Malicious Chrome and Edge Extensions Affect Millions of Users

Malicious Chrome and Edge Extensions Affect Millions of Users

Three million Google Chrome and Microsoft Edge users could be at risk of data theft and phishing after researchers discovered malware hidden in multiple browser extensions.

At least 28 third-party extensions were found to contain malicious JavaScript which could download additional malware, according to Avast. The extensions themselves are mainly designed to help users download video from some of the world’s most popular sites including Facebook, Vimeo, Instagram and YouTube.

Avast claimed the end goal for those behind the scheme could be to monetize traffic by forcing users to visit third-party sites, which they then get paid for, although users could also end up on phishing sites.

“Anytime a user clicks on a link, the extensions send information about the click to the attacker’s control server, which can optionally send a command to redirect the victim from the real link target to a new hijacked URL before later redirecting them to the actual website they wanted to visit,” the Prague-based security vendor explained.

“User privacy is compromised by this procedure since a log of all clicks is being sent to these third-party intermediary websites. The actors also exfiltrate and collect the users’ birth dates, email addresses, and device information, including first sign-in time, last login time, name of the device, operating system, used browser and its version, even IP addresses (which could be used to find the approximate geographical location history of the user).”

At present it’s unclear whether the extensions were built deliberately with malware concealed within, or if malicious actors waited for them to become popular and then pushed a malware-laden update.

“It could also be that the author sold the original extensions to someone else after creating them, and then the buyer introduced the malware afterwards,” said Jan Rubín, malware researcher at Avast.

“The extensions’ backdoors are well hidden and the extensions only start to exhibit malicious behavior days after installation, which made it hard for any security software to discover.”

Although Avast first detected the threat in November, the vendor admitted it could have been active for years.

Interestingly, if an infected user performs a web search on one of the malicious domains, the malware in question will cease activity on their machine, in order to hide from view. Avast claimed it will do the same if it detects that the user may be a web developer, although it’s unclear how.

As the extensions are currently still available, Avast recommended users disable or uninstall them.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

BEC Hits Double Digits as COVID-19 Scams Abound

BEC Hits Double Digits as COVID-19 Scams Abound

Business email compromise (BEC) attacks have surged over the past year-and-a-half, while scams designed to part users with their money remain a persistent phishing threat, according to Barracuda Networks.

Volume 5 of the security vendor’s Spear Phishing: Top Threats and Trends report details the activity of targeted email threats during the period August-October 2020, distilled from 2.3 million attacks during the period.

Barracuda Networks has created 13 classes of email threat, which are not mutually exclusive: spam, malware, BEC, data exfiltration, URL phishing, scamming, spear-phishing, domain impersonation, brand impersonation, extortion, conversation hijacking, lateral phishing and account takeover.

Of the spear-phishing attacks it recorded during the period, BEC detections grew by 5% from the period December 2018-February 2019 to reach 12% of the total.

The largest number of attacks (50%) were simply labelled “phishing,” meaning they involved some form of brand impersonation.

However, “scamming” attacks comprised over a third (36%). These typically try to trick the recipient into sending money or handing over their financial details. Examples include tech support scams, or fake exhortations from charities or political organizations requesting funds to support various causes.

COVID-19 attacks have not grown much since March, when Barracuda claimed to have recorded a 667% spike. Between June and October this year they represented around 2% of all spear-phishing attacks, with scams (72%) comprising the vast majority, followed by regular phishing (18%), extortion (6%) and BEC (3%).

Interestingly, 13% of all spear-phishing attacks were said to come from internally compromised accounts during the August-October 2020 time period.

“These internal messages do not pass through email gateways, leaving organizations exposed to threats they may deliver. Messages that originate from these compromised accounts, especially if they are coming from a colleague, can potentially have a higher success rate compared to other attacks because people trust messages sent from someone they know,” the report explained.

“Organizations need to invest in protection against account takeover, by scanning messages sent internally within the organization and training users to recognize signs of a compromised account and email messages that come from compromised accounts.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Analysis of 5G Network Security Reveals Attack Possibilities

Analysis of 5G Network Security Reveals Attack Possibilities

Exploitation of vulnerabilities within the 5G network architecture could allow Denial of Service (DoS) attacks and for attackers to conduct remote attacks.

According to new research from Positive Technologies on the security of the network architecture, interaction of network elements, and subscriber authentication and registration procedures, key areas of network security include proper configuration of equipment, as well as authentication and authorization of network elements. In the absence of these elements, the network becomes vulnerable.

Speaking on a webinar to launch the report, Positive Technologies CTO Dmitry Kurbatov said attacks had moved from SMS and call interception, and subscriber DoS, which were prevalent in 2015, and this led to mobile network operators (MNOs) implementing security defenses to mitigate these threats. However in 2020 with the introduction of 5G, and with the start of remote working, there was “burst of interest” in the use of 5G.

Kurbatov said that 5G was initially launched with “stand alone” terminals which used the previous LTE and 4G networks, allowing it to be rolled out fast, but also “they are quite vulnerable and still at risk of attacks because of a long list of long-standing vulnerabilities.” He said the big question now for all of telecoms and security, is “what will be the security situation within 5G once transition is over and after networks are deployed in pure stand alone mode?”

Having performed some test attacks, Kurbatov was able to perform a Man in the Middle attack, and this is critical as “this attack is performed by remote” and usually we expect attacks to require physical proximity. This factor is not needed “as the hacker can be far far away from the victim and still conduct this attack and be physically safe.” In doing that, they can download firmware to a device, and when you consider that 5G will be used in industrial environments, that is why its security is critical.

In a second demo, Kurbatov demonstrated a DoS attack which he said will be critical because of 5G’s use in critical applications, such as connected cars and industrial automation. “So a DoS is super critical because when the network or service is down, like point of sale, ATM, CCTV or any kind of safety control will be immediately disconnected,” he said. “So the ability to run the main functions will be distracted, so DoS is critical as it can impact the entire city of the future.”

Kurbatov said these two attack techniques were selected “in order to explain some of the deficiencies in the 5G architecture which can heavily impact both businesses and subscribers.” He also said there are other vulnerabilities which can be exploited, and he said there are three reasons why this is happening:

  • Internal protocols like PFCP is much like the previously known GTP which has been proven to be vulnerable, as this can assist attackers in exploiting deficiencies in the protocols to help them “run the network the way they would like to.”
  • Network exposure, due to misconfiguration, is a common problem. “Probably more than 70% of cybersecurity incidents happen because of misconfiguration or vulnerabilities,” he said. “Misconfiguration can allow an attack to get access to the core mobile network.”
  • 5G will still work in parallel with LTE for the next decade, but according to forecasts, by 2025 the majority of the traffic will be handled by LTE networks and only partially by 5G. “This is because the penetration of new technologies is not that big.”

Kurbatov said the “cost of failure is much more than remediation” and 5G is a critical infrastructure “not only for industry but for modern society, and that is why focusing on prevention will really save time, money and probably lives.”

Asked by Infosecurity  why these protocols are an issue now and have not been a problem in the past, Kurbatov said these are brand new vulnerabilities as they are used in 5G protocols, and have not used before, but “will be adopted soon in all of the networks.” He said the technology type in 5G is different as “all the same type of major risks can be executed on the larger scale as 5G is the technology of all the technologies.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk