added.

Infection Chain

Attackers initiated the infection process by sending a Microsoft Word document containing a decoy image claiming to have been made with Windows 11 Alpha. The image then asks the user to Enable Editing and Enable Content to begin the next stage of the malicious activity.

The primary aim of the FIN7 group is to pilfer sensitive financial information like credit/debit card details and trade them on underground darknet marketplaces. FIN7 targeted a California-based point-of-sales (POS) technology provider to obtain payment card data and later sell the information for monitory benefits. The FIN7 actors are responsible for stealing over 15 million card records from 6,500 POS terminals.

In a similar threat analysis, cybersecurity experts from Bitdefender uncovered a new financially motivated malware campaign by the infamous threat actor group FIN8, circulating a new version of its BADHATCH malware, tracked as Sardonic. Read More Here

U.S. Cyber Command Warns Active Exploitation of Atlassian Confluence Vulnerability

Zoho Vulnerability , Atlassian Confluence Vulnerability

Organizations in the U.S. continue to sustain series of unpatched vulnerability exploits. The U.S. Cyber Command (USCYBERCOM) recently warned organizations to patch the actively exploiting Atlassian Confluence critical vulnerability CVE-2021-26084 immediately.

“Mass exploitation of Atlassian Confluence CVE-2021-26084 is ongoing and expected to accelerate. Please patch immediately if you haven’t already — this cannot wait until after the weekend,” USCYBERCOM said.

Atlassian Confluence Vulnerability

The CVE-2021-26084 vulnerability is an Object-Graph Navigation Language (OGNL) injection flaw that affects Atlassian Confluence Servers and Confluence Data Center software installed on Confluence self-hosted project management platforms. The vulnerability enables an unauthenticated hacker to execute arbitrary code on Confluence Server or Data Center installations.

The vulnerability was discovered by Benny Jacob (SnowyOwl) in the Atlassian public bug bounty program.

Affected versions include:

  • version < 6.13.23
  • 14.0 ≤ version < 7.4.11
  • 5.0 ≤ version < 7.11.5
  • 12.0 ≤ version < 7.12.5

Atlassian Releases Patch

In a security advisory, Atlassian detailed the severity and impacts of the vulnerability. It said, “The vulnerability is being actively exploited in the wild. Affected servers should be patched immediately. The vulnerability is exploitable by unauthenticated users regardless of configuration.”

Atlassian recommended organizations identify vulnerable devices and update them to the latest Long Term Support release to avoid potential risks.

What the Experts Say…

The latest warning from the U.S. Cyber Command created a buzz in the cybersecurity community. Security experts from threat intelligence firm Bad Packets claimed it has identified a mass exploit activity targeting vulnerable Atlassian Confluence servers across the U.S., Brazil, Hong Kong, China, Nepal, Romania, and Russia.

Also, security firm Censys that it detected over 14,701 services that self-identified as a Confluence server. Of those, 13,596 ports and 12,876 individual IPv4 hosts are running an exploitable version of the software.

Ransomware Vulnerabilities That Could Bring Down Your Organization

ransomware, fonix, fonix ransomware, Cybereason Partners with Intel for Hardware-Enabled Ransomware Prevention, Kronos

Today, 266 vulnerabilities are associated with ransomware, and attackers are increasingly exploiting these weaknesses to launch devastating ransomware attacks. Therefore, identifying and remediating these vulnerabilities needs to be a critical priority for organizations if they wish to remain safe from ransomware attacks.

By Ram Movva, Chairman and Co-founder of Cyber Security Works 

We have witnessed dangerously disruptive ransomware attacks in 2021. The ransomware attacks on Colonial Pipeline, JBS USA Holdings, Kaseya, and Accenture — the most recent victim of LockBit — are proof that the lack of cyber hygiene is rampant. These attacks highlight the need for the continual assessment of vulnerabilities and the prioritization of remediation.

As our research in ransomware expands, we have updated our Q1 report with new ransomware markers and emerging trends that would help organizations worldwide to stay a step ahead of attackers and proactively defend themselves against such attacks.

In the Q2 Index Update, we highlight the following:

  • Insights about vulnerabilities that have recently become associated with ransomware
  • New Advanced Persistent Threat (APT) groups using ransomware in their attack arsenal
  • Newly discovered ransomware families
  • Categories of weaknesses that have contributed vulnerabilities to ransomware
  • Emerging ransomware trends

New Vulnerabilities in the Ransomware Arsenal

In this quarter, our research shows that six vulnerabilities have become associated with seven ransomware strains; among them are the infamous Darkside, Conti, FiveHands, and the newly christened, Qlocker.

With this update, the total number of vulnerabilities associated with ransomware has increased to 266. We have also noticed a 1.5% increase in the number of actively exploited vulnerabilities that are trending currently, reiterating that a risk-based approach for the remediation of vulnerabilities is the need of the hour.

One of the most compelling observations during this quarter was the exploitation of zero-day vulnerabilities even before vendors published their discovery or released patches.

On April 19, 2021, thousands of QNAP devices were attacked by Qlocker, causing service disruptions and data loss for its users. Qlocker had compromised CVE-2021-28799, a QNAP zero-day vulnerability discovered only on April 22, 2021—for which a patch was published on May 1, 2021. Meanwhile, the attackers had already made more than $350,000 in ransom money, even while the vendor was still investigating the incident. The National Vulnerability Database (NVD) released details about this vulnerability 11 days after the patch was released.

Timeline of Common Vulnerabilities and Exposures (CVE) -2021-28799

The FiveHands ransomware attack on SonicWall Virtual Private Network (VPN) devices is yet another example that showcases the need for a risk-based approach. In this case, SonicWall had published details about CVE-2021-20016 on January 23, 2021, and the patch was scheduled to be released on February 03, 2021. However, attackers struck before the patch was published. The NVD added the vulnerability to its database on February 04, 2021.

Timeline of Common Vulnerabilities and Exposures (CVE) -2021-20016

Both incidents highlight the following:

  1. Organizations that depend only on updates released by the NVD to plan their remediation and patch management need to rethink their strategy and adopt a risk-based approach to mitigate trending threats.
  2. With ransomware attackers going after zero-day vulnerabilities, vendors must proactively release patches without delays.
  3. Software developers need to be more mindful about coding errors and misconfigurations, ensuring they do not introduce weaknesses that attackers could compromise to launch crippling attacks.

Vulnerability Analyses

Exploit Type

Our research also focuses on the type of exploit linked to ransomware-related vulnerabilities. For instance, Remote Code Execution (RCE) and Privilege Escalation (PE) are the most dangerous vulnerabilities that attackers weaponize and exploit.

Since the publication of the ransomware report in February 2021, we have observed that 43 vulnerabilities have become associated with ransomware this year, and 35% (15 vulnerabilities) have been categorized as RCE/PE exploit types. In this quarterly update, we observed that RCE/web application exploit CVE-2018-13374 has been associated with Conti ransomware.

Overall, 40% of vulnerabilities (107) tied to ransomware are categorized as RCE/PE exploits. Our recommendation to organizations is to prioritize these vulnerabilities and patch them first.

Low-Scoring Vulnerabilities

Low-scoring vulnerabilities deceptively fly under the radar. Security teams tend to sideline low-scoring vulnerabilities and patch vulnerabilities based only on their Common Vulnerability Scoring System (CVSS) version3 (v3) or version2 (v2) scores. Such organizations will still be vulnerable to ransomware attacks because 59% of the vulnerabilities associated with ransomware are low-scoring* ones.

In our quarterly update, we have seen a 3.9% increase in low-scoring vulnerabilities linked to ransomware. While security teams may overlook these vulnerabilities, risk-based platforms will flag these vulnerabilities as high-risk despite the low score provided by the NVD. However, many organizations do not use or remain unaware of such tools, leaving their low-scoring vulnerabilities unpatched and their network open to a ransomware attack.

*CVSS v2 scores less than eight were considered low-scoring for the ransomware research report.

Actively Exploited Vulnerabilities

While vulnerabilities that have become associated with ransomware should always be considered high risk and must be prioritized for remediation, we also look at those Common Vulnerabilities and Exposures (CVEs) that are currently trending in hacker channels and being exploited in the wild.

At present, 134 vulnerabilities are being actively exploited. Security teams will need to move these vulnerabilities to the top of their patching list because these weaknesses are being increasingly compromised to launch damaging ransomware attacks.

New APT Groups

We have been observing an increase in APT group attacks since the beginning of this year. From SolarWinds to DarkSide’s attack on the Colonial Pipeline, APT groups have targeted critical industries and sectors and have added ransomware to their arsenal to mount disruptive attacks.

In this quarter, we have noted a 17% increase in the number of APT groups adopting ransomware as part of their arsenal to mount attacks on their targets. This brings the total number of APT groups with ransomware associations to 40.

New Ransomware Families

This quarter also brought about a 4.2% increase in ransomware families, with six new families joining the fray. Our findings show that the Crypwall ransomware family retains its position as the biggest ransomware family in the world, with 66 CVEs within its fold. In this quarter, we have also noted that the Cerber strain has overtaken Locky with 65 CVEs tied to ransomware.

Comparatively, new ransomware families are focused on much smaller vulnerability packages for exploitation. For instance, Apostle, DarkRadiation, FiveHands, and Qlocker exploit one vulnerability each. The Epsilon Red Group has three CVE associations, DarkSide has four associations, and Pay2Key has five associations.

New CWE Categories

Significantly, we have spotted two new Common Weakness Enumeration (CWE) categories during our research—CWE-134 (Use of Externally Controlled Format String) and CWE-732 (Incorrect Permission Assignment for Critical Resource).

CWE-134 is a weakness that, when combined with an unauthenticated RCE vector, can directly allow hackers to access the victim’s machine. Also, attackers can use these CWEs along with others in a chain to achieve their malicious motives.

CWE-732 leads to incorrect Permission Assignment for Critical Resource that can result in the exposure of sensitive information. It exposes VPN credentials in cleartext or an easily readable format, thereby allowing the VPN to be easily compromised. There is also a strong possibility of attackers using attack chaining to infiltrate the victim’s network. Software developers need to ensure that they do not introduce these weaknesses in their products while they write code.

Old Vulnerabilities

There has been a marginal increase in the number of old vulnerabilities that have recently become associated with ransomware. CVE-2017-1000253, CVE-2018-13374, and CVE-2019-1579 have been linked to DarkRadiation, Conti, and Pay2Key, respectively, in this quarter. This brings the total count of older vulnerabilities (published in or before 2020) associated with ransomware to 255, which is 95% of the total number of ransomware vulnerabilities.

The Way Forward

The most recent ransomware attacks have been so disruptive that they are considered acts of war, prompting world leaders to politicize these attacks with those countries where the ransomware seems to have originated.

Based on our research, ransomware vulnerabilities have been steadily increasing each quarter, and attackers are finding innovative ways to compromise and exploit weaknesses in software products and devices. As we head into Q3, we will be tracking zero-day exploits and the association between APT groups and ransomware.

Organizations can combat ransomware only with accurate vulnerability data aligned with the relevant threat context. A risk-based approach to detect, prioritize, and remediate these vulnerabilities would keep the attackers at bay. Our recommendation would be to adopt continuous vulnerability management to help organizations mitigate ransomware threats, even as they trend.

Watch out for our next quarterly update to get the latest statistics, exploits, and trends on ransomware!


Ransomware Research

RiskSense, a risk-based vulnerability management company (recently acquired by Ivanti), has been tracking ransomware attacks since 2019 — when they published their first report. In 2020, RiskSense, along with Cyber Security Works, investigated and identified the vulnerabilities tied to ransomware, and the Spotlight Report was published in February 2021. Since the vulnerabilities associated with ransomware have been steadily increasing, we have decided to release quarterly reports with updates on important metrics. The next quarterly report is due in October 2021.


About the Author

Ram MovvaRam Movva, the Chairman and Co-founder of Cyber Security Works (CSW), is an industry expert in offensive security and intrusion detection. With a master’s degree from Georgia Tech, Movva was with TIBCO for over a decade. He was also part of the founding team at RiskSense, a risk-based vulnerability management company. After spending 15 years in the U.S., Movva co-founded CSW in 2008. Under his strategic leadership, CSW has enabled companies worldwide to improve their security posture.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.