The DarkSide Ransomware Gang

The New York Times has a long story on the DarkSide ransomware gang.

A glimpse into DarkSide’s secret communications in the months leading up to the Colonial Pipeline attack reveals a criminal operation on the rise, pulling in millions of dollars in ransom payments each month.

DarkSide offers what is known as “ransomware as a service,” in which a malware developer charges a user fee to so-called affiliates like Woris, who may not have the technical skills to actually create ransomware but are still capable of breaking into a victim’s computer systems.

DarkSide’s services include providing technical support for hackers, negotiating with targets like the publishing company, processing payments, and devising tailored pressure campaigns through blackmail and other means, such as secondary hacks to crash websites. DarkSide’s user fees operated on a sliding scale: 25 percent for any ransoms less than $500,000 down to 10 percent for ransoms over $5 million, according to the computer security firm, FireEye.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

The What, Why, and How of AI and Threat Detection

There are more online users now than ever before, thanks to the availability of network-capable devices and online services. The internet population in Canada is the highest it has been, topping the charts at 33 million. That number is only expected to increase through the upcoming years. However, this growing number and continued adoption of online services pose increasing cybersecurity risks as cybercriminals take advantage of more online users and exploit vulnerabilities in online infrastructure. This is why we need AI-backed software to provide advanced protection for online users.   

The nature of these online threats is ever-changing, making it difficult for legacy threat detection systems to monitor threat behavior and detect new malicious code. Fortunately, threat detection systems such as McAfee’s Antivirus and Threat Detection Defense adapt to incorporate the latest threat intelligence and artificial intelligence (AI) driven behavioral analysis. Here’s how AI impacts cybersecurity to go beyond traditional methods to protect online users. 

What is AI? 

Most of today’s antivirus and threat detection software leverages behavioral heuristic-based detection based on machine learning models to detect known malicious behavior. Traditional methods rely on data analytics to detect known threat signatures or footprints with incredible accuracy. However, these conventional methods do not account for new malicious code, otherwise known as zero-day malware, for which there is no known information available. AI is mission-critical to cybersecurity since it enables security software and providers to take a more intelligent approach to virus and malware detection. Unlike AI–backed software, traditional methods rely solely on signature-based software and data analytics.  

Similar to human-like reasoning, machine learning models follow a three-stage process to gather input, process it, and generate an output in the form of threat leads. Threat detection software can gather information from threat intelligence to understand known malware using these models. It then processes this data, stores it, and uses it to draw inferences and make decisions and predictions. Behavioral heuristic-based detection leverages multiple facets of machine learning, one of which is deep learning. 

Deep learning employs neural networks to emulate the function of neurons in the human brain. This architecture uses validation algorithms for crosschecking data and complex mathematical equations, which applies an “if this, then that” approach to reasoning. It looks at what occurred in the past and analyzes current and predictive data to reach a conclusion. As the numerous layers in this framework process more data, the more accurate the prediction becomes. 

Many antivirus and detection systems also use ensemble learning. This process takes a layered approach by applying multiple learning models to create one that is more robust and comprehensive. Ensemble learning can boost detection performance with fewer errors for a more accurate conclusion.  

Additionally, today’s detection software leverages supervised learning techniques by taking a “learn by example” approach. This process strives to develop an algorithm by understanding the relationship between a given input and the desired output. 

Machine learning is only a piece of an effective antivirus and threat detection framework. A proper framework combines new data types with machine learning and cognitive reasoning to develop a highly advanced analytical framework. This framework will allow for advanced threat detection, prevention, and remediation.  

How Can AI Help Cybersecurity? 

Online threats are increasing at a staggering pace. McAfee Labs observed an average of 588 malware threats per minuteThese risks exist and are often exacerbated for several reasons, one of which is the complexity and connectivity of today’s world. Threat detection analysts are unable to detect new malware manually due to their high volume. However, AI can identify and categorize new malware based on malicious behavior before they get a chance to affect online users. AIenabled software can also detect mutated malware that attempts to avoid detection by legacy antivirus systems.  

Today, there are more interconnected devices and online usage ingrained into people’s everyday lives. However, the growing number of digital devices creates a broader attack surface. In other words, hackers will have a higher chance of infiltrating a device and those connected to it. 

Additionally, mobile usage is putting online users at significant risk. Over 85% of the Canadian population owns a smartphone. Hackers are noticing the rising number of mobile users and are rapidly taking advantage of the fact to target users with mobile-specific malware. 

The increased online connectivity through various devices also means that more information is being stored and processed online. Nowadays, more people are placing their data and privacy in the hands of corporations that have a critical responsibility to safeguard their users’ data. The fact of the matter is that not all companies can guarantee the safeguards required to uphold this promise, ultimately resulting in data and privacy breaches. 

In response to these risks and the rising sophistication of the online landscape, security companies combine AI, threat intelligence, and data science to analyze and resolve new and complex cyber threats. AI-backed threat protection identifies and learns about new malware using machine learning modelsThis enables AI-backed antivirus software to protect online users more efficiently and reliably than ever before 

Top 3 Benefits of AI-backed Threat Detection Software  

AI addresses numerous challenges posed by increasing malware complexity and volume, making it critical for online security and privacy protection. Here are the top 3 ways AI enhances cybersecurity to better protect online users.  

1. Effective threat detection 

The most significant difference between traditional signature-based threat detection methods and advanced AI-backed methods is the capability to detect zero-day malware. Functioning exclusively from either of these two methods will not result in an adequate level of protection. However, combining theresults in a greater probability of detecting more threats with higher precision. Each method will ultimately play on the other’s strengths for a maximum level of protection. 

2. Enhanced vulnerability management 

AI enables threat detection software to think like a hacker. It can help software identify vulnerabilities that cybercriminals would typically exploit and flag them to the user. It also enables threat detection software to better pinpoint weaknesses in user devices before a threat has even occurred, unlike conventional methods. AI-backed security advances past traditional methods to better predict what a hacker would consider a vulnerability. 

2. Better security recommendations 

AI can help users understand the risks they face daily. An advanced threat detection software backed by AI can provide a more prescriptive solution to identifying risks and how to handle them. A better explanation results in a better understanding of the issue. As a result, users are more aware of how to mitigate the incident or vulnerability in the future.

Take a Smarter Approach to Security 

AI and machine learning are only a piece of an effective threat detection framework. A proper threat detection framework combines new data types with the latest machine learning capabilities to develop a highly advanced analytical framework. This framework will allow for better threat cyber threat detection, prevention, and remediation.

Stay Updated

To stay updated on all things and on top of the latest consumer and mobile security threats, follow@McAfee_Home on Twitter, subscribe to ournewsletter, listen to our podcastHackable?, and ‘Like’ us on Facebook.  

The post The What, Why, and How of AI and Threat Detection appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Rhode Islander Charged with Phishing Political Candidates

Rhode Islander Charged with Phishing Political Candidates

A woman from Rhode Island has been charged with impersonating Microsoft to steal personal information from political candidates and their campaign staff. 

Cranston resident Diana Lebeau allegedly sent phishing emails to approximately 22 members of the campaign staff of a candidate for political office in or around January 2020. 

In the emails, the 21-year-old allegedly posed as either the campaign’s managers or one of the campaign’s co-chairs. Recipients were directed to enter their account login details into an attached spreadsheet, or to click on a link that took them to a Google Form that requested the same credentials.

Lebeau is further accused of sending several phishing emails to the political candidate’s spouse and to colleagues at the spouse’s workplace. In these emails, Lebeau allegedly impersonated Microsoft’s Security Team or an employee of the workplace’s technology helpdesk.

Recipients were asked to add their account credentials to spreadsheets attached to the emails or were asked to enter sensitive data on a website spoofing that of the spouse’s employer.

In March 2020, Lebeau allegedly launched another phishing campaign targeting a different candidate for political office. Lebeau is accused of impersonating the candidate’s cable and internet provider over email to steal the candidate’s account credentials. 

She is further accused of impersonating this candidate in online chats with the same cable and internet provider, as a ruse to reset and obtain the candidate’s account password.

According to the charging document, Lebeau’s alleged actions were not motivated by financial or political aims and were not carried out to benefit any foreign government, instrumentality, or agent.

Lebeau has been charged with attempted unauthorized access to a protected computer. If convicted, she could be sentenced to up to one year in prison, be placed under supervised release for up to 12 months and be fined up to $100,000.

“The best first-line defense against an attack like this is training,” commented Lookout‘s Hank Schless. 

“Be sure to constantly run security training and include mobile in those sessions. Simple steps like always checking the sender’s reply-to address or asking IT before replying to a message could save your organization from being the victim of the next big data breach.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Convicts “King of Fraud”

US Convicts “King of Fraud”

A Russian cyber-criminal has been convicted of running a sophisticated digital advertising scam that defrauded American companies out of millions of dollars.

Aleksandr Zhukov used infrastructure spread around the world to trick companies including the New York Times and Comcast into thinking that they were paying for legitimate digital advertising. In reality, Zhukov and his co-conspirators were using coding and domain spoofing to fraudulently obtain revenue. 

Zhukov and his co-perpetrators made it appear as though they ran legitimate companies that placed ads in front of real human internet users browsing genuine internet web pages. However, the evidence at trial established that Zhukov and his accomplices faked both the users and the web pages. 

Computers they controlled were programmed to load advertisements on spoofed web pages via an automated program. The con defrauded American brands, ad platforms and others in the US digital advertising industry out of more than $7m. 

Victims of the scam included household names the New York Post, Nestle Purina, and Time Warner Cable, and the Texas Scottish Rite Hospital for Children.

Zhukov carried out his digital advertising fraud scheme between September 2014 and December 2016 through a purported advertising network named Media Methane.  

Media Methane arranged with advertising networks to receive payments in return for placing ad tags on websites. Instead of placing the tags on real publishers’ websites, Media Methane rented more than 2,000 computer servers housed in commercial datacenters in Texas and the Netherlands and used those datacenter servers to load ads on fabricated websites, spoofing over 6,000 domains. 

“The defendants programmed the datacenter servers to simulate the internet activity of human internet users: browsing the internet through a fake browser, using a fake mouse to move around and scroll down a web page, starting and stopping a video player midway, and falsely appearing to be signed into Facebook,” said the Department of Justice. 

When discussing the scheme with one of his co-conspirators, Zhukov referred to himself as the “king of fraud.”

Zhukov was arrested in Bulgaria in November 2018 and extradited to the United States in January 2019. On May 28, 2021, after a three-week trial, a federal jury in Brooklyn convicted Zhukov of wire fraud conspiracy, wire fraud, money laundering conspiracy, and money laundering.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Model Sues Law Firm Over Data Breach

Model Sues Law Firm Over Data Breach

A fashion model is suing Baltimore-based law firm Goldberg Segalla for allegedly exposing her personal data when filing records in a different data breach lawsuit.

Stephanie Hoffman claims the firm leaked her information twice on the Public Access to Court Electronic Records (PACER) service, which provides electronic public access to federal court records.

Goldberg Segalla is representing Hoffman’s former modeling agency, Major Model Management Inc (MMMI), in an ongoing proposed class-action lawsuit concerning an alleged data breach. 

That suit, which was also brought by Hoffman, accuses MMMI of failing to adhere to state laws, industry standards and best practices when collecting and storing the personal information of the models it contracted with.

MMMI is seeking to dismiss Hoffman’s lawsuit. In a filing made on February 4, the agency argued that Hoffman either waived her claims in her contract, or that state law does not apply in this case. 

Connecticut resident Hoffman, who won Model of the Year at the International Modeling & Talent Association (IMTA) in New York and has modeled multiple times at New York Fashion Week, claims Goldberg Segalla exposed her data in a December 3 filing relating to the MMMI suit.

The plaintiff alleges that her Social Security number, birth date, passport information, home address, cell number, email address and signature were shared by the law firm without redactions in Manhattan federal court. 

The filing was sealed by US District Judge Laura Taylor Swain on December 3, but Hoffman claims that Goldberg Segalla re-filed the exhibit later that day and only partially redacted her Social Security number and birth date.

In an eight-page complaint filed in New York County Supreme Court, Hoffman claims her data was exposed until January 29, when the court was asked to seal the partially redacted filing. 

Hoffman claims in the suit that she “has been placed at an imminent, immediate, and continuing increased risk of harm from fraud and identity theft.”

The model said that she has been told by prospective employers and third-party credit institutions that her Social Security number “is being used for fraudulent criminal activity.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk