Malicious Domain in SolarWinds Hack Turned into ‘Killswitch’

A key malicious domain name used to control potentially thousands of computer systems compromised via the months-long breach at network monitoring software vendor SolarWinds was commandeered by security experts and used as a “killswitch” designed to turn the sprawling cybercrime operation against itself, KrebsOnSecurity has learned.

Austin, Texas-based SolarWinds disclosed this week that a compromise of its software update servers earlier this year may have resulted in malicious code being pushed to nearly 18,000 customers of its Orion platform. Many U.S. federal agencies and Fortune 500 firms use(d) Orion to monitor the health of their IT networks.

On Dec. 13, cyber incident response firm FireEye published a detailed writeup on the malware infrastructure used in the SolarWinds compromise, presenting evidence that the Orion software was first compromised back in March 2020. FireEye said hacked networks were seen communicating with a malicious domain name — avsvmcloud[.]com — one of several domains the attackers had set up to control affected systems.

As first reported here on Tuesday, there were signs over the past few days that control over the domain had been transferred to Microsoft. Asked about the changeover, Microsoft referred questions to FireEye and to GoDaddy, the current domain name registrar for the malicious site.

Today, FireEye responded that the domain seizure was part of a collaborative effort to prevent networks that may have been affected by the compromised SolarWinds software update from communicating with the attackers. What’s more, the company said the domain was reconfigured to act as a “killswitch” that would prevent the malware from continuing to operate in some circumstances.

“SUNBURST is the malware that was distributed through SolarWinds software,” FireEye said in a statement shared with KrebsOnSecurity. “As part of FireEye’s analysis of SUNBURST, we identified a killswitch that would prevent SUNBURST from continuing to operate.”

The statement continues:

“Depending on the IP address returned when the malware resolves avsvmcloud[.]com, under certain conditions, the malware would terminate itself and prevent further execution. FireEye collaborated with GoDaddy and Microsoft to deactivate SUNBURST infections.”

“This killswitch will affect new and previous SUNBURST infections by disabling SUNBURST deployments that are still beaconing to avsvmcloud[.]com. However, in the intrusions FireEye has seen, this actor moved quickly to establish additional persistent mechanisms to access to victim networks beyond the SUNBURST backdoor.

This killswitch will not remove the actor from victim networks where they have established other backdoors. However, it will make it more difficult to for the actor to leverage the previously distributed versions of SUNBURST.”

It is likely that given their visibility into and control over the malicious domain, Microsoft, FireEye, GoDaddy and others now have a decent idea which companies may still be struggling with SUNBURST infections.

The killswitch revelations came as security researchers said they’d made progress in decoding SUNBURST’s obfuscated communications methods. Chinese cybersecurity firm RedDrip Team published their findings on Github, saying its decoder tool had identified nearly a hundred suspected victims of the SolarWinds/Orion breach, including universities, governments and high tech companies.

Meanwhile, the potential legal fallout for SolarWinds in the wake of this breach continues to worsen. The Washington Post reported Tuesday that top investors in SolarWinds sold millions of dollars in stock in the days before the intrusion was revealed. SolarWinds’s stock price has fallen more than 20 percent in the past few days. The Post cited former enforcement officials at the U.S. Securities and Exchange Commission (SEC) saying the sales were likely to prompt an insider trading investigation.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ohio Couple Sold Secrets to China

Ohio Couple Sold Secrets to China

An Ohio man has admitted to conspiring with his spouse to steal scientific trade secrets from a children’s hospital and sell them to the People’s Republic of China. 

Former Dublin resident Yu Zhou and his 47-year-old wife, Li Chen, confessed to establishing a company in China to personally profit from cutting-edge research work done at Nationwide Children’s Hospital in Columbus, Ohio.

Zhou and Chen worked in separate medical research labs at NCH’s Research Institute for 10 years each, Zhou starting his job in 2007 and Chen beginning hers in 2008.

The couple were arrested in California in July 2019 and charged with conspiring to steal exosome-related secrets concerning the scientific research, identification, and treatment of a range of pediatric medical conditions.

While working at the institute, 50-year-old Zhou’s research included a novel isolation method in which exosomes could be isolated from one drop of blood.

“This method was vital to the research being conducted in Zhou’s lab—because necrotizing enterocolitis is a condition found primarily in premature babies, only small amounts of fluid can safely be taken from them,” said the Department of Justice. 

Husband and wife monetized this secret research by creating “isolation kits” then starting a company in China to sell their product. The couple received benefits from the Chinese government, including the State Administration of Foreign Expert Affairs and the National Natural Science Foundation of China.

Zhou pleaded guilty in US District Court on December 11 to conspiring to steal trade secrets and to one count of wire fraud. Chen pleaded guilty to the same crimes on July 30. 

As part of their pleas, the couple has agreed to forfeit property or gains associated with their crimes. For Chen, this included approximately $1.4m, 500,000 shares of common stock of Avalon GloboCare Corp., and 400 shares of common stock of GenExosome Technologies, Inc. The details of Zhou’s forfeiture will be finalized through the sentencing process.

“China’s endemic efforts to rob, replicate and replace products that they do not have the ability to develop themselves will not go unchecked, and those who seek to profit from the theft of trade secrets will be held accountable,” said John Demers, assistant attorney general for national security. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

California Hospital Notifies 67k Patients of Data Breach

California Hospital Notifies 67k Patients of Data Breach

A hospital in California has notified 67,000 patients that their personal data may have been exposed in a cyber-attack.

In a letter dated December 8, Sonoma Valley Hospital told patients that it was one of several American healthcare providers victimized two months ago in a wide-sweeping ransomware campaign.

“SVH experienced a ransomware cyber-attack on October 11, 2020 by what is believed to be a Russian threat actor,” wrote the hospital.

“This event was part of a broader attack on dozens of hospitals across the country.”

The hospital said the attack was discovered on the day that it occurred and that systems were shut down immediately in an effort to minimize any damage. 

SVH said that it hired external information technology and forensics experts to help its own cybersecurity team mitigate the threats and followed their advice to not pay the ransom demanded by the attackers. 

“After discovering the attack, our cybersecurity team—in partnership with outside information technology and forensics experts—successfully prevented the cybercriminal from blocking our system access and ultimately expelled them from our system,” said SVH.

The hospital said that before being booted out of their system, the cyber-criminal(s) behind the attack “may have removed a copy of a subset of data.”

A forensic examination of what the criminals could have accessed indicates that patients’ names, addresses, dates of birth, insurer group numbers, and subscriber numbers may have been exposed. 

Other details that could have been accessed by the criminals included diagnosis or procedure codes, date of service, place of service, amount of claim, and secondary payer information.

“Based on the reports of the forensics analysts, the hospital does not believe patient financial information (such as credit card or social security numbers) was accessed, nor was patient information in the hospital’s electronic health record system,” stated SVH. 

The hospital said that it is not aware of any misuse or attempted misuse of patient health information, and hospital forensics experts have searched for any potential re-disclosures.

While surgeries, emergency care, and the hospital’s “Follow My Health” patient portal have not been impacted by the attack, some diagnostic tests were disrupted.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Twitter Fined Half a Million Dollars for Privacy Violation

Twitter Fined Half a Million Dollars for Privacy Violation

Twitter has been fined over half a million dollars for violating European Union data protection laws in the first EU-wide privacy case. 

The EU’s chief data watchdog today announced that it has issued an administrative fine of 450,000 euros ($547,000) to the social media titan for being too slow to notify Android phone users located across the EU of a data breach that threatened their privacy.

A further finding of the investigation into the breach by Ireland’s Data Protection Commission (DPC) was that Twitter failed to adequately document the security incident. 

The DPC’s investigation into the incident commenced in January 2019 following receipt of a breach notification from Twitter. On Tuesday, the DPC stated that Twitter “infringed Article 33(1) and 33(5) of the General Data Protection Regulation (GDPR) in terms of a failure to notify the breach on time to the DPC and a failure to adequately document the breach.” 

Under EU data protection rules, it is a requirement to report a breach within 72 hours of discovery. 

The commission described the not insignificant financial penalty levied on the American company as “an effective, proportionate and dissuasive measure.”

According to the Binding Decision of the Board, the data breach arose from a bug in Twitter’s design that caused the protected tweets of Android device users to become unprotected without their consent if users changed the email address associated with their Twitter account. 

The bug, which affected 88,726 EU and EEA users between September 2017 and January 2019, was traced back to a code change made on November 4, 2014. It was discovered on December 26, 2018, by the external contractor managing Twitter’s bug bounty program.

Referencing the significance of the Twitter inquiry, the DPC stated: “The draft decision in this inquiry, having been submitted to other Concerned Supervisory Authorities under Article 60 of the GDPR in May of this year, was the first one to go through the Article 65 (‘dispute resolution’) process since the introduction of the GDPR and was the first Draft Decision in a ‘big tech’ case on which all EU supervisory authorities were consulted as Concerned Supervisory Authorities.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Businesses Often Do Not Inform Customers of Tracking

Businesses Often Do Not Inform Customers of Tracking

Almost three-quarters of businesses admit that tracking of customer data happens, but without consent.

According to research from Zoho Corp, a survey of 1400 business leaders about third party ad tracking found 100% of respondents said their companies allow it, and 57% are “comfortable” or “very comfortable” with the way third-parties use customer data. However, 72% admit they know that tracking happens but do not inform customers.

In the USA and Canada, 62% of companies don’t inform customers that they allow tracking code from third-party services on their websites, despite the majority claiming to have well-defined consumer data privacy policies that are strictly applied.

Raju Vegesna, Zoho’s chief evangelist, told Infosecurity that he believed businesses have a moral obligation to be transparent with customers about what data they collect and who they share this sensitive information with.

“Our survey findings show an alarming disconnect between how business leaders view the strength of their privacy policies and what information they keep secret from customers,” he said. “Right now, our remote workforce is reliant on software solutions to continue business operations; business leaders need to put themselves in the position of their customers and ask ‘as a user, do I want to be tracked?’ ”

However, he claimed many businesses are failing this ethical test, which shows they care more about profits than privacy. “We shouldn’t have to wait for regulation to spur businesses to take stronger stances on consumer data privacy protections,” he said. 

Asked if businesses should be more transparent on what is collected, and who they supply this data to, Niamh Muldoon, senior director of trust and security at OneLogin, said: “Leaders in trust and security have built their brand and reputation with their customers by being transparent with the use of data while providing assurance that appropriate controls are in place to protect the data as it is inputted, processed and stored.

“The survey results highlight the lack of awareness and understanding amongst business leaders on how to build trust and security into a brand and use it as a key business differentiator.”

Matthew Pahl, security researcher at DomainTools said businesses will continue to place profit over privacy. “As soon as it becomes unprofitable for businesses to allow widespread tracking of customer habits and data, we will see a change in corporate practices.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#BSEC: Staying Alert to the Growing Dangers of Cybercrime

#BSEC: Staying Alert to the Growing Dangers of Cybercrime

Cybercrime is becoming increasingly dangerous to organizations and individuals alike, according to Chief Supt. Andrew Gould, national cybercrime programme lead at the National Police Chiefs’ Council speaking during the BankSec 2020 virtual conference.

One reason for this is that cybercrime is becoming easier to conduct, with tools more readily available from the internet and able to be deployed without much technical skill. “That barrier to entry to the criminal marketplace is lower than it’s ever been,” noted Gould.

The rise in cybercrime as a service, whereby nefarious actors from across the world can be employed relatively cheaply to help undertake attacks, has been another big factor in recent years.

The kinds of attacks being launched are also becoming more consequential. While ransomware remains the biggest attack vector, with Gould observing that the malware used is “more complex and damaging”, the behavior of cyber-villains becoming “more confrontational.”

Business fraud attacks – in particular, phishing and business email compromise (BEC) attempts, have grown exponentially recently according to Gould. “There are millions of pounds that organizations are losing to this every week which causes tremendous disruption,” he outlined.

Another trend highlighted is that criminals are conducting far more research and planning ahead of attacks, largely as a result of improved security. Much of this is discovering personal information on social media sites in order to launch more impactful phishing messages for example, with Gould stating that people should “consider the kind of information they’re posting and how that can potentially be used against you or your organization by appearing to be more realistic.”

For organizations to mitigate against these threats, Gould said it is vital that backups are in place, which unfortunately is often not the case. “You can recover from just about any security breach unless you don’t have effective backups – if you can’t restore from backups you can potentially lose everything,” he said.

His other main advice to organizations is to have strong password policies, ensuring the use of three random words and two-factor authentication is mandated across staff, as per National Cyber Security Centre (NCSC) recommendations. He commented: “If your organization is enforcing those standards for your staff and for your customers, you are going to mitigate a lot of current successful attacks.”

In terms of the police response to cybercrime in the UK, Gould explained that a much more proactive approach is now being taken. While there is a very strong and integrated national network, a greater focus on preventing these types of crime at a local level is crucial. Now, every police force in the country has a cybercrime unit which undertakes initiatives such as giving advice to victims, helping organizations improve their defences and incident response strategies, as well as identifying young people who are at risk of going down the path of cybercrime in order to “point them on a more meaningful path.”

Gould added: “Unlike other areas of crime, these are skills we want to encourage because there’s a huge skills shortage in the industry – so we want people to test their skills and improve, but in a safe way.”

He said this approach has taken the pressure off the regional teams to focus on organized crime groups, “so there’s a level of proactive, covert operations against the high end crime groups that’s gone from strength to strength.” This, he believes will lead to increased numbers of cybercrime arrests and prosecutions in the months and years ahead.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Millions of Medical Imaging Files Freely Accessible on Unprotected Servers

Millions of Medical Imaging Files Freely Accessible on Unprotected Servers

Over 45 million medical imaging files are freely accessible on unprotected servers, according to a new investigation by CybelAngel

The researchers discovered that a huge range of sensitive medical images, including X-rays and CT scans, can be accessed without the requirement for a username and password. Instances were even found of login portals accepting blank usernames and passwords.

The team scanned around 4.3 billion IP addresses, and found that more than 45 million of these images were left exposed on over 2140 unprotected servers across 67 countries including the US, UK and Germany.

CybelAngel also revealed that personal information was among the data left unencrypted and without password protection online. This includes personally identifiable information such as name, birth date, address and personal healthcare information including height, weight and diagnosis.

The easy availability of this kind of imagery and data leaves patients at risk of blackmail and ransomware as well as fraud, according to the study authors, who noted that medical data is in high demand on the dark web.

The investigators added that healthcare providers may be liable to sanctions for these breaches of sensitive patient information under data protection laws such as the GDPR in Europe.

Author of the report, David Sygula, senior cybersecurity analyst at CybelAngel commented: “The fact that we did not use any hacking tools throughout our research highlights the ease with which we were able to discover and access these files. This is a concerning discovery and proves that more stringent security processes must be put in place to protect how sensitive medical data is shared and stored by healthcare professionals. A balance between security and accessibility is imperative to prevent leaks from becoming a major data breach.”

Todd Carroll, VP cyber operations at CybelAngel added: “Medical centers work with a vast, interconnected web of third-party providers and the cloud is an essential platform for sharing and storing data. However, gaps in security, such as this, present a huge risk, both for the individuals whose data is compromised and the healthcare institutions that are governed by regulations to protect patients’ data.

“The health sector has faced unprecedented challenges this year, however the security and privacy of their patients’ most personal records must be protected, to prevent highly confidential data falling into the wrong hands.” 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

DHS, CISA and NCSC Issue Warnings After SolarWinds Attack

DHS, CISA and NCSC Issue Warnings After SolarWinds Attack

Government agencies have issued warnings about the fresh spate of attacks, apparently from nation-state actors against major security vendors.

Last week FireEye disclosed that it had spotted an attack from nation state actors looking for data on government clients, where attackers were able to access some internal systems and steal some of FireEye’s red team tools. It was later disclosed that the attack was enabled by using trojanized updates to SolarWinds’ Orion IT monitoring and management software, although Solarwinds said that fewer than 18,000 of its global customers had been affected.

The Cybersecurity and Infrastructure Security Agency (CISA) has issued Emergency Directive 21-01 in response to the SolarWinds compromise which calls “on all federal civilian agencies to review their networks for indicators of compromise and disconnect or power down SolarWinds Orion products immediately.”

In a statement, CISA acting director Brandon Wales said “the compromise of SolarWinds’ Orion Network Management Products poses unacceptable risks to the security of federal networks.”

He said: “Tonight’s directive is intended to mitigate potential compromises within federal civilian networks, and we urge all our partners—in the public and private sectors—to assess their exposure to this compromise and to secure their networks against any exploitation.”  

Also, Alexei Woltornist, assistant secretary for public affairs at the Department of Homeland Security, said DHS is aware of cyber breaches across the federal government and working closely with its partners in the public and private sector on the federal response.

A spokesperson for the UK’s National Cybersecurity Centre (NCSC) said in a statement: “The NCSC is working closely with FireEye and international partners on this incident. Investigations are ongoing, and we are working extensively with partners and stakeholders to assess any UK impact. The NCSC recommends that organizations read FireEye’s update on their investigation and follow the company’s suggested security mitigations.”

It recommended organizations ensure any instances of SolarWinds Orion are configured according to the company’s latest guidance, and have these instances installed behind firewalls, disabling internet access for the instances, and limiting the ports and connections to only what are critically necessary.

Commenting, Sam Curry, chief security officer at Cybereason, said: “If 2020 has taught us anything, it is that the COVID-19 pandemic has improved the resiliency of security professionals and reinforced how determined defenders are to rid networks of cyber-espionage adversaries. In fact, all UK companies should respond with a cold, logical, rational response.

“In general, now is not the time for security experts to panic. A practical and measured response is advised.”

If SolarWinds is being used in your organization, Curry recommended strengthening your security posture as follows:

  • Isolate machines running SolarWinds until further information is available as the investigation unfolds
  • Reimage impacted machine
  • Reset credentials for accounts that have access to SolarWinds machines
  • Upgrade to Orion Platform version 2020.2.1 HF1 as soon as possible. Solar Winds has also provided further mitigation steps

“In addition, set up a task force to look through all data logs, check the hygiene of systems and make sure everyone is generally on high alert for future attacks,” he said. “Ensure your company is always on the hunt for adversaries. The sooner you do these things the sooner you can assume no one is lurking in your network in silent mode.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#BSEC: The Continuous Evolution of Cyber-Attacks

#BSEC: The Continuous Evolution of Cyber-Attacks

Current and likely future cyber-attack trends were highlighted by Sarah Armstrong-Smith, chief security advisor, Microsoft Cybersecurity Solutions Group (UK) during the BankSec 2020 virtual conference.

Through its analysis, Microsoft found that phishing and business email compromise (BEC) attacks remain the most common tactic employed, but are becoming increasingly sophisticated in nature. “The ultimate aim is credential theft,” noted Armstrong-Smith, revealing that in the last year, Microsoft have processed six trillion different messages, blocking 13 billion malicious emails.

One trend observed in regard to BEC attacks is the rise of CEO impersonation, while brands commonly spoofed include large tech companies like Microsoft and Amazon.

There has also been a substantial growth in high impact ransomware incidents in recent times, with a notable feature being that they are “driven by human ransomware and active reconnaissance,” according to Armstrong-Smith. She added: “Cyber-criminals really do take their time to learn about your company and how and when they are going to launch an attack.” This targeted approach means that attacks can be launched in as little as 45 minutes from accessing an organizations’ system.

Armstrong-Smith additionally highlighted how cyber-criminals are rapidly responding to the changing news cycle, which has been especially evident during the COVID-19 pandemic this year. This enables attacks to be timed to be most impactful. For instance, once a global pandemic was declared from the beginning of March, and governments began taking action to stop the spread of the virus, “there was a massive peak in COVID-related attacks,” including phishing lures and fake domains.

At the same point this year, Microsoft detected a huge rise in DDoS attacks, designed to exploit businesses while they were distracted in a number of areas, such as shifting to remote working. Another method employed by malicious actors is to combine DDoS attacks and ransomware. Armstrong-Smith noted: “Cyber-criminals are really evolving in terms of what they’re doing and how they do it.”

This means organizations must be ready for further changes in the methods used by cyber-criminals going forward. One of these could be in response to improved cybersecurity technologies, and in particular, the growing use of machine learning to detect threats. According to Armstrong-Smith, there are signs that threat actors are looking at disrupting and “poisoning” the algorithms of machine learning tools, skewing the results they give, and therefore security decisions made.

A further major security threat that is expected to surge in the coming years relates to the increasing use of IoT devices by employees and organizations. This issue has been exacerbated this year by the shift to home working, where staff have “multiply different devices that are potentially sat on the same network.” Armstrong-Smith noted that we are likely to see moves to smart buildings and even smart cities in the future, which will mean “everything is actually interconnected in one way or another, across the internet.”

In response to this evolving threat landscape, she said it is vital that organizations improve their resilience. This requires a mindset shift, moving “away from trying to stop everything to actually assuming compromise,” and the ability “to recover as quickly as possible.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Spotify Resets Passwords After Leaking User Data to Partners

Spotify Resets Passwords After Leaking User Data to Partners

Spotify has been forced to issue a password reset for users after admitting that their information was exposed to some of the firm’s third-party business partners.

The music streaming giant said in a customer data breach notification sent to the California attorney general that the privacy snafu was only discovered and fixed after seven months.

“On Thursday November 12, Spotify discovered a vulnerability in our system that inadvertently exposed your Spotify account registration information, which may have included email address, your preferred display name, password, gender, and date of birth only to certain business partners of Spotify,” it explained.

“Spotify did not make this information publicly accessible. We estimate that this vulnerability existed as of April 9, 2020 until we discovered it on November 12, 2020, when we took immediate steps to correct it.”

Spotify said it has contacted all of those partners to ensure they delete the exposed customer information, and has reset the passwords of affected users.

“We have no reason to believe that any unauthorized use of your information has or will occur, however, we urge you to change the passwords of all other online accounts for which you use the same email address and password,” it added.

This is the third security incident affecting the firm in recent months. A few days ago a hacktivist calling themselves ‘Daniel’ hijacked the Spotify for Artists page, posting messages in support of Taylor Swift and Donald Trump.

A few days before that, in late November, security researchers discovered a leaky cloud database containing logins for up to 350,000 Spotify users likely to have been part of a credential stuffing campaign.

Laurence Pitt, technical security lead at Juniper Networks, urged internet users to use a password manager to help them store strong, unique credentials for each online account.

“Many people pay for premium Spotify services and with access to a password, anyone would be able to redirect a subscription for their own use,” he added.

“Password re-use is dangerous because if any of the data from this exposure does fall into the wrong hands, then it will end up in brute-force attack databases providing valid username/password combinations for access to other services.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk