Home Blog Page 59

FBI Raises Red Alert About Hive Ransomware Group

Hive Ransomware

Authorities from the FBI are warning about a new ransomware group, tracked as Hive, which was behind the recent attacks on multiple health care systems.  The Hive ransomware gang took down IT systems at Memorial Health System, disrupting health care services and risking the lives of several patients. First observed in June 2021, Hive ransomware operates as an affiliate-based ransomware service.

In an official statement, the FBI stated that the Hive gang uses multiple tactics, techniques, and procedures (TTPs) to compromise targeted networks. The group is known to leverage various phishing lures with malicious attachments to access critical systems and use Remote Desktop Protocol (RDP) to move laterally on the network.

Hive Ransomware Attack Procedure

After encrypting critical files, the Hive ransomware deploys two malicious scripts hive.bat and shadow.bat – to perform cleanup after the encryption process. The threat actors then threaten their victims to leak the data on their dark website HiveLeaks. “After compromising a victim network, Hive ransomware actors exfiltrate data and encrypt files on the network. The actors leave a ransom note in each affected directory within a victim’s system, which provides instructions on how to purchase the decryption software,” the FBI stated in a statement.

Hive Ransom Note

Your network has been breached, and all data were encrypted. Personal data, financial reports and important documents are ready to disclose. To decrypt all the data or prevent exfiltrated files from being disclosed at http://hiveleakdbtnp76ulyhi52eag6c6tyc3xw7ez7iqy6wc34gd2nekazyd.onion/ you will need to purchase our decryption software.

The attackers also provided specific guidelines on how to obtain the decryption key.

Say No to Ransom: FBI

Paying ransom may encourage threat actors to continue their extortion activities. It also does not guarantee the recovery of encrypted files. While the FBI does not encourage paying ransom to cybercriminals, it urged the victims to report any ransomware attacks as they happen.

“FBI understands that when businesses are faced with an inability to function, executives will evaluate all options to protect their shareholders, employees, and customers. Whether you or your organization decide to pay the ransom, the FBI urges you to report ransomware incidents to your local field office. Doing so provides investigators with the critical information they need to track ransomware attackers, hold them accountable under U.S. law, and prevent future attacks,” the FBI added.

Mitigations

FBI also recommended specific security measures to prevent potential cyberthreats. These include:

  • Back-up critical data offline.
  • Ensure copies of critical data are in the cloud or on an external hard drive or storage device.
  • Secure your back-ups and ensure data is not accessible for modification or deletion from the system where the data resides.
  • Use two-factor authentication with strong passwords, including for remote access services.
  • Monitor cyber threat reporting regarding the publication of compromised VPN login credentials and change passwords/settings if applicable.
  • Keep computers, devices, and applications patched and up-to-date.
  • Install and regularly update anti-virus or anti-malware software on all hosts.

The FBI asked organizations to report any suspicious activity on their network systems to their local FBI field office at www.fbi.gov/contact-us/field-offices.

“Zero-Trust Is Not a Product or Solution That Can Be Installed”

Under the prevailing circumstances of the pandemic, IT assets are no longer present behind the safe confines of corporate firewalls. Rather, they are dispersed and extend into the homes of employees. And organizations use a blend of cloud environments and on-premise with enterprise applications spread across multiple clouds. To complicate matters, users are bypassing IT and deploying their own applications without following processes and policies to secure these applications. The merger of operational technology and information technology also poses a threat to enterprise networks as there is poor visibility and security with OT systems. In this scenario, an identity-based approach and zero-trust are some of the most effective approaches to secure endpoint devices, networks and IT infrastructure.

Kartik Shahani, Country Manager for Tenable in India met Brian Pereira, Editor-in-Chief, CISO MAG to discuss how Active Directory can help establish a zero-trust policy for organizations. Shahani offers advice and tips for zero-trust security.

VIDEO: What exactly is Zero-trust?

https://youtu.be/Ueh4hB3Qrzg

Based in Mumbai, India, Shahani has over 30 years of experience in the IT industry, driving momentum for enterprises. He spearheads initiatives for Tenable in the enterprise security market, manages operations and continues efforts towards channel activities in India.

He has extensive experience in the telecommunications, finance and government sectors. Along with his innovative sales strategies, he is instrumental in driving growth in India. Shahani previously worked in RSA Security, a division of Dell EMC, where he was Director for Channel in the Asia Pacific and Japan. Prior to this, he was the Executive Director of Integrated Security for India and South Asia at IBM. 

According to Tenable’s 2020 Threat Landscape Retrospective, there were 29 zero-day vulnerabilities disclosed in 2020. And 35.7% were browser-related vulnerabilities. The next highest at 28.8% is OS-related vulnerabilities. What would you suggest as ways to mitigate browser-related and OS-related vulnerabilities? What should vendors and end-users do?

Zero-days may garner most of the attention but known yet unpatched vulnerabilities enable most breaches and have become favored by advanced attackers. Considering that web browsers are the gateway to the internet, patching these assets is an essential part of securing the enterprise network. Users of Apple devices should regularly update to the latest version to protect themselves against threats.

Why should Trust be treated as a vulnerability today?

Just as software vulnerabilities are often exploited in cyberattacks, trust is no different in perimeter-based defenses. Cybercriminals exploit privileges and trust to perform the lateral movement as part of the attack path. With a zero-trust approach, security teams can identify where trust is built into systems and networks and harden those systems. Multi-factor authentication, encryption software, identity and access management tools will also help secure critical business assets. A cybersecurity strategy that removes trust entirely from digital systems is, in fact, a great equalizer, one that any proponent of “flat” corporate hierarchies ought to be more than happy to embrace.

Can you explain how Active Directory (AD) is at the center of enabling trust?

Most organizations grant user access and privileges based on the notion that some users are more trustworthy than others based on their role. A never trust, always verify approach, derails anyone who sees themselves as “trustier than thou” because zero-trust relies on the systematic and continuous evaluation of users and their permissions. By viewing trust as a vulnerability, organizations can ensure users can only access the information they need to. Continuously monitoring the AD, allows security teams to detect unusual activity, monitor rights abuses and even stop lateral movement.

How do cyber hygiene fundamentals make zero-trust security possible?

Great security starts with a complete and continuous understanding of the attack surface, from on-premises to cloud infrastructure and from a growing remote workforce to all users connected to the network. The fundamentals of cyber hygiene include identifying systems that could potentially compromise the environment, identifying the roles of users who have access to those systems, and identifying cybersecurity vulnerabilities that could arise. With full visibility, organizations can determine who needs access to what assets and grant permission to access them on a need-to-know basis.

This is where AD plays a pivotal role. It is critical for organizations to mitigate AD misconfigurations, evaluate user rights and continuously monitor AD for suspicious activity. Once vulnerabilities arising out of trust are addressed, organizations can focus on monitoring the entire attack surface and regularly patch vulnerabilities that pose the greatest threat to critical business assets.

Can you share some tips for accelerating your zero-trust journey?

Zero-trust is not a product or solution that can be installed. It’s a strategy for implementing cybersecurity in a business world without perimeters. It’s built upon cyber best practices and sound cyber hygiene, such as vulnerability management, proactive patching and continuous monitoring. Identifying each and every user in the network provides full visibility into the attack surface including IT, OT and IoT. Once security teams know how data flows within the organization, identifying critical assets that need to be secured becomes easier. Limiting access to these assets reduces the attack pathways and allows ease in monitoring the attack surface, identifying end-point vulnerabilities and patching them regularly.

What are the potential risks that you see with the confluence of OT and IT?

In modern industrial and critical infrastructure environments, an increasing number of operational technology (OT) devices are now connected to the outside world. While this convergence presents many opportunities, it also introduces new risks. Many of the systems within the OT world are unpatched or unsupported making them especially vulnerable to malicious activity.  Since IT and OT environments are often interconnected, an attack that originates on an IT network can move laterally to the OT environment and vice versa.

Therefore, having complete visibility is of utmost importance. OT operators need to take a full inventory of all assets, firmware version, patch level, state, configuration and vulnerability positions of everything that is present within the OT infrastructure.


Brian PereiraAbout the Interviewer

Brian Pereira is the Editor-in-Chief of CISO MAG. He has been writing on business technology concepts for the past 27 years and has achieved basic certifications in cloud computing (IBM) and cybersecurity (EC-Council).

 

Five Critical Skills You Need to Have as a Web Application Penetration Tester

Web Application Penetration Tester

Two decades back, most of the tasks related to web application security were conducted by quality assurance teams. These professionals were responsible for ensuring that the application was safe from cyberattacks and data breaches. In the era of rapid digitization, IoT and innovative technologies have changed the way we store and exchange data, but they have also increased the challenges in cybersecurity. Therefore, the need for a web application penetration tester to mitigate these risks became prominent. Web application penetration tester’s job profile has become niche and rewarding with time. Also, the demand for certified web application penetration testers has jumped across all industry verticals.

See also: What is Penetration Testing? What Does a Penetration Tester Do?

The average total cost of a data breach increased by nearly 10% to $4.24 million in 2021: IBM Ponemon Institute Survey.[1]

Senior management members should focus on employing web application testers as a way forward for 2022 and beyond. Freshers and tech professionals looking for a new job profile to increase their employability, salary, and job security would also benefit from web application hacking and security testing.   

New job opportunities will keep flowing if you are ready to accept a web application penetration tester’s challenges, roles, and responsibilities. Here are five important skills you will need to become a remarkable professional in this field:    

1. Reflected, Stored and DOM-based Cross-Site Scripting (XSS)

Application security risks increase when users interact with a vulnerable application. XSS or cross-site scripting allows attackers to compromise these interactions and circumvent the origin policy that segregates websites from each other. In the absence of a web application penetration tester, the attacker can fully control the application’s functionality if the victim user has privileged access.   

A web application penetration tester closes these vulnerabilities by validating user inputs. A professional tester would filter out special characters and encode the output to prevent stored XSS attacks and reflected XSS attacks. They also create a content security policy through which they mitigate the impact of XSS.   

Through foolproof web app penetration testing, you will eliminate XSS attacks. Your customers will not face the issue of session hijacking, assuring data safety and privacy.   

2. Advanced Web Application Penetration Testing

Advanced web application penetration testing directly benefits the companies that develop web applications, APIs, and mobile applications. Developers use open-source components and plugins while creating these apps. Any security gap increases the chance of a cyberattack causing unprecedented damage.  

Web application penetration testers know how to patch vulnerabilities making in-app purchases safer. You may think that a vulnerability scan is enough to eliminate these issues and launch the app, but it is not entirely true. Vulnerability scans are essential for web application security testing. But this process would only highlight the open weaknesses, while advanced web application penetration testing would tell you how your app will fare against a real-world cyberattack.   

eCommerce companies would significantly benefit from website security testing, ensuring secure payments and transactions

3. Insecure Direct Object Reference Prevention (IDOR)

Insecure Direct Object Reference or IDOR does not cause any real security issue. Instead, it creates an environment that provides attackers with unauthorized data. It opens the possibility of an enumeration attack where the attacker can identify access to the associated objects. As a result, users go to sites or pages that they do not intend to visit.   

A web application penetration tester would close IDOR issues through two methods. First, they will use an indirect reference map that eliminates IDOR vulnerabilities by replacing the actual references (name, IDs, keys, etc.) with alternate IDs which map to the original values. Web application penetration testers also validate user access through which the server only allows the users with valid credentials to access the data or make changes to it.

4. Using Components with Known Vulnerabilities

Web application testing checklist also includes vulnerable libraries and frameworks. Cybercriminals can use automated scanning tools to find flaws in these components and then manipulate the data the way they want. Most website testing tools will highlight these issues, but only a professional would know how to close the security gaps.   

Your business and the product can be at significant risk if a malicious actor finds any pre-existing vulnerabilities. Only a web application penetration tester would know how to identify such risks and close them in advance. Organizations can also arrange web application security training for their employees who work in the IT department. This way, they will save funds by hiring new professionals and help their employees learn new skills.

5. Network Scanning and Authentication Bypass

Experienced web application penetration testers should know how to use network scanning and authentication bypass tools. These methodologies also make vulnerability identification much faster and easier. However, in the wrong hands, these tools can pose severe risks to client data. Only trained website security testing professionals can perform scanning and authentication bypass to ensure a threat-free environment.   

Aspiring web application penetration testers should choose a training program that covers technical skills and soft skills. EC-Council’s Web Application Hacking and Security course keep these requirements as a priority for training.  

About EC-Council’s Web Application Hacking and Security Certification

The modern testing approach for web applications is not just limited to conventional security methods. Aspiring cyber or Tech professionals interested in learning this skill should look for a course covering the latest case studies and market research to understand everything thoroughly.   

EC-Council’s Web Application Hacking and Security Certification is for aspiring web application penetration testers who like to go beyond conventional security practices. The course module teaches the modern techniques of defending and securing web applications. Participants learning new skills through this program would get an understanding of the essential web application testing checklist. Knowledge of web application testing techniques will help them combat cybercrimes amidst the emerging threats of phishing, unauthorized intrusions, and other forms of cyberattack. As a web application penetration tester, your skills will align with the most in-demand cybersecurity job roles.   

Web Application Security Professional

 


Frequently Asked Questions (FAQs)

1. Who Can Learn Web Application Hacking and Security? 

Web application and security training are for working professionals and students alike. But professionals in the following job profiles will progress and get hired faster compared to their peers 

  • Penetration Tester 
  • Ethical Hacker 
  • Web Application Penetration Tester/Security Engineer/Auditor 
  • Red Team Engineer 
  • Information Security Engineer 
  • Risk/Vulnerability Analyst 
  • Vulnerability Manager 
  • Incident responder 

2. Why Should I Learn Web Application Testing? 

Web application testing is among the top in-demand skills in cybersecurity profiles. In the USA itself, there are more than 5000 vacancies and the requirement is rising due to lack of professionals. As a web application tester, you will find interesting opportunities with a lucrative salary and job security.


References:

[1] https://www.ibm.com/account/reg/us-en/signup?formid=urx-50915&_ga=2.10519666.716610455.1628850973-202413231.1622444786 

How to Protect Your Credit Card Data Online

Credit Card Data

Sensitive financial data remains a primary target for cybercriminals. Adversaries often target sensitive financial data such as credit/debit card numbers, CVV, and other bank details to compromise and trade on darknet forums. Threat actors obtain credit card data or payment information after a data breach incident or via Magecart attacks.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

In Magecart attacks, also known as web-skimming or e-skimming, fraudsters inject malicious JavaScript code into website payment processing pages to steal customer payment card details. The malicious code then collects the users’ payment data while making purchases on the compromised website.

Trading and advertising credit card and banking information on dark web forums has become prevalent today. Cybersecurity researchers from Group-IB recently detected a post in which threat actors exposed compromised card details on various darknet forums, including crdclub and xss. The exposed file contained over one million stolen credit and debit card details belonging to over 1,000 banks across 100 countries, including India, the U.S., Mexico, Australia, and Brazil.

How to Protect Your Credit Card Data 

1. Report Unusual Activity

Using multiple credit/debit cards online may result in unnecessary risks. Attackers could spy on other credit cards if one of your cards gets stolen or its data gets exposed. In the event of card loss and to avoid misuse of data, report to your banker immediately. Change your credentials (card and online banking) in case your card provider suffers a data breach.

2. Create Unique Passwords 

Strong authentication comes first while talking about online security. Make sure you have complex and unique passwords/PINs to your online accounts. Remember to update your username and passwords regularly to reduce the risk of brute force attacks.

3. Shop Only on Trusted Sites 

The proliferation of e-commerce sites also resulted in fake online stores. The operators of these stores harvest users’ private data to launch various financial frauds. Always shop on websites that you are familiar with. Check for ‘Https’ and the lock symbol to verify the authenticity of the site. Threat actors often steal users’ payment card details by directing them to fraudulent sites that impersonate legitimate brands. Also, don’t save your credit card details on e-commerce sites. For additional security, enter the card details like CVV number, card number, and expiry date each time you shop online.

 4. Secure Your Device and Network

Always shop on a secure network. Cybercriminals often target devices using public Wi-Fi. Use a VPN to keep your browsing private and safe. Also, update your device regularly to fix unpatched vulnerabilities. Invest in good antivirus solution to avoid malware intrusions.

Wrap Up 

A small amount of your credit card or banking data might cost you a fortune in case it falls into the wrong hands. Apart from financial discipline, having cyber discipline will certainly help in protecting your data and money.

About the Author:

Rudra Srinivas

 

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

More from the Rudra.

 

Email Threats Continue to be Gateway of Major Cyberattacks

Bait attacks, Email Attacks

Cyberattacks via unsolicited emails remain an effective attack vector as threat actors continue to evolve their phishing techniques. Adversaries are quick to adopt new phishing lures and develop advanced malware variants. Social engineering and email attacks are often the initial steps in high-profile ransomware or cyberattacks. A recent survey from Abnormal Security, a cloud-native email security platform provider, revealed the adverse impact of socially engineered and rising email attacks causing severe financial and reputational damage to organizations globally.

See also: 5 Best Practices to Strengthen Email Security in your Organization

In its Q3 2021 Email Threat Report, Abnormal Security revealed that over 137 account takeover attacks occurred per 100,000 mailboxes for C-suite employees. The researchers observed a significant rise in credential phishing and brute force attacks, using which attackers obtained sensitive data like passwords and usernames.

The report identified advanced email attacks across eight major industry sectors: manufacturing, technology, retail and consumer goods, energy and infrastructure services, medical, media and television, finance, and hospitality.

Key Findings

  • 5% of all companies were targeted by brute force attacks in early June 2021
  • 61% of organizations experienced a vendor email compromise attack this quarter
  • 22% more business email compromise attacks since Q4 2020
  • 60% chance of a successful account takeover each week for organizations with 50,000+ employees
  • 73% of all advanced threats were credential phishing attacks
  • 80% probability of attack every week for retail and consumer goods, technology, and media and television companies

Impersonation at its Peak

The survey also stressed that impersonation attacks have become prevalent since the beginning of the pandemic. Cybercriminals mimic popular brand names to trick their victims into providing private data like login credentials. Impersonation of internal systems like IT help desk and IT support rose 46% over the past two quarters.

“Socially-engineered attacks are dramatically rising within enterprises worldwide, creating unprecedented financial and reputational risks. These never-before-seen attacks are becoming more sophisticated with every passing day. They don’t contain indicators of compromise, such as links, attachments, and reputational risks, so they evade secure email gateways and other traditional email infrastructure, landing in inboxes where unsuspecting employees fall victim to their schemes, which include ransomware. To effectively protect against these attacks, we can no longer rely only upon established threat intelligence. To baseline good behavior, we need to look further to comprehensively understand employee and vendor identities and their relationships, all with deep context, including content and tone. Any subtle deviations from this baseline expose the possibility of a threat or attack,” said Evan Reiser, CEO, Abnormal Security.

The increase in different kinds of impersonation and email threats represents the sophistication of threat vectors and stresses the need for robust email security practices.

The Importance of Team Diversity in Detecting Phishing Scams

Phishing, phishing attacks

An email subject line catches a user’s interest. The user clicks through and gets compromised. This is a classic phishing attack; it remains one of the biggest threats we face. Billions of spam emails are sent every day and email accounts for 94% of malware with a known source.

By Deika Elmi, Security Communicator and Educator

Why does anyone still click on phishing emails? The same reason anyone clicks on any email. It looks important or interesting, at least for long enough to click. Emails about vacation giveaways are now, giveaways themselves. Phishing has improved in its deception tactics. Early in the pandemic, a whole wave of phishing attacks pretended to be news about COVID.

See also: Five Phishing Baits You Need to Know [INFOGRAPHIC]

Different claims compel different audiences. Young adults fell for attacks based on scarcity (“you can save money if you fill this out!”). In contrast, older people fell for attacks based on reciprocity (“we’ve already given you a gift, click here to collect it!”), according to a 2017 study presented at the Conference on Human Factors in Computing Systems (CHI). Phishing is a lot like advertising. Different attacks are tailored to different targets.

However, there is much confusion about determining the most vulnerable populations. The CHI study also found that older women fell for phishing most. Other studies find that young people fall for phishing more, or that men get more mobile device viruses than women. Some academics found more experienced users were less vulnerable, while a Symantec study found that software devs were more vulnerable than the general public.

How do you reconcile such seemingly contradictory findings? You don’t. There’s little reason to think any demographic is universally more vulnerable to phishing. Different hooks will catch different audiences. But there is a proven strategy to address these various phishing attacks.

Reflect Who You Protect

Your cybersecurity team needs to understand your users’ perspectives to protect them. The more diverse your cybersecurity team, the wider the resources they can draw on to detect phishing scams.

Approximately 90% of data breaches are caused by human error. Your cybersecurity team has to anticipate the kinds of mistakes your users will make. Phishing vectors that seem obviously sketchy to one audience can hook another. Consider the different tools and platforms your users use and think about what attacks to take most seriously on each.

Slack phishing might catch young workers who think Slack is safe from outsiders. Older workers might not use that channel at all. Caller ID spoofing is often targeted at older adults, who may trust their phone more than their computer or not know that caller IDs can now be spoofed.

There is some gender difference in scam tactics. A scam that tries to panic the user into thinking they accidentally sent $500 to gun company Springfield Armory is more likely to work on men. A scam that offers free gift cards on Pinterest is more likely to work on women.

But the cure for gender-diverse scams is to have gender-diverse cybersecurity teams. Multiple studies have shown that gender-diverse teams make better business decisions than homogenous teams, as much as 73% of the time.

Yet only 24% of cybersecurity professionals are women, according to a widely cited 2019 report by (ISC)2. More recent studies hover around there, e.g. 21.9% per Zippia Careers and 25% per Cybersecurity Ventures. But the good news is this number is on the rise from around 11% in 2013, per (ISC)2.

Women in Cybersecurity Today

Women in cybersecurity trend younger and better-educated, but less experienced and lower-paid. Interestingly, women in cybersecurity are disproportionately likely to fill leadership roles like CTO or Vice President of IT, compared to men in cybersecurity. For example, Alissa Abdullah, Chief Information Security Officer at Xerox, Ann Barron-DiCamillo the Head of Cyber Operations at Citibank, or Marnie Wilking, the Global Head of Security, Privacy, and Technology Risk Management for Wayfair. In academia, Jennifer Granick served as the Director of Civil Liberties for the Stanford Law School Center for Internet and Society. The pay gap does persist in managerial roles but is smaller for younger workers than older workers.

Why do fewer women enter the field of cybersecurity? Since cybersecurity jobs often stem from STEM itself, the gender imbalance in STEM fields affects cybersecurity. STEM subject areas start out with rough gender parity in elementary school, but the proportion of women drops precipitously until women make up only 8% of STEM majors graduating from college. Evidence suggests that young girls and teens form preconceptions about professional industries and are heavily influenced by parental and societal influences. Furthermore, a lot of the terminology in cybersecurity sounds militaristic, another field with a large gender disproportion.

There’s the issue of fewer women entering the workforce but then there’s the issue of women staying in the field. The last year has heightened existing strains on women in the workplace. Many women in tech are considering leaving for the same old reasons why half of the young women who start in tech leave. More than 2.3 million women in the U.S. stopped working between February 2020 and February 2021. That tilted the proportion of women in the overall (not cyber-specific) workforce back to 1980s levels.

Women have a lot of pulls on our schedules that few men think about. Familial obligations are just some of many examples. One of the biggest is unpaid care work. Do you know how we just had a pandemic? Where a lot of people needed more care? Over 10% of women were caring for an ailing family member before the pandemic, and 10% took on new caregiving responsibilities as a result of the pandemic.

Like other areas of tech, cybersecurity has a “leaky pipeline” – the proportion of women who enter the industry has increased faster than the proportion who stay. Companies with many early-career cybersecurity professionals should think about how to retain them. Flexible work arrangements are a common ask for women – and inflexibility is a common reason they leave.

Your cybersecurity team should look similar to your userbase and workforce. Give your female employees flexibility, and attract experts who understand the perspectives of the people they’re there to protect.


About the Author

Deika ElmiDeika is a first-generation American, with roots in both Africa and Europe. She has lived on three continents and is a polyglot who speaks five languages fluently. An innovative security professional, Deika forecasts the future of business and creates clear strategies to get ahead of burgeoning trends. With 20 years of experience, she builds security in and across all operational processes and is passionate about security communication and advocacy. Her expertise spans third-party management and risk, changing global government cybersecurity demands, and consumer privacy expectations.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

New Ransomware LockFile Targets Victims with Intermittent Encryption Technique

JVCKenwood, LockFile ransomware, ransomware attacks in India, Suppress ransomware payment channels

A new ransomware variant has been making the rounds in the cyberthreat landscape. Security experts from Sophos uncovered new ransomware dubbed LockFile targeting victims with a new kind of intermittent encryption technique. The researchers stated that LockFile operators are found exploiting lately discovered security vulnerabilities, including ProxyShell and PetitPotam to compromise Microsoft Exchange servers and deploy malware.

LockFile Intermittent Encryption

The researchers stated that LockFile ransomware encrypts every 16 bytes of a file with its intermittent encryption technique, which helps the ransomware to evade security detections. It is found that LockFile ransomware uses memory-mapped input/output (I/O) to encrypt a file that allows the attackers to stealthily encrypt cached documents in the compromised system’s memory and renames them to lower case and adds a .lockfile file extension.

After encrypting all the documents on the infected device, the LockFile ransomware deletes itself with the cmd /c ping 127.0.0.1 -n 5 && del “C:\Users\Mark\Desktop\LockFile.exe” && exit command, which means there will be no ransomware binary for incident responders or antivirus software to find or clean up.

Similarities with Other Players

Similar to WastedLocker and Maze ransomware, operators behind LockFile ransomware leverage memory-mapped input/output methods to encrypt compromised files. In addition, researchers also found that LockFile’s ransom note looks similar to LockBit 2.0. ransomware.

“The notable feature of this ransomware is not the fact that it implements partial encryption. LockBit 2.0, DarkSide and BlackMatter ransomware, for example, are all known to encrypt only part of the documents they attack (in their case the first 4,096 bytes, 512 KB and 1 MB respectively,) just to finish the encryption stage of the attack faster. What sets LockFile apart is that is doesn’t encrypt the first few blocks. Instead, LockFile encrypts every other 16 bytes of a document. This means that a text document, for instance, remains partially readable,” said Mark Loman, Sophos director of engineering.

Emerging Ransomware Groups

Infamous ransomware groups like LockBit 2.0, DarkSide, and BlackMatter caused severe damages to organizations globally. LockBit 2.0 ransomware gang is even considered as one of the emerging ransomware groups along with AvosLocker, Hive, and HelloKitty, which have the potential to become prevalent threats in the future. It’s high time governments and organizations collectively disrupt these new ransomware groups before they cause damage to nations’ critical digital assets. Read More Here

Attackers Use Fake FMWhatsapp to Spread Triada Trojan

FMWhatsapp

From data privacy violations to fake applications, WhatsApp has been in the news for various reasons since the beginning of 2021. The popular instant messaging service provider has sustained a new kind of malware attack lately. A threat analysis report from Kaspersky uncovered a modified yet malicious version of WhatsApp tracked as FMWhatsapp that is distributing Triada mobile Trojan. The fake WhatsApp version displays malware-infused ads, accesses users’ SMSs, and downloads other Trojans.

Malicious WhatsApp Version

Threat actors are luring users to install the modified version of WhatsApp, which reportedly provides additional features than the official one. Once the user installs and starts using the app, fraudsters start their malicious activities by distributing malicious code via unwanted ads. Initially, FMWhatsapp compromises user devices and automatically downloads Trojans.

The Trojans then launch ads, issue paid subscriptions to the device owner,  intercepting the SMS to confirm login, and exposing the victim device to other threats. In addition, the Triada Trojan automatically installs the MobOk Trojan that opens a subscription page in an invisible window and clicks the subscribe button for the user.

“With this app, it is hard for users to recognize the potential threat because the mod application does what is proposed – it adds additional features. However, we have observed how cybercriminals have started to spread malicious files through the ad blocks in such apps. That is why we recommend you only use messenger software downloaded from official app stores. They may lack some additional functions, but they will not install a bunch of malware on your smartphone,” said Igor Golovin, a security expert at Kaspersky.

Different types of malware downloaded by FMWhatsapp include: 

  • Trojan-Downloader.AndroidOS.Agent.ic. This malware downloads and launches other malicious modules.
  • Trojan-Downloader.AndroidOS.Gapac.e. – displays full-screen ads when users least expect them to pop up.
  • Trojan-Downloader.AndroidOS.Helper.a – downloads and launches the xHelper Trojan installer module. It also runs invisible ads in the background to increase the number of views they get.
  • AndroidOS.MobOk.i – signs the device owner up for paid subscriptions.
  • AndroidOS.Subscriber.l – serves to sign victims up for premium subscriptions.
  • AndroidOS.Whatreg.b – signs into WhatsApp accounts on the victim’s phone. The malware gathers information about the user’s device and mobile operator, then sends it to the command-and-control server.

Indicators of Compromise (IOC)

  • MD5

Trojan.AndroidOS.Triada.ef b1aa5d5bf39fee0b1e201d835e4dc8de

  • C&C
    http://t1k22.c8xwor[.]com:13002/
    https://dgmxn.c8xwor[.]com:13001/

Protective Measures

Security experts from Kaspersky recommended specific measures to protect against malicious applications like FMWhatsapp. These include:

  • Only install applications from official stores and reliable resources.
  • Remember to check which permissions you give to the installed applications – some of them can be very dangerous.
  • Install a reliable mobile antivirus on your smartphone to detect and prevent possible threats.

How to Learn Ethical Hacking from Scratch and Start Your Career

learn ethical hacking

As businesses and government organizations face increasing risks of cyber threats in the digitalization era, the interest to learn ethical hacking programs has increasedThe demand for these courses will only escalate in the future as organizations are taking stock of their cybersecurity strategies and increasing the workforceUndoubtedly, cybersecurity experts are in great demand. 

So, let’s understand the significance of cybersecurity in today’s times.  

Importance of Cybersecurity   

Cyberattacks can cripple the infrastructure of any industry and disrupt its operation 

Ransomware attacks are more common in the news headlines. Malicious hackers exploit system vulnerabilities and access data of corporations and high-profile government bodies, and demand millions of dollars in exchange.   

In 2021 alone, there were close to 80 ransomware attacks, as per BitSight ransomware analysis. 

Cyberattacks have spurred in the wake of the pandemic. The shift to a remote work framework also contributes to the rise in system vulnerabilities. The recent attacks on JBS Foods, Colonial Pipeline, Kia Motors America, and Kaseya, among many others, have highlighted the importance of cybersecurity strategiesA skilled cyber workforce is the need of the hour to thwart cybercrime. As security and IT professionals need to safeguard an organization’s digital assets, taking an ethical hacking course can help them advance their careers in this domain 

If you are a beginner and intrigued by the world of professional penetration testingyou can learn ethical hacking and acquire the skills needed to become an ethical hacker 

Before you learn ethical hacking, it’s important to ask yourself why you want to become an ethical hackerTo help you understand the basics of this field, we shall discuss the concepts of ethical hacking and the skills you require to progress in this field.

What is Ethical Hacking? 

Ethical Hacking is a legal attempt of intruding a network or system by cybersecurity experts to identify potential security vulnerabilities or weaknesses – before they can be exploited by malicious hackers. 

What do they do?  

Ethical hackers perform penetration testing to gauge the potential dangers that could result from system flaws. They are trained to think like the black hats or malicious hackers to exploit a system or network flaw and strengthen a company’s security or cyber defenses. Hence, they are also known as white hat hackers 

Malicious hacking can be disruptive for your business. Organizations are no strangers to cyberattacks. Apart from the huge losses that a corporation can face, the company’s reputation also comes under the scanner. Your crucial data and website are prone to attacks with the advances in communications and technology. The Internet is changing the way we store and share information, but it also ushers in potential risks. Hackers employ various modern techniques to access your company’s data and confidential information through phishing, planting malware etc.  

Therefore, the role of ethical hackers in protecting your business information is crucial. They can perform pen tests to assess cyber threats and help chalk out security measures to safeguard your data from theft or damage.   

If you are a novice, you can undergo comprehensive training to learn ethical hacking step by step 

Can You Learn Ethical Hacking on Your Own?  

If you wish to learn ethical hacking on your own, it may seem simple but needs a lot of expertise and knowledge. At the same time, technology is rapidly evolving, and so are the hacking tools and techniques. Therefore, aspirants must keep themselves updated with the latest industry trends and hacking resources. 

Apart from technical skills, one should know basic hacking tools and penetration testing 

Learning different ethical hacking phases requires in-depth training and hands-on learning on attack vectors, SQL injection attack, DoS and DDoS, firewalls, password cracking, enumeration, cloud computing etc.  

While one can learn ethical hacking from scratch through various resources online, choosing the right one can be a daunting task. That’s why you need a structured method of learning from a credible source.  EC-Council’s Certified Ethical Hacker (C|EH) training program is an accredited course. If you find this field exciting and enjoy being creative and think out of the box, you can move to the next step.  

 Next, we shall discuss the essential skills one needs to become an ethical hacker and benefit from this field. 

Skills Needed to Learn Ethical Hacking   

Your ethical hacking career roadmap depends on your field of study. An essential requirement of computer and networking skills and knowledge of coding and operating systems is necessary. If you are in the nascent stage of your career, you can switch to this fieldAspirants can acquire the necessary skills to chalk out their ethical hacking learning plan 

One needs to master soft skills and hard skills for a successful ethical hacking career. A proficient pen tester can think and reason like a black hat or cybercriminal to sniff out security threats. Therefore, soft skills such as analytical and critical thinking, problem-solving abilities, and communication skills are crucial for ethical hackers. 

Apart from soft skills, one should also have thorough technical knowledge. Therefore, understanding hard skills such as computer and programming languages, networking concepts, cryptography, operating systems like Linux, Ubuntu, web applications and security, digital forensics etc., are crucial for ethical hackers to know. 

Educational requirement

Employers require applicants to show a bachelor’s degree in computer science, information technology, or cybersecurity. People who hold a diploma in network security can also learn ethical hacking and expand their careers. 

How Soon Can You Complete Ethical Hacking Programs? 

The field of cybersecurity is vast and mastering the art of ethical hacking requires extensive knowledge and experience. However, aspirants must have a basic certificate in computers, IT, or an equivalent field. It also depends on the course you are pursuing. Some programs have a duration ranging from 6 months to two years. If you join EC-Council’s Certified Ethical Hacker (C|EH) training, it will take you five days to complete the course 

Why Should You Join the Certified Ethical Hacker Program?   

One of the many challenges people face while looking for ethical hacking programs is searching for a credible course. One of the frequent questions which most people ask is, “Is the course recognized?”  

EC-Council’s Certified Ethical Hacker is a credible program and ANSI 17024 Compliant. It’s also stated as a baseline certification on the U.S Department of Defense (DoD) 8570/8140 Directive, the British NCSC Intelligence Agency, and several others. 

The course is designed for security professionals who want to carve a niche in this field and explore the numerous opportunities as ethical hackers. A certification in C|EH trains participants to take up job roles as a security auditor, a hacking tool analyst, a vulnerability tester, and many more. They get training in real-life scenarios pertaining to security threats, attack vectors, risks, and countermeasures.  

Scope and Opportunities

It’s one of the most promising fields if you are passionate about finding and fixing security patches. As per a report published in study.com, the U.S. Bureau of Labor Statistics (BLS) predicts a projected 32% increase in job opportunities for Ethical Hackers and information security analysts from 2019 to 2029.  

According to PayScalethe median salary per year of a Certified Ethical Hacker is $94K in the U.S.C$79k in Canada¥6m in Japan£44k in the U.K.  

According to Salary Explorer, the average salary an ethical hacker can expect in China is 316,000 CNY (Chinese Yuan) 

While cybersecurity professionals are highly paid across the spectrum, there is a shortage of trained professionals to fill cybersecurity positions. According to Cybersecurity Ventures’ forecast, there will be around 3.5 million unfilled positions in 2021. There is a vast disparity in the skills gap for cybersecurity jobs. 

So, how can we lower the skill-demand disparity in this field?

With increasing cybercrime amidst the pandemic, one of the best ways to handle this is to upgrade cybersecurity specialists with the latest resources and encourage new aspirants to join this field. 

Organizations are recruiting Infosecurity professionals across the globe to devise strategies to secure their data from theft.  

Besides, performing the task of an ethical hacker is no small task, and it requires one to upskill themselves with the latest tools and techniques. So, companies need to train and retrain IT and security professionals, recruit new talent from these fields with the required aptitude, and train them in cybersecurity verticals, including ethical hacking.  

Securing a certification in Ethical Hacking increases your awareness about potential cybersecurity threats that can lead to possible reputational damage. EC-Council’s Certified Ethical Hacker program modules are mapped to the skill set one requires to become a successful ethical hacker and combat cybercrime.  

So, it is a solution where everyone benefits from certified ethical hacker. 

About EC-Council’s Certified Ethical Hacker (C|EH) Program   

The Certified Ethical Hacker (C|EH) is an accredited program and pioneer in setting a global standard for ethical hacking. 

The C|EH program includes twenty-four incredible hacking challenges across four levels of complexity that cover eighteen attack vectors. This hacking challenge enables participants to face real-life scenarios in this field.  

C|EH has classified five phases of ethical hacking, including:    

  • Reconnaissance    
  • Gaining access    
  • Enumeration    
  • Maintaining access
  • Covering your tracks     

The C|EH exam covers 125 multiple choice questions with a duration of four hours. It evaluates your competencies in Attack Prevention, Attack Detection, Information Security Threats and Attack Vectors, Procedures, Methodologies, and more. 

Our training options

  • iLearn (Self Study) 

Through iLearn’s training option, one can learn through pre-recorded lectures by one of EC-Council’s leading professional practitioners. These lectures are designed to facilitate self-learning through a streaming video format 

  • IWeek (Live Online)  

IWeek offers participants the option to access the online, instructor-led training live. Fast Internet connectivity is all you need to learn from live instructors anywhere. 

  • Master Class   

This training option lets participants learn from certified and renowned instructors. They also have the chance to team up with leading Infosecurity experts. This solution also lets you benefit from a host of additional features like iLearn access, add-on certification training, and more.   

Further, In-person and Education Partner training are the other two solutions that C|EH offers for their participants. 

You do not necessarily have to attend the C|EH program before taking the examination. However, self-study participants must clear a standard eligibility process to take the examination. 

What Can I Expect to Learn?

 Participants can look forward to learning the following in their program:   

  • Ethical hacking concepts   
  • Linux basics
  • Evading IDS (Intrusion Detection System) and firewalls
  • Malware threats   
  • Enumeration   
  • Sniffing   
  • SQL Injection  
  • Hacking wired and wireless networks
  • Vulnerability Analysis
  • Hacking web servers, applications, and IoT (Internet of Things) devices 

If you are still deciding whether C|EH is a good fit for you or not, you can download whitepapers, watch recordings of webinars, and sign up with CodeRed. For the uninitiated, EC-Council offers subscription-based learning through CodeRed. One can learn through thousands of easy bite-sized videos and content and enhance their knowledge. 

So, grab the opportunities and make a career out of ethical hacking.

20+ Job Roles | 10,000+ Job Openings | Avg. Salary of $93,000

Become a Certified Ethical Hacker.


FAQs (Frequently Asked Questions) 

  • Who is eligible for the C|EH program? 

Anybody with sound knowledge in computer and programming can learn this course. People who want to explore the world of penetration testing and combating cybercrime can take up this course. 

  • What is the relevant work experience needed to be an ethical hacker?  

Some employers also expect you to have a certain level of related work experience in computer technology. As such, ethical hackers can initially assume a network defender, penetration tester, or systems analyst position.


References: 

  1. https://cybersecurityventures.com/jobs/ 
  2. https://delhitrainingcourses.com/blog/learn-ethical-hacking-from-basics/ 

Discussing the Impact of the Kaseya Supply Chain Attacks

According to a GEP Research Report, the total cost of supply chain disruptions in 2020 was $4tn. While these disruptions were caused due to various reasons, such as COVID-19, diverging regulations, and commodity pricing fluctuations, 36% of the respondents said their supply chains were impacted due to cyberattacks. The Kaseya Supply Chain Attacks are a recent example.

In the survey, which included 400 C-suite executives at European and U.S. global companies, 64% reported revenue losses between 6% and 20% in 2020.

As U.S. businesses were shutting for the 4th of July national holiday, adversaries launched a well-timed supply chain attack on Florida-based software company, Kaseya Ltd., which makes a VSA product for managed service providers.

Attackers were targeting MSPs and then their customers who used the Kaseya VSA solution on-premise, with ransomware being executed at the end-point products.

Due to this, customers who use the on-premise VSA client were impacted by ransomware attacks.

In a move that was quite unexpected, on July 21, Kaseya received a universal decryptor for victims of the REvil ransomware attack. Since the decryption key was obtained from a “third-party,” the company tested its credibility and confirmed that it is actively helping its customers to decrypt their data and ensure safety.

REvil mysteriously disappeared from the internet on July 13 and all their sites were taken down.

Brian Pereira, Editor-in-Chief, CISO MAG, spoke to Andrew Hollister, Deputy CSO and VP Labs LogRhythm to discuss the impact of the Kaseya supply chain attack and mitigation strategies to check supply chain attacks.

Andrew Hollister is Vice President of LogRhythm Labs and Deputy Chief Security Officer (CSO) for EMEA, IMETA, and APJ. He is the most senior engineering lead outside the U.S. at the Security Information and Event Management (SIEM) platform provider. Hollister is responsible for overseeing LogRhythm Labs’ research in Threat, Compliance and Operational Risk. He also advises on LogRhythm’s product strategy and direction. Over the last nine years, Hollister has proven himself an invaluable member of the business and leadership team in Customer Care, Sales, Labs, and the OCSO organization.


About the Interviewer

Brian PereiraBrian Pereira is the Editor-in-Chief of CISO MAG. He has been writing on business technology concepts for the past 27 years and has achieved foundational certifications in cloud computing (IBM) and cybersecurity (EC-Council).

 

More stories from Brian