Home Blog Page 67

Attackers Found Using Programming Languages to Create New Malware Variants

New Programming Language

The rising sophistication observed in recent cyberattacks confirms that cybercriminals are constantly enhancing their computer skills and hacking techniques. According to research from BlackBerry, several malware authors are leveraging exotic programming languages to advance their hacking skills and evade security detections. The researchOld Dogs New Tricks: Attackers Adopt Exotic Programming Languages” revealed that threat actors are reportedly using Nim, Go, Rust, and DLang to create new malicious codes and malware variants.

“Malware authors are known for their ability to adapt and modify their skills and behaviors to take advantage of newer technologies. This has multiple benefits from the development cycle and an inherent lack of coverage from protective products. This paper looks into less prolific programming languages and their use in the malware space. Industry and customers must understand and keep tab on these trends, as they are only going to increase,” said Eric Milam, VP of threat research at BlackBerry.

Why Attackers Using New Programming Languages

Cybercriminals are known for their opportunistic behavior and financial motives, and often misuse vulnerable systems with their changing malware campaigns. With rising ransom and double-extortion schemes, several malware groups are applying new or rarely known programming languages to fix loopholes in their existing language for efficient memory management and to attack effectively. Malware authors are also rewriting their codes, which were originally written in traditional languages like C and C++, by using unknown programming languages.

The researchers stated that Nim, Go, Rust, and DLang have a variety of qualities that attract malware authors. These include:

  • Easy learning curve
  • Can be cross-compiled to target different operating systems and architectures
  • Suitable for the building of lightweight and/or stand-alone utilities
  • Include multiple paradigm support, such as object-orientated, structured, and functional
  • Draws inspiration from C and C++ languages.
  • Suitable for the development of a wide range of project and application types

Challenge for Defenders

As malicious actors seek new approaches to hide their activities, security experts and organizations should also adopt security advancements to defend against evolving malware attacks. Organizations should ensure that their security analysts become familiar with newer programming languages to predict hacker moves and potential threats.

“These languages can come with several improvements once they’re adopted into the software development lifecycle of a threat actor. Although this trend might sound bad for researchers, the inverse is also true. By using these languages for enhanced detection evasion, or for quality-of-life improvements, they also inadvertently aid us in our hunt for malicious samples. Due to the relatively low number of compiled binaries in these languages, it is arguably easier to identify malicious samples,” the research report stated.

How Digital Forensics Complements Cybersecurity

digital forensics, cyber forensics, forensics, digital identity

Analyzing pieces of evidence found in a digital device is a laborious task. The challenges of which are further augmented by the ever-changing methods and technologies adopted by threat actors. Digital forensics applies scientific methods to analyze and recreate the sequence of events that occurred either during the security breach in a corporate firm or during a criminal investigation for the law and enforcement body. This process of procuring artifacts, analyzing, documenting, and reporting is accompanied by many challenges and aided by useful tools and technology that this article aims to describe in brief.

By Anis Pankhania CISO Cloud Infrastructure Services, Capgemini India

Trends in Cybercrime

As stated earlier, the ever-changing threat landscape and the development of technology being used maliciously pose a variety of challenges for the digital forensic investigator. Organizations are under constant threat of attack as there is no shortage of factors that induce disruption, which range from substantial information breaches to malware and botnet assaults. Some of the current trends in cyberattacks could be listed as:

  • Malware: The spreading of malware today has turned into a sort of continuous campaign, with the majority of recent incidents involving the use of ransomware or some other form of malware. Spyware and ransomware are the most dangerous malware that poses a serious threat to information security, as they tend to encrypt or exfiltrate sensitive information. To make matters worse, this malware is increasingly equipped with sophisticated anti-forensic techniques that tend to increase the amount of time required for the investigators to retrieve any artifact or evidence. Encryption of data itself is an anti-forensic technique wherein if the threat actor gains a greater privilege, then not only the sensitive information (which is to be held for ransom) but also their digital footprints could be encrypted, never to be decrypted again. Ransomware typically targets all types of file extensions without any barriers, as such files that are of some importance to the victim. Even if the targeted organization pays the ransom, which by the way is now illegal, according
    to the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC), there is very little probability of getting back the encrypted data.
  • Botnets: Botnets are compromised systems that are controlled by the threat actors through a remote network of command and control without the knowledge of their owners/users. Botnets are generally used to conduct a DDoS attack, cryptojacking, click fraud, phishing, spam, and multiple other malicious operations. The threat actor could issue the command for the attack to the bots at any moment through the command-and-control network. A high level of internet privacy and security knowledge is required on the part of the network administrator and forensic analyst to identify and stop the botnet attack.
  • Cryptojacking: This is the advanced application of the botnet network, where the bots are installed with crypto mining programs to mine cryptocurrency. This cryptojacking malware is designed to hijack the processor of the device to run crypto-mining programs effectively, which will, in turn, overheat the power source, hence, damaging the device. Though crypto mining is not illegal, it is a legitimate method used by blockchain experts to mine and generate digital currency, but this process requires high and fast performance on the part of the systems, which is generally expensive. Where legitimate miners use their high-end systems and tools, malicious attackers use their botnet network to mine digital currency.

Importance of Cyber Forensics

Though it may seem that cyber forensics exists due to the existence and implementation of cybersecurity programs, and a failed information security framework feeds the digital forensics operations. But in reality, both are co-dependent and go hand-in-hand. Digital forensics provides the information that feeds the developments in cybersecurity. The cumulative information about the state of security is obtained through numerous cases investigated through cyber forensics. Understanding this delicate balance between the two will help cybersecurity professionals to create a better security architecture…To read the full story, subscribe to CISO MAG

This story first appeared in the June 2021 issue of CISO MAG.


About the Author

Anis PankhaniaAnis Pankhania is a technology leader, with a thorough understanding of adapting technology expertise to “business vision.” He is an award-winning information security leader with 23 years of experience in leading the complete information security, infrastructure management, digitalization, application development and management, program/ project management, IT network and data center operations, telecom circle/ corporate/business operations, etc. The majority of his tenure has been spent with large telecom and IT companies in India (Bharti Airtel, Aircel, IBM, and Vodafone). Pankhania established IT divisions from scratch, involving the design of strategy & execution roadmap, objectives, operating procedures, multi-site facilities, end-user workspace for 30k+ end users.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Is ‘BlackMatter’ a Successor to DarkSide and REvil?

BlackMatter Group, Volvo Cars ransomware attack

There is no shortage of cybercriminal groups on the dark web. New threat actor groups and ransomware cartels continue to make their presence felt in the threat landscape. Cybersecurity researchers from threat intelligence firm Recorded Future recently spotted a new ransomware group, tracked as BlackMatter, advertising for recruits on two darknet forums, Exploit and XSS. The group reportedly posted ads for hiring “initial access brokers,” individuals with access to compromised enterprise networks.

BlackMatter Requirements

Researchers stated that the BlackMatter gang is looking for affiliates who can access corporate networks that have 500 to 15,000 hosts. The group is focused on companies having revenue of $100 million per year, with locations in the U.S., the U.K., Canada, and Australia. The ransomware group was allegedly willing to pay up to $100,000 for access to high-profile networks.

“Once the group finds a suitable target, they will use the access granted by the broker to deploy tools that take over a company’s internal systems and then deploy their file-encrypting payload,” the researchers said.

BlackMatter Capabilities

The BlackMatter gang can encrypt different operating systems and architectures, including Windows, Linux (Ubuntu, Debian, CentOS), VMWare ESXi 5+ virtual endpoints, and network-attached storage (NAS) devices like Synology, OpenMediaVault, FreeNAS, and TrueNAS. In addition, the group has a website – Leak Site – on the dark web, which is used to publish victims’ data if they refuse to pay the ransom.

BlackMatter Targets

The group stated that they do not aim to attack hospitals, the defense industry, critical infrastructure facilities (nuclear power plants, power plants, water treatment facilities), the oil and gas industry (pipelines, oil refineries), non-profit organizations, and government agencies. They further claimed that if a victim is from the aforementioned sectors, they’ll decrypt their files for free.

Criminal Connections

While there is no evidence of any attacks from the BlackMatter gang yet, several security experts suspect that the group is a successor of the DarkSide ransomware group. The researchers claim that BlackMatter has capabilities similar to DarkSide, REvil, and LockBit ransomware operators. DarkSide gang recently disrupted the services of   Colonial Pipeline in a ransomware attack. The company reportedly paid a $4.4 million ransom to restore its services.

Two Critical Vulnerabilities Identified in Zimbra Webmail Solution

Vulnerabilities in Zimbra

Unpatched vulnerabilities are a gateway for hacker intrusions. They make cybercriminals’ jobs easy to break into targeted network systems. Cybersecurity experts from security firm SonarSource recently uncovered two critical vulnerabilities in Zimbra’s enterprise webmail solution that could allow an attacker to compromise and obtain persistent access to business email accounts. Zimbra is a popular open-source solution provider for enterprise mail services to global public and private organizations.

The vulnerabilities, tracked as CVE-2021-35208 and CVE-2021-35209,  existed in Zimbra 8.8.15 version. “A combination of these vulnerabilities could enable an unauthenticated attacker to compromise a targeted organization’s Zimbra webmail server. As a result, an attacker would gain unrestricted access to all sent and received emails of all employees,” Zimbra said. 

Vulnerability 1

Tracked as CVE-2021-35208, this vulnerability is a Cross-Site Scripting (XSS) flaw that triggers in a victim browser via a malicious email with a specially crafted JavaScript payload. If exploited successfully, the flaw enables an attacker to obtain illicit access to the victims’ email accounts and their webmail sessions.

Vulnerability 2

Tracked as CVE-2021-35209, this is a Server-Side Request Forgery (SSRF) flaw that can be exploited by a remote attacker by combining it with the XSS vulnerability. The flaw allows unauthorized access to Zimbra’s HTTP client and pilfers private information like access tokens and credentials from Google Cloud and Amazon Web Services.

Both the vulnerabilities could be exploited by sending a single malicious email to the targeted user. Once the victim opens the malicious email, the JavaScript payload automatically deploys and infects the Zimbra web interface to exploit the second flaw in the backend.

Zimbra fixed both the flaws in its latest security update after SonarSource reported the issue. “Zimbra would like to alert its customers that they can introduce an SSRF security vulnerability in the Proxy Servlet. If this servlet is configured to allow a particular domain (via zimbraProxyAllowedDomains configuration setting), and that domain resolves to an internal IP address (such as 127.0.0.1), an attacker could access services running on a different port on the same server, which would normally not be exposed publicly. So, we urge our customers to review this configuration setting to ensure that there are no vulnerabilities are introduced,” Zimbra added.

Related Story:

How to Detect Malicious Email Attachments

Florida DEO Suffers Data Breach, Over 57K Accounts Affected

DEO data breach

Whether it’s to gain fame or obtain a large amount of private data, threat actors often target government agencies. Recently, Florida’s Department of Economic Opportunity (DEO) revealed that it has sustained a data breach that targeted its unemployment benefits system, affecting over 57,920 claimant accounts. The security incident reportedly affected user accounts in the Reemployment Assistance Claims and Benefits Information System – CONNECT.  While the attackers behind the data breach are unknown, the authorities at DEO have notified the affected users via email.

Information Accessed

Threat actors allegedly accessed sensitive information from the CONNECT public claimant portal between April 27, 2021, and July 16, 2021. The exposed data in the breach include social security numbers, driver’s license numbers, bank account numbers, addresses, phone numbers, and birthdates. The attackers may also have obtained the PIN used to access the CONNECT account.

As a security precaution, DEO locked the CONNECT accounts and enhanced its authentication procedures and network security systems to defend against future threats. The department advised the affected users to monitor and report if they suspect any unauthorized activity in their credit accounts. The DEO is also offering identity protection services to the impacted users.

Repercussions of the Data Breach 

Data leaks continue to impact organizations globally, affecting their customers with various security risks. Adversaries often leverage leaked data to launch different phishing attacks and commit identity thefts, financial frauds, and other online frauds. The affected users are urged to stay vigilant and avoid responding to an unknown email/text communication or click/download any URLs from unknown sources.

80 U.S. Municipalities Suffered Breach

The DEO data breach comes on the heels after WizCaze uncovered a data breach that affected the residents of over 100 U.S. cities that used a product from PeopleGIS. Over 1,000 GB of data and over 1.6 million files were held in 80 misconfigured Amazon S3 buckets. As per the investigation, the data breach affected users in over 100 U.S. cities that used “mapsonline.net” from the web service provider- PeopleGIS. Read More Here…

eScan’s Mobile Security Application Capable of Detecting and Blocking Pegasus Spyware

Pegasus Spyware, Mobile Security, spyware

Pegasus spyware from the NSO Group has made it to the global mainstream media, thanks to it being at the core of a major surveillance campaign reported by 17 media organizations led by the Paris-based group, Forbidden Stories and Amnesty International.

Per reports, 50,000 phone numbers, primarily belonging to journalists, government officials, and human rights activists across the globe, were put under surveillance, violating the basic human right of privacy.

The Global Spyware Market Index Report from Top10VPN.com revealed some startling statistics:

  • 74 countries have bought and/or used invasive spyware technology since 2015.
  • Spyware firms: 86% are based in countries considered full or flawed democracies by the EIU.
  • Suspected customers: 55% are authoritarian or hybrid regimes, with only 7% considered full democracies.
  • FinFisher has the most reported state customers (34), followed by Circles (25), and NSO Group (23).

Responding to the imminent attack, MicroWorld Technologies, a security solution provider with a specialization in cybersecurity, emphasized that their Mobile Security solution is capable of detecting and blocking Pegasus spyware along with similar digital threats.

MicroWorld Technologies houses two brands under its banner namely eScan and Nemasis.

Govind RammurthySpeaking exclusively with CISO MAG about detecting spyware, Govind Rammurthy, MD and CEO of MicroWorld Technologies Inc., said, “The Pegasus attack, which the world has recently encountered uses a zero-click method and surely has been difficult to track if one doesn’t know the existing vulnerabilities in their devices. The new upgrade to Pegasus has been designed to bypass the need for any kind of social engineering tactic. However, with time and experience, we have been able to detect current infections and block the spyware.”

 

The spyware has evolved with time, and unlike its earlier versions that used the spear phishing technique, Pegasus is capable of exploiting bugs in iMessage, allowing it to gain access to millions of iPhones through a backdoor.

Rammurthy further articulated, “Pegasus is a spyware-equipped remote access tool (RAT). The spyware can monitor the user’s activities remotely using the phone’s microphone and camera, as well as take screenshots and record keystrokes. This infection is treated like any other spyware by eScan’s Mobile Security for Android and the action is taken accordingly on it. In case of any active or dormant version of Pegasus is identified while scanning, a warning is triggered on the device by our mobile security application, keeping the user safe from unauthorized surveillance.”

eScan’s mobile security application for Android and Apple devices detects any dormant and active strains of the spyware that is present within the storage space of the device.

Privacy violation

Globally governments and authorities are working toward banning spyware and working on policies to prevent these surveillance attacks. With more incidents coming to the fore and awareness being created, significant activity is being reported globally, questioning the misuse of spyware.

