Home Blog Page 94

CISOs are Struggling with Continuous Security Debts: Surveys

CISOs in remote working

With the increase in the volume of cyberattacks, security leaders are changing their cybersecurity measures accordingly. However, cybercriminals too become consistent in advancing their hacking skills to create new techniques to launch cyberattacks. From high-profile ransomware attacks to sharing malicious tools and offensive knowledge-making, cybercriminal groups are becoming more effective.

Most CISOs and other security professionals report that turning away cybersecurity budgets is increasing the volume of cyberattacks. According to a joint security analysis from F-Secure and Omnisperience, CISOs encountered a rising security debt to protect their organizations against evolving cyber threats.

According to the analysis, 96% of CISOs stated that they face well-organized cybercriminal attacks motivated by financial gain. Nearly 72% of them said adversaries are moving faster than they are, and a similar number (69%) say their adversaries have improved their attack capabilities in the last 12-18 months.

Key Findings:

  • Employees are the primary attack vector, according to 71% of the CISOs interviewed, as attackers take advantage of social channels to launch more sophisticated targeted attacks.
  • The top three threats CISOs and their teams face are phishing, ransomware, and business email compromise (BEC).
  • Securing the mobile or remote workforce, which has exploded during the pandemic, presents several risks, particularly where employees and devices are separated from traditional controls that could prevent their compromise.
  • A vast majority of CISOs – 71% – report that their ideas about what constitutes “good security” have evolved recently.

“Despite pervasive ‘security debt’ and reporting a rising number of cyberattacks, CISOs say that say the number of incidents, which includes a breach or unauthorized access to a system, they faced remained pretty much the same. This could be because CISOs have made the right investments. However, it is the incidents that haven’t been discovered which worry us most. Because of the sophisticated nature of some of these attacks, organizations may not have the technology or people to identify they are in the middle of a compromise that, for example, may result in a ransomware deployment month down the road,” said F-Secure’s Michael Greaves, security advisor for Managed Detection and Response.

Apathetic Leadership a Major Concern

A similar joint analysis from cybersecurity firm Sophos and Tech Research Asia revealed that cybersecurity budgets remained stagnant and executive teams continue to underestimate the consequences of cyberattacks. The survey “The Future of Cybersecurity in Asia Pacific and Japan” found that nearly 70% of organizations in the Asia Pacific suffered a data breach in 2020, an increase of 36% from 2019.

It was found that cybersecurity budgets remained unchanged between 2019 and 2021 despite the increase in cyberattacks. Around 59% of organizations claimed that their cybersecurity budget is below where it needs to be, the same percentage it was in 2019.

“Ultimately, security is about right-sizing the risk. If the risk increases, budgets should also increase, but in this climate of uncertainty, we’ve seen organizations take a conservative approach to security spending, which is impacting their ability to stay ahead of cybercriminals,” said Trevor Clarke, lead analyst, and director at Tech Research Asia.

Cybercriminals Enjoy a Cheesy Crust of Domino’s India through a Data Breach

domino's data breach

Previously, a preliminary report from UpGuard had given Domino’s Pizza’s security posture a “B-grade” rating, based on the security folds implemented by the pizza serving giant. It had scored 713 out of the total 950 points which are awarded based on UpGuard’s internal parameters and standards. However, it seems like this incident has come back to haunt them. Domino’s Pizza is one of the most popular pizza chains in India and has reportedly faced a data breach incident that leaked nearly 13TB worth of its internal data. The data breach was brought to light by Alon Gal, a renowned cybersecurity researcher and chief technical officer at Hudson Rock, an Israeli cybersecurity firm.

Alon tweeted his findings on Sunday stating that the leaked information included 180 million order details of Domino’s Pizza deliveries across India. These order details include the following:

  • Customer names
  • Phone numbers
  • Email IDs
  • Delivery address

Additionally, the payment details of certain orders made through the Domino’s India app have also been compromised, exposing nearly one million credit card details of its customers.

Related News:

Security Researchers Call Out MobiKwik for KYC Data Leak

According to Alon, apart from the order and credit card details, threat actors claimed to have internal data which includes employee details of more than 250 employees across various departments such as IT, legal, finance, marketing, operations, etc.

Alon’s investigation also found that the threat actor who has put up a sale post for the leaked information over a dark web forum has two offers at hand – 2 bitcoins and 8 bitcoins respectively — and can also be bought cumulatively for 10 bitcoins (no discount on offer here: pun intended). This means the complete data set is being sold for nearly $550,000 to a single user. However, the malicious actors have alternatively offered the same data set for 50 bitcoins (approximately $28,46,000) to Domino’s India if it did not want the data to “go public.”

Apparently, the post from the adversaries suggests that they are also trying to create a data leak search portal like the one which was created in the recently surfaced MobiKwik data breach, where users were able to post queries on the leaked data. However, their technical knowledge seems to be limited to the front end and they struggle when it comes to MySQL. Thus, they have posted a freelancing offer for this and are ready for a one-time payment of $1,000. They have asked interested users to send a backend API consisting of one MySQL and one MongoDB table with some backend code to take search input and display output in a JSON format.

Later, Alon Gal tweeted that plenty of large-scale Indian breaches are taking place lately. This is worrying,” and we second that.

Related News:

India’s Data Breach Saga Continues; Country’s Second Largest Stockbroker, Upstox, Hit!

Patch Now! Researchers Find Zero-Day Flaws in Google and Microsoft

Microsoft Azure App, Zero-Day Vulnerability

The risks from cybercriminals exploiting zero-day vulnerabilities have become a continuous threat for organizations, globally. Recently, security experts from Kaspersky found a zero-day vulnerability tracked as CVE-2021-28310 in Microsoft Windows component known as Desktop Window Manager (DWM). The researchers stated that threat actors have likely exploited the flaw.

Microsoft immediately released a security patch to fix the vulnerability after Kaspersky reported the issue. Users and businesses were urged to apply the fix as early as possible to avoid any risks.

What is a Zero-Day Vulnerability?

A zero-day vulnerability is a flaw in a piece of software that is unknown to the programmer or vendor responsible for the application. Because the vulnerability isn’t known, there is no patch available. And hence, zero-day vulnerabilities pose a higher risk to users and businesses.

However, the vulnerability is known to the attacker who exploits the vulnerability to attack the system. The software vendor might eventually issue a patch to fix the vulnerability once it becomes known. A third-party researcher or individual could expose this zero-day vulnerability.

It is not uncommon to see organizations failing to update their security applications after the vendor issues a patch/fix. And those organizations become victims of the attack, even though there is a patch available for that vulnerability.

Zero-Day Flaw in Desktop Window Manager

The CVE-2021-28310 flaw is a privilege escalation vulnerability that allows a remote attacker to gain admin privileges and execute arbitrary code on victims’ devices. The privilege escalation flaw gives extended rights to cybercriminals to compromise sensitive data from the victim’s computer. Kaspersky researchers suggest that threat actors may have already abused this flaw along with other loopholes in the users’ systems by evading the detection from security tools.

Desktop Window Manager (DWM) is a critical component responsible for rendering the windows that use the operating system. The DWM controls all the required information from the buffer of each program and formulates the composite view of the overall interface that the user perceives.

“A program can trick Desktop Window Manager into giving it access that it shouldn’t have. In this case, the vulnerability allowed the attackers to execute arbitrary code on victims’ machines — it essentially gave them full control over the computers,” Kaspersky said.

How to Fix the Flaw

  • The security researchers urged users to immediately apply the security update released by Microsoft to prevent intrusions from threat actors.
  • It is recommended to implement a robust endpoint security solution and patch management capabilities.
  • Employ an enterprise-grade security solution to identify and advanced network-layer cyber threats.

Zero-Day Flaw Affecting Google Chrome

In a similar vulnerability investigation, Indian security researcher Rajvardhan Agarwal discovered a new zero-day vulnerability affecting new versions of popular web browsers, including Google Chrome, Microsoft Edge, and other Chromium-powered browsers like Opera and Brave.

Commenting on the vulnerability disclosure, Satnam Narang, Staff Research Engineer at  Tenable said, “An attacker cannot compromise the underlying operating system or access confidential information without combining this vulnerability with a second vulnerability to escape the sandbox. Zero-days may garner most of the attention but known yet unpatched vulnerabilities enable most breaches and have become favored by advanced attackers. Despite the limited impact from the public disclosure of another Google Chrome vulnerability, we continue to encourage users and organizations alike to ensure they are patching their browsers like Chrome and Edge as soon as possible.”

Amid Today’s Threat Landscape, Protecting Active Directory is a CISO-Level Concern

active directory
active directory

Despite Active Directory’s critical role in today’s IT infrastructure, CISOs rarely list protecting it as a top priority. They assume that policy management and periodic audits are sufficient to cover it, and too often, it fades into the background as part of the plumbing — something they just expect to function as it should. Active Directory (AD) is a solution businesses use to set and control privileges and permissions, which means ease of access and operations are essential. Unfortunately, constant changes and continuing growth make it complex to protect.

By Carolyn Crandall, Chief Security Advocate, and CMO, Attivo Networks

Stolen credentials are on the rise, and privileged access is a factor in the majority of cyberattacks. With more and more cybercriminals looking to move laterally within the network and escalate their privileges, AD represents an increasingly high-value target. The complexity of securing AD and the growing frequency with which attackers target it means that CISOs can no longer view it as a backburner item — its security is now a CISO-level concern.

The Complexity of Securing Active Directory

Over 95 million Active Directory accounts are under attack every day, demonstrating the frequency that cybercriminals attempt to compromise AD to acquire additional permissions and escalate their attacks. AD is a “master key” that manages permissions across the enterprise, and — unfortunately — access control is no simple matter. Overprovisioning is common, especially in group policies, and legacy permissions can be difficult to track. Orphaned credentials are an issue that can be hard to gain visibility into, and mergers and acquisitions can add further complexity, as merging disparate user groups and assets are often challenging. Security teams commonly lack visibility into AD changes, making it challenging to protect what they can’t see.

More than Just Plumbing

More than 90% of Global Fortune 1000 organizations use AD for authentication, identity management, and access control. Unfortunately, AD configurations become increasingly complex over time, resulting in overprovisioning and errors. The addition of temporary workers, mergers and acquisitions, and third-party vendors that need some level of access compounds the situation. In addition, the number of users, devices, and applications accessing company networks is growing every day, and today’s networks now extend from the endpoint to the cloud.

Privileged access covers credentials, databases, infrastructure, and network devices. AD touches all of these areas, which is why attackers see AD as the ultimate prize, granting them access to the rest of the network. Whether they aim to gather passwords via a DCSync attack, push changes to AD ACLs and settings via a DCShadow attack, or create anything with a Golden Ticket attack, AD is a high-value target for attackers.

Given its role in maintaining operations and allowing employees to do their work efficiently, losing control of Active Directory can cause everything from a small to complete disruption of service.

Active Directory Attacks Can Cause Serious Damage

Privileged access abuse is a factor in 80% of known security breaches, including the recent highly damaging SolarWinds and Microsoft breaches. If attackers compromise AD, they can use stolen credentials—or escalate privileges for credentials they already possess — to move laterally throughout the network. Once an attacker has “domain administrator” control of AD, an attack becomes highly difficult to stop and can require extreme measures to restore the AD environment to a non-compromised status.

Third-party attacks like the SolarWinds breach highlight how attackers can bypass perimeter defenses. In this case, modified SolarWinds products provided attackers with a backdoor into numerous company networks — circumventing any perimeter protections those organizations may have in place. Without in-network defenses, there is little to stop attackers from making a beeline for AD — and with the average cost of a data breach now at nearly $4 million, an attack that compromises AD will almost certainly be an expensive one. Payout demands for ransomware breaches, almost all of which use AD as an element of their attack, have climbed to record-breaking heights. In mid-March, PC giant Acer was hit by a $50 million ransomware attack, demanding the highest known ransom to date.

How CISOs Can Change Their Thinking

Identifying the right metrics can be a challenge for CISOs. When talking to a company board, they often feel compelled to focus on metrics like intrusion attempts, incident rates, response times, and other numbers, which, while important, do not tell the whole story. Additional metrics like excess privilege exposures can help contextualize the threat to AD and the network at large. These metrics may take some further explaining, but they provide a more comprehensive picture of network health and security.

Attackers tend to leverage many things during attacks. First, they prey on endpoints and users. They will next attempt to compromise the endpoint, then focus on local privilege escalation. Inside the network, they will conduct network and AD reconnaissance and then focus on attacking AD. Attackers always seek greater privileges, but many security teams rely on SIEMs and AD monitoring solutions, which are inefficient and only useful after an incident has occurred. And while maintaining AD privileges and policies is table stakes, it will not stop an attacker already in possession of privileged account credentials from accessing valuable assets.

Given what we know about how attackers operate, CISOs must pay more attention to lateral movement and identity protection and entitlement than to authentication and authorization. With greater visibility into potential threat paths and exposures, security teams can remediate issues and set traps for would-be attackers by hiding real AD objects and seeding the network with false ones. Rather than identifying signs of an attack after it has taken place, CISOs can enable their security teams to take a more proactive approach, tricking attackers into giving themselves away before they can escalate their attacks.

Making AD a Top-Level Priority

Attackers today view AD as an easy target, in part because organizations consider it protected by the perimeter, policies, and log management, which savvy attackers have proven they can repeatedly defeat. By shifting their attention to vulnerability visibility, lateral movement, and privilege escalation detection, CISOs can make life much more difficult for attackers and prevent minor incursions from becoming full-scale breaches. By recognizing that AD has become an attack vector of choice, CISOs can more effectively protect their networks from today’s most damaging attack tactics.


About the Author

Carolyn CrandallCarolyn Crandall holds the roles of Chief Security Advocate and CMO at Attivo Networks. She is a high-impact technology executive with over 30 years of experience in building new markets and successful enterprise infrastructure companies. She has held leadership positions at Cisco, Juniper Networks, Nimble Storage, Riverbed, and Seagate. Crandall has received many industry recognitions including Top 25 Women in Cybersecurity 2019 by Cyber Defense Magazine, Reboot Leadership Honoree (CIO/C-Suite) 2018 by SC Media, Marketing Hall of Femme Honoree 2018 by DMN, Business Woman of the Year 2018 by CEO Today Magazine, Cyber Security Marketer of the Year 2020 by CyberDojo (RSA), and for 9 years a Power Woman by Everything Channel (CRN).

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

“Every bit of compromised PII can be used for social engineering attacks to target individuals or institutions”

PII for social engineering attacks

Marcus Fowler is Director of Strategic Threat at Darktrace. Before joining Darktrace in 2019, he spent 15 years at the Central Intelligence Agency (CIA) developing global cyber operations and technical strategies. He has led cyber efforts with various U.S. Intelligence Community elements and global partners and has extensive experience advising senior leaders on cyber efforts.

Fowler was a Department Chief and Executive Leader for one of the CIA’s largest departments, where he led hundreds of officers. He served as the subject matter expert and senior representative to national security data and cyber policy and strategy discussions. He also led a significant multi-million-dollar budget focused on combining innovative data exploitation techniques and also drove the development of complex engineering solutions, specialized tool development, new data science applications, and private sector and foreign partner outreach. He is recognized as a leader in developing and deploying innovative cyber solutions.

Prior to serving at the CIA, Fowler was an officer in the United States Marine Corps. He has an engineering degree from the United States Naval Academy and a Masters’ Degree in International Security Studies from The Fletcher School. He also completed Harvard Business School’s Executive Education Advanced Management Program.

In an exclusive interview with Augustin Kurian from CISO MAG, Fowler talks in detail about his journey, his time with the CIA, the evolution of cyberattacks, and a bit about the cybersecurity of elections.

Edited excerpts of the interview follow:

You started your career with the United States Marine Corps, and you were the Company Executive Officer. Following which you had a brief stint in Celixir. You then served the CIA for nearly 15 years before joining Darktrace. Tell us more about your journey.

Security has always been present in my professional interests and career. While attending the U.S. Naval Academy, I was drawn to the Marine Corps and the force protection and security missions it conducted. As a Marine, I had the opportunity to serve as the Executive Officer of a Security Forces Company responsible for the physical security of sensitive sites. I was also stationed overseas in Italy when the USS Cole terrorist attack in Yemen occurred. I was quickly assigned to assist in standing up Port Vulnerability Assessment Teams designed to forward deploy ahead of ships coming to port and work with the local Embassy and police forces to evaluate the overall port security.

This experience led me to get a Master’s degree focusing on international security studies and finally to the Central Intelligence Agency. It was during the early days at the Agency that I started to gravitate towards mission areas that allowed me to run teams focused on developing and deploying emerging technologies to maximize mission impact, specifically around cyber and big data.

I wouldn’t trade a minute of my Agency time for anything — the men and women that serve there are incredible and dedicated Americans. However, I had reached a point in my career where I felt the need to explore the private sector and see if there was a company or role that resonated equally with me. In the end, I was drawn to Darktrace’s trailblazing innovation, applying artificial intelligence and machine learning to the critical area of cybersecurity, as well as to the opportunity to work closely with an amazing group of subject matter experts, including mathematicians, machine learning experts, white hat hackers, CISOs, industry analysts, and ex-intelligence members.

How do you differentiate between older and newer cyberthreats?

Given we are seeing old cyber threats get recycled or re-engineered it is difficult to differentiate between old and new.

It is almost easier to differentiate between the different tiers of attackers. There’s the lower level or “Bottom Feeders” taking advantage of unpatched networks or devices, poor password management, and targets conducting poor cyber hygiene. This is compared to the “Apex Predators,” which these days include not only nation-states but most likely some cybercriminals as well. It is this second group that is conducting slow and low attacks targeting sensitive data, going after third parties to hit many targets at once, and creating zero-day tools.

Two recent trends that I’m increasingly concerned about — and which we’re seeing from both tiers of cyber-actors — are the increases in speed and scale of cyberthreats.

Has critical infrastructure always been the epicenter of cyberattacks?

Most offensive cyber-efforts have historically been more about stealing sensitive data, from classified military secrets to financial data to PII. With the rise of ransomware attacks, the destruction or encryption of critical data and, by extension, the disruption of critical IT-driven processes, is currently the greatest concern for many companies today. However, if we think about nation-states and their aims then critical infrastructure is a natural center of gravity and offers the greatest opportunity for disruption and asymmetric strategic advantage. If we think about smaller, less-militarily capable countries and their ability – or really inability – to project power against a stronger, more forward-deployed adversary, cyber can be the perfect equalizer.

Tell us about the types of highly sophisticated attacks you see attempted against government organizations on a regular basis. These can be during your tenure with the CIA as well as during the times Darktrace took up government projects and security.

For reasons you and your audience no doubt understand, I’m not able to discuss anything I saw during my time at the agency. That said, I can certainly say that Darktrace is seeing, and thankfully detecting and stopping, a consistent stream of sophisticated and novel attacks.

One that immediately comes to mind is an incredibly slow and sophisticated attack against a large U.S. city where Darktrace detected an attacker attempting to exfiltrate sensitive data. It would have been very difficult for a human to see what was happening and it was our AI that was able to build the full story of the intrusion and alert the security team.

We have also seen IoT devices, specifically security cameras deploying facial recognition software, begin beaconing out to a foreign country. The list goes on and on, from targeted spear-phishing enabled by complex social engineering to advanced insider threat leveraging Raspberry Pis.

DISA had recently fallen victim to a cyberattack. The attack on the critical agency which oversees military communications, including calls for POTUS, had many experts wondering, what this means for the national security of the country — especially in the lead up to the election. What does the attack mean for national security and election security?

This is incredibly troubling and certainly should increase concerns around election security and even the U.S. census, which launches online this week, and is expecting to see most respondents leverage the online platform to respond.

When a breach does occur, I get frustrated when I see public or private organizations try and assuage fears by saying not to worry because no “sensitive” data was stolen. As a former intelligence officer, I can tell you firsthand that every bit of personally identifiable information can be used for social engineering attacks to target either individuals or institutions, especially if this data can be correlated against other stolen big data sets.

It is critical that as more and more important government and democratic processes move online and leverage the scale and accessibility that new technology affords, security — not convenience and access — be the top priority.

What types of cyberattacks can mar elections? What are the best practices that need to be established?

The goal of cyberattacks targeting the election will be greater than marring just the election but rather aimed at undermining the credibility of our democratic institutions and processes. There is a focus on the voting infrastructure and votes, but a large-scale series of ransomware attacks could have the same impact by causing public service and potentially, transportation disruption. Especially if these attacks were aimed at swing states this could certainly fuel conspiracy theories and allow portions of the population to call the election into question. Cyberattacks could also serve as an outstanding complement to large-scale disinformation efforts as well.

Beyond targeting the credibility of the election, cybercriminals will most likely attempt to take advantage of the general chaos and increased cyber activity around the election to conduct large-scale spear-phishing campaigns.

As for best practices, the most immediate step that needs to be taken is that state and federal agencies and municipalities need to review their processes and communication plans around a ransomware event, especially one conducted around the election that could have an impact on voting. I think State, Local, and Federal agencies need to be more strategic – resourcing their cybersecurity teams more efficiently and more in line with the current threats and leveraging technology that will help buy back time for their security teams through autonomous response and investigation.

From an individual standpoint, stay vigilant, question what you read, validate the information with multiple sources, don’t click on links in emails, verify the sender, and go straight to the official website to get the contact details.

Several private entities are also working with the government and the election commission. Do you think there is a need for a public-private partnership toward securing election infrastructure?

Public-private partnership is key. There needs to be a high level of transparency and intel-sharing. Organizations need to be sharing what is or isn’t working – the technologies that are providing them with visibility, that are stopping attacks, the threats that are slipping through – all these details are key.

The need for private-public partnership also extends beyond election security, with critical infrastructure being one great example. Private companies own and operate some critical infrastructure in the U.S. – the same critical infrastructure that we’ve seen nation-states attempt to target. The government needs to be working closely with these private corporations to ensure they are prepared for advanced, nation-state attacks that might target critical infrastructure in the upcoming future.

Which of the following poses a bigger threat to the upcoming U.S. elections: Accessing a campaign strategy that would deliver a competitive advantage to the adversary; Opportunistically digging for information that could be reputationally damaging to prominent individuals, or Disrupting the organization to slow productivity?

When we think about threats to the upcoming elections, I would break them up into two groups.

For undermining the election, disinformation operations supported by cyber operations pose the greatest threat.

Adversaries looking to hack a campaign to get the upper hand will likely be going after the information that could reputationally damage a candidate. This is less about broad disruption or undermining trust, and more about swaying individual voters and out-maneuvering a campaign. One would hope that we don’t see this type of targeting between campaigns, as we have enough to worry about from foreign actors.

Do you think artificial intelligence and machine learning will be useful in protecting election infrastructure as these can not only detect these attacks early but also stop them before confidence and data integrity are seriously undermined?

In the face of advanced threats, artificial intelligence and machine learning have become crucial in protecting IT infrastructure at large, including the election. Given the current speed of attacks and the cybersecurity skills shortage, we can no longer expect human teams to be able to identify and stop threats before they can do damage without support from technology.

AI is supercharging every stage of cyber defense: visibility, using AI to understand a digital environments’ unique sense of self, investigation, augmenting the human team to supercharge threat triage and prioritization, and response, autonomously responding to disrupt a threat within seconds while maintaining business operations.

I do want to be clear about the specific types of AI that are able to respond to attacks. Some AI applications, often those that rely on supervised machine learning, attempt to predict the threat actor or attack by analyzing historical attacks. It’s nearly impossible to accurately predict what attackers might launch or target next, even with AI. However, with unsupervised machine learning, AI can understand and enforce what is normal for a company or government by learning the digital “pattern of life.” This approach can stop ransomware, novel threats, or insider threat in seconds, buying back valuable time for security teams.

With AI, we are finally seeing the advantage shift from the attacker back to the defender.

This interview first appeared in the May 2020 issue of CISO MAG. Subscribe to CISO MAG


Augustin Kurian

About the Author

Augustin Kurian the Assistant Editor of CISO MAG. He writes interviews and features.

Internet Swamped with Over 100K Pages Serving Malicious PDFs

malicious PDFs

Cybersecurity researchers found threat actors using search engines to lure business professionals into installing a Remote Access Trojan (RAT) inadvertently.

According to an analysis from eSentire, threats actors are targeting users who are in search of business PDF forms like invoices, templates, receipts, document templates, and questionnaires. Attackers are reportedly hiding RAT into these forms to redirect the users to the fraudulent websites that host the malware. Hackers are leveraging the malicious document templates to infiltrate into victims’ devices.

“Once the RAT is on the victim’s computer and activated, the threat actors can send commands and upload additional malware to the infected system, such as ransomware, a credential stealer, a banking Trojan, or simply use the RAT as a foothold into the victim’s network,” eSentire said.

Spreading Malicious PDFs

eSentire researchers found that whenever the user downloads a form, it simultaneously installs the SolarMarker RAT (also known as Yellow Cockatoo, Jupyter, and Polazert). Once SolarMarker is active, cybercriminals send commands and upload additional malware payloads to the infected system. The researchers suspect that SolarMarker is capable of carrying out a wide range of attacks including ransomware, credential theft, fraud, or cyber espionage operations.

eSentire discovered over 100,000 web pages deployed by threat actors via Google Sites. These unique web pages contain popular business terms/particular keywords like a template, invoice, receipt, questionnaire, and resume. “In a precursory search, 70,000 unique web pages included the mention of either template or invoice. These common business terms serve as keywords for the threat actors’ search optimization strategy, convincing Google’s web crawler that the intended content meets conditions for a high PageRank score,” eSentire added.

Other Findings on SolarMarker

  • The threat actors have created tens of hundreds of web pages with popular business terms, such as invoice, statement, receipt, questionnaire, so that when a business professional is searching the Internet for a specific business template, there is a chance that the top search results will include one of their malicious pages.
  • The infection process relies on exploiting the user, not an application. The user simply executes a binary disguised as a PDF to infect the machine. This is an increasingly common trend with malware delivery, which speaks to the improved security of applications such as browsers that handle vulnerable code. Unfortunately, it reveals a glaring blind spot in controls that allow users to execute untrusted binaries or script files at will.
  • The SolarMarker campaign utilizes a variety of decoy applications. Most recently, TRU observed that the Slim PDF reader software was a decoy being downloaded onto the victim’s computer. This serves as a distraction, as well as an additional element to help convince the victim that they are downloading a pdf.

“Security leaders and their teams need to know that the threat group behind SolarMarker has gone to a lot of effort to compromise business professionals, spreading a wide net, and using many tactics to successfully disguise their traps. Another troubling aspect of this campaign is that the SolarMarker group has populated many of their malicious web pages with keywords relating to financial documents, e.g., statements, receipts, invoices, etc.,” said Spence Hutchinson, Manager of Threat Intelligence for eSentire.

SolarWinds Hack Orchestrated by Russia’s SVR, Claims U.S. and U.K.

Joe Biden, Biden, POTUS, new POTUS, U.S. President, SolarWinds, Solar Winds hack, SolarWinds cyberattack, cybersecurity, cybersecurity budget, cybersecurity head, national cybersecurity head, Joe Biden cybersecurity budget

Earlier in December 2020, the White House had acknowledged that a Russian state-sponsored group known as the Cozy Bear or APT 29 carried out a targeted cyberattack on several U.S. government agencies. The hack successfully compromised the networks of several public and private organizations around the globe. But there was no formal proof affirming Russia’s involvement. However, the Biden administration, along with the U.K. government, has now sanctioned and specifically blamed Russia for the SolarWinds hack and said it was an attempt to “destabilize our societies.”

Related News:

White House Confirms Cyberattack on U.S. Dept of Treasury and Commerce

Biden Ups the Ante in the Cyber Space

A hack of this capacity required a thorough investigation and an ample amount of time. But the new POTUS, Joe Biden, took the issue of cybersecurity on his first day in office. He announced three new appointments for the national cybersecurity agencies, a budget of $10 billion to strengthen the cyber defenses, and asked for a detailed report on what was called the biggest hack of the decade – the SolarWinds cyberattack.

Related News:

Biden Takes Up Cybersecurity on His First Day in Office

Biden closely followed up on this and, in late February 2021, was readying sanctions and other measures against Russia for their “serious” cyber espionage campaigns against multiple government and corporate networks.

Both U.S. and U.K. Find Traces of SVR’s Involvement

According to the U.S. and U.K. governments, the SolarWinds attack was conducted by the Russian Foreign Intelligence Service – SVR (also known as APT29, Cozy Bear, or the Dukes).

The SVR is Russia’s civilian foreign intelligence service and is reportedly a successor to the KGB’s First Chief Directorate. SVR is known to target overseas governmental, diplomatic, think-tank, health care, and energy sectors for intelligence purposes. It invests a lot in developing advanced capabilities that would help them dodge their enemies’ well-guarded systems. This could be why they stole the “red team tools,” used by the cybersecurity firm FireEye to know more about the techniques associated with other known threat actors, which would further strengthen their position.

A press release from the U.K. government said,

The U.K. can today reveal for the first time that Russia’s Foreign Intelligence Service (SVR) was behind a series of cyber intrusions, including the SolarWinds compromise. The U.K. and U.S. are today calling out Russia for carrying out the SolarWinds compromise, which is part of a wider pattern of activities by the Russian Intelligence Services against the U.K. and its allies.

The National Cyber Security Centre (NCSC) has extensively assessed the SolarWinds compromise and concluded that the overall impact on the U.K. of the SVR’s exploitation of this software is low. The NCSC found 14 public sector organizations using the SolarWinds Orion tool but only six have been identified to be targeted through this vulnerability.

Biden’s Sanctions Against Russia

Concurring with the U.K., the Biden administration announced that the U.S. was imposing sanctions against Russia-linked technology firms, and additionally, expelling 10 Russian diplomats who are allegedly linked to their intelligence arm (SVR), which attempted interference in the presidential elections and for conducting cyberattacks against federal agencies.

The U.S. Department of Treasury said,

Today, we took multiple sanctions actions under a new Executive Order (E.O.) targeting aggressive and harmful activities by the Government of the Russian Federation. Treasury’s actions include the implementation of new prohibitions on certain dealings in Russian sovereign debt, as well as targeted sanctions on technology companies that support the Russian Intelligence Services’ efforts to carry out malicious cyber activities against the U.S.

As per the notifications, the six technology companies that have been apprehended by the U.S. government for providing support to Russian Intelligence Services’ cyber operations include:

  • ERA Technopolis
  • Pasit, AO (Pasit)
  • Federal State Autonomous Scientific Establishment Scientific Research Institute Specialized Security Computing Devices and Automation (SVA)
  • Neobit, OOO (Neobit)
  • Advanced System Technology, AO (AST)
  • Pozitiv Teknolodzhiz, AO (Positive Technologies)

On the other hand, the U.K.’s Foreign, Commonwealth, and Development Office (FCDO) has decided to tighten the grip on Russia by summoning the Russian ambassador to the U.K. to probe the SolarWinds cyberattack and the subsequent malicious activities. FCDO Permanent Under-Secretary Sir Philip Barton made clear that the U.K. supports the actions announced by President Biden in response to Russia’s recent activity. He added that the “Government is deeply concerned about a pattern of malign behavior by the Russian State,” and that Russia needs to cease its provocations and de-escalate the brewing tensions at the earliest.

Related News:

Decoding the SolarWinds Hack

Microsoft and FireEye Create a “Killswitch” for Sunburst Malware Affecting SolarWinds’ Orion

Saint Bot – A New Malware Downloader Spotted

BazaCall BazaLoader

Security experts from Malwarebytes discovered a new malware strain used in phishing attacks to install credential stealers and additional malware payloads. Tracked as Saint Bot, the malware poses a wide variety of sophisticated techniques across the infection stages, including anti-analysis tactics, process injection, and command and control infrastructure and communication.

Discovery of Saint Bot Malware

Malwarebytes researchers stated that they found a phishing email in late March 2021, with a ZIP file attachment that contained a PowerShell script disguised as a link to a Bitcoin wallet. The researchers further found that the obfuscated PowerShell downloader initiates the infection process by deploying Saint Bot malware, which was used in various COVID-19 themed phishing campaigns against government and private enterprises globally.

Saint Bot Capabilities

Saint Bot has additional capabilities such as malware stealers including Taurus and AutoIt. “Its design allows to utilize it for distributing any kind of malware. Although currently, it does not appear to be widespread, there is an indication that it is being actively developed. Furthermore, Saint Bot employs a wide variety of techniques which, although not novel, indicate some level of sophistication considering its relatively new appearance,” Malwarebytes said.

How does Saint Bot spread?

Saint Bot is mostly distributed in a malicious ZIP file attachment  bitcoin.zip, luring the victim to get to a Bitcoin wallet. Once the victim opens the file, it provides a pair of files: a .lnk file that leads to a Bitcoin wallet and a .txt file that claims to be a password to the wallet.

Once opened, the .lnk file redirects the user to C:\Windows\System32\cmd.exe, which contains a malicious PowerShell script that downloads the next stage of the malware from the embedded link. Once the malware is implanted successfully, it connects to its Command-and-Control server (C2) and proceeds with its main actions

Delivery Path

Image Courtesy: Malwarebytes

Execution Flow

  • Install itself
  • Inject itself into EhStorAurhn.exe
  • Communicate with the C2 and proceed with the main operations

“Saint Bot is yet another tiny downloader. We suspect it is being sold as a commodity on one of the darknet forums, and not linked with any specific actor. The author seems to have some knowledge of malware design, which is visible by the wide range of techniques used. Yet, all the deployed techniques are well-known and pretty standard, not showing much creativity so far. Will it become the next widespread downloader or disappear from the landscape, pushed away by some other, similar products? We have yet to see,” Malwarebytes added.

Malvertising Mayhem: Here’s Everything You Need to Know

BotenaGo, malware over encrypted connections

Cybercriminals often create innovative malware variants and malicious campaigns to steal users’ identities or private information. In most malware-related attacks, threat actors deploy malware via phishing emails and messages, in which malware is downloaded when a victim clicks/opens a malicious attachment or URL. However, there are certain instances, where users unknowingly invite the malware into their systems through Malvertising.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

What is Malvertising?

Malvertising (malware advertising) is a malicious technique used by cybercriminals to spread malware code or scripts via legitimate-looking ads on websites. In malvertising, malware authors purchase ad space on popular websites to run their malware-infused ads on their web pages. With malicious codes hidden inside these ads, they often redirect the users to fraudulent websites or install malware on their devices.

Threat actor groups often leverage malvertising tactics to deploy various forms of malware, including Banking Trojans, ransomware, crypto-mining scripts, and information stealing bots. Besides, certain campaigns install malware scripts that execute click-fraud operations in the background.

How does it Affect You?

Several popular brands have inadvertently published malicious ads, leaving their site visitors open to various kinds of malware attacks. Malvertising can bring adverse effects to users when they click/open a malicious ad, which:

  • Executes code that installs malware on the victims’ system.
  • Redirects the victim to fraudulent sites, dragging users to malicious schemes.
  • Reroutes users to a phishing website similar to a popular brand to trick users into entering login credentials.

Beware of the Malvertising Mayhem

Cybersecurity experts continue to observe malvertising attempts from state-sponsored attackers. Even popular brands have fallen victim to malvertising operators, losing their credibility towards users. Recently, security researchers from Proofpoint discovered a new malvertising campaign, dubbed CopperStealer, making the rounds online via fake software sites that targeted popular brands like Facebook, Google, Instagram, Amazon, and Apple. It was found that threat actors behind the CopperStealer malware campaign are leveraging compromised accounts to run malicious ads and deliver additional malware on targeted sources.

How to prevent Malvertising 

While it is difficult for a publisher to find out malicious ads on their website, certain security measures can help defend against malvertising campaigns. These include:

  • Use antivirus software and update it regularly
  • Stay wary of Clickbait ads
  • Do not click on suspicious ads
  • Deploy Ad blockers
  • Clear cache and cookies
  • Update browsers and plugins regularly
  • Say no to the “Save Password” feature on browsers
  • Whenever you see a suspicious ad, report it to the site holder

A legitimate browser or website doesn’t guarantee your online security. Adversaries everywhere are looking for loopholes to target unwitting users. It is our responsibility to raise security awareness that helps us in defending evolving threats.

About the Author

 

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

Read More from the author.

What is DDoS and How Can I Better Defend My Business Against this Threat?

DDoS Attacks

DDoS attacks are attempts to flood your network resources and disrupt the normal flow of traffic. Think of it as a sudden traffic jam that prevents you from reaching your destination quickly. This means regular visitors can’t visit your website.

SPONSORED CONTENT

By Ho Chin Chow, Deputy Director, Product Management, SPTel

The methodology and complexity of DDoS attacks can differ.

Unfortunately, it’s not difficult for anyone to instigate a DDoS attack. On the dark web, a DDoS attack can go for as low as a few hundreds of dollars for a 24-hour attack.

It’s also not easy to trace the perpetrator behind a DDoS attack. DDoS makes use of computer systems that have been infected by malware to launch attacks. This can include computers and Internet of Things (IoT) devices. Since these are legitimate devices that have been infected, it can be difficult to differentiate normal traffic from traffic sent from compromised devices.

Read on to learn more about DDoS attacks, their impact to businesses and how you can better defend against such threats.


About the Author

Ho Chin Chow is the Deputy Director of Product Management in SPTel and Product Owner of SPTel’s product portfolio consisting of Connectivity, Internet, SDWAN, IoT-aaS, Managed Network & Security. He is engaged in thought leadership within SPTel and leads the product track in its digitalization project. He is an accomplished product management professional with 18 years of telecommunications experience. His product knowledge spans both local and regional spheres.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.