Dutch Insider Attack on COVID-19 Data

Insider data theft:

Dutch police have arrested two individuals on Friday for allegedly selling data from the Dutch health ministry’s COVID-19 systems on the criminal underground.

[…]

According to Verlaan, the two suspects worked in DDG call centers, where they had access to official Dutch government COVID-19 systems and databases.

They were working from home:

“Because people are working from home, they can easily take photos of their screens. This is one of the issues when your administrative staff is working from home,” Victor Gevers, Chair of the Dutch Institute for Vulnerability Disclosure, told ZDNet in an interview today.

All of this remote call-center work brings with it additional risks.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Arrest, Seizures Tied to Netwalker Ransomware

U.S. and Bulgarian authorities this week seized the darkweb site used by the NetWalker ransomware cybercrime group to publish data stolen from its victims. In connection with the seizure, a Canadian national suspected of extorting more than $27 million through the spreading of NetWalker was charged in a Florida court.

The victim shaming site maintained by the NetWalker ransomware group, after being seized by authorities this week.

NetWalker is a ransomware-as-a-service crimeware product in which affiliates rent access to the continuously updated malware code in exchange for a percentage of any funds extorted from victims. The crooks behind NetWalker used the now-seized website to publish personal and proprietary data stolen from their prey, as part of a public pressure campaign to convince victims to pay up.

NetWalker has been among the most rapacious ransomware strains, hitting at least 305 victims from 27 countries — the majority in the United States, according to Chainalysis, a company that tracks the flow virtual currency payments.

“Chainalysis has traced more than $46 million worth of funds in NetWalker ransoms since it first came on the scene in August 2019,” the company said in a blog post detailing its assistance with the investigation. “It picked up steam in mid-2020, growing the average ransom to $65,000 last year, up from $18,800 in 2019.”

Image: Chainalysis

In a statement on the seizure, the Justice Department said the NetWalker ransomware has impacted numerous victims, including companies, municipalities, hospitals, law enforcement, emergency services, school districts, colleges, and universities. For example, the University of California, San Francisco paid $1.4 million last summer in exchange for a digital key needed to unlock files encrypted by the ransomware.

“Attacks have specifically targeted the healthcare sector during the COVID-19 pandemic, taking advantage of the global crisis to extort victims,” the DOJ said.

U.S. prosecutors say one of NetWalker’s top affiliates was Sebastien Vachon-Desjardins, of Gatineau, in Ottawa, Canada. An indictment unsealed today in Florida alleges Vachon-Desjardins obtained at least $27.6 million from the scheme.

The DOJ’s media advisory doesn’t mention the defendant’s age, but a 2015 report in the Gatineau local news website ledroit.com suggests this may not be his first offense. According to the story, a then-27-year-old Sebastien Vachon-Desjardins was sentenced to more than three years in prison for drug trafficking: He was reportedly found in possession of more than 50,000 methamphetamine tablets.

The NetWalker action came on the same day that European authorities announced a coordinated takedown targeting the Emotet crimeware-as-a-service network. Emotet is a pay-per-install botnet that is used by several distinct cybercrime groups to deploy secondary malware — most notably the ransomware strain Ryuk and Trickbot, a powerful banking trojan.

The NetWalker ransomware affiliate program kicked off in March 2020, when the administrator of the crimeware project began recruiting people on the dark web. Like many other ransomware programs, NetWalker does not permit affiliates to infect systems physically located in Russia or in any other countries that are part of the Commonwealth of Independent States (CIS) — which includes most of the nations in the former Soviet Union. This is a prohibition typically made by cybercrime operations that are coordinated out of Russia and/or other CIS nations because it helps minimize the chances that local authorities will investigate their crimes.

The following advertisement (translated into English by cybersecurity firm Intel 471) was posted by the NetWalker affiliate program manager last year to a top cybercrime forum. It illustrates the allure of the ransomware affiliate model, which handles everything from updating the malware to slip past the latest antivirus updates, to leasing space on the dark web where affiliates can interact with victims and negotiate payment. The affiliate, on the other hand, need only focus on finding new victims.

We are recruiting affiliates for network processing and spamming.
We are interested in people whose priority is quality and not quantity.
We prefer candidates who can work with large networks and have their own access to them.
We are going to recruit a limited number of affiliates and then close the openings until they are available again.

We offer you prompt and flexible ransomware, a user-friendly admin panel in Tor, an automated service.

Encryption of shared accesses: if several users are logged in to the target computer, the ransomware will infect their mapped drives, as well as network resources where those users are logged in — shared accesses/NAS etc.

Powershell build. Each build is unique, in that the malware is inside the script – it is not downloaded from the internet. This makes bypassing antivirus protection easier, including Windows Defender (cloud+).

A fully automated blog where the victim’s dumped data is directed. The data is published according to your settings. Instant and automated payouts: initially 20 percent, no less than 16 percent.

Accessibility of a crypting service to avoid AV detections.

The ransomware has been in use since September 2019 and proved to be reliable. The files encrypted with it cannot be decrypted.

Targeting Russia or the CIS is prohibited.

You’ll get all the information about the ransomware as well as terms and conditions after you place an application via PM.

Application form:
1) The field you specialize in.
2) Your experience. What other affiliate programs have you been in and what was your profit?
3) How many accesses [to networks] do you have? When are you ready to start? How many accesses do you plan on monetizing?

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

International Action Targets Emotet Crimeware

Authorities across Europe on Tuesday said they’d seized control over Emotet, a prolific malware strain and cybercrime-as-service operation. Investigators say the action could help quarantine more than a million Microsoft Windows systems currently compromised with malware tied to Emotet infections.

First surfacing in 2014, Emotet began as a banking trojan, but over the years it has evolved into one of the more aggressive platforms for spreading malware that lays the groundwork for ransomware attacks.

In a statement published Wednesday morning on an action dubbed “Operation Ladybird,” the European police agency Europol said the investigation involved authorities in the Netherlands, Germany, United States, the United Kingdom, France, Lithuania, Canada and Ukraine.

“The EMOTET infrastructure essentially acted as a primary door opener for computer systems on a global scale,” Europol said. “Once this unauthorised access was established, these were sold to other top-level criminal groups to deploy further illicit activities such data theft and extortion through ransomware.”

Experts say Emotet is a pay-per-install botnet that is used by several distinct cybercrime groups to deploy secondary malware — most notably the ransomware strain Ryuk and Trickbot, a powerful banking trojan. It propagates mainly via malicious links and attachments sent through compromised email accounts, blasting out tens of thousands of malware-laced missives daily.

Emotet relies on several hierarchical tiers of control servers that communicate with infected systems. Those controllers coordinate the dissemination of second-stage malware and the theft of passwords and other data, and their distributed nature is designed to make the crimeware infrastructure more difficult to dismantle or commandeer.

In a separate statement on the malware takeover, the Dutch National police said two of the three primary servers were located in the Netherlands.

“A software update is placed on the Dutch central servers for all infected computer systems,” the Dutch authorities wrote. “All infected computer systems will automatically retrieve the update there, after which the Emotet infection will be quarantined. Simultaneous action in all the countries concerned was necessary to be able to effectively dismantle the network and thwart any reconstruction.”

A statement from the German Federal Criminal Police Office about their participation in Operation Ladybird said prosecutors seized 17 servers in Germany that acted as Emotet controllers.

“As part of this investigation, various servers were initially identified in Germany with which the malicious software is distributed and the victim systems are monitored and controlled using encrypted communication,” the German police said.

Sources close to the investigation told KrebsOnSecurity the law enforcement action included the arrest of several suspects in Europe thought to be connected to the crimeware gang. The core group of criminals behind Emotet are widely considered to be operating out of Russia.

A statement by the National Police of Ukraine says two citizens of Ukraine were identified “who ensured the proper functioning of the infrastructure for the spread of the virus and maintained its smooth operation.”

A video released to YouTube by the NPU this morning shows authorities there raiding a residence, seizing cash and computer equipment, and what appear to be numerous large bars made of gold or perhaps silver. The Ukrainian policeman speaking in that video said the crooks behind Emotet have caused more than $2 billion in losses globally. That is almost certainly a very conservative number.

Police in the Netherlands seized huge volumes of data stolen by Emotet infections, including email addresses, usernames and passwords. A tool on the Dutch police website lets users learn if their email address has been compromised by Emotet.

But because Emotet is typically used to install additional malware that gets its hooks deeply into infected systems, cleaning up after it is going to be far more complicated and may require a complete rebuild of compromised computers.

The U.S. Cybersecurity & Infrastructure Security Agency has labeled Emotet “one of the most prevalent ongoing threats” that is difficult to combat because of its ‘worm-like’ features that enable network-wide infections.” Hence, a single Emotet infection can often lead to multiple systems on the same network getting compromised.

It is too soon to say how effective this operation has been in fully wresting control over Emotet, but a takedown of this size is a significant action.

In October, Microsoft used trademark law to disrupt the Trickbot botnet. Around the same time, the U.S. Cyber Command also took aim at Trickbot. However, neither of those actions completely dismantled the crimeware network, which remains in operation today.

Roman Hüssy, a Swiss information technology expert who maintains Feodotracker — a site that lists the location of major botnet controllers — told KrebsOnSecurity that prior to January 25, some 98 Emotet control servers were active. The site now lists 20 Emotet controllers online, although it is unclear if any of those remaining servers have been commandeered as part of the quarantine effort.

A current list of Emotet control servers online. Source: Feodotracker.abuse.ch

Further reading: Team Cymru on taking down Emotet

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Syntax Releases First IT Trends Report

Syntax Releases First IT Trends Report

Multi-cloud and multi-ERP managed cloud services provider Syntax released its first ever “IT Trends Report” today.

The report is based on an October 2020 survey of 500 IT leaders and decision makers in the US who were asked to describe how the COVID-19 pandemic had impacted their businesses and to share the strategic decisions they plan to make in 2021.

The majority of those with in-house security teams (83%) said that they are considering outsourcing security efforts to a managed service provider (MSP) in 2021. However, 91% of respondents said that they employ either their own security operations center (SOC) or in-house security talent. 

Shrinking budgets had an impact on team size, with 79% of IT leaders reporting that they had to reduce team headcounts due to budget cuts in 2020. 

Over three-quarters of companies (77%) reported experiencing increasingly frequent cyber-attacks when the pandemic started.

“The pandemic has presented unparalleled challenges for businesses of all industries and sizes,” said Marc Caruso, chief architect of Syntax. 

“Despite the challenges of accelerated digital transformation timelines, this year has provided many lessons for IT and business leaders. One of the most important being the optimization of the best management and security practices for our cloud-native future of working-from-anywhere.”

More than half (56%) of the IT leaders said that they will allocate more than 40% of their IT budget to cybersecurity in 2021. Additionally, 37% listed “improving cybersecurity protections” as a top IT investment this year.

The report found that data analytics had been pushed onto the back burner in 2020, with 42% of IT leaders reporting the deprioritization of this and other business intelligence initiatives. In what could be show of optimism over what 2021 may hold, more than half (55%) said they are planning to increase investments in this space in 2021 as they leverage growing repositories of data to drive business decisions. 

Christian Primeau, global CEO of Syntax, doesn’t expect the monumental shift to remote working practices wrought by the pandemic to be permanent. 

He said: “When we return to our pre-pandemic environments, IT teams will increasingly rely on MSPs and third-party partners to support more aspects of IT governance, including cybersecurity, application management, disaster recovery, cloud migration, and more.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Hacker Admits Targeting Major US Websites

Hacker Admits Targeting Major US Websites

A hacker who became the first ever Cypriot national to be extradited to the United States has pleaded guilty to extorting major American website operators with stolen user data. 

Joshua Polloso Epifaniou was a teenager when he started hacking into websites, stealing information, and threatening to release it if he didn’t receive a ransom. 

The 21-year-old resident of Nicosia, Cyprus, was arrested by Cypriot authorities in February 2018. In July last year, Epifaniou was extradited to the US to face charges in both Georgia and Arizona. 

According to US authorities, between at least October 2014 and November 2016, Epifaniou searched website traffic rankings to identify targets to extort. He then worked with co-conspirators to steal personally identifiable information from user and customer databases belonging to victim websites. 

Among the websites hit by Epifaniou were a free online game publisher based in California, a New York City hardware company, an online employment website headquartered in Virginia, a consumer report website headquartered in Phoenix, and a sports news website based in Atlanta, Georgia, and owned by Turner Broadcasting System Inc.

To steal data, Epifaniou either directly exploited security vulnerabilities in the victim websites or obtained a chunk of data from a co-conspirator who had hacked into the victim network.

Epifaniou then used proxy servers located in foreign countries to log into online email accounts and send messages to victims demanding a ransom payment in crypto-currency to prevent the stolen data being leaked. 

On January 25, the Northern District of Georgia announced that Epifaniou had pleaded guilty to accessing multiple major websites based in the United States without authorization, stealing user data, and demanding that the website operators pay a ransom to prevent his release of the data. 

“This conviction represents the determination of FBI investigators to hold cyber criminals accountable for extorting US companies and citizens no matter where they may be hiding,” said Chris Hacker, special agent in charge of FBI Atlanta.

Prior to the plea, Epifaniou paid nearly $600,000 in restitution to the victims. He also agreed to forfeit an additional $389,113 and nearly 70,000 euros to the government in his plea agreement.

Sentencing is scheduled for March 3, 2021.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Twitter Asks Users to Police Misinformation

Twitter Asks Users to Police Misinformation

Social media giant Twitter has launched a new pilot scheme in the United States to tackle the spread of misinformation.

Under the new Birdwatch scheme, users are invited to identify information in other people’s tweets they think is misleading and write notes that “provide informative context.”

Twitter said it believes that a community-driven approach in which users monitor each other and provide a free fact-checking service will allow more content to be flagged as misinformation. 

“We apply labels and add context to Tweets, but we don’t want to limit efforts to circumstances where something breaks our rules or receives widespread public attention,” said the company in a blog post yesterday.  

For now, any notes that are made will not show up on Twitter but will only be visible on a separate Birdwatch site where pilot participants can rate the helpfulness of notes added by other contributors. 

“Eventually we aim to make notes visible directly on Tweets for the global Twitter audience, when there is consensus from a broad and diverse set of contributors,” said Twitter. 

All data contributed to Birdwatch will be publicly available and downloadable in TSV files. When fully fledged, Birdwatch will be powered by algorithms based on the reputations of the contributors and “consensus systems.”  

A computer will rank the notes made on tweets according to how helpful they are. 

Commenting on the pilot scheme’s introduction, Twitter user @morganiswizard wrote: “So let me get this straight, you’re trying to stop random people from spreading misinformation by letting other random people decide what misinformation is? ok.”

Another Twitter user, Ben Collins, said that he was worried how the Birdwatch scheme would work in the open internet.

“The big thing I’m worried about with Birdwatch? Brigading,” said Collins. “Say one extremist forum really hates one true tweet by a specific user. They all sign up en masse and drown out good info.

“As this rolls out to more people, I don’t see a defense against that.”

He added: “Long term, Twitter wants to take the labeling of harmful lies out of the mouth of a faceless team at the company and give it to the community.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Dr Gary McGraw Appointed to IriusRisk Threat Modeling Technical Advisory Board

Dr Gary McGraw Appointed to IriusRisk Threat Modeling Technical Advisory Board

Application security threat modeling solutions provider IriusRisk has announced the appointment of Dr Gary McGraw to its threat modeling technical advisory board.

Dr McGraw – who has a PhD in computer science and cognitive science – joins existing advisor Adam Shostack and will assist in the strategic direction and development of the AppSec firm. The board’s aim is to accelerate IriusRisk’s efforts to push threat modeling to the forefront of the security agenda.

“As a field, software security has made impressive progress over the last two decades,” said Dr McGraw. “Now it is time to automate what we know about security engineering, threat modeling and architectural risk analysis. IriusRisk is leading the charge to take software security to the next level.”

Speaking on Dr McGraw’s appointment, Shostack commented: “I’m excited to be working with Gary to expand the board. The incredible brain trust that IriusRisk is building to help shape product strategy is going to be hard to match.”

IriusRisk CEO Stephen de Vries has stated additional plans to expand the advisory board further and welcomed interest from the wider security community to accelerate threat modeling as a common industry best practice within security and development teams.

“We are privileged to have two of the pioneers in software security on our advisory board so that our customers can benefit from their experience in implementing threat modeling and architectural security programs in large engineering teams,” he added.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Mastercard Introduces Quantum-Resistant Specs to Enhance Contactless Security

Mastercard Introduces Quantum-Resistant Specs to Enhance Contactless Security

Credit card firm Mastercard has unveiled new quantum-resistant standards that are designed to enhance the security and privacy of contactless payments.

As a result of the move, Mastercard will become the first payments network to bring quantum-era security and privacy to contactless payments. The Enhanced Contactless (Ecos) specifications have been introduced following a surge in contactless payments over the past year, fuelled by the desire for more hygienic payment methods in-store as a result of the COVID-19 pandemic. Mastercard revealed that contactless penetration made up 41% of in-person purchase transactions globally in the third quarter of 2020, a year-on-year rise of 30%.

Ecos will enable the utilization of new quantum-resistant technology in order to deliver advances in algorithms and cryptography. Convenience will be maintained as contactless interactions will remain under half a second, and Mastercard said that, in time, any device can become a payment device without the need for a backup swipe or dip of a card.

The specifications also aim to enhance privacy by offering advanced protection when account information is shared between the card or digital wallet and checkout terminal.

The firm added that the Ecos specifications will enable merchants, financial institutions and customers to make such security transitions seamlessly over the coming years, with digital wallets, mobile payments, contactless cards and point-of-sale terminals continuing to work as they do today. This is because Ecos is implemented via a software upgrade without the need for new hardware of terminals.

Ajay Bhalla, president, cyber and intelligence at Mastercard, commented: “Contactless is the present and future of in-person payments. 2020 brought with it a rapid acceleration of digitization and reinforced the importance of digital solutions – like contactless – to help meet our everyday needs. As the ecosystem continues to evolve, more connected devices and the Internet of Things (IoT) are going to create more user demand and an even greater need for constant innovation to build next-generation capability, helping to ensure that technology never outpaces trust.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

TikTok Bug Gave Access to Contacts’ Profile Details

TikTok Bug Gave Access to Contacts’ Profile Details

Researchers have discovered a vulnerability in TikTok which could have allowed attackers to harvest users’ phone numbers and personal profile details.

Check Point revealed today that the flaw, which has now been fixed by the popular social network, was found in the app’s “Find Friends” feature.

The problem stems from the fact that TikTok allows users to sync their phone contacts with the app, thus connecting user profiles with phone numbers.

If exploited, the flaw could have allowed attackers to bypass the app’s HTTP message signing to login, and then sync contacts to discover the profiles of all the TikTok users in the victim’s phone book.

Worse still, the SMS log-in process from a mobile device involved TikTok servers generating a token and session cookies, but these did not expire for 60 days, meaning an attacker could use the same cookies to login for weeks.

Among the profile details exposed by the vulnerability are TikTok nickname, profile and avatar pictures, unique user IDs and settings including whether a user is a follower or if a user’s profile is hidden.

Check Point head of products vulnerabilities research, Oded Vanunu, said his team was curious to see if the TikTok platform could be used to gain access to private user data. 

“We were able to bypass multiple protection mechanisms of TikTok, that led to privacy violation. The vulnerability could have allowed an attacker to build a database of user details and their respective phone numbers,” he explained.

“An attacker with that degree of sensitive information could perform a range of malicious activities, such as spear phishing or other criminal actions. Our message to TikTok users is to share the bare minimum, when it comes to your personal data, and to update your phone’s operating system and applications to the latest versions.”

A TikTok statement recognized the work of “trusted partners” like Check Point in making the platform safer for users.

“We continue to strengthen our defenses, both by constantly upgrading our internal capabilities such as investing in automation defenses, and also by working with third parties,” it added.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk