Police Have Disrupted the Emotet Botnet

A coordinated effort has captured the command-and-control servers of the Emotet botnet:

Emotet establishes a backdoor onto Windows computer systems via automated phishing emails that distribute Word documents compromised with malware. Subjects of emails and documents in Emotet campaigns are regularly altered to provide the best chance of luring victims into opening emails and installing malware ­ regular themes include invoices, shipping notices and information about COVID-19.

Those behind the Emotet lease their army of infected machines out to other cyber criminals as a gateway for additional malware attacks, including remote access tools (RATs) and ransomware.

[…]

A week of action by law enforcement agencies around the world gained control of Emotet’s infrastructure of hundreds of servers around the world and disrupted it from the inside.

Machines infected by Emotet are now directed to infrastructure controlled by law enforcement, meaning cyber criminals can no longer exploit machines compromised and the malware can no longer spread to new targets, something which will cause significant disruption to cyber-criminal operations.

[…]

The Emotet takedown is the result of over two years of coordinated work by law enforcement operations around the world, including the Dutch National Police, Germany’s Federal Crime Police, France’s National Police, the Lithuanian Criminal Police Bureau, the Royal Canadian Mounted Police, the US Federal Bureau of Investigation, the UK’s National Crime Agency, and the National Police of Ukraine.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#RSAC365: #COVID19 Fundamentally Altered Global Attack Surface

#RSAC365: #COVID19 Fundamentally Altered Global Attack Surface

Speaking at the RSAC 365 Virtual Summit Jason Rivera, director, Strategic Threat Advisory Group at CrowdStrike, explored how the COVID-19 health crisis has fundamentally altered the attack surface for organizations across the world.

“We had to use the internet so much more than we ever have in the past. If we use the internet more, then we have a larger, more complex attack surface. That in turn allows adversaries opportunities they did not have before.”

Rivera outlined three distinct ways in which the attack surface has changed in the post-pandemic world when compared to before the health crisis began.

The first concerns internal factors, he continued. Pre-COVID, internal assets such as critical workloads/endpoints, applications and data were contained within defined network boundaries. Transition to remote working has resulted in an exponential increase of exposure to internal assets, implying additional emphasis on defending workloads and endpoints.

The second factor Rivera referred to concerns network perimeters. Pre-COVID, in-person workplaces were largely reliant on firewalls, physical appliances, email gateway and network security solutions. Post-COVID, remote working requirements have forced the mass use of VPN and RDP technologies, which place greater strain on perimeter security.

The third factor cited by Rivera was that of external factors. Pre-COVID, there was a clear differentiation between internal and external environments with an internet characterized by ‘normal’ levels of traffic. Post-COVID, there has been increased reliance on cloud capabilities, blurring the lines between internal and external assets, whilst internet traffic has grown exponentially.

Rivera outlined how, as companies were faced by such issues, adversaries levied tactics designed specifically to exploit pandemic-induced attack surface changes.

“Our adversaries have demonstrated their capability to rapidly adapt,” he said, with web distribution, situational phishing, remote desktop exploitation and COVID-themed lures all proving to be common themes.

Attackers, both of a criminal and state-sponsored nature, have also shifted techniques from big game ransomware hunting, data theft and fraud, national security/economic espionage and internal influencing to ransom-as-a-service, data extortion, themed downloaders and epidemiological tech and decision making throughout the course of the pandemic, Rivera explained.

Addressing how organizations can defend against the heightened cyber-risks brought about by the pandemic, Rivera said it is a “situation of evolve or get left behind,” proposing four key areas of evolution to focus on:

  1. Decrease reliance on the idea of securing a defined a perimeter
  2. Prioritize simplicity and adaptability
  3. Evolve from reactive to proactive measures
  4. Prepare the workforce for the “new normal”

To conclude, Rivera said: “Your ability to defeat cyber-threats rests almost entirely on your understanding of the [security] problem[s]” your organization faces.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Emotet Disrupted Through Global Action

Emotet Disrupted Through Global Action

Infamous botnet Emotet has been brought down by an international law enforcement operation.

Earlier today, Europol announced that Emotet’s infrastructure had been taken over by investigators in a coordinated action by authorities in Canada, France, Germany, Lithuania, the Netherlands, the United Kingdom, the United States, and Ukraine, with international activity coordinated by Europol and Eurojust.

First discovered as a banking trojan in 2014, the malware evolved into a powerful tool used by cyber-criminals the world over to gain unauthorized access to computer systems. Emotet’s creators—APT group TA542—offered the malware for hire to other cyber-criminals, who used it to install other malware, such as banking trojans or ransomware, onto a victim’s computer.

“EMOTET was much more than just a malware,” said Europol. “Its unique way of infecting networks by spreading the threat laterally after gaining access to just a few devices in the network made it one of the most resilient malwares in the wild.” 

The botnet’s infrastructure was supported by several hundred servers located across the world, all with different functionalities. While some were dedicated to managing infected computers or spreading the malware to new victim devices, others were set up to serve criminal groups and thwart takedown attempts.

“It is hard to overstate the significance of the achievement announced by Europol today in bringing the EMOTET botnet offline,” said Nominet CISO Cath Goulding. “It will have immediate effect from a cyber security perspective, with EMOTET consistently ranking as one of the most persistent threats facing individuals and organizations.”

Vectra CEO and president Hietsh Sheth welcomed the news of Emotet’s takedown but cautioned that it was long overdue. 

“The result here is gratifying, but the havoc EMOTET wreaked across numberless networks in seven years is alarming,” said Sheth. 

“None of us know how many malware cousins of EMOTET are doing more damage right now, but if each takes seven years to neutralize, we will remain in perpetual crisis,” he added. 

Digital Shadows threat researcher Stefano De Blasi expects Emotet’s operators to bounce back from this blow to their operations.

“Malicious botnets are exceptionally versatile, and it is likely that their operators will sooner or later be able to recover from this blow and rebuild their infrastructure—just like the TrickBot operators did,” said De Blasi.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#RSAC365: Will Recent Treasury Guidance Reduce Ransomware Payments in the US?

#RSAC365: Will Recent Treasury Guidance Reduce Ransomware Payments in the US?

The ways organizations should react following a ransomware attack were discussed during a session at the RSAC 365 Virtual Summit.

This topic was highlighted in context of an advisory issued in October 2020 by the US Department of the Treasury concerning the payment of ransomware. Adam Hickey, deputy assistant attorney general, National Security Division, Department of Justice, explained that “essentially it reminds the audience that if you engage in transactions with a sanctioned entity or person, you can be civilly liable, and the Treasury has the authority to bring an enforcement action even if you didn’t know what you were doing.”

This advisory covers malicious actors that have been designated under the scope the Office of Foreign Assets Control (OFAC)’s cyber-related sanctions program, including Cryptolocker, SamSam, WannaCry 2.0 and Dridex. Hickey added that it outlines factors that will impact the Treasury’s judgement on whether a penalty is appropriate. This includes “whether the US company or entity had a risk-based compliance program in place, designed to identify and mitigate sanctions risk” and also if the victim “reached out to law enforcement and was transparent with them.”

While some have viewed this as harsh on ransomware victims, Hickey said the guidance is aimed more towards the intermediaries that may be relied on to make a ransomware payment, such as insurance firms and forensic companies, helping ensure they develop risk-based compliance programs.

Such a strict approach is necessary amid rising ransomware attacks to make all online users safer, according to Hickey.  He commented: “As an individual entity you may be better off paying the ransom, but all of us are worse off if you do because with every dollar that goes to the ransomware operator, it expands the market for it, making it more profitable, and ensures that there will be more ransomware in the future.”

However, Stewart Baker, counsel at legal firm Steptoe & Johnson LLP, was not convinced this approach will be effective in its overall aim of deterring ransomware gangs, and may simply serve to inflict additional burdens on organizations already reeling from an attack. He noted that while the advisory may be primarily aimed at the facilitators of payments and helps make that clear, the reality remains that “if you pay it you are clearly subject to liability under OFAC.”

With many businesses, such as those with inadequate backups, often left with little choice but to pay ransoms, Baker commented that “all it really does simply add to the pain the victim suffers and I’m not sure it’s going to affect the people who are serving ransomware,” adding that he has not seen any evidence that ransomware actors are even deterred from using old tools and techniques on the cyber-related sanctions program.

Nevertheless, Hickey believes the message the guidance sends out is important because encouraging paying ransoms is inherently worse for everyone, especially if it is conducted by rogue nation state actors such as North Korea and Iran that may use any payments to help fund terrorist activities. He also hopes it will encourage organizations to better protect themselves against such attacks. “Fortunately there are ways victims can protect themselves to some degree from ransomware, like backups,” he outlined.

Hickey concluded by stating it is always best for companies in such a position to inform law enforcement and be open and transparent about the situation. “Even if you think paying the ransom is the only option, it could leave you less secure in the future, because there’s no guarantee that the bad actor is going to pull every tool you have off your network – if you pay once why wouldn’t you pay again?” he said.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Insurers Defend Covering Ransomware Payments

UK Insurers Defend Covering Ransomware Payments

Insurance providers in the United Kingdom have defended the inclusion of ransomware payments in first-party cyber-insurance policies.

Cyber-risk insurance covers the cost of restoring loss to business income or reputation caused by damage to computers and computer networks.

The Association of British Insurers (ABI) said that while insurance was “not an alternative” to taking appropriate action to minimize risk, firms could suffer financial ruin without cyber coverage. 

The ABI comments were made in response to a warning issued earlier this week by the UK’s former National Cyber Security Centre director Professor Ciaran Martin. Speaking to The Guardian, Martin said that insurers who pay out claims from companies who have paid ransoms to cyber-attackers to regain access to systems and data are funding organized crime. 

Martin, who stepped down from his position as Britain’s top cybersecurity official last August, expressed concern that ransomware attacks were “close to getting out of control.”

Extortion laws in the UK prohibit the payment of ransoms to terrorists; however, no legal barriers are in place to stop companies from paying ransomware gangs to retrieve exfiltrated data and system access following a cyber-attack. 

“People are paying bitcoin to criminals and claiming back cash. I see this as so avoidable,” said Martin. 

“At the moment, companies have incentives to pay ransoms to make sure this all goes away. You have to look seriously about changing the law on insurance and banning these payments, or at the very least, having a major consultation with the industry.”

He added: “The law is nobody’s fault, it was written for another purpose, but it has become OK to pay out to criminals.”

An ABI spokesperson told the BBC that insurers do require customers to take “reasonable precautions” to prevent cyber-attacks from occurring. 

“Some might argue that any insurance that covers against a criminal act could lull the policyholder into a false sense of security,” they said.

Martin, who now works at Oxford University’s Blavatnik School of Government, told the BBC: “I have some sympathy with insurers, because as long as it’s legal, there are incentives to pay.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Grindr Faces $11.7m Data Privacy Fine

Grindr Faces $11.7m Data Privacy Fine

The world’s largest social networking and dating app for gay, bisexual and trans people is facing a hefty fine in Norway over an alleged breach of data privacy. 

On Tuesday, Norway’s Data Protection Authority (NDPA) announced its intention to fine Grindr 100 million Norwegian crowns ($11.7m) for illegally disclosing user data to advertising firms.

The American company, which launched back in 2009, said that the allegations made by the Norwegian regulator hark back to 2018, when Grindr had different privacy policies and practices in place.

The large financial penalty corresponds to approximately 10% of Grindr’s estimated global annual revenue.

“Our preliminary conclusion is that Grindr has shared user data to a number of third parties without legal basis,” said Bjørn Erik Thon, data protection commissioner of the NDPA.

The Norwegian Consumer Council filed a complaint against Grindr last year, accusing the company of unlawfully sharing the personal data of app users with third parties for marketing purposes. User information allegedly shared included user profile data, GPS location, and the fact that the user was on Grindr.

In the advance notification of an administrative fine issued to Grindr, Thon wrote that the NDPA had received three complaints from the Norwegian Consumer Council (NCC) in January 2020 regarding the company’s data practices.

The complaints addressed concerns on the data sharing between Grindr and its advertising partners Twitter, Xandr, OpenX Software, AdColony, and Smaato.

An investigation into the complaints found that to use the app, users were forced to accept Grindr’s privacy policy in its entirety and were not asked specifically if they wanted to consent to the sharing of their data with third parties. 

“Grindr is seen as a safe space, and many users wish to be discrete. Nonetheless, their data have been shared with an unknown number of third parties, and any information regarding this was hidden away,” said Thon.

Grindr has 13.7 million active users, of which thousands reside in Norway. The company has been given until February 15, 2021, to comment on the NDPA’s findings.

The NCC also filed complaints against five of the third parties receiving data from Grindr: MoPub (owned by Twitter), Xandr, OpenX Software, AdColony, and Smaato. These cases are ongoing.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Global Public-Private Partnerships Key to Fighting Cybercrime

Global Public-Private Partnerships Key to Fighting Cybercrime

The importance of public-private engagement on a global scale in combatting cybercrime was discussed during a virtual Microsoft security briefing.

Opening the discussion, Amy Hogan-Burney, general manager, digital crimes unit at Microsoft, highlighted how the cyber-threat landscape has evolved since the start of the COVID-19 pandemic. While the tactics used by cyber-criminals have not altered significantly as they were already operating in the digital space, the shift to remote working has made it easier to target organizations.

Additionally, cyber-criminals have been able to leverage the evolving nature of the COVID-19 crisis to ensure common techniques such as phishing are more effective. “There’s definitely a common theme that, if there is a geo-political issue, then cyber-criminals will use that in order to target individuals and specifically people working from home,” said Hogan-Burney.

Craig Jones, director of cybercrime at Interpol, observed that attacks such as phishing, which entice users to click on malicious links, have been more likely to succeed when COVID-related lures are utilized. “There’s the human factor in all this,” he explained. “That’s us – the communities who click on those links and want that information and to understand what’s going on.”

Both speakers revealed they are now seeing cyber-criminals looking to take advantage of the very topical issue of vaccine rollouts. Hogan-Burney said: “The first thing we’re going to see is the social engineering aspect that’s always prevalent in cybercrime in order to gain access to systems.” Jones added that criminals are starting to use counterfeit vaccines and certificates to trick people, noting that those living in poorer areas will be especially vulnerable to such techniques. “Those that do not have access to the vaccine will want to get hold of it through whatever means,” he stated.

In this increasingly dangerous landscape, the need for law enforcement agencies to work across borders and with multiple private entities has grown substantially. Honan-Burney said that “criminals frankly don’t care where we’re located, they don’t care about geographic borders and they don’t care about where their victims are or where their infrastructure is except for is it effective.” She continued: “So, to a certain extent, we have to do the same thing, and say it doesn’t matter that I’m sitting in the US, the actor is in Nigeria and the victims are around the world; we have to work together.”

Jones agreed, highlighting that the investigation of cybercrime often requires law enforcement agencies to gain access to data from numerous different organizations. “You might have one company that only sees one small part of it and we have to start aggregating that,” he explained.

Private companies working with law enforcement in this way is still a relationship that requires fine-tuning, and Honan-Burney noted that each have different goals which can create “friction” at times. For example, a primary goal of Microsoft is to ensure users have safe access to technology, and this sometimes means the company proactively takes down infrastructure used by criminals. “That methodology also means we are taking things that law enforcement would use to collect evidence,” she admitted.

Nevertheless, she believes co-ordination now between companies like Microsoft and law enforcement is improving, as there is growing recognition of the importance of bringing cyber-criminals to justice to enhance digital security over the long-term. “That criminal goes on to perpetrate crime, so I am more than happy that we do appropriate criminal referrals so that we can help,” commented Hogan-Burney.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Growing Digital Adoption Providing Extra Opportunities for Cyber-Criminals

Growing Digital Adoption Providing Extra Opportunities for Cyber-Criminals

Increased digital adoption since the start of COVID-19 is leaving consumers more vulnerable to cyber-attacks, according to McAfee’s 2021 Consumer Security Mindset Report.

The analysis found that Brits across all age groups have embraced new digital solutions amid ongoing social distancing restrictions. Nearly three-quarters purchased at least one connected device in 2020 and one in five brought at least three. However, more than half (56%) did not adopt or purchase any additional security solutions last year, while almost two-thirds (65%) said they have never considered the value of their data stored online.

There was also a significant increase in the amount of data shared online, with 71% of Brits using digital features designed for convenience for the first time in 2020, including text and email notifications (39%) and paperless transaction records (37%).

Amongst the ‘boomer’ generation, aged 55-74, over half (52%) revealed they have either introduced or increased their use of digital tools to adopt their social lives, including the use of social media. Close to half (46%) began or increased their use of online banking, with 82% stating they would continue to do so beyond COVID-19. Encouragingly, this group were more vigilant on security than any other, with over half (52%) “always” checking if the software on their devices is up-to-date.

Those aged 19-34 also ramped up their use of digital solutions, with 65% starting to, or increasing online shopping, while 53% grew their use of online banking. However, this generation were weakest on security, with 28% admitting they have never checked if their device software is up-to-date.

Terry Hicks, EVP of McAfee’s Consumer Business, commented: “The first step in protecting ourselves is realizing that there’s a lot we can do to stay safe online and to preserve our digital wellness. Yet, there’s a long way to go for British consumers.

“It’s important to remember that we can always work on our own safe online habits – from the apps we install, to the websites we click on, to the emails we open. Making this shift in our mindset and behaviors is a necessity in protecting what we value most – our privacy and identity – giving Brits much needed peace of mind as they continue their digital adoption.”

Reflecting on the rise in online banking last year, Adam Philpott, EMEA president, McAfee, added: “The pandemic has forced many changes that we expect to stick even after the restrictions lift, whether this is the way we shop or the way we look after our money. Services like online banking empower the consumer to manage their finances at any given moment, but this also comes with an abundance of potential risks and threats if the correct procedures aren’t put in place.

“With the UK public’s increasing reliance on digital banking, financial services organizations need to protect and educate their customers on how best to protect their finances and personal data. This will be especially important for customers using online banking for the first time.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

More Security Vendors Admit to SolarWinds Attacks

More Security Vendors Admit to SolarWinds Attacks

Several more cybersecurity vendors have revealed that they were attacked by the same threat actors that compromised SolarWinds, although there appears to have been minimal if any impact on customers.

Mimecast revealed a couple of weeks ago that a “sophisticated threat actor” obtained one of its certificates used to authenticate Mimecast products to Microsoft 365 (M365) Exchange Web Services, in a bid to compromise customers’ M365 tenants.

In an update yesterday, the email security vendor confirmed that this incident was related to the suspected Russian state espionage campaign centered around the compromise of SolarWinds Orion software.

However, most customers affected by this have already broken and then re-established connections with new keys, and Microsoft has disabled use of the old keys.

“Our investigation also showed that the threat actor accessed, and potentially exfiltrated, certain encrypted service account credentials created by customers hosted in the US and the UK. These credentials establish connections from Mimecast tenants to on-premises and cloud services, which include LDAP, Azure Active Directory, Exchange Web Services, POP3 journaling and SMTP-authenticated delivery routes,” it continued.

“Although we are not aware that any of the encrypted credentials have been decrypted or misused, we are advising customers hosted in the US and UK to take precautionary steps to reset their credentials.”

Also yesterday, Fidelis Cybersecurity released a blog post explaining that it had installed an evaluation copy of the Trojanized SolarWinds Orion software on one of its machines last May. However, the machine was not running in its production environment, limiting the impact.

“Our current belief, subject to change given additional information, is that the test and evaluation machine where this software was installed was sufficiently isolated and powered up too infrequently for the attacker to take it to the next stage of the attack,” explained CISO Chris Kubic.

Another security vendor, Qualys, sent a statement to Infosecurity explaining that, in a similar way to Fidelis, it isolated the malware-laden Orion software in a test environment.

“As part of our standard research and engineering process our researchers downloaded and installed the impacted version of SolarWinds Orion software in a sandbox environment for evaluation,” it said.

“This sandbox environment is completely segregated from our production and customer data environments. Our security team conducted a detailed investigation and has confirmed there was no impact on our production environment.”

FireEye, CrowdStrike, Malwarebytes, Microsoft and Palo Alto Networks have all previously revealed how they were targeted by the attack group.

The revelations point to the sheer scale and audacity of the attackers, but also a reassuring willingness on the part of affected vendors to share any learnings with the wider cybersecurity community.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk