APT31 Fingered for Cyber-Attack on Finnish Parliament

APT31 Fingered for Cyber-Attack on Finnish Parliament

An advanced persistent threat group (APT) with links to the Chinese government has been blamed for a cyber-espionage attack on Finland’s parliament. 

The Finnish Security and Intelligence Service (Supo) announced on Thursday that APT31 was behind a cyber-espionage campaign that targeted the Finnish parliament last fall

Security companies including Checkpoint and FireEye have linked APT31’s activities with the state cyber-operations of the People’s Republic of China. 

“Supo identified a state-run cyber espionage operation targeted last year against the parliament with the aim of intruding into its IT systems,” stated the service. “According to Supo intelligence, APT31 was responsible for the attack.”

A number of parliamentary email accounts were compromised in the attack, which was detected by the legislature’s internal technical surveillance. The National Bureau of Investigation (NBI) said at the time that some accounts belonging to MPs were impacted.

In a statement released March 18, the NBI said that while the investigation into the cyber-attack was ongoing, police had “found some indications of possible perpetrators.”

“We are investigating links to the APT31 group, but we will not disclose any details about the facts discovered as the criminal investigation is ongoing,” said Detective Superintendent Tero Muurman of the NBI.

Muurman said that the motive of the attack was still being determined. 

“We have not excluded the possibility that the purpose of the attack was to gather intelligence to benefit a foreign state or to harm Finland’s interests,” he said.

Muurman added that while the attack was a big deal on a national scale, when contemplated from an international perspective, it was not unusual. 

“This is an unfortunate situation for the victims and, given the nature of the institution attacked, the incident is exceptional in Finland,” said Muurman. 

“However, globally speaking, it is not so unique as similar incidents are discovered worldwide every now and then.”

Since the attack, Supo said that the parliament has taken steps to improve its information security. 

Speaker of Parliament Anu Vehviläinen (Cen) said: “When the suspected crimes in an investigation are aggravated espionage, aggravated burglary, and aggravated breach of confidentiality, everyone understands how serious the matter is.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Protective Intelligence Honors Launched

Protective Intelligence Honors Launched

The Ontic Center for Protective Intelligence has launched a new monthly honor program to recognize the pioneers and thought leaders driving the physical security and protection industry. 

Each month, the program will recognize groundbreaking professionals who have developed either new models or new areas of knowledge, and veteran practitioners who are actively contributing to advancing their industry. 

Among the inaugural trailblazers recognized by the center’s new Protective Intelligence Honors program is the founder and president of Hetherington Group, a cyber investigations consulting, publishing, and training firm. 

Since starting her career as a librarian in the early 1990s, Cynthia Hetherington has led national and international investigations in corporate due diligence and fraud, personal asset recovery, and background checks for more than 25 years. 

Her investigations, which have included the top two Ponzi cases in United States history, have recovered millions of dollars in high-profile corruption cases. 

Hetherington, who specializes in the financial, pharmaceutical, and telecommunications industries, has authored three books on how to carry out investigations. 

Describing how she would like to see physical security evolve in the next decade, Hetherington said: “It’s critical to create clearly defined programs for faster outcomes to prevent violence or danger to our clients.”

In 2015, Hetherington founded the OSMOSIS Institute, which hosts the annual OSMOSIS conference at which hundreds of investigators complete training and gain insights into open source intelligence. She is also the founder of industry newsletter “Data2know: Internet & Online Intelligence.”

Since 1998, she has trained over 180,000 corporate security professionals, accountants, auditors, military intelligence professionals, attorneys, and federal, state, and local agencies in online intelligence best practices. 

“Failure of imagination leads to most disasters, thinking that it’s impossible they might occur. We are honoring the men and women whose remarkable vision, insight, courage and leadership have kept countless lives safe and are influencing an industry shift to a proactive, always-on physical security approach in the public and private sectors,” said Fred Burton, executive director of the Ontic Center for Protective Intelligence. 

“The impact of these honorees on history, how we conduct our lives today and the future cannot be overstated, and we are indebted to them for all they have done and continue to do to keep us from harm.” 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

ESET Exposes Malware Disguised as Clubhouse App

ESET Exposes Malware Disguised as Clubhouse App

ESET has uncovered malware designed to leverage the growing popularity of invite-only social media app Clubhouse.

Revealing its findings in a blog post, the cybersecurity firm said the Trojan malware aims to steal users’ login information for a variety of online services. Disguised as an Android version of the audio chat app (which does not current exist), it is capable of taking credentials for over 450 apps and is also able to bypass SMS-based two factor authentication (2FA).

In the scheme, users are tricked into downloading the fake app from a website that has the look and feel of the genuine Clubhouse website. Once the malware, nicknamed “BlackRock,” is downloaded onto a device, it can set about stealing login details for 458 online services. The online services targeted include Twitter, WhatsApp, Facebook, Amazon, Netflix, Outlook, eBay, Coinbase, Plus500, Cash App, BBVA and Lloyds Bank.

BlackRock uses an overlay attack to try and steal the victim’s credentials whenever one of the targeted applications is launched. Following the overlay, the user is requested to login, unwittingly handing over their credentials to the attackers.

Worryingly, the malware can also intercept text messages, meaning SMS-based 2FA will not necessarily help. Additionally, the malicious app asks the victim to enable accessibility services, which would allow the cyber-criminals to effectively take control of the device.

ESET malware researcher Lukas Stefanko said: “The website looks like the real deal. To be frank, it is a well-executed copy of the legitimate Clubhouse website. However, once the user clicks on ‘Get it on Google Play’, the app will be automatically downloaded onto the user’s device. By contrast, legitimate websites would always redirect the user to Google Play, rather than directly download an Android Package Kit, or APK for short.”

Commenting on the research, Tom Lysemose Hansen, CTO at app security company Promon outlined: “It was only a matter of time before malicious actors capitalized on the growing demand for Clubhouse to release an Android app. This is a classic case of malware, once downloaded onto the device, using a system of overlays to steal login credentials from a list of targeted applications. The convincing nature of the website and the fact that the malware is able to steal login credentials from more than 450 apps and bypass SMS-based two-factor authentication, makes this extremely concerning.”

He added: “Smartphone users (and Android users in particular) should be on the lookout for common tell-tale signs that indicate a website is not legitimate. These can include not being secure (if the webpage starts with HTTP instead of HTTPS) or if the domain looks strange (in this case it was .mobi instead of .com used by the legitimate website).”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Russian Man Pleads Guilty in Tesla Extortion Plot

Russian Man Pleads Guilty in Tesla Extortion Plot

A Russian national has pleaded guilty to his role in a conspiracy to extort motoring giant Tesla via data-stealing ransomware.

Egor Igorevich Kriuchkov, 27, pleaded guilty to one count of conspiracy to intentionally cause damage to a protected computer and is expected to be sentenced on May 10.

The case itself first broke last August, after Tesla boss Elon Musk cited a news report on the story, tweeting: “Much appreciated. This was a serious attack.”

According to court documents, Kriuchkov travelled first from Russia to California and then made numerous subsequent trips to Nevada in August 2020. His mission was to entice a Tesla employee there to participate in the scheme.

However, the employee — who is said to be a Russian-speaking non-US citizen — reported Kruichkov to his managers, who then contacted the FBI.

The end goal was apparently to install data-stealing ransomware from the inside, with which to extort Tesla out of millions of dollars. The insider was reportedly offered $1 million for his help in the conspiracy.

Kriuchkov is said to have initially contacted the unnamed employee via WhatsApp, before meeting him socially several times from August 1-3, including during a trip to Lake Taho with other Tesla employees. The Russian reportedly gave the insider a burner phone and told him to leave it in airplane mode until the funds were transferred.

The DoJ statement on the case doesn’t mention ransomware but instead focuses on the data theft element of the plot.

“This case highlights our office’s commitment to protecting trade secrets and other confidential information belonging to US businesses — which is becoming even more important each day as Nevada evolves into a center for technological innovation,” said acting US attorney Christopher Chiou for the District of Nevada.

“Along with our law enforcement partners, we will continue to prioritize stopping cyber-criminals from harming American companies and consumers.”

Given the audacity of the conspiracy and the willingness of Kruichkov to recruit an insider face-to-face, there are suspicions that current or former state operatives could have been involved.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Website Builders Take Hands-Off Approach to Fake News

Website Builders Take Hands-Off Approach to Fake News

Fewer than a third of companies offering website creation tools took down potentially harmful misinformation about COVID-19, according to a new study from Website Planet.

The web building resource deliberately created outlandish fake news in paid-for accounts with seven of the most popular CMS providers: Weebly, Jimdo, GoDaddy, Webnode, Squarespace, WordPress and Google Sites.

This included deliberately eye-catching conspiracy theories such as that COVID-19 is a man-made virus or biological weapon, and others that claimed vaccination is ineffective or dangerous.

The same content was used for each site, and the “about us” sections presented the websites’ owners as “truth seekers and experts” without any evidence.

Website Planet then reached out to each website builder to flag the misinformation. Disappointingly, despite many having policies that explicitly prohibited fake news, or at least harmful information, just two out of the seven took down the offending content.

Jimdo and Weebly took action swiftly, although in the latter’s case without informing the individual who made the complaint.

Squarespace and WordPress said they would investigate, but no action was taken at the time of writing. In Squarespace’s case the firm has a clear policy prohibiting “false, fraudulent, inaccurate or deceiving content,” although WordPress takes a more hands-off approach, stating effectively that content is the customer’s responsibility.

GoDaddy and Webnode wrote back to say they would not be taking the offending content down. In the former’s case it claimed that “as a hosting provider, it is not our place to determine if the site you have mentioned is actually engaging in illegal activities.”

Webnode claimed the misinformation was not an obvious misuse of its services.

Google Sites did not reply to the researchers at all. Although its Abuse Program Policies section has an entire section devoted to fake news, there was no relevant drop-down misinformation category to select when reporting abuse, according to the report.

The inconsistent response by these tech firms contrasts the activities of the major social networks such as Facebook and Twitter, which are actively removing misinformation on COVID-19.

“People often invoke the First Amendment to argue that they should be able to say whatever they want with no consequences – but that’s a misinterpretation,” argued Website Planet.

“Freedom of speech does not mean that anyone can say anything, regardless of its effects. You can’t go around threatening, defaming, or otherwise endangering people through your words. And there’s a big difference between censoring content that doesn’t serve one’s personal interests and restricting content that heightens a public health risk.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK’s CEOs Commit to Cyber Spending After Pandemic

UK’s CEOs Commit to Cyber Spending After Pandemic

Over two-thirds of UK-based CEOs plan to increase long-term cybersecurity budgets, with many expressing increasing concerns over the risk of online threats to the business, according to PwC.

The global consulting giant interviewed nearly 1800 business leaders in the UK as part of a global survey of CEOs.

Its 24th annual UK CEO Survey revealed the major impact the pandemic has had on decision-making at the apex of the country’s private sector organizations.

The number reporting concerns over cyber-threats increased from 80% last year to 91%, while almost half (48%) said they were “extremely concerned” about the threat posed by cyber-risk to business growth.

PwC claimed these changing responses were influenced heavily by the rapid shift to support remote working and push more services online in the early days of the crisis. These efforts enabled attackers to find new gaps in protection which allowed them to flourish.

Trend Micro claimed to have blocked 20% more threats last year — an average of 119,000 per minute globally. Threat actors targeted distracted home workers using unsecured devices and networks, as well as vulnerabilities in remote working infrastructure such as VPNs, and RDP endpoints whose passwords were previously breached or easy to crack.

“As the criticality of technology has increased over the past year, so have UK CEOs’ fears of cyber security threats. This heightened concern is understandable as the stakes are so much higher than they were 12 months ago,” argued PwC cybersecurity leader, Chris Gaines.

“Businesses have become more aware of how reliant on technology they are for their very survival, and as such the risk of cybersecurity attacks naturally weighs more heavily on their minds.”

The criticality of cybersecurity is clear from the study: respondents selected cyber as the number one threat which is factored into their strategic risk management activities, above “pandemics and other health crises” and “uncertain economic growth.”

As a result, a majority of the UK’s CEOs are responding to these challenges by committing more investment to cyber and data privacy over the coming three years.

“Securing an enterprise is far more than ensuring the CIO builds the right technical controls. It is about simplifying the organization to be securable. It is about assessing, understanding and managing the cyber risk impact of every business decision,” concluded Gaines.

“It is also about recognizing that much of cybersecurity risk originates from vulnerabilities outside their organization.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk