Minor Behind 2016 PlayStation DDoS Attacks

Minor Behind 2016 PlayStation DDoS Attacks

An unnamed individual in the United States has pleaded guilty to creating a botnet and using it to launch a series of cyber-attacks against the gaming community before reaching their 18th birthday.

The Distributed Denial of Service (DDoS) attacks, carried out in October 2016, caused what the United States Department of Justice described as “massive disruption to the internet.”

As a result of the attacks, websites, including those pertaining to Sony, Twitter, Amazon, PayPal, Tumblr, Netflix, and Southern New Hampshire University (SNHU), became either completely inaccessible or accessible only intermittently for several hours on October 21, 2016. 

“As a result of the individual’s DDoS attacks, Dyn, Sony, SNHU, and other entities and individuals suffered losses including lost advertising revenues and remediation costs,” said the DOJ. 

“Sony estimated that its resultant losses included approximately $2.7 million in net revenue.”

On December 9, the Department announced that an individual, formerly a juvenile, had pleaded guilty to committing acts of federal juvenile delinquency in relation to the 2016 cyber-attacks.

Unsealed court documents revealed that from approximately 2015 until November 2016, the individual conspired with others to build and operate at least one online botnet, which they then used to launch DDoS attacks against multiple victim computers.

The botnet was a variant of the Mirai botnet that infected Internet-of-Things devices, such as internet-connected video cameras and recorders, turning them into bots that could launch DDoS attacks.

The individual and their co-conspirators specifically targeted computers belonging to online gamers or to gaming platforms, knocking then offline completely or otherwise significantly impairing their functionality.

On October 21, 2016, the individual and others launched multiple DDoS attacks against the Sony PlayStation Network’s gaming platform in an attempt to knock it offline for a sustained period.

According to the plea agreement, the individual conspired to commit computer fraud and abuse by operating a botnet and by intentionally damaging a computer. Because the individual was aged under 18 when they committed the offenses, their identity is being withheld pursuant to the Juvenile Delinquency Act.

The guilty plea was entered in a closed proceeding before Chief Judge Landya McCafferty in the District of New Hampshire. Judge McCafferty scheduled the individual’s sentencing to take place on January 7, 2021.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

One Million US Dental Patients Impacted by Data Breach

One Million US Dental Patients Impacted by Data Breach

An American healthcare provider has started notifying more than a million patients that their data may have been exposed as the result of a cyber-attack.

Dental Care Alliance discovered on October 11 that it had been the victim of a hack that began on September 18, 2020. The company, which is headquartered in Sarasota, Florida, was able to contain the attack by October 13.

Patient data that may have been accessed in the security incident included names, addresses, dental diagnosis and treatment information, patient account numbers, billing information, bank account numbers, the name of the patient’s dentist, and health insurance information. 

Dave Quigley, general counsel for DCA, told Databreaches.net that the breach had been reported to all relevant regulatory bodies and that DCA had notified all 1,004,304 people affected by the incident via letter in November. 

Explaining why no remediation services such as credit monitoring had been offered to patients impacted by the breach, Quigley said: “We have seen no specific evidence that personal information was used for malicious purposes.” 

He added: “We will continue to do all that is necessary and appropriate to support and inform impacted individuals in the days ahead.”

A review of what data the attackers were able to access concluded that bank account numbers belonging to only 10% of the individuals impacted by the hack were visible to an unauthorized third party. 

Dental Care Alliance is a dental support organization with more than 320 affiliated dental practices across 20 states. The LLC was established in 1991 by Dr. Steven Matzkin and currently works with more than 700 dentists. 

The incident comes 10 months after a ransomware attack on Colorado information technology company Complete Technology Solutions (CTS) impacted about 100 dental practices in the United States, leaving staff unable to access patient records and treatment schedules.

Practices in Colorado, Kansas, Nebraska, and Nevada were impacted by the incident, including the Pediatric Dental Specialists of Greater Nebraska. 

Co-owner Dr. Jessica Meeske, describing the effect of the attack on the practice, told the American Dental Association: “You are absolutely paralyzed in the same way as if you lost your location physically.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ransomware Campaign Targets MySQL Servers

Ransomware Campaign Targets MySQL Servers

Internet-connected MySQL databases around the world are being targeted by a double extortion ransomware campaign that researchers have dubbed PLEASE_READ_ME.

The campaign, which dates back to at least January 2020, was detected by researchers at Guardicore Labs. So far, it has breached more than 83,000 of the more than five million internet-facing MySQL databases in existence worldwide. 

Simple but effective in its approach, the campaign uses file-less ransomware to exploit weak credentials in MySQL servers. After gaining entry, the attackers lock the databases and steal data. 

The attack is a double extortion because its authors use two different tactics to turn a profit. First, they try to blackmail the database owners into handing over money to retrieve access to their data. Second, they sell the stolen data online to the highest bidder. 

Researchers noted that the attackers have been able to offer over 250,000 databases for sale on a dark web auction site so far. 

The attackers leave a backdoor user on the database for persistence, allowing them to re-access the network whenever the mood strikes them.

Researchers were able to trace the origins of the attacks to 11 different IP addresses, the majority of which are based in Ireland and the UK.

Since spotting the first attack on January 24, the Guardicore Global Sensors Network (GGSN) has reported a total of 92 attacks. Since October, the rate at which attacks are being launched has risen steeply.

Two variants have been used over the campaign’s lifetime, showing an evolution in the attackers’ tactics. The first was used from January to the end of November for 63 attacks, and the second phase kicked off on October 3, halting at November’s end. 

In phase one, the attackers left a ransom note with their wallet address, the amount of Bitcoin to pay, and an email address for technical support. Victims were given 10 days to pay up. 

“We found that a total of 1.2867640900000001 BTC had been transferred to these wallets, equivalent to 24,906 USD,” noted researchers.  

In the second phase, the attackers ditched the Bitcoin wallet in favor of a website in the TOR network where payment could be made.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cyber Helpline Receives Lottery Funding to Help Growing Number of Victims

Cyber Helpline Receives Lottery Funding to Help Growing Number of Victims

The Cyber Helpline, a volunteer organization that offers emergency assistance to victims of cybercrime and cyber-stalking in the UK, has been awarded £10,000 in lottery funding.

The group said the money will be used to support its helpline and chatbox services, with demand rising rapidly due to the growing levels of cybercrime following the shift to digital during COVID-19. This includes further investment into its chatbot technology, which ensures 24/7 support is available to victims, as well as enabling the onboarding of new volunteers as helpline responders to deal with live cybercrime issues.

The Cyber Helpline was formed several years ago in response to a lack of support for cybercrime victims in the UK, and currently provides practical assistance to around 400 victims every month. It has a team of 50 volunteer cybersecurity experts.

It noted common issues it responds to include cyber-stalking, lost devices, hacked accounts, online bullying and harassment and sextortion.

The funding comes from The National Lottery Community Fund, which distributes money raised from National Lottery players for good causes.

Rory Innes, founder of The Cyber Helpline, commented: “We’re delighted that The National Lottery Community Fund has recognized our work in this way. Now, thanks to National Lottery players, we will be able to support hundreds more victims of cybercrime in the UK and alleviate the severe emotional and financial burden caused by these attacks. At a time when the country is going through a national lockdown and economic hardship amid redundancies and closed businesses, we see our mission of creating a country where the cyber-criminals do not win as more important than ever.”

Back in August, INTERPOL observed that cybercrime is growing at an “alarming pace” as a result of COVID-19, while earlier this week, McAfee revealed that total global losses from cybercrime has exceeded $1tn.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Vade Secure Appoints Ex-Israeli Military Staff Sergeant Maya Gershon as CRO

Vade Secure Appoints Ex-Israeli Military Staff Sergeant Maya Gershon as CRO

Email defense provider Vade Secure has announced the appointment of former Israeli military staff sergeant Maya Gershon as its new chief revenue officer.

Gershon is an electrical and computer engineering graduate who started her career working at Unit 8200, a top-secret and classified cyber-unit of the Israeli Military Intelligence.

She brings 20 years of sales and marketing experience to Vade Secure, having previously held leadership positions at companies including WeWork, Intel, Cisco and IronSource.

Gershon assumes leadership of the firm’s global sales and marketing activities and heads up the acceleration of its business development.

“Our international development strategy is based on indirect sales via our MSP partners, aggregators, ISPs and OEMs,” said Gershon. “My goal is to accelerate this strong momentum with our partners in our existing markets and within new markets by developing effective and partially automated sales and marketing processes, resulting in a virtuous chain of new business generation for Vade Secure and its partners.” 

The appointment announcement coincides with the opening of Vade Secure’s first office on Israeli soil, which is located in the local technological ecosystem with access to Israel’s talent pool.

“Nearly 100% of Israeli cybersecurity companies sell their products and services internationally,” said Georges Lotigier, CEO of Vade Secure. “With its internationally oriented market, Israel was a planned step in Vade Secure’s global expansion strategy. Maya brings us her experience in international growth acceleration while being immersed in one of the world’s most important cybersecurity ecosystems.” 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#WALLIXLive: Focus on Identity and Access Management to Secure Remote Workforce

#WALLIXLive: Focus on Identity and Access Management to Secure Remote Workforce

Identity and access management will be crucial to securing workforces going forward, according to a panel speaking of experts during the Wallix Live: The State of Security event.

The speakers acknowledged the “herculean” effort of many organizations to successfully roll out mass remote working at very short notice this year after the COVID-19 pandemic struck. All the indications are that this way of working will be utilized far more going forward, and “the net result is that more people than ever before will need to access corporate data from their homes and personal devices,” said Didier Lesteven, executive vice-president sales and marketing at Wallix.

Despite the many benefits of remote working demonstrated during this period to both employers and staff, this way of working clearly adds to the security risks for organizations, who are no longer able to rely on a strong outer perimeter strategy, with information accessed across multiple devices and networks.

This requires a fundamental reshaping of organizations’ security strategies, and “identity access becomes a critical point if we are trying to secure these new ways of working,” commented Soumya Banerjee, cyber-expert at McKinsey.

Outside of the corporate buildings, it is much harder for security staff to gain visibility of the identities of those accessing different parts of the network, especially as increasing numbers of companies move to multi-cloud environments. Yet gaining this control is critical.

Laura Deaner, CISO, S&P Global, noted that within an organization, “everyone is important to a criminal because if they can get in, they will get in, so they don’t need to necessarily target C-suites – they can target anyone, including people who have privileged access and identities.”

The concept of security by design, which aims to proactively address risks early in the system development cycle, could be applied to manage access and identity more securely. Lesteven outlined that organizations must have a clear strategy by which users are identified, authenticated and the resources they are allowed to gain secure access to are managed, all of which “needs to be monitored for future auditing purposes.”

He added: “These global security process need to be by design and applied to all steps of the digital journey of any users.”

This approach needs to be taken in consideration of the expectations of users, however, as it may be a source of frustration if it is harder to gain access to data compared to being in the office environment. In the view of Banerjee, this requires security teams to learn and understand the perspective of users and what they want. “As an identity professional, my approach is now about how I can make it more human centric, experience based and then see what the technology and process enablers are for that experience.”

Ultimately, finding the right balance, and potentially compromise, is key. Deaner concluded: “The most challenging thing is the balance between usability and security. I want everyone on my network to feel like they’re able to operate effectively, but I also have to protect them.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#BHEU: North Korea’s Cyber-Offense Strategy Evolving to Focus on International Economic Targets

#BHEU: North Korea’s Cyber-Offense Strategy Evolving to Focus on International Economic Targets

North Korea’s offensive cyber-program evolved from one of power projection to one which is “dual-focused” and going after international economic targets.

Speaking at Black Hat Europe 2020, Crowdstrike researchers Jason Rivera and Josh Burgess discussed how North Korea had advanced its strategy from one of showing force, which was more prevalent under the leadership of Kim Jong-Il, to one which is now going after targets other than the US, South Korea and Japan.

At first, it had engaged in DDoS attacks and deploying wiper malware, but Rivera, director of the strategic threat advisory group at Crowdstrike, said it was not able to do “any serious damage.” However, attacks became more focused and targeted, such as data exfiltration from South Korea’s Ministry of Defense and the attacking of the Seattle subway system and the 2014 attack on Sony Pictures.

In the power protection era, Rivera said that they would often focus attacks on military targets and demonstrate its nuclear capabilities “to push back its regional adversaries” as well as the USA.

The next phase focused on generating currency, due to the economic sanctions placed on North Korea because of its nuclear program “in order to bypass some of the financial hardships brought on by these sanctions.” Rivera said Crowdstrike had observed North Korea engaging in different types of currency generation operations, including fraudulent attacks, ransomware, attacks on the SWIFT banking systems and ATM cash out schemes.

However, it’s current activity is on a dual-focused effort, where it goes after economic targets for currency generation, but also attacks critical infrastructure, international targets  and even the United Nations. “Also, with currency  generation, we see the targeting of non-traditional targets, such as crypto-currency exchanges, especially those located in East Asia,” Rivera said.

“We also see a lot of focus on economic growth targeting, taking a page out of China’s playbook. China engages in a lot of espionage in support of their own economy, and we’re now seeing North Korea do the same and it appears to be focused on critical infrastructure sectors where they need a lot of help.” This includes power generation and agriculture, to empower its economy.

North Korea is also targeting international organizations like the UN and Israel’s industrial base. “This demonstrates a high degree on behalf of the North Korean regime and at this point they do believe that they have succeeded and got to the point where they are at now, taking it to the next level,” he said.

Burgess, technical lead for threat intelligence at Crowdstrike, said the focus on energy production is on all forms including oil, gas and coal, and this has seen targets in the USA being hit. “It was more designed to steal than anything else, especially in a recent oil and gas campaign, as it was designed to go through and pilfer out information and throw the wiper on the end and make it seem like they could control power,” Burgess said. “Everything was designed to be more business focused and disable business.”

Looking forward, Rivera predicted an increased use of advanced ransomware, including offering ransomware-as-a-service and data extortion where data is stolen and encrypted, and the victim is blackmailed into paying up or the data is exposed.

Rivera also said North Korea is expected to follow China’s lead and carry out more economic espionage, and follow a concept of “cyber-brinkmanship” where two sides make threats and it comes down to “who calls chicken first.” He said Crowdstrike has seen North Korea “bring its adversaries to the edge and use cyber or nuclear threats to determine the effects.” As it would not survive a nuclear encounter and this would lead to international condemnation and a potential regime change, Rivera said he expected North Korea to move to the cyber-side “as this is safer for them.”

Rivera said: “The cyber-route still allows them to project power, still allows them to take swipes at their adversaries, but does so in a much safer way and has a lower risk of kinetic retaliation but also a lower risk of having the Kim dynasty replaced.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Senior Managers Set Terrible Example for Secure Remote Working

Senior Managers Set Terrible Example for Secure Remote Working

Senior managers in UK and US companies are routinely exposing their organization to cyber-threats with more risky device and password management practices than their junior colleagues, according to OneLogin.

The identity and access management (IAM) provider polled 2000 remote workers in both countries this month, to compile its State of Remote Work Survey 2.0.

It found that senior managers were twice as likely to share a work device with someone outside the organization: 42% admitted doing so versus 20% of their junior counterparts.

They were also more than twice as likely to share passwords: 19% confessed to giving their credentials to a family member compared to only 7% of junior employees.

Finally, nearly a third (30%) of senior staff admitted working from public Wi-Fi, versus just 15% of junior workers.

The report also revealed that remote workers in the US appear to be less security-focused than their counterparts across the Atlantic. In total, 7% more American than UK respondents shared work devices, 9% more worked on public Wi-Fi and 8% more downloaded personal applications.

Brad Brooks, CEO of OneLogin, argued that distributed working has made it important for employees to take greater responsibility for their security posture.

“The effects of the pandemic mean that virtually all organizations are now operating, to some degree, outside of the controlled and protected office environment. That is, without the corporate-grade firewalls and on-site IT people we all once relied on for protection,” he added.

“Understanding the sanctity of their corporate passwords and devices, and the potential dangers of working on an unsecure Wi-Fi network should be top priorities for all remote workers. More importantly, it is up to senior management to lead by example. Unfortunately, these results appear to indicate otherwise.”

The report also revealed that male respondents were more likely to engage in risky behavior than their female colleagues.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Leaky Elasticsearch Server Reveals Massive Instagram Click Farm

Leaky Elasticsearch Server Reveals Massive Instagram Click Farm

Security researchers have uncovered a massive Instagram click farm in central Asia, operating tens of thousands of fake profiles.

A team at vpnMentor found the operation thanks to a completely unsecured Elasticsearch database it was using, connected to the public-facing internet.

“The click farm appears to be run by a sophisticated operation that has built a highly automated process to create tens of thousands of fake proxy accounts on Instagram. Each account had its own avatar, bio and ‘persona,’ appearing to join Instagram from all over the world,” said vpnMentor.

“Each fake account would then publish posts, view others’ posts, follow, react and engage with profiles. The click farm was also using proxy servers and IP addresses to hide its activity.”

Operated from either Armenia or Kazakhstan, this C&C server contained usernames, passwords, proxy IP addresses and email addresses for the fake accounts, as well as related SMS verification codes and phone numbers.

The researchers tied the operation back to central Asia as many of the IP addresses and mobile phone numbers used to authenticate and run the fake accounts were from Armenia and Kazakhstan.

“Click farms are often paid by individuals or companies to inflate their followers and engagement. The people hiring click farms then use this to leverage sponsorship posts and other forms of income from the app. In doing so, they’re defrauding any company or third party that pays them based on followers and engagement,” explained vpnMentor.

“Click farms are also used to spread fake news and misinformation. There is plenty of evidence that this is already a widespread practice and a popular form of election interference, manipulation and indirect attack on rivals by governments like Russia, China, Iran and their allies.”

After notifying Facebook about the server on September 21, it was shut down the following day.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Hackers Raid European Agency for Pfizer Vaccine Docs

Hackers Raid European Agency for Pfizer Vaccine Docs

The European Medicines Agency (EMA) has suffered a cyber-attack which led to the compromise of documents related to the Pfizer/BioNTech vaccine, currently being deployed in the UK.

The agency itself only issued a very brief statement, saying it could not provide more details while an investigation was still underway.

“EMA has been the subject of a cyber-attack,” it noted. “The agency has swiftly launched a full investigation, in close cooperation with law enforcement and other relevant entities.”

However, BioNTech disclosed more about the incident.

“Today, we were informed by the EMA that the agency has been subject to a cyber-attack and that some documents relating to the regulatory submission for Pfizer and BioNTech’s COVID-19 vaccine candidate, BNT162b2, which has been stored on an EMA server, had been unlawfully accessed,” it revealed.

The news comes just days after IBM revealed a sophisticated nation state phishing campaign against various organizations that provide the cold chain storage needed to distribute the Pfizer vaccine globally.

Sensitive information on vaccines developed in the West has been sought-after by nation state actors from China, Russia and North Korea for months. In October, an Indian pharma giant making Russia’s Sputnik-V vaccine was forced to shut several facilities after an unspecified incident.

Warnings from the likes of the National Cyber Security Centre (NCSC), Microsoft and US authorities have come thick and fast throughout the year.

Mark Hendry, director of data protection and cybersecurity at law firm DWF, said it’s unclear whether the EMA attack was nation state or cybercrime-oriented.

“Being aware of the cyber-attackers’ mind set is important in anticipating, preparing for and defending against such attacks,” he added. 

“Businesses should consider identifying and planning for recurring or one-off events in their organizational lifecycle when they might become a likely target of attack and ensure that robust people, process and technology-based defense and response systems are in place to deal with threats.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk