Hades Ransomware Linked to Hafnium and Exchange Attacks

Hades Ransomware Linked to Hafnium and Exchange Attacks

Security experts have linked the Hades ransomware operation to the Hafnium state-backed group that was behind early attacks on Microsoft Exchange servers.

The ransomware crew was responsible for attacks on trucking giant Forward Air and a handful of others. It has been linked to infamous Russian cybercrime operation Evil Corp (Indrik Spider), as a new variant of its WasterdLocker ransomware, designed to help the group escape sanctions that would discourage victims to pay up.

However, a new report from Awake Security claims to have found a domain used for command-and-control in a Hades attack in December 2020, just before the zero-day Exchange server attacks were discovered.

“Our team was pulled in after the compromise and encryption to review the situation and in this one case a Hafnium domain was identified as an indicator of compromise within the timeline of the Hades attack,” explained Awake Security VP, Jason Bevis.

“Moreover, this domain was associated with an Exchange server and was being used for command-and-control in the days leading up to the encryption event.”

He claimed there are two possibilities: an advanced threat actor is operating under the guise of Hades, or multiple independent groups coincidentally compromised the same environment, due to poor security.

Other findings mark Hades out as an unusual ransomware group. Very few victims have been identified, and most seem to come from manufacturing sectors.

Bevis also noted “very little sophistication” in the leak sites set up by the group, with its Twitter account, a page on Hackforums, and Pagebin and Hastebin pages all subsequently removed.

“As incident responders know it is common for ransomware actors to set up leak sites for their data, but what was interesting about Hades is that they used methods for both their leaks and their drop sites that would likely be taken down within a very short time,” he argued.

“We know the actor requested amounts in the range of $5 to $10m of ransom and was very slow to respond to some individuals. In some cases, they may not have responded at all. In fact, one Twitter user even claimed ‘TA never responds.’ If there were only a few organizations attacked, why would it take so long to respond to requests for ransom? Was there another potential motive here? Why haven’t we seen Hades since?”

Bevis also noted that the data leaked on the sites is far less impactful than the information the group has actually stolen, which relates to detailed manufacturing processes.

The report also pointed to remnants of activity from the TimosaraHackerTerm (THT) ransomware group in some Hades victim environments a few weeks prior to the latter’s attacks. These include use of Bitlocker or BestCrypt for encryption, connection to a Romanian IP address and use of VSS Admin to clear shadow copies of the local machine.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#IMOS21: Infosecurity Magazine Spring Online Summit Now Available On-Demand

#IMOS21: Infosecurity Magazine Spring Online Summit Now Available On-Demand

Last week (March 23 and 24) Infosecurity Magazine hosted its annual Spring Online Summit – a two-day virtual event showcasing 14 live, CPE-accredited sessions moderated by the Infosecurity editorial team, featuring an array of experts and thought-leaders discussing various topics and issues currently impacting the information security industry.

Infosecurity is delighted to announce that the full event is now available to watch on-demand via the Infosecurity website.

The immersive education program includes keynote presentations from industry leaders Javvad Malik and Wendy Nather, along with presentations on DevSecOps culture, the evolving power of AI in security and the key principles of bug bounty programs.

Further sessions include panel discussions on:

  • Home to Office: A CISO’s Guide to Securing Hybrid Working Environments
  • Establishing a Cybersecurity Culture of Inclusion
  • Ransomware Everywhere: Understanding Attack Evolution
  • How Hackers Used and Abused the Pandemic to Profit
  • Putting People First: Dealing with Team Burnout and Mental Health
  • The Scourge of Dis- and Misinformation in 2021
  • And more!

If you have not already registered for/viewed the latest Online Summit, or if you want to watch any of it again again, all content is now available to watch back anytime, anywhere via Infosecurity’s on-demand feature!

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK’s CNI Security Threatened by Staff Burnout

UK’s CNI Security Threatened by Staff Burnout

The security of the UK’s transport, energy and other critical national infrastructures (CNI) could be threatened by staff burnout and IT skills shortages, according to new research from cybersecurity services company Bridewell Consulting.

The firm discovered that, in the last year, 85% of IT decision-makers working to protect Britain’s infrastructure have felt increased pressure to improve cybersecurity controls. Of those, 47% have suffered unsustainable stress, 41% have been absent because of burnout, 32% are looking for another job and 28% have resigned, Bridewell Consulting claimed.

Meanwhile, a lack of skilled and knowledgeable IT staff continues to add to the pressures felt by CNI security teams, the research found, with 84% of those polled believing there will be a critical cybersecurity skills shortage in the CNI sector in the next three to five years.

The findings make for concerning reading, particularly given the prevalence and potentially serious implications of IT security incidents on CNI. As many as 86% of CNI organizations detected cyber-attacks in the last year and 93% of these experienced at least one successful attack.

Scott Nicholson, Co-CEO at Bridewell, said: “Cybersecurity experts are a vital first line of defense but stress and burnout seem to be seriously affecting individuals’ wellbeing. The prospect of people leaving jobs as a result is particularly worrying at a time when the threat of attacks is so high. Ultimately, cybersecurity isn’t just an IT or OT issue – it’s a business issue. Tackling it as such will result in the strongest, most effective teams, equipped with the right tools to keep our infrastructure safe.”

The findings from Bridewell Consulting come just a few days after Forcepoint released similar research about the security implications of staff stress and burnout. In said research, it was discovered that the pressures of remote working and caregiving during the COVID-19 pandemic have taken a significant psychological toll on UK employees, leading to risky behaviors online which could expose employers to cyber-threats.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

German MPs Hit by Russian-Backed Phishing Attacks

German MPs Hit by Russian-Backed Phishing Attacks

German lawmakers have been targeted once again by phishing attacks reportedly linked to Russian intelligence services.

Local reports claimed yesterday that seven members of the Bundestag and 31 members of the state parliament had their inboxes compromised, although these appear to have been personal rather than official accounts.

The phishing emails were spoofed to appear as if urgent messages sent by providers GMX and T-Online.

The politicians belong to governing parties the CDU/CSU and SPD.

Political activists in Hamburg and Bremen were also attacked, according to Der Spiegel.

It’s unclear whether any sensitive information was leaked as a result of the attacks. The report claimed that the campaign has been attributed to a GRU-linked group known as “Ghostwriter.”

Ghostwriter operations in the past have been mainly focused on creating and disseminating online propaganda designed to turn people, especially in eastern Europe and the Baltic, against the US and NATO.

Previous fake news stories created by the group included the supposed desecration of a Jewish cemetery by German NATO soldiers in Lithuania, and a Lithuanian child that had been ‘run over’ by a NATO tank.

The group also uses photos, fabricated letters and other documents to try and add legitimacy to its outlandish claims.

The attack on the lawmakers calls to mind a 2015 raid by suspected Russian hackers that resulted in the loss of 16GB of data, after Trojan malware was implanted on parliamentary computers.

German politicians have also been snooped on in the past by NSA eavesdroppers, according to reports.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Aussie TV Network Taken Off Air by Ransomware

Aussie TV Network Taken Off Air by Ransomware

An Australian TV network was taken off-air for over 24 hours by suspected state-backed attackers, in what it described as the largest attack on a media company in the country’s history.

Production systems at the Sydney-headquartered Nine Network, currently the country’s top-rated network, went offline early on Sunday morning, its own news site reported this morning.

Although some shows are back on air, the channel’s news and current affairs output has been significantly affected by the attack.

All staff have reportedly been ordered to work from home indefinitely while the firm deals with the fall-out.

“Our IT teams are working around the clock to fully restore our systems, which have primarily affected our broadcast and corporate business units. Publishing and radio systems continue to be operational,” said Nine Entertainment’s people and culture director, Vanessa Morley, in an email.

The latest report from the network’s online news site claimed that ransomware was used but no ransom has yet been demanded, indicating that state-backed players may be responsible.

This evening, the network is set to broadcast a warts-and-all expose of Russian President Vladimir Putin’s use of poison to murder overseas dissidents. However, there’s no firm evidence as yet to link the attacks back to the Kremlin.

China is also currently in a tense stand-off with Australia. It has levied unilateral tariffs on Australian products in response to Aussie blocks on Chinese investment in sensitive areas and calls for an investigation into the origin of COVID-19.

The attack on Nine Network came just hours after Parliament House was hit by a suspected ransomware attack which forced local technicians to cut IT access. The outage continued for over 30 hours from Saturday lunchtime, local time, with the attack targeted at an external service provider, according to reports.

Parliamentary staff were also sent an alert on Sunday night about a phishing scam over WhatsApp.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Protect Your Digital Wellness: Don’t Post Your Vaccination Card Online

Protect Your Digital Wellness: Don’t Post Your Vaccination Card Online 

Think Twice Before Posting Your Vaccination Card on Social Media

After much anticipation, you finally get a notification that you’re eligible to receive your COVID-19 vaccine. Upon getting your first dose, you may be eager to celebrate by sharing a picture of your vaccination card on social media. After all, many of your peers have been doing the same. However, these posts could actually put your online privacy and personal information at risk. While you want to share the good news, experts warn that scammers could potentially exploit the information on your card.

How Vaccine Selfies Could Affect Your Online Security

With more people becoming eligible to receive the COVID-19 vaccine, there has been a surge in social media posts featuring peoples’ vaccine cards. However, the Better Business Bureau stated that posting photos of your card can give criminals the data they need to create and sell fake vaccination cards. Not only do vaccine cards remind you of when your next appointment is, but they also contain important personal information such as your name, date of birth, and when and where you were vaccinated.

Currently, these cards are the only proof that people have that they’ve been vaccinated. While there is still uncertainty around the next phase of the pandemic and when life will return to “normal,” it’s possible these cards could be what gets you into a restaurant or on an airplane. If you post your vaccination card on social media, scammers could potentially forge your card and use it as their own pass into public places or use it to receive a second dose. Publicly posting medical information could also void your HIPAA protections. Furthermore, cybercriminals could significantly profit from your personal information since health care records sell for more than Social Security and credit card numbers on the dark web.

Protect Your Digital Wellness

Your digital wellness is just as important as your physical wellness, so protecting your online data is crucial. It’s a good rule of thumb not to post photos with your name and other identifiable information on the internet. Although it may be tempting to post your vaccination card on social media, consider these tips to help protect your online security:

1. Check your privacy settings

Think about who you want to share the good news with and what social media platform would be best for this. Create private groups or carefully select which followers can see your posts. Then, verify that you’ve updated your privacy settings accordingly. This will prevent scammers from lurking on your posts and extracting your personal information.

2. Find alternatives to share that you’re vaccinated

Instead of posting a photo of your vaccine card, share a picture of yourself outside the vaccination center. If your vaccination center provides “I got vaccinated” stickers, you can post a picture of that as well.

Taking steps towards protecting your digital well-being is just as important as taking steps towards protecting your physical health. By following these steps, you can help ensure that your online security will not be jeopardized by celebrating your vaccination.

Stay Updated

 To stay updated on all things McAfee and on top of the latest consumer and mobile security threats, follow @McAfee_Home on Twitter, subscribe to our email, listen to our podcast Hackable?, and ‘Like’ us on Facebook.

 

 

The post Protect Your Digital Wellness: Don’t Post Your Vaccination Card Online appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk