Category: Cyber Security

  • Enterprise players face ‘one-two-punch’ extortion in ransomware attacks – Cyber Security

    Enterprise players face ‘one-two-punch’ extortion in ransomware attacks – Cyber Security

    [ad_1]

    BLACK HAT USA: The adoption of double-extortion attacks against companies in ransomware campaigns is a rising trend in the space, researchers warn.

    Ransomware variants are typically programs that aim to prevent users from accessing systems and any data stored on infected devices or networks. After locking victims out, files and drives will often be encrypted — and in some cases, backups, too — in order to extort a payment from the user. 

    Today, well-known ransomware families include WannaCry, Cryptolocker, NotPetya, Gandcrab, and Locky. 

    Ransomware now seems to make the headlines month-on-month. Recently, the cases of Colonial Pipeline and Kaseya highlighted just how disruptive a successful attack can be to a business, as well as its customers — and according to Cisco Talos, it’s likely to only become worse in the future. 

    In 1989, the AIDS Trojan — arguably one of the earliest forms of ransomware — was spread through floppy disks. Now, automated tools are used to brute-forcing internet-facing systems and load ransomware; ransomware is deployed in supply-chain attacks, and cryptocurrencies allow criminals to more easily secure blackmail payments without a reliable paper trail.

    As a global issue and one that law enforcement struggles to grapple with, ransomware operators may be less likely to be apprehended than in more traditional forms of crime — and as big business, these cybercriminals are now going after large companies in the quest for the highest financial gain possible. 

    At Black Hat USA, Edmund Brumaghin, research engineer at Cisco Secure said the so-called trend of “big game hunting” has further evolved the tactics employed by ransomware operators. 

    Now big game hunting has gone “mainstream,” Brumaghin says that cyberattackers are not deploying ransomware immediately on a target system. Instead, such as in the example of typical SamSam attacks, threat actors now, more often, will obtain an initial access point through an endpoint and then move laterally across a network, pivoting to gain access to as many systems as possible. 

    screenshot-2021-07-29-at-12-35-07.pngscreenshot-2021-07-29-at-12-35-07.png

    Cisco Talos

    “Once they had maximized the percentage of the environment that was under their control, then they would deploy the ransomware simultaneously,” Brumaghin commented. “It’s one of those types of attacks where they know that organizations may be forced to pay out because of instead of a single endpoint being infected, now, 70 or 80 percent of server-side infrastructure is being impacted operationally at the same time.” 

    After a victim has lost control of their systems, they are then faced with another problem: the emerging trend of double-extortion. While an attacker is lurking on a network, they may also rifle through files and exfiltrate sensitive, corporate data — including customer or client information and intellectual property — and they will then threaten their victims with its sale or a public leak. 

    “Not only are you saying you only have X amount of time to pay the ransom demand and regain access to your server, if you don’t pay by a certain time, we’re going to start releasing all of this sensitive information on the internet to the general public,” Brumaghin noted.

    This tactic, which the researcher says “adds another level of extortion in ransomware attacks,” has become so popular in recent years that ransomware operators often create ‘leak’ sites, in both the dark and clear web, as portals for data dumps and in order to communicate with victims. 

    According to the researcher, this is a “one-two-punch” method that is made worse now that ransomware groups will also employ Initial Access Brokers (IABs) to cut out some of the legwork required in launching a cyberattack.

    IABs can be found on dark web forums and contacted privately. These traders sell initial access to a compromised system — such as through a VPN vulnerability or stolen credentials — and so attackers can bypass the initial stages of infection if they are willing to pay for access to a target network, saving both time and effort. 

    “It makes a lot of sense from a threat actor’s perspective,” Brumaghin said. “When you consider some of the ransom demands we’re seeing, in a lot of cases, it makes sense to them instead of trying to go through all the effort [..] they can simply rely on initial access brokers to give them access that has already been achieved.”

    Finally, Cisco’s security team has also noted an uptick in ransomware ‘cartels’: groups that sharing information and working together to identify the techniques and tactics that are most likely to result in revenue generation. 

    Brumaghin commented:

    “We’re seeing a ton of new threat actors begin to adopt this business model and we continue to see new ones emerge, so it’s something organizations really need to be aware of.”

    Previous and related coverage


    Have a tip? Get in touch securely via WhatsApp | Signal at +447713 025 499, or over at Keybase: charlie0


    [ad_2]

    Source link

  • RansomEXX ransomware leaks files stolen from Italian luxury brand Zegna – Cyber Security

    RansomEXX ransomware leaks files stolen from Italian luxury brand Zegna – Cyber Security

    [ad_1]

    RansomEXX ransomware operators hit the popular Italian luxury fashion house Ermenegildo Zegna Holding and started leaking stolen files.

    Zegna is one of the most famous Italian luxury fashion houses. It was founded in 1910 by Ermenegildo Zegna in Trivero, Biella Province of the Piedmont region of Northern Italy.

    Ermenegildo Zegna Group is the largest menswear brand in the world by revenue. As of 2018, Ermenegildo Zegna operated 480 retail stores (267 of which company-owned) across the world. Following the company’s strongly export-oriented strategy, exports account for over 90% of total sales.

    The revenge of the company was €1.159 billion as 2018.

    The RansomEXX ransomware group claims to have stolen 20.74GB of data from the company and leaked 43 archives (42 archives of 500MB in size and 1 archive containing 239.54MB of documents).

    Zegna

    The RansomEXX gang has been active since 2018 under the name Defray, in June 2020 the group rebranded as RansomEXX. The RansomEXX ransomware targets both Windows systems and virtual machines running VMware ESXi servers.

    Recently the RansomEXX gang infected the systems at Italy’s Lazio region causing problems for the ongoing COVID19 vaccination campaign. This week the ransomware gang RansomEXX ransomware gang hit the Taiwanese manufacturer and distributor of computer hardware GIGABYTE and claims to have stolen 112GB of data.

    Follow me on Twitter: @securityaffairs and Facebook

    Pierluigi Paganini

    (SecurityAffairs – hacking, Zegna)




    [ad_2]

    Source link

  • Spanish, French and Dutch Languages Added to Security Awareness Training – Cyber Security

    [ad_1]

    A Global Challenge

    The steady stream of cyberattacks seen throughout 2019 turned into a torrent over the last year – ransomware, phishing scams and data breaches are now at an all-time high. Of course, the growing cybersecurity threat isn’t contained to just one country. The effects are being felt the world over.

    The National Cybersecurity Agency of France (ANSSI) is trying to tackle the 255% surge in ransomware attacks reported in 2020. Meanwhile Spain is trying crack down on malicious actors operating inside the country.

    And in an interview with workers in the U.S., Japan, Australia and throughout Europe, 54% say they spend more time working from home now than they did at the beginning of 2020. The blurred lines between home life and work life leads to the use of improperly secured personal devices with ramifications being felt by small, medium and large businesses. But with cyberattacks at an all-time high, 63% of companies have kept their cybersecurity trainings at the same level that it was at the end of 2019.

    Tackling Cyber Threats

    Our networked world connects us to points all over, so it’s no wonder cybersecurity needs to be taken seriously across the globe. The fight against these threats is complicated, but most successful attacks share a common vector – the human factor.

    Because of this shared element, security experts know where to focus their energy. In fact, research shows that Webroot® Security Awareness Training improves cyber resilience and helps defend against cyberattacks.

    Expanded Offerings

    The truly global nature of cyber threats is why Webroot is expanding its language offerings for our Security Awareness Training. This training helps employees keep security top of mind so businesses become more secure.

    Now offered in Dutch, Spanish and French, our Security Awareness Training features native narration throughout. Other available options offer courses with only translated captions overlaid on existing content while our trainings convey important security information in an engaging experience.

    Why Training is Critical

    Often, attackers have a built-in advantage when they zero in on a target – they can practice. They can probe for different ways in and try a variety of tactics, like email attacks or SMS and voice phishing. And they only need to be successful once.

    That’s why training is such a critical part of security. It levels the playing field by letting end users practice what they learn while they discover how to keep themselves and their business safe.

    Further Language Expansion Planned

    Dutch, Spanish and French mark just the beginning of expanded language offerings from Webroot Security Awareness Training. Stay posted to learn about expansions to more languages coming soon.

    Kyle Machado

    About the Author

    Kyle Machado

    Kyle Machado is a writer at Carbonite + Webroot. He tells the story of the people and products that help keep our digital lives secure.

    [ad_2]

    Source link

  • Italian energy company ERG hit by LockBit 2.0 ransomware gang – Cyber Security

    Italian energy company ERG hit by LockBit 2.0 ransomware gang – Cyber Security

    [ad_1]

    ERG SPA, an Italian energy company, reports a minor impact on its operations after the recent ransomware attack conducted by LockBit 2.0 gang.

    Recently the Italian energy company ERG was hit by the LockBit 2.0 ransomware gang, now the company reported “only a few minor disruptions” for its ICT infrastructure. The company is active in the production of wind energy, solar energy, hydroelectric energy and high-yield thermoelectric cogeneration energy with low environmental impact.

    “Concerning the recent rumours in the media on hacker attacks on institutions and companies, ERG reports that it has experienced only a few minor disruptions to its ICT infrastructure, which are currently being overcome, also thanks to the prompt deployment of its internal cybersecurity procedures.” reads the notice published by ERG.

    “The company confirms that all its plants are operating smoothly and have not experienced any downtime, thus ensuring continuous business operations.”

    ERG added that all its plants are operating smoothly and have not experienced any downtime, thus ensuring continuous business operations

    The ransomware gang has already added the Italian company to the list of victims published on its leak site. The crooks will start leaking the stolen data on August 14, 2021, at 00:00:00.

    LockBit 2.0 ERG

    The LockBit ransomware operations began in September 2019, but in June 2021 the group launched the LockBit 2.0 ransomware-as-a-service.

    ERG isn’t the only Italian organization under attack, multiple Italian companies were targeted with an unprecedented wave of ransomware attacks in the last weeks.

    A major cyber attack paralyzed the IT systems at the region Lazio health portal which is used by residents for COVID-19 vaccine registration. According to sources informed about the event, the attack was carried out by the RansomEXX ransomware, as first reported by BleepingComputer that received a copy of the ransom note used in the attack.

    Follow me on Twitter: @securityaffairs and Facebook

    Pierluigi Paganini

    (SecurityAffairs – hacking, LockBit 2.0)




    [ad_2]

    Source link

  • China-linked APT31 targets Russia for the first time – Cyber Security

    China-linked APT31 targets Russia for the first time – Cyber Security

    [ad_1]

    China-linked APT31 group employed a new strain of malware in attacks aimed at entities in Mongolia, Belarus, Canada, the US, and Russia.

    Researchers from Positive Technologies reported that China-linked APT31 group has been using a new piece of malware in a recent wave of attacks targeting Mongolia, Belarus, Canada, the United States, and Russia.

    Experts found many similarities between the malware and the DropboxAES RAT that was first spotted by researchers at Secureworks and that was previously attributed to APT31. Positive Technologies pointed out that the two samples were the same malware with only minor differences.

    APT31 (aka Zirconium) is a China-linked APT group that was involved in multiple cyber espionage operations, it made the headlines recently after Check Point Research team discovered that the group used a tool dubbed Jian, which is a clone of NSA Equation Group ‘s “EpMe” hacking tool, years before it was leaked online by Shadow Brokers hackers.

    In July 2021, the French national cyber-security agency ANSSI warned of ongoing attacks against a large number of French organizations conducted by the Chine-linked APT31 cyberespionage group. The state-sponsored hackers are hijacking home routers to set up a proxy mesh of compromised devices to conceal its attack infrastructure. The campaign began at the beginning of 2021 and is still ongoing, the alert published by the French agency includes a list of 161 IP addresses associated with hijacked devices that were involved in the attack.

    The technique allows masquerading the actual source of attacks against France entities.

    Researchers reported that the attackers employed the new malware in approximately 10 attacks aimed at the above states between January and July 2021.

    APT31 employed a new dropper that leverages DLL sideloading to execute the malicious binary on the target machine.

    “The main objective of the dropper, the appearance of the main function of which is shown in Figure 1, is the creation of two files on the infected computer: a malicious library and an application vulnerable to DLL Sideloading (this application is then launched). Both files are always created over the same path: C:ProgramDataApacha. In the absence of this directory, it is created and the process is restarted.” reads the analysis published by the experts.

    The application launched by the dropper loads the malicious library and calls one of its functions. The library mimics the legitimate MSVCR100.dll which is included in Visual C ++ for Microsoft Visual Studio. Experts pointed out that the size of the malicious library employed in the attack is much smaller than the legitimate one.

    APT31

    In order to avoid detection, threat actors also signed the dropper used in some attacks with a valid digital signature likely stolen.

    The malware employed in the attacks allows operators to steal information from infected systems, get info on mapped drives, search for files and documents, create a process, create a new stream with a file download from the server, create a new stream sending the file to the server, create a directory, or delete itself.

    “In the study PT ESC specialists analyzed new versions of the malware used by APT31 in attacks from January to July this year. The revealed similarities with earlier versions of malicious samples described by researchers, such as in 2020, suggest that the group is expanding the geography of its interests to countries where its growing activity can be detected, Russia in particular. We believe that further instances will be revealed soon of this group being used in attacks, including against Russia, along with other tools that might be identified by code correspondence or network infrastructure.” Positive Technologies concludes.

    Follow me on Twitter: @securityaffairs and Facebook

    Pierluigi Paganini

    (SecurityAffairs – hacking, APT31)




    [ad_2]

    Source link

  • 5 factors for success in cybersecurity projects among shifting priorities – Cyber Security

    5 factors for success in cybersecurity projects among shifting priorities – Cyber Security

    [ad_1]

    As more companies are considering the shift to a fully or hybrid remote workforce, accelerating plans to acquire digital and cloud services to address increasing cybersecurity risks is necessary.

    Safe secure cloud computing information technology mobile internet network technology

    Image: Rick_Jo, Getty Images/iStockphoto

    Cybersecurity and regulatory compliance have become two of the biggest concerns of corporate boards. When it comes to the impact of the COVID-19 pandemic and the new realities of employees working from home, many businesses have been forced to reassess many of their IT assumptions and priorities—especially those around cloud cybersecurity projects.

    SEE: Security incident response policy (TechRepublic Premium)

    What is cloud security?

    Cloud security involves using technologies, policies, controls and services to protect data, applications and infrastructure from threats. This is accomplished by delivering hosted services, such as software, hardware and storage over the internet. Often cloud cybersecurity is part of a hybrid cloud or multicloud infrastructure architecture designed to address advanced cloud cybersecurity challenges such as lack of visibility and tracking, ever-changing workloads and cloud compliance and governance.

    Top cybersecurity priorities 

    Almost 20% of the world’s workforce is expected to continue to work remotely post-COVID-19. As a result, Gartner sheds light on the top project priorities for security and risk management leaders in 2021 and beyond, including these five. 

    1. Cybersecurity mesh that enables the distributed enterprise to deploy and extend security where it’s most needed.
    2. Cyber-savvy boards, dedicated committees that focus on discussing cybersecurity matters.
    3. Vendor consolidation, as a way to reduce costs and better security. Almost 80% of organizations are planning to adopt a vendor-consolidation strategy.
    4. Identity-first security now represents the way all information workers will function, whether they are remote or on-premises.
    5. Managing machine identities focuses on establishing an enterprise-wide strategy for managing machine identities, certificates and secrets for more secure digital transformation.

    While the COVID-19 crisis impacted people’s personal lives and security, it also struck corporate, institutional operations and each technology provider that supported them. The cybersecurity spillover has now reached technology providers—making their roles more difficult. 

    SEE: How to manage passwords: Best practices and security tips (free PDF) (TechRepublic)

    Technology providers are also being challenged to rethink their strategies and solutions to get ahead of incidents and threats. Project budgets are being stretched or completely bypassed to keep up, and throughout project execution, continuously monitoring customers’ needs and shifting priorities is becoming all in a day’s work. 

    McKinsey’s findings throughout the pandemic also showed these realities in shifting priorities playing out in many ways, including the following:

    • The rerouting of resources previously designated for a security-automation project to cover gaps in multifactor authentication.
    • The postponing of cybersecurity war games and the diverting of resources to accelerate the rollout of a VPN.
    • The delaying of red team exercises to close vulnerabilities in remote-work applications.

    As more of these companies adopt security controls for cloud-based business functions, McKinsey anticipates budget increases within specific segments such as financial services and insurance industries.

    SEE: Research: Video conferencing tools and cloud-based solutions dominate digital workspaces; VPN and VDI less popular with SMBs (TechRepublic Premium)

    How successful companies will be in making these cybersecurity projects shifts will be dependent on these factors. 

    1. Developing and maintaining a cyber-resilient culture.
    2. Maintaining focus on protecting critical assets and services.
    3. Maintaining a balance in risk-informed decisions. 
    4. Updating and practicing responses and business continuity plans throughout a new normal.
    5. Strengthening ecosystem-wide collaboration.

    Company and security experts will need to be closely aligned in their approach and priorities to meet the challenges that exist and lay ahead effectively. 

    Also see

    [ad_2]

    Source link

  • China-linked APT groups target telecom companies in Southeast Asia – Cyber Security

    China-linked APT groups target telecom companies in Southeast Asia – Cyber Security

    [ad_1]

    China linked APT groups have targeted networks of at least five major telecommunications companies operating in Southeast Asia since 2017.

    Cybereason researchers identified three clusters of activity associated with China-linked threat actors that carried out a series of attacks against networks of at least five major telecommunications companies located in South Asia since 2017.

    “The goal of the attackers behind these intrusions was to gain and maintain continuous access to telecommunication providers and to facilitate cyber espionage by collecting sensitive information, compromising high-profile business assets such as the billing servers that contain Call Detail Record (CDR) data, as well as key network components such as the Domain Controllers, Web Servers and Microsoft Exchange servers,” states the report published by Cybereason.

    The three clusters were linked to the China-linked APT groups tracked as Soft Cell (aka Gallium), Naikon APT (aka APT30 or Lotus Panda), and TG-3390 (aka APT27 or Emissary Panda).

    Below are the details of each cluster:

    • Cluster A: Operated by Soft Cell, the activity associated with this cluster started in 2018 and continued through Q1 2021.
    • Cluster B: Operated by the Naikon APT, the activity associated with this cluster was first observed in Q4 2020 and continued through Q1 2021.
    • Cluster C: It was classified by Cybereason as a “mini-cluster” with a unique OWA backdoor that was deployed by cyberspies across multiple Microsoft Exchange and IIS servers. The analysis of the backdoor shows many similarities with a known backdoor, tracked as Iron Tiger, employed in campaigns conducted by the Group-3390 (APT27 / Emissary Panda). The activity related to this cluster was observed between 2017 and Q1 2021.
    China-linked APT groups

    The attackers spent a significant effort to avoid detection, like the HAFNIUM attacks, the threat actors exploited the ProxyLogon vulnerabilities affecting Microsoft Exchange Servers to gain access to the targeted networks.

    “They then proceeded to compromise critical network assets such as Domain Controllers (DC) and billing systems which contain highly sensitive information like Call Detail Record (CDR) data, allowing them access to the sensitive communications of anyone using the affected telecoms’ services.” continues the analysis..

    Naikon APT employed a backdoor tracked “Nebulae” that supports common backdoor capabilities, including the ability to collect LogicalDrive information, manipulate files and folders, download and upload files from and to the command-and-control server, list/execute/terminate processes on compromised devices.

    Experts found multiple overlaps between the activities of the clusters, below the hypothesis elaborated by the experts:

    • One hypothesis is that the clusters represent the work of two or more teams with different sets of expertise (e.g initial access team, foothold, telco-technology specialized team, etc.) all working together and reporting to the same Chinese threat actor. 
    • A second hypothesis is that there are two or more Chinese threat actors with different agendas / tasks that are aware of each other’s work and potentially even working in tandem. 
    • Another plausible hypothesis is that the clusters are not interconnected and that the threat actors are working independently with no collaboration, or even piggybacking on the access achieved by one of the actors involved. 

    Follow me on Twitter: @securityaffairs and Facebook

    Pierluigi Paganini

    (SecurityAffairs – hacking, China-linked APT)




    [ad_2]

    Source link

  • BazarCaller – the malware gang that talks you into infecting yourself – Cyber Security

    BazarCaller – the malware gang that talks you into infecting yourself – Cyber Security

    [ad_1]

    You’re almost certainly familiar with vishing, a phone-based scam in which cybercriminals leave messages on your voicemail in the hope that you’ll call them back later to find out what’s going on.

    In fact, if you have a long-standing phone number, like we do, you may well get more of these scam calls (perhaps even many more of them) than genuine calls, so you’ll know the sort of angle they take, which often goes along these lines:

    [Synthetic voice] Your Amazon Prime subscription will auto-renew. Your card will be billed for [several tens of dollars]. To cancel your subscription or to discuss this renewal, press 1 now.

    Sometimes, they’ll read out the number to call them back on, to re-iterate not only that it matches the number that shows up in your call history, but also that it’s a local number, right there in your own town or country.

    The crooks do this to “prove” that caller is local too, rather than sitting overseas in some scammy boiler-room call centre, far from the reach of law enforcement and the regulators in your part of the world.

    Unfortunately, the number that shows up in your call history (known by various names around the world, including Caller ID and calling line identification) doesn’t tell you where the caller is actually located.

    Firstly, Caller ID is easy to spoof, so crooks can disguise their real number, or make it look as though they’re calling from somewhere you trust, such as your bank.

    Secondly, if it’s not spoofed, Caller ID doesn’t tell you where a returned call will ultimately end up, but merely reports the last known phone number that it passed through on the way to you.

    If a call centre (or a cybercriminal) calls you from overseas using a voice-over-IP (VoIP) service, where the call is transmitted cheaply over the internet until it reaches your country and only then redirected into the phone network, you will see a local number in your call history, but it won’t actually be the caller’s ID. Always keep in mind that the name Caller ID is misleading because it doesn’t identify the person who called you at all. Even calling line identification is an inaccurate name, given that the number that shows up can be modified and therefore doesn’t reliably identify the calling line, either.

    Call us back

    So, Caller ID can’t be trusted, and unexpected phone calls, like unwanted emails, could by-and-large have come from anyone.

    That’s why many of us dump all our calls to voicemail these days, and respond only to the likely ones.

    With this in mind, you may be wondering why crooks still bother running phone-based scams, especially when these require human interaction each and every time someone returns a call, unlike web-based scams, which largely look after themselves.

    The answer, of course, is that variety is the spice of life, or, sadly, that variation is one of the secrets of scamming.

    Sometimes, simply being different from what everyone has been told to watch out for is enough to get victims to let their guard down.

    The other advantage, for the crooks, of runnning what you might call human-led scams instead of pure online ones is that the scammers in the call centre only ever deal with people who are already concerned enough to call back of their own accord.

    In other words, call-back scamming may be a more time-consuming way of interacting with each potential victim, but:

    • Many people feel comfortable about carrying out risky computer behaviours such as installling unknown software if there is an “IT helpdesk” person talking to them at the same time.
    • Human scammers can adapt and respond in real time to objections or fears that potential victims might raise, thus keeping those callers on the hook for much longer than if they were left to their own devices.

    Call us first

    As you probably know, there’s a fascinating world of hybrid scamming that mixes together email-based and phone-based treachery.

    Technical support scammers – those lowlifes who find fake viruses on your computer and then charge you real money for pretending to remove them – have been doing this for years.

    They know that potential victims have been taught “not to click through” and to “watch out for dodgy popup links”, so many scams these days invite you to call a local phone number instead of clicking a link or opening an attachment.

    At first, this feels as though it should be safer, because you’re not immediately exposing your browser or your computer to a site or a file that you aren’t sure of.

    There’s always a chance, you might think, to make your own judgment of the “helpdesk expert” at the other end…

    …before typing in the link they just gave you, or installing the software they just recommended.

    Don’t click, call us instead

    Unfortunately, as we wrote earlier this year, it’s not just the technical support scammers using this “don’t click a dangerous link, call this handy phone number instead” trick.

    In April 2021, we warned of a malware crew using a similar trick to talk you into infecting yourself with their malware, known as BazarLoader (also known as BazaLoader), thus giving them a foothold on your computer to mount pretty much any sort of cyberattack they want:

    Rather than deciding in advance whether they’re going to hit you with a keylogger, a data stealer or a ransomware attack, the crooks who talk to you on the phone helpfully explain how to open a booby-trapped Office file that they deliver to you.

    By tricking you into bypassing the security checks that would otherwise keep you safe, they implant a general-purpose bot or zombie program onto your computer that can:

    • Download and run another programs, disguising them as an unexceptionable apps such as Notepad or Explorer.
    • Download and run DLLs, Windows software modules that many people think of as safer than EXE files because they aren’t standalone programs that you can launch as apps in their own right.
    • Download and run a batch file or PowerShell script. PowerShell is widely used by system administrators these days because it makes it easy to create full-blown Windows programs in the form of plain text files.
    • Get rid of itself from disk and exit. By cleaning up their malware tools after an attack, the crooks make it harder for you to figure out what happened and thus make it tricky to know what to look out for in future.

    BazarLoader is back

    We’re writing this article now as a followup to a reminder that came from Microsoft itself last week, with the self-explanatory title:

    BazaCall: Phony call centers lead to exfiltration and ransomware

    As you can imagine, Microsoft takes this sort of attack at least as personally as anyone else, not least because the primary malware infiltration vehicle that the BazarLoader/BazarCaller crooks use is to talk you into infecting youself via some sort of Microsoft Office file.

    Ironically, the crooks use the pretence that the file is “protected” and therefore needs to be handled in a special way – something that a crooked “helpdesk support team member” will glibly and happily tell you how to do.

    Of course, the “special way” of handling the “protected” file, shown above as ENABLE EDITING and ENABLE CONTENT, involves turning off Microsoft’s default security settings, thus allowing malware embedded in the Office file to run, rather than blocking it.

    In the latest round of attacks, you are urged via email by the BazarCaller scammers to phone them up if you want to “resolve” a “purchase” that was just debited to your account, such as:

    • Converting a software trial into an auto-billed “premium” paid package. (Call for details, or to cancel if this is an error, etc.)
    • Joining a fitness program you showed an interest in. (Call with included personal ID for help or details, etc.)
    • Autorenewing a service membership you’re already part of. (Call if you want to cancel, etc.)

    The crooks know that you’ll know that you didn’t intend to make or authorise the purchase they’re warning you about.

    They’re also hoping that you’ll want to check how the “mistake” happened, and get the charge removed from your card.

    Don’t do it!

    What to do?

    • Never assume that calling a phone number is safer than clicking on a web link. Either way could put you directly into contact with cybercrooks.
    • Never rely on contact details given to you by an outsider. If you are concerned about unauthorised payments taken off your card, contact your bank or card provider directly for advice. Always use the phone number or website on the back of your physical card, or printed on documentation that’s already in your possession.
    • Never change a security setting on your computer because someone you don’t know told you to. If you’re wondering whether a link is safe to download, or an Office file is safe to open, find someone you already know and trust (e.g. a member of your own IT team from work, or a trusted friend in your own circle) and ask them directly.
    • Never feel compelled to call a number back, whether you are being threatened or flattered. If you have any vulnerable friends or family whom you think might easily be misled on the phone, make sure they know to call you first.
    • Listen to our special podcast episode on social engineering. Phone scammers can be much more persuasive than messages received via email or the web. Phone scammers adapt their lies and treachery line by line as they go along, and typically have the “gift of the gab” to explain away any concerns you might have along the way.

    LEARN MORE ABOUT SOCIAL ENGINEERING

    Listen to our special-episode podcast with Rachel Tobac, a renowned social engineering expert, and give yourself the confidence and understanding not to get sucked into saying or doing the wrong thing online:

    Remember that gangs like the BazarCaller crew talk people into infecting themselves with malware, including ransomware, for a living.

    Cybercrooks of this sort typically have a lot more practice in telling you what you want to hear, the way you want to hear it, than you have in picking out which bits of what they just said are a pack of lies.

    If in doubt, don’t give it out!


    [ad_2]

    Source link

  • More evidence suggests that DarkSide and BlackMatter are the same group – Cyber Security

    More evidence suggests that DarkSide and BlackMatter are the same group – Cyber Security

    [ad_1]

    Researchers found evidence that the DarkSide ransomware gang has rebranded as a new BlackMatter ransomware operation.

    BleepingComputer found evidence that after the clamorous Colonia Pipeline attack, the DarkSide ransomware gang has rebranded as a new BlackMatter ransomware operation. The experts analyzed encryption algorithms in a decryptor used by BlackMatter, which is actively attacking corporate entities.

    BleepingComputer became aware of a victim that paid a $4 million ransom to BlackMatter gang. The company received by the cybercriminals gang both Windows and Linux ESXi decryptors.

    BleepingComputer shared a decryptor from a BlackMatter victim with Emisosft CTO Fabian Wosar who confirmed that the new ransomware gang is using the same unique encryption methods (a custom implementation of Salsa20 matrix) implemented by the DarkSide.

    DarkSide also used an RSA-1024 implementation unique to their encryptor, which is the same used by BlackMatter.

    The above and other similarities, such as the similar text on the leak sites, suggest that BlackMatter rebrand from DarkSide.

    BlackMatter ransomware Darkside

    On its leak site BlackMatter states that it doesn’t attack:

    • Hospitals.
    • Critical infrastructure facilities (nuclear power plants, power plants, water treatment facilities).
    • Oil and gas industry (pipelines, oil refineries).
    • Defense industry.
    • Non-profit companies.

    Follow me on Twitter: @securityaffairs and Facebook

    Pierluigi Paganini

    (SecurityAffairs – hacking, BlackMatter)




    [ad_2]

    Source link

  • Conceptual Differences Between SSF and PA-DSS – Cyber Security

    Conceptual Differences Between SSF and PA-DSS – Cyber Security

    [ad_1]

    To assist stakeholders in their migration from PA-DSS to the Software Security Framework, PCI Security Standards Council (PCI SSC) is publishing a series of blog posts to guide payment software vendors and assessors through the key differences between PA-DSS and the SSF. In Part One of our multi-part blog series, PCI SSC’s Sr. Manager, Public Relations Alicia Malone sits down with PCI SSC’s Sr. Manager, Emerging Standards Jake Marcinko to discuss some of the conceptual differences between PA-DSS and the Software Security Framework that stakeholders should be aware of as they work to transition between programs.

    What is the PCI Software Security Framework?

    Jake Marcinko: The PCI Software Security Framework (SSF) is a collection of security standards and associated validation and listing programs for promoting software security in the payments industry. The SSF is comprised of the Secure Software Standard and the Secure Software Lifecycle (Secure SLC) Standard.

    The Secure Software Standard defines the security features and attributes that payment software must possess, and the Secure SLC Standard defines the security processes and capabilities that a software vendor must have in place to ensure its software is developed securely.

    The SSF replaces the PCI Payment Application Data Security Standard (PA-DSS) which is being retired in October 2022.

    Why was the Software Security Framework created and why is PA-DSS being retired?

    Jake Marcinko: PA-DSS was one of the first standards and programs of its kind. It laid the groundwork for software security in the payments industry, and it has served the payment industry’s needs for over 10 years. Those needs, however, have evolved to the point that it no longer made sense to make incremental changes to an aging standard and program. A new approach was needed to support modern payment software architectures and software development methodologies, and to protect payment software from increasingly complex software attacks.

    What benefits does the Software Security Framework provide over PA-DSS?

    Jake Marcinko: The SSF builds on many of the concepts introduced in PA-DSS but is designed to provide both software vendors and assessors a more dynamic, faster-to-market approach to security validation for a broader array of software types compared to PA-DSS.

    In PA-DSS, the scope of software eligible for validation and listing was limited to software that facilitates payment authorization. Under the SSF, the eligibility criteria for software validation has been expanded to include software providing additional functions such as fraud monitoring or cardholder authentication. Additionally, by separating software requirements and vendor requirements into different standards, vendors who produce software that is ineligible for validation to the Secure Software Standard are able to demonstrate good software security hygiene through independent Secure SLC validation.

    PCI SSC recommends that software vendors with eligible payment software products have both their software development lifecycle (SDLC) practices and payment software validated to the respective SSF standards. Validating to both standards not only demonstrates that a vendor’s payment software is secure upon validation, but also demonstrates greater assurance that the software will remain secure throughout its lifetime. To encourage validation to both standards and to support faster time-to-market strategies, the SSF provides a more streamlined listing management process to Secure SLC qualified software vendors with validated payment software. This process enables qualified software vendors to manage and publish updates to their validated payment software listings more quickly than previously supported under PA-DSS.

    More information on these and other benefits can be found in the respective Program Guides under the Software Security section of the PCI SSC Document Library.

    What are ‘objective-based’ requirements in the Software Security Framework and how are they different from PA-DSS requirements?

    Jake Marcinko: PA-DSS requirements specify the practices and security controls that must be implemented to meet a particular security objective. The SSF supports a newer approach among PCI security standards, including the PCI 3-D Secure (3DS) security standards and the Customized Approach in PCI DSS version 4.0, where security requirements are expressed as security objectives that provide greater flexibility in how requirements are met. This approach is referred to as ‘objective-based’ and recognizes that there are often many different ways to satisfy a particular security objective.

    How does the objective-based approach provide software vendors more flexibility?

    Jake Marcinko: The objective-based approach enables software vendors to choose the practices and methods that best meet the security objectives given the entity’s unique business requirements and capabilities, rather than having to implement the specific practices and methods stipulated in more prescriptive security standards such as PA-DSS.

    For example, where PA-DSS requires the use of specific password complexity parameters such as minimum length and composition, the corresponding control objective in the Secure Software Standard requires that authentication methods be ‘sufficiently strong and robust to protect authentication credentials from being forged, spoofed, leaked, guessed, or circumvented’ in accordance with industry-accepted methods. This enables software vendors to choose which industry-accepted authentication methods to implement to meet the control objective rather than having to implement the password complexity parameters stipulated in PA-DSS.

    How does the objective-based approach benefit security assessors?

    Jake Marcinko: The testing procedures in PA-DSS specify the verification methods that assessors are required to use to validate security requirements, with limited flexibility. The SSF permits assessors to deviate somewhat from the methods stated in the test requirements where necessary. This is referred to as ‘alternative testing’ and it permits assessors to use alternative verification methods if the stated methods aren’t sufficient to properly validate the control objectives.

    For example, many SSF test requirements require examination of software vendor documentation and evidence to validate control objectives. In certain circumstances, it may be more appropriate to validate a control objective using interviews or other assessor-provided tools. Under the SSF, assessors are permitted to use such verification methods even if those verification methods aren’t explicitly stated in the test requirement. This provides assessors greater flexibility in determining how best to confirm control objectives have been met. The use of alternative testing does not allow assessors or software vendors to change what the test requirement is verifying, or to reduce the thoroughness of the testing.

    How does the Software Security Framework’s support for PCI DSS differ from PA-DSS?

    Jake Marcinko: PA-DSS was developed explicitly to facilitate PCI DSS compliance for entities implementing payment applications in a cardholder data environment. The SSF was developed with broader applicability in mind and covers a broader range of security topics and data assets than PA-DSS and PCI DSS. The SSF is also intended to apply to payment software and software vendors regardless of whether PCI DSS applies to the environment in which the payment software is deployed.

    For these reasons, the security requirements in the SSF standards do not map directly to PCI DSS requirements like the PA-DSS requirements do. With that said, the SSF security standards still support an entity’s PCI DSS compliance by enabling entities who use qualified software vendors and/or validated payment software to potentially meet some PCI DSS requirements without the need for additional detailed testing.

    For example, bespoke or custom software provided by a Secure SLC qualified software vendor is confirmed to have been developed in accordance with a rigorous set of secure software development best practices. The use of such software by a merchant or service provider (who may also be the Secure SLC qualified software vendor) may satisfy a number of sub-requirements under PCI DSS Requirement 6 without the need to have those sub-requirements retested by a QSA.

    Similarly, payment software that has been validated to the Secure Software Standard is confirmed to possess robust sensitive data protection mechanisms. Use of such software by a merchant or service provider may satisfy corresponding requirements in PCI DSS for the protection of cardholder data and authentication credentials during storage and transmission.

    Entities anticipating the publication of PCI DSS v4.0 should expect even greater alignment between PCI DSS and the SSF standards with the introduction of the Customized Approach. Please refer to the PCI SSC website for more information on PCI DSS v4.0.

    How will the differences between PA-DSS and the Software Security Framework impact vendors of currently validated PA-DSS applications?

    Jake Marcinko: It is possible that some vendors with PA-DSS validated applications may need to upgrade their software or software development practices to meet applicable SSF requirements. This isn’t intended to undermine the value that PA-DSS validation has provided over the years. Given the increasing complexity of modern software and the sophistication of modern software attacks, the SSF standards contain additional requirements that weren’t included in PA-DSS.

    PCI SSC recognizes that there are a number of important differences between PA-DSS and the SSF, and a lot of information about the Secure Software and Secure SLC standards and programs that stakeholders must absorb. To assist with the transition between PA-DSS and SSF, PCI SSC is offering informational training classes for software vendors; details can be found in the Training and Qualification section of the PCI SSC website. Software vendors with validated PA-DSS applications are also encouraged to start working with a qualified SSF assessor company to help understand the differences and to begin the transition to SSF before PA-DSS is retired in October 2022.

    Coming Soon: In Part Two of this blog series, we will discuss some of the key technical differences between PA-DSS and the SSF, including what critical assets are and why they are important; how cryptography and data storage requirements are different; and how the concept of the PA-DSS Implementation Guide has evolved. If you have any questions or topics related to the PA-DSS to SSF transition that you would like us to clarify in guidance, please forward those to software@pcisecuritystandards.org

    Read more about the Software Security Framework.

    Sign up for Informational Training today!

    [ad_2]

    Source link