Home Blog Page 73

How Video Streaming Services Can Stay One Step Ahead of Cybercriminals

streaming services

The global video streaming industry is a multi-billion-dollar market that includes renowned brands such as Disney and Netflix alongside smaller, more niche players. Many of these services have experienced exponential growth due to the pandemic. In 2020, the viewing figures for streaming services were up 71% compared to the previous year.

By Darren Lepke, Head of Video Product Management for Verizon Media

Yet, with great success often comes additional risks and responsibilities. When it comes to security, streaming providers think first about content protection and methods of thwarting piracy e.g. DRM and Forensic Watermarking. Streaming services are also home to data from potentially millions of customers, which includes names, email addresses, and payment details. This new focus on consumer data is an example of how threats continue to evolve and shows that no industry is safe.

Many streaming services have struggled to evolve their cybersecurity tools in line with the growth of their subscriber base, leaving them vulnerable to cyberattacks that take advantage of the vulnerabilities specific to OTT platforms and technologies. It’s a vicious cycle:  The more popular a streaming service becomes, the more susceptible it becomes to cyberattacks due to the growing numbers of users and devices, giving cybercriminals a greater surface area to attack.

Every single streaming service has the potential to attract unwanted cyberattacks from cybercriminals. The most common cyberattacks include:

  • Application attacks: cybercriminals exploit vulnerabilities in the application architecture and software code that may or may not be publicly known.
  • Distributed denial-of-service (DDoS) attacks: these types of attacks use artificial traffic to disrupt a site or service, making it inaccessible or slow to respond to legitimate users.
  • Credential stuffing: hackers exploit the fact that people tend to use the same username and password combination across multiple accounts. In such an attack, the hackers can buy vast lists of stolen credentials from the dark web and use automation to try each one to gain access to the target service.

Verizon Media recently surveyed security professionals at streaming and OTT service companies to better understand how well prepared these platforms are for cyberattacks. Participants included broadcasters, publishers, studios, content owners, D2C platforms, aggregators, and sports leagues. Although these attack types differ, they are often used in a coordinated fashion. Our survey found that most streaming services have most likely already suffered from a security breach:

  • 80% of our survey participants said they are not prepared for DDoS and Application Attacks
  • 50% said security breaches had corrupted their service’s user experience
  • 30% of respondents said a security breach that had caused a service outage
  • 14% of respondents said their content had been misappropriated

Even streaming services with a powerful cybersecurity solution cannot afford to let their guard down by becoming complacent. Cybercriminals are relentless and will continue to bombard streaming platforms with attacks until they find a vulnerability they can exploit. One of the primary ways streaming platforms can keep pace with cyber threats is by deploying cloud-based solutions.  Our survey found that 30% of responders consider moving to cloud-based security solutions to help minimize security gaps. Adapting to the cloud and CDNs solutions offers streaming services greater scalability and reliability and lower operational costs than on-premise solutions.

We’re likely to see more OTT platforms move to cloud-based solutions, such as WAF, DDoS, and bot detection/mitigation. DDoS Protection is crucial as the latest data suggests it’s a matter of when, not if, a platform experiences this type of attack. Typically, specialized hardware has been used as the first line of defense against DDoS attacks, but they require regular maintenance and support, and they often struggle to keep pace with high-volume DDoS attacks. On the other hand, scrubbing stations, cloud protection, and CDN protection are fast becoming the preferred tools for these types of threats.

Additionally, phishing is one of the oldest and most successful methods for acquiring account passwords. Phishing can involve using users’ email addresses and passwords to start phishing attempts, obtain access to other accounts, or retrieve the billing and credit card information linked with the account. This is where Web Application Firewalls (WAFs) come in handy as they help in eliminating application vulnerabilities that hackers exploit in DDoS, app, credential stuffing, and phishing attacks. They protect servers by analyzing HTTP/HTTPS traffic and applying rules to conversations between the server and clients. The WAF is uniquely positioned to protect against app threats such as SQL injections and cross-scripting attacks. They can help defend against API attacks via mobile apps, malicious botnet attacks, and phishing attacks by ensuring access policies are up to date and enforced. WAF solutions effectively prevent attacks targeting Internet applications. It is worth remembering that these solutions are constantly evolving and that no tool can eliminate all the application’s vulnerabilities. It is often necessary to use more than one type of security.

Bots may become helpful in the battle against cybercriminals. Bots are most commonly thought of as tools to help consumers shop and keep support costs low for services by assisting people to self-diagnose problems. However, they have also become one of the cybercriminal’s favorite tools. Attackers use bots to orchestrate DDoS attacks and handle the massive number of login attempts required for credential stuffing attacks. We’re seeing more streaming services move to cloud-proxies for bot management solutions that are fully integrated into a cloud or CDN service provider implementation. The cloud or CDN provider handles all aspects of the bot management solution for the service provider.

One of the standard approaches to bot management is fingerprinting. The bot looks for changes in behavior, such as if the request seems right based on the browser the requester claims to be using or any unusual behavior, like keystrokes hitting faster than is humanly possible. Once a bot is detected, the security solution must be careful with dealing with the threat. Simply blocking the request or giving a standard error will alert the hacker that they have been blocked. The hacker may then resort to enhanced techniques or a different sort of attack. In this scenario, it is better to fake a response to trick the bot into thinking it has launched a successful attack.

Streaming services are vulnerable to cyberattacks, which will only grow in line with the popularity of these platforms. There is an urgent need for these businesses to work with security experts to identify the gaps between their security priorities and their preparedness and implement robust security solutions to minimize the risk of content and user data falling into the hands of cybercriminals.


About the Author

Darren Lepke is the Head of Video Product Management for Verizon Media. With over 15 years of technology leadership, Lepke has built a proven track record in product management, marketing, and business development. He has deep technical knowledge in software development (large scale cloud SaaS, mobile apps, connected device applications), web services APIs, online advertising, streaming media formats, and metadata management.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Mobile Malware – A Persistent Threat Targeting COVID Vaccines and Banking Activities

Malware and Vulnerability Trends Report, Mobile malware threats

In addition to high-profile ransomware attacks on various industry vectors, cyberattacks on mobile devices surged during the pandemic. When employees across the globe were adjusting to remote working, cybercriminals leveraged different kinds of mobile attacks exploiting the security loopholes in the system. COVID-19-themed cyberattacks took a massive toll on the cybersecurity community. Threat actors disrupted operations of several companies and government agencies compromised thousands of users’ sensitive data by spreading mobile malware, fake apps, and other mobile-related scams.

According to McAfee’s Mobile Threat Report 2021, hackers used Trojans, fraudulent apps, and malicious SMSs to target unwitting users. The fraudsters capitalized on pandemic fears with bogus vaccine-related apps, text messages, and social media links.

Key Findings 

  • Over 90% of malware attacks during the pandemic happened due to mobile Trojans.
  • In total, McAfee uncovered over 43 million mobile malware variants in Q4 2020.
  • A new kind of mobile malware, dubbed Etinu, was found to be distributed via Google Play and targeted users in Southwest Asia and the Middle East. The malware has more than 700K downloads before it was detected and removed.
  • Banking Trojan activity increased 141% between Q3 and Q4 2020, which are distributed via phishing and fraudulent messages.
  • McAfee discovered Brazilian Remote Access Tool Android (BRATA), a banking Trojan, targeting thousands of users into downloading it.

Vaccine Rollout Increases Mobile Threats

McAfee stated that the COVID-19 vaccination campaigns created ample opportunities for cybercriminals across the globe. Threat actors distributed malware disguised as vaccination slot booking SMS and registration ads. Once the user clicks on the link, it automatically downloads the malware and takes control of the victim’s device.

Unfortunately, some of these fake vaccine campaigns started in November 2020, before any vaccines had officially been approved.

“As people increasingly spend more time online owing to the pandemic and staying connected on their mobile devices, hackers are cashing into target unsuspecting consumers. With the dramatic increase in threats and cybercriminals exploiting mobile devices, our ongoing effort is to ensure that we protect what is of paramount importance to consumers – their personal data. As fraudsters continue to experiment with newer methods and advanced techniques to bypass security screening, we aim to assist consumers by guiding them to remain vigilant and raise awareness on the importance of safeguarding their data and personal devices,” said Venkat Krishnapur, vice-president of engineering and managing director, McAfee Enterprise, India.

Bitcoin Craze Gives Rise to the Cryptocurrency-based Cyberattacks: Report

cryptocurrency-related cyberattacks

Just a couple of days back, Kevin Mandia, CEO of cybersecurity firm FireEye, told CNN that the rise in ransomware attacks is closely associated with the proliferated use of digital or cryptocurrency. He added, “There is a direct connection.” Mandia’s statement proved to be true because research from cybersecurity company Barracuda revealed that a staggering 192% rise in cryptocurrency-related cyberattacks has been registered after the Bitcoin surge in October 2020.

The study, which was conducted between October 2020 and May 2021, saw the researchers discretely analyze phishing and business email compromise (BEC) attacks. After monitoring the trends closely, it was observed that the volume of cryptocurrency-related attacks was associated with the rapidly rising price of Bitcoin. The price of Bitcoin increased nearly 400% during the observation period and saw a subsequent 192% increase in impersonation (i.e., phishing and BEC) attacks.

Until recently, the real-world usage of Bitcoins looked like a far-fetched dream. However, with companies embracing this digital payment option, cryptocurrency has now started gaining more value than expected.

As rightfully stated by Mandia, cryptocurrency has been traditionally used in ransomware attacks and was evident in the Colonial Pipeline attack or the JBS attack, where the companies were asked to pay millions of dollars in Bitcoin as ransom. Mark Lukie, Systems Engineer Manager, Barracuda, Asia-Pacific said, “You don’t need to be a technical genius to launch a ransomware attack. Ransomware-as-a-service — where you can hire a group to carry out an attack for you — is flourishing on the dark web, making ransomware more accessible to criminals, and driving an increasing number of attacks.”

However, Barracuda’s study reveals that cybercriminals are now not just using cryptocurrency for ransomware attacks but are also pivoting towards newer attack vectors. This includes spear phishing, impersonation, and BEC attacks. Cybercriminals are using malicious tactics like sending fake security alerts to steal Bitcoin login credentials, targeting employees with personalized emails, and even tricking users into purchasing or donating cryptocurrency to fake charities.

Another key trend that Barracuda’s researchers observed was that, with every passing year, there has been a spike in both ransomware attacks and the ransom amounts. In 2019, the ransom demand ranged from a few thousand dollars to $2 million, but by mid-2021, the demand reached the ceiling at $20 million.

As a note of caution, Lukie suggested, “Staying on top of the latest trends in email attacks and providing employees with security awareness training to identify and avoid attacks, as the highest priority when it comes to protecting against these kinds of attacks. While making sure you have watertight security solutions in place that provide bot mitigation, DDoS protection, API security, and credential stuffing to secure web applications against ransomware, backing-up data to minimize downtime, data loss, and get your systems restored quickly following an attack, is also necessary and give you peace of mind.”

Related News:

Most Phishing Emails Originate from Eastern Europe: Barracuda

Sigh of Relief for Lorenz Ransomware Victims; Free Decryptor Released

Harness Your System, Free Decryptor, federal government, cybersecurity

Organizations become helpless when their digital assets are encrypted in the event of a ransomware attack, making it difficult for victim companies to recover their files without paying ransom to cybercriminals. Several security researchers and firms often create free decryption tools to help the victims of ransomware attacks. Recently, cybersecurity firm Tesorion developed and released a decryption key to help the victims of Lorenz ransomware in recovering their files without paying any ransom. The free decryptor is available at NoMoreRansom, an initiative from Tesorion to help ransomware victims.

“Based on our analysis of the Lorenz ransomware we have come to the conclusion that we can decrypt (non-corrupted) affected files in some cases without paying the ransom. Supported file types include Microsoft Office documents, PDF files, and some image and movie types. We built a decryptor that we are providing to victims free of charge,” Tesorion said.

Lorenz Ransomware

Tesorion researchers stated that Lorenz ransomware operators are active since April 2021, targeting organizations across the globe. Like many ransomware groups, Lorenz leverages double extortion techniques by stealing victims’ data before encrypting and then threatening them to publish it online if the ransom is not paid. The group has allegedly posted sensitive stolen data of its 12 victims on the dark web.

The Lorenz ransomware used a blend of RSA and AES-128 in CBC mode to encrypt the victim files on a compromised device by generating a random password for each file. In addition, the operators sent the computer name of the compromised system to a command & control (c2) server before the encryption. The ransom demand of Lorenz operators is between $500,000 and $700,000.

“The Lorenz ransomware appears to be a variant of the ThunderCrypt ransomware. We have not analyzed any ThunderCrypt samples and therefore, we do not know whether the file encryption is similar or not,” Tesorion added.   

The Free Decryption Movement

This is not the first time that a company has come to rescue the victims of ransomware attacks. In the recent past, cybersecurity firm Bitdefender released a decryption tool that allowed organizations to recover files encrypted by DarkSide ransomware operators without paying any ransom. The free decryptor tool automatically scans the systems for encrypted files and decrypts them. Read More Here

Secure and Private Compute Summit: Keeping Data Secure Throughout the Data Lifecycle

secure and private compute summit, data, data science

The speed of cloud adoption, the quality of AI development, and the ability to collaborate on sensitive data are often hindered by data security, privacy, and regulatory concerns over how confidential sensitive data is whilst it is being worked on.

Breakthrough confidential computing and privacy-preserving technologies are helping organizations overcome these challenges by protecting data whilst it is in use, closing the final security gap in the data lifecycle. These technologies will enable your organization to adhere to data protection regulations and unlock the power of your sensitive data at a viable cost.

To utilize confidential computing and privacy-preserving technologies, learning how to explain the value of these technologies across organizations, seamlessly integrating them, and identifying which of the technologies is most appropriate to use is crucial.

Introducing the Secure and Private Compute Summit, taking place virtually on July 6-8. This free conference will guide you on how to solve the challenge of keeping data in use private and secure by bringing together multidisciplinary teams from enterprises that are handling sensitive data, the cloud service providers, the system integrators, and the confidential computing and privacy-preserving technology providers.

Here’s a first look at some of the sessions you can attend:

  • How Privacy-Preserving Technologies are Empowering Open Banking Through the Mastercard Digital Identity System; with Bob Schukai, Executive Vice President, Technology Development, Fintech & New Infrastructure, Mastercard
  • Avoiding Data Protection Legislation Penalties Through Using Confidential Computing and Privacy-Preserving Technologies; with Pulkit Vohra, Data Protection Officer, BT
  • Cost-Benefit Analysis of the Privacy-Preserving and Confidential Computing Technologies; with Juan Ramón Troncoso-Pastoriza, Senior Researcher, EPFL (Ecole Polytechnique Fédérale de Lausanne); Shoumeng Yan, Director of Confidential Computing, and Senior Staff Engineer, Ant Financial; Suraj Kapa, Medical Director, AI for Knowledge Management and Delivery, Mayo Clinic
  • Introducing the Confidential Public Cloud – Closing the Final Security Gap in the Data Lifecycle; with Tom Rondeau, Program Manager, DARPA (Defense Advanced Research Projects Agency); V K Cody Bumgardner, Division Chief for Pathology Informatics, University of Kentucky; Christine Huang, Sr. Expert in Data Privacy and Protection, SAP
View the full agenda here.

Upon leaving this event you will be able to close this final security gap in the data lifecycle and be connected with the best confidential computing and privacy-preserving technologies that solve your data security and privacy challenges. This year we are delighted to be partnering with Intel, Duality, Enveil, Decentriq, R3, and Anjuna.

This event is completely free to attend, so what’s stopping you? Book your complimentary pass here.

“By 2025, 50% of large organizations will adopt privacy-enhancing computation for processing data in untrusted environments or multiparty data analytics use cases” – Gartner, 2021.

To find out more, visit www.secureandprivatecompute.com

Rep. Veasey and Others Introduce American Cybersecurity Literacy Act to Mitigate Cyber Risks

American Cybersecurity Literacy Act

Improving cybersecurity awareness among individuals could eventually help mitigate cyber risks. And educating users on different kinds of cyberattacks will make them act accordingly in the event of any potential cyberthreats. Recently, the Bipartisan House lawmakers introduced a new legislation to boost cybersecurity awareness and knowledge on data security among internet users in the U.S. The legislation, the American Cybersecurity Literacy Act, comes after a series of cyberattacks on the country’s critical infrastructure.

The proposed legislation was led by representatives Marc Veasey (D-TX), Adam Kinzinger (IL-16), Anna Eshoo (D-CA), Gus Bilirakis (R-FL), and Chrissy Houlihan (D-PA).

The proposed Act mandates the National Telecommunications and Information Administration (NTIA) to set up a cyber literacy campaign to bring awareness on online security and prevention of potential cyberattacks. The awareness programs include basic security lessons on how to detect phishing emails, the importance of strong passwords, using multi-factor authentication, and risks associated with the public internet.

Commenting on the new legislation,  Congressman Veasey said, “Congress expanding internet availability to millions across our country has underscored the importance for all Americans to know how to properly protect themselves online. The American Cybersecurity Literacy Act will provide federal resources to educate our constituents on how to do everything from properly identifying secure websites to knowing about the potential cybersecurity risks of using publicly available Wi-Fi networks. Ensuring that all Americans have the tools to protect themselves against harmful cyber-attacks make us all safer in the long run.”

Organizations in the U.S. have been suffering from a series of cyberattacks for years. From the persistent SolarWinds attackAccellion data leak, to Microsoft Exchange Servers hack, the threat landscape has grown to more sophisticated ransomware attacks like the Colonial pipeline hack,  disrupting the critical fuel operations in the country.

Do Americans Worry About Cybersecurity?

A recent survey revealed that most Americans are least worried about cybersecurity despite rising cyberattacks in the country. The survey, 2020 Unisys Security Index, found that two in three Americans are not concerned about online security. Over 70% of Americans said they were not worried about their data security being compromised while working from home.

NOBELIUM Group Targeted a Customer Care Agent at Microsoft

security, tech provider

It’s a daily routine for the cybersecurity community to encounter new kinds of cyberthreats from old perpetrators. Recently, the Microsoft Threat Intelligence Center (MSTIC) confirmed a new threat activity from NOBELIUM, the Russian state-sponsored group, which was allegedly behind the SolarWinds hacks, the SUNBURST backdoor, GoldMax malware, and the TEARDROP malware campaigns.

The MSTIC stated that they observed password spray and brute-force attacks from the group targeting certain specific entities, including IT companies (57%), government organizations (20%), and a small percentage of think tanks, non-governmental organizations, and financial services.  The attackers mostly targeted the U.S.-based organizations (45%), followed by the U.K. (10%), Germany and Canada.

Information Stealing Malware

Microsoft stated it also found information-stealing malware on a device belonging to one of its customer support representatives, who had access to the account information of some of its customers. The attackers could have possibly used customers’ compromised data in some of their high-profile attacks. While the investigation is still ongoing, Microsoft has notified all the affected customers and recommended them to take security precautions like two-factor authentication (2FA) or multi-factor authentication to protect their sensitive data from potential threats.

“We responded quickly, removed the access, and secured the device. The investigation is ongoing, but we can confirm that our support agents are configured with the minimal set of permissions required as part of our Zero Trust least privileged access approach to customer information. We are notifying all impacted customers and are supporting them to ensure their accounts remain secure,” MSTIC said.

New Email-Based Attacks from NOBELIUM

Last month,  the MSTIC discovered a large-scale malicious email campaign by the NOBELIUM threat group. The attackers misused the legitimate mass-mailing service, Constant Contact, to imitate as a U.S.-based firm and spread malicious URLs across a wide range of industries.

NOBELIUM email campaign leveraged spear-phishing emails, with malicious HTML attachments, to compromise the targeted systems. Once the victim downloads the attachment, a JavaScript within the HTML file automatically deploys itself and executes the Cobalt Strike Beacon on the compromised system. NOBELIUM reportedly targeted over 3,000 individual accounts across 150 organizations.

“Similar spear-phishing campaigns were detected throughout March, which included the NOBELIUM actor making several alterations to the accompanying HTML document based on the intended target. MSTIC also observed the actor experimenting with removing the ISO from Firebase, and instead encoding it within the HTML document. Similarly, the actor experimented with redirecting the HTML document to an ISO, which contained an RTF document, with the malicious Cobalt Strike Beacon DLL encoded within the RTF,” MSTIC added.

What are the Opportunities for Software Developers in Cybersecurity?

Career Changers, software developers in cybersecurity

In the first article in this brand-new series, titled, Career Changers, CISO MAG reached out to software developers and DevSecOps specialists. For this article, we explore careers for software developers in the field of Cybersecurity. What are the opportunities for developers? What skills do they need to acquire to prepare for cybersecurity roles, and how long will it take to adjust to the new role?

By Brian Pereira, Editor-in-Chief, CISO MAG

Our first question was: What are the career opportunities for software developers in cybersecurity?

software developers in cybersecurity, Ram Movva, President and Co-founder of Cyber Security Works (CSW)Ram Movva, President and Co-founder of Cyber Security Works (CSW) says there are a lot of career opportunities for software developers in cybersecurity.

“From a career opportunity perspective, a software developer can build products for the cybersecurity industry, especially SaaS-based software. We have 100+ openings for software developers in CSW and are building SaaS products,” says Movva.

Ambuj Kumar, DevSecOps Engineer at Curl, software developers in cybersecurityWe also spoke to DevSecOps specialists. Ambuj Kumar, DevSecOps Engineer at Curl, says software developers have a “bright career” if they come over to cybersecurity because they know coding, which is “helpful in the long run.”

Both Kumar and Movva believe that cybersecurity is important for every industry and every business. So, it does not matter which industry a software engineer is writing the code for – it is about the security aspects in the coding and “security by design.” In industry terms, this is called “shift-left,” which means security should come in at the very beginning of the software development lifecycle.

software developers in cybersecurity, Riddhi Patel, Sr. DevSecOps Engineer at IBM Riddhi Patel, Sr. DevSecOps Engineer at IBM, concurs with their views and says everyone wants their product or data to be secured. She tells us that organizations are now thinking more about secure coding principles.

“Enterprises have started understanding their liabilities and realize that having cybersecurity analysts in the organization is not enough. They are now training their developers to build security into software and learn code securely. Today, every organization is shifting security to the left in the software development lifecycle. So, it’s a great opportunity for developers to work with Security Engineers and learn more about cybersecurity,” says Patel. 

Skills and Training

Our next question to them was about skilling and training. We asked: What are the additional skills that a software engineer needs to acquire? And what is the best way to go about it?

“Software professionals who understand the security aspects of safe coding can become successful security practitioners, ethical hackers, and security analysts. They can implement DevSecOps for companies that are building products or providing security services,” informs Movva. “If you are a major in computer science, with a B.Sc, MCA or BE degree, and know how to write code, you can thrive in the cybersecurity industry — even if you are fresh out of college.”

Kumar says software developers need to understand network security, web security, and mobile security — and different security vulnerabilities. He says they should opt for training and certifications such as OSCP, CISSP, CEH.

Brought to you by:

The EC-Council, which owns and publishes CISO MAG, offers various courses to train software engineers for cybersecurity. One can also pursue CISSP, CEH and other certifications through the EC-Council. View a list of courses and certifications here: https://www.eccouncil.org/programs/

The Right Approach

And what are the opportunities? What is the best approach?

“In my opinion, if a person is working as a developer/software engineer and thinking about a career in cybersecurity, I would suggest that they aspire to be a security engineer (DevSecOps Engineer). They can start understanding more about cybersecurity attacks and how they happen due to insecure coding — and the impact of those attacks. As much as they learn about security attacks, they can start thinking about secure coding, which is more in demand,” says Patel.

Patel also mentioned Static Application Security Testing (SAST), a white box method of testing where security engineers will have the source code, and they need to run a SAST tool. With this tool, they can review source code manually for some critical functionalities (like authentication, business logic functionalities, any payment-related functionality) to find the vulnerable functions or vulnerability in third-party libraries used in the application.

Another method is Dynamic Application Security Testing (DAST), a black-box testing method that examines an application while it is running to find vulnerabilities that can be exploited by an attacker.

“There are a lot of things to test in DAST, but one area that needs developer attention is to review client-side coding or a script which is executing at client side. I believe the experience of secure coding will help to find out vulnerable client-side code easily,” added Patel.

Patel also suggests that developers should take part in the discussion/process of threat modeling because it provides a better idea to develop secure code, which helps to understand how to focus on functionality based on the highest risk while developing and have the least authorization for the same that helps to reduce Application Vulnerability Risk.

So how long will it take to acquire all these skills?

Says Kumar, “Overall, for a software developer, it tasks five to six months of consistent hard work to establish a career in cybersecurity.”

Patel agrees and says it will take time to understand security concepts. But one must learn “in the right direction” and “be consistent.”

Views expressed in this article are personal and should not be attributed to the organizations where these individuals are employed.


About the Author

Brian PereiraBrian Pereira is the Editor-in-Chief of CISO MAG. He has been writing on business technology concepts for the past 27 years and has achieved basic certifications in cloud computing (IBM) and cybersecurity (EC-Council).

Microsoft Inadvertently Signed Netfilter Loaded with Rootkit Malware

WhisperGate malware campaign, Flagpro malware, MosaicLoader Malware, drinik

Cyberattacks continue to evolve as threat actors often find or create new hacking methods to break into targeted organizational networks. Recently, Microsoft stated that unknown attackers are spreading malicious drivers loaded with rootkit malware via Windows systems. The technology giant stated the malicious driver “Netfilter” is found communicating with command-and-control (C2) servers hosted in China. The driver is allegedly targeting gaming environments in East Asian countries, manipulating the geo-locations of the gamers to play from anywhere.

Microsoft stated the attacker submitted the malicious driver for certification via the Windows Hardware Compatibility Program (WHCP). The drivers are suspended and under investigation to find any additional signs of malware. The malware allows threat actors to exploit other gamers by compromising their accounts via common hacking tools like keyloggers.

Cybercriminals used advanced techniques in this campaign which are used post-exploitation. “It’s important to understand that the techniques used in this attack occur post-exploitation, meaning an attacker must either have already gained administrative privileges to be able to run the installer to update the registry and install the malicious driver the next time the system boots or convince the user to do it on their behalf,” Microsoft said.

Indicators of compromise

  • 42.4[.]180
  • 113.202[.]180

While the threat actors behind this campaign are still unknown, Microsoft stated that the investigation is still ongoing. “We will be sharing an update on how we are refining our partner access policies, validation, and the signing process to further enhance our protection. There are no actions customers should take other than follow security best practices and deploy Antivirus software such as Windows Defender for Endpoint. By sharing the information we’ve learned with this report, we are raising awareness of these techniques so that more protections can be built-in across the industry and to increase the degree of difficulty for attackers,” Microsoft added.

Video Gamers – The Primary Targets  

Research from Akamai Technologies reveals a surge in web application attacks on video gamers during the pandemic. It stated that the gaming industry sustained more than 240 million web application attacks in 2020, which is a 340% surge from 2019. The research also highlighted the global crises that resulted in the rise of cyberattack traffic in the gaming industry. Read More Here

Ransomware Operators are Introducing More RaaS Schemes: McAfee Report

Bitcoin, Ransomware Attacks

The year 2021 is the genesis of many changes in the regular business model. From the new normal of remote working to new attack vectors, the year has been witness to multiple security challenges. The cyberattack landscape took new dimensions, making organizations question their existing cybersecurity capabilities. Cybercriminal and malware activities have increased exponentially in the Q1 of 2021, according to McAfee Threats Report: June 2021. From regular hacking activities to customized Ransomware-as-a-Service (RaaS) campaigns, cybercriminals have changed their attack vectors by targeting high-profile organizations for a huge ransom.

McAfee’s Key Findings

  • Coin Miner malware increased 117% primarily due to growth in 64-bit coin miner applications
  • The growth of Mirai-based malware strains also increased cyberattacks on IoT devices (55%) and Linux systems (38%)
  • Newly discovered malware threats averaged 688 per minute, an increase of 40 threats per minute in Q4 2020.

Ransomware Saw a Decline 

This might come as a surprise to everyone. However, McAfee revealed that ransomware attacks have declined by 50% in Q1. This is because ransomware operators are now focusing on large organizations rather than targeting small and medium-level companies.

The attackers have been leveraging unique RaaS affiliate groups to target large organizations and are demanding high ransom. This shift in attack technique resulted in the decline of infamous ransomware family attacks between January 2021 and March 2021.  Besides, regular ransomware attacks shifted their focus to monetize their cybercrimes with payments in cryptocurrency. Instead of encrypting systems and holding them hostage until the ransom is paid, Coin Miner malware compromised targeted systems and stealthily used them to mine crypto coins.

“Many more countries have experienced such attacks. What it will not show is that victims are paying the ransoms, and criminals are introducing more Ransomware-as-a-Service (RaaS) schemes as a result,” said Raj Samani, McAfee fellow and chief scientist.

According to the report, the REvil RaaS group is the most detected ransomware threat in Q1, followed by the Ryuk, RansomeXX, Thanos, NetWalker, MountLocker, Conti, WastedLocker, Babuk, and Maze ransomware strains.

“Criminals will always evolve their techniques to combine whatever tools enable them to best maximize their monetary gains with the minimum of complication and risk. We first saw them use ransomware to extract small payments from millions of individual victims. Today, we see Ransomware as a Service supporting many players in these illicit schemes holding organizations hostage and extorting massive sums for the criminals,” Samani added.