Rammurthy, condemns this campaign saying, “In this digital age, data and privacy are of highest importance. Any form of interception of communication is illicit in nature and strict action should be taken against the perpetrators of this campaign. At the same time, the masses should collectively educate themselves on how to spot the signs of such a pernicious campaign and use cybersecurity solutions that can actively thwart the advances of such spyware.”

Shweta Thakare, Vice President – Global Sales and Marketing of MicroWorld Technologies Inc., adds, “We severely castigate the Pegasus campaign that has come to light. It not only violates the freedom of the press but also the basic human rights of the citizens of the free world. Our research and development teams have worked relentlessly to provide a solution for this digital atrocity and we are happy to announce that our cybersecurity solution for mobiles, irrespective of the platform can detect and mitigate this threat with ease.”

MicroWorld concluded that keeping the evolving threat landscape in mind, its team is currently working on adding more upgrades through which the application would be able to proactively detect any security flaws within the device and plug it before a threat actor could capitalize on it. Consequently, both the present and the future are in secure hands.

New ‘MosaicLoader’ Malware Targets Users Downloading Cracked Software

WhisperGate malware campaign, Flagpro malware, MosaicLoader Malware, drinik

Adversaries often target users with various phishing tactics. But sometimes, unwitting users fall into a hacker’s trap, revealing their private data to attackers. Cybersecurity researchers from Bitdefender recently identified a new malware variant that targets users who are looking online for pirated software.

Tracked as MosaicLoader, the malware is distributed via paid advertisements in search results, specially crafted to trick users into clicking the malicious ads link and infect their devices. Once deployed on the system, MosaicLoader creates a complex chain of processes and automatically downloads additional payloads like cookie stealers, crypto-currency miners, and backdoors like Glupteba. Glupteba is a malware Trojan with advanced features that could turn the infected system into a remotely controlled bot and steal personal information.

MosaicLoader’s Infection Flow

Initially, the MosaicLoader malware adds local exclusions in Windows Defender for legitimate-looking filenames to evade security detections. The malware then deploys additional malware payloads to gain persistent access to the targeted device. The execution flow of MosaicLoader include:

Creating a fake software file > Code obfuscation with execution order > Auto-downloading with several malware strains.

Impact

In addition to MosaicLoader, Bitdefender researchers also identified a malware sprayer distributing Facebook cookie stealers to access users’ login cookies from browsers. This allows threat actors to take over victims’ Facebook accounts, deploy malware, and steal identities. They even leveraged a variety of RATs like AsyncRAT and Powershell Dropper for their cyberespionage campaigns to obtain users’ log keystrokes, audio from the microphone, and images from the infected system.

“Due to MosaicLoader’s capabilities, user privacy may be severely affected. The malware sprayer can deliver Facebook cookie stealers on the system that might exfiltrate login data, resulting in complete account takeovers, posts that can harm the reputation of businesses or persons, or posts that spread malware. Another significantly dangerous malware delivered through MosaicLoader is the Remote Access Trojans. They can log keypresses on the system, record audio from the microphone and images from the webcam, capture screenshots, etc. With this private information, attackers can take over accounts, steal digital identities and attempt to blackmail victims,” Bitdefender said.

Indicators of Compromise

URLs

t1.cloudshielding.xyz

c1.checkblanco.xyz

s1.chunkserving.com

m1.uptime66.com

5a014483-ff8f-467e-a260-28565368d9be.certbooster.com

0129e158-aa17-4900-99a6-30f4a49bd0a4.nordlt.com

Integral.hacking101.net

IP Address

195.181.169.92

Mitigation

While the MosaicLoader campaign has not targeted any specific countries or sectors, the attackers are mostly targeting personal computers.

To prevent MosaicLoader infections:

  • Organizations should apply the indicators of compromises (IOCs) to endpoint detection and response (EDR) systems
  • Ensure employees avoid downloading pirated software or applications
  • Always download from authentic sources
  • Keep devices updated

Empowering CISOs to Extend Security from the Firewall to Mobile Apps in the Wild

Mobile Apps Security, mobile apps

Mobile devices and the apps that live on them are finally being recognized as serious threats to enterprise security. Three-fifths of the senior professionals responsible for the procurement, deployment, and security of mobile devices say that they are their company’s biggest security risk, and more than three-quarters (76%) said they’d come under pressure to sacrifice these devices’ security for expedience, according to the 2021 Verizon Mobile Security Index.

By Tom Tovar, CEO and Co-creator of Appdome

Apps on these devices represent a serious security risk. Nearly one in ten organizations (8,2%) encountered malware on a mobile device in 2020, which was nearly four times more than in 2018. Additionally, one in 25 apps was found to leak sensitive credentials.

That’s important, because 49% of frontline workers and 57% of information workers are equipped with mobile devices, and almost nine in 10 of U.S. enterprises (87%) say their people will continue working from home at least part of the time once pandemic restrictions lift, according to IDC.

The implications for enterprises are clear: employees will be using mobile apps to do their jobs, and they’ll be doing so outside the firewall, which will require a new approach to security. After all, firewalls do a pretty good job of keeping unauthorized traffic from coming into the corporate network, but mobile devices are operating well outside that perimeter. Behind a firewall, to connect to servers outside the perimeter, users must first present themselves as real and authorized, and the server must also prove its authenticity.

Protecting Mobile Apps

Nearly all mobile devices must connect to multiple networks and servers in order to function. After all, it’s not too much of an exaggeration to describe a mobile app as a wrapper around a collection of APIs. Without a connection to services outside the corporate network, most mobile apps can’t function or, if they do function, it’s with limited capabilities.

Additionally, anyone can go get a mobile app, so long as it’s published on one of the many public app stores. No permission is necessary, and there’s no need to present who you truly are. At most, the user needs an email address, and those are simple to come by. As a result, the app must be able to protect itself, and not just from external threats. Improperly protected apps can be compromised by trojans and other malware that the user may inadvertently install on their device.

Because the data in an enterprise app is valuable to malicious actors, they contain information on your employees, URLs to back-end servers, secrets that enable the app to access those servers, and more. With this information, a hacker could penetrate the firewall, set up shop inside your environment, and move laterally across the network to infect and compromise valuable digital assets.

“But what about the app sandbox?” I can hear some readers saying, “Isn’t that a protected, sealed-off area where the app runs?” It is, but apps can request permission from other apps to interconnect. You’ve surely seen these requests, yourself, and if you’re like most users, you accept them without giving it much thought. Mobile malware preys on this tendency to gain access to enterprise apps and, if the data inside isn’t properly protected, it’s at risk.

To protect mobile apps, CISOs need to ensure that both proprietary and licensed business apps address the following common mobile app security weaknesses.

Weak or Incomplete App Hardening

Any mobile app’s first line of defense must be hardening the app by “shielding” it with Runtime Application Self-Protection (RASP) measures such as jailbreak/rooting prevention, anti-debugging, anti-tampering, and anti-reversing. All too often, these protections are implemented in a superficial manner — for example, an anti-tampering measure that only checks at app installation or is included in mostly un-obfuscated source code where developer tools can easily eliminate it.

Lack of Obfuscation

If the source code isn’t properly obfuscated, attackers can use common disassemblers, decompilers, and debuggers to reverse-engineer apps and reveal the source code. More sophisticated hackers can abuse dynamic instrumentation toolkits to inject code dynamically into memory while the app is running to change logic, functionality, state, and behavior.

In so doing, cybercriminals can learn how to launch devastating attacks on an organization’s back-end servers, obtain free services (such as free items that would normally require an in-game purchase) and create effective trojans that look and feel like a genuine app.

Weak or Insufficient encryption

Many apps fail to encrypt sensitive data stored within them sufficiently, and some even forgo encryption altogether. It’s not difficult to access API keys and secrets if they’re stored unencrypted as strings within apps, and, unfortunately, that’s frequently the case. For example, hackers can also intercept login credentials in the clear when they traverse a network to log into their bank account via the app.

Encryption is a standard security measure, but it’s difficult to do because it can break sharing authentication and authorization with other apps and servers if not properly implemented. Additionally, the many different varieties of key size and strength, cipher strength, and encryption algorithms differ. It’s difficult to know which will provide sufficient protection without degrading performance if you’re not an expert. After all, encryption is a resource-hungry activity, and if it’s not performed efficiently, an app can slow to a crawl.

Securing These Exploits is Difficult

To ensure that apps can protect themselves in the wild outside of the network perimeter, the enterprise needs to ensure its apps employ a layered approach to security. Apps must be sufficiently hardened to prevent tampering, debugging, and reversing. Data must be encrypted both in transit and at rest, and dynamic key generation techniques must be applied to data that will be stored in the app sandbox. Certificate validation must be employed to protect against man-in-the-middle attacks, and code must be properly obfuscated to hide it and the secrets it contains from prying eyes.

Given the difficulty, too many enterprise apps are released without proper security. And that’s a serious mistake, especially since it’s no longer necessary to manually encode software. Software development kits (SDKs) do provide some security, though the quality varies, and integrating them still requires a significant amount of manual coding. More recently, fully automated platforms have emerged that can fuse strong security to an app binary in minutes.

However, a CISO chooses to ensure their apps are secure; they must be protected because, in the world of mobile apps, there is no firewall.


About the Author

Tom TovarTom Tovar is CEO and co-creator of Appdome, the mobile industry’s first no-code mobile security solutions platform. Prior to Appdome, Tom served as executive chairman of  Badgeville, an enterprise engagement platform acquired by CallidusCloud; CEO of Nominum, a DNS security and services provider that was acquired by Akamai; and chief compliance officer and VP of corporate development and legal affairs at Netscreen Technologies. He began his career as a corporate and securities attorney with Cooley Godward LLP.

Tovar holds a JD from Stanford Law School and a BBA in finance and accounting from the University of Houston.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

These Are the Four Common DNS Attacks

DNS attacks

From banking to e-commerce and retail to restaurant chains, it’s imperative for every business to have a digital presence on the internet today. However, the advantage of online presence comes with a cost — security risks to a company’s digital assets. Threat actors leverage various malicious techniques to manipulate digital assets, and one of them is Domain Name System (DNS) attacks. According to the 2021 Global DNS Threat Report, nearly 90% of organizations have suffered a DNS attack last year, with over 26% of organizations reporting that sensitive customer information is still being stolen.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

What is a DNS Attack?

DNS is a service that allows users to access websites on their devices by using a domain name to connect a cloud network via an Internet Protocol (IP) address. The DNS protocol interprets an alphabetic domain name into a numeric IP address. In DNS attacks, cybercriminals exploit the unpatched vulnerabilities in the domain name system to compromise targeted devices and pilfer sensitive data.

Types of DNS Attacks

Cybercriminals often take advantage of security loopholes or unpatched flaws in the domain name system to launch different kinds of DNS attacks. These include:

1. DNS Spoofing Attack

Also known as DNS cache poisoning or DNS poisoning, a DNS spoofing attack corrupts the DNS server by changing the actual IP address with the bogus one in the server’s cache memory. Attackers use this technique to redirect the web traffic to the hackers-controlled site to harvest sensitive data.

2. DDoS Attack

In a Distributed Denial of Service (DDoS) attack, adversaries try to make a targeted system or service unavailable to its users by flooding it with unwanted incoming traffic from multiple sources.

3. DNS Reflection/Amplification Attack

A DNS reflection/amplification attack is a two-step DDoS attack in which the hacker manipulates open DNS servers with a spoofed IP address to send massive web traffic to the targeted victim. The DNS reflection attack could make the victim organization unable to access its data.

4. Fast Flux DNS Attack

In fast-flux attacks, threat actors use botnets to hide their phishing and malware activities from security scans by using ever-changing IP addresses of compromised hosts acting as proxies.

Mitigating DNS Attacks

DNS service is like a giant contact list that a device uses to reach the stipulated IP address. Implementing a robust security plan and following some basic security precautions can help defend against evolving DNS attacks. These include:

  • Always use the latest version of DNS software
  • Constantly monitor the In and Out web traffic
  • Enable multifactor authentication to the DNS infrastructure
  • Deploy Domain Name System Security Extensions (DNSSEC) for better verification
  • Keep the DNS server updated by fixing unpatched flaws
  • Regularly audit the DNS zones

Internet is open for everyone, including cybercriminals who severely exploit the weak points in a company’s security infrastructure. Having a robust DNS security strengthening policy will certainly help organizations mitigate various DNS attacks.

About the Author:

Rudra Srinivas

 

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

Read More from the author.

 

How Uber’s 2016 Data Breach Took a Wrong Turn

Uber Data Breach

Mistakes are inevitable, but intentional acts may result in severe repercussions. Uber’s negligence of hiding a data breach took the taxi-aggregator to multiple wrong roads. The Office of the Australian Information Commissioner (OAIC) recently revealed its findings on the Uber 2016 data breach. The privacy watchdog stated that Uber meddled with users’ data privacy, risking the data of around 1.2 million Australians in 2016.

In an official statement, Angelene Falk, Australia’s Information and Privacy Commissioner, said that the U.S.-based Uber Technologies Inc. and Dutch-based Uber B.V. had failed to protect the personal information of its Australian customers and drivers when attackers allegedly accessed users’ data in October and November 2016.

Uber required the attackers to destroy the stolen data to ensure there was no sign of data breach. However, the investigation by the OAIC unveiled that Uber didn’t take any protective security measures to safeguard Australians’ personal information and violated the Privacy Act 1988.

“Commissioner Falk found the Uber companies breached the Privacy Act 1988 by not taking reasonable steps to protect Australians’ personal information from unauthorized access and to destroy or de-identify the data as required. They also failed to take reasonable steps to implement practices, procedures, and systems to ensure compliance with the Australian Privacy Principles,” the OAIC said.

De-Identification of the Breach

In 2016, Uber sustained a data breach that compromised the personal data from the company’s network, including names and driver’s license information of 600,000 drivers, email IDs, and phone numbers of 57 million Uber users. Instead of reporting the security incident, Uber reportedly paid the attackers, Glover and Mereacre, $100,000 in ransom to keep the hack a secret. In October 2019, the two perpetrators pleaded guilty for their extortion scheme. Uber was penalized in millions by multiple data privacy regulators for not disclosing the security breach until November 2017.

Falk alleged that Uber ignored the security incident by not conducting any security audit on users’ personal information that was illicitly accessed by the attackers. While Falk claimed that Australians’ data had been transferred to servers located in the U.S. via an outsourcing setup, the U.S.-based Uber Technologies Inc. argued it was not subject to the Privacy Act.

“We need to ensure that in future Uber protects the personal information of Australians in line with the Privacy Act. The matter also raises complex issues around the application of the Privacy Act to overseas-based companies that outsource the handling of Australians’ personal information to other companies within their corporate group,” Falk said.

What is Uber required to do?

Commissioner Falk has ordered Uber companies in all the locations to:

  • Maintain data retention and destruction policy
  • Enable an information security program and incident response plan to comply with the Australian Privacy Principles
  • Appoint an independent cybersecurity expert to review and report on these policies and programs and their implementation
  • Submit the security audit reports to the OAIC regularly

“This determination makes my view of global corporations’ responsibilities under Australian privacy law clear. Australians need assurance that they are protected by the Privacy Act when they provide personal information to a company, even if it is transferred overseas within the corporate group,” Falk added.