McAfee: COVID-19 Themed Attacks Continue to Surge

McAfee: COVID-19 Themed Attacks Continue to Surge

COVID-19 themed cyber-attacks increased by 114% in Q4 2020 compared to Q3, according to data from the McAfee Threats Report: April 2021. This followed rises of 605% and 240% in Q2 and Q3 2020 respectively, demonstrating that threat actors have continued to leverage the pandemic to target organizations and individuals.

The study, which looked at the evolving threat landscape in the final quarter of 2020, found there was a 10% overall rise in malware detections in Q4 compared to Q3, reaching an average of 648 threats per minute.

There was a particularly large surge in Powershell threats in Q4 compared to Q3, up by 208%, which McAfee said was largely driven by Donoff malware. Additionally, mobile malware grew by 118% quarter-on-quarter, partly due to a growth in SMS Reg samples. The HiddenAds, Clicker, MoqHao, HiddenApp, Dropper and FakeApp strains were the most commonly detected mobile malware families.

There was also a significant increase in ransomware attacks in Q4, up by 69%. This was driven by Cryptodefense, with REvil, Thanos, Ryuk, RansomeXX and Maze groups the most common families detected, according to the data.

The technology sector was heavily targeted during Q4 of 2020, with McAfee observing a 100% rise in publicly reported cyber-incidents against this industry. A similar rate of increase (93%) was seen in the public sector.

This report also highlighted the most common MITRE ATT&CK techniques used by cyber-criminals in Q4. These included System Information Discovery, Obfuscated Files or Information, File and Directory Discovery, Data Encryption for Impact, Stop Services, Process Injection, Process Discovery, Masquerading Techniques and Exploits of Public Facing Applications.   

Raj Samani, McAfee fellow and chief scientist commented: “The world—and enterprises—adjusted amidst pandemic restrictions and sustained remote work challenges, while security threats continued to evolve in complexity and increase in volume.

“Though a large percentage of employees grew more proficient and productive in working remotely, enterprises endured more opportunistic COVID-19 related campaigns among a new cast of bad-actor schemes. Furthermore, ransomware and malware targeting vulnerabilities in work-related apps and processes were active and remain dangerous threats capable of taking over networks and data, while costing millions in assets and recovery costs.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Destructive Attacks Surged in 2020 for Financial Institutions

Destructive Attacks Surged in 2020 for Financial Institutions

Cyber-attacks against global financial institutions are increasingly characterized by attempts to counter incident response, with destructive efforts surging 118% over the past year, according to VMware.

The tech giant’s Modern Bank Heists 4.0 report was compiled from interviews with over 120 CISOs and security leaders from some of the world’s biggest banks.

It revealed that attackers are becoming increasingly adept at circumventing incident responders — in fact, counter incident response happened 63% of the time over the past year.

This includes activities such as blocking events from hitting SIEM systems, disabling security tools, clearing logs, manipulating time stamps and deploying destructive malware and wipers.

More than half (54%) of respondents said they experienced destructive attacks over the past year.

Elsewhere, supply chain attacks are also on the rise as threat actors look for easier ways to bypass corporate security.

Nearly two-fifths (38%) of respondents said they’d experienced an increase in so-called island hopping, where a supplier is attacked en route to a bigger target. This figure was itself a 13% increase on last year.

As for the end goal of attacks, it appears to be wire transfer fraud, recorded by 57% of respondents, and insider trading. On the latter, 41% of financial institutions said they’d experienced an increase in brokerage account takeovers, enabling attackers to gather intel to make strategic financial bets.

Even more (51%) said they’d experienced attacks targeting non-public information, which again could be used to provide intel for trades.

VMware had several recommendations for security teams including: integrating network detection and endpoint protection; conducting weekly threat hunting exercises; deploying workload security; and using deception practices.

It also urged incident response teams to spend more time monitoring after an attack is discovered, to understand all avenues of entry used by the threat actors. Agents should be deployed in monitor-only mode and renamed to something innocuous to ensure attackers don’t catch on and change their tactics, VMware added.

Tom Kellermann, head of cybersecurity strategy at VMware’s Security Business Unit, argued that organized cybercrime gangs continue to evolve their tactics.

“These groups have become national assets for the nation-states who offer them protection and power. In tandem with this, we’ve seen traditional crime groups digitize over the past year as the pandemic hampered them from conducting business as usual,” he added.

“This has popularized the industry of services provided by the dark web, increased collaboration between cybercrime groups, and ensured cyber cartels are now more powerful than their traditional organized crime counterparts.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Name:Wreck Bugs Could Impact 100M IoT Devices

Name:Wreck Bugs Could Impact 100M IoT Devices

Security experts have discovered a new set of DNS vulnerabilities which could impact over 100 million IoT devices used by consumers and enterprises.

Forescout teamed up with Israeli consultancy JSOF to uncover nine vulnerabilities they have labelled Name:Wreck.

They affect popular IT software FreeBSD and IoT/OT firmware IPnet, Nucleus NET and NetX. Forescout claimed that, although not all devices running the software are vulnerable, even if just 1% were, that could impact as many as 100 million globally.

In the UK alone it is estimated that around 36,000 could be affected.

The bugs themselves enable either remote code execution or denial of service, with sectors including government, enterprise, healthcare, manufacturing and retail at risk.

Plausible but hypothetical scenarios include attackers exploiting the flaws to extort payments from victim organizations by sabotaging critical functions in manufacturing plants, hospitals, hotels and retail facilities.

Threat actors could also monetize attacks by using exploits to access enterprise and government networks, with an eye on data theft.

The report urged organizations running vulnerable devices to limit their network exposure via segmentation, and to rely more on internal DNS servers.

It also recommended patching, although this can be a challenge for IoT/OT devices running on mission critical systems that can’t be taken offline, or which rely on legacy applications.

Forescout Research Labs research manager, Daniel dos Santos, warned that the Name:Wreck bugs have the potential to cause significant and widespread disruption.

“Unless urgent action is taken to adequately protect networks and the devices connected to them, it could be just a matter of time until these vulnerabilities are exploited, potentially resulting in major government data hacks, manufacturer disruption or [compromise of] hotel guest safety and security,” he added.

Patches are now available for FreeBSD, Nucleus NET, and NetX.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Food Shortages at Dutch Supermarkets After Ransomware Outage

Food Shortages at Dutch Supermarkets After Ransomware Outage

There were empty shelves at branches of the Netherlands’ largest supermarket chain recently after a ransomware attack on a key logistics supplier.

With over 1000 locations around the country, Albert Heijn is an industry giant. Yet the supermarket firm suffered major food shortages after the cyber-attack on key supplier Bakker Logistiek, according to local reports.

Among the foodstuffs most affected by the attack were deliveries of packaged cheese. A note on the Albert Heijn website currently warns of a “technical malfunction” affecting supplies.

“The logistics service provider is working hard to solve the problem as quickly as possible and to quickly restore availability. We apologize for the inconvenience,” it notes.

The attack itself occurred over the Easter weekend and forced Bakker Logistiek to return to pen and paper as IT pulled the plug on digital systems.

That meant orders were not coming in or being fulfilled in warehouses, as the whole process is usually highly automated for maximum efficiency.

Cheese deliveries were reportedly held up for three days, creating a backlog of orders and supermarket shortages.

Bakker Logistiek spokesperson, Toon Verhoeven, said the firm had worked hard to get systems back online over the past week and that stocks were finally being shipped.

He refused to speculate on whether the ransomware actors had been paid or not, claiming that the case is now with the police.

According to one report, he claimed the attackers may have gained an initial foothold inside the network after compromising a Microsoft Exchange Server — exploiting the infamous ProxyLogon vulnerability. However, there’s no official confirmation on this yet.

A December report from non-profit the Identity Theft Resource Center (ITRC) claimed that financially motivated cyber-criminals are increasingly eschewing traditional data breaches in favor of ransomware and Business Email Compromise (BEC) — as these attacks have a bigger and better ROI.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk