Home Blog Page 91

Think Before You Scan! Malicious QR Codes in the Wild

Crypto ATMs and QR Codes

Since the outbreak of the COVID-19 pandemic, people across the globe have encountered dramatic changes in their daily lives. From the way we used to communicate to the way we worked, the pandemic has affected every facet of our daily routine. In particular, the ongoing crisis encouraged people to make contactless transactions through Quick-Response (QR) codes. However, the swift adaption of digital payments has increased the risks more than ever. Most people are turning to QR transactions unaware of the threats posed to them.

What is a QR Code?

A QR code is a type of barcode that allows a user to access information instantly by a digital device.  QR codes store data as a series of pixels in a square-shaped grid and are mostly used to track details of a particular product in a supply chain.

QR Code Abuse

Since QR codes have made mobile payments efficient, threat actors find them easy to abuse. This is called ‘Qshing.’

According to a recent survey from cybersecurity firm Ivanti,  consumer-based QR codes pose severe security threats to corporate systems and data. The survey conducted on 4,100 consumers across the U.S., U.K., France, Germany, China, and Japan revealed that the heightened need for contactless transactions has increased the use of QR codes. Nearly 57% of respondents claimed an increase in QR code use since March of 2020, and 83% of survey respondents said they’ve used QR codes for the first time to make payments in the last year.

Ivanti revealed that the proliferation of QR codes is leveraged to infiltrate mobile devices and steal sensitive financial data.

Malicious QR Codes in the Wild

Cybercriminals often follow trends. Several QR code payment frauds have been reported as consumers are making more digital payments than ever. Threat actors embed malicious URLs containing malware into a QR code to exfiltrate data from the user’s device when scanned. At times, they also embed malware in a QR code that redirects the victim to a phishing page asking to enter sensitive information. 

Threats from Malicious QR Codes

  • The malicious QR codes can add unknown/suspicious contacts to the mobile contact list.
  • They can connect the victim’s device to a malicious network.
  • The malware embedded in the QR code can automatically initiate phone calls, draft emails, and send text messages.
  • It can reveal the user’s location.
  • Automatic fraudulent payments are initiated.

Things to Remember

Don’t initiate the payment, if you get a notification to put any sensitive information when you scan a QR code.

  • Avoid scanning random QR codes from suspicious or unknown sources.
  • Don’t scan QR codes received via emails.
  • Make sure the QR is original and not pasted over with another one.
  • Use QR scanner software to view the URL before clicking on it.

Guidelines from a Banker

Recently, India’s largest bank, the State Bank of India (SBI), issued an alert relating to QR code scans. Posting a tweet and awareness video on QR payments frauds, the banker warned people to be vigilant while scanning QR codes shared by anyone unless the objective is to pay.

https://www.youtube.com/watch?v=bu8JZLIHg-c

“You don’t receive money when you scan the QR code. All you get is a message that your bank account is debited for an ‘X’ amount. Do not scan QR codes shared by anyone unless the objective is to pay. Stay alert. Stay safe,” the SBI said.

Good cyber hygiene, awareness of mobile threats, and security can help in mitigating the rising threat from malicious QR codes.

Leveraging Security Psychology to Mitigate Cybersecurity Risk

security, teams, skills

Problem Statement: Human risk is real, and information and cybersecurity awareness trainings are not assuring and adequate. Period.

Often security trainings are compliance-focused, as against assurance-focused. Agree?

By Ashish Paliwal, Information Security Officer, Sony

Scare Tactic

Email scams related to COVID-19 surged 667% in March 2020 alone. Users are now three times more likely to click on pandemic-related phishing scams. Furthermore, 90% of newly created Coronavirus Domains are scammy with a 2000% increase in malicious files with “Zoom” in name as an example. Going back a bit, data breaches exposed 4.1 billion records in the first six months of 2019 globally; and 76% of businesses reported being a victim of a phishing attack in the same year.

security psychology

Studies

  • Leron Zinatullin, a security researcher, in his book titled The Psychology of Information Security published in 2016 refers to below common reasons for non-compliance:
    1. No clear reason to comply
    2. Cost of compliance too HIGH
    3. Inability of compliance
  • Iacovos Kirlappos, Adam Beautement, and M. Angela Sasse‘s research report published in 2013 on “Security-Awareness Principal Agents” abandons the traditional
    “command-and-control” approach which mostly comprises of a long list of do’s and don’ts often as part of “annual security training” which has little to no effect on security behaviors.
  • Furthermore, research on “Susceptibility to Persuasion” by the University of Cambridge, endorses a similar school of thought, consisting of 10 broad categories with each to have proven in the past to have some connection with individuals being persuaded to do something; like respond to an advert or change their usual behavior slightly.

Ref: Susceptibility to persuasion (i.e. persuadability) is a phenomenon of the subject who is persuaded, but is influenced by the plausibility of the story of which they are persuaded.

Also, refer to the Persuasion Techniques (below) published by Dr. BJ Forgg, Director of Behavior Design Lab @ Stanford University.

  1. Principle of reciprocation: People feel obligated to return a favor.
  2. Principle of scarcity: When something is scarce, people will value it more.
  3. Principle of authority: When a request is made by a legitimate authority, people are inclined to follow/believe the request.
  4. Principle of commitment and consistency: People do as they told they would.
  5. Principle of consensus: People do as other people do.
  6. Principle of liking: We say “yes” to people we like.
  • Lastly, an article titled “Awareness Isn’t Enough” published by Jinan Budge, Principal Analyst @ Forrester also endorses influencing behavior by explicitly calling out the ABC of Security (Awareness, Behavior, and Culture). I suggest attempting drawing assurances from these.

Psychology and Cybersecurity

Proposal

Build a “control ecosystem” by tying together psychological and behavioral traits influencing “security” decisions, to positively impact and pre-empt the same via Plan A and/or Plan B.

Plan A

  • Psychometric test with emphasis on the overlap of security traits with that of personality influencing any positive and/or negative behavior
  • Venturing beyond security trainings into areas of behavioral modeling

Plan B

Introduction of the concept of Security Behaviour Reflection (SBR) Score

What is SBR Score all about?

  • At the start of the year, all in the organization are assigned or start with say 100 points or $1000 (for example.)
  • Penalize negative behaviors via deduction of points/$ (E.g. For phishing cases, -10 points for clicking, +10 for reporting, and -5 in case of no action. For data leakage, -25 points; etc.)
  • Urge managers to consider SBR Scorecard for promotion and/or appraisal decisions
  • Managers of reportees with maximum or minimum scorers to be rewarded and/or trained in accordance.

POC/Test Results

For testing/learning via a very small sample set, leveraged Cattell’s 16 PF (Personality Factors) survey (https://openpsychometrics.org/tests/16PF.php).

Psychology Negative Traits Psychology Positive Traits

Meaning, correlations can be drawn between negative security behaviors and high tension, lower vigilance, and apprehensions. And, emotionally stable, rule conscious, and rational employees are more likely to exhibit positive security behavior.

Learnings

  • Reassurance on behavioral aspects influencing security decisions
  • Aligning approach to focus on positive and negative traits complementing organizational/industry context and culture

Benefits

  • Endorsing Security Culture
  • Threat Landscape Reduction
  • Data Security
  • Client Confidence ($)

Challenges 

  • Psychometric tests are ‘point-in-time’ indicators, and not 100% fool-proof
  • $ aspect
    • Psychometric tests are charged on ‘per-test’ basis
    • # of psychometric required can be high depending on the size of your org
  • Addressing the ‘privacy’ aspect before initiating psychometric tests (explicitly or implicitly)
  • For SBR scoring, heavy reliance on allied teams (like incident management team, team managing and floating anti-phishing campaigns, etc.) with effective false-positive validations and considerations.

Work Arounds

  • Create psychometrics tests in-house with a best-effort-basis algorithm
  • Review onboarding (HR) policy for inclusion of ‘permissions’ for running psychometric tests

Recommendation / Way Forward: Engage!

  1. Consider conducting psychometric tests for new-joiners and information and cybersecurity offenders. These tests can also be tailored to fit the organizational context and culture.
  2. Next, Structured Cognitive Behavioral Trainings (SCBT) can be imparted in addition to regular infosec trainings.
  3. Consider introduction of the concept of Security Behavior Reflection (SBR) Scores at an enterprise level.

Meanwhile, stay safe and stay psyched about security!


About the Author

Ashish PaliwalAshish Paliwal is a security innovator and change agent with extensive information security, risk, and infrastructure management expertise of 12+ years while translating evolving industry risks into ambitious technology roadmaps and robust security programs.

 

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

U.S. Space Command to Launch New Cyber Center for Better Cyber Integration

Cybersecurity meeting, Biden Administration and Tech Giants, Zero-Trust Model

Cybersecurity is a critical element for the smooth functioning of a business. Having the right security solution works wonders for an IT architecture for now and the future. Keeping this in mind, the U.S. government announced the launch of a joint cyber center to promote the collaboration between the Space and Cyber Command Centers in the U.S. The launch of the new cyber center was announced by the commander of U.S. Cyber Command, General James Dickinson, during a 2022 fiscal budget hearing with U.S. Strategic Command and Space Command (USSPACECOM). In a testimony, Dickinson warned about rising cyberthreats from the East targeting organizations in the U.S.

“We are setting up a joint cyber center within the command as we speak. I also have, as a result of the command standing up, I’ve got five service components provided by each of the services to the combatant command with two of those — my Navy component as well as my Marines component — who are dual-hatted,” Dickinson said.

Achieving Digital Superiority

Dickinson stressed creating a robust cybersecurity environment to secure the nation’s intellectual and technological infrastructure from evolving cyberthreats. He stated the importance of funding fundamental capabilities like cybersecurity, battlespace awareness, command and control, and deterrent space capabilities.

Rising Threat from East

Dickinson warned about potential threats from adversaries in Iran, North Korea, China, and Russia. He informed that Russia and China are developing anti-satellite weapon systems to attain national security goals and counter the U.S. military capabilities. Both countries are reportedly restructuring their militaries to develop deeper competency in technical military fields like electronic warfare, cyberspace, and space operations.

Besides, North Korea and Iran are also advancing their counter-space threats via cyberattacks, jamming, and electronic warfare. Iran and North Korea are also said to rely on irregular methods to counter U.S. capabilities.

“We must capitalize on machine learning and artificial intelligence developments to secure our systems, advance our capabilities, and increase the speed of our decision-making process. Accordingly, within our efforts to maintain digital superiority, USSPACECOM is determined to innovate for competitive advantage, evolve cyber operations for an agile and resilient posture, and invest in game-changing technologies. Future years will require additional resources to accomplish all of this, and to ensure the U.S. can adequately address the evolving and expanding cyber threats posed by our strategic competitors and adversaries,” Dickinson concluded.

Eaton Releases Patches to Fix Severe Vulnerabilities in its Intelligent Power Manager Software

power

Eaton, a power management solutions provider had some severe vulnerabilities in its Intelligent power management (IPM) solution, which potentially allowed threat actors to penetrate and disrupt the power supply. Eaton has released patches to fix it.

Eaton’s IPM Vulnerabilities

Eaton’s IPM solution ensures system uptime and data integrity by rendering remote access to organizations. Using this solution one can remotely monitor, manage, and control the uninterruptible power supply (UPS) devices on the network.

However, as per the security advisories published this month by Eaton and the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the IPM product was plagued with six high-severity vulnerabilities. While some of the vulnerabilities can only be exploited by an authenticated attacker, others can be exploited without authentication, including for arbitrary code execution.

Related News:

Did a Cyberattack Cause Power Outage in India’s Financial Capital?

Vulnerability Details

 CVE-2021-23276 

CVSS v3 Base Score – 7.1

CWE-89: Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)

Eaton Intelligent Power Manager (IPM) prior to version 1.69 is vulnerable to authenticated SQL injection. A malicious user could send a specifically crafted packet to exploit this vulnerability. Successful exploitation could allow attackers to add users to the database.

 CVE-2021-23277 

CVSS v3 Base Score 8.3

CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code (‘Eval Injection’)

Eaton Intelligent Power Manager (IPM) prior to version 1.69 is vulnerable to unauthenticated eval injection vulnerability. The software does not neutralize code syntax from users before using in the dynamic evaluation call in ‘loadUserFile’ function under scripts/libs/utils.js. Successful exploitation could allow attackers to control the input to the function and execute attacker-controlled commands.

 CVE-2021-23278 

CVSS v3 Base Score – 8.7

CWE-20: Improper Input Validation

Eaton Intelligent Power Manager (IPM) prior to version 1.69 is vulnerable to authenticated arbitrary file delete vulnerability. This vulnerability incurs due to improper input validation at server/maps_srv.js with action ‘removeBackground’ and server/node_upgrade_srv.js with action ‘removeFirmware.’ An attacker could send specifically crafted packets to delete the files on the system where IPM software is installed.

 CVE-2021-23279 

CVSS v3 Base Score – 8.0

CWE-20: Improper Input Validation

Eaton Intelligent Power Manager (IPM) prior to version 1.69 is vulnerable to unauthenticated arbitrary file delete vulnerability. This is induced due to improper input validation in meta_driver_srv.js class with ‘saveDriverData’ action using invalidated ‘driverID’. An attacker could send specifically crafted packets to delete the files on the system where IPM software is installed.

 CVE-2021-23280 

CVSS v3 Base Score – 8.0

CWE-434: Unrestricted Upload of File with Dangerous Type

Eaton Intelligent Power Manager (IPM) prior to version 1.69 is vulnerable to authenticated arbitrary file upload vulnerability. IPM’s maps_srv.js allowed an attacker to upload a malicious NodeJS file using ‘uploadBackgroud’ action. An attacker could upload a malicious code or execute any command using a specially crafted packet to exploit the vulnerability.

 CVE-2021-23281 

CVSS v3 Base Score – 8.3

CWE-94: Improper Control of Generation of Code (‘Code Injection’)

Eaton Intelligent Power Manager (IPM) prior to version 1.69 is vulnerable to unauthenticated remote code execution vulnerability. IPM software does not sanitize the date provided via ‘coverterCheckList’ action in meta_driver_srv.js class. Attackers could send a specifically crafted packet to make IPM connect to rouge SNMP server and execute attacker-controlled code.

Eaton’s Affected Products

As per Eaton’s advisory, the following three products and their subsequent versions were affected due to these vulnerabilities:

  • Eaton Intelligent Power Manager (IPM) – all versions prior to 1.69
  • Eaton Intelligent Power Manager Virtual Appliance (IPM VA) – all versions prior to 1.69
  • Eaton Intelligent Power Protector (IPP) – all versions prior to 1.68

Amir Preminger, VP of research at industrial cybersecurity firm Claroty, who has been credited by Eaton for reporting the six vulnerabilities, told SecurityWeek that the issues were identified on a web server interface of the IPM software that enables users to configure the product. This web server is typically accessible from the local network and is not hosted on public-facing servers.

The goal of the Eaton IPM software is to enable users to manage their UPS system. By exploiting a server using this software, an attacker can disrupt the UPS operations and therefore disrupt the power supply to equipment that relies on the UPS as its power source. The bottom line is that this product should be patched since a few of the CVEs are pre-auth and could be exploited by adversaries without prior knowledge about the server setup.

– Preminger explained

In addition to applying the patches, Eaton has recommended its users to block ports 4679 and 4680 to prevent exploitation. For additional info on general best security practices recommended by Eaton, click here.

Related News:

RedEcho Attacked 10 Indian Power Sector Companies and 2 Seaports: Recorded Future

Ransom Mafia Extort Money By Forming Ransomware Cartels

Ransomware gangs

The adage “Apes Together Strong,” denotes apes working together for a common goal that would eventually benefit them. Similarly, several cybercriminal groups join hands to make their hacking attempts more intense and successful. Most of the threat actor groups have a presence in underground marketplaces where they share details related to malicious tools, malware samples, and hacking targets. We often encounter news about various ransomware campaigns globally, but what most of us do not know is that they are often interrelated.

A recent analysis by threat intelligence firm Analyst1, called “Ransom Mafia – Analysis of the World’s First Ransomware Cartel,” revealed that cybercriminal groups behind certain ransomware campaigns often maintain a relationship with each other to form a cartel in the underground hacking world.

A ransomware cartel is a gathering of several cybercriminal gangs who collaborate in ransom operations by sharing resources, tactics, and profits. Analyst1 researchers analyzed the attackers’ Bitcoin wallets and their associated transactions to find out the money trail from victims to the threat actor gang and from the gang to their other partners in the cartel. A ransomware cartel is often formed to expand its reach and revenue.

The Origin of Ransomware Cartel

Researchers found that threat actor group Twisted Spider began a cartel in November 2020, after announcing the shutdown of its Maze ransomware operations. While the retirement claim was false and misleading, the Twisted Spider gang formed a ransomware cartel with Wizard Spider, Viking Spider, Lockbit, and SunCrypt gangs.

Image Courtesy: Analyst1

“The first tie we found provided evidence that the groups are working together and sharing resources to extort victims. Several gangs compromised and stole victim data, which they passed on to Twisted Spider. Twisted Spider then posted the victim’s data and attempted to negotiate a ransom on their data leak site. This type of collaboration and sharing would not occur unless all three criminal elements had a trusted relationship with one another,” Analyst1 said.

Key Findings

  • The cartel-affiliated gangs distributing/posting victim data across leak websites belonged to other gangs within the cartel. In other words, one gang breached and stole data from a victim and passed it to another gang to post publicly and negotiate with the victim.
  • Multiple gangs within the cartel coordinate via Cartel leak websites, including sharing tactics, command and control infrastructure, and sharing/posting victim data.
  • Attackers are moving towards automating their attacks. Multiple gangs have added automated capabilities into their ransom payloads, allowing them to spread and infect their victims without human interaction.
  • Ransom demands continue to increase. Collectively, gangs in the cartel generated hundreds of millions of dollars from ransomware and data extortion operations.
  • Several cartel gangs offer Ransomware as a Service (RaaS), hiring hackers to execute attacks while providing them with malware, infrastructure, and ransom negotiation services.
  • Attackers are conducting PR interviews with reporters, issuing press releases, and leveraging social media ads and call centers to harass and pressure victims into paying.
  • Attackers are reinvesting profits made from ransom operations to advance both tactics and malware to increase their success and revenue. Malware is updated regularly, adding new sophisticated features.
  • Wizard Spider developed unique malware geared towards espionage. Analyst1 could not validate how Wizard Spider uses it in attacks. Its existence alone is troubling. We found no other gang in the cartel that uses or develops espionage malware.

The Cartel Continues

Ransomware groups deliberately announce that they are shutting down their operations, however, end up making their cartel affiliations to come back stronger and larger.

“Analyst1 believes these ransomware gangs will continue to work with one another. The working relationship, however, will likely continue to be done behind the scenes and not on a public level. Groups will continue to share tactics and resources, making them far more dangerous than if they were operating independently. Both ransomware and malware used to gain initial compromise will increase in their levels of sophistication and capability,” Analyst1 added.

In IT Security, All Roads Lead to Identity

Microsoft 2022 flaw, Cybersecurity interest, Personnel Security Program

The increasing use of cloud services and automation solutions or even the switch to remote work has made identity the new perimeter security. With the ever-expanding attack surface, identity management has become critical for maintaining a robust security posture. Beyond privileged access management (PAM), an identity security strategy is the next logical step to protect the company against cyberthreats.

By Jeffrey Kok, Vice President of Solution Engineer, Asia Pacific and Japan at CyberArk 

In today’s environment, any identity – whether it is a customer, an employee working remotely, a third-party vendor, or just any device or application connected to the network can become privileged and create an attack path to an organization’s most valuable assets.

Privileged access is intertwined with identities. For instance, developers need access to the company’s source code to implement changes on applications or databases. Consultants or third-party providers will need access to company resources while working on projects.

The recent SolarWinds digital supply chain attack involved the compromise of identity and manipulation of privileged access. Due to this attack, PWC Hong Kong recommended that businesses implement a zero-trust network architecture through identity identification and access controls.

With the growing adoption of cloud services and the shift to remote work, the use of privileged access as an attack vector is particularly evident. In a cloud environment, in principle, any human or machine identity can be configured with thousands of authorizations unique to each cloud, which means it is possible to assign authorization to users, groups, and roles depending on the respective task profile. However, many companies unintentionally grant access rights within their cloud services that identities do not actually need or use.

Studies show that accounts and roles with too many authorizations are among the most common misconfigurations of cloud services. According to CyberArk’s CISO View survey, end-users are reported to be the most targeted group – including business users with access to sensitive data. 56% of respondents reported being targets of cyberattacks.

Companies also need to give more focus to employees working remotely when designing security strategies. End devices of individual employees are an important first point of entry into the company network. Privileged access options for remote employees must be secured by implementing security procedures such as multi-factor authentication, single sign-on (SSO), and access rights management. This means that the access management for privileged users must be expanded to include the company’s entire user community.

In Singapore, work from home orders were lifted since April 5 and up to 75% of employees can return to the office. Many businesses are making the transition in phases to manage access to information and assets from both within and outside the corporate networks. IT teams can manage the transition by taking an identity-driven approach to security, which applies the right level of authentication and security controls based on the user’s role.

Cloud and remote work have one thing in common. Both scenarios have made the traditional network perimeter de facto worthless. Thus, a comprehensive identity security approach based on privileged access management must focus on securing individual identities – regardless of whether it is a person or a machine.

Mitigating the risks through identity management

Identity security solutions help mitigate risks through secure identity authentication, well-defined access permissions, and a structured process in granting access to critical resources. In other words, a zero-trust principle should apply. With identity security solutions in place, all attempts to establish a connection to critical systems or access company resources go through rigorous identity checks and multi-factor authentication. The more critical the access, the stronger the verification process.

Every identity-based security strategy should contain two essential components: the assignment of context-related user access rights and the tracking and monitoring of non-human access. Security teams must consider the roles and activities each user needs to perform to grant the appropriate access levels. By granting the least privilege and using a just-in-time approach, security teams can prevent the permanent accumulation of rights, thus making it much more difficult for attackers to identify and approach their target.

On the other hand, identity management needs to expand beyond human activities and include devices, applications, programs, and automation. In hybrid cloud environments, non-human access must also be assigned to a secured and controlled structure of rights and permissions. A good example of this is Robotic Process Automation (RPA) that supports automation projects in a business environment. While RPA offers benefits to the business such as improving work efficiency and simplifying compliance, RPA technology introduces a new cyberattack surface for both humans and non-human identities. By taking steps such as removing privileged credentials from scripts or limiting the bot’s access, IT teams can prevent unauthorized access and misuse of the privileged credentials used in RPA.

With the increasing number of cyberattacks, companies need a security strategy that responds to the changing needs of the business. As the company network expands and the number of business applications and cloud workloads increases, implementing comprehensive identity security management can bolster the company’s security defenses.


About the Author

Jeffrey Kok is Vice President of Solution Engineers, Asia Pacific and Japan at CyberArk. Kok is responsible for working with various internal teams at CyberArk to qualify leads, identify business issues and drivers in any particular sales opportunity, and managing the entire presales and solution process of the business cycle.

Prior to joining CyberArk, Kok was Technical Consultant Director, Asia Pacific and Japan for RSA, managing a team of senior pre-sales engineers and technicians. While in this role he built a strong and high-performing cross-regional pre-sales practice.

Kok has more than 17 years of experience in the cybersecurity industry, serving in companies and institutions including RSA, Cisco Systems, Nera Telecommunications, and the National University of Singapore (NUS).

Kok holds a Bachelor of Applied Science in Computer Engineering from the Nanyang Technological University and CISSP certification.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Months After the Breach, Threat Actors Leaked Database of 20 Mn BigBasket Customers

Compromised Email Accounts

The pandemic has given a lift to e-commerce platforms. Due to the social distancing norms, travel restrictions, and curfews, people all over the world found themselves more occupied with digital browsing. And this sparked an online shopping spree, changing shopping habits from physical trolleys to smart carts. Using this trend to their advantage, threat actors targeted several online retail platforms throughout 2020. One such platform, which suffered a massive data breach last year, was BigBasket – an Indian online grocery delivery service. But it seems cybercriminals do not want to let the company go just yet!

Recently, a database with data of BigBasket’s 20 million customers was leaked on a darknet forum. It is likely that the current data leak is linked to its October 30, 2020, data breach, which included users’ full names, contact details, email IDs, password hashes (potentially hashed OTPs), pin, full addresses, birth dates, locations, and IP addresses of logins among many others.

According to Twitter posts of both Alon Gal, Co-Founder & CTO @ cybercrime intelligence firm Hudson Rock, and independent security researcher Rajshekhar Rajaharia, the infamous threat actor group ShinyHunters leaked the database on the dark web, making it available to anyone to download.

Related story: India’s E-Commerce Platform BigBasket Allegedly Suffers Massive Data Breach

What’s the Impact?

Attackers claimed to have decrypted millions of passwords linked to BigBasket customers, which could put the affected customers at risk as threat actors might obtain access to their other online accounts using the decrypted passwords and email addresses.

“Beware!! If you are using #BigBasket, change your passwords immediately on BigBasket and the remaining sites. Groups on the dark web have claimed to decrypt millions of the listed passwords. ShinyHunters posted this alleged database for free,” said Rajaharia.

Commenting on the hackers’ post, BigBasket said, “This article / social media post refers to an alleged data breach in Nov-2020 and not something that has happened recently. The reason we know it’s not recent is that the article /social media post mentions the release of hashed passwords. We had eliminated all hashed passwords from our system and moved to a secure OTP-based authentication mechanism quite sometime back. Also, our site does not collect or store any sensitive personal data of customers like credit card details. So, customer data continues to be safe, and no further action needs to be taken by customers.”

FBI’s Advice

Several incidents have been reported in recent times where malicious actors were found selling stolen information on the darknet markets, hence the FBI has warned consumers to be vigilant while shopping online. In a security alert, the FBI stated that the attackers are targeting shoppers by redirecting them to fraudulent websites via social media platforms and search engines.

D.C. Metropolitan Police Department Alleged Victim of Recent Babuk Ransomware Attack

Ransomware Attack on Azusa Police

The ransomware menace is spreading like wildfire. And while the law-and-order machinery seems to be putting out this fire, they seem to have been bearing the brunt of it too. The operators of the latest ransomware threat – Babuk – have threatened to leak critical data which can potentially expose several Metropolitan Police Departments’ investigations and their confidential informants.

Babuk’s Latest Victim

Babuk ransomware gang, which was first discovered at the beginning of the year, is popularly known to use the double extortion technique: download and encrypt. This way they lay hands on sensitive information, which can be further leveraged to pressurize their victims into paying a ransom. In a post published on its leak website, Babuk operators claimed that they had successfully targeted the systems of the Washington D.C. Metropolitan Police Department and downloaded 250GB worth of sensitive and highly confidential information.

Screenshots shared online suggest that the exfiltrated data contains the following:

  • Investigation reports
  • Officer disciplinary files
  • Documents on local gangs
  • Mugshots
  • Administrative files

Related News:

McAfee Reveals the Unknown About Babuk Ransomware

Babuk Warns of “Larger Attacks”

Initially, the Babuk ransomware operators said that they would remain tight-lipped about this attack and expected the Metropolitan Police Department to reach out to them for paying the ransom to avoid further trouble. Sean Hickman, a public spokesperson for D.C. Police, acknowledged this attack and said, “We are aware of unauthorized access on our server.” However, there seems to be inaction from the department’s side due to which the Babuk operators updated their warning on their leak website. It now reads:

Hello! Even an institution such as D.C. can be threatened, we have downloaded a sufficient amount of information from your internal networks, and we advise you to contact us as soon as possible, to prevent leakage, if no response is received within 3 days, we will start to contact gangs in order to drain the informants, we will continue to attack the state sector of the USA, FBI, CSA, we find 0 day before you, even larger attacks await you soon.

To further investigate the extent and impact of the attack, the D.C. Metropolitan Police Department has engaged with the FBI.

Related News:

Has Babuk Ransomware Gang Attempted a Slam Dunk on Houston Rockets?

Click Studios’ Password Manager ‘Passwordstate’ Hacked via Update Feature

biggest data breaches in India,data breach, Aptoide Android App Admits Data Breach, Suspends Sign-Up Option Temporarily, Panasonic

A majority of industry experts agree that using password managers is the most secure way to protect your passwords. Password managers give an extra layer of protection to your online accounts by encrypting all your saved passwords. However, there is no way to stay 100% secure online. Even a robust and reliable password manager can be hacked. And this came true when cybersecurity researchers from CSIS Security Group recently discovered a supply chain hack on Passwordstate , a password manager owned by an Australian firm Click Studios.

 Deployment of a Corrupted Update

In an official release, Click Studios stated that it suffered a data breach, between April 20 and April 22, after an unknown attacker deployed a corrupted update to Passwordstate by compromising its In-Place Upgrade functionality. The attack lasted for around 28 hours before it was shut down, exposing users’ sensitive data online.  Reportedly, the users who performed In-Place Upgrades between April 20, 8:33 PM UTC and April 22, 0:30 AM UTC have likely downloaded a malformed Passwordstate_upgrade.zip file injected by the attackers.

Moserpass Malware

The researchers claimed that threat actors deployed malware, tracked as Moserpass, in the form of a ZIP archive file – Passwordstate_upgrade.zip containing a modified version of a library – moserware.secretsplitter.dll. The ZIP file connects with the remote server to fetch a second-stage payload – upgrade_service_upgrade.zip that extracted Passwordstate users’ data and exported the information to the adversary’s Content Delivery Network (CDN) network.

  Image Courtesy: CSIS Group

Indicators of Compromise

  1. Malicious dll: f23f9c2aaf94147b2c5d4b39b56514cd67102d3293bdef85101e2c05ee1c3bf9
    SecretSplitter.dll

    2. User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.128 Safari/537.36

    3. C&C: https://passwordstate-18ed2.kxcdn[.]com/upgrade_service_upgrade.zip

 Massive Data Exposed

Initial analysis of the compromised data indicates that Moserpass malware harvested users’ sensitive details including, computer name, username, domain name, current process name, current process ID, all running processes name and IDs, all running services’ name, display name, status, Passwordstate instance’s Proxy Server Address, username, and password.

“The Domain Name and Hostname aren’t extracted as part of this. Although the encryption key and database connection string are used to process data via hooking into the Passwordstate Service process, there is no evidence of encryption keys or database connection strings being posted to the bad actor CDN network,” Click Studios said.

Remedial Measures

Click Studios urged the affected customers to immediately:

  • Download the advised hotfix file.
  • Use PowerShell to confirm the checksum of the hotfix file matches the details supplied.
  • Stop the Passwordstate Service and Internet Information Server.
  • Extract the hotfix to the specified folder.
  • Restart the Passwordstate Service, and Internet Information Server.

Besides, the company advised all its customers to reset passwords on their Passwordstate account as a precautionary measure. Click Studios recommended password resets based on:

  • All credentials for externally facing systems, i.e., Firewalls, VPN, external websites, etc.
  • All credentials for internal infrastructure, i.e., Switches, Storage Systems, Local Accounts.
  • All remaining credentials stored in Passwordstate.

Passwordstate has more than 29,000 customers globally and this data breach could potentially have impacted a large number of users.

“Click Studios is continuing to work with our customers, identifying if they have been affected and advising them of the required remedial actions. Click Studios is also liaising with a Nationally Based 3rd party for assistance on in-depth analysis and direction for specialist technical support,” Click Studios added.

Resetting all your stored passwords, and especially firewalls, VPNs, switches, or any server passwords will help prevent any future risk.

How does the GDPR impact business marketing and customer engagement?

GDPR

The enforcement of GDPR Regulation has a far-reaching implication on businesses globally. The regulation does not just affect the way business is conducted but also has a direct impact on customer engagement. The EU Data Protection law requires all businesses handling the personal data of EU citizens to follow guidelines for the way they collect, use and store personal data. With this, it comes as no surprise that businesses have had a direct and significant impact on the enforcement of the regulation. In this article today, we have covered how GDPR has an impact on businesses and the customer engagement process. But, before that let us first understand the GDPR Regulation and the rights granted to individuals to learn their effect on businesses globally.

By Narendra Sahoo, Founder, and Director, VISTA InfoSec

Consumer Rights under the GDPR Regulation

Under the GDPR Regulation, individuals are provided numerous rights on the way their personal data can be processed or used. So here is the list of rights granted to individuals under the GDPR Regulation that may have a direct or indirect impact on business-

  • Right to Access– Individuals have the right to request access to their personal data and get information on how their data is used by the company. The company must also provide a copy of the personal data free of cost in an electronic format if requested by the individual.
  • Right to be Forgotten – If the consumer wants to withdraw their consent from a company to use their personal data, then they have the right to have their data deleted. The same has to be communicated to the third party who has access to their data.
  • Right to Data Portability– Individuals have a right to transfer their data from one service provider to another. More importantly, it must happen in a commonly used and machine-readable format.
  • Right to be Informed–Individuals must be informed before their personal data is gathered. Consumers have the right to opt-in or opt-out for their data collection. Further, consent for the same must be freely given rather than implied.
  • Right to Correct Information–Individuals have the right to correct or update their personal data if it is incomplete or incorrect.
  • Right to Restrict Processing– Individuals have the right to restrict the processing of their personal data. However, in this case, the record can be stored, but not be used.
  • Right to Object– The individuals have the right to object to the processing of their data for direct marketing. There are no exemptions to this rule, and any processing must stop as soon as the request is received.
  • Right to be Notified– In case of a data breach that compromises an individual’s personal data, the individual has a right to be informed within 72 hours of first having become aware of the breach.

The rights given to individuals under the GDPR Regulation has a significant impact on the way how business work. With rights like the Right to Restrict Processing, Right to Object, Right to be Forgotten, organizations will have to come up with a different business model to communicate, market, and engage with customers for their business. Explaining more on this, we have detailed how the EU GDPR Regulation impacts business.

What is the business impact of GDPR Regulation?

  • The definition of personal data which is protected by the GDPR Regulation is now much broader and includes IP addresses besides the name, contacts, financial and medical information. So, businesses will have to take separate consent before collecting any information on the website through cookies.
  • Individual consent which is a major requirement in the GDPR Regulation complicates the process for businesses because they now need to have a lawful reason to collect, process, and store personal data. Businesses will need to get separate permissions for every time the business plans to process the personal data in a way that is different than what was communicated when the consent was actually taken.
  • With broader Data subject rights including the right to erase, right to transfer to other services upon request, it defiantly impacts businesses that are data-driven by nature.
  • Businesses will now have to dedicate certain resources towards ensuring that the data processing documents and necessary records of consent, safety procedures, and reports on all processing activities are maintained.

Impact on Business Marketing, Communication & Customer Engagement

Enforcement of GDPR requires six lawful bases to process an individual’s personal data. This includes consent, contract, legal obligation, vital interests, public/government task, and legitimate interest. All of this has a significant impact on a business’s way of marketing and communication. Let us understand how the GDPR has changed the marketing game for businesses today.

GDPR Effect on Online Marketing Businesses

With the enforcement of GDPR Regulation businesses is now restricted from freely using the personal data of individuals in their marketing strategy. Businesses will now require consent even before collecting or using an individual’s personal data. Moreover, as a data controller, organizations will be accountable for data collection, storage, and usage. So, for instance, if you use Google AdSense on your website, you will need the visitor’s consent to view personalized ads. This significantly impacts the efficiency and output of the advertising strategy.

GDPR Effect on Customer Engagement

Sending random cold emails to potential customers is now restricted with the enforcement of GDPR. Businesses will now need to verify whether or not they are allowed to contact them. When sending cold emails, businesses should ensure there is a legitimate interest involved. Simply put, businesses have to ensure they are emailing the right individual with a message the receiver will be interested in hearing. On the other hand, if the business has gained verifiable consent via a signup form, they are good to go with the process.

Note – If the email address is not of an individual alone but a company mail, there is a probability of it not falling in the scope of “personal data.”

GDPR Effect on using client Database for Marketing

If a business has purchased a potential client database from a third party, they still stand responsible for gaining appropriate consent for gathering or using the data. The conditions for obtaining consent are stricter under GDPR requirements as the individual are given the right to withdraw consent any time they wish to do so. Moreover, it is important to note that consent will not be valid unless separate consents are obtained for different processing activities. This further goes on to say that businesses will have to prove that the individual agreed to a certain action, to receive a newsletter for instance. In order to sign up for any future communication, prospects will have to fill out a form or tick a box to confirm it was their actions in an email confirming the same. Businesses are not allowed to assume or add a disclaimer, and just simply provide an opt-out option. Even in the case where the sales staff of your organization may have collected business cards from potential clients at trade shows will require appropriate consent from those individuals before adding them to the mailing list or processing their information. They are required to prove that consent was given and that the individual has no objection to receiving the communication.

Conclusion

The GDPR Regulation has brought in a lot of changes to the way how businesses work.  Emphasizing more on Data Privacy and Data Protection, businesses will have to change their way of conducting marketing activities or managing such activities. Businesses will have to look for a new, legit and legal way of collecting customer information with their consent, keeping in mind the Data Privacy rules. They will now have to carefully review their business processes, applications, and forms to be compliant with the regulation. Businesses will have to implement double opt-in rules and implement best email marketing practices that are in line with the Privacy regulation of GDPR.


About the Author 

Narendra Sahoo - GDPR impact on business marketing and engagementNarendra Sahoo (PCI QSA, PCI QPA, CISSP, CISA, and CRISC) is the Founder and Director of VISTA InfoSec, a global Information Security Consulting firm, based in the U.S., Singapore & India. Mr. Sahoo holds more than 25 years of experience in the IT Industry, with expertise in Information Risk Consulting, Assessment, & Compliance services. VISTA InfoSec specializes in Information Security audit, consulting, and certification services which include GDPR Compliance and Audit, HIPAA, CCPA, NESA, MAS-TRM, PCI DSS Compliance & Audit, PCI PIN, SOC2, PDPA, PDPB to name a few. The company has for years (since 2004) worked with organizations across the globe to address the Regulatory and Information Security challenges in their industry.VISTA InfoSec has been instrumental in helping top multinational companies achieve compliance and secure their IT infrastructure.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.