California City Hid Cyber-attack

California City Hid Cyber-attack

A California city whose police department recently revealed it had been victimized by cyber-criminals has now acknowledged it suffered an earlier cyber-attack in 2018.

Azusa’s 63-officer police department was targeted by the DoppelPaymer ransomware gang late last winter. The attack was kept secret while officials worked with the FBI, Los Angeles County Sheriff’s Department, and ransomware consultants to try to retrieve hundreds of highly sensitive files encrypted in the incident. 

In April, a stash of the department’s documents was leaked online after the city elected not to pay the ransom demanded by the gang. Among the information leaked were criminal case files and payroll data containing Social Security numbers, driver’s license numbers, medical information, and financial account information.

The city finally publicly acknowledged the hack on May 27 to coincide with the start of Memorial Day weekend, when America’s attention typically flits away from the news cycle and toward outdoor social activities and honoring the fallen. 

Azusa PD issued a “notification of data security breach” stating that it had been hit by a “sophisticated ransomware attack” and that “certain Azusa Police information was acquired by the unauthorized individual.”

Now the city has said that it was attacked with ransomware by another unnamed cyber-criminal organization in the fall of 2018. Azusa City Manager Sergio Gonzalez said that the city’s insurers, Chubb, paid $65,000 to regain control of 10 data servers at the police department that were taken over by the hackers for more than a week.

“We were able to unlock one server after the ransom was paid but immediately after found a free key to unlock all other locked servers,” Gonzalez said in an email. 

“No information was compromised. Our servers were just locked.”

Gonzalez said that the 2018 attack had not been reported because an investigation had determined that no data had been exposed in the incident. 

“We verified with forensic experts that no data was compromised,” wrote Gonzalez. “That’s essentially why we did not and were not required to report it (publicly).”

Whittier Daily News reports that the 2018 attack began when a city employee opened an email and clicked on a malicious link. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Qualys Announces Passing of Former CEO Philippe Courtot

Qualys Announces Passing of Former CEO Philippe Courtot

Cloud security firm Qualys has announced the sad news of the passing of its former CEO, chairman and leader for the past 20 years, Philippe Courtot, at the age of 76.

Courtot oversaw the significant growth of Qualys since becoming its CEO in March 2001, initially investing in the company in 1999 when it was founded. His vision to build a cloud delivery platform that would allow for scanning any network on a global scale became realised in Qualys’ global expansion over the past two decades. It first went public in 2012.

Under his leadership, Qualys completed several acquisitions. In recent years these include Second Front Systems and endpoint detection and response startup Spell Security.

Born in 1944 in France, Courtot began his career selling minicomputers before arriving in the US in 1981. After a spell as CEO of Thomson CGR Medical, he founded email platform provider cc:Mail in 1988, achieving a 40% market share before selling the business to Lotus in 1991. He was then appointed president and CEO of Verity before joining Signio, where he oversaw its acquisition by VeriSign.

Courtot was also involved in several initiatives to support the security industry’s role more generally.  These include supporting the formation of the Cloud Security Alliance in 2008, founding the Trustworthy Internet Movement and CSO Interchange, and becoming a trustee for The Internet Society.

Additionally, he received a number of personal awards for his work in security over the years. In 2019, Courtot picked up the Decade of Vision Leadership Award from the Cloud Security Alliance. Last year Courtot received the Benefactor Award from the International Systems and Security Association (ISSA) Education Foundation for supporting cybersecurity and cybersecurity education.

Commenting, Sumedh Thakar, Qualys president and CEO, said: “Philippe was my mentor and advisor; the entire Qualys team and I are deeply saddened by his passing, and our thoughts and prayers are with his family. We are forever grateful for Philippe’s exceptional leadership, vision and passion for helping enterprise customers with practical solutions to the biggest challenges around security. He was dedicated to making life easier for everyone from security analysts through to CISOs.”

Sandra E. Bergeron, Qualys’ lead independent director, stated: “The board and company are incredibly saddened at the loss of Philippe. He was a transformational leader with a passion for business and cybersecurity, who cared deeply about Qualys and its employees. We look forward to honoring him by continuing to grow the company based on his vision.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Colonial Pipeline Incident Sparks ‘Help Desk’ Phishing Attacks

Colonial Pipeline Incident Sparks ‘Help Desk’ Phishing Attacks

Researchers have discovered a new phishing campaign designed to spread ransomware and steal data by capitalizing on interest in the recent Colonial Pipeline outage.

Security vendor Inky spotted the malicious emails, which said several Microsoft 365 customers were targeted.

Emails were spoofed to appear as if sent from the recipient’s “Help Desk.” They were instructed to click on a malicious link in order to download a critical “ransomware system update” to protect their organization from the same fate as Colonial Pipeline.

“The malicious emails were sent from newly created domains (ms-sysupdate.com and selectivepatch.com) controlled by cyber-criminals. The domain names, sufficiently plausible to appear legitimate, were nonetheless different enough so that garden variety anti-phishing software would not be able to use regular expression matching to detect their perfidy,” explained VP of security strategy, Roger Kay.

“Both domains were registered with NameCheap, a registrar popular with bad actors. Its domains are inexpensive, and the company accepts Bitcoin as payment for hosting services (handy for those trying to remain anonymous). The malicious links in the emails belonged to — surprise — the same domain that sent the emails.”

The download itself is, in fact, Cobalt Strike — a legitimate pen-testing tool often used in ransomware attacks and data exfiltration and which could be used in this instance to control targeted systems.

Anti-phishing software must be used to mitigate the risks posed by such attacks in conjunction with well-thought-out policies such as IT teams never asking employees to download certain file types, Kay concluded.

In related news, it has been reported that the DarkSide group responsible for the attack on Colonial Pipeline may have breached the critical infrastructure organization via a single compromised password.

A Mandiant VP working on the case reportedly claimed that the VPN account log-in allowed remote attackers to infiltrate the company’s network, even though the account was no longer in use at the time. The credential was subsequently found on the dark web, meaning it may have been previously reused across multiple accounts.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Latvian Woman Charged with Developing Malware for Trickbot

Latvian Woman Charged with Developing Malware for Trickbot

A 55-year-old Latvian woman has been charged on multiple counts for her alleged role in developing malware for the infamous Trickbot group.

On Friday, Alla Witte, aka “Max,” was charged with 19 counts of a 47-count indictment after being arrested in February in Miami.

The indictment claimed that she helped develop code related to the control, deployment, and payments of ransomware and software to track authorized users of the malware and tools and protocols to store stolen login credentials.

Trickbot started life several years ago as a banking Trojan. However, subsequent iterations turned it into a multi-purpose modular threat used by cyber-criminals to gain access to victims’ networks and deploy additional malware, including ransomware.

According to the Department of Justice (DoJ), Witte and her co-conspirators stole money and sensitive information globally from individuals and businesses, including banks, beginning November 2015.

Trickbot apparently helped them steal online banking logins and other personal information, including credit card numbers, emails, passwords, dates of birth, social security numbers and addresses. The DOJ alleged that Witte and her co-conspirators used bank account access to steal funds and launder money.

Witte is charged with:

  • One count of conspiracy to commit computer fraud and aggravated identity theft
  • One count of conspiracy to commit wire and bank fraud affecting a financial institution
  • Eight counts of bank fraud affecting a financial institution
  • Eight counts of aggravated identity theft
  • One count of conspiracy to commit money laundering

The crimes she’s accused of could land Witte with a maximum sentence of over 300 years.

The group is accused of infecting tens of millions of computers and stealing millions of dollars over the past six years.

“The Trickbot malware was designed to steal the personal and financial information of millions of people around the world, thereby causing extensive financial harm and inflicting significant damage to critical infrastructure within the United States and abroad,” said acting US attorney, Bridget Brennan, of the Northern District of Ohio.

“Federal law enforcement, along with assistance provided by international partners, continue to fight and disrupt ransomware and malware where feasible. We are united in our efforts to hold transnational hackers accountable for their actions.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Warning of New Ransomware Surge in Education Sector

Warning of New Ransomware Surge in Education Sector

The UK’s leading cybersecurity authority has updated its guidance on ransomware following a spate of attacks on the education sector.

GCHQ spin-off, the National Cyber Security Centre (NCSC), said it was investigating another rise in threats targeting schools, universities and colleges.

“Ransomware attacks can have a devastating impact on organizations, with victims requiring a significant amount of recovery time to reinstate critical services. These events can also be high profile in nature, with wide public and media interest,” the NCSC said.

“In recent incidents affecting the education sector, ransomware has led to the loss of student coursework, school financial records as well as data relating to COVID-19 testing.”

Recent trends highlighted by the organization include the targeting of networks through VPNs and remote desktop protocol (RDP) endpoints, by exploiting unpatched bugs or weak passwords/lack of multi-factor authentication (MFA). It also pointed to the threat from phishing emails and other unpatched systems like Microsoft Exchange Server.

Using legitimate tools such as Mimikatz, PsExec, and Cobalt Strike is also widespread in enabling lateral movement that traditional security tools have trouble spotting, the NCSC added.

Recently, researchers have seen attempts to sabotage backup/auditing devices to make data recovery more complex, encrypt entire virtual servers, and use scripting environments like PowerShell to deploy tooling and malware.

In April, both the University of Portsmouth and the University of Hertfordshire suffered network outages lasting days after ransomware threat actors struck.

The Harris Federation, which runs 50 primary and secondary academies in the London area, was struck in March, impacting nearly 40,000 pupils.

The NCSC’s updated report recommended a defense-in-depth approach to protection, including MFA, anti-virus, prompt patching, and disabling macros and scripting environments to help disrupt ransomware attack vectors.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk