Sophisticated Watering Hole Attack

Google’s Project Zero has exposed a sophisticated watering-hole attack targeting both Windows and Android:

Some of the exploits were zero-days, meaning they targeted vulnerabilities that at the time were unknown to Google, Microsoft, and most outside researchers (both companies have since patched the security flaws). The hackers delivered the exploits through watering-hole attacks, which compromise sites frequented by the targets of interest and lace the sites with code that installs malware on visitors’ devices. The boobytrapped sites made use of two exploit servers, one for Windows users and the other for users of Android

The use of zero-days and complex infrastructure isn’t in itself a sign of sophistication, but it does show above-average skill by a professional team of hackers. Combined with the robustness of the attack code — ­which chained together multiple exploits in an efficient manner — the campaign demonstrates it was carried out by a “highly sophisticated actor.”

[…]

The modularity of the payloads, the interchangeable exploit chains, and the logging, targeting, and maturity of the operation also set the campaign apart, the researcher said.

No attribution was made, but the list of countries likely to be behind this isn’t very large. If you were to ask me to guess based on available information, I would guess it was the US — specifically, the NSA. It shows a care and precision that it’s known for. But I have no actual evidence for that guess.

All the vulnerabilities were fixed by last April.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

MAZE Exfiltration Tactic Widely Adopted

MAZE Exfiltration Tactic Widely Adopted

New research by New Zealand company Emsisoft has found that a cyber-blackmail tactic first debuted by ransomware gang MAZE has been adopted by over a dozen other criminal cyber-gangs.

The internationally renowned security software company declared a ransomware crisis in the last month of 2019. Their latest ransomware report shows that this particular type of malware has had a huge impact on the United States in 2020.

Emsisoft threat analyst Brett Callow described the numbers in “The State of Ransomware in the US: Report and Statistics 2020” as “pretty grim.”

At least 2,354 US governments, healthcare facilities, and schools were impacted by ransomware last year, including 113 federal, state, and municipal governments and agencies, 560 healthcare facilities, and 1,681 schools, colleges, and universities.

Researchers noted that the attacks “caused significant, and sometimes life-threatening, disruption: ambulances carrying emergency patients had to be redirected, cancer treatments were delayed, lab test results were inaccessible, hospital employees were furloughed and 911 services were interrupted.”

In 2020, MAZE became the first ransomware group to be observed exfiltrating data from its victims and using the threat of publication as additional leverage to extort payment. 

“At the beginning of 2020, only the Maze group used this tactic,” wrote researchers. “By the end of the year, at least 17 others had adopted it and were publishing stolen data on so-called leak sites.”

According to a November report by Coveware, some ransomware gangs that exfiltrate data don’t delete it, even after receiving a ransom from their victims. Coveware observed REvil (Sodinokibi) asking for a second ransom payment for stolen data it had already been paid to erase. 

Netwalker (Mailto) and Mespinoza (Pysa) were observed publishing exfiltrated data on dedicated leak-site portals despite receiving ransoms from their victims. 

Emsisoft found that in 2019 and in 2020, the same number of federal, state, county, and municipal governments and agencies were impacted by ransomware (113). 

“Of the 60 incidents that occurred in Q1 and Q2, data was stolen and released in only one case; it was, however, stolen and released in 23 of the 53 incidents that occurred in Q3 and Q4,” they wrote.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Suspicious Vaccine-Related Domains Triple

Suspicious Vaccine-Related Domains Triple

The number of suspicious domains that feature the word “vaccine” in their title increased by almost 100% in the month after the first Pfizer COVID-19 vaccine was given outside of a clinical trial.

British grandmother Margaret Keenan became the first person in the world to receive the vaccine on December 8, 2020, a week before her 91st birthday. 

New research by American cybersecurity software company Webroot observed that December 8 through January 6, there was an 94.8% increase in suspicious domain names using “vaccine” compared with the previous 30 days.

When compared with the month of March 2020, the total use of the word “vaccine” within suspicious domain names between December and January 6 was found to have increased by 336%.

“As 2021 brings the first mass vaccination programs to fight COVID-19, we’re already seeing cybercriminals exploiting the publicity and anticipation surrounding these to target businesses and consumers in phishing and domain spoofing attacks,” said Nick Emanuel, senior director of product at Webroot.

“Scams using keywords based on emotive subjects concerning medical safety and the pandemic are always going to be more effective, especially when they’re in the public interest.”

Webroot’s Real-Time Anti-Phishing protection system detected a rise in malicious URLs using other words related to the pandemic.

Over 4,500 new suspicious domains were found, which contained a combination of words relating to “COVID-19,” “Corona,” “Vaccine,” “Cure COVID,” and others.

The word “vaccine” was specifically included in the title of 934 domains, while misspellings of “vaccine” cropped up in 611 more. 

“COVID” was in the title of 2,295 suspicious domains, and “Test” or “Testing” appeared in the title of 622 domains.

Threat actors also appeared to be using public interest in travel restrictions as a phishing lure. Among the suspicious domain titles flagged by researchers were “COVID Validator,” “Testing Update,” “COVID Travelcard,” and “Private Vaccine.”

“For individuals, defending against these kinds of attacks should involve security awareness training and remaining vigilant in scrutinising the types of emails they receive,” said Emanuel. 

“This should also be underpinned by cybersecurity technology such as email filtering, anti-virus protection, and strong password policies.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Atlanta Synagogue Reports Cyber-Attack

Atlanta Synagogue Reports Cyber-Attack

An annual religious service held in Atlanta in honor of Martin Luther King Jr. Day was disrupted by a cyber-attack. 

Threat actors reportedly targeted a Shabbat service that was being broadcast live over the internet from Atlanta synagogue The Temple on January 15. The attack occurred as US Senator-elect Raphael Warnock, the pastor at Martin Luther King Jr.’s historic Ebenezer Baptist Church in Atlanta, was delivering a sermon.

People attempting to watch the service live via the Temple’s website were unable to access it, according to a letter penned by the synagogue’s president, Kent Alexander.

Writing to the congregation on Saturday, Alexander said: “To the many of you who tried to log on through the Temple website but could not, and missed the service, we apologize and want to offer an explanation.

“Our website service provider informed our executive director, Mark Jacobson, last night that ‘malicious user agents’ had continuously loaded the Temple website with the objective of shutting it down.” 

Alexander did not name the service provider but added that he had been told that the attack was the “largest-ever attack affecting the provider’s network of client synagogues” and that websites across the United States had also been blocked.

“Eventually, access was restored for all, but The Temple was last,” the director wrote. “Our site was down for over an hour into the service.”

The incident is currently under investigation by the authorities. Alexander theorized that the attack was inspired by religious and racial bigotry.  

After highlighting that Warnock will soon become Georgia’s first African American senator, Alexander wrote: “Presumably, The Temple was singled out by a racist and anti-Semitic group or individual bent on silencing our joint Temple-Ebenezer Baptist Church MLK Jr. Shabbat.”

The Temple was founded in 1867 and is located in the city’s midtown. An annual Martin Luther King Jr. Day Shabbat service has been hosted there for over a decade. 

In 1958, the Temple’s north entrance was bombed by the “Confederate Underground” in an incident denounced by then President Dwight Eisenhower. The bomb, made using 50 sticks of dynamite, caused damage valued at $750k today.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

World Economic Forum: Action Required to Address Digital Inequalities Post-COVID

World Economic Forum: Action Required to Address Digital Inequalities Post-COVID

“A world leader once said ‘a decade can go by without any real news and then you can feel a decade happening in a week.’ I feel that a decade has happened in the past year,” commented Børge Bende, president of the World Economic Forum (WEF), speaking during a press conference highlighting the findings from the organization’s 16thGlobal Risks Report 2021.

This has arisen from the ongoing COVID-19 pandemic, which has brought about substantial changes to the political, economic and social landscape. During the webinar, the panellists emphasized the growing importance of technology, both in helping governments and businesses function amid the ongoing crisis, and for the rebuilding of the world’s economy going forward.

Peter Giger, group chief risk officer, Zurich Insurance Group, explained that COVID-19 had accelerated the so-called ‘fourth industrial revolution’ by rapidly expanding areas such as e-commerce, online education, digital healthcare and remote working. “These shifts will continue to transform human interactions and livelihoods long after COVID is behind us,” he outlined.

This move towards a “digital economy” offers great opportunities but also poses the risk of more global inequality by the creation of an “underclass” of people who are excluded from work as a result of a lack of internet and educational access. For instance, the report noted that internet usage ranges from 87% of the population in high-income countries to under 17% in low-income countries. Widening inequality gaps is particularly dangerous at this time of substantial polarization and the biggest peacetime economic slump in history, as it will threaten global stability, according to Bende.

It is for this reason that the report listed digital inequality as one of the main risks over the coming years, and argued that economic growth needs to be more inclusive and sustainable. It is therefore critical that efforts are made to improve access to the internet and the development of digital skills. Bende added: “We have to invest in global access to the internet and we have to invest in schools, upskilling, reskilling, making sure that inequalities are not growing but are declining.”

As well as the potential sowing of more division through digital inequality, the panel highlighted other dangers that a rapid shift to technology brings. One of these is cybersecurity failures, which the WEF report highlighted as a big worry over the next two years. Carolina Klint, risk management leader for continental Europe at Marsh, noted that the almost overnight shift to home working many businesses were forced to undertake last year has “exponentially increased cyber-exposures and created more complex and potentially less secure networks.” Klint added: “Businesses should now really take the time to assess changes that were made in the heat of the pandemic and verify that the right investments have been made in networks and controls.”

Another major issue emanating from greater internet usage is the rise in misinformation, which has been particularly demonstrated by the fear-mongering and conspiracy theories linked to the COVID-19 crisis. In the view of Giger, this is causing more disconnect and polarization, as well as threatening democracy. However, governments must be cautious when taking regulatory action over this, and on protecting people from big tech monopolies, as this could lead to information censorship and more restricted internet access, risking “our hard won personal freedoms.”

Ultimately, the panel stated that the pandemic has provided an important lesson to countries in dealing with unexpected events. Guillaume Barthe-Dejean, director, chairman’s office at SK Group.  noted that those countries “that digitized early tended to perform better” both from a health and economic point of view. These were nations such as Japan, Korea and China, which have effective track and trace systems, more effective communications, a greater continuity of public services and minimized labor disruptions. Barthe-Dejean added: “That’s a real learning point from hyper-connected economies such as South Korea, which has the highest internet penetration, at 96.2% of it’s population.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cloud Config Error Exposes X-Rated College Pics

Cloud Config Error Exposes X-Rated College Pics

A cloud misconfiguration at a now-defunct social media app has exposed hundreds of thousands of files, including explicit photos of users that they thought had been deleted, according to vpnMentor.

A research team led by Noam Rotem discovered the AWS S3 bucket on October 13 last year, tracing it back to Fleek and owner Squid Inc.

The app apparently marketed itself as an uncensored alternative to Snapchat “Campus Stories.” A hit with US college students, it promised to automatically delete photos after a short period, encouraging users to post salacious pics of themselves engaged in sexually explicit and illegal activities.

However, as the researchers found, many photos were not deleted at all — in fact, they were still being stored long after the app was closed down in 2019.

“Many of these were shared in folders given offensive and derogatory names like ‘asianAss’ by the app’s developers,” vpnMentor explained.

“Fleek users were mostly college students naive of the implications of uploading images that show them engaging in embarrassing and criminal activities, such as drug use. If cyber-criminals obtained these images and knew how to find the people exposed, they could easily target them and blackmail them for large sums of money.”

In total, the research team found around 377,000 files in the 32GB bucket. This also included photos and bot scripts which it’s believed relate to a paid chat room service the app’s owners were trying to promote to users.

To encourage male users, the app’s owners appear to have created numerous bot accounts using images of women scraped from the internet. To ‘chat’ to these bots, users would have to pay a fee.

Having contacted both Squid Inc’s founder and AWS to notify about the privacy snafu, vpnMentor found the bucket had been secured about a week after it was discovered. However, it’s unclear whether the data has been deleted or not.

“Never share anything you’d be embarrassed about online — few systems are 100% secure from hacking, leaks, or dishonest people saving incriminating images to hurt you in the future,” warned vpnMentor.

“It’s also important to know what happens to your data after a company that has collected it goes bankrupt or shuts down. Often, with smaller companies, the owner maintains possession of the data, and there’s very little accountability stopping them from misusing it or sharing with others in the future.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Most Financial Services Have Suffered COVID-Linked Cyber-Attacks

Most Financial Services Have Suffered COVID-Linked Cyber-Attacks

Financial services firms were hit hard over the past year, with 70% experiencing a successful cyber-attack and most of these blaming COVID-related conditions for the incident, according to Keeper Security.

The password security firm commissioned the Ponemon Institute to poll over 370 UK IT security leaders in the sector, as part of a larger global study.

It revealed that the rapid shift to remote working forced on businesses during the pandemic provided threat actors with an opportunity to target remote workers.

Over half (57%) of respondents argued that cyber-attacks are increasing in severity as a result of work-from-home (WFH) and 41% argued that remote workers are putting the business at risk of a major data breach.

Respondents were most concerned about a lack of physical security wherever their employees are remote working from (48%) and their devices becoming infected with malware (34%). This matters in the UK especially as it boasts more privileged users than any other country: 31% of remote workers have access to critical, sensitive and proprietary information.

Trend Micro research last year revealed that home workers often engage in more risky behavior than when they’re at the office. When combined with the surge in COVID-19 phishing emails and devices that may be shared with other users in the same household and/or less well protected than corporate equivalents, it adds up to a potential perfect storm of risk.

Insufficient budget and lack of know-how on combatting cyber-attacks were flagged by respondents as the biggest IT security challenges with remote working.

They were most concerned about the threat to customer records (50%) and financial information (48%). IT security managers right to be worried, given the potential regulatory and reputational impact of a breach.

According to Keeper Security CEO, Darren Guccione, things are particularly precarious given the double whammy of the pandemic and Brexit, which saw UK banks lose their crucial “passporting” rights.

“The adjustments to life as we know it due to COVID-19, and the limitations set to be imposed by Brexit, have seen businesses struggle adopt essential operational requirements to stay afloat,” he argued.

“Without rigorous security in place, financial institutions across the UK jeopardise their future. It only takes one cyber-attack to destroy the reputation of the entire business.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

GDPR Fines Surge 39% Over Past Year Despite #COVID19

GDPR Fines Surge 39% Over Past Year Despite #COVID19

The past year has seen double-digit increases in the value of GDPR fines imposed by regulators and the volume of breaches notified to regulators, according to a new analysis by DLA Piper.

The international law firm said that €158.5m ($192m, £141m) in fines was imposed since January 28 2020, a 39% increase on the previous 20-month period since the law came into force in May 2018.

Breach notifications surged by 19%, the second consecutive double-digit increase, to reach 121,165 over the past year.

In total, €272.5m ($332m, £45m) in fines has been issued since the start of the new regulatory regime, with Italy (€69m) having imposed the larges number, followed by Germany and France.

Total breach notification volumes have reached 281,000, with Germany (77,747), the Netherlands (66,527) and the UK (30,536) topping the table. However, when weighted according to national populations, Denmark comes top, followed by the Netherlands and Ireland.

Although the upward trajectory of fines and notifications would suggest that the GDPR is forcing organizations to be more transparent about incidents and providing regulators with a powerful statutory instrument to punish major transgressors, the truth is more nuanced.

In the UK, for example, the Information Commissioner’s Office (ICO), a leading regulator in the drafting of the legislation, significantly reduced fines planned for BA and Marriot International, from a combined £282m to just £38m last year. It is believed the COVID-19 pandemic may have been a factor.

Concerns were raised last year that national regulators are simply not resourced sufficiently to launch major investigations against the world’s biggest companies, especially tech giants with deep pockets.

However, the coming year is likely to see a ramping up of regulatory pressure, warned Ross McKean, chair of DLA Piper’s UK Data Protection and Security Group.

“Regulators have adopted some extremely strict interpretations of GDPR, setting the scene for heated legal battles in the years ahead. However, we have also seen regulators show a degree of leniency this year in response to the ongoing pandemic with several high-profile fines being reduced due to financial hardship,” he explained.

“During the coming year we anticipate the first enforcement actions relating to GDPR’s restrictions on transfers of personal data to the US and other ‘third countries’ as the aftershocks from the ruling by Europe’s highest court in the Schrems II case continue to be felt.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk