Home Blog Page 93

Justice Department to Launch Ransomware Taskforce

Ransomware Attacks, Graff ransomware attack

Ransomware operators continue to innovate hacking techniques to encrypt victims’ sensitive information and demand ransom or threaten targets of leaking their data online. Besides this, cybercriminals also increased their ransom demands as multiple ransomware groups from underground forums are collaborating to target large organizations.

Recently, the FBI stated that it received nearly 800,000 cybercrime complaints in 2020, with reported losses of $4.2 billion. The agency stated that it several of these complaints were about various cybercrimes, including COVID-19-themed cyberattacks. The number of ransomware attacks also continue to rise, with 2,474 incidents reported in 2020. The staggering figure was a 69% increase in total complaints from 2019.

To address the mounting ransomware attacks on organizations, the Department of Justice (DoJ) of the U.S. is launching a new task force to identify the root cause of rising ransomware attacks in the country.

What Does the Task Force Do?

According to an internal memo shared with CNN, the DoJ made certain outlines for the new initiative which combines the efforts across the federal government to pursue and disrupt ransomware operators. The preventive actions may include everything from the takedown of servers that spread ransomware to disruption of cybercriminal groups performing ransomware campaigns.

Besides this, the DoJ is also planning to deploy additional resources to training and intelligence sharing on the present cybersecurity landscape. The agency is also reaching out to organizations in the private sector to gain insights on various ransomware and extortion threats. Commenting about the new initiative, the Acting Deputy Attorney General John Carlin said, “Although the Department has taken significant steps to address cybercrime, we must bring the full authorities and resources of the Department to bear to confront the many dimensions and root causes of this threat.”

The Year of Ransomware

The DoJ described 2020 as the worst year ever for ransomware attacks particularly highlighting the recent high-profile cyberattacks like the Russian-backed SolarWinds hacking campaign and exploitation of Microsoft Exchange server vulnerabilities.

An Effort to Prevent the National Security Threat

The new task force initiative comes days after the Department of Homeland Security (DHS) stated that it is fighting against ransomware operators targeting the country. In an RSA conference, Alejandro Mayorkas, the U.S. Secretary of Homeland Security, shed light on the present threat landscape, cybersecurity challenges, and their plans to address cybersecurity vulnerabilities. Describing it as a national security threat, Mayorkas stated that ransomware attacks significantly increased with threat actors adopting new tactics to encrypt organizations’ critical data.

REvil Ransomware Gang Targets Apple’s Supplier, Quanta; Threatens to Leak Blueprints

Apple Is Hackers’ Favorite for Brand Phishing Attacks, REvil gang threatens Apple blueprint leak

The REvil ransomware gang reportedly hacked Taiwanese manufacturer Quanta Computer, which among others, manufactures Apple’s iWatch and MacBook devices. As per the REvil gang’s claims, Quanta did not pay heed to their warnings and thus the threat actors have now published a ransom note along with a warning to Apple, demanding a ransom of $50 million. They have further threatened to leak the blueprints of Apple devices to its competitors if their demands are not met in time.

It Began with Quanta

On Tuesday, Apple revealed its latest lineup of iPads and iMacs in a live stream event from its headquarters in Cupertino, California. Apple, for the first time, has powered these products with its own M1 chip, which has already been introduced in Apple’s MacBook Pro, Mini, and Air.

However, just hours before the event went live, breaking news coming from across the North Pacific Ocean (in Taiwan) popped a surprise for the tech giant. Apple’s key manufacturer, Quanta Computers, was allegedly hacked by the REvil (aka Sodinokibi) ransomware gang and the threat actors claimed that they had exfiltrated the blueprints of Apple’s product suite manufactured with Quanta.

Quanta not only provides manufacturing services for Apple but also to other tech heavyweights like Dell, Hewlett-Packard, Alienware, Lenovo, Cisco, and Microsoft. Thus, if the incident holds true, not only Apple but also many others could be at risk of “theft of intellectual property.”

Related News:

REvil Ransomware Hits Acer; Threat Actors Demand $50 Million in Ransom

REvil’s Warning

The notorious threat group who has been on an attacking spree off late, first revealed about the latest attack on its “Happy Blog” – a public-facing website where the gang names and shames its victims to mount pressure on them for paying up. The published post read:

In order to not wait for the upcoming Apple presentations, today we, the REvil group, will provide data on the upcoming releases of the company so beloved by many. Tim Cook can say thank you Quanta. From our side a lot of time has been devoted to solving this problem. Quanta has made it clear that it does not care about the data of its customers and employees, thereby allowing the publication and sale of all data we have.

The gang further specifically warned Apple that it was already in negotiations with other major brands for its confidential product drawings and personal data, and that time was running out for them. The note said, We recommend that Apple buy back the available data by May 1.

If Quanta and Apple fail to pay the ransom, the amount would be doubled to $100 million and more leaked files will be added on their “Happy Blog” in a PDF format with every passing day thereafter.

Quanta Accepts Breach

After initial apprehensions, Quanta accepted that they were targeted with a cyberattack and are therefore taking stringent countermeasures. Quanta’s security update stated:

Quanta Computer’s information security team has worked with external IT experts in response to cyberattacks on a small number of Quanta servers. We have reported to and kept seamless communications with the relevant law enforcement and data protection authorities concerning recent abnormal activities observed. There is no material impact on the Company’s business operation.

Quanta added that its defense mechanism was activated in no time and only a small range of services was impacted by the attack, which was later brought back to normalcy. As a result of this attack, Quanta has subsequently upgraded its cybersecurity measures with immediate effect.

Related News:

REvil Ransomware Buys KPOT Malware; Adds Another Weapon to its Arsenal

Emergency Directive! CISA Warns About Ivanti Pulse Connect Secure Vulnerabilities

CISA vulnerabilities, Microsoft Vulnerabilities, HP Device Manager Susceptible to Dictionary Attacks

Software programs often have flaws/vulnerabilities, which are often exploited by cybercriminals to gain access to victims’ data. Recently, federal agencies have been ordered to address multiple vulnerabilities affecting Ivanti Pulse Connect Secure (PCS) VPN appliances on their network systems. Pulse Connect Secure VPN provides TLS and mobile VPN solutions to organizations globally.

The Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Homeland Security (DHS) warned about the actively exploited vulnerabilities: CVE-2019-11510, CVE-2020-8260, CVE-2020-8243, and CVE-2021-22893.

The Impact

If exploited successfully, the vulnerabilities could allow an attacker, to launch remote code execution to obtain privileged access to install programs, view, alter, or delete data from the compromised system. CISA found that the exploitation of Pulse Connect Secure products poses a serious threat to Federal Civilian Executive Branch agencies.

Deployment of Malicious Web Shells

CISA stated that cybercriminals are exploiting the flaws to deploy malicious web shells on the Pulse Connect Secure appliances to manipulate various functions including authentication bypass, multi-factor authentication bypass, password logging, and persistence through patching.

Ivanti has recommended mitigation measures and is working on developing a patch for the vulnerabilities. “In the past, intruders were primarily targeting infrastructure devices. While intruders can perform several types of attacks on network devices, malicious actors are now looking for ways to subvert the normal behavior of infrastructure devices. In general, these intruders can gain access, typically by exploiting vulnerabilities on the system or possibly manipulate an authorized user via several social engineering attacks,” Ivanti said.

Required Actions

By 5 pm EDT on Friday, April 23, 2021, all federal agencies using Ivanti’s services should:

Mitigation Measures

CISA urged organizations using Ivanti Pulse Connect Secure appliances to immediately implement the vulnerability mitigation measures released by the company. These include:

  • Reviewing the Pulse Secure Connect Integrity Tool Quick Start Guide.
  • Running the Pulse Secure Connect Integrity Tool.
  • Reviewing “Unauthenticated Web Requests” log for evidence of exploitation if enabled.
  • Changing all passwords associated with accounts passing through the Pulse. Secure environment (including user accounts, service accounts, administrative accounts, and any accounts that could be modified by any account described above, all these accounts should be assumed to be compromised).
  • Reviewing logs for any unauthorized authentications originating from the Pulse.
  • Connecting Secure appliance IP address or the DHCP lease range of the Pulse.
  • Connecting Secure appliance’s VPN lease pool.
  • Looking for unauthorized applications and scheduled tasks in their environment.
  • Ensuring no new administrators were created, or non-privileged users were added to privileged groups.
  • Removing any remote access programs not approved by the organization.
  • Carefully inspect scheduled tasks for scripts or executables that may allow a threat actor to connect to an environment.

“The cyber threat actor is using exploited devices located on residential IP space — including publicly facing Network Attached Storage (NAS) devices and small home business routers from multiple vendors — to proxy their connection to interact with the web shells they placed on these devices. These devices, which the threat actor is using to proxy the connection, correlate with the country of the victim and allow the actor activity to blend in with normal telework user activity,” CISA said.

Speed is the Reason Why 1 In 3 Employees Do Not Use VPN

Cybersecurity, digital investigations, and eDiscovery will never be the same. Market uncertainty and changing consumer behavior have increased cybercrime and fraud, while remote workforces are redefining network perimeters, opening new avenues for hackers to access private and sensitive data.

In a brief interaction with Augustin Kurian from CISO MAG, Anthony Di Bello, VP of Strategic Development, OpenText, talks about how the pandemic has accelerated market changes in cybersecurity and the use of VPN for remote employees among several others. Anthony leads a team of market development directors driving OpenText strategic direction within information security, data discovery, legal, analytics, and AI/ML software markets.

Edited excerpts from the interview follow:

While many rushed to adopt cloud during the pandemic, it threw up new cloud security issues. This was attributed to misconfigurations, and over- or under-provisioning. What do you think will happen on the cloud security front? How will technologies like threat intelligence and AI help secure cloud applications and services? 

The first step organizations need to take that relies heavily on virtualized and containerized infrastructure is ensuring logging capabilities are not only deployed but also turned on. For example, Kubernetes requires the deployment and configuration of the Google Cloud Operations suite (formerly Stackdriver) to take full advantage of the information logged within Kubernetes clusters. Once logging is properly configured, that information then needs to be fed into a security analytics platform to take advantage of use cases such as machine-learning-powered threat hunting. Through this process, organizations can detect anomalous or malicious activity originating from the containerized environment.

According to research from OpenText Webroot, 63% of web-borne malware and 15% of phishing attacks are delivered over cloud applications. The number of enterprises and small-to-medium businesses using cloud-based applications for file sharing, data storage, project collaboration, and more skyrocketed during the pandemic and will continue to grow. As cloud applications become more prevalent, organizations must balance application use with security, or face regulatory & compliance issues, data loss, and security breaches.

Actionable threat intelligence is critical to help secure cloud applications and services. Threat intelligence provides data around three major areas of concern within cloud applications or services: which services are being used within an organization? How are the applications being used? And what are the security reputations of these applications or services? Threat intelligence services help organizations enforce data-centric security policies to prevent unwanted interactions with cloud services and associated applications. Threat intelligence can also help organizations supplement the information they already have on which cloud applications pose security or compliance risks, as well as identify user actions within these applications.

There is still a huge chunk of organizations that fail to fully discover privileged accounts while many do nothing at all to discover these accounts. How worrying is this trend in the age of remote working and what can be done to counter it?

This is a major concern. Organizations need to implement technology or retain services to discover privileged accounts across the enterprise and this is no small task. For a large enterprise, simply understanding what and where all the systems, applications, and cloud services are, and identifying the associated user/admin accounts is a daunting task by itself.

An earlier EC-Council survey pointed out that 1 in 3 employees don’t use VPN to connect to the company network while working from home, escalating vulnerabilities emerging from insider threats to sharp levels. Why do you think there is such a trend even after increased knowledge about cybersecurity globally? 

The use of VPN, over slower consumer internet connections, can slow down a device. Particularly when that device is streaming multiple audio and video feeds while presenting from any number of applications, as is typical when conducting meetings from the home office. Employees want to get their work done in the most efficient way possible… if a simple fix to a slow computer is working disconnected to VPN, it’s an easy choice for… 1 in 3 employees. This highlights the need for host-based security controls that do not require the device to be behind the firewall to ensure a level of security.

Many a time, recruiters are unable to recruit knowledgeable or skilled personnel to deploy their security automation tools. This is a major hindrance to a good cybersecurity posture. Do you think there is enough stress on the need for security automation programs?  

There is plenty of stress on the need for security automation. An entire technology category has emerged to address this (Security Orchestration, Automation, & Response), and most security vendors focus heavily on API development. What’s lacking is clear, rational guidance on how and where to focus initial automation efforts. Trying to “automate all things now!” can be overwhelming for smaller infosec and security operations teams. We suggest teams first conduct a threat modeling exercise to help focus efforts on where the biggest gains can be made, then identify processes where lots of “heavy lifting” is done manually. Think automating the capture/collection of memory triggered to a particular alert category. This both abstracts away the need to perform “collections” and provides security teams more actionable intelligence from endpoints seeing the state of a device exactly when an alert was generated. Such basic automation also accounts for the typical attacker work schedule, which is typically nights and weekends.

When it comes to malware detection and protection, several companies are relying on signature-based malware monitoring. What are the challenges in using signature-based malware monitoring? 

You miss 100% of threats that don’t have a signature. How long did SUNBURST go unnoticed? HAFNIUM? These are clear and present examples of why relying solely on signature-based monitoring is an incomplete solution.

What are the plans for OpenText? What is the status of integration of Carbonite/Webroot solutions since the acquisition last year?  

We continue to look for every opportunity to bring Carbonite and Webroot products to our OpenText enterprise customers, and this includes OpenText itself.  Last year, we adopted Carbonite backup on every OpenText endpoint to help protect our entire workforce as they shifted to remote work environments.  At the same time, we have been able to bring OpenText solutions and services to the Webroot managed service provider (MSP) community. We also have deeper integration between EnCase Endpoint Security and BrightCloud Threat Intelligence; we’ve integrated File reputation and in our upcoming 21.2 release, we will be bringing URL and DNS reputation feeds into EnCase Endpoint Security. Carbonite and Webroot continue to help OpenText bring comprehensive cyber resilience solutions to the enterprise, MSP, business, and consumer markets.


Augustin Kurian

About the Interviewer

Augustin Kurian the Assistant Editor of CISO MAG. He writes interviews and features.

 

API Security Outlook: A Guide to API Security

As application architectures become more cloud-native and based on microservices, Application Programming Interfaces (APIs) have become critical to securing your apps as their primary communication channels. Simultaneously, the increase in complexity has made it harder to know what is going on within the application environment and in between those apps (which are likely to be interconnected through APIs) — meaning a broader attack surface but decreasing visibility. Both developers and security professionals need unprecedented API visibility and protection intelligence to secure apps and their APIs against the increasingly sophisticated threats and vulnerabilities. EC-Council and CISO MAG recently hosted a virtual panel discussion titled “API Security Outlook – A guide to API Security in a Digitally Transformed World” with a panel of experts comprising of Inon Shkedy, Head of Security Research, Traceable; Nikesh Dubey, CISO – Infosec & GRC, AGC Networks; and Nicole Darren Ford, VP & CISO, Carrier.

SPONSORED CONTENT

Inon Shkedy spearheaded the discussion with his observations on the need for API security adoption. He opined that APIs are the base case building blocks and the security of APIs must be clearly understood. API breaches are making the headlines every day. Since APIs allow businesses to put data to use, multi-billion-dollar companies become tantalizing targets. What many people fail to understand is that APIs are one of the favorite entry points for cybercriminals since they appear attractive and lucrative for threat actors.

Shkedy has over eight years of experience in application security. He currently provides security consultation to Silicon Valley startups and leads the research for Traceable AI in the field of API security.

Shkedy said, “The main problem is that APIs are exposed to other attack vectors. What organizations need to focus on is a proper asset management and better visibility of APIs and endpoints.”

Nikesh Dubey concurred and added, “We need to understand what are APIs. APIs have now become a lethal threat landscape. In fact, several major recent cyberattacks can be linked to API breaches. These include the Panera cyberattack, where nearly 37 million user accounts were compromised. Even during the SolarWinds attack, there is a theory that attributes the breach to the API breach of VMWare Workspace.”

A strong advocate of Security and GRC principals, Dubey serves as the CISO for AGC Networks (USA) and is leading AGC’s Security Advisory practice in North America.

Nicole Darden Ford explained the complications of managing APIs. According to her, “Managing APIs has become complicated. Often APIs are made like a one-way road only for one specific purpose, but if something goes wrong, it becomes useless. For organizations, it is important to understand all the APIs and technology around API gateways. Organizations have been investing in APIs and I think it is high time, they start investing in API security as well.”

Ford is an IT strategic leader with 20+ years of success spanning the federal government and corporate venues. In her current role as Vice President and Chief Information Security Officer for Carrier, Ford oversees global Information Security and Product (IoT) Cybersecurity.

The panelists concluded the discussion by stating the need for establishing best practices, adopting a layered security approach with APIs, and bettering API management. Shkedy stressed having a standardization for API security, zero-trust architecture, and the necessity of cyber hygiene. Dubey emphasized keeping track of the third parties and building a robust vendor relation, while Ford called attention to performing better due diligence and audit.

 

 

 

 

About CISO MAG

CISO MAG – a thought-leadership publication from EC-Council – provides vital stories, trends, interviews, and news from around the security world to help security leaders stay informed. The magazine includes comprehensive analysis, cutting-edge features, and contributions from thought leaders.

About EC-Council

EC-Council, officially incorporated as the International Council of E-Commerce Consultants, was formed to create information security training and certification programs to help the very community our connected economy would rely on to save them from a devastating Cyberattack. EC-Council rapidly gained the support of top researchers and subject matter experts around the world and launched its first Information Security Program, the Certified Ethical Hacker. With this ever-growing team of subject matter experts and InfoSec researchers, EC-Council continued to build various standards, certifications, and training programs in the electronic commerce and information security space, becoming the largest cybersecurity certification body in the world. Learn more at https://www.eccouncil.org.

 

 

SPONSORED CONTENT

Information Technology Internal Audit Considerations Amidst COVID-19

Information Technology Internal Audit

The COVID-19 pandemic, as an unpredictable event, has triggered a ripple effect on people, businesses, governments, and society as a whole. Resultantly, organizations resorted to adopting innovative rapid changes and continued to operate in ways that are quite different from the standard practices, and they had never been projected previously. With new ways of working and technological advancements, the pandemic brings not only risks but also opportunities for organizations. So, there is a need to respond, oversee, anticipate and manage both risks and opportunities in a changing environment.

By Muhammad Tariq Ahmed Khan, Head of Information Security Audit, Internal Audit Division, Arab National Bank, Riyadh

Background

Since the recent changes are triggering both risks and opportunities, organizations are inclined to take immediate and appropriate actions to support their employees, customers, and stakeholders while reducing the impact of the pandemic. Pandemic also brings an opportunity for Internal Audit to adapt to the new changes and to evaluate the operational challenges faced by the organizations and provide them assurances about the effectiveness of their control environments.

To assist in this process, I have highlighted the following ways that can help Information Technology Internal Audit (IT Auditors) to provide reasonable assurance and recommendations to Senior Management and the Board.

Risk Assessment

IT Auditors should adopt an agile audit approach to revisit their plans to reprioritize the IT audit engagements as per the organization’s changing risk profile, regulatory requirements, and evolving practices embraced by the organization to assist the management in focusing the critical risks in order to better protect the organization.

The plan should be flexible to cover the emerging risks caused by new products and services as a result of COVID-19.

In addition, the scope of the IT audit engagements should be continuously reviewed in line with the changing risks and control environment.

Business Continuity Planning (BCP)

Since organizations have revised their business continuity plans and have permitted the employees to work from home, it is a unique opportunity for IT Auditors to give another look at whether their organization’s Business Continuity Plans (BCPs) are still adequate, relevant, and up-to-date to cope with the COVID-19 and other specific scenarios. For instance, IT Auditors should:

  1. Evaluate the key business continuity risks and dependencies including suppliers and vendors.
  2. Evaluate that the revised business continuity plans are aligned with the overall organization’s strategic plan.
  3. Attend crisis management meetings and discussions with the management to assess whether the current and future risks have been identified.
  4. Check that an alternative mechanism is available to communicate security when if systems go down?

Cybersecurity

Due to remote work environments, organizations are facing an increased landscape of cyber-attacks such as susceptibility of social engineering (phishing) attacks and malware, which is impacting organization risks and audit plans. Although it is not the responsibility of an internal audit to manage risks, an internal audit should provide reasonable assurance on the governance and the management of the cybersecurity risk.

IT Auditor considerations should include:

  1. How organizations are raising awareness to promote proactive identification and reporting of malicious activities?
  2. Are awareness sessions customized to cover current and new threats as employees are more susceptible to social engineering attacks due to employees increased workloads, usage of technologies, and augmented stress levels?
  3. Is the organization having a 24/7 monitoring of suspicious activities caused by disgruntled employees (external/ internal)?
  4. Are technological controls to reduce the risk of increased phishing attacks implemented?
  5. Is phishing testing carried out to raise awareness?

User Access Controls

Due to flexible working hours and 24/7 working from home, employees are required to have excessive access to several systems. IT Auditors should evaluate that:

  1. Whether access to employees is granted based on the need to have, need to know, and need to do principles or not?
  2. Has a dual-factor authentication mechanism been activated?
  3. Are segregation of duties ensured while granting access?
  4. Are Audit trails maintained for every access granted, and activities performed?
  5. Are privileged administration activities exclusively monitored?

Virtual Private Network (VPN)

Due to the Covid-19 crisis, the ways of doing business have dramatically changed around the world. Consequently, organizations have permitted their employees to work from home (WFH), which has led to a massive rise in VPN traffic on the networks. The main objective of using a VPN is that it facilitates remote employees to connect to their working networks by creating a private and secure tunnel across a public network connection while ensuring that data is encrypted and transmitted securely.

IT Auditors considerations for VPN may include that:

  1. Are VPN and other remote access solutions patched timely and secure configurations are being used?
  2. Are devices/ machines used for connecting remotely secured and controlled by deploying endpoint protection software?
  3. Do VPN and other remote access solutions have appropriate licenses in place to cover the required number of connections by the employees?
  4. Is an increased bandwidth capacity available to support remote access?

Privacy

As an implication of the COVID-19 pandemic, privacy rights also have been amplified. The IT Audit considerations are set out below:

  1. Are legal responsibilities in terms of protecting end-users’ privacy rights identified?
  2. Have risk assessments of products or services to assess privacy rights risks, including granting third-party access to employees’ sensitive information?
  3. Is collected private data deleted after the crisis? How is it being ensured?
  4. Is there any process to ensure that all the data collected is relevant to the required business purposes and is not more than necessary in any way?
  5. Is there any policy or disclaimer about the transparency of the type of data being gathered, with whom will it be shared? And for what purposes?

The COVID-19 pandemic has exposed the organizations to huge, unexpected, and rapid changes whether voluntarily in response to the emerging pandemic situation or enforced by the regulators. Since organizations have faced their own unique set of challenges, Internal Audit should understand the changing circumstances, new ways of working conditions, the new risk landscape and actors, and how best to add value to organizations by changing challenges into opportunities.

Note

This article provides indicative guidance to Internal Auditors (IT Auditors in particular) in developing a better understanding of the areas of risks and associated potential impacts on their organizations.


About the Author

Muhammad Tariq Ahmed KhanMuhammad Tariq Ahmed Khan is Head of Cybersecurity Audit, Internal Audit Division, Arab National Bank, Riyadh. He is a “Subject Matter Expert” in Technology and Cybersecurity Audits. He has more than 21 years of experience in the Banking industry, in areas such as IT, Cybersecurity, and IT Audit. He has a solid understanding and application of Risk-Based Audit methodology, ISMS (ISO 27001), ISO 22301, NIST and COBIT, IT & Information Security regulatory compliance. To his credit, Tariq also has sound technical knowledge (as evident by his pertinent professional certifications) in various IT platforms and IT project management – with experience in Disaster Recovery, and Business Continuity Management.

He has published articles on different topics of cybersecurity and he has spoken at regional and international seminars and conferences.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

WhatsApp Pink and Fake Facebook Messenger Scams Explained

WhatsApp Pink and Fake Facebook Messenger

Cybercriminals often target businesses that hold large amounts of users’ sensitive information. And social networking services like Facebook and WhatsApp always top the list when it comes to hacker intrusions and other security incidents. Cybersecurity experts from global cyberthreat hunting firm Group-IB discovered a large-scale scam campaign targeting Facebook Messenger users across the world in over 80 countries in Europe, the Middle East, and Africa (MEA) region, Asia, and North and South America.

Fake Facebook Messenger Campaign  

Group-IB researchers found that cybercriminals have been stealing users’ login credentials by distributing a fake updated version of Facebook Messenger. Researchers discovered over 1,000 such fake Facebook profiles employed in the scheme. “The number of Facebook posts inviting users to install “The latest Messenger update” reached 5,700. To draw users’ attention, fraudsters registered accounts with the names mimicking the real app — Messanger, Meseenger, Masssengar, etc. — and used Facebook Messenger’s official logo as their profile picture,” Group-IB said.

Facebook Ad promoting a Facebook Messenger Update

Image Courtesy: Group-IB

The fake ads reportedly targeted a large set of users globally across India, Canada, the U.S., France, Germany, Nigeria, Italy, Singapore, Malaysia, and South Africa. 

How does the scam work?

 Malicious links are promoted as download links in the updated version. Once the user clicks on the link, it redirects the victim to a fake Facebook Messenger website with a login form asking users to enter their credentials.

Attackers leveraged web hosting platforms like blogspot.com, sites.google.com, github.io, and godaddysites.com to host fake Facebook Messenger login pages. They also used the services of linktr.ee, bit.ly, cutt.us, cutt.ly, and rb.gy to shorten the links and bypass spam filters. “Users who fell victim to this scheme risk leaking their personal data and have their account hijacked. Scammers, in turn, are likely to use the compromised account to either blackmail the victim, pushing them to pay a ransom to have access to their account restored, or further scale up the scheme using the Facebook profile to distribute scam ads,” Group-IB added.

WhatsApp Pink Scam

A malicious app named WhatsApp Pink is making rounds online to gain control over users’ devices and steal their information.

According to Indian security researcher Rajshekhar Rajaharia, threat actors are sending malicious links to users claiming to provide new WhatsApp features in pink color. If a user clicks on the link, it automatically redirects the victim to a fake page with an option to download the malicious WhatsApp Pink app. The malicious link can possibly lock the targeted users out of their WhatsApp accounts or worse – devices.

Cybersecurity After COVID-19

COVID-19 Cyberthreats

In addition to the health and economic impacts of COVID-19, society had to grapple with a plethora of new and persistent cybersecurity threats. As the initial health impacts of the pandemic fade, we need to understand the aftermath as it pertains to attacks on information systems around the world. At the outset of COVID-19, we saw a perfect storm of failures in people, processes, and technologies that lead to numerous attacks and cybersecurity incidents around the world. Many different reasons lead to these episodes. While cybersecurity defenders do their best, various conditions created an environment conducive to bad actors, which they quickly took advantage of. CISOs must have a clear understanding of the technologies and processes in place and make the necessary adjustments after COVID-19 to prevent attackers from succeeding in perpetuity.

By Eric Jeffery, Senior Solutions Architect, IBM 

How Did We Get Here?

Some of the weaknesses that arose in cybersecurity defense involved technical components while others dealt with human error. Human failures occurred for different reasons, some due to a lack of knowledge, others due to overwork, and yet even more because information technology professionals were thrust into fields they were not familiar with. When I spoke with the IT leadership at a university in Utah and a government agency in New Mexico, it was clear that their organizations suffered in delivering IT services at the start of COVID-19.  I was told that staff had to quickly shift from other tasks and engage with new technologies which lead to productivity impacts and security concerns.  A healthcare system in the northeast, diverted its security team from critical projects to align them with supporting COVID-19 requirements.  This resource shift opened them up to risks of attacks slipping by as the security team was no longer working on their security operations center and instead of helping in other areas of IT.

Being overworked, stressed, and asked to handle technologies they were not skilled in created new weaknesses for hackers to exploit. I observed that many organizations were wholly unprepared to handle the information technology challenges that arose from COVID-19. For instance, a major entertainment firm on the east coast pulled back from deploying security infrastructure due to revenue loss tied to COVID-19.  They also moved staff to other areas in their information technology organization.  Removing front-line security resources lead to increased risks for the organization as a direct result of COVID-19.  As the famous cybersecurity professional Bruce Schneier states, “Security is not a product, but a process.”[1] COVID-19 and the aftermath show organizations the need to always prepare and implement proper processes and not wait to see how they respond in a crisis.

New Challenges

Some of the most prevalent errors that lead to the increase in attacks and successful breaches involve the following areas:

1. Social Engineering: Social engineering in a time of fear and uncertainty makes people more vulnerable, desperate, and less vigilant. Canada’s National Observer reported in April that a security firm witnessed a 4,000% increase in ransomware emails.[2] In early May Datrium stated that nearly 70% of IT professionals from large firms experienced ransomware attacks since COVID-19 began.[3] SDX Central reported that ransomware attacks skyrocketed 148% in March.[4] Europol reported, “Phishing and ransomware campaigns are being launched to exploit the current crisis and are expected to continue to increase in scope and scale.”[5] The number of successful ransomware attacks during the COVID-19 work at home rush exemplifies how susceptible individuals and companies are to social engineering. According to VMware Carbon Black threat researchers [6], ransomware attacks skyrocketed 148% in March, compared to baseline levels in February, as corporations shift to remote work because of the coronavirus pandemic.

2. Firewall Misconfiguration: When employees connect from a corporate location, managing and maintaining firewall rules is commonplace and simple. As staff migrates to remote locations, the combinations and permutations of rules become exponentially more difficult to manage. Organizations undoubtedly suffered from security weaknesses when they had to make modifications to access control lists to support remote workers. One incorrect digit opens a plethora of attack vectors that hackers can take advantage of. Gartner states that 99% of all firewall breaches through 2023 will be due to firewall misconfigurations, not system flaws.[7] We saw this exact issue with the Capital One AWS data breach[8]. When network engineers are tasked with the job of rapidly modifying firewall configurations, errors undoubtedly occur, and new holes open, leaving organizations at risk.

3. Virtual Private Network (VPN) Configurations: When setting up virtual private networks, entities must decide if they want all traffic traversing their corporate network or if they want remote workers to utilize their own internet service provider to manage the load for specific network requirements. The technical term for this capability is split tunneling. When enabled, users bypass internal security mechanisms including proxy servers, data loss prevention systems, and intrusion detection and prevention devices. That is the drawback, but the benefits include that corporate networks do not become overloaded and users do not have to go over long distances to reach network resources.

During COVID-19, network security professionals began seeing increased connections to known botnets. In a Twitter post, MalwareTechBlog reported on April 18th that “Emotet is back and better (worse) than before. After months of inactivity, all botnets are showing signs of life and utilizing new evasion techniques.”[9]

ZDNet also reported that Emotet, “today’s most dangerous botnet” comes back to life.

This occurred, in part, because infected systems that were protected behind corporate networks and proxy servers were not prevented from reaching out to the command and control systems. Additionally, according to the Official site of the state of New Jersey, “new cyber threats are revealed that exploit public concern over COVID-19… [including] software that, when downloaded, installed the BlackNET remote access trojan and added the compromised system to a botnet.”[10]

Organizations need to improve endpoint protection, so systems do not become or stay infected. Proper endpoint hygiene reduces the need for proxy servers and limits the risks of enabling split tunneling.

4. Unsecured and Unprotected Endpoints: With millions of professionals shifting from working in an office to working remotely, companies struggled to find enough laptops for their staff to use. As The Wall Street Journal reported on May 8th, “Store Shelves Stripped of Laptops as Coronavirus increases Working From Home.”[11] This shortage of systems leads individuals to use personal equipment to do even the most basic work, including email, file sharing, and instant messaging. Using personal systems on a corporate network adds additional risks as internal IT teams have little to no control over what is on the personal systems. Bring Your Own Device (BYOD) has been an issue for IT professionals for years and with COVID-19, that list of devices just skyrocketed. Weaknesses in-home networks and personal devices add a new level of threat to corporate environments.

5. Transmitting Data Improperly: Companies and agencies face numerous risks when it comes to having staff use personal email for business use. There are legal and privacy concerns as well as regulatory and technological risks associated with improper use of email transmissions.  Prior to COVID-19, according to Avatier, an identity and access management firm, nearly 4 in 10 people use personal email accounts for work-related emails.[12] The increase in remote work will increase this number due to the ease of access being outside of a corporate environment.  When employees work in a corporate office with properly configured systems, IT can control how data gets transmitted. Removing employees from a static environment and allowing them to use either personal or company systems on personal networks potentially eliminates these safeguards.

Employees need to communicate and most often they take the path of least resistance. If they cannot email a file through the company email account, they quickly default to an MSN, Gmail, or Mail.com account. This activity completely opens the organization to untraceable data loss. In addition to email communications, individuals may switch from Slack or MS Teams to using text messaging or WhatsApp. While employees could do this from the office, it is easier for IT teams to identify these bypasses if the employee resides on a corporate network. With so many individuals working at home, the threat of data loss due to COVID-19 changes in our way of working is incalculable.

This story first appeared in the July 2020 issue of CISO MAG. To read the full version, Subscribe Now


References

  1. https://www.azquotes.com/author/21361-Bruce_Schneier
  2. https://www.nationalobserver.com/2020/04/14/news/4000-increase-ransomware-emails-during-covid-19
  3. https://www.upi.com/Top_News/US/2020/05/06/Ransomware-attacks-up-since-start-of-COVID-19-crisis-study-finds/9951588771542/
  4. https://www.sdxcentral.com/articles/news/ransomware-attacks-spike-148-amid-covid-19-scams/2020/04/
  5. https://www.europol.europa.eu/publications-documents/catching-virus-cybercrime-disinformation-and-covid-19-pandemic
  6. https://www.sdxcentral.com/articles/news/ransomware-attacks-spike-148-amid-covid-19-scams/2020/04/
  7. https://www.firemon.com/security-teams-unprepared-for-covid-19-cyberthreats/
  8. https://www.washingtonpost.com/technology/2019/07/30/capital-one-looked-cloud-security-its-own-firewall-couldnt-stop-hacker/
  9. https://twitter.com/MalwareTechBlog/status/1251606958005604352
  10. https://www.cyber.nj.gov/alerts-advisories/covid-19-cyber-threats-continue-to-evolve
  11. https://www.wsj.com/articles/store-shelves-stripped-of-laptops-as-coronavirus-increases-working-from-home-11584534112?mod=e2twd
  12. https://www.avatier.com/blog/wp-content/uploads/2017/08/personal-vs-work-email_infographic.png?x22788

About the Author

Eric JeffreyEric Jeffery has over 20 years of experience in cybersecurity and currently works as a Senior Solutions Architect for IBM. He has published numerous articles and spoken at several conferences around the U.S. during his tenure in information technology. Jeffery recently started a Podcast under the moniker of Cyber Security Grey BeardTM where he helps students and early professionals begin and grow in the cybersecurity field.

Disclaimer

The comments and statements in this article are my own and don’t necessarily represent IBM’s positions, strategies, or opinions.

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Chinese State-Actors Exploit Big Data for Financial Benefit

Exploit of Big Data

No doubt Big Data is helping organizations globally in growing their businesses at an unprecedented rate. It offers rich insights for decision-making and strategic planning. Businesses that leverage big data can be immensely successful. On the other hand, companies often ignore the drawbacks linked with it like data breaches, cyberattacks, and privacy lapses. If you aren’t protecting your crown jewels, it will fall into the wrong hands with catastrophic results.

Big Data is Growing Big

Statistics show enterprises that leveraged Big Data generated massive revenues. According to a survey, Big Data was responsible for profits amounting to $122 billion in 2015 and it is expected to generate a whopping $274.3 billion by 2022.

Since Big Data involves a large volume of both structured and unstructured data, companies collect, process, and analyze it as per the business requirements and systematically leverage it to maximize business opportunities. Organizations working on Big Data handle huge amounts of users’ personalized data to analyze their online behavior.

Risks Around Big Data Security

Several cybersecurity experts reported that threat actors are taking advantage of legitimate Big Data sources to exploit users’ valuable information.  Recent research from Intel 471 revealed that adversaries are misusing Big Data technology to steal users’ data and sell it on the Chinese-language dark web markets. “With China injecting Big Data into every economic sector, the environment has become ripe for criminals to create and execute schemes that hide in the noise brought on by the amount of data at hand,” Intel 471 said.

Key Highlights

  • A threat actor in January 2021 offered real-time data for casino gaming, lottery, and stocks on a popular forum used by Chinese-linked cybercriminals. The data allegedly originated from big data sources of two of the most popular mobile network operators in China.
  • In February 2021, cybercriminals offered website and application crawler data collection services on a Chinese-language cybercrime marketplace. The actor claimed to have access to insider channels of Chinese mobile operators for data collection purposes.
  • In early March, an actor on a marketplace offered 10,000 user records tied to a parenting application. The offering was described as big data from an undisclosed mobile operator or operators.
  • In late March, another actor offered big data information for Canada and the U.S. that included commercial databases of Canadian and U.S. businesses and investors, a hacked Twitter database, and Canadian and U.S. citizens’ information.

Malicious Schemes by Chinese Actors

Intel 471 researchers observed a series of malicious schemes involving different layers of cybercriminal activities to illicitly obtain users’ data and trade it on darknet forums. Cybercriminals maintained a data underground monetization chain consisting of a group of individuals working as per the commands, which include:

  • A boss or requester who requires data for illegal use or commands a group or syndicate dealing with illegal products or services.
  • Insiders or attackers who receive instructions directly from a boss and can gain access to raw data and extract the information from a service provider. These individuals profit from the information they provide to the main boss or requester.
  • Middlemen who act as intermediaries for the boss and any other individuals requesting to purchase such data products. The middlemen profit by taking a cut of the commission from product sales.
  • Underground platforms serve as an avenue for the syndicate or middlemen to advertise their products. End users, such as scammers, multiple types of threat actors, and even direct marketers can purchase the data or engage the services of such syndicates directly on these platforms.

“The schemes themselves proliferate partly due to China’s desire to be a global epicenter in big data analytics, especially as it pushes to become synonymous with new technology sectors like the Internet of Things (IoT),” Intel 471 added.

Why DDI Plays an Important (But Overlooked) Role in Zero Trust Security

Zero Trust, cybersecurity

The Zero Trust security model isn’t entirely new, but it’s becoming more important as network perimeters disappear and applications and data are more distributed. Zero Trust assumes that threats can arise anywhere, inside or outside the network, and that every component of the network where data, assets, applications, and services reside must be validated and secured.

By Chris Buijs, Field CTO, NS1

For Zero Trust to be truly effective, organizations adopting these principles must extend the framework to all parts of their infrastructure. DDI can be an important first step in implementing Zero Trust, but so far, few people have recognized the value of this proposition.

DDI is a collective reference term that covers Domain Name System (DNS), Dynamic Host Configuration Protocol (DHCP), and IP Address Management (IPAM). These three components comprise the foundation of core network services that enable all communications over an IP-based network. In fact, nothing can happen on a network without these critical services, which is how DDI plays into the notion of Zero Trust.

Traditional Implementation of a Zero Trust Architecture

The traditional concept of a Zero Trust Architecture follows a pattern:

A user wanting to connect to a resource initiates a secure connection and authenticates to a Zero Trust broker. The broker applies security policies according to the user’s identity and device attributes. Access is granted to a specific resource or set of resources only after the user and his or her device have met the requirements of the security policy. A secure session providing connectivity to the resource is then established and continuously monitored for potentially malicious behavior. If suspicious activity is identified, the user’s session can be isolated or dropped to prevent a breach.

That’s a lot of steps, a lot of security infrastructure, and a lot of network activity required to establish a trusted connection between a user and a resource. But much of this effort may not even be necessary if the DDI infrastructure is used first to evaluate the requested connection. In particular, DNS and DHCP offer many opportunities to enrich Zero Trust by including the underlay of the network as part of the process.

What the DDI Services Do

Enterprises use private DNS servers to store the names and IP addresses of internal file servers, mail servers, domain controllers, database servers, application servers, and the like. So, for example, if a user requests to connect to the Zero Trust broker, the internal DNS system will know the address where the broker service can be found before the user’s actual connection ever takes place.

DHCP simplifies the management of IP addresses on networks. No two hosts can have the same IP address, and configuring them manually would likely lead to errors. Also, some IP addresses, such as those for containers, virtual servers, and mobile devices, are needed on a non-permanent basis. Thus, a DHCP server is a network server that automatically provides and assigns IP addresses and other network parameters to client devices and other services.

IPAM is the administration of DNS and DHCP. It provides the means for planning, tracking, and managing the IP address space used in a network.

Using DDI to Enable Zero Trust

Together, DNS, DHCP, and IPAM are important factors in securing a network because these services enable everything on the network, and they get addressed before any application transaction happens. Think of it this way: If there is no IP address, there can be no connection or communication on the network. Thus, before any application connects to an endpoint, server, cloud entity, or whatever, there are first some network calls that must happen through these DDI services. This provides great leverage for security and influence on how an application is going to act.

Consider a network that doesn’t permit external access to YouTube for whatever reason. What happens if an app on the network wants to execute a link to YouTube? The first thing that happens is a DNS call that asks, “Where is YouTube on the Internet?” At this point, a rule on the DNS server can step in and say, “You’re on a private network, and YouTube isn’t allowed.” Consequently, the app is denied its DNS request, and no external communication ever takes place. Because this is all “built-in” to the DNS function, nothing else is required. As a bonus, because there is no network traffic, no bandwidth is consumed.

The good news is that DNS is already built into every application, so there’s no need to install anything to get the metrics or the data that can be used for security purposes. It’s all there, but it’s often overlooked. It’s time to put this facility to work to enable and enforce Zero Trust to protect data and applications.


About the Author

Chris Buijs is an evangelist and network and security specialist with more than 20 years of experience focusing on DDI (DNS, DHCP, and IPAM). He has held various leadership roles and capacities at vendors, and resellers. Chris has a rich background as a lobbyist for various issues to create awareness on tech-forward topics, including IPv6 and DNSSEC, and turns organizations into forward-thinking entities.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.