UK Jails Cyber-Voyeur

UK Jails Cyber-Voyeur

A former civil servant has been imprisoned in the United Kingdom for hacking into the computer accounts of nearly 600 women and girls to blackmail them into sharing sexually explicit images of themselves. 

Akash Sondhi, of Chafford Hundred, Essex, engaged in a cybercrime spree that lasted nearly three and a half years and impacted 573 victims located around the world in countries including Australia, Hong Kong, and the UK.

The 27-year-old, who was described by the Crown Prosecution Service as “an extremely manipulative man,” was sentenced today in Basildon Crown Court to 11 years in prison for blackmail, voyeurism, and cybercrimes. 

Judge Samantha Cohen told Sondhi: “You were a source of pride to your family, but now you are a source of shame.”

Between December 26, 2017, and March 17, 2020, Sondhi gained unauthorized access to hundreds of victims’ social media accounts. Snapchat, a messaging app that lets users exchange pictures and video that are meant to disappear shortly after they’re viewed, was his favored hunting ground. 

After gaining access to an account, Sondhi would trawl it for indecent images that he could use to threaten his victim. 

“Sondhi told them if they didn’t send him nude images of themselves, he would post intimate images of them to their friends and family,” said the CPS. 

Some of the young women complied with Sondhi’s requests, and in at least six cases, this serial sextortionist carried out his threats to expose their private images.

The CPS said that a number of Sondhi’s victims reported experiencing serious emotional and psychological harm as a result of his actions. One victim even attempted to kill herself. 

“Akash Sondhi is an extremely manipulative man who inflicted emotional and psychological damage on young women while also getting gratification from their images and videos,” said CPS senior crown prosecutor Joseph Stickings.

“Following a diligent and thorough investigation conducted by the Essex Police Cyber Crime Unit the CPS was able to build a comprehensive case of 65 counts reflecting the high level of his offending.”

Stickings went on to thank all of the victims who came forward to report Sondhi’s crimes, commending them for their bravery.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

iboss Raises $145m in Funding

iboss Raises $145m in Funding

American cloud security provider iboss today announced that it has raised $145m in new funding.

The fresh financing will be spent on supporting the company’s “rapid growth” in a market it says is worth $25bn.

iboss is a privately held company founded in 2003 that is headquartered in Boston, Massachusetts. The company is known for its cloud platform, which provides network security as a service, delivered in the cloud, as a complete SaaS offering. 

According to the company’s CEO, Paul Martini, the ongoing global health pandemic has accelerated the shift to cloud-based cybersecurity providers, giving iboss a boost.

“COVID-19 has exposed massive vulnerabilities with outdated, hardware-based cybersecurity solutions and accelerated the timeline of moving away from the old method of securing physical office perimeters,” said Martini. 

“Implementing modern architecture that provides network security in the cloud is the best way to ensure safety and productivity, even as remote workers rely more and more on fast connections for things like video meetings and online productivity apps.”

iboss uses a Secure Access Service Edge (SASE) model to protect dispersed workforces that increasingly connect to cloud applications such as Microsoft Office 365 and Zoom. 

“iboss has created the largest, most modern and comprehensive SASE security platform on the market and is the only platform that can fully transition organizations from on-prem security appliances to SaaS security delivered in the cloud,” said Dave DeWalt, founder of NightDragon and co-chairman of iboss. 

“What makes this stronger is that iboss is an open security platform that allows organizations to apply the security engines and log analytics platforms of their choosing compared to existing closed SASE solutions that lack this flexibility and restrict better security due to lack of collaboration with top cybersecurity intelligence vendors.”

The funding round was led by NightDragon and global investment firm Francisco Partners. 

“We are thrilled to partner with iboss and participate in this growth financing,” said Francisco Partners’ head of credit, Scott Eisenberg.

“As the traditional enterprise perimeter dissolves, security solutions need to enable safe access to apps and services anytime, anywhere. iboss’ cloud-first solution was designed to address this transformational infrastructure shift.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

FBI Warns of Swatting Attacks

FBI Warns of Swatting Attacks

A spate of swatting attacks waged against users of smart-home devices in America has prompted the Federal Bureau of Investigation to issue a public warning

The term ‘swatting’ is used to describe a hoax call made to emergency services, typically reporting an immediate threat to human life, to trigger a response from law enforcement and the deployment of a S.W.A.T. team to a specific residence. 

The FBI said on December 29 that law enforcement agencies have received reports from smart-home device manufacturers that offenders have been gaining unauthorized access to devices using stolen passwords. The cyber-attackers have focused their malicious activity on owners of devices that have camera and voice capabilities. 

After gaining control of a device, the attackers take over the live-stream camera and device speakers. They then initiate contact with first responders, falsely informing them that a crime or emergency situation is unfolding at the victim’s home address. 

As law enforcement responds to the residence, the attacker watches the swatting attack they have manufactured unfold via livestream footage, engaging with the responding police through the camera and speakers. 

In some cases, attackers have live-streamed the incidents they manufactured online via shared community platforms.

“Swatting may be motivated by revenge, used as a form of harassment, or used as a prank, but it is a serious crime that may have potentially deadly consequences,” warned the FBI.

“Confusion on the part of homeowners or responding officers has resulted in health-related or violent consequences and pulls limited resources away from valid emergencies.”

The FBI said that it is working with private-sector partners who design and build smart devices to advise customers about the swatting attacks and how to avoid being victimized. The Bureau is also taking steps to alert law enforcement first responders to this dangerous threat.

Users of smart-home devices with cameras and voice capabilities are advised to use complex, unique passwords and enable two-factor authentication to help protect against swatting attacks. 

“It is highly recommended that the user’s second factor for two-factor or multi-factor authentication be a mobile device number and not a secondary e-mail account,” said the FBI.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ericom Appoints First Ever Chief Strategy Officer

Ericom Appoints First Ever Chief Strategy Officer

Cybersecurity firm Ericom Software has announced the appointment of Dr Chase Cunningham as its first chief strategy officer. Joining from market research company Forrester, Cunningham will be responsible for shaping Ericom’s strategic vision, roadmap and key partnerships.

Cunningham has over 19 years of experience in the cybersecurity sector, with particular expertise in the area of zero-trust. At Forrester, he helped develop its zero-trust certification program and was the principal driving force for its zero-trust eXtended (ZTX) framework.

Before working at Forrester, he held the position of director of cyber-threat intelligence at Armor, where he was responsible for designing and managing the cloud security and intelligence engine for enterprise customers. Prior to this, he worked for a number of US government agencies, including the NSA, CIA and FBI, in the areas of cyber-forensic and cyber-analytic operations. There, he worked with clients to enhance their security architecture, such as optimizing security operations command systems and centers and installing encryption and analytic systems. Cunningham is also a retired US Navy chief.

Ericom hopes the appointment will enable it to expand its zero-trust secure web and application access solution portfolio.

Commenting on the announcement, David Canellos, CEO of Ericom, said: “Chase’s zero-trust vision and drive have had a major impact on the global cybersecurity market, and his passion, real world expertise and candor are valued and appreciated by industry executives and as well as government leaders. We believe that his insights and hands-on security expertise will enable the digital transformation that is crucial for our customers’ secure growth and success.

“His guidance and direction of our strategic programs and technology innovation will help us rapidly deliver more impactful cloud cybersecurity solutions for our customers and partners.”

Cunningham commented: “Ericom has a strong history of helping its customers establish secure connectivity and network access, and it has evolved into a nimble and highly innovative zero-trust security player.

“I look forward to helping the company ramp up that evolution and build out its security portfolio, providing an unmatched set of capabilities to help secure businesses as they digitally transform in the future.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ransomware Surge Drives 45% Increase in Healthcare Cyber-Attacks

Ransomware Surge Drives 45% Increase in Healthcare Cyber-Attacks

Cyber-attacks on global healthcare organizations (HCOs) increased at more than double the rate of those targeting other sectors over the past two months, according to Check Point.

The security vendor’s latest data covers the period from the beginning of November to the end of 2020, and compares it with the previous two months (September-October), a spokesperson confirmed to Infosecurity.

It revealed a 45% increase in attacks on the healthcare sector, versus less than half this figure (22%) for all other verticals. November was particularly bad, with HCOs suffering 626 weekly attacks on average per organization, compared with 430 in the previous two months.

Although the attacks span a variety of categories — including ransomware, botnets, remote code execution and DDoS — perhaps unsurprisingly, it is ransomware that displayed the largest increase overall and poses the biggest threat to HCOs, according to Check Point.

Ryuk and Sodinokibi (REvil) were highlighted as the main culprits.

In fact, financially motivated cyber-criminals have been going after the healthcare sector since the start of the COVID-19 crisis, well aware that hospitals and clinics are distracted with the huge surge in cases coming through their doors.

Microsoft revealed in April how these groups are increasingly using APT-style tactics to gain a foothold in networks, perform lateral movement and credential theft, and exfiltrate data before deploying their ransomware payload.

Central Europe experienced the biggest rise in cyber-attacks on its HCOs during the period (145%), followed by East Asia (137%) and Latin America (112%).

Europe recorded a 67% increase, although Spain saw attacks double and Germany recorded a 220% surge. Although North America (37%) saw the smallest rise regionally, Canada experienced the biggest increase of any country, at 250%.

“This past year, a number of hospital networks across the globe were successfully hit with ransomware attacks, making cyber criminals hungry for more,” explained Check Point manager of data intelligence, Omer Dembinsky.

“Furthermore, the usage of Ryuk ransomware emphasizes the trend of having more targeted and tailored ransomware attacks rather than using a massive spam campaign. This allows the attackers to make sure they hit the most critical parts of the organization and have a higher chance of getting their ransom paid.”

Check Point urged organizations to look for the presence of Trickbot, Emotet, Dridex and Cobalt Strike, as these often presage ransomware, and to be on their guard on weekends, when attackers often strike.

Virtual patching, employee education and anti-ransomware solutions are also crucial tools in the CISO’s armory, it added.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Chinese APT Group Linked to Ransomware Attacks

Chinese APT Group Linked to Ransomware Attacks

A well-known Chinese state-backed APT group is believed to have been responsible for multiple ransomware attacks against firms last year, according to new research.

A report from Security Joes and Pro reveals how the vendors uncovered the links after investigating an incident in which ransomware encrypted “several core servers” at an unidentified victim organization.

They found samples of malware linked to the DRBControl campaign which targeted major gaming companies and is associated with two well-known Chinese-backed groups, APT27 (aka Emissary Panda) and Winnti.

Specifically, they claimed to have detected an older version of the Clambling backdoor used in that campaign, an ASPXSpy webshell previously used by APT27, and the PlugX RAT which is often used in Chinese attacks.

Although Winnti is known for financially motivated attacks, APT27 is generally more focused on data theft. However, the latter has previously been linked to one ransomware attack, featuring the Polar variant.

“There are extremely strong links to APT27 in terms of code similarities and TTPs,” the report noted. “This incident occurred at a time when where COVID-19 was rampant across China with lockdowns being put into place, and therefore a switch to a financial focus would not be surprising.”

The attack itself does not seem to have been particularly sophisticated.

The initial vector was a third-party service provider that itself had been infected by a third party, and the attackers used Windows own BitLocker encryption tool to lock down targeted servers.

ASPXSpy was deployed for lateral movement and PlugX and Clambling were loaded into memory using a Google Updater executable vulnerable to DLL side-loading. Popular open source tool Mimikatz was also used in the attack and a publicly available exploit for CVE-2017-0213 was used to escalate privileges.

Gaming firms are an increasingly popular target among financially motivated attackers, according to new research released yesterday by Kela. The threat intelligence firm claimed to have discovered one million compromised internal accounts from gaming companies on the dark web, and 500,000 breached credentials belonging to employees.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

HelpSystems Acquires FileCatalyst to Boost Data Transfer Portfolio

HelpSystems Acquires FileCatalyst to Boost Data Transfer Portfolio

Software firm HelpSystems has announced the acquisition of FileCatalyst to boost the speed and security of its file transfer offerings.

FileCatalyst specializes in helping transfer extremely large files in organizations at hundreds of times faster than what the file transfer protocol allows. These include the sharing of video and other media-rich files, big data and extensive databases, which are particularly important for industries such as broadcast media and live sports.

This enables businesses to work more efficiently while avoiding latency and packet loss when moving around large amounts of data across global networks. 

This type of service has become increasingly important as a result of the shift to home working brought about by the COVID-19 pandemic, with file sharing often taking place across insecure channels, networks and devices. For instance, last year a study found that nearly half of SME businesses regularly share confidential files via email, including financial and employee data in spreadsheets.

Kate Bolseth, CEO of HelpSystems, commented: “Our customers and partners have expressed a growing need to move significant volumes of data more quickly than ever before, and FileCatalyst addresses this problem effectively for many well-known organizations.

“FileCatalyst is an excellent addition to our managed file transfer and robotic process automation offerings, and we are pleased to bring the FileCatalyst team and their strong file acceleration knowledge into the global HelpSystems family.”

Chris Bailey, CEO and co-founder of FileCatalyst, said: “We are thrilled to become part of a company with deep roots and expertise in both cybersecurity and automation. Our customers will find value in pairing our file transfer acceleration solutions with HelpSystems’ extensive solution suites.”

This announcement follows a number of other recent acquisitions by HelpSystems, including cloud-based data protection provider Vera last month and data classification companies Titus and Boldon James in June 2020.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

NYSE U-Turn Means Chinese Telcos Escape Delisting

NYSE U-Turn Means Chinese Telcos Escape Delisting

The world’s largest stock exchange has reversed its decision to ban three Chinese telecoms companies after a Presidential order was issued late last year.

The New York Stock Exchange (NYSE) had issued its original decision to delist the firms on December 31 following President Trump’s executive order the month previously.

In it, Trump claimed that ostensibly civilian businesses in China are actually part of a giant military-industrial complex, and that by listing on US exchanges they are effectively raising funds from unwitting investors in order to modernize China’s military.

“Through the national strategy of military-civil fusion, the PRC increases the size of the country’s military-industrial complex by compelling civilian Chinese companies to support its military and intelligence activities,” it said. 

“Those companies, though remaining ostensibly private and civilian, directly support the PRC’s military, intelligence and security apparatuses and aid in their development and modernization.”

However, in a brief statement on Monday, the NYSE said it had reconsidered its decision regarding China Telecom, China Mobile and China Unicom.

“In light of further consultation with relevant regulatory authorities in connection with Office of Foreign Assets Control FAQ 857 … the New York Stock Exchange LLC announced today that NYSE Regulation no longer intends to move forward with the delisting action in relation to the three issuers enumerated below which was announced on December 31 2020,” it stated.

A link in the statement takes readers to a US Treasury FAQ page.

The move follows a tersely worded statement from the China Securities Regulatory Commission over the weekend, which claimed that the US continues to “groundlessly suppress foreign companies listed on the US markets.”

Last month, a new law passed Congress which will force Chinese firms to comply with Public Company Accounting Oversight Board’s (PCAOB) audits or be delisted. Companies from many other nations do this in line with SEC rules to provide maximum transparency to investors, although China has resisted for over a decade.

The NYSE ended its brief statement by admitting that it will continue to assess the applicability of the executive order to the Chinese telcos and their listing status.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk