NSA on Authentication Hacks (Related to SolarWinds Breach)

The NSA has published an advisory outlining how “malicious cyber actors” are “are manipulating trust in federated authentication environments to access protected data in the cloud.” This is related to the SolarWinds hack I have previously written about, and represents one of the techniques the SVR is using once it has gained access to target networks.

From the summary:

Malicious cyberactors are abusing trust in federated authentication environments to access protected data. The exploitation occurs after the actors have gained initial access to a victim’s on-premises network. The actors leverage privileged access in the on-premises environment to subvert the mechanisms that the organization uses to grant access to cloud and on-premises resources and/or to compromise administrator credentials with the ability to manage cloud resources. The actors demonstrate two sets of tactics, techniques,and procedures (TTP) for gaining access to the victim network’s cloud resources, often with a particular focus on organizational email.

In the first TTP, the actors compromise on-premises components of a federated SSO infrastructure and steal the credential or private key that is used to sign Security Assertion Markup Language (SAML) tokens(TA0006, T1552, T1552.004). Using the private keys, the actors then forge trusted authentication tokens to access cloud resources. A recent NSA Cybersecurity Advisory warned of actors exploiting a vulnerability in VMware Access and VMware Identity Manager that allowed them to perform this TTP and abuse federated SSO infrastructure.While that example of this TTP may have previously been attributed to nation-state actors, a wealth of actors could be leveraging this TTP for their objectives. This SAML forgery technique has been known and used by cyber actors since at least 2017.

In a variation of the first TTP, if the malicious cyber actors are unable to obtain anon-premises signing key, they would attempt to gain sufficient administrative privileges within the cloud tenant to add a malicious certificate trust relationship for forging SAML tokens.

In the second TTP, the actors leverage a compromised global administrator account to assign credentials to cloud application service principals (identities for cloud applications that allow the applications to be invoked to access other cloud resources). The actors then invoke the application’s credentials for automated access to cloud resources (often email in particular) that would otherwise be difficult for the actors to access or would more easily be noticed as suspicious (T1114, T1114.002).

This is an ongoing story, and I expect to see a lot more about TTP — nice acronym there — in coming weeks.

Related: Tom Bossert has a scathing op-ed on the breach. Jack Goldsmith’s essay is worth reading. So is Nick Weaver’s.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Schools Are Buying Cell Phone Unlocking Systems

Gizmodo is reporting that schools in the US are buying equipment to unlock cell phones from companies like Cellebrite:

Gizmodo has reviewed similar accounting documents from eight school districts, seven of which are in Texas, showing that administrators paid as much $11,582 for the controversial surveillance technology. Known as mobile device forensic tools (MDFTs), this type of tech is able to siphon text messages, photos, and application data from student’s devices. Together, the districts encompass hundreds of schools, potentially exposing hundreds of thousands of students to invasive cell phone searches.

The eighth district was in Los Angeles.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

VMware Flaw a Vector in SolarWinds Breach?

U.S. government cybersecurity agencies warned this week that the attackers behind the widespread hacking spree stemming from the compromise at network software firm SolarWinds used weaknesses in other, non-SolarWinds products to attack high-value targets. According to sources, among those was a flaw in software virtualization platform VMware, which the U.S. National Security Agency (NSA) warned on Dec. 7 was being used by Russian hackers to impersonate authorized users on victim networks.

On Dec. 7, 2020, the NSA said “Russian state-sponsored malicious cyber actors are exploiting a vulnerability in VMware Access and VMware Identity Manager products, allowing the actors access to protected data and abusing federated authentication.”

VMware released a software update to plug the security hole (CVE-2020-4006) on Dec. 3, and said it learned about the flaw from the NSA.

The NSA advisory (PDF) came less than 24 hours before cyber incident response firm FireEye said it discovered attackers had broken into its networks and stolen more than 300 proprietary software tools the company developed to help customers secure their networks.

On Dec. 13, FireEye disclosed that the incident was the result of the SolarWinds compromise, which involved malicious code being surreptitiously inserted into updates shipped by SolarWinds for users of its Orion network management software as far back as March 2020.

