Try This One Weird Trick Russian Hackers Hate

In a Twitter discussion last week on ransomware attacks, KrebsOnSecurity noted that virtually all ransomware strains have a built-in failsafe designed to cover the backsides of the malware purveyors: They simply will not install on a Microsoft Windows computer that already has one of many types of virtual keyboards installed — such as Russian or Ukrainian. So many readers had questions in response to the tweet that I thought it was worth a blog post exploring this one weird cyber defense trick.

The Commonwealth of Independent States (CIS) more or less matches the exclusion list on an awful lot of malware coming out of Eastern Europe.

The Twitter thread came up in a discussion on the ransomware attack against Colonial Pipeline, which earlier this month shut down 5,500 miles of fuel pipe for nearly a week, causing fuel station supply shortages throughout the country and driving up prices. The FBI said the attack was the work of DarkSide, a new-ish ransomware-as-a-service offering that says it targets only large corporations.

DarkSide and other Russian-language affiliate moneymaking programs have long barred their criminal associates from installing malicious software on computers in a host of Eastern European countries, including Ukraine and Russia. This prohibition dates back to the earliest days of organized cybercrime, and it is intended to minimize scrutiny and interference from local authorities.

In Russia, for example, authorities there generally will not initiate a cybercrime investigation against one of their own unless a company or individual within the country’s borders files an official complaint as a victim. Ensuring that no affiliates can produce victims in their own countries is the easiest way for these criminals to stay off the radar of domestic law enforcement agencies.

Possibly feeling the heat from being referenced in President Biden’s Executive Order on cybersecurity this past week, the DarkSide group sought to distance itself from their attack against Colonial Pipeline. In a message posted to its victim shaming blog, DarkSide tried to say it was “apolitical” and that it didn’t wish to participate in geopolitics.

“Our goal is to make money, and not creating problems for society,” the DarkSide criminals wrote last week. “From today we introduce moderation and check each company that our partners want to encrypt to avoid social consequences in the future.”

But here’s the thing: Digital extortion gangs like DarkSide take great care to make their entire platforms geopolitical, because their malware is engineered to work only in certain parts of the world.

DarkSide, like a great many other malware strains, has a hard-coded do-not-install list of countries which are the principal members of the Commonwealth of Independent States (CIS) — former Soviet satellites that all currently have favorable relations with the Kremlin, including Azerbaijan, Belarus, Georgia, Romania, Turkmenistan, Ukraine and Uzbekistan. The full exclusion list in DarkSide (published by Cybereason) is below:

Image: Cybereason.

Simply put, countless malware strains will check for the presence of one of these languages on the system, and if they’re detected the malware will exit and fail to install.

[Side note. Many security experts have pointed to connections between the DarkSide and REvil (a.k.a. “Sodinokibi”) ransomware groups. REvil was previously known as GandCrab, and one of the many things GandCrab had in common with REvil was that both programs barred affiliates from infecting victims in Syria. As we can see from the chart above, Syria is also exempted from infections by DarkSide ransomware. And DarkSide itself proved their connection to REvil this past week when it announced it was closing up shop after its servers and bitcoin funds were seized.]

CAVEAT EMPTOR

Will installing one of these languages keep your Windows computer safe from all malware? Absolutely not. There is plenty of malware that doesn’t care where in the world you are. And there is no substitute for adopting a defense-in-depth posture, and avoiding risky behaviors online.

But is there really a downside to taking this simple, free, prophylactic approach? None that I can see, other than perhaps a sinking feeling of capitulation. The worst that could happen is that you accidentally toggle the language settings and all your menu options are in Russian.

If this happens (and the first time it does the experience may be a bit jarring) hit the Windows key and the space bar at the same time; if you have more than one language installed you will see the ability to quickly toggle from one to the other. The little box that pops up when one hits that keyboard combo looks like this:

Cybercriminals are notoriously responsive to defenses which cut into their profitability, so why wouldn’t the bad guys just change things up and start ignoring the language check? Well, they certainly can and maybe even will do that (a recent version of DarkSide analyzed by Mandiant did not perform the system language check).

But doing so increases the risk to their personal safety and fortunes by some non-trivial amount, said Allison Nixon, chief research officer at New York City-based cyber investigations firm Unit221B.

Nixon said because of Russia’s unique legal culture, criminal hackers in that country employ these checks to ensure they are only attacking victims outside of the country.

“This is for their legal protection,” Nixon said. “Installing a Cyrillic keyboard, or changing a specific registry entry to say ‘RU’, and so forth, might be enough to convince malware that you are Russian and off limits. This can technically be used as a ‘vaccine’ against Russian malware.”

Nixon said if enough people do this in large numbers, it may in the short term protect some people, but more importantly in the long term it forces Russian hackers to make a choice: Risk losing legal protections, or risk losing income.

“Essentially, Russian hackers will end up facing the same difficulty that defenders in the West must face — the fact that it is very difficult to tell the difference between a domestic machine and a foreign machine masquerading as a domestic one,” she said.

KrebsOnSecurity asked Nixon’s colleague at Unit221B — founder Lance James — what he thought about the efficacy of another anti-malware approach suggested by Twitter followers who chimed in on last week’s discussion: Adding entries to the Windows registry that specify the system is running as a virtual machine (VM). In a bid to stymie analysis by antivirus and security firms, some malware authors have traditionally configured their malware to quit installing if it detects it is running in a virtual environment.

But James said this prohibition is no longer quite so common, particularly since so many organizations have transitioned to virtual environments for everyday use.

“Being a virtual machine doesn’t stop malware like it used to,” James said. “In fact, a lot of the ransomware we’re seeing now is running on VMs.”

But James says he loves the idea of everyone adding a language from the CIS country list so much he’s produced his own clickable two-line Windows batch script that adds a Russian language reference in the specific Windows registry keys that are checked by malware. The script effectively allows one’s Windows PC to look like it has a Russian keyboard installed without actually downloading the added script libraries from Microsoft.

To install a different keyboard language on a Windows 10 computer the old fashioned way, hit the Windows key and X at the same time, then select Settings, and then select “Time and Language.” Select Language, and then scroll down and you should see an option to install another character set. Pick one, and the language should be installed the next time you reboot. Again, if for some reason you need to toggle between languages, Windows+Spacebar is your friend.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Lemonade Denies “Unforgivably Negligent” Security Gaffe

Lemonade Denies “Unforgivably Negligent” Security Gaffe

Insurtech company Lemonade has refuted claims put forward by a short seller that it has an “unforgivably negligent security flaw” on its website.

Muddy Waters Research LLC alleges that a vulnerability exists on Lemonade’s website that could potentially expose customers’ personally identifiable information. 

The investor claims that it was able to log in to and edit Lemonade customer accounts without having to enter any user credentials. 

In an open letter to Lemonade CEO Dan Schreiber dated May 13, Muddy Waters CEO Carson Block wrote that the vulnerability was “so gaping” that search engines including Google, Bing, and the Wayback Machine have inadvertently accessed the site and indexed PII belonging to Lemonade customers.  

“By clicking on search results from public search engines, we shockingly found ourselves logged in to and able to edit Lemonade customers’ accounts without having to provide any credentials whatsoever!” wrote Block.

According to Muddy Waters, the flaw appears to have existed since at least July 2020, “yet it is detectable through an industry standard off-the-shelf security testing application that costs $400 per year.”

Block wrote that “it is clear that Lemonade does not give a f*ck about securing its customers’ sensitive personal information.”

Lemonade denied the existence of a security flaw and said that no security breach had taken place. 

 “We’ll try to make this short,” Lemonade told Infosecurity Magazine. “What Muddy Waters Research found were links to four insurance quotes shared by Lemonade users themselves (aka, they loved it so much, they shared ’em). 

“That’s not a vulnerability. We designed our quotes to be shareable, so anyone can share their quote with their family, friends, or mortgage bank.

“Turns out some people also like to brag about their quotes on Pinterest and UX blogs. Here’s an example: https://reallygoodux.io/blog/lemonade-user-onboarding. Since Google indexes Pinterest and blogs, these links end up being discoverable on Google, and Muddy Waters discovered them.”

They added: “We truly hope the folks over at Muddy Waters Research didn’t spend too much time on this.”

Muddy Waters went public with its report of an alleged security flaw before privately informing Lemonade of its intentions.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Sentences Cyber-Stalker Who Sent Sex Workers to Family’s Home

US Sentences Cyber-Stalker Who Sent Sex Workers to Family’s Home

A cyber-stalker from Hawaii who tormented a Utah family by sending more than 500 unwanted service people to their home has been placed under three years of supervision.

Loren M. Okamura was arrested in December 2019 on charges of cyber-stalking, making interstate threats, and transporting a person over state lines for the purpose of prostitution. 

Over a seven-month period that started in August 2018, Okamura sent up to 20 people a day to the North Salt Lake residence of Walt Gilmore and his family. Service providers deliberately misled by Okamura included tow-truck company employees, plumbers, locksmiths, food delivery workers, electricians, and sex workers. 

Unwanted visitors turned up at the Gilmores’ home at all hours of the day and night. The problem became so bad that the family erected a sign in their front yard warning service providers about the scam and asking them to contact the police.

Okamura also sent Gilmore’s daughter threatening messages and leaked her picture and address online. In one email he warned her that she had better “sleep with one eye open and keep looking over your shoulder.”

The cyber-stalker’s actions caused Utah police to be sent out to the Gilmores’ residence more than 80 times over a four-month period from November 2018 to February 2019.

In July 2020, 45-year-old Okamura pleaded guilty to all charges in the case that North Salt Lake police described as “stalking on steroids” and “pretty vicious.”

Speaking via video conference at his sentencing, which took place in US district court in Utah on Thursday, Okamura apologized for his crimes against the Gilmore family. Okamura claimed that his actions were linked to the depression he had fallen into after his wife died.

“I would like to apologize for my actions,” Okamura said. “These events are not in my character. I’m looking to close my chapter and start a new chapter.”

In sentencing Okamura, the judge gave him credit for the nearly 12 months the cyber-stalker had spent in jail before being released in October 2020 after he accepted a plea deal. 

Okamura was sentenced to three years of supervision and ordered to abide by strict limitations when using the internet. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Rapid7 Source Code Accessed in Cyber-attack

Rapid7 Source Code Accessed in Cyber-attack

Source code and credentials belonging to cybersecurity company Rapid7 were accessed by an unauthorized third party during a supply-chain attack on Codecov.

Starting on January 31, hackers gained restricted access to hundreds of networks belonging to Codecov’s customers by tampering with one of the San Francisco–based company’s software development tools.

Codecov, whose customers include IBM and Hewlett-Packard, announced on April 15 that a malicious party had gained access to its Bash Uploader script and modified it.

“The actor gained access because of an error in Codecov’s Docker image creation process that allowed the actor to extract the credential required to modify our Bash Uploader script,” stated Codecov.

On its website, Codecov said it had put together a non-exhaustive lists of environment variables that were compromised in the attack. The company advises its customers to log in to their accounts “as soon as possible to see if you are in this affected population.”

On Thursday, Rapid7 announced that it was among the customers of the stricken firm to be impacted by the attack. 

“A small subset of our source code repositories for internal tooling for our MDR service was accessed by an unauthorized party outside of Rapid7,” stated the company.

“These repositories contained some internal credentials, which have all been rotated, and alert-related data for a subset of our MDR customers.”

Rapid7 added that no other corporate systems or production environments had been accessed in the security incident, and no unauthorized changes had been made to these repositories.

Customers of Rapid7 who were in turn impacted by the attack have been notified by the company. 

“Computer security companies are just regular companies. Some have better security than other companies, some not so much,” commented KnowBe4‘s Roger Grimes.

“I remember the first time a company I worked for did a security review of the source code of a far larger, very popular security company that nearly the whole world used at the time. You would think that their source code would be tight, error free. Instead, it had hundreds of security vulnerabilities. Simple, easy-to-see, security vulnerabilities.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ireland’s Healthcare System’s IT Offline Following Ransomware Attack

Ireland’s Healthcare System’s IT Offline Following Ransomware Attack

Ireland’s healthcare system is being subjected to a ransomware attack, which has led to its taking its IT systems offline and the cancellation of a number of hospital appointments.

HSE Ireland, the body responsible for the provision of health and personal social services for everyone living in Ireland, revealed the ongoing incident in a tweet this morning, stating: “There is a significant ransomware attack on the HSE IT systems. We have taken the precaution of shutting down all our IT systems in order to protect them from this attack and to allow us to fully assess the situation with our own security partners.

“We apologise for inconvenience caused to patients and to the public and will give further information as it becomes available.”

The organization stressed that COVID-19 vaccination services are not affected and will continue as normal, as will the operations of Ireland’s National Ambulance Service.

However, as a result of the attack, maternity care provider Rotunda Hospital in Dublin announced that it has cancelled all outpatient visits today, except for those who are 36 weeks pregnant or later.

Speaking to RTE’s Morning Ireland, HSE chief executive Paul Reid said the organization is working to contain a sophisticated human-operated ransomware attack on its IT systems, adding that the incident is impacting all national and local systems involved in all core services.

Discussing the news with Infosecurity, Brian Honan, CEO of BH Consulting, who is based in Ireland, gave his thoughts on HSE’s reaction to the incident: “I have to applaud the HSE’s response to this. Firstly, they announced that it was a ransomware attack so as to avoid any speculation and secondly they described the impact it had on their systems. Throughout the day the HSE has had several senior officials speak publicly and kept the public updated with what is going on. The reaction to shut down IT systems to protect them from any further compromise is also a very positive and proactive step to protect those systems, although it does mean the impact of the attack, the number of systems going offline, is large. The HSE has also engaged the Irish National Cyber Security Centre, the Irish Defence forces, and the Garda (Irish police) to deal with the attack.

“The next steps are to identify how the breach happened, close the gaps that allowed the attackers in, and then recover your systems from safe and secure backups. If they have no reliable backups then the choice is to pay the ransom or rebuild the data manually. It should be noted the HSE have stated they are not going to pay the ransom which is a stance that should be applauded.”

Honan went on to discuss the attack in the context of the current threat landscape. “It demonstrates that criminals have no conscience as they will attack a victim no matter what the victim is. To attack a health service and hospitals in the normal times is abhorrent, to do so during a pandemic is simply repulsive behavior by those behind these attacks.

“However, this attack and others is symptomatic of a problem that has been growing over the past years and will unfortunately continue to grow. Ransomware attacks are proving too lucrative for criminals to turn their backs on. Until recently the attacks have been seen as an IT problem, but attacking hospitals and critical infrastructure (the Colonial Pipeline attack last week) demonstrates that ransomware is a critical threat against our society, our economies and our lives and we need a coordinate response from governments to tackle this scourge.”

Also commenting on the story, Dean Ferrando, systems engineering manager (EMEA) at Tripwire, said: “Whenever we see an attack on healthcare services, it is always a serious concern because it can have a direct impact on the safety and lives of people. Given the increased cyber-attacks against healthcare organizations, it is simply no longer sufficient to merely be compliant with security frameworks. Remember, ransomware doesn’t just suddenly appear on systems. It has to get there through exploited vulnerabilities, phishing, or other means. While we tend to focus on the ransomware itself, the best way to avoid becoming a victim is to prevent the infection in the first place. And the best way to prevent ransomware infections is to address the infection vectors by hardening systems, patching vulnerabilities, ensuring systems are configured securely, and preventing phishing. Also, security training for all personnel is a critical element of any cyber-defense strategy.”

David Higgins, EMEA technical director at CyberArk, noted the huge damage attacks of this nature can have on healthcare: “The success of this ransomware campaign is concerning for so many reasons. Previous attacks such as WannaCry in 2017, which cost the NHS £92m and saw 19,000 appointments cancelled, are a stark reminder of the consequences this kind of cyber-attack can have. They’re callous, and what’s devastating is that they can lead to the loss of life.”

The new incident is the latest in a number of recent high-profile ransomware attacks, with use of this tactic surging during the past year. These include the ransomware attack on the East Coast Fuel pipeline in the US last week, following which it has been reported that the operator, Colonial Pipeline, paid a $5m ransom within hours of the incident.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Microsoft Alerts Aviation and Travel Firms to RAT Campaign

Microsoft Alerts Aviation and Travel Firms to RAT Campaign

Microsoft is warning the aerospace and travel sectors of a new targeted attack campaign aimed at stealing sensitive information from affected companies.

The tech giant said it had been tracking the “dynamic campaign” for several months via a series of spear-phishing emails designed to deliver an “actively developed loader.”

The screenshot posted to Microsoft Security Intelligence Twitter feed was of a phishing email spoofing a legitimate organization and requesting a quote for a cargo charter.

“An image posing as a PDF file contains an embedded link (typically abusing legitimate web services) that downloads a malicious VBScript, which drops the RAT payloads,” it explained.

These payloads are either RevengeRAT or AsyncRAT.

“The RATs connect to a C2 server on hosted on a dynamic hosting site to register with the attackers, and then uses a UTF-8-encoded PowerShell and fileless techniques to download three additional stages from pastebin[.]com or similar sites,” Microsoft said.

“The Trojans continuously re-run components until they are able to inject into processes like RegAsm, InstallUtil, or RevSvcs. They steal credentials, screenshots and webcam data, browser and clipboard data, system and network into, and exfiltrates data often via SMTP Port 587.”

The loader which drops the RATs was identified by Morphisec last week as a “highly sophisticated” crypter-as-a-service dubbed “Snip3.”

It features several methods of bypassing detection by security tools, including: the use of Pastebin and top4top for staging; recognition of Windows Sandbox and VMWare virtualization; executing PowerShell code with the “remotesigned” parameter; and compiling RunPE loaders on the endpoint in runtime.

Microsoft claimed its 365 Defender product detects multiple components of the attack, but urged organizations in the targeted sectors to check whether they’ve been affected. It published a list of hunting queries so organizations can check for similar activities, emails, implants and other indicators of attack.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Quarter of CISOs Self-Medicate as Pandemic Stress Spikes

Quarter of CISOs Self-Medicate as Pandemic Stress Spikes

An increase in work-related stress and a lack of paid leave opportunities during COVID-19 have raised concerns that some IT and security executives may be self-medicating to cope with the extra pressure.

Security vendor OneLogin polled 250 tech leaders across the globe to compile its IAMokay Mental Health Survey.

It found that over three-quarters (77%) believe the pandemic has increased workplace stress while 86% also reported an increase in workload. A quarter (25%) reported that they were being forced to undertake a “significant” amount of extra work.

On the positive front, three-quarters (74%) believe their organization cares about their mental health, and nearly half (49%) said their employer has provided access to mental health services.

However, more than half (54%) said they’ve been unable to take paid time off in the past six months, which can increase stress levels significantly.

A quarter (24%) admitted to having taken alcohol, narcotics or prescription medication in the past to alleviate stress. Those in construction (54%), education (41%), professional services (33%) and financial services (33%) are most likely to have done so, according to OneLogin.

“Historically, business has been preoccupied with efficiency, while sacrificing human relationships. On some level, this perspective may have worked in the past, but times have changed,” argued Robin Massey, an industrial organizational psychologist cited in the study.

“What we know is the current state of the body influences behaviors, feelings and thinking. Therefore, it is important to understand how physiological factors are interrelated with the relational and psychological.”

The findings chime with a Nominet study from 2019 which revealed that 91% of UK and US CISOs suffer moderate or high stress, over a quarter (27%) said this is impacting their mental or physical health and 17% admitted turning to medication or alcohol as a result.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Colonial Reportedly Paid $5 Million Ransom

Colonial Reportedly Paid $5 Million Ransom

Ransomware surged 102% year-on-year at the start of 2021 as it emerged that Colonial Pipeline agreed to pay $5 million to extorters after a crippling attack that began last week.

The East Coast fuel pipeline was offline for five days after an attack struck last Thursday. However, contrary to initial reports that it refused to engage with the DarkSide threat group, the company actually paid within hours of the attack, two people familiar with the matter told Bloomberg.

It’s unclear whether the payment was funded by the company’s cyber-insurance policy. Such efforts have come under criticism of late for perpetuating the ransomware epidemic.

In fact, global insurer AXA recently revealed that it would no longer reimburse customers for payments to ransomware groups, although the new rules are restricted to France.

“In my opinion, the biggest factor at play here is the feedback loop of malicious activity created by surrendering and paying the ransom. This allows the groups to achieve a greater level of sophistication during their next attacks, whether that be via training, new tooling, purchasing credentials, or recruitment,” argued Mitch Mellard, principal threat intelligence analyst at Talion.

“Feeding this industry only ensures that they become collectively more of a threat in the long run, facilitating more breaches, more payments, and thus the cycle continues.”

The news comes as new figures from Check Point revealed that the number of ransomware victims it is monitoring has soared 102% year-on-year in the year-to-date.

The most heavily targeted sector in April was healthcare, with average weekly attacks during the month hitting nearly 110, followed by utilities (59) and insurance/legal (34).

The security vendor urged organizations to be particularly watchful near weekends and holidays when many attacks take place. It urged the use of behavior-based detection tools, prompt patching, user education and threat hunting for malware commonly used in initial access attacks.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk