#BHEU: Ransomware Attackers Professionalizing Operations with Partnership Platforms

#BHEU: Ransomware Attackers Professionalizing Operations with Partnership Platforms

Speaking during Black Hat Europe 2020 Mitchell Clarke and Tom Hall, principal incident response consultants at Mandiant, explored the evolving global ransomware threat landscape.

Clarke and Hall explained that ransom demands are becoming larger, attackers smarter and intrusions longer, with cyber-criminals professionalizing and streamlining their ransomware strategies through partnership platforms – commonly coined Ransomware-as-a-Service offerings.

“These are operators that will target a number of organizations and sell access to ransomware threat actors,” explained Hall.

Ransomware crews have been detected leveraging high-profile critical vulnerabilities to gain footholds in as many victim networks as possible, only to come back weeks or even months later to leverage those footholds into full-scale ransomware deployments, the speakers said.

Such affiliate ransomware platforms are attractive to cyber-criminals because they offer key benefits including malware generation, communication and negotiation with victims and, in some cases, payment processing and decryption utility delivery, Mitchell explained.

One prime example of a prevalent ransomware affiliate group that has established itself in 2020 is REvil, Mitchell added.

“REvil are interesting because they run a Ransomware-as-a-Service platform – a platform with many different affiliates or other attackers that join in to use the same malware and the same platform.”

Looking forward, and due to the ongoing scaling-up of ransomware operators through business-like service platforms, Mitchell predicted that ransomware will continue to pose a major threat to organizations in 2021, citing increasing ransom demands and pay-outs, numbers of victims, damage to organizations and extortion of stolen data.

“Potentially, we will get to a point where the only way to recover [from ransomware] is to pay the ransom or to have a good backup mechanism in place, which may be quite rare at the moment. With so many victims and so much compromise going on, unfortunately, the only trend [for ransomware] is upwards,” Mitchell concluded.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Insider Cybersecurity Risk Soars During Lockdown

Insider Cybersecurity Risk Soars During Lockdown

Many insider threats are now considered more critical to corporate cybersecurity than before the pandemic, as organizations struggle to manage remote working staff, according to Netwrix.

The security vendor polled 937 IT professionals about how the COVID-19 crisis has changed the risk landscape, to compile its 2020 Cyber Threats Report.

Around a quarter admitted they feel more vulnerable to threats now than before the pandemic, with 85% of CISOs admitting they sacrificed cybersecurity to rapidly support remote working. As a result, 60% of respondents are concerned they may have left some security gaps in the process.

In many cases, it is concerns about user behavior that dominate: 58% believe that employees might ignore security rules and put data at risk.

The main insider risks highlighted by respondents as a critical threat to the organization are: accidental improper sharing of data (68%); misconfiguration of cloud services (66%); accidental mistakes by IT administrators (62%) and data theft by employees (66%).

Accidental IT admin mistakes (27%) and improper sharing of data (26%) were the second and third most common incident experienced by organizations, after phishing.

They were also among the hardest to detect; both took days rather than hours or minutes to spot in over a third of cases.

Large enterprises were more likely to experience IT administrator mistakes: 33% reported suffering at least one incident since working from home began.

“In this age of remote work, the insider threat can’t go unaddressed. We cannot emphasize enough the importance of paying attention to how employees handle sensitive data and follow security policies,” argued Ilia Sotnikov, VP of product management at Netwrix.

“Now is the time to revisit the founding principles of security — including tracking user activity, automating change and configuration auditing, and enabling alerts on harmful actions — to ensure that insider misbehavior is detected and addressed in a timely manner.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#BHEU: Collision of Cyber-Communities Creating Tension and Risk

#BHEU: Collision of Cyber-Communities Creating Tension and Risk

The clash of four groups of cyber-communities has created risk overlaps and occasional tension, but there is the opportunity to overcome that.

Speaking in the opening keynote of Black Hat Europe 2020, Black Hat and DEFCON founder Jeff Moss said the groups “collide and create tension” among the primary four actors in our space:

  • Organized criminals – who are mostly interested in how to make the most amount of money with the least amount of risk
  • Governments – who are not as single-minded as a crime group, as they may have differing interests among different agencies, and may “conduct some clandestine operations to steal some secrets.” He said on a domestic and policy front, we see governments with a handful of agendas
  • Companies – who manufacture the product, build the infrastructure and are generally interested in maximizing return, minimizing disruption, regulation and embarrassment. “They are the experts who built the product, so they are the ones mostly seen in front of government and lobbyists”
  • The academic, hacker and security research community – who are those trying to figure out how the product works and asking, under the surface, is it doing what the manufacturers claims and if not “we want to tell the world about it”

“Through this process we’ve come up with disclosure and that led to bug bounty programs, and we act as a neutral third party telling policy makers what is and isn’t possible, and this leads to tension,” he said. This can be tension between the researcher and government, as the government wants to know what is possible, and they need a voice to tell them something different that is not coming from the lobbyists.

He said security researchers have moved more and more into the realm of policy; “we’re now providing that information as policy makers have grown up with technology and computers and are now asking us our opinion.”

Moss said this is a “very dangerous time for us now” as, on one hand, we’re being asked for our opinion, which is a great thing, but this is also a risk “and if we screw this up we may not be taken seriously, so it is very important that the community of infosec researchers and the community of government learn from each other and we learn how to work through this tension.”

He concluded by saying that governments have been around for hundreds of years, while technology researchers are pretty new “and we’re not steeped in the ways of political navigation,” so researchers need to be given a chance and also need to be guided on how to get the most from our knowledge.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Microsoft Patches Just 58 CVEs in Light December Update

Microsoft Patches Just 58 CVEs in Light December Update

Microsoft spread some festive cheer among sysadmins this month with a Patch Tuesday only around half as large as most of its updates this year, fixing just 58 CVEs.

Of those, nine were rated critical, with CVE-2020-17132 singled out by Recorded Future senior security architect Allan Liska as a priority.

“The vulnerability impacts Microsoft Exchange 2013 through 2019 and requires the attacker to be authenticated. Unusually, Microsoft does not include an attack scenario in the description other than to say the vulnerability is the result of improper validation of cmdlet (lightweight commands used in PowerShell) arguments,” he explained.

“One item of note: Microsoft thanked researchers from three different organizations for reporting this vulnerability, which means it is likely easy to locate and exploit. A fourth researcher reported CVE-2020-17142, a similar vulnerability in Microsoft Exchange (affecting cmdlets).”

Liska added that sysadmins should also prioritize CVE-2020-17117, another RCE bug in Microsoft Exchange which also affects versions 2013-2019.

The other critical disclosures cover SharePoint, Hyper-V, Chakra Scripting and several other workstation vulnerabilities.

Liska also pointed to several RCE bugs in Excel which could allow attackers to execute arbitrary code on a victim’s machine: CVE-2020-17122, CVE-2020-17123, CVE-2020-17125, CVE-2020-17127, CVE-2020-17128, CVE-2020-17129 and CVE-2020-17130.

“Microsoft lists all of these vulnerabilities as Important rather than Critical, but given the speed with which attackers often weaponize Microsoft Office vulnerabilities, these should be prioritized in patching,” he argued.

Microsoft also issued guidance to address vulnerabilities in DNS resolver as part of a new advisory, ADV200013.

“The vulnerability is a spoofing vulnerability in DNS resolver that could allow an attacker to exploit a DNS cache poisoning caused by IP fragmentation,” explained Ivanti senior product manager, Todd Schell. “An attacker could spoof the DNS packet which can be cached by the DNS forwarder or the DNS resolver. A workaround for configuring DNS servers is outlined in the advisory.”

Not to be outdone, Adobe fixed 14 vulnerabilities in Adobe Reader this month, four of which were critical.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

FireEye Hacked

FireEye was hacked by — they believe — “a nation with top-tier offensive capabilities”:

During our investigation to date, we have found that the attacker targeted and accessed certain Red Team assessment tools that we use to test our customers’ security. These tools mimic the behavior of many cyber threat actors and enable FireEye to provide essential diagnostic security services to our customers. None of the tools contain zero-day exploits. Consistent with our goal to protect the community, we are proactively releasing methods and means to detect the use of our stolen Red Team tools.

We are not sure if the attacker intends to use our Red Team tools or to publicly disclose them. Nevertheless, out of an abundance of caution, we have developed more than 300 countermeasures for our customers, and the community at large, to use in order to minimize the potential impact of the theft of these tools.

We have seen no evidence to date that any attacker has used the stolen Red Team tools. We, as well as others in the security community, will continue to monitor for any such activity. At this time, we want to ensure that the entire security community is both aware and protected against the attempted use of these Red Team tools. Specifically, here is what we are doing:

  • We have prepared countermeasures that can detect or block the use of our stolen Red Team tools.
  • We have implemented countermeasures into our security products.
  • We are sharing these countermeasures with our colleagues in the security community so that they can update their security tools.
  • We are making the countermeasures publicly available on our GitHub.
  • We will continue to share and refine any additional mitigations for the Red Team tools as they become available, both publicly and directly with our security partners.

Consistent with a nation-state cyber-espionage effort, the attacker primarily sought information related to certain government customers. While the attacker was able to access some of our internal systems, at this point in our investigation, we have seen no evidence that the attacker exfiltrated data from our primary systems that store customer information from our incident response or consulting engagements, or the metadata collected by our products in our dynamic threat intelligence systems. If we discover that customer information was taken, we will contact them directly.

From the New York Times:

The hack was the biggest known theft of cybersecurity tools since those of the National Security Agency were purloined in 2016 by a still-unidentified group that calls itself the ShadowBrokers. That group dumped the N.S.A.’s hacking tools online over several months, handing nation-states and hackers the “keys to the digital kingdom,” as one former N.S.A. operator put it. North Korea and Russia ultimately used the N.S.A.’s stolen weaponry in destructive attacks on government agencies, hospitals and the world’s biggest conglomerates ­- at a cost of more than $10 billion.

The N.S.A.’s tools were most likely more useful than FireEye’s since the U.S. government builds purpose-made digital weapons. FireEye’s Red Team tools are essentially built from malware that the company has seen used in a wide range of attacks.

Russia is presumed to be the attacker.

Reuters article. Boing Boing post. Slashdot thread. Wired article.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Judge Blocks Extradition of Alleged Webcam Hacker

UK Judge Blocks Extradition of Alleged Webcam Hacker

A British judge has ruled against extraditing to the United States a man accused of hacking into hundreds of webcams all over the world to spy on victims without their consent.

Christopher Taylor allegedly duped 772 victims in 39 countries into downloading computer software called Cammy between August 2012 and July 2015. 

By installing the software, victims unwittingly gave Taylor access to their computers. He is accused of using this access to install software that gave him control over victims’ webcams. 

The 58-year-old from Wigan was apprehended by Greater Manchester Police in February 2016 after network administrators at the Georgia Institute of Technology, in Atlanta, found the software installed on a laptop connected to the university’s computer network.

Administrators contacted the FBI, who were able to trace the software back to an IP address used by Taylor. 

It has been reported that during an interview with Greater Manchester Police and FBI agent Roderick Coffin in 2016, Taylor admitted using software to compromise victims’ webcams and to download videos and screenshots of copulating couples and women undressing. 

When police searched Taylor’s hard drives, they discovered 770 images of victims that included individuals who were in a state of undress and engaging in sexual activity. 

Among Taylor’s alleged victims are 52 UK residents and 52 US residents. 

The United States requested that Taylor be extradited to Georgia, where he has been charged with wire fraud and two counts of computer fraud.

In Westminster Magistrates Court on Monday, Taylor’s lawyer, Ben Cooper QC, argued that his client should face legal proceedings in the UK rather than in the United States.

“Most of the harm did not occur in the US and it is no more in the interests of the 722 worldwide victims to conduct the trial in the US than in the UK,” Cooper told the court.

District Judge Michael Fanning ordered Taylor’s discharge from the United States’ extradition request.

“I do find in your favor,” the judge said. “I do find extradition would not be in the interests of justice.”

Taylor was released on bail pending the US government’s appeal.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk