Home Blog Page 58

Top 10 Common Types of Network Security Attacks Explained

Microsoft, Cyberattack on Olympus

The risk of network security attacks is mounting as businesses transition to a remote work environment and embrace sophisticated technology.

The IT (Information Technology) and security professionals’ roles are also evolving rapidly. Most organizations entrust them to keep all network endpoints secure to prevent theft and damage.

With online shared resources for storing sensitive data and trade secrets gaining prominence, and data exchange moving to cloud infrastructure, the risks are enormous.

So, what are network threats? This article explains network attacks, the common types of network security threats and attacks to give you a better understanding.

Network Security Attacks Explained

Cyberattacks in the form of data theft, ransomware etc., can bring the operations of any organization to a halt. For instance, the ransomware attack on Colonial Pipeline on May 7, 2021, disrupted entire operations, and it is labeled as one of the most significant cyberattacks on American energy architects.

Network security attacks attempt to disrupt an organization’s operations, steal data, or corrupt files by gaining unauthorized access to the company’s network.

So, these threats are a matter of grave concern, and therefore, it is even more critical for companies to secure their network from network breaches.

Cybercriminals intrude on an organization’s network and system for numerous reasons. The motives behind the actions of cybercriminals can range from greed and political reasons to personal espionage and competition. So given the damage cyberattacks can cause, they are detrimental to a company’s finances and balance sheet and hampers their reputation.

Therefore, an organization must have a skilled cyber workforce who can design robust network security policies to protect their client data and other digital assets.

Network engineers, IT and Security professionals, system analysts and administrators should all have a sound knowledge of network security attack types to detect, analyze and mitigate the risks.

Therefore, it is essential to learn of the common network security threats to minimize the risk of a data breach.

Common Types of Networking Attacks

We have previously mentioned how network threats and attacks can hinder your network security and applications. Furthermore, as people become more reliant on digital communication technologies, common types of networking attacks are on the rise. Here, we discuss the top 10 networking threats and attacks.

1. Computer Virus

Computer viruses are one of the most common network security attacks that can cause sizeable damage to your data.

A type of malware, they are unique pieces of code that can wreak havoc and spread from computer to computer. Did you know that computer viruses poison at least 30% of the world’s computers? Malware infections are quite common, and a virus-like Trojan horse can severely damage a system network. If you click on an email with a malicious link or download links from infected websites, these viruses can corrupt your files, infect other computers from your list and steal your personal information.

 2. Malware

One of the most dangerous cybercrimes that can cause massive damage is a Malware attack. Hackers attempt to gain unauthorized access into the target system and disrupt or corrupt the files and data through malicious codes called malware. Moreover, it can affect both internal and external endpoint devices of a network.

3. Computer Worm 

Computer worms are nothing but a malicious type of software that spreads from one infected computer to the other by duplicating copies. They further their objectives by exploiting network vulnerabilities. Moreover, it can affect your system without any help from external users.

4. Phishing

Another common type of network security attack is phishing which is a form of social engineering attack. Cybercriminals trick users into clicking on a fraudulent email link or message which appears legitimate. So, when unsuspecting targets click the link, the malware is downloaded into their phones or systems, allowing the hackers to steal sensitive data or information such as credit card numbers or banking passwords.

5. Botnet

Botnets comprise the network of compromised systems connected to the Internet. The hacker gains access to all these devices on the network and manipulates the bots to send spam, perform data theft and enable DDoS (Distributed Denial of Service) attacks.

6. DoS (Denial of Service) and DDoS Attacks

All of us must have experienced website crashes at some point or the other. Sometimes, the server can crash due to a surge in the website traffic either due to a product launch, a new promotional plan, or a sale.

However, website crashes also happen due to cyberattacks in the form of DoS and DDoS attacks. As a result, the system crashes because of malicious traffic overload, and the users cannot access the website. These types of network security attacks aim to cripple the IT infrastructure of the victim network.

The difference between DoS and DDoS attacks is that hackers launch DoS attacks through one host network. DDoS attacks are more sophisticated, and attackers can use several computers to exploit targeted systems. Since the attack is launched from several compromised systems, it’s hard to detect DDoS threats.

7. Man-in-the-middle

Another generic form of network threats arises out of MIM (man-in-the-middle) attacks. In this type of cyberattack, black hats hijack the private communication intended between two parties. By intercepting the communication, the attacker tries to monitor and control their messages to either disrupt files, steal confidential data or spy on the victims.

8. Ransomware

Ransomware attacks have gained momentum in 2021. We have witnessed a bevy of such threats recently that have had severe repercussions. Ransomware is malicious software that hackers encrypt all files on target systems, networks, and servers. Other ransomware campaigns can gain access to a network and lock files until a ransom is paid in exchange for the decryption key by exploiting weak passwords and other vulnerabilities.

9. 5G Based Attacks

5G-based attacks are a  more advanced form of network security threat. While 5G networks enable high-speed transfers of data, it also raises the risk of cyberattacks. Hackers are attacking multiple systems, mobiles, and IoT (Internet of Things) networks using 5G devices to deploy swarm-based network security attacks. The attacker can also make changes in real-time.

10. SQL Injection Attacks

SQL Injection attacks are one of the most common attack vectors that hackers use to steal data. This type of network attack is common on poorly designed applications and websites. Since they contain vulnerable user-input fields (such as search and login pages, product and support request forms, comments area, and so on) that hackers can easily hack by changing the scripts.

SQL injection attack is a severe threat and one of the major attack vectors that hackers use. Moreover, it can easily infect or exploit any website that uses a SQL-based database.

We explained the importance of network security measures previously. But to implement these measures, an organization needs to have a qualified workforce with the required skill set.

Therefore, companies need a skilled Network Defender to keep their businesses afloat and safe from network adversaries. Hence, upskilling your team with a credible program in network defense is the key to staying one step ahead of cybercriminals.

Join the Certified Network Defender (C|ND) Program  

If you are looking for a credible program to upskill your talent or wish to train your IT employees in network defense, EC Council’s Certified Network Defender (C|ND) certification program is the next-generation network training you need. The program modules aim to convert network administrators into network defense experts.

Network security goes beyond just configuring firewall security or installing an antivirus. Increasing network security attacks pose a serious threat to organizations’ cybersecurity measures. Network defenders protect your systems from falling prey to malware, ransomware attacks, and other security breaches.

Recognized and Accredited by DoD 8570 & ANSI/ISO/IEC 17024

Get your Network Security Certification at EC-Council


FAQs

  1. What can be the impact of a network attack?

Network security attacks can affect your organization’s reputation and lead to data theft and damage. With online shared resources for storing sensitive data and trade secrets gaining prominence, and data exchange moving to cloud infrastructure, the risks are enormous.

  1. What is the biggest threat to network security?

No network, no matter how secure, is safe from intrusions and cybercriminals. Some of the severe emerging threats to network security are DDoS attacks, man-in-the-middle attacks, phishing attacks, inadequate network protocols, and ransomware attacks.


References:

  1. https://securitytrails.com/blog/top-10-common-network-security-threats-explained
  2. https://blog.newcloudnetworks.com/10-types-of-network-security-attacks

How Can You Identify Network Security Threats and Vulnerabilities?

Network Security Threats, SSID Stripping

Network security threats have become a much bigger issue today. With the expansion of Internet services and the increasing remote work culture, network vulnerabilities will only grow by leaps and bounds.

Whether it’s a home or business network, security from unauthorized intrusions is of utmost importance to protect your sensitive information from damage and theft.

So, how can organizations detect and mitigate the threats to network security? This article attempts to explain network security threats, their importance, network security threat types, and how one can identify them.

What Are Network Security Threats?

Network security threats are illegal intrusions into your organization’s network, resulting in a ransomware attack in the absence of robust security protocols. Cybercriminals exploit network vulnerabilities for personal gain or to disrupt operations. All facets of our lives are digitalized, and with the heavy reliance on Internet, damage from a computer virus is one of the most common security threats that we need to mitigate. DoS (Denial of Service) and DDoS (Distributed Denial of Service) attacks, Trojan Horse, spyware etc., are other dangerous forms of network threats that can affect your organization. We shall learn of such types of network security threats later in this article.

Given the unprecedented rise in cyberattacks arising out of network security loopholes, one cannot undermine the need for robust network security tools and experts, which leads us to the next section of this article.

Importance of Network Security

In the wake of the recent cyberattacks, organizations need to take robust security measures to protect their online data from theft and damage.

Network security ensures the safety of your businesses’ shared resources and client data using the appropriate tools and techniques.

However, for implementing the appropriate security testing techniques, one needs to have the right skill set. Therefore, the need for Certified Network Defenders in organizations is growing steadily.

An ordinary person with limited knowledge of systems security may not know how to detect anomalies and nip them in the bud. Businesses need to have a skilled and Certified Network Defender who can measure the risks and evaluate them accordingly. Without a skilled resource, a company’s chances of falling prey to cyberattacks are quite high. Network defenders need to understand the different types of network attacks so that they can differentiate them from other types of network security threats.

Next, we shall learn of the distinct types of network security threats and how you can identify network flaws.

What Are the Four Main Types of Network Security Threats?

1. Structured threats

Structured threats are a direct form of attack intended for a specific target chosen through some random search. They are a part of organized attacks that a malicious hacker or a group of hackers execute to disrupt a network or system security. Racial and political motives, personal espionage, international terrorism etc., are just a few of the reasons which lead to direct attacks. The hackers are skilled professionals who know the system and network flaws and work around them to launch their attack—all such types of cybercrime or attacks which are not tied to the hacker comprise the structured threats.

2. Unstructured threats

Unstructured threats fall under the category of indirect attacks that amateurs carry out with minimal knowledge. So, these disorganized threats are vague and ambiguous. While the intent of these attacks may not always be malicious, the result could have a rippling effect. Most amateurs execute these attacks simply out of curiosity or for showing off.

3. External threats

Attacks that stem from outside the targeted organization without any authorized access to the network are external threats. The perpetrators who compromise the security from outside the organization use dial-up access, malicious software, phishing techniques etc, to further their objectives.

4. Internal threats

Internal threats are the attacks that originate from within the targeted organization to disrupt network security. They could be current or former associates who have authorized access to data files, systems, networks etc. Such threats can incur huge losses to the organizations if left unidentified.

Network security vulnerabilities are detrimental to an organization’s reputation and operation. So, how can one detect the loopholes in network security before the hackers do? Let’s find out.

How Can You Identify Network Security Threats?

To defend your network security, you need to have a skilled Network defender who can secure your network and identify the network threats before cybercriminals do. Next, we shall understand four different ways to detect network flaws.

1. Ensure network visibility

Most people miss out on the first major step to monitor their network for any loopholes or system flaws. Therefore, network visibility is important. Your organization’s network defender should think like the black hats to identify the potential vulnerabilities and prevent intrusions. Consider it this way: if you need to defend yourself from outside forces, you’ll first put security measures in place inside your home. You’ll cover all the bases and imagine yourself in the shoes of your adversary, envisioning how they might harm you. You must be aware of your territory to do so. Similarly, to protect your organization’s network from hackers, you must ensure that your network is visible, set up security protocols, and mitigate the risks.

2. Set up computer and network access

Given the number of security breaches and intrusions, a network defender should ensure that not everyone is allowed a significant level of access to the company’s system and networks. One can never eliminate internal threats. Therefore, preventive measures are essential to protect an organization’s digital assets. Setting up controls for computer and network access is one such step. Therefore, drafting and executing corrective network security measures are essential to identify potential risks and lay out a recovery plan if the need arises.

3. Firewall configuration

Configuring your system with a network firewall can block unauthorized or unwanted network traffic or intrusions. Another effective way to identify threats is configuring firewalls to detect suspicious activities, malware, or anomalies by scanning incoming traffic and block them.

4. Penetration Testing

One of the best ways to ensure that your network defense is robust is to conduct pen tests. A penetrating test helps businesses identify their network vulnerabilities and take corrective measures to rectify them.

So, it goes without saying that the role of network defenders is paramount. Without a certified network defender to patch your network flaws and mitigate the vulnerabilities before cybercriminals do, your business can take a massive hit.

However, mapping your workforce to the appropriate skill set that can help prevent network security threats is also crucial. EC Council’s Certified Network Defender (C|ND) program is designed to help aspirants with the skills required to detect network threats and devise security measures.

Why Should You Pursue Certified Network Defender Program?

EC Council’s Certified Network Defender program aims to train IT professionals and equip them with the skills they would need to defend and mitigate network security attacks. The program modules are framed by industry experts and include hands-on lab training, updated tools, and resources to tackle real-world scenarios. C|ND focuses on comprehensive network training and defense training to churn out efficient Network Defenders. This certification teaches participants to use threat intelligence to predict cyberthreats before they occur.

So, if you are ready to manifest your IT and networking skills to the best of your knowledge and increase your network defense skills, the C|ND program is just right for you.

Recognized and Accredited by DoD 8570 & ANSI/ISO/IEC 17024

Get your Network Security Certification at EC-Council


FAQs

  1. What are some threats to your network security?

The five common security threats that businesses and organizations face are phishing attacks, ransomware, malware attacks, data breaches and insider threats.

  1. How can you mitigate network security threats?

With cybercrimes rapidly evolving and increasing at light speed, organizations can take some robust measures to defend their networks. Using network protection measures like installing a firewall, using a virtual private network (VPN) etc., you can protect your network traffic. Other measures include monitoring your access control and keeping your software updated from time-to-time.


References:

  1. https://www.cynet.com/network-attacks/network-attacks-and-network-security-threats/
  2. https://securityscorecard.com/blog/identify-network-security-threats-and-vulnerabilities

Ireland Data Regulator Fines WhatsApp $266 Mn Over GDPR Violations

Ireland DPC fine on WhatsApp

Days after suffering a malware attack, WhatsApp now faced a massive penalty from Ireland’s Data Privacy Commissioner (DPC) with a €225 million ($266 million) fine for violating the GDPR guidelines. The DPC’s investigation on WhatsApp Ireland Ltd., which commenced on December 10, 2018, concluded that the Facebook-owned messaging service provider has failed to maintain the transparency of data belonging to both users and non-users of WhatsApp services. It revealed that WhatsApp had not informed its users about the processing of information between WhatsApp and other Facebook companies.

In July 2021, the European Data Protection Board (EDPB) instructed the DPC to reassess and increase its proposed fine. Following this, the DPC has imposed a fine of €225 million under transparency infringements. As per GDPR guidelines, organizations processing users’ information should be transparent and notify their users and keep them informed.

In addition to the penalty, the DPC also ordered WhatsApp to bring its processing into compliance by taking a range of specified remedial actions.

What WhatsApp Says…

Responding to the DPC’s decision, WhatsApp stated that it will appeal. “We disagree with the decision today regarding the transparency we provided to people in 2018, and the penalties are entirely disproportionate.”

What Experts Say…

The latest penalty on WhatsApp has triggered many debates and viewpoints in the cybersecurity community. Commenting on the fine, Max Schrems, a European privacy expert and Chair of non-profit noyb.eu, said, “WhatsApp will surely appeal the decision. In the Irish court system, this means that years will pass before any fine is paid. In our cases, we often had the feeling that the DPC is more concerned with headlines than with actually doing the hard groundwork. It will be exciting to see if the DPC will fully defend this decision, as its European counterparts were forced to make it. I can imagine that the DPC will not put many resources on the case or ‘settle’ with WhatsApp in Ireland. We will monitor this case closely to ensure that the DPC is following through with this decision.”

FIN8 Hackers Found Using Sardonic Malware to Attack Financial Institutions

Sardonic, BitMart

Information of companies and their staff published on the dark web makes financial companies and their employees a primary target of cybercriminals. Recently, cybersecurity experts from Bitdefender uncovered a new financially motivated malware campaign by the infamous threat actor group FIN8, circulating a new version of its BADHATCH malware, tracked as Sardonic. Active since January 2016, the FIN8 gang is known to launch attacks on finance companies.

Sardonic – A New Backdoor in the FIN8 Ecosystem

The researchers stated that Sardonic malware has several new components that were reportedly created just before the attack. The Sardonic backdoor has a wide range of capabilities helping attackers create new malware variants instantly without updating the components.

“FIN8 is known for taking extended breaks to improve their tactics, techniques, and procedures (TTPs), which increases their success rate. With each new version of their toolkit, they start with small tests on a limited pool of victims before launching a full-scale attack,” Bitdefender said in a statement.

FIN8’s Living off the Land Attack (LotL)

FIN8 primarily targets companies that provide financial services and their POS (point of sale) terminals via living off the land (LotL) attacks. In LotL attacks, hackers leverage tools or techniques that already exist in the threat landscape. Bitdefender researchers found FIN8 actors using built-in tools and interfaces such as PowerShell or WMI and exploiting legitimate services like sslip.io to hide their malicious activities.

In addition, FIN8 actors leverage different hacking vectors, including:

  • Social Engineering
  • Malicious Payload Download
  • Lateral Movement
  • Trial and Error to overcome defenses
  • Attempt to establish persistency

Remediation

Bitdefender team also recommended security measures to minimize the impact of this malware. These include:

  • Separate the POS network from the ones used by employees or guests
  • Introduce cybersecurity awareness training for employees to help them spot phishing emails.
  • Tune the email security solution to automatically discard malicious or suspicious attachments.
  • Integrate threat intelligence into existing SIEM or security controls for relevant Indicators of compromise.
  • Small and medium organizations should consider outsourcing security operations to managed detection and response providers.

5 High Paying Computer Forensics Jobs You Need to Know

computer forensics job

Computer forensics job prospects are also rising, owing to an unprecedented rise in cybercrime because of a shift to remote work and digital reliance.

Ransomware attacks in 2021 have highlighted the necessity for digital forensics investigators to evaluate and probe security breaches. It’s no surprise that the Kaseya attack, Colonial Pipe Attack among several high-profile cybercrimes, heightens the need for expanding digital forensics infrastructure.

Computer forensics is crucial for tracing the perpetrators’ digital footprints and solving the missing puzzle related to cyberattacks. Digital forensics experts gather and preserve the information or evidence. After that, the investigator examines the system, computer files etc., to identify the changes, how it was changed, and track the perpetrator.

Digital forensics is a growing field that will only expand in the future to accommodate the demand for cybersecurity specialists. This article talks about the top high-paying forensic jobs and their respective salaries.

Before that, let’s help you understand why this field is a career opportunity.

Is Computer Forensics a Promising Career?

There is a growing demand for computer forensics jobs to solve cybercrime. A report forecasts the digital forensics market to reach $8,210.5 million by 2026. Digital forensics methods are applied to crack cases ranging from human trafficking to aiding companies to recover data from cyberattacks. And with the cases piling up, there will be a high demand for computer forensics job roles in the future.  Exploring this field can open a multitude of opportunities for you. So, let’s learn of some of the highest paying computer forensics job roles along with the respective salaries.

Computer Forensics Job Salary

According to PayScale, the average salary for a computer forensic analyst is $75,073. The median salary for an entry-level computer forensic analyst is $65,371, according to Salary.com.

Again, what you can earn as a forensic computer analyst depends on a combination of factors like location, certifications, and expertise.

There are many computers forensic jobs in the market, with employers looking out for IT and Security professionals to identify cybercrime and secure and recover their sensitive and crucial data in case of a security breach.

Next, we shall learn of some highest-paying computer forensics job prospects.

What Are the Highest Paying Forensics Job Roles?

The field of computer forensics science is rife with opportunities. However, what you can earn depends on your qualifications, skill set, and your experience.

1. Cybercrime Investigator

If you have analytical and problem-solving skills, taking up the job role as a Cybercrime Investigator can be rewarding. From identity theft, fraud to money laundering and cyberbullying, a cybercrime investigator works to gather evidence for all these crimes in cyberspace. One can look forward to earning an average salary of $92,432 per year, according to SimplyHired.

2. Malware Analyst

Malware Analyst is one of the top paying computer forensics job profiles.  One can earn a median salary of $92,880 per year, according to PayScale. The role of a Malware Analyst is to identify, examine and report cyberthreats. Sound knowledge in Programming languages and learning data recovery techniques can certainly pave the way for your career as a Malware Analyst.

3. Forensic Accountant

A plurality of cybercrimes these days involve financial scams such as illegal transactions and money laundering. In such cases, forensic accountants play a pivotal role in investigating security breaches and analyzing computers and information technology.

A forensic accountant can expect to earn an average base salary of $71,464 per year, as per PayScale. Furthermore, they can expect to grow in their field and earn up to $101,648 per annum.

4. Forensic Computer Analyst

According to PayScale, a Forensic Computer Analyst with forensics skills earns a medium $73,851 per annum.

A forensic computer analyst investigates the data in the computer and network to present evidence in legal proceedings. They help law enforcement in retrieving data from computers, hard drives etc., in cybercrimes. After a thorough analysis, they use various tools and techniques to recover deleted files and retrieve information. So, if this field excites you, you can acquire the necessary skills to analyze computer hard drives and storage devices.

5. Information Technology Auditor

An Information Technology Auditor can expect to earn an average salary of $64,894 per year, according to Salary.com. PayScale forecasts that people with over ten years’ experience can earn anything between $100,000 and $118,000.

Information Technology Auditor is a significant role in the field of computer forensics. The key roles are to detect security flaws in networking systems, measure the risk factors, and offer security solutions. So, if you are passionate about finding loopholes in network security, you will find this field rewarding.

Other competitive forensics job roles are Cyber Defense Analyst, Information Security Analyst, Mobile Forensics Expert, Intelligence Technology Analyst, Cryptanalyst, Security Consultant, and more.

If you plan to kickstart your career in computer forensics, EC Council’s C|HFI certification can open endless opportunities for you.

Start a Career in Digital Forensics With EC-Council’s C|HFI Certification Program

The Computer Hacking Forensic Investigator (C|HFI) certification program by EC-Council aims to enhance the participant’s competence in identifying an intruder’s footprints. The modules also train individuals to gather all the relevant digital evidence needed to prosecute the perpetrator in a court of law.

C|HFI trains its participants in the core concepts of digital forensics, giving a methodological approach to computer forensics and evidence analysis that circles Dark Web, IoT, and Cloud Forensics. The program modules include using ground-breaking forensics tools and techniques to help the learner successfully execute digital investigations, identify complex security threats, and assist in data recovery programs.

One must also learn basic network defense skills or IT or cybersecurity experience before pursuing a career in digital forensics.

A career in computer forensics science comes with promising opportunities. The demand for a skilled computer forensic analyst will only increase with the rising complexities of cyberattacks. So, getting a computer forensics degree and acquiring the necessary skills will broaden your opportunities and allow you to land a high-paying job.

20+ Job Roles | 4,000+ Job Openings | Avg. Salary of $96,000

Start your C|HFI Certification and Explore New Career Opportunities in the World of Digital Forensics.


FAQs (Frequently Asked Questions)

1. What is the role of computer forensics in an investigation?

To gather the digital forensics evidence in case of cybercrime, one can understand the role of a computer forensics expert in three steps to track the attacker:

  • Preserving or securing the digital device
  • Analyzing the state of digital device
  • Reporting retrieved information

2. How Does Computer Forensics Work?

The importance of digital forensics in investigating cybercrime is paramount. It is a branch of forensic science that examines and analyzes devices that store digital information. Your hard drive, computer, network, phone, server etc. are a few examples that comprise this infrastructure.

Computer forensics investigators can gather crucial information from computer documents, texts, online transactions, and other digital footprints to present key evidence in cybercrime. Everything we do has moved online, starting from storing to sharing information on cloud infrastructure. Forensic investigators can round up shreds of evidence from your cloud-based backup systems and access your text messages, images, videos, emails, and restore the deleted files as well.


References:

  1. https://searchsecurity.techtarget.com/definition/computer-forensics
  2. https://www.gmercyu.edu/academics/learn/computer-forensics-career-guide
  3. https://www.eccouncil.org/programs/computer-hacking-forensic-investigator-chfi/
  4. https://www.forensicscienceonline.org/top-careers/

Beware! Hackers Found Exploiting Proxyware to Sell Users’ Internet Connection

Proxyware

It’s common for threat actors to leverage a variety of new malicious techniques for financial gain. Recently, security experts from Cisco Talos uncovered a new kind of threat vector in which attackers are misusing users’ internet connections to monetize their malware campaigns. Internet-sharing services or Proxyware platforms like Honeygain and Nanowire are being exploited to sell users’ internet bandwidth without their knowledge.

What is Proxyware?

Proxyware is a software that allows enterprises to share a percentage of their (unused) internet bandwidth with others in exchange for nominal fees. For this, users should install the client application to join their network operated by a Proxyware platform provider and sell their internet access to other users.

The researchers stated that threat actors are leveraging multiple hacking techniques to monetize Proxyware platforms. Several malware campaigns and malicious cryptocurrency mining operations are using these platforms to monetize the internet bandwidth of victims.

“As Proxyware has grown in popularity, attackers have taken notice and are now attempting to exploit this interest to monetize their malware campaigns. Trojanized installers are some of the most common threats taking advantage of public interest in Proxyware to infect victims. These applications pose significant privacy and operational risks to organizations as they may allow nefarious or abusive network traffic to appear as if it originates from their corporate networks resulting in reputational damages that may also lead to service disruption,” Cisco Talos said.

The researchers claim to have identified a malware family exploiting the patched version of the Honeygain client and Nanowire client Proxyware applications.

Mitigation

Organizations should be aware of the implications of internet sharing platforms as they pose severe risks to critical corporate networks. Security admins should learn how the Proxyware services work and how they are being abused if not secured.

“This is a recent trend, but the potential to grow is enormous. We are already seeing serious abuse by threat actors that stand to make a significant amount of money off these attacks. These networks may also allow threat actors to obfuscate the source of their attacks, making them appear as if they are originating from legitimate corporate networks. Security analysts could struggle to analyze and/or respond to these attacks and render conventional network defenses that rely on reputation or IP-based blocklists ineffective. Some users or organizations could even eventually become wrapped up in part of a law enforcement investigation if their infrastructure is used for illicit or illegal purposes,” Cisco Talos added.

CISA Urges Organizations to Avoid Bad Security Practices

CISA, cybersecurity, cybersecurity technologies

The cyber threat landscape is growing exponentially worldwide, with organizations suffering a series of ransomware and extortion attacks. According to an analysis from the NCC Group, ransomware attacks surged by 288% between January-March 2021 and April-June 2021. The victims of ransomware attacks also suffered data leaks and distributed denial of service (DDoS) attacks, causing additional damages.

Readiness to Defend Ransomware

Many organizations have raised their cybersecurity budgets to defend against evolving threats. However, most companies are failing to implement effective cybersecurity practices to tackle potential security incidents.

The Cybersecurity and Infrastructure Security Agency (CISA) stated that ‘Bad Practices’ increase the risk of hacker intrusions, causing severe damage to critical infrastructure. “All organizations, and particularly those supporting designated Critical Infrastructure or National Critical Functions (NCF) should implement an effective cybersecurity program to protect against cyber threats and manage cyber risk in a manner commensurate with the criticality of those NCFs to national security, national economic security, and/or national public health and safety,” CISA stated in a statement.

Bad Cybersecurity Practices to Avoid

CISA has listed certain bad practices that are extremely risky for organizations that support critical infrastructure for the nation. These include:

  • The use of unsupported (or end-of-life) software in service of NCF is dangerous. It significantly elevates risk to national security, national economic security, and national public health and safety. This dangerous practice is especially egregious in technologies accessible from the Internet.
  • Use of known/fixed/default passwords and credentials in service of Critical Infrastructure and NCF.
  • The use of single-factor authentication for remote or administrative access to systems supporting Critical Infrastructure and NCF is risky and increases the chance of hacker intrusions. Threat actors could easily obtain access to critical systems with poor authentication. Weak or easy-to-guess passwords can be guessed with different hacking tactics like phishing, credential stuffing, keylogging, social engineering, and brute-force attacks.

CISA urged organizations to implement robust cybersecurity plans for better security. The agency also created a discussion page to engage with administrators and IT professionals from industry, federal and state governments, and local governments to gather different perspectives and inputs.

Ransomware – What is new?

Ransomware attacks, ransomware, Sinclair Broadcast group

Executives are worried.  They see organizations crippled by ransomware, often for days or weeks, and rumors of multimillion-dollar fines being paid.

By Ian Mann, CEO and Founder, ECSC Group plc

In this article, we explore the evolving strategy of ransomware attackers, and more critically, what is causing this increase in damaging attacks, and how you can prevent them.

See also: Rags to Riches! The Evolution of Ransomware Operators

Evolving Ransomware attacks – The Four Generations

What has changed over the years is the strategy of the groups conducting ransomware.  These can be broken down into four distinct generations of attack.

Generation 1 – Keep asking for more

The first generation of ransomware involved encryption of your files or systems and demanding payment.  Unless you paid, there was often a demand for a further payment(s).  This wasn’t a very smart attack strategy, as the ‘professional guidance’ quickly became not to pay.

Generation 2 – The honorable attacker

The attackers soon realized that not being paid is bad for business, and so started to ‘honor’ the release of decryption keys on the first payment.  As payments were often modest in comparison to the damage caused, many organizations started to pay – even somewhere paying ransoms is not legal (they found alternative routes for the payment).  This proved successful for the attackers, as paying became a viable option where recovery proved difficult or impossible.

Generation 3 – The ability to pay

If you wanted proof that most hackers don’t target individual organizations, then the third generation of ransomware proves this.  Here the attackers don’t ask for a specific payment.  Rather, they ask you to contact them and give you a quote.  This gives the attacker a chance to identify you, and assess the level of payment appropriate to your pain.

Generation 4 – Recovery disruption

The latest attack strategies are really adding additional elements to the Generation 3 strategy.  Here the attacker carries out additional activities prior to deploying and activating the ransomware, namely;

  1. Disable, disrupt, or encrypt the backups.
  2. Steal sensitive data that has potential value.
  3. Disable logging on target systems and the entry route.

These additional levels of sophistication are intended to hamper attempts to recover systems, or data, when payment isn’t made, whilst also providing an alternative source for extorting a ransom – your data.  If you recover your systems without paying, expect the same demand for money or your most sensitive data will be released on the Internet (they’ll give you a sample of your data to prove they have it.)

Preventing Ransomware

So, the attackers are getting smarter, making more money, and finding more organizations to attack.  What can you do to defend yourself?

Your belief may be that the hackers will always get in if they try hard enough.  This is understandable, as the movies tend to portray hacking activities as easily achieved by those smart enough, and never prevented by sufficient defenses – even the most sensitive government establishments.  In addition, executives and many cybersecurity specialists are often guided by the media following an attack, where the tendency is to focus on the suspected hacking groups deploying ransomware, which countries they might be operating from, and implying that they cannot be stopped without international co-operation.  The victims of ransomware are often happy for this to be the focus of conversation, as it distracts from the real question of what did the ‘victim’ do, or not do, that allowed the hackers to get in?  Something the victim doesn’t want to make public as it points the finger of blame back at them.

It is usually much later when regulators publish reports that accompany fines, or perhaps disclosed in court cases, that you can actually identify the organizational failings that lead to ransomware.  Or, listen to the specialist organizations that are responding to a wide range of cybersecurity breaches each day.

Having been directly involved in cybersecurity incident response for over two decades, I am surprised how much actually hasn’t changed when you find the root cause of a cybersecurity breach.  Actual breaches are not caused by the latest esoteric hacking technique being discussed in security forums, or promoted by vendors to push their latest protection or detection technologies.  Breaches are happening because of well-known, well-proven attack techniques against vulnerabilities and attack vectors that have been ‘fixed’ for years.

Don’t Let Them In

As you learn more about the actual root causes of cybersecurity breaches (that more often than not lead to ransomware) you will develop a more empowering belief: you can prevent ALL cybersecurity breaches.

So, let’s look at the main root causes of today’s cyber breaches:

Multi-Factor Authentication (lack of)

Any Internet-facing login, whether from a ‘traditional’ IT environment, or into your new cloud environment, is an easy target.  Usually, targeted by either phishing against the users or exploiting weak (or already compromised) user passwords.

No excuses.  Fix this now.  It is more important than anything else you are doing with your cybersecurity.  Fix this and read the rest of this article later.

Unprotected Web Servers

Due to their easy visibility to attackers, these are always going to be targeted. The easiest solution (a good Web Application Firewall) is now commonplace.  Unfortunately, most are not configured correctly or tuned to give proper protection.

Patching Internet-facing Devices

These firewalls, VPN end-points, Remote Access Gateways should have priority in your patching efforts, as their vulnerabilities are easily detected by hackers and can be the first point of entry.

Protecting Backups

Whilst not a direct root cause of the attack, this is worth mentioning as it becomes critical if you do suffer ransomware.  Having off-line copies of backup data that cannot be destroyed by the attacker could save the day in a crisis.  Your ability to recover your systems will be directly linked to your ability to protect backup data and restore critical systems (perhaps something you should test!)

The common thread here is that these failings are:

  1. Well-known vulnerabilities with relatively simple preventive measures.
  2. Not related to fancy new cyber technologies.

The More Difficult Challenge

Whilst your new empowering belief that you can prevent all breaches will serve you well, there are some recent large-scale hacks that present you with a more difficult challenge.  These include the recent breaches caused by technology providers being compromised, such as SolarWinds, Microsoft, and Kaseya, that in turn affect thousands of organizations.

I’m not going to guess at the individual failings within these organizations that may have led to the original breach.  These will likely surface with time.  More useful for you is to focus on how to protect yourself against these types of attacks.

At first sight, these categories of attacks look difficult to defend against, as your technology provider is hacked and your solution is in turn compromised, giving attackers a route into your systems.

However, there are some elements of these attacks that give you a chance to survive them without suffering a breach.

Firstly, these types of attacks affect thousands of organizations.  This means, unless you are a particularly attractive target for the hacking group involved, it is quite unlikely that they will have the resources to compromise your systems quickly.  They are likely to focus their limited resources on higher-profile/profitable targets.  Remember, the really successful hackers remain undetected by keeping their activities quiet and their numbers small.

Secondly, these new threats get lots of publicity, so you and your specialist advisors have access to timely information so you can remove the threat and repair your defenses before you are likely to become compromised.  You can also enhance your detection systems with the individual characteristics of the attack as these become known.

A Positive Note To Finish

So, in conclusion, although ransomware appears to be on the rise, and the impacts are worryingly high, you can prevent yourself from becoming a victim.  The evidence shows that breaches are preventable, often by attending to the basics of sound cybersecurity protection.


About the Author

Ian MannIan Mann is the CEO and founder of the cyber security consultancy firm ECSC Group plc. He has over 20 years of experience in the cybersecurity sector, having previously worked as an adviser for GCHQ, and established a Cisco Networking Academy for Dixons City Technology College prior to founding ECSC in 2000.

Mann’s professional certifications include CISSP, PCI QSA, and ISO Lead Auditor, and he holds a B.Eng. in Electrical and Electronic Engineering from the University of Nottingham, and an MBA from the Open University. He is the author of the acclaimed social engineering text Hacking the Human, and Hacking the Human II: Adventures of a Social Engineer.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

What Is Steganography and Its Popular Techniques in Cybersecurity?

Steganography in cybersecurity

The word steganography stems from the Greek origin “steganos” (secret) and “graphy” (writing or drawing), which loosely translates to hidden writing. It is a technique to obscure data or information within other pieces of ordinary images, audio, or video files from unwanted eyes. Only the sender and recipient will know of the existence of the embedded message, audio, or image.

Steganography Explained in Brief

People have been using ingenious ways to conceal data and information within other carrier files since ancient times. It is not a new or modern technique. Painters and artists across the globe have made use of this technique to conceal signatures and other hidden messages within their art or paintings.

Today, digital steganography is the most common way of concealing information from third parties. Embedding messages within image files on a system is a widespread steganography technique.

To put it another way, steganography is a type of obfuscation that uses images and other forms of media to conceal information and hide its presence without raising suspicions. It is different from obfuscation which intends to make the hidden message difficult to read/decode. Now, let’s understand the differences between steganography and obfuscation.

Steganography vs Obfuscation

STEGANOGRAPHY OBFUSCATION
It is an obfuscation method to conceal images or text within a carrier (medium of hiding the information, e.g., images, audio, or video files. Obfuscation is the process of concealing the information with the deliberate intent of making it difficult to decode or interpret the message.
Only the two parties interacting through these embedded codes will be aware of the data’s presence because it is encrypted. The hidden contents are simple texts or photos, but they are uniquely concealed. Programming codes are obfuscated to protect sensitive data of trades, intellectual property etc., from malicious hackers. It makes it difficult for hackers to read the codes and thus prevents malicious exploits. The cryptic messages appear difficult to read and often require specialists to decipher the code.
A few steganography examples include concealing information in the file header, playing an audio track in reverse to find a secret message etc. One can also hide one’s private banking details or trade secrets in a cover image, audio, or text (source). Some examples of obfuscation include address obfuscation, code flow obfuscation, and more. It can be an effective tool against reverse engineering. Obfuscation techniques can also bypass antivirus tools.

 

This article explains how steganography works using popular techniques and is relevant for protecting critical information from threat actors.

How Does It Work?

Steganography is a combination of science and art. It employs a variety of inventive ways across several mediums to conceal text from prying eyes. It embeds hidden messages by dropping the unwanted data in computer files like HTML, text etc., and replacing it with unreadable text or code.

Recently, we have been witnessing a considerable rise in malware attacks using steganographic techniques to encrypt messages to attack target systems.

Let’s understand how threat actors are using Steganography techniques to their advantage.

Where Is Steganography Used?

As we pointed out earlier, Steganography conceals the encrypted message or information, but it does not hide the data between the two communication parties. Hackers use steganography techniques to corrupt files, conceal malicious payloads and more. Digital steganography is a popular technique for embedding messages within a medium like an image, audio, or video and hiding it from unwanted eyes. While malicious hackers use this process to bypass security measures, they are not the only ones who use steganography techniques.

Ethical hackers, forensics examiners, spies, government security and intelligence agencies also use digital steganography tools and methods. The government carries out secret exchange of messages in the interest of national security using steganography methods as it mitigates the risk of information leakage.

Military, businesses, and educational institutions use steganography techniques as well.

To understand steganography techniques, one needs to know their diverse types as well. Let’s unravel steganography types in detail.

What Are the Various Types of Steganography Methods?

Based on the intent, there can be different steganography types.

1. Steganography in Images

Hiding information inside an image finds widespread use in digital steganography. Digital images are available in different formats, and algorithms in use also vary to hide covert information inside an image. Some of the algorithms used here are:

  • Least Significant Bit Insertion
  • Encrypt and Scatter
  • Redundant Pattern encoding
  • Masking and Filtering
  • Coding and Cosine Transformation

2. Steganography in Videos

The art of concealing confidential data in video formats from unauthorized parties is video steganography. A few of the popular techniques or approaches in this type are:

  • Least Significant Bit Insertion
  • Real-time Video Steganography

3. Steganography in Audio

The technique of using an audio file to transmit hidden text messages or audio in an unreadable manner to third parties is audio steganography. Some common forms are:

  • LSB coding
  • Echo hiding
  • Phase coding
  • Spread spectrum
  • Parity coding

3 Techniques Used in Steganography

There are multiple steganography techniques used to transmit secret information through carrier files. Let’s learn about the three popular steganography techniques.

1. Least Significant Bit

A greyscale image pixel is segregated into eight bits. The eighth or last bit is known as the Least Significant Bit, and that is why this bit serves as a carrier for hiding information or data in the image as it affects the pixel value by only one. When you change the least significant bit, the naked eye cannot perceive the change in the image as the image may only appear slightly altered. So, one cannot see or differentiate much from the image.

Hackers cleverly use this to embed malicious code in digital images and target systems. When the target downloads the carrier file, the malware is installed on their computer, giving them access to the device. The attacker can thus breach security codes and disrupt the files.

2. Palette Based Technique

Digital images become the medium for carrying malware in this steganography technique.

This technique also uses digital images as malware carriers. The attackers embed the message in palette-based images like the GIF files. Threat hunters or ethical hackers have a challenging time detecting the malware because it is encrypted and is difficult to decrypt.

3. Secure Cover Selection

This process is about finding the right block image to carry the malware. Cybercriminals compare the images they choose as the medium to the blocks of the malware. If they find an image block that matches the identified malware, they fit it into the carrier image. What we get is an identical image that carries the malware, and it’s also not detected by any threat application.

These are a few popular steganography methods that black hat hackers use to conceal their malware attacks from ethical hackers. Steganography can make the work of ethical hackers or threat hunters difficult as hackers can attack in stealth mode using these methods. However, ethical hackers can employ a few preventive measures against such attacks, like educating end-users, deployment of security patches, and updating software regularly.

Let’s learn how an ethical hacking program certification can help you understand steganography techniques and tools.

Start Your Career in Ethical Hacking With EC-Council’s C|EH Program

If you want to identify malware to prevent potential attacks, you’ll need to know the latest countermeasures tools against steganography.

Getting trained on the Certified Ethical Hacker (C|EH) program from EC-Council will equip you with the skills to detect network adversaries. You will also learn how attackers use steganographic techniques to send malware through email and digital images to target systems. By learning about the countermeasure tools, one can detect the carrier files with the hidden text or audio. So, if you are ready to start your career in ethical hacking, join the C|EH program.

20+ Job Roles | 10,000+ Job Openings | Avg. Salary of $93,000

Become a Certified Ethical Hacker.


FAQs (Frequently Asked Questions)

1. What is Steganography and how it works?

Steganography uses creative methods to hide information by embedding messages within other mediums, like audio, text, or video. It replaces parts of unused data in regular computer files with bits of concealed information.

2. How is Steganography used today?

While malicious hackers use this process to bypass security measures, they are not the only ones who use steganography techniques.

Ethical hackers, forensics examiners, spies, government security agencies, etc., also use digital steganography methods regularly. The government carries out secret exchange of messages in the interest of national security using steganography as it cuts down the risk of information leakage.


References:

  1. https://www.edureka.co/blog/steganography-tutorial 
  2. https://www.jigsawacademy.com/blogs/cyber-security/steganography/ 
  3. https://searchsecurity.techtarget.com/definition/steganography 

Cyberattack Lands on Bangkok Airways

Bangkok Airways

Cyberattacks on airlines always seem to have a hard landing. The recent victim of airline attacks is Thailand-based Bangkok Airways. The airline company admitted that it suffered a security incident that disrupted its IT operations and compromised its users’ data.  However, the incident did not affect its operational or aeronautical security systems.

The initial investigation revealed that attackers illicitly accessed customers’ personal data, including passenger name, family name, nationality, gender, phone number, email, address, contact information, passport information, historical travel information, partial credit card information, and special meal information.

While Bangkok Airways did not reveal the perpetrator of the attack, the incident has been reported to the Royal Thai police for further investigation.

“The company highly recommends passengers to contact their bank or credit card provider and follow their advice and change any compromised passwords as soon as possible. The company also alerted passengers to be aware of any suspicious or unsolicited calls and/or emails, as the attacker may claim Bangkok Airways and attempt to gather personal data by deception. Bangkok Airways will not be contacting any customers asking for credit card details and any such requests. In case of such event occurs, passengers should take legal actions,” Bangkok Airways said in a statement.

Is LockBit Group involved?

Several security experts suspect that the LockBit ransomware gang is behind this attack. A dark web criminal intelligence and investigation platform, DarkTracer, stated that operators behind LockBit ransomware have purportedly stolen 103GB worth of files from Bangkok Airways.

Cyber intrusions by LockBit ransomware operators have surged lately. The LockBit gang operates as a ransomware-as-a-service (RaaS) model appointing affiliates and insiders to carry out intrusion activities. The gang recently targeted the global IT consultancy giant Accenture, compromised its servers that held over 6TB of information, and demanded a $50 million ransom in exchange for the decryption key.