KashmirBlack Botnet Uses DevOps to Stay Agile

KashmirBlack Botnet Uses DevOps to Stay Agile

Security researchers have lifted the lid on a highly sophisticated global botnet operation performing millions of attacks per day, including cryptocurrency mining, spamming and defacements.

Dubbed “KashmirBlack” by a team at Imperva, hundreds of thousands of compromised machines are controlled by a single command and control (C&C) server.

Active since around November 2019, it spreads by targeting an almost decade-old PHPUnit RCE vulnerability in popular content management system (CMS) software. Imperva warned that the pandemic has arguably created more potential victims for the botnet, given that many businesses have been scrambling to create an online presence via such platforms.

The botnet’s infrastructure is apparently more sophisticated than most, using DevOps techniques to drive agility and ensure new payloads and exploits can be added fairly easily.

This agility also means the botnet can rapidly change the repositories such as GitHub where it stores malicious code, as well as its C&C infrastructure, which Imperva claimed recently migrated to Dropbox to hide its tracks.

In a sign of how alert the botherders are to potential outside disruption, Imperva claimed that they blocked access to its honeypot servers in just three days after growing suspicious.

Indonesian web defacement cybercrime group PhantomGhost has been linked to the botnet, the security vendor claimed.

“This is the first time we have been able to get visibility into how exactly a botnet like this operates; an important discovery that will help the industry better understand how these nefarious groups evolve and sustain their activity,” said Ofir Shaty, Imperva security researcher and research co-author.

“The level of orchestration is remarkable. It’s a very polished operation using the latest software development techniques. With potentially millions of victims across the world, this level of sophistication should be a cause for concern. Once a server is being controlled by a hacker, it has the potential to compromise other servers in the domain in a domino effect, leading to potential data leakage, driving down brand reputation, and eventually losing revenue.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#InfosecurityOnline: The Three Key Elements of Zero-Trust

#InfosecurityOnline: The Three Key Elements of Zero-Trust

Speaking during the Infosecurity Online event Manja Kuchel, senior product marketing manager at SolarWinds, outlined the three key elements of an effective zero-trust approach to security within organizations.

The first is risk assessment, Kuchel said, which involves defining where your sensitive data is located and who should have access to what.

“This is something that no tool can do for you, because this is an internal ‘home work’ type of process,” she explained. “You really need to sit down and analyze your sensitive data; this can be done on a personal, identity or departmental level, depending on the size of the company or title structure.

“This should bring executive-level managers and IT administration together – this needs to be a cross-company approach.”

Once that has element is established, the next step in the zero-trust process focuses on risk management, explained Kuchel. This includes defining access rights, taking into account identities and profiles, the types of resources being accessed and levels of access privilege.

“There are various tools that can help here – but the aim is to manage your risk situation and look into what you can do to limit access rights and limit access to information.”

The third and final step centers around risk containment: detecting, monitoring and responding to incidents.

“You should detect unusual security events; whenever something is happening, a user plugging in a USB stick that is against company policy [for example], you and the user should be alerted. Administrators should then be able to respond to such actions or even block or allow those actions – so not only seeing it, but being able to prevent things from happening.”

This three-step zero-trust cycle is one that never really stops, Kuchel said, and “you should be assessing the risk once a year – that is really something that the organizations should be doing as a regular drill.

“Also, the management of risk should be regularly adjusted in order to ensure people only ever have the correct access rights, as they might change and it needs to be revisited.”

Risk containment is very continuous too, she added, so that should always be up and running.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Retail, Hospitality and Travel Hit by 64 Billion Credential Stuffing Attacks

Retail, Hospitality and Travel Hit by 64 Billion Credential Stuffing Attacks

Over 60% of credential stuffing attacks detected over the past two years have been targeted at retail, travel and hospitality businesses, according to Akamai.

The security vendor’s latest report, Loyalty for Sale, is compiled from internet traffic flowing through its extensive global content delivery network.

It revealed that, during the period July 1 2018 to June 30 2020, it detected over 100 billion credential stuffing attempts. Almost 64 billion of these were aimed at cracking open user accounts in the retail, travel and hospitality sectors.

Further, retail accounted for the vast majority (90%+) of the attacks aimed at these verticals.

Such attacks remain popular given the continuous surge of breached log-ins onto underground sites and the potentially rich pickings to be found inside cracked accounts.

“Criminals are not picky — anything that can be accessed can be used in some way,” said Steve Ragan, Akamai security researcher and report author.

“This is why credential stuffing has become so popular over the past few years. These days, retail and loyalty profiles contain a smorgasbord of personal information, and in some cases financial information too. All of this data can be collected, sold and traded, or even compiled for extensive profiles that can later be used for crimes such as identity theft.”

Akamai also claimed that during the early days of the COVID-19 crisis as consumers flooded online sites to purchase goods, cyber-criminals began recirculating old credential lists in an attempt to identity new vulnerable accounts.

The report identified not just credential stuffing activity but also attempts to compromise sites directly via SQL Injection (SQLi) and Local File Inclusion (LFI) attacks.

Akamai detected nearly 4.4 billion web attacks against the retail, hospitality and travel sectors, comprising 41% of the total across all verticals. Once again, retail (83%) was the most popular target, while SQLi attacks (79%) were the number one choice of cyber-criminals across the three verticals.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US: Iran Was Behind Proud Boys Email Campaign

US: Iran Was Behind Proud Boys Email Campaign

US officials have blamed Iranian hackers for a clumsy attempt to intimidate registered Democrat voters via spoofed emails, ahead of the upcoming Presidential election.

The campaign impersonated the far-right Proud Boys group in two waves of emails sent out this week, according to Proofpoint. Some emails included the recipient’s home address in a bid to turn up the pressure.

One message titled “Vote Trump or else” is typical. It noted: “You are currently registered as a Democrat and we know this because we have gained access into the entire voting infrastructure. You will vote for Trump on election day or we will come after you.”

In fact, such contact information is relatively easy to obtain in the US from public voter records.

The first set of emails used a compromised infrastructure traced back to a Saudi Arabian insurance company while the second used an Estonian IP address.

In the latter, an embedded video also purported to show mail-in voting fraud in action.

However, at a hastily arranged press conference on Wednesday evening, director of national intelligence, John Ratcliffe, debunked the emails as state-sponsored misinformation.

“We have confirmed that some voter registration information has been obtained by Iran and separately by Russia. This data can be used by foreign actors to attempt to communicate false information to registered voters that they hope will cause confusion sow chaos and undermine your confidence in American democracy,” he said.

“To that end, we have already seen Iran sending spoofed emails designed to intimidate voters, incite social unrest and damage President Trump.”

Ratcliffe also described the video and any claims about fraudulent ballots as “not true.

“Know that our election systems are resilient and you can be confident your votes are secure,” he added.

Ratcliffe also warned that Russian disinformation efforts may pick up over the final week before the election as state actors have obtained voter registration data.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#InfosecurityOnline: Are the Cloud and Automation Driving or Hindering Your Business?

#InfosecurityOnline: Are the Cloud and Automation Driving or Hindering Your Business?

Consider where you can add automation and where your point solutions are not supporting your business. 

Speaking during the Infosecurity Online event Palo Alto Networks vice-president Matt Poulton said 2020 has been the year when automation has been accelerated by companies who are looking for what they can automate to be more efficient.

Poulton said COVID-19 has added “more pressure in terms of resource, or more pressure on you because of a distributed workforce,” and companies go through huge changes because of digital transformation. He said that, if digital transformation is done well, it “can shape the way you work” as multi-cloud environments become the norm, and apps are developed to be more agile, but this comes with the dilemma of whether security hinders or supports the introduction of cloud.

“We see that transformation creates a lot of risk,” he said. “More devices mean more data, as my home office is now a device sitting on the corporate network, and we’re seeing the number of endpoints increase dramatically, and this will continue to rise.”

Poulton explained that the advent of containers and Kubernetes has seen a rapid rise in the number of cloud deployments, and this is often done faster than security deployments. “Cloud is the biggest challenge organizations are facing, and the migration of data centers into cloud environments is huge.

“We at Palo Alto Networks need to create solutions to meet your challenges, as you have a lot of point solutions,” Poulton said. “We see that data is now everywhere and it is like water, how do you contain it, do you let it flow, how do you ensure it is not polluted?”

He said that innovation cannot be slowed down, and staying ahead of the increased complexity becomes harder as cloud and remote working become the norm, “and you have hundreds of mini VPNs and a huge VDI network, the perimeter is gone.”

In order to feel confident, Poulton said there is still a desire for better visibility, and for analysts to know what is “normal” and what trusted intelligence is within the organization. He added, with multi-cloud use, it is common to use 25 tools, “so how do you get simplicity, how do you get flexibility?”

He went on to say that the concept of “best of breed” is not enough anymore, as this leaves analysts looking at multiple screens in order to do an investigation, “as point solutions don’t communicate.”

He said: “You simply don’t have a 360 degree picture of your threats. So we challenge you to think, are best in breed point solutions good enough for you, as they do not scale.

“It is not about the data, it is not about good data, it is about all the data. Better decisions must come from better data. We need to give you the visibility to act quickly, so automation in terms of data intelligence as data enrichment is key.”

Poulton said cloud provides an opportunity to put a solution in place to eradicate point solutions, move into a structured format and provide visibility in one place.

“The best defense is an AI-led defense, but there are lots of things we can use clever computing power for; to automate for you and give you better visibility and detection,” he said.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk