Home Blog Page 97

The Future is Now – Threats are for Real

Power and Utility

The power/electrical sector is crucial because it enables all critical infrastructure for the smooth functioning of a society. Given its significance, it is also on the radar of several cybercrime groups. The effects of cyberattacks on electrical infrastructure are far-reaching and impact public safety and national and economic security. Research from security firm Recorded Future recently found a China-linked threat actors group dubbed RedEcho, targeting 12 Indian organizations, 10 of which are in the power sector.

Here’s what Dick Wilkinson, Chief Technology Officer, New Mexico Judicial Information Division, has to say about cyberattacks on power companies:

Dick Wilkinson“The threat of major public systems like electricity and water being attacked by nefarious cyber actors has been a popular science fiction theme for the past 30 years. This kind of threat is no longer a fantasy and is happening today, meaning the future is now.

The ability to launch attacks against electrical systems has existed for quite some time. The political interest or risk to launch these attacks was a bigger restraint than the technical ability of most countries or hacking groups. Critical infrastructure was also much more focused on analog controls and the systems were not as fully infiltrated by connected tech devices until the past decade. These two factors, politics and connectivity, have both moved in opposite directions over the past decade. As hacking news becomes commonplace and even very big attacks become part of the daily news cycle, threat actors are emboldened to cross lines they would not have in the recent past. The networks at risk have become more connected by several orders of magnitude and the attacks have become easier to launch, meaning proliferation to even more actors, not just large nation states. The intersection of these two trends brings us to the threat environment of today. We are in the infancy of this trend of attacks on infrastructure and the international political community will need to act very quickly to create sound legal frameworks to control this dark world of cybercrime as well as legitimate cyber military activity.”


Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Cybercrime Group Lazarus Upgrades its Arsenal with Vyveva Malware

Rootkits, Mobile Malware in Asia

Cybersecurity researchers from ESET have discovered a new backdoor malware deployed by the scandalous Lazarus hacking group to target freight and logistic organizations in South Africa. Dubbed Vyveva, the malware is capable of performing certain backdoor functionalities like exfiltrating files, harvesting information from an infected system, and running arbitrary code by remotely connecting to a command-and-control (C2) server. The malware also leverages fake TLS connections for network communication to connect to its C2 via the Tor network. While Vyveva was first spotted in June 2020, the researchers stated that the malware could have been active since 2018.

The Lazarus Link

Lazarus is a North Korea-based hacking group active since 2014 and accused of several cybercriminal acts. It has often targeted global companies with new malware strains such as AppleJeus, Fileless, ThreatNeedle, and MATA.

ESET researchers stated that the new Vyveva malware has similarities to Lazarus’s NukeSped malware. Besides, malware functionalities like using fake TLS in network communication, command-line execution chains, and the way of using encryption and Tor services are similar to Lazarus operations.

“Our telemetry data suggests targeted deployment as we found only two victim machines, both of which are servers owned by a freight logistics company located in South Africa. The backdoor features capabilities for file exfiltration, timestomping, gathering information about the victim computer and its drives, and other common backdoor functionality such as running arbitrary code specified by the malware’s operators. This indicates that the intent of the operation is most likely espionage,” security researcher Filip Jurčacko said.

Vyveva’s Components

So far, the researchers found three components of Vyveva malware –  Installer, Loader, and Backdoor.

Image source: ESET

Among its various capabilities, the Vyveva backdoor allows attackers to alter any file’s date using metadata from other files on the system or by setting a random date between the years 2000 to 2004.

Besides, Vyveva uses the Tor library based on the official Tor source code to communicate with a C&C server at three-minute intervals. The Tor library transfers information about the victim system and its drives before receiving commands. And the backdoor function exports the directory contains – TorSocket.dll with self-explanatory exports close_ch, connect_ch, open_ch, read_ch, write_ch.

“Vyveva constitutes yet another addition to Lazarus’s extensive malware arsenal. Attacking a company in South Africa also illustrates the broad geographical targeting of this APT group,” Jurčacko added.

Lazarus’ Recent Threat Activity

A recent joint advisory from the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and the U.S. Department of Treasury (DoT) revealed that the Lazarus hacking group is using different kinds of AppleJeus malware to target cryptocurrency exchanges and crypto-wallets. The agencies stated the Group developed seven fake cryptocurrency trading applications Celas Trade ProJMT TradingUnion CryptoKupay WalletCoinGoTradeDorusio, and Ants2Whale to steal cryptocurrency. Read More

Stay Ahead of Cyberattacks with Virtual Cybersecurity

firewall

Digital technologies have become akin to lifelines to many companies, with the initial onset of the pandemic crippling many aspects of business activities and operations. In fact, 73% of Singapore businesses have ramped up digitalization efforts amid COVID-19, according to a study on innovation by Microsoft and IDC Asia Pacific — as both a measure to remain resilient and a timely opportunity to innovate.

SPONSORED CONTENT

By Ho Chin Chow, Deputy Director, Product Management, SPTel

With more business activities and operations taking place digitally, cybersecurity has become natural, perhaps even urgent, consideration as companies become more vulnerable to cyber threats and attacks. A separate study commissioned by Cisco found that about 60% of organizations based locally have experienced at least a 25% increase in cyber threats since the pandemic started. In this report by Fortinet, they found that attackers were using the pandemic to hide malicious activities behind seemingly innocuous COVID-19 lures, which shows the sophistication of newer attacks that play to users’ fears and concerns. Vulnerable devices on home networks were also found to significantly expand the attack surface for organizations with increased remote working.

With cyber threats constantly evolving and becoming more sophisticated, chief information security officers (CISOs) and cybersecurity teams need to be able to react swiftly to protect their institutions against cyber threats while maintaining business continuity. Companies can ill-afford issues like data breaches, network outages, and malicious attacks compromising data integrity, that will impact their bottom line, reputation, and their customers.

Securing IT networks with on-premise solutions is no longer sufficient, with cloud-based security touted as the future for efficient cybersecurity management, CIOs and CTOs are left wondering – What are my virtual security options? Read on to find out!


About the Author

Ho Chin Chow is the Deputy Director of Product Management in SPTel and Product Owner of SPTel’s product portfolio consisting of Connectivity, Internet, SDWAN, IoT-aaS, Managed Network & Security. He is engaged in thought leadership within SPTel and leads the product track in its digitalization project. He is an accomplished product management professional with 18 years of telecommunications experience. His product knowledge spans both local and regional spheres.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Most Phishing Emails Originate from Eastern Europe: Barracuda

“PerSwaysion” Phishing Campaign Targets High-Ranked Professionals Across The Globe, IKEA email reply-chain attack

Phishing attacks remain a severe threat to small and large organizations globally. It is the most common and popular technique for cybercriminals to pilfer user credentials, commit fraud schemes, and spread malware.

A Juvenile form of attack

Phishing attacks may seem like a low-level cybercrime, but they are well-orchestrated and capable of exploiting a large group of users’ security or an entire organization’s security.    From finding potential targets and creating phishing lures to stealing data, cybercriminals are constantly enhancing their phishing skills. Usually, a common method used by hackers in their phishing emails is encouraging the potential victim to click/open a malicious link or an attachment as matter of urgency.

Who is at fault – humans or technology?

Despite constant security awareness sessions, employees still fall victim to phishing emails. This is because hackers use sophisticated social engineering techniques to trick victims into doing the required task. Humans are the weakest link in any security chain. A single negligent or careless act of an employee can put the entire company’s network into the hands of cybercriminals.

The Phishing Geography A joint analysis from Barracuda and Columbia University found that the majority of phishing emails originate from countries in Eastern Europe, Central America, the Middle East, and Africa. The researchers examined more than two billion emails, including 218,000 phishing emails, sent in January 2020, to find out the geolocation and network infrastructure of the phishing emails.

Countries with a high volume of phishing emails:  

  • Lithuania
  • Latvia
  • Serbia
  • Ukraine
  • Russia
  • Bahamas
  • Puerto Rico
  • Colombia
  • Iran
  • Palestine
  • Kazakhstan

 Things to Remember

  • Countries that have a higher probability of phishing are located in parts of Eastern Europe, Central America, the Middle East, and Africa.
  • Phishing emails are more likely to have routes that traverse multiple countries.
  • Many of the networks that attackers use to send their attacks from are surprisingly large, legitimate cloud providers.

“The networks with the very highest number of phishing attacks are surprisingly owned by large cloud providers. This is expected, as they also have the highest total volume of emails sent. For such networks, the probability of any given email being a phishing email is very low. Most of the attacks originating from these networks are likely coming from compromised email accounts or servers, which the attackers were able to obtain the credentials for,” Barracuda said.

Prevention is better than detection

Organizations mostly train employees on detecting various phishing emails by looking for errors, malicious links, or attachments. Alternatively, organizations can also consider a permanent solution like deploying artificial intelligence or machine learning-based tools to analyze the company’s communication patterns and identify any anomalies that may lead to potentials threats.


Related Stories:

Improving Risk Posture with Automation and AI Monitoring

IT security, cybersecurity, privacy, and data management are ranked as top challenges for the board of directors, corporates, oversight authorities, and IT audit functions. The digital transformation has greatly impacted the way businesses track, measure, and analyze risk across domains. To delve deeper into the subject and to gain a better understanding, EC-Council and CISO MAG recently organized a webinar titled, “Improving Risk Posture with Automation and AI Monitoring” where Christoper Smith, GRC Consultant for OneTrust GRC, reviewed some key areas where organizations can leverage AI to inform decisions and implement automation to integrate into first-line business applications to engage stakeholders and enhance compliance and board reporting. ​The webinar was attended by cybersecurity experts from more than 30 countries.

Smith kickstarted the webinar by discussing the ever-evolving cyber risk landscape and how there are several opportunities for businesses to tackle these threat vectors. Talking about the risk management drivers, he stressed having a pro-active risk management approach while defining risk as business outcomes and how it is imperative to gain real-time insights. He also stressed operational resilience and the need for integrating continuity plans.

He continued the discussion by shedding some light on the increased attack surface and the importance of cybersecurity and data privacy, with three focus areas: data processing, the emerging risk from vectors like shadow IT and fourth party, and digital transformation and adoption of new technology. “When it comes to threat actors, they do not have a downtime. Cybercriminals are ever-evolving with their strategy to launch cyberattacks,” he opined.

Smith also assessed the need to evaluate fourth-party risks. These included indirect data exchange with your vendor’s vendors, tracking third-party systems, and approving specialized tools for shadow IT and fourth-party risks in the line of business.

He pointed out that when data processing occurs at third-party vendor systems, it is important to ask yourself these questions:

  • Who owns SaaS data?
  • Where is the data located?
  • How resilient are the services?
  • Can you confirm that processes are upheld?

Smith further discussed aligning business objectives for improving the risk posture. According to him, a holistic outlook is needed to approach the emerging risks, and these begin by applying best practices. These include:

  • Selecting a baseline: Selecting compliance framework to model and measure program performance
  • Building Risk Methodology: Identifying score, stakeholders, and risk scoring and management processes
  • Harmonizing Objectives: Aligning resources with everyone working toward the same risk mitigation goal, based on their unique risk motivators
  • Data Ready: Know what you want to use and why you want to use it- ensure repeatable quality can be obtained and maintained

He stated that risk mitigation and AI today include robotic process automation, machine learning, predictive analysis, and intelligent risk automation, and hence it is critical to invest in artificial intelligence.  As AI and ML analyzes cybersecurity from a holistic perspective, it can be leveraged to improve the cybersecurity posture of businesses.

Following the webinar, Smith engaged in a Q&A session with the audience.

About CISO MAG

CISO MAG – a thought-leadership publication from EC-Council – provides vital stories, trends, interviews, and news from around the security world to help security leaders stay informed. The magazine includes comprehensive analysis, cutting-edge features, and contributions from thought leaders.

About EC-Council

EC-Council, officially incorporated as the International Council of E-Commerce Consultants, was formed to create information security training and certification programs to help the very community our connected economy would rely on to save them from a devastating Cyberattack. EC-Council rapidly gained the support of top researchers and subject matter experts around the world and launched its first Information Security Program, the Certified Ethical Hacker. With this ever-growing team of subject matter experts and InfoSec researchers, EC-Council continued to build various standards, certifications, and training programs in the electronic commerce and information security space, becoming the largest cybersecurity certification body in the world. Learn more at https://www.eccouncil.org.

Top Irish Colleges Face the Ire of Ransomware Attacks

University

Ransomware attackers going after educational institutions is not new. Recently, the FBI’s Cyber Division issued an alert warning about an uptick in cyberattacks against higher education institutions and K-12 schools, delivering the PYSA ransomware. However, the ransomware epidemic now seems to have crossed the continents and rocked one of Europe’s most sought-after educational hub – Ireland. Two of Ireland’s top colleges – the National College of Ireland (NCI) and the Technological University Dublin (TU Dublin) ­ – have reportedly been hit by ransomware attacks.

Attack on National College of Ireland

The National College of Ireland first announced the disruption of its IT services on April 3, 2021.  As per the “Outage” update, NCI informed its students and faculty that the disruption had affected multiple college systems including Moodle, their Library service, and the MyDetails service which is provided specifically for the current academic year’s college students. The NCI, though, displayed a proactive and transparent approach by further adding,

Our IT teams and external service providers are currently working to rectify these issues. However, at present, we do not have a timeframe for IT services to resume.

Additionally, the authorities promised to keep everyone in the loop by giving timely and regular updates, and they did! On April 6, 2021, the NCI released an update confirming that it was indeed a ransomware attack that “resulted in the college suspending access to all NCI IT systems.”

TU Dublin’s Tallaght Campus Also Falls Prey

The Tallaght campus of TU Dublin was the other major educational institution that reported a cyber incident during the same timeframe. The university website read that “some” ICT systems have been disrupted and the investigation is ongoing.

ransomware attack on Irish colleges
Technological University Dublin’s Site-Wide Notice

Like the NCI, TU Dublin also assured regular updates about its ongoing investigation but via email. In the update email, which was sent to the students and further obtained by DataBreaches.net, the authorities confirmed that the TU Dublin’s Tallaght campus had been “subjected to a significant ransomware attack,” on April 1, 2021, which affected its entire on-site ICT systems.

While investigating the aftermath of the ransomware attack, the authorities observed that access to the main ICT systems and on-campus backups was cut out. However, it was encouraging to know that TU Dublin’s cloud services of the main ICT systems remained operational and available including Moodle, email, and MS TEAMS.

Both, the NCI and TU Dublin, have informed the relevant statutory authorities, including the Office of the Data Protection Commissioner and An Garda Síochána  (the national police service of the Republic of Ireland), as per Irish regulatory protocols. Additionally, as a precautionary measure, the college authorities have requested its students and faculty to avoid using any ICT systems as the damages and number of devices infected are still being investigated.

Watch Out Ireland!

As per PWC’s “Irish Economic Crime Survey 2020,” Ireland is now Europe’s largest data hosting cluster. However, it was found that 51% of firms in Ireland have experienced an economic crime and another 69% experienced cybercrime in the last 24 months, which is more than twice what companies experienced worldwide (34%). These alarming numbers demand an elevated level of focus on the need for putting data protection systems in place.

Related News:

PYSA Ransomware Targets Education Institutions: FBI

Maastricht University Ransomware Attack: All Systems Blacked-Out

Cring Ransomware Targets Unpatched Vulnerabilities in Fortinet VPNs

Security experts from Kaspersky identified a new strain of ransomware exploiting unpatched vulnerabilities in Fortinet VPN devices. Dubbed as Cring, the ransomware is targeting industrial sector entities to compromise and encrypt their network systems. Kaspersky stated that the operators behind the Cring ransomware performed a series of attacks on industries in European countries in Q1 2021. Attackers temporally disrupted their operations by encrypting critical systems in demand for ransom.

Cring ransomware, also known as Ghost, Crypt3r, Vjiszy1lo, Phantom, was initially discovered by Amigo_A in January 2021, and reported by the CSIRT team of Swiss telecommunications provider Swisscom.

How Cring Ransomware Spreads 

The attackers exploited the CVE-2018-13379 vulnerability in the Fortinet VPN to gain access to the corporate network and extract the session file of the VPN Gateway, which contained sensitive information such as usernames and passwords in plaintext.

After gaining access to the first system, the Cring operators download the Mimikatz utility to that system, which is then used to steal the account credentials of Windows users who had logged into the affected system earlier. Leveraging the Mimikatz utility, the attackers compromise the domain administrator account to deploy ransomware payloads on other systems on the company’s network by using the Cobalt Strike framework.

“Sorry, your network is encrypted, and most files are encrypted using special technology. The file cannot be recovered by any security company. If you do not believe that you can even consult a security company, your answer will be that you need to pay the corresponding fees, but we have a good reputation. After receiving the corresponding fee, we will immediately send the decryption program and KEY. You can contact us to get two file decryption services, and then you will get all decryption services after paying our fee, usually, the cost is about 2 bitcoins,” Cring operators ransom note read.

Key Findings

  • The Cringe operators identified the vulnerable device themselves by scanning IP addresses.
  • The operators may have bought a ready-made list containing IP addresses of vulnerable Fortigate VPN Gateway devices.
  • Several days before the initiation of the main attack phase, the attackers performed test connections to the VPN Gateway, apparently to check that the vulnerable version of the software was used on the device.
  • In autumn 2020, an offer to buy a database of such devices appeared on a dark web forum.

 Indicators of compromise (IOC)

File path

  • %temp%\execute.bat (downloader script)
  • C:__output (Cring executable)

MD5

  • c5d712f82d5d37bb284acd4468ab3533 (Cring executable)
  • 317098d8e21fa4e52c1162fb24ba10ae (Cring executable)
  • 44d5c28b36807c69104969f5fed6f63f (downloader script)

IP addresses

  • 227.156[.]216 (used by the threat actor during the attack)
  • 227.156[.]214 (used by the threat actor during the attack)
  • 12.112[.]204 (Cobalt Strike CnC)
  • 67.231[.]128 (malware hosting)

APT Group Targets Fortinet products

In a related news, federal agencies recently warned about the Advanced Persistent Threat (APT) actors targeting unpatched vulnerabilities in Fortinet FortiOS. In a joint advisory, the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) revealed that threat actors are scanning devices on ports 4443, 8443, and 10443 to exploit unpatched vulnerabilities – CVE-2018-13379, CVE-2020-12812, and CVE-2019-5591.

Reportedly, the APT actors are trying to break into multiple governments, commercial, and technology services networks to launch various cyberattacks like Distributed Denial-of-service (DDoS) attacks, ransomware, SQL injection attacks, spear-phishing campaigns, website defacements, and disinformation campaigns.

Protective Measures

The FBI and CISA also recommended certain security measures. These include:

  • Immediately patch CVE-2018-13379, CVE-2020-12812, and CVE-2019-5591.
  • If FortiOS is not used by your organization, add key artifact files used by FortiOS to your organization’s execution deny list. Any attempts to install or run this program and its associated files should be prevented.
  • Regularly back up data, air gap, and password-protect backup copies offline. Ensure copies of critical data are not accessible for modification or deletion from the primary system where the data resides.
  • Implement a recovery plan to restore sensitive or proprietary data from a physically separate, segmented, secure location (e.g., hard drive, storage device, the cloud). • Install updates/patch operating systems, software, and firmware as soon as updates/patches are released.
  • Disable unused remote access/Remote Desktop Protocol (RDP) ports and monitor remote access/RDP logs.
  • Focus on awareness and training. Provide users with training on information security principles and techniques, particularly on recognizing and avoiding phishing emails.

“The APT actors may be using any or all of these CVEs to gain access to networks across multiple critical infrastructure sectors to gain access to key networks as pre-positioning for follow-on data exfiltration or data encryption attacks. APT actors may use other CVEs or common exploitation techniques to gain access to critical infrastructure networks to pre-position for follow-on attacks,” the advisory added.

How to Remove Single Points of Failure from your Digital Infrastructure

User Verification Policy, zero trust approach

On 24th August, 79AD, the eruption of Mount Vesuvius caught the 20,000 local residents of Pompeii off guard, burying the magnificent Roman trading town for the next 1520 years. Walking through the archaeological site today, we can’t help but feel the distress of the people whose petrified casts we see, frozen in the moment of horror when the city was destroyed. Yet there is something curious too about the scenes.

By Julia O’Toole, Founder and CEO of MyCena Security Solutions

We now know there were clear signs of the impending eruption: an earthquake in 59AD, ground raising up, underground springs drying up, and animals acting strangely. Yet right up to the fatal eruption, the city was bustling with activity. In the final years of Pompeii, the rich had kept pouring their savings into a building and decorating their villas and gardens, enriching them with beautiful fountains and baths that were connected to a state-of-the-art city water heating and distribution system, all as if nothing had happened. But why did people keep building on an obviously active volcano? Was it a race for social status? The certainty that the gods would protect the city? Collective blindness?

Why cybersecurity feels like Pompeii

In the last few months, we have witnessed a couple of big eruptions in cybersecurity. From the SolarWinds hack to the Microsoft Exchange Servers vulnerabilities exploitation, we discovered how one intern’s password led to a massive operation of cyber-espionage, how a remote access password almost led to the water poisoning of a 20,000 people town, how unpatched vulnerabilities at one software supplier led, in a matter of days, to a massive and indiscriminate supply-chain attack on hundreds of thousands of customers.

The terrifying part of the story isn’t the breaches themselves. No system is unbreachable, as hackers go around firewalls, antivirus, IDS, IPS, WAF, DLP, MFA … and look for an easy door to open. What’s terrifying is that after they set foot inside a network, hackers can go unnoticed for very long periods of time yet launch rapid attacks from the inside of critical services, Fortune 500 companies, cybersecurity leaders, federal agencies… not just once, but time and time again.

Those eruptions are the emerging signs of a more profound problem at the heart of our digital infrastructure: the over-bearing presence of single points of failure, all from which a domino effect can start and wipe out entire sections of our networks. Yet as supply-chain integration increases, the number and impact of single points of failure grow exponentially too, to the point some fear “the” single eruption that can wipe out everything that was built before.

If cyber-resilience is the aim, segmentation is the game

After the recent attacks, the consensus is we need to build back better. But to build back stronger will require more than shuffling a few policies and technologies at the fringe. It requires building cyber-resilience from the core. For that, we need to go back to the drawing board and remove single points of failure from our digital infrastructure so that single wipe-out events can never happen again.

Thankfully, going back to the drawing board doesn’t require reinventing the wheel. Cybersecurity can take a leaf out of the best practices in buildings security. For example, to prevent a fire started in one room from spreading and burning the rest of the building, many countries have fire door regulations in place. To prevent a breach in one system from spreading and infecting the rest of the digital infrastructure, we could have systems segmentation regulations, which would require the segmentation of networks into smaller clusters, separate strong unique access for each cluster, and credentials decentralization to remove single points of access (and failure).

If that all seems logical, the question remains – how to segment and control each access individually when people can’t remember dozens of strong passwords like 7%uet£%Er@fhRAw4853?

Rediscovering Christopher Alexander and the system-thinking human-centred approach

There is a classic trap in mathematics. You start solving one piece of a complex equation and by the time you get so deep into your calculations, you forget which equation you were trying to solve in the first place. This happened with passwords. People were so focused on solving one problem – people forgetting passwords – that they lost sight of the stakes and the main goal, which is segmentation.

To avoid this trap, let’s turn to one of the most influential thinkers on complex networks: British-American architect and design theorist Christopher Alexander. As an introduction, Alexander is regarded as the father of the pattern language movement. Trained in mathematics, biology, physics, cognition, computer science, and architecture, his work has influenced programming language design, modular programming, object-oriented programming, software engineering, agile software development, and other design methodologies. Throughout the 1960s and 1970s, his seminal book “Notes on the Synthesis of Form” was considered required reading for researchers in computer science.

Central to Alexander’s work is the concern for “design wholeness”, which I call a system-thinking human-centred approach. For a design to solve a complex problem, all the conditions critical to the solution have to be satisfied individually, simultaneously and be easy to use by humans. In our cyber-resilience challenge, this would mean segment systems, control each system access individually and independently, decentralize access keys so they don’t all sit in the same basket, protect access keys so that only the rightful owner can access and use them, and make the whole system simple to use so that people can quickly access any system whenever they need, all at the same time. This challenge is like solving complex mathematical equations, except the solution has to come in a design form. Below is what a good solution to our cyber-resilience challenge would look like. The positive (+) inferences between two conditions mean they co-exist. For example, satisfying the condition “protect keys” does not cancel out the condition “segment systems”, and vice-versa.

Three situations encountered in companies today

Now let’s compare this challenge with three situations often encountered in companies today:

Situation 1:

The company lets employees create their own passwords to access company assets and systems… Since people can’t remember their passwords, they use simple passwords like 123456, or recycled patterns with endings like 123, 123., 123!, 123?. Therefore, there is no segmentation of systems as all passwords are easy to crack using common credentials attacks like credentials stuffing, social engineering, brute force, password spraying, dictionary attacks… As soon as a hacker gets hold of one password, they can quickly find the others and move laterally through the network. Therefore, handing over credentials security and management to employees does not satisfy any of the conditions and is not a solution to the cyber-resilience challenge.

Situation 2:

The company creates strong passwords for each system but then puts them behind a single point of access (Single Sign On, passwords managers, identity, excel spreadsheet, notebook, post-its, browser…) which contradicts “segment systems” and “control each access”, meaning this is not a solution to the cyber-resilience challenge.

Situation 3:

The company uses MFA and a zero-trust approach. This is the same configuration as situation 2, but with extra verification. MFA provides extra verification on the perimeter of the system. But if the hacker intercepts tokens (e.g. SIM swap) to get inside the network, they can access everything at once. A zero-trust approach provides extra layers of verification inside the network. But if the hacker steals your identity (e.g. deepfakes) they can pass every security check and access everything. Since neither satisfies the condition “decentralize keys”, neither is a solution to the cyber-resilience challenge.

How to solve complex design problems using the mathematical scarcity of good sequences

As with complex mathematical problems, people can spend years looking for solutions without finding them. It took almost 100 years and many failed attempts by generations of mathematicians before Grigori Perelman solved the Poincaré conjecture in 2003.

Thankfully, Alexander offers us a pragmatic approach to find good design solutions. In his seminal 4-tome book series which took him and his team 30 years to write and publish, ‘The Nature of Order, Volume 2 The Process of Creating Life, The Sequence of Unfolding §7’, he calls it “the Mathematical Scarcity of Good Sequences”. To solve complex design problems you can, through tests and trials, identify and eliminate from the trillions of possible sequences, those including previously found bad subsequences, which narrows down the range of potential good sequences. The main quality of good sequences is their stability: once a good sequence, always a good sequence. They are unambiguously and timelessly backtrack-free, which means there will never in the future be a need to backtrack and undo the process. If backtracking is necessary, it means the sequence was bad in the first place and should have been discarded.

This experimental approach is actually how people have designed and built houses, towns, and cities throughout centuries, each generation of builders standing on the shoulders of previous generations, incrementally solving new design problems and creating new patterns. However, this slow development of form has been compromised in recent decades by the rapid increase in the quantity, complexity, and difficulty of new problems. With no one to turn to for help, individual builders have had to solve contemporary design problems which lie beyond a single individual’s grasp.

Borrowing patterns from nature and the past

If there is no one to turn to, then where should one look for answers or inspiration? Nature is a good place to start, as it abounds with good sequences everyone can see and use. Another place to look for and identify good patterns is in the past. Interestingly, once you engage in the process of identifying good sequences for complex design problems, it becomes second nature. That’s why inventors often unexpectedly trip over the missing piece of the puzzle they have long been looking for.

I had been looking for over 20 years (thankfully not 100) to solve my own password problems using mathematics, neuroscience, and technology, when I tripped over the missing piece during a visit to the 3000-year-old ancient Greek city of Mycenae. To enter the city, you had to pass through a first gate called the Lion’s Gate; once inside the city, you had to pass a second gate to get to the garrison, and once inside the garrison’s quarter, you had to pass the third gate to get to the king’s palace.

Suddenly the penny dropped: a password is a key. No one ever cuts or remembers how to cut a key before they open a door. People just pick the right key and use it. By using a method of access for structured stored data, we could ensure only the rightful owner could access their own keys. A good sequence to the cyber-resilience design challenge could therefore include a local private digital credentials fortress which only the owner can access to find their keys, after passing multiple layers of security like in the ancient city, as shown below. This sequence satisfies the condition “protect keys” and, at the same time, satisfies the conditions “segment systems,” “control access” and decentralize keys.”

The illustration below shows an absence of a master key, central repository, or single points of failure in the model. You can keep as many keys as there are segmented systems. Each system key is strong, unique, and totally independent from the others. You can segregate and keep the most sensitive keys in the deepest and most secure levels. All keys are decentralized, locally encrypted, and only accessible by the owner.

There is one last condition to satisfy in order to solve the cyber-resilience design challenge: it has to be simple to use. Here again, we used an iterative à la Alexander process and spent a few years working with our clients to find and develop the shortest path for the brain in daily situations. That includes no more passwords to create, remember, type, or see; working for all systems (IT, OT, IoT, ICS, legacy…), minimizing frictions on deployment, user enrolment, credentials distribution, daily management, setting roles and permissions, usage monitoring… Having satisfied the last condition, our system diagram now looks like this, satisfying all of the critical conditions for cyber-resilience.

Conclusion

Remember the moral of Aesop’s fable of the hare and the tortoise: “Slow and steady wins the race”. We believe that in the mad rush to take everything digital, it pays to step back and rethink cybersecurity with a more long-term, system-thinking human-centred approach.

There will be more and bigger eruptions in the months to come. As we witness hackers taking over networks by becoming super-admins time and again, the cost of not removing single points of failure (master key, SSO, centralized and privileged access, identity, super-admin accounts…) from your digital infrastructure could be fatal. To be cyber-resilient and reduce the risks of lateral movement, identity theft, ransomware attacks, supply-chain attacks… segmentation is key! The other advantage of moving away from the reach of single wipe-out events is that you can sleep without fearing “the next Pompeii.”

WRITE FOR CISO MAG

Do you want to write for CISO MAG? Please read our guidelines here.


About the Author

Julia O’Toole is a French inventor and entrepreneur. She is the founder and CEO of MyCena Security Solutions. Using maths, neuroscience, and technology, Julia and her team research and design innovative and easy-to-use solutions to complex problems. She uses revolutionary ways to solve the biggest problem in cybersecurity: passwords.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Telegram Bots and Google Forms: The New Phishing Tools of Cybercriminals

phishing, Telegram bots and Google Forms used for phishing

In January 2021, the phone numbers of Facebook’s 533 million users went on sale on the online messaging platform, Telegram. Cybercriminals are known to leverage popular messaging platforms to sell the data exfiltrated during their malicious campaigns. However, to everyone’s surprise, they used a Telegram bot to make the sale. The bot was trained to charge a minimal fee of $20 per search. However, a new report from cybersecurity firm Group-IB has now revealed that growing usage of Telegram bots and Google Forms has been observed in phishing toolkits to automate their malicious phishing campaigns.

Group-IB’s CERT closely analyzed the tools used to create the phishing toolkits. They discovered that, in 2020, most of the toolkits were used to imitate online services that included online tools to view documents, online shopping, streaming services, etc. (30.7%), email clients (22.8%), and financial organizations (20.33%). In addition to this, their analysis of last year also identified phishing kits targeting over 260 unique brands, with Microsoft, PayPal, Google, and Yahoo leading the list of most exploited brands.

Telegram bots and Google Forms
Image Credit: Group-iB

But what is a phishing toolkit?

A phishing toolkit is a set of tools that helps create and operate phishing web pages mimicking a specific brand or company or even several at once. Phishing toolkits are usually sold on underground forums to cybercriminals who lack strong coding skills. These phishing kits help them to effortlessly build an infrastructure for large-scale phishing campaigns. By extracting phishing toolkits, cybersecurity analysts can dissect the mechanism behind the phishing attack and figure out where the exfiltrated data is sent. In addition, a thorough examination of phishing toolkits can help forensic analysts detect digital traces that might lead to their developers.

The functionality of phishing kits is not just limited to generating fake websites or pages to steal user data. Some drop malicious payloads on the victim’s system. Sellers of the phishing toolkits sometimes use this technique to deceive their buyers and attempt to mint money twice. By using a special script embedded in the text body of the phishing kit, they can direct the stolen data to their network hosts or also intercept access to their customers’ hosting service.

Stolen Data Collection Methodology

For collecting the data, cybercriminals mainly use free email services to which all the information harvested on phishing websites is automatically sent. This tactic is so widely used that it accounts for 66% of the total number of emails found in the phishing toolkits. Additionally, the analysis also shows that most email accounts detected were created using Gmail and Yandex mailing services.

The analysts further divided alternative ways for cybercriminals to obtain data into two major categories:

  1. Local: Where the data is stored in a file located on the phishing resource itself.
  2. Remote: Where it is sent to a different server (like a C2 server).

Cybercriminals actively use legitimate services to obtain compromised data. However, a new trend was recorded over the reporting period: successful leveraging of Google Forms.

Not only are Google Forms easy to create, but they also come with the advantage of being hosted under the google.com domain which helps gain potential victims’ trust. Cybersecurity awareness training often teaches users to look out for mistakes or tricks that can betray a scam. However, when the shared URL begins with docs.google.com, it might just be enough to fool people into entering their password and other credentials required in the form.

Yaroslav Kargalev, Deputy Head of CERT-GIB, said,

Phishing kits have changed the rules of the game in this segment of the fight against cybercrime. In the past, cybercriminals stopped their campaigns after the fraudulent resources had been blocked and quickly switched to other brands. Today, they automate their attacks and instantly replace the blocked phishing websites with new web pages. In turn, automating such attacks leads to the spread of more complex social engineering used in large-scale attacks rather than separate incidents, as used to be the case. This keeps one of the oldest cybercriminal professions afloat.

The traditional approach consisting of monitoring and blocking phishing websites is far from enough today. Companies must identify all the elements of the attackers’ infrastructure and block the entire network of fraudulent resources than separate modules. For this, you need to have a Cyber Threat Intelligence (CTI) analyst on board who can analyze phishing and other forms of attacks, and attribute them to a specific cybercriminal group targeting your firm.

However, the employment gap in cybersecurity is currently concerning, with 3.5 million unfilled positions globally. So, if you are interestedin training your employees or gaining hands-on knowledge in the CTI field, check out EC-Council’s Certified Threat Intelligence Analyst (CTIA) course.

Related News:

Phone Numbers of 533 Mn Facebook Users on Sale via Telegram Bot

4 Common Attack Vectors You Need to Know

data breaches, Verizon Data Breach Investigation Report

Online adversaries always advance their hacking techniques to enhance their attack vectors. Cybercriminal groups focus on different kinds of cyberthreats such as data breaches, malware, phishing, or Distributed Denial of Service (DDoS) attacks. According to the 2021 Cyber Security Report, cybercriminal groups have largely exploited the pandemic situations by targeting all business sectors, cybersecurity professionals, and C-Level executives. It was found that, on average, one new organization globally becomes a victim of a ransomware attack every 10 seconds. It might be alarming to find that over 46% of organizations had at least one employee who downloaded a malicious mobile application.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

There might be different attack vectors for hackers, but the goal is only one – target victims’ digital assets.

What is an attack vector?   

An attack vector is any method or path used by an attacker to gain unauthorized access to a victim’s network system, break into users’ devices, or exploit known vulnerabilities. Attack vectors enable cybercriminals to meet their goal of successfully launching cyberattacks.

Categories of an Attack Vector

Usually, the attack vectors leveraged by cybercriminals fall under two categories: Active attacks and Passive attacks.

In an Active attack vector, attackers try to obtain unauthorized access to a network system by disrupting its operations. Exploiting unpatched vulnerabilities, email spoofing, malware, and ransomware attacks come under Active attack vectors.

In a Passive attack vector, attackers aim to gain access to a targeted system without affecting its resources. Spear-phishing, URL hijacking, and other social engineering-based attacks come under Passive attacks.

Common Types of Attack Vectors

Threat actors utilize both active and passive attack vectors to target their victims, with the end goal of exploiting targeted devices or pilfer sensitive information. While there are several attacks vectors that malicious actors leverage, the most common attack vectors include:

1. Brute-Force Attack

A brute force attack is a credentials-cracking technique in which attackers try to guess usernames and passwords to gain unauthorized access to a targeted source by the trial-and-error method. Attackers launch brute-forcing both manually and by using automated tools that leverage a list of password combinations to crack the users’ passwords.

How to Avoid Brute-force Attacks

  • Use strong passwords/passphrases
  • Restrict access to authentication URLs
  • Use CAPTCHA feature for authentication
  • Enable two-factor authentication (2FA)
  • Enable account lockout option, after multiple wrong login attempts

2. Cross-Site Scripting (XSS)

Cross-Site Scripting or XSS attacks involve injecting malicious code into web applications to target the visitors of a particular website. The attackers mostly deploy malicious scripts or code, written in JavaScript, Flash, and HTML, in the website’s content or comment section. In XSS attacks, threat actors aim to steal users’ browser cookies and pilfer sensitive information such as login credentials, financial details, and other private information.

How to prevent XXS attacks

  • Avoid accepting third-party cookies
  • Be wary of user comments on websites
  • Never click/open suspicious URLs

3. Phishing Attacks

A phishing attack is a common cyberthreat in which hackers target a particular user or group of users with malicious URLs and attachments sent via phishing emails. Once a user clicks/opens the malicious URL or attachment in a phishing email, it’ll redirect the user to a fake login page tricking the user into entering login credentials.

At times, attackers also send dangerous malware like Adware, Spyware, Banking Trojans, Ransomware, and cryptocurrency miners which cause a severe impact to users and organizations. Five Phishing Baits to Know

How to prevent being phished

  • Never open/click on suspicious emails
  • Use anti-phishing software to filter phishing emails

4. DDoS Attacks

In Distributed Denial of Service (DDoS) attacks, cybercriminals try to make a targeted system or service unavailable to its users by flooding it with unwanted incoming messages and traffic from different sources.

Attackers mostly launch DDoS attacks on network resources like data centers, servers, and websites of a computer system. DDoS attacks cause disruption of services or even crash of the services.

DDoS Countermeasures

  • Use DDoS-prevention services
  • Enable Content Delivery Network (CDN) solutions

Wrap-up

To prevent various attack vectors cybercriminals leverage, we need to first identify an enterprise’s security loopholes and vulnerabilities. Companies need to device a management solution for BYODs, especially in these testing times of remote working. With complete awareness of different attack vectors and proper security measures in place such as having a spam firewall or web filter, one can stay ahead of cybercriminals and their social engineering techniques.


About the Author

 

Rudra Srinivas is a Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.