Chinese Cloud Hopper Attackers Use Zerologon in New Campaign

Chinese Cloud Hopper Attackers Use Zerologon in New Campaign

Chinese state-sponsored attackers are operating a major global campaign against multiple verticals exploiting the Zerologon vulnerability, according to new research from Symantec.

The security giant claimed that the Cicada group (aka APT10, Cloud Hopper) is targeting Japanese companies and their subsidiaries in 17 countries with information-stealing attacks. Affected sectors include automotive, pharmaceutical, engineering and managed service providers (MSPs).

APT10 is well-known to researchers, having been unmasked as the entity behind the infamous Cloud Hopper campaign against global MSPs back in 2017 — at the time branded “one of the largest ever sustained global cyber-espionage campaigns.”

The current campaign is said to have been ongoing since October 2019, with attackers maintaining persistence on some of their victims’ networks for a year, although for others the attacks lasted just days.

Symantec was first alerted to the campaign when it noticed suspicious DLL side-loading activity on one of its customer’s networks. The technique was in fact used by APT10 during multiple stages of attacks to load malware into legitimate processes, the report claimed.

Other classic techniques used by the group include “living off the land” via use of legitimate Windows functions like PowerShell, dual use and publicly available tools like WMIExec, and custom malware like the newly discovered Backdoor.Hartip.

The group was also observed exploiting the Zerologon elevation-of-privilege bug patched back in August, to remotely hijack a domain to compromise all Active Directory identity services.

“Intelligence gathering and stealing information has generally been the motivation behind Cicada’s attacks in the past, and that would appear to be the case in this attack campaign too. We observed the attackers archiving some folders of interest in these attacks, including in one organization folders relating to human resources, audit and expense data, and meeting memos,” the report noted.

“The group’s use of techniques such as DLL side-loading and a wide array of living-off-the-land tools underline the need for organizations to have a comprehensive security solution in place to detect this kind of suspicious activity before actors like Cicada have the chance to deploy malware or steal information from their networks.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#DxPsummit: How Zoom Met 2020’s Security Challenges

#DxPsummit: How Zoom Met 2020’s Security Challenges

This was the year that Zoom became a verb that everyone uses in context as it became “a critical service for everybody.”

Speaking as part of Druva’s Cloud Data Protection Summit, Druva CMO Thomas Been talked to Zoom corporate CIO Sunil Madan about the challenges the company has faced this year.

Madan said the mission of Zoom was to support businesses and to be frictionless and, in a secure way, get more things done. “This year has brought some unprecedented challenges for many organizations, including Zoom, with the exponential growth of the product, the consumption of the product and the global scale of the product – we had daily uses grow from 10 million to 300 million in a matter of weeks,” he said.

“We planned for over-subscription, but never by 30-times, that is unheard of, so we got together and figured out how to scale over-subscription, and luckily we have architected the product and could horizontally scale, whether at the data center or at the country or global level.”

He also said the company was designed as an enterprise product, but remote working made it a consumer product as well, and this made the company think about how to give a good experience for both.

Speaking on security and privacy challenges, Madan said there has been a “fair few challenges faced” as Zoom became a consumer product as well as a business product.

“That was the best change going forward, as we now look at ourselves through a different lens,” he said. “We put together a 90-day plan, we went through a security review, and put everything on hold for 90 days so we could take care of security and privacy.”

He said this enabled the company to come back “redefined” and with confidence for users, who know they are using a secure platform. Speaking on how the rapid change drove Zoom’s data protection strategy, Madan said COVID-19 has brought humanitarian challenges to the world, but “Zoom users are trying their best to stay connected.”

He said that everyone is looking for solutions, and most companies had gone through this accelerated transformation to remote working, and most organizations were not ready for it. “We’re dealing with a level of complexity at home and an IT team that was corporate and is now at home.”

This means that there is so much reliance on cloud, which he said “is saving humanity” as data protection and retention became important.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Attacks on Pharma Rise Amid Targeting of #COVID19 Vaccine Development

Attacks on Pharma Rise Amid Targeting of #COVID19 Vaccine Development

Attacks on the biotech and pharmaceutical industry have risen by 50% in 2020 compared to 2019, according to a new report from BlueVoyant.

These findings come amid positive recent news regarding the development of COVID-19 vaccines. It is unsurprising therefore that the cybersecurity firm found that eight of the most prominent companies working to create a vaccine for this virus have faced disproportionate levels of targeted malicious attacks in 2020 compared to other major pharma organizations.

Additionally, the researchers said the number one emerging threat this year is nation state espionage aimed at stealing COVID-19 vaccine research data, although the top threat overall in this sector remains ransomware.

In an analysis of open-source records of 25 publicly reported attacks during the past four years as well as research into 20 companies, including 12 of the largest biotech and pharma organizations in the world, BlueVoyant noted an escalating number of attacks. It observed that of the 25 attacks reported to the media since 2017, 10 (40%) occurred in 2020, while 80% of the 20 companies researched had experienced malicious, international and focused efforts this year.

Worryingly, most of the companies analyzed had not implemented important defenses against these types of attacks, such as securing open remote desktop access ports and phishing security.

Jim Penrose, COO, BlueVoyant, commented: “Pharmaceutical companies develop highly lucrative IP, they handle large amounts of patient and healthcare data and as such are a prime target for criminals looking to compromise, steal and exploit information. Now they face an even more elevated risk environment in the current pandemic as well-resourced nation state actors mount aggressive and focused campaigns.”

Jim Rosenthal, founder and CEO at BlueVoyant, added: “The ongoing effort to find a vaccine and cure for COVID-19 is an endeavor we all want to succeed. The high level of cyber-risk associated with the firms working on this critical mission ought to be a call for action to take immediate measures to drive down cyber-risk. Around the globe all citizens want peace of mind that these firms will guarantee confidentiality, integrity and availability in their research, development, manufacturing and data management activities as they race against the clock to deliver life-saving breakthroughs.”

Earlier this week, it was reported that data breaches in the healthcare industry are expected to triple in volume in the coming year.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk