Increase in Ransomware Sophistication and Leverage of Legacy Malware Predicted for 2021

Increase in Ransomware Sophistication and Leverage of Legacy Malware Predicted for 2021

An increase in ransomware sophistication, commodity malware and abuse of legitimate tools are predicted to be the main threats for the next year.

According to the Sophos 2021 Threat Report, there will be a gap between ransomware operators at different ends of the skills and resource spectrum, with big-game hunting ransomware families continuing to refine and change their tactics, techniques and procedures to become more evasive and nation state-like in sophistication.

Sophos claimed this will involve the targeting of larger organizations with multi-million dollar ransom demands, while an increase in the number of entry level, apprentice-type attackers looking for ransomware-for-rent will also increase.

Chester Wisniewski, principal research scientist at Sophos, said: “During 2020, Sophos saw a clear trend towards adversaries differentiating themselves in terms of their skills and targets. However, we’ve also seen ransomware families sharing best-of-breed tools and forming self-styled collaborative cartels.

“The cyber-threat landscape abhors a vacuum: if one threat disappears another one will quickly take its place. In many ways, it is almost impossible to predict where ransomware will go next, but the attack trends discussed in our report this year are likely to continue into 2021.”

Speaking to Infosecurity, Darren Guccione, CEO of Keeper Security, said in that 2020, cyber-criminals have taken advantage of the business disruptions caused by the global health crisis, particularly the sudden and dramatic rise in remote work. He cited statistics from Coveware which claim that the average enterprise ransomware payment increased to more than $100,000 in the first quarter of 2020, a rise of 33% from the final quarter of 2019.

“This dramatic surge is due to cyber-criminals increasingly attacking large enterprises with deep pockets and leveraging legacy systems,” he explained. “Additionally, healthcare organizations saw a 350% year-on-year increase in ransomware attacks at the end of 2019 compared to the same timeframe in 2018.”

Also, commodity malware, such as loaders and botnets, which can seem like low-level malware noise but are designed to secure a foothold in a target, gather essential data and share data back to a command-and-control network, should be taken seriously.

“Commodity malware can seem like a sandstorm of low-level noise clogging up the security alert system,” said Wisniewski. “Defenders need to take these attacks seriously, because of where they might lead: they may not realize that the attack was likely against more than one machine and that seemingly common malware like Emotet and Buer Loader can lead to Ryuk, Netwalker and other advanced attacks, which IT may not notice until the ransomware deploys. Underestimating ‘minor’ infections could prove very costly.”

Guccione said the environment most businesses are operating in at the moment is extremely volatile, and now more than ever businesses should look to educate employees from the ground-up on the increasing cyber-risks and provide best practices for ensuring devices within their network are secure.

“It is the responsibility of business leaders to remind employees of the accountability they have as individuals for the safety and security of their own devices,” he said. “Only with the buy-in of all stakeholders do organizations have the best chance of securing their endpoints in the most efficient way possible.”

Wisniewski also said the abuse of everyday tools and techniques to disguise an active attack featured prominently in Sophos’ research, as this technique challenges traditional security approaches because the appearance of known tools doesn’t automatically trigger a red flag. “This is where the rapidly growing field of human-led threat hunting and managed threat response really comes into its own.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Americold Operations Downed by Cyber-Attack

Americold Operations Downed by Cyber-Attack

US cold storage firm Americold has been hit by what appears to be a ransomware attack affecting business operations.

The 117-year-old firm operates temperature-controlled warehouses and transportation to support the cold chains needed to supply, for example, vaccines like the one being developed by Pfizer and BioNTech for COVID-19.

However, in a regulatory filing with the Securities and Exchange Commission (SEC), the firm revealed that its IT network was hit by an unspecified “cybersecurity incident” on Monday.

“As a precautionary measure, the company took immediate steps to help contain the incident and implemented business continuity plans, where appropriate, to continue ongoing operations. The company has notified and is working closely with law enforcement, cybersecurity experts and legal counsel,” it said.

“Security, in all its forms, remains a top priority at Americold, and the company will continue to seek to take all appropriate measures to further safeguard the integrity of its information technology infrastructure, data and customer information.”

With total revenue in 2020 so far exceeding $1.4bn, Americold would certainly seem like a prime candidate to extort with “human-operated” ransomware. The nature of its business also means that operational outages could seriously impact customers, potentially piling on the pressure to pay in order to resume business-as-usual.

One truck driver took to Twitter on Monday to post a picture of an affected Americold depot in the mid-west.

“At a Americold and their systems are down,” they noted. “They are unable to assign me to a door. Well let the waiting begin.”

Jamie Akhtar, CEO and co-founder of CyberSmart, said the incident highlighted the importance of good cybersecurity in supply chains.

“In order to strengthen the security ecosystem, businesses should not just concern themselves with their own security practices but hold their distributors and suppliers to account,” he added. “The UK is making some headway in this direction by requiring the Cyber Essentials certification for certain sectors. Other industries would do well to follow suit.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Chinese APT FunnyDream Runs Riot in Southeast Asia

Chinese APT FunnyDream Runs Riot in Southeast Asia

Security researchers have uncovered another Chinese APT group, this time targeting southeast Asian governments, which has compromised over 200 machines in the past two years.

Bitdefender dubbed the group “FunnyDream” after one of the backdoors used in the attacks. It appears to have been active since at least 2018.

Focused on exfiltrating sensitive information, it uses spyware tools such as Filepak for file collection, ScreenCap for taking screenshots and Keyrecord for logging keystrokes on victim machines.

Although the initial threat vector isn’t known, Bitdefender claimed it is likely to be a phishing email. Three backdoors are then used for command and control (C&C): Chinoxy to gain persistence after initial access, open source RAT PcShare for complex espionage and the custom made FunnyDream toolkit.

Controlling the three backdoors is C&C infrastructure located mainly in Hong Kong, but also elsewhere in China and Vietnam.

Although 200 systems have shown signs of infection so far, Bitdefender warned that in some victim networks the domain controllers may have been compromised, allowing attackers to move laterally and gain control over a large number of machines.

“Attributing APT style attacks to a particular group or country can be extremely difficult — as false-flag forensic artifacts can be manufactured, C&C infrastructure can reside anywhere in the world and the tools used can be repurposed from other APT groups,” the vendor said.

“However, evidence suggests a Chinese-speaking APT group using Chinese language binaries, and the Chinoxy backdoor used during the campaign is a Trojan known to have been used by Chinese-speaking threat actors.”

The specific target governments were not named in the report, although China has tense relations with many countries that border the South China Sea due to territorial claims and other geopolitical disputes.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Trump Fires CISA Boss Who Said Election Was “Most Secure in History”

Trump Fires CISA Boss Who Said Election Was “Most Secure in History”

The well-respected head of a US government cybersecurity agency has been fired by Donald Trump after confirming the Presidential election was free, fair and secure.

As rumored last week and reported by Infosecurity, Christopher Krebs was on Tuesday “terminated” via a tweet from the White House, Trump’s increasingly favored way of dealing with high ranking government officials who displease him.

In it, the outgoing President repeated baseless allegations of voter fraud in the election, prompting Twitter to once again label his tweets with a warning label indicating possible misinformation.

In response, Krebs tweeted simply: “Honored to serve. We did it right. Defend Today, Secure Tomorrow.”

Trump’s ire seems to have been drawn by a recent statement from Krebs’s former employer, the Cybersecurity and Infrastructure Security Agency (CISA), and various election infrastructure agencies, that the November 3 election was “the most secure in American history.

“There is no evidence that any voting system deleted or lost votes, changed votes, or was in any way compromised,” it continued.

This official undermining of Trump’s narrative from the bodies whose job it is to monitor the election, proved too much for the President to take. CISA also runs a Rumor Control website to debunk mis- and disinformation circulating about the elections – many of which were promoted by Trump himself and supporters.

Although Krebs was a rare Trump appointee when he joined CISA as someone who enjoyed bipartisan support, there were no Republican lawmakers to speak out in support of his service.

However, Democrat senator and vice-chair of the Senate Intelligence Committee, Mark Warner, stepped up.

“Chris Krebs is an extraordinary public servant and exactly the person Americans want protecting the security of our elections,” he tweeted. “It speaks volumes that the President chose to fire him simply for telling the truth.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Three-Quarters of IT/Security Execs Concerned Over Security of Remote Workforce

Three-Quarters of IT/Security Execs Concerned Over Security of Remote Workforce

Nearly three-quarters (73%) of security and IT executives are concerned about additional risks posed to their organization by a distributed workforce since COVID-19, according to the Skybox Security 2020 Cybersecurity in the New Normal: Securing the Distributed Workforce report.

In the survey of 295 executives, the security firm reported it has observed a 34% year-on-year rise in vulnerabilities in 2020, which it said is a “leading indicator for the growth of future attacks.”

It highlighted that many organizations are not taking the steps needed to adequately protect their remote workforces. Over 30% of respondents revealed that software updates and BYOD policies were deprioritized since the start of the pandemic, while 42% said reporting was deprioritized.

In addition, almost a third (32%) found it difficult to validate whether network and security configurations undermine their security posture, and over half (55%) admitted it was at least moderately difficult to determine whether these configurations did not increase risk.

This is despite the fact that 70% of the security and IT executives predict that at least a third of their workforce will still be operating remotely in 18 months’ time.

The researchers also found that there was some complacency amongst the respondents in regard to their organizations’ security capabilities. Although only 11% stated they could confidently maintain a holistic security approach, 93% felt sure changes were being correctly validated.

“Traditional detect-and-respond approaches are no longer enough. A radical new approach is needed – one that is rooted in the development of preventative and prescriptive vulnerability and threat management practices,” commented Gidi Cohen, co-founder and CEO, Skybox Security. “To advance change, it is integral that everything, including data and talent, is working towards enriching the security program as a whole.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk