Home Blog Page 74

Adversaries on a Vaccine Trail

covid-19 vaccine, vaccine

To most of the world’s population, COVID-19 vaccines may be the most highly valued commodity today. That is not an exaggeration. While governments around the world announce vaccination campaigns in a phased manner, with timelines to vaccinate the entire population — President Joe Biden has set a deadline of May 2021 for vaccinating all adults — people grow more anxious each day. In February, the UN announced that more than 130 countries don’t have a single COVID-19 vaccine, while 10 countries have already dispersed 75% of all vaccines. That is a stark indicator of the rich-poor nation divide. Naturally, there is competition among nations to produce vaccines, with some nations practicing “vaccine diplomacy” or using it for regional dominance among “friendly nations.” Vaccine producers are working overtime to produce enough vaccine doses to fulfill government commitments and timelines. While pharmaceutical companies stepped up their production schedules to develop and test vaccines, adversaries tracked the news and devised campaigns to leverage the momentum generated by news coverage. They capitalize on the fear and uncertainty of people to spread misinformation and to plan attack vectors. The result: phishing campaigns with vaccine themes; malware attacks for exfiltration of sensitive and personal information and clinical trial data. Fake websites are purporting to offer (miss) information about vaccine distribution. There are attacks on supply chains and networks of pharma companies too.

By Team CISO MAG

Attacks on Pharma Companies Not New

Attacks on pharma companies occurred even before the pandemic. The attacks increased in the early months of the pandemic.

Yihao Lim, Principal Intelligence Advisor (Asia Pacific), FireEye, told CISO MAG that his company researchers have been closely monitoring attacks on pharma companies and industry institutions.

“This is not new. Since last year, we saw activities directed towards pharmaceutical companies. Not everyone is doing a vaccine, and sometimes it is not specifically to steal vaccine data. Sometimes it is just to understand what is going on in these companies and to find out if there is any new research,” said Lim.

Rohan Vaidya, Regional Director of Sales – India, CyberArk, says Indian pharma companies were attacked much before the pandemic set in. He takes us back to the beginning of 2019 when many Indian pharma companies were applying for FDA licenses for manufacturing, and then exporting drugs to the U.S. The FDA mandated certain policies for these companies to protect their intellectual property and infrastructure.

“We had conversations with these companies at that time and we realized that there was a constant attack vector that was actually happening. All conversations pointed to the fact that there have been certain incidences which they were working on and fixing. They were consulting companies and figuring out which (security) solution to buy,” said Vaidya.

Vaidya confirms that the scale of attacks on pharma companies started increasing even before the pandemic…To read the full story, subscribe to CISO MAG.

This story first appeared in the April 2021 issue of CISO MAG.

Episode #12: Digital Transformation Amid COVID-19, and the Impediments

Digital Transformation

The ongoing pandemic and uncertain market conditions have had a significant impact on Indian organizations’ IT strategies. IT delivery witnessed a massive change with organizations aggressively adopting a cloud-first approach, digital transformation and putting even more pressure on legacy data protection. According to Veeam’s Data protection Report 2021, 64% of Indian organizations accelerated their Digital Transformation initiatives to enable real-time data capture, lower processing time, and accelerate business outcomes. 73% of Indian organizations increased cloud adoption and 73% increased their hybrid-IT deployment.

Organizations also faced tremendous IT challenges with respect to legacy systems and data protection. According to the report, 77% of organizations face an issue with recovering applications in an acceptable timeframe and 69% of them face a ‘protection gap’.  Due to this, IT leaders are looking for immediate results to address their critical data protection needs.

In this podcast with Augustin Kurian, Assistant Editor of CISO MAG, Sandeep Bhambure, Vice President and Managing Director, Veeam India and SAARC, discusses key insights, trends, and gap analysis from the report.

RSS: https://feeds.soundcloud.com/users/soundcloud:users:899202688/sounds.rss

Spotify: https://open.spotify.com/show/7pBhvwEVAaL4uUJnzD5rWO

 

Bhambure is a successful business leader with over 20 years of experience in the IT industry in sales leadership and general management. An industry veteran with a proven track record of consistently driving business growth,  he has built lasting relationships with ISVs, system integrators, OEMs, independent consultants, and regulators across India.

Most recently, Bhambure was the Regional Director (enterprise) and Country Manager (cloud service providers business) at Dell EMC. Prior to this, he held senior sales leadership roles within IRIS Software, Symantec, and SAS. He began his career at Sonata Software as a Regional Manager (ERP).

REvil Ransomware Gang Targets Popular U.K. clothing brand, FCUK

ransomware, ryuk ransomware, cox media

U.K.-based quirky fashion brand, French Connection (better known by the tag name FCUK) has reportedly been attacked by the REvil (aka Sodinokibi) ransomware gang. The attack was first reported by The Register, which confirmed that “no evidence” of customer data compromise was found but passport and identification card details of its employees, including that of the Founder and CEO Stephen Marks was stolen during the ransomware attack as a “proof-of-breach.”

The REvil group reportedly penetrated the backend servers of FCUK, allowing them to exfiltrate critical insider data before encrypting the systems. Soon after the attack was spotted, the IT team of FCUK sprung into action and suspended all affected systems on their network to contain the damages. The company is working closely with an undisclosed third-party cybersecurity firm to resolve the issue at the earliest. It also reported the incident to the Information Commissioner’s Office (ICO) as per the regulatory protocol.

Just hours after this incident, Brazilian healthcare company Grupo Fleury announced that it was a victim of a ransomware attack targeted by the same group – Revil. As per The Rio Times, its systems remained offline as the majority of them were blocked in the aftermath of the attack.

REvil Ransomware Gang’s Menace in Q1 2021

Just a day back, McAfee Labs released their ransomware research and findings from Q1 2021. McAfee detected 1,358 ransomware-related malware families containing signatures of the REvil ransomware group alone. Another interesting fact noted by McAfee’s researchers was that “smaller” ransomware campaigns (i.e., campaigns targeted at smaller companies) saw a downfall in Q1 while the Ransomware-as-a-Service (RaaS) campaigns targeted and breached larger organizations. Besides, the majority of these victims received a custom-made variant. This highlights the threatening dominance of the REvil group and its flourishing ransomware attack surface across industries.

Related News:

REvil Ransomware Gang Targets Apple’s Supplier, Quanta; Threatens to Leak Blueprints

Pakistan-linked Hacker Suspected of Targeting Indian Power Companies with ReverseRat

Android Trojan, Trojan, ReverseRat, Numando Banking Trojan

Days after reports of cyberespionage campaigns by Chinese state-sponsored actors targeting the Indian power sector, security researchers uncovered a new cyber operation by suspected Pakistani hackers. Cybersecurity firm Lumen’s Black Lotus Labs recently uncovered a new remote access trojan (RAT), dubbed ReverseRat, targeting public and private energy companies in the South and Central Asia regions. Along with ReverseRat, threat actors also deployed an open-source RAT known as AllaKore to compromise targeted machines and obtain access.

The most affected organizations in the campaign are based in India, followed by a small number of organizations in Afghanistan. Lumen suspects Pakistan state-sponsored actors are likely behind this campaign, which is said to have begun in January 2021.

The ReverseRat campaign uses advanced techniques to evade detection from security scans. These include:

  • Leveraging compromised domains to store malicious files
  • Selecting high-profile victims after compromising their domains
  • Using repurposed open-source code and In-memory component during initial access
  • Alteration of registry keys to stealthily access the targeted device

ReverseRat Infection Chain

  • First, attackers send specially crafted malicious URLs to the targets.
  • Once the victim clicks on the link, it automatically downloads a .zip file containing a Microsoft shortcut file (.lnk) and a benign PDF file.
  • The zip file then deploys two HTA files named CactusTorch and preBotHta , which contain malicious JavaScript code.
  • Finally, ReverseRat starts its execution.

“While this threat actor’s targets have thus far remained within the South and Central Asian regions, they have proven effective at gaining access to networks of interest. Despite previously relying upon open-source frameworks such as AllaKore, the actor was able to remain effective and expand its capabilities with the development of the Svchostt agent and other components of the ReverseRat project. We assess that as the actor continues to develop these capabilities, utilize compromised domains, and refine these multi-step infection processes, it will pose a real threat to organizations in and beyond these regions. While this actor is not as sophisticated as the most-skilled state-sponsored actors, it should be continually monitored,” Lumen said.

Attention Gamers! Your Cybersecurity Score Matters

Gaming

Cybercriminals and ransomware operators often play with their hacking skills, targeting victims for sensitive information. Despite enhanced security measures, threat actors targeted all sectors during the pandemic, and the online gaming industry has been the most affected.

According to research from Akamai Technologies, the gaming industry sustained more than 240 million web application attacks in 2020, which is a 340% surge from 2019. The “State of the Internet/Security report, Gaming in a Pandemic” highlighted the global crises that resulted in the rise of cyberattack traffic in the gaming industry.

Rise of Web Application Attacks

It was observed that SQL injection was the top web application attack in 2020, accounting for 59% of all attacks, followed by local file inclusion (LFI) attacks (24%). While Cross-site scripting (XSS) attacks accounted for 8%, remote file inclusion (RFI) attacks were recorded at 7%. Threat actors leveraged different kinds of web application vectors to target gamers’ login credentials and sensitive information stored within the applications.

The report also stated that the video game industry encountered nearly 11 billion credential stuffing attacks in 2020 — a 224% increase compared to last year. Cyberattacks on gamers and game developers were recorded at a rate of millions per day, with 100 million attacks within two days. Cybercriminals were found trading stolen credentials and other private data on various dark web markets, from other actors, to launch account take over, phishing, and credential stuffing attacks.

“Criminals are relentless, and we have the data to show it. We’re observing a remarkable persistence in video game industry defenses being tested on a daily – and often hourly – basis by criminals probing for vulnerabilities through which to breach servers and expose information. We’re also seeing numerous group chats forming on popular social networks that are dedicated to sharing attack techniques and best practices,” said Steve Ragan, Akamai security researcher and author of the State of the Internet / Security report.

“Recycling and using simple passwords make credential stuffing such a constant problem and effective tool for criminals. A successful attack against one account can compromise any other account where the same username and password combination is being used. Using tools like password managers and opting into multi-factor authentication wherever possible can help eliminate recycling and make it far more difficult for bad actors to execute successful attacks.”

Risks with Mobile Gaming Apps  

Threat actors also frequently target mobile game apps and in-app purchases. They look for gamers’ purchase data or transaction details by creating fake mobile applications. Earlier, Google reportedly removed 21 malicious Android apps from its Play Store after discovering intrusive adware and Trojans in them. According to a report from security solutions provider Avast, the fraudulent apps were disguised as gaming apps and contained HiddenAds Trojan.

NIST Releases Preliminary Draft for Ransomware Risk Management

ransomware, fonix, fonix ransomware, Cybereason Partners with Intel for Hardware-Enabled Ransomware Prevention, Kronos

Not long ago, President Joe Biden passed an Executive Order encouraging the initiation of stronger cybersecurity reforms across the public and private sectors in the country. It was specifically aimed at closing the gaps and fixing the loopholes that have been invariably exploited by the threat actors in the recent past. Biden particularly referenced this towards the SolarWinds incident and a plethora of ransomware attacks that hit U.S. hospitals at the far end of 2020 and has since been on an upward tilt. In line with this executive order and with an intent to immediately address the ransomware menace, NIST’s National Cybersecurity Center of Excellence (NCCoE) has released a preliminary draft titled “Cybersecurity Framework Profile for Ransomware Risk Management” that is currently open for public comments.

Ransomware Risk Management

The ransomware risk management profiling established in this draft is based on NIST’s cybersecurity framework version 1.1, and is built on the core functions to identify, protect, detect, respond, and recover. Each function is further divided into several sub-categories and selected informative references, which then guide the implementation to achieve the objective of each core function. NIST has additionally mentioned how ransomware can affect each core function of the Cybersecurity Framework and how to effectively manage a ransomware risk in each of these instances.

Among the basic measures listed in this draft by NIST, the most common yet effective recommendations against any form of cyberattack include an antivirus solution, up-to-date patch application, role-based access control (RBAC), backup and restore plan, etc. However, one of the most important steps for recovery from a ransomware attack is an incident recovery plan, which the NIST highlights and says, “could be a part of a continuity plan as well.”

According to NIST, the said Ransomware Profile is intended and applicable for organizations that:

  • Have already adopted the Cybersecurity Framework.
  • Are familiar with the Cybersecurity Framework and want to improve their risk posture.
  • Are unfamiliar with the Cybersecurity Framework but need to implement a risk management framework to meet ransomware threats.

The first draft of the ransomware profile will be open for comments until July 9, 2021, post which it will undergo changes and/or additions based on the recommendations and will be released again for further comments. Only after this, the final version of the Ransomware Risk Management document will be published for broader implementation.

Related News:

The Zero Trust Primer: A Simple Overview of the NIST 800-207 Draft

EU Proposes a Joint Cyber Unit to Boost Cybersecurity Readiness

EU Joint Cyber Unit

New threat vectors are emerging every day and it’s a challenge for organizations to tackle them with basic cybersecurity measures. Governments and organizations across the globe are looking for additional resources and cybersecurity collaborations to deter the evolving cyberthreat landscape. In a recent official announcement, the European Union (EU) proposed a Joint Cyber Unit to enhance cybersecurity readiness against rising state-sponsored attacks.

The suggested Joint Cyber Unit is intended to bring cybersecurity expertise and resources from the cybersecurity community, law enforcement agencies, defense, and private organizations across the EU and its Member States.

Common Platform for Cybersecurity

The Joint Cyber Unit will enable the cooperation of both physical and virtual platforms where industry experts, institutions, and enterprises can perform joint operations and share intelligence on how to effectively respond and prevent high-profile attacks. The proposal to create the Joint Cyber Unit is a critical move towards enhancing the European cybersecurity crisis management. It ensures a coordinated response from the authorities in event of a cyberattack and assists in recovering from it.

Commenting on the new proposal, Josep Borrell, High Representative of the Union for Foreign Affairs and Security Policy, said, “The Joint Cyber Unit is a very important step for Europe to protect its governments, citizens, and businesses from global cyber threats. When it comes to cyberattacks, we are all vulnerable and that is why cooperation at all levels is crucial. There is no big or small. We need to defend ourselves, but we also need to serve as a beacon for others in promoting global, open, stable, and secure cyberspace.”

Cybersecurity – A Top Priority

According to a report released by Hiscox, a cyber insurance providing company, cyberattacks across several verticals in the U.S. and Europe have seen a sharp surge, whereas the cyber readiness of the organizations has come to a halt. The survey included nearly 5,400 private and public sector organizations from the U.S., the U.K., Belgium, France, Germany, Spain, and the Netherlands.

Cybersecurity has become a top priority for the EU and its Member States to protect the critical infrastructure, health care facilities, research centers, and civilians from potential state-sponsored attacks, especially during the pandemic.

Business Email Compromise: The Most Common Threat Vector Across Sectors

Business Email Compromise Attacks

Business Email Compromise (BEC) attacks have become the most common email threats across various sectors, giving rise to many social engineering and financial frauds. In a BEC attack, threat actors initially pilfer credentials of targeted business email accounts, and later use them to launch phishing and social engineering attacks on unwitting employees. Besides, threat actors often use stolen credentials to launch financial fraud campaigns like fraudulent email messages, requests for out-of-channel fund transfers, and deleted accounting trails.

According to the 2021 Business Email Compromise Report from GreatHorn, of all security incidents suffered by organizations last year, BEC attacks accounted for 50%, resulting in other kinds of threats like loss of data (16%), compromised accounts (36%), and payment fraud (16%).

Key Findings

  • Spoofing email accounts (71%) and spear-phishing attacks (69%) are the most common type of BEC attacks.
  • Nearly 30% of organizations claimed that over 50% of malicious links are received via emails, which are intended to steal credentials.
  • 34% of respondents stated that the finance department is the most targeted and frequent victim of spear-phishing attacks.
  • Over 65% of security experts admitted that their organization has suffered a spear-phishing attack in 2021.

Information is Wealth

Our sensitive information is cybercriminals’ wealth. Once attackers get hold of our private data, they could misuse it for various fraudulent activities. BEC attackers typically spoof company’s or high-profile employee identity to spread the malware. The report claimed that threat actors are using company names (68%), targeted employee names (66%), and manager-level names (53%) to phish executives into performing hackers’ intended activities.

The report is based on the responses of 270 IT and cybersecurity professionals in the U.S., involved in fighting against BEC attacks and related email threats.

BEC Attacks Continue to Rise

Similar research from the APWG (Anti-Phishing Working Group) revealed how enterprises lose their wealth to BEC attacks. The email attacks have become a highly remunerative line of business for threat actors. In its “Phishing Activity Trends Report,” APWG stated that the average wire transfer loss from BEC attacks surged from $54,000 in Q1 2020 to $80,183 in Q2 2020, as cybercriminals expected high returns.

Related story: How to Detect Suspicious Email Attachments

Belgium’s City of Liège Falls Victim to a Cyberattack

City of Liège, dutch-parliament, norwegian paliament cyberattack

Belgium has been a hotbed for cyberattacks. First, the country’s leading internet service provider (ISP), Belnet, was being attacked with multiple instances of DDoS attacks. The aftermath of the cyberattack was felt on Belgium’s government and private sector organizations, which included well-known universities, public administrations, and research institutes. And before the dust of this surgically targeted attack could settle, Belgium’s City of Liège issued a red flag stating, they have fallen “victim to a large-scale targeted computer attack of criminal nature.”

What is affected in the City of Liège?

As per the status message published on the city’s official website, several civil status and population-related services were affected due to the massive cyberattack and remained partially unavailable when the news was being reported. Of the many Municipal Departments of the City of Liège, people having appointments with public services were advised against visiting the respective premises until access to the city’s IT networks was restored. Impacted services include:

  • Foreign population service (foreign nationals service)
  • Birth service
  • Wedding service
  • Nationalities service
  • Burial service
  • Welcoming cemeteries

Additionally, due to the unavailability of the online services, the Municipality stated that no new documents such as passports, driving licenses, or identity cards could be ordered, however, the ones that were already ordered were available at certain town halls and district centers.

Was Ryuk Ransomware Gang responsible?

Although the official statement did not mention the type of attack, the perpetrators, or whether any data was stolen,  some regional news reports claimed that the City of Liège was targeted with a ransomware attack by the notorious Ryuk ransomware gang. This is a possibility based on the theory that, a day after the attack, “black screens” were being displayed on the systems of some of the employees in the city. Yet, nothing can be confirmed unless an official statement is released by the city’s municipality/council.

Belgium’s Cybersecurity Strategy 2.0

The country has already taken note of the increased volume of cyberattacks targeted at its public and private infrastructure and introduced the country’s Cybersecurity Strategy 2.0, a month back. To keep its cyber defenses at par with the evolving threats of today, Belgium’s National Security Council approved the addition of a new and more refined cybersecurity strategy based on six specific objectives. Click here to read more about it in detail.

Birlasoft and Regulativ.ai Co-Develop AI-Led Cyber-Regulatory Reporting Platform

Security and Compliance in Cloud

The rapid pace of Digital Transformation has unleashed a high volume of cyberthreats. This is making cybersecurity and compliance a top priority for CXOs and making it critical for businesses to ensure their cyber-regulatory compliance roadmap is in place. To address this, Birlasoft Ltd, part of the $2.4 billion diversified The CK Birla Group, has partnered with a startup named Regulativ.ai to co-develop a new AI/ML-based cyber-regulatory reporting platform. The two companies said the co-developed platform will help regulated enterprises gain a deeper understanding of their cyber regulatory compliance risks and provide them with actionable reports to mitigate risks and ensure compliance.

By Brian Pereira, Editor-in-Chief, CISO MAG

cyber-regulatory reporting platform, Shilpa Bhandari, SVP and Global Head - BFSI, Birlasoft,
Shilpa Bhandari, SVP and Global Head – BFSI, Birlasoft

Speaking to CISO MAG, Shilpa Bhandari, SVP and Global Head – BFSI, Birlasoft said, “CISOs are looking for a view of their posture or the organization’s posture to cyber regulatory compliance requirements in various jurisdictions. The process today is highly manual and highly inefficient so rarely are they able to get a live view of where the organization is compliant and where there are gaps from a cyber regulatory perspective. This cyber-regulatory reporting platform, with its degree of automation and integration with various data sources, leverages machine learning and digital technologies to give CISOs that view on a more current basis. This is going to help CISOs do action planning around gaps that they want to prioritize to address, to work with the CEOs and even the Board, to prioritize and seek more budgets.”

Bhandari informed that there is also an element of auditability in the solution.

“It is an online platform with the ability to look at all the data sources, internal and external, that are being used to provide this reporting to a Chief Compliance Officer or Head of Audit,” she added. 

Solving a Major Pain Point

cyber-regulatory reporting platform, Jinal Shah, CEO, Regulativ.ai
Jinal Shah, CEO, Regulativ.ai

Jinal Shah, CEO, Regulativ.ai told CISO MAG that the cyber-regulatory reporting platform is solving many pain points for organizations.

“The fundamental pain point is inefficiency in organizations that are required to comply with the various statutory cyber regulatory & cyber audit and certification requirements. The inefficiencies are due to lack of collaboration between teams, lack of information, lack of data, or poor-quality data. Each CISO organization collects data from all manner of sources to put together a report for the regulator. It takes time to collect the data, sanitize it, verify it, and clean it. This could take anything between 500 – 600 manhours per assessment, per year,” said Shah.

Cyber-Regulatory Reporting Platform

Compliance has become a huge challenge for security teams when there are so many norms to follow and varying output formats. Manual processes cannot do justice. Static budgets mean security teams cannot be expanded. As if that wasn’t enough, the volume and variety of threats are increasing exponentially.

Shah also informed us that this cloud-based solution uses an NLP engine to automate the extraction of the entities from the questions of the policies that are published by the regulators. It identifies key entities and keywords and generates data mappings with the organization’s data. In that sense, the solution creates a taxonomy of regulations that are fed to the NLP engine. He claims the overall automation can realize significant efficiency benefits to organizations of anything between 40% – 70%.

Regulativ.ai is a team of technologists collectively with 115 years of experience in Banking, and 30 years in AI and ML. Its technology platform caters to regulated sectors (Financial, Health care, Aviation, Defence, Non-profits) addressing increasing cybersecurity regulatory compliance challenges.

Regulativ.ai was recently selected as a member of global CYBERTECH100 2021, from a field of over 1,000 companies. CYBERTECH100 identifies the 100 most innovative global companies that every financial institution needs to know about when they consider and develop their information security and financial crime-fighting strategies.

Regulation in Multiple Geographies

The cyber-regulatory reporting platform can be adapted for use in various geographies to comply with local regulations. For now, Birlasoft wants to focus on North America and the English-speaking countries in Europe.

“We are starting with N. America and Europe. Within Europe, our presence will be in the four English-speaking economies, namely Germany, U.K., Switzerland, and France. But we also see many opportunities in Southeast Asia,” said Bhandari.

Shah says there are “no restrictions” in terms of what regulations can be covered within the cyber-regulatory reporting platform.

“We’re looking at various regulations around the world: the U.S. regulations (NYDFS, NFA, FINRA) the U.K. ones, Hong Kong, Singapore, India. All the regulations we see there are known standards. They are all structured differently because they expect a different response from each client — and the response itself is not structured correctly. The U.S, the U.K., and EU are seen as leaders in legislation and regulation policies. All the other OECD countries will typically look at those regulators and regulations to set the lead. So, it makes sense for us to tackle those jurisdictions first to get those regulations automated,” said Shah.


About the Author

Brian PereiraBrian Pereira is the Editor-in-Chief of CISO MAG. He has been writing on business technology concepts for the past 27 years and has achieved basic certifications in cloud computing (IBM) and cybersecurity (EC-Council).