In its advisory on the VMware vulnerability, the NSA urged patching it “as soon as possible,” specifically encouraging the National Security System, Department of Defense, and defense contractors to make doing so a high priority.

The NSA said that in order to exploit this particular flaw, hackers would already need to have access to a vulnerable VMware device’s management interface — i.e., they would need to be on the target’s internal network (provided the vulnerable VMware interface was not accessible from the Internet). However, the SolarWinds compromise would have provided that internal access nicely.

In response to questions from KrebsOnSecurity, VMware said it has “received no notification or indication that the CVE 2020-4006 was used in conjunction with the SolarWinds supply chain compromise.”

VMware added that while some of its own networks used the vulnerable SolarWinds Orion software, an investigation has so far revealed no evidence of exploitation.

“While we have identified limited instances of the vulnerable SolarWinds Orion software in our environment, our own internal investigation has not revealed any indication of exploitation,” the company said in a statement. “This has also been confirmed by SolarWinds own investigations to date.”

On Dec. 17, DHS’s Cybersecurity and Infrastructure Security Agency (CISA) released a sobering alert on the SolarWinds attack, noting that CISA had evidence of additional access vectors other than the SolarWinds Orion platform.

CISA’s advisory specifically noted that “one of the principal ways the adversary is accomplishing this objective is by compromising the Security Assertion Markup Language (SAML) signing certificate using their escalated Active Directory privileges. Once this is accomplished, the adversary creates unauthorized but valid tokens and presents them to services that trust SAML tokens from the environment. These tokens can then be used to access resources in hosted environments, such as email, for data exfiltration via authorized application programming interfaces (APIs).”

Indeed, the NSA’s Dec. 7 advisory said the hacking activity it saw involving the VMware vulnerability “led to the installation of a web shell and follow-on malicious activity where credentials in the form of SAML authentication assertions were generated and sent to Microsoft Active Directory Federation Services (ADFS), which in turn granted the actors access to protected data.”

Also on Dec. 17, the NSA released a far more detailed advisory explaining how it has seen the VMware vulnerability being used to forge SAML tokens, this time specifically referencing the SolarWinds compromise.

Asked about the potential connection, the NSA said only that “if malicious cyber actors gain initial access to networks through the SolarWinds compromise, the TTPs [tactics, techniques and procedures] noted in our December 17 advisory may be used to forge credentials and maintain persistent access.”

“Our guidance in this advisory helps detect and mitigate against this, no matter the initial access method,” the NSA said.

CISA’s analysis suggested the crooks behind the SolarWinds intrusion were heavily focused on impersonating trusted personnel on targeted networks, and that they’d devised clever ways to bypass multi-factor authentication (MFA) systems protecting networks they targeted.

The bulletin references research released earlier this week by security firm Volexity, which described encountering the same attackers using a novel technique to bypass MFA protections provided by Duo for Microsoft Outlook Web App (OWA) users.

Duo’s parent Cisco Systems Inc. responded that the attack described by Volexity didn’t target any specific vulnerability in its products. As Ars Technica explained, the bypass involving Duo’s protections could have just as easily involved any of Duo’s competitors.

“MFA threat modeling generally doesn’t include a complete system compromise of an OWA server,” Ars’ Dan Goodin wrote. “The level of access the hacker achieved was enough to neuter just about any defense.”

Several media outlets, including The New York Times and The Washington Post, have cited anonymous government sources saying the group behind the SolarWinds hacks was known as APT29 or “Cozy Bear,” an advanced threat group believed to be part of the Russian Federal Security Service (FSB).

SolarWinds has said almost 18,000 customers may have received the backdoored Orion software updates. So far, only a handful of customers targeted by the suspected Russian hackers behind the SolarWinds compromise have been made public — including the U.S. Commerce, Energy and Treasury departments, and the DHS.

No doubt we will hear about new victims in the public and private sector in the coming days and weeks. In the meantime, thousands of organizations are facing incredibly costly, disruptive and time-intensive work in determining whether they were compromised and if so what to do about it.

The CISA advisory notes the attackers behind the SolarWinds compromises targeted key personnel at victim firms — including cyber incident response staff, and IT email accounts. The warning suggests organizations that suspect they were victims should assume their email communications and internal network traffic are compromised, and rely upon or build out-of-band systems for discussing internally how they will proceed to clean up the mess.

“If the adversary has compromised administrative level credentials in an environment—or if organizations identify SAML abuse in the environment, simply mitigating individual issues, systems, servers, or specific user accounts will likely not lead to the adversary’s removal from the network,” CISA warned. “In such cases, organizations should consider the entire identity trust store as compromised. In the event of a total identity compromise, a full reconstitution of identity and trust services is required to successfully remediate. In this reconstitution, it bears repeating that this threat actor is among the most capable, and in many cases, a full rebuild of the environment is the safest action.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Disinformation Spreaders Predicted by AI

Disinformation Spreaders Predicted by AI

Researchers at a British university have created a new algorithm that uses artificial intelligence to predict which Twitter users are going to spread disinformation before they do it.

The machine-learning algorithm was developed by a team of researchers at the University of Sheffield, led by PhD student Yida Mu and Dr. Nikos Aletras from the university’s Department of Computer Science. It can pinpoint with 79.7% accuracy which users are likely to share content from a news source deemed to be unreliable. 

To create the algorithm, the researchers analyzed over 1 million publicly available tweets from approximately 6,200 Twitter aficionados. Users were then split into those who shared unreliably sourced news and those who shared reliably sourced news, and this data was used to train the algorithm.

The study found that Twitter users who shared stories from unreliable sources were more likely to write about the world around them, posting on social media about politics or religion. Words used frequently by this category of users included “liberal,” “government,” “Islam,” “Israel,” and “media.”

Twitter users who shared stories from news sources the study categorized as reliable were more focused on themselves, often tweeting about their emotions and personal lives and favoring the words “I’ll,” “birthday,” “wanna,” and “mood.”

The reliable news sharers were found to express their views in language that was more polite than that used by the sharers of disinformation. Rude language and the spread of unreliable content were found to correlate with high online political hostility. 

“Social media has become one of the most popular ways that people access the news, with millions of users turning to platforms such as Twitter and Facebook every day to find out about key events that are happening both at home and around the world,” said Dr. Nikos Aletras, lecturer in Natural Language Processing at the University of Sheffield. 

“However, social media has become the primary platform for spreading disinformation, which is having a huge impact on society and can influence people’s judgement of what is happening in the world around them.”

The study, “Identifying Twitter users who repost unreliable news sources with linguistic information,” was published in PeerJ journal.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Healthcare.gov Data Thief Jailed

Healthcare.gov Data Thief Jailed

An employee at a tech company based in Virginia has been sent to prison for stealing personally identifiable information (PII) from Healthcare.gov customers and exploiting it for profit. 

Colbi Trent Defiore accessed data belonging to more than 8,000 individuals without authorization while working at a contact center in Bogalusa, Louisiana. The 27-year-old then stole the data and used it fraudulently for his own personal financial gain, applying for credit cards and personal loans. 

At the time that he committed the offenses, Defiore was employed as a seasonal worker for a company that supported the Centers for Medicare & Medicaid Services (CMS) by operating contact centers to assist with Medicare enrollment and other processes.

The company, which was unnamed in the court documents, required all to undergo training on how to handle consumers’ PII appropriately. Despite the training, Defiore admitted to accessing and obtaining consumers’ data on multiple occasions in November 2018 by improperly accessing the Healthcare.gov database.

The Carriere, Mississippi, resident conducted bulk searches of the database, an action that he was prohibited from doing. He then copied his search results onto a clipboard and emailed them to his work email account. 

After his working day had ended, Defiore accessed his work email remotely without authorization to retrieve the stolen data. 

The personal information of at least five consumers was used illegally by Defiore to apply for at least six credit cards, loans, and lines of credit for his personal benefit. 

Defiore was charged November 7, 2019, by a federal grand jury in a one-count indictment with intentionally accessing a protected computer in excess of authorization for the purpose of commercial advantage and private financial gain, and in furtherance of the commission of a felony.

“In total, Defiore’s conduct caused reasonably foreseeable loss to the companies that operated the call center, including costs associated with responding to the offense, conducting a damage assessment, responding to and remediating damage, contacting consumers who were potential victims, and providing theft protection services for consumer-victims, in the amount of $587,000,” said the Department of Justice. 

Defiore was sentenced to 42 months’ imprisonment, 3 years of supervised release, and payment of a $100 special assessment fee.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Indian Police Bust Illegal Call Center

Indian Police Bust Illegal Call Center

Police in India have arrested 54 people in a raid on an illegal call center that targeted foreign nationals with fraud scams.

The Delhi cybercrime unit launched an investigation after receiving intelligence that a large-scale fraud operation was being run from a location in Moti Nagar, New Delhi. 

Police were informed that a team of scammers were calling up targets in America and other countries and conning them into transferring money to criminals via Bitcoin wallets and the purchase of gift cards.

A variety of scams were practiced at the call center, including one that involved impersonating various law enforcement agencies and threatening the targets with arrest or legal action. Victims were told that they could avoid jail or being swept up in the court system if they chose to pay an Alternate Dispute Resolution. 

Victims who opted to pay the ADR were then asked to disclose all the details of their assets, including bank account details and the amount of money contained in the accounts. The scammers then told victims that the only way to move money safely was through the purchase of Google gift cards or via Bitcoin wallets. 

Other government agencies, including the United States Drug Enforcement Agency, Social Security Administration, and the US Marshals Service, were spoofed by the scammers. Victims were told their assets had been frozen as part of a criminal investigation into illegal transactions. 

A raid on the call center, led by Assistant Commissioner of Police Aditya Gautam, resulted in the arrest of 45 men and 9 women and the seizure of 89 desktop computers, cell phones, and a server. 

Among the suspects detained by Delhi’s cybercrime unit were four alleged ‘closers’ whose job it was to close each fraudulent transaction by ensuring the victim transferred the money.

According to India TV News, the scammers would call up their victims and read from an elaborate script to dupe them into transferring money. The operation is reported to have conned more than 4,500 victims out of between $1.2m and $1.3m.

The news source states that initial investigations suggest that the owner of the call center is located in Dubai.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Two-Thirds of Orgs Expect Increase in #COVID19 Phishing Attacks Next Year

Two-Thirds of Orgs Expect Increase in #COVID19 Phishing Attacks Next Year

Nearly two-thirds (64%) of business decision makers expect their company to face a rise in COVID-19 themed phishing attacks in 2021, according to a new study from Centrify.

In a survey of 200 business decision makers across large and medium-sized UK enterprises, over half (52%) also said they anticipated a growth in cyber-attacks targeting their organizations as a result of the most recent national lockdown in the UK, which ended on December 2.

Despite these fears, over a third (37%) are not planning to train new employees on data management policies and cybersecurity risks linked to the COVID-19 crisis. Additionally, 37% admitted they do not have sufficient access management systems in place to verify employee identities and credentials when they are accessing company data.

Security professionals have observed a huge rise in phishing attacks this year, with pandemic-related subjects providing especially strong lures. Research from Barracuda showed that phishing emails spiked by 667% in under a month when the pandemic struck, while last month it was reported that the HMRC detected a 73% rise in email phishing attacks from March to September in the UK.

Howard Greenfield, chief revenue officer at Centrify, commented: “COVID-themed email, SMS and web-based phishing attacks have not been uncommon over the last year, and so far we’ve seen cyber-attack campaigns using the guise of charity, government financial aid initiatives and business support schemes to lure thousands of victims into leaking sensitive information, such as log-in credentials and payment details.

“In fact, these phishing campaigns have been so sophisticated and widespread in 2020 that business leaders can only reasonably assume that a colleague or employee has already fallen victim to one – especially if they have been working remotely this year for the first time in their career.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ransomware and Cyber-Extortion Payments Double in 2020

Ransomware and Cyber-Extortion Payments Double in 2020

The total cost of ransom payments doubled year-on-year during the first six months of 2020.

Based on incidents reported to Beazley’s in-house breach response team, BBR Services, ransomware attacks increased in terms of both severity and costs this year compared to 2019 and have become the biggest cyber-threat facing organizations.

Paul Bantick, Beazley’s global head of cyber and technology, said: “Our underwriting, claims and threat intelligence database shows that ransomware attacks are much more sophisticated and severe, thus, it is critical that organizations adopt a layered approach to security and take stringent measures to make it hard for threat actors at every step.”

Jack Kudale, founder and CEO of Cowbell Cyber, said those organizations who fall victim to a ransomware attack are often caught off guard with no backup, and their only option is to pay the ransom. “In other words, ransomware attacks are working for the criminals and they can demand higher payment,” he added.

Mohit Tiwari, co-founder and CEO at Symmetry Systems agreed, explaining that running a ransomware campaign (including tools, negotiations and money transfer) is becoming commoditized, and therefore paying the ransom is becoming an acceptable, and even normal, response for victims. 

Beazley claimed that ransomware is no longer the sole problem, as the rise of cyber-extortion events will involve threat actors who exploit access into networks, install highly persistent malware, target backups, steal data and threaten to expose the compromise. “Ransomware is avoidable but requires regular and thorough training of employees on how to avoid this evolving threat,” it said.

“Organizations should not only try to prevent a ransomware infection, but prepare in case they do get infected, through multiple layers of security, each reducing the risk and probability of ransomware.”

Beazley also claimed that the number of cyber-extortion demands being paid has doubled year-on-year.

Dirk Schrader, global vice-president at New Net Technologies (NNT) told Infosecurity that cyber-crooks are playing the game with all the cards they have in their hand, and the “reputation” card is one of them.

“If the victim is a valuable, known brand, serving thousands of customers, the threat to publish the data increases the chances to get what they ask for,” he said. “A prominent example for this approach is the case of the utilities provider in the German city of Ludwigshafen, where the attackers actually published the full data set as the provider refused to pay.”

Tiwari said the amount being paid may continue to increase since it is easier to scale attacks than to dramatically improve the security posture of a legacy company.

Kudale concluded: “Businesses have to consider the financial impact of a ransomware attack beyond the ransom payment; business interruption, loss of income and now breach damages such as compromised data. The best outcome for businesses is to have a backup and subscribe to a cyber insurance policy that covers recovery expenses and brings expertise in negotiating a ransom payment if at all needed.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Experts Urge Users to Ignore Facebook Christmas Bonus Scam

Experts Urge Users to Ignore Facebook Christmas Bonus Scam

Identity theft experts are warning Facebook users to be on the lookout for a “Christmas bonus” scam which appears to be endorsed by their friends on the social network.

Variations on these scams appear to have been circulating on Facebook since at least 2015.

Most recently, users are being targeted by messages claiming to offer them a “Christmas bonus” or “Christmas benefit,” according to the non-profit Identity Theft Resource Center (ITRC).

“Facebook users receive messages from individuals in their contact lists about winning a ‘Christmas bonus.’ The messages are coming from the cloned accounts of friends, and they state that the individual has won a Facebook Christmas Bonus Giveaway,” it explained. 

“The targeted victim is then directed to contact a ‘Facebook Agent,’ who will send a message that [it] is a random contest sponsored by [legitimate US lottery game] Powerball.”

Although there are variations on this theme, the bottom line is that the scammers want either victims’ personal information or their money, or both.

They will usually ask for personal details in order to process the ‘bonus.’ They may also ask for a small ‘transfer fee’ in order to wire the winnings into the victim’s bank account.

The ITRC urged users to delete any such messages and inform their friends that their account may have been hijacked or cloned. They can also report any attempted fraud like this to Facebook itself.

A COVID-fuelled recession in many parts of the world has provided scammers with an opportunity to trick more victims into parting with their money and/or personal data.

They’re also commonplace across email channels, according to new research from Barracuda Networks.

The security vendor claimed that 36% of spear-phishing emails it analyzed between August and October 2020 were “scams,” as well as 72% of all COVID-themed phishing missives.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk