Spawn of Demonbot Attacks IoT Devices

Spawn of Demonbot Attacks IoT Devices

Threat researchers have spotted a new kind of cyber-attack that uses a variant of Mirai malware to target a port used by IoT devices.

The attack, orchestrated by someone using the alias “Priority,” was detected by a team at Juniper Threat Labs. Priority appears to have been up to no good since September 10.

Researchers noted that this new malicious kid on the block is hitting port 60001 using the Demonbot variant of Mirai together with a second variant developed by Scarface.

Port 60001 is a common port used by IoT devices, most notably the Defeway cameras, which make up over 90% of all cameras using this port. These cameras are being installed within networks with no password protection.

“While the users feel they are simply giving themselves access to view their camera from anywhere, it is actually giving attackers the ability to install botnets, such as Mirai, on the device,” said Juniper’s Jesse Lands.

Priority has been observed attacking ports 5500, 5501, 5502, 5050, and 60001 with a simple command that leverages the MVPower DVR Shell Unauthenticated Command Execution, reported by Unit 42 as part of the Omni Botnet variant of Mirai.

Researchers believe the attacker is either an unsophisticated amateur or someone who wishes to hide their true identity by appearing to be more criminally inexperienced than they actually are.

“What is interesting about this attacker is Juniper Threat Labs has not witnessed them using any additional exploits, perhaps showing again the attacker’s immaturity in the attack methodology,” noted researchers.

“In contrast, we see the majority of attackers using Mirai variants running three to seven different vulnerabilities against multiple protocols or devices.”

Priority has bucked this trend by limiting their attack to a single exploit and making it clear that their sights are locked on port 60001.

“The other ports appear more like a diversion, leading us to believe that the attacker has a specific objective in mind,” noted researchers.

All the attacks were found to have originated from an IP address owned by Virtual Private Server (VPS) provider Digital Ocean and linked to their Santa Clara data center.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Two Charged in ATO Attack on US Athletes

Two Charged in ATO Attack on US Athletes

Two men are to go before the US federal court after being charged with the unauthorized takeover of social media accounts belonging to American football and basketball stars.

Trevontae Washington and Ronnie Magrehbi have each been charged with one count of conspiracy to commit wire fraud and one count of conspiracy to commit computer fraud and abuse in two separate criminal complaints.

Both men are accused of illegally accessing social media and other personal online accounts belonging to professional and semi-professional athletes, including athletes employed by the National Football League (NFL) and the National Basketball Association (NBA), between December 2017 and April 2019.

Court documents allege that 21-year-old Washington, of Thibodaux, Louisiana, used a phishing attack to obtain the login credentials of his victims.

The Department of Justice said that using platforms like Instagram, Washington sent the sporting professionals messages “with embedded links to what appeared to be legitimate social media log-in sites, but which, in fact, were used to steal the athletes’ usernames and passwords.”

Once the athletes entered their credentials, Washington and others allegedly locked the players out of their accounts and used them to gain access to other accounts. Washington then allegedly sold access to the compromised accounts for amounts ranging from $500 to $1,000.

One victim was tricked into entering his details into what he thought was an authentic Facebook page. He then lost access to his Facebook, Twitter, Instagram, Snapchat, and Yahoo accounts.

While Washington is accused of successfully targeting two professional football players and a professional basketball player, 20-year-old Magrehbi is alleged to have obtained access to accounts belonging to one professional football player, including an Instagram account and personal email account.

Magrehbi, of Orlando, Florida, allegedly extorted the player, demanding payment in return for restoring access to the accounts. The victimized player sent funds to their attacker on at least one occasion, portions of which were transferred to a personal bank account controlled by Magrehbi.

Despite having paid their attacker, the player was not given back access to their own online accounts.

If found guilty on both counts, each defendant could face up to 25 years in prison and a maximum fine of $500,000.

Two men are to go before the US federal court after being charged with the unauthorized takeover of social media accounts belonging to stars of American football and basketball.

Trevontae Washington and Ronnie Magrehbi have each been charged with one count of conspiracy to commit wire fraud and one count of conspiracy to commit computer fraud and abuse in two separate criminal complaints.

Both men are accused of illegally accessing social media and other personal online accounts belonging to professional and semi-professional athletes, including athletes employed by the National Football League (NFL) and the National Basketball Association (NBA), between December 2017 and April 2019.

Court documents allege that 21-year-old Washington, of Thibodaux, Louisiana, used a phishing attack to obtain the login credentials of his victims.

The Department of Justice said that using platforms like Instagram, Washington sent the sporting professionals messages “with embedded links to what appeared to be legitimate social media log-in sites, but which, in fact, were used to steal the athletes’ usernames and passwords”.

Once the athletes entered their credentials, Washington and others allegedly locked the players out of their accounts and used them to gain access to other accounts. Washington then allegedly sold access to the compromised accounts for amounts ranging from $500 to $1,000.

One victim was tricked into entering his details into what he thought was an authentic Facebook page. He then lost access to his Facebook, Twitter, Instagram and Snapchat and Yahoo accounts.

While Washington is accused of successfully targeting two professional football players and a professional basketball player, 20-year-old Magrehbi is alleged to have obtained access to accounts belonging to one professional football player, including an Instagram account and personal email account.

Magrehbi, of Orlando Florida allegedly extorted the player, demanding payment in return for restoring access to the accounts. The victimized player sent funds to their attacker on at least one occasion, portions of which were transferred to a personal bank account controlled by Magrehbi.

Despite having paid their attacker, the player was not given back access to their own online accounts.

If found guilty on both counts, each defendant could face up to 25 years in prison and a maximum fine of $500,000.

Two men are to go before the US federal court after being charged with the unauthorized takeover of social media accounts belonging to stars of American football and basketball.

Trevontae Washington and Ronnie Magrehbi have each been charged with one count of conspiracy to commit wire fraud and one count of conspiracy to commit computer fraud and abuse in two separate criminal complaints.

Both men are accused of illegally accessing social media and other personal online accounts belonging to professional and semi-professional athletes, including athletes employed by the National Football League (NFL) and the National Basketball Association (NBA), between December 2017 and April 2019.

Court documents allege that 21-year-old Washington, of Thibodaux, Louisiana, used a phishing attack to obtain the login credentials of his victims.

The Department of Justice said that using platforms like Instagram, Washington sent the sporting professionals messages “with embedded links to what appeared to be legitimate social media log-in sites, but which, in fact, were used to steal the athletes’ usernames and passwords”.

Once the athletes entered their credentials, Washington and others allegedly locked the players out of their accounts and used them to gain access to other accounts. Washington then allegedly sold access to the compromised accounts for amounts ranging from $500 to $1,000.

One victim was tricked into entering his details into what he thought was an authentic Facebook page. He then lost access to his Facebook, Twitter, Instagram and Snapchat and Yahoo accounts.

While Washington is accused of successfully targeting two professional football players and a professional basketball player, 20-year-old Magrehbi is alleged to have obtained access to accounts belonging to one professional football player, including an Instagram account and personal email account.

Magrehbi, of Orlando Florida allegedly extorted the player, demanding payment in return for restoring access to the accounts. The victimized player sent funds to their attacker on at least one occasion, portions of which were transferred to a personal bank account controlled by Magrehbi.

Despite having paid their attacker, the player was not given back access to their own online accounts.

If found guilty on both counts, each defendant could face up to 25 years in prison and a maximum fine of $500,000.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Treasury: Paying Ransomware Gangs Could Violate Regulations

US Treasury: Paying Ransomware Gangs Could Violate Regulations

The United States Treasury has warned companies that they could be fined for paying or facilitating ransom payments to cyber-criminal gangs. 

An advisory published yesterday by the Treasury’s Office of Foreign Assets Control (OFAC) stated: “Companies that facilitate ransomware payments to cyber actors on behalf of victims, including financial institutions, cyber insurance firms, and companies involved in digital forensics and incident response, not only encourage future ransomware payment demands but also may risk violating OFAC regulations.”

OFAC said paying ransomware gangs who are operating under economic sanctions was a threat to US national security interests because it could fund the expansion of their criminal activities and could also encourage them to carry out further ransomware attacks.

The Office also noted that “paying a ransom to cyber actors does not guarantee that the victim will regain access to its stolen data.”

OFAC underlined the fact that Americans are prohibited under the International Emergency Economic Powers Act from engaging in transactions with individuals or entities on the office’s Specially Designated Nationals and Blocked Persons List. US citizens are also restricted by embargoes placed on certain regions and countries that include Cuba, Iran, Syria, and North Korea.

The advisory stated that violating OFAC regulations could result in a financial penalty. 

“OFAC may impose civil penalties for sanctions violations based on strict liability, meaning that a person subject to US jurisdiction may be held civilly liable even if it did not know or have reason to know it was engaging in a transaction with a person that is prohibited under sanctions laws and regulations administered by OFAC.”

OFAC urged financial institutions and other companies to implement a risk-based compliance program to mitigate exposure to sanctions-related violations. Ransomware victims and those involved with addressing ransomware attacks were asked to contact OFAC immediately if they believe a request for a ransomware payment may involve a sanctions nexus. 

Commenting on the advisory, CynergisTek CEO Caleb Barlow said: “A ransomware payment is no longer a get out of free jail card. Enterprises have to invest in defenses.” 

Barlow added that the issuance of the advisory was “likely accelerated” by “Garmin knowingly paying an adversary on the sanction list” millions of dollars to recover data after a ransomware attack.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Former Australian PM Talks Importance of Cyber Awareness

Former Australian PM Talks Importance of Cyber Awareness

“Everybody is so connected, the attack vectors are ubiquitous so you’ve got to make sure that everybody is maintaining a high level of cybersecurity awareness.”

Speaking on the Risky Business podcast, former Australian Prime Minster Malcolm Turnbull said his concern was senior leadership does not have a clear idea of who has system administrator access, and where data was actually stored. Turnbull also said there were too many instances of large scale, industrial machinery being secured with common passwords such as “1234.”

Turnbull, who served as Prime Minister between September 2015 and August 2018, said that a business may have the best defenses and knowledgeable staff, “but if a law firm or accounting firm is doing some work for me has got lesser standards, then everything can be thwarted.” This was an example of the need for an increase in the level of awareness across the board as that is why there are government departments offering advice.

Turnbull also said he saw cybersecurity as an opportunity and a threat, “and there a lot of dimensions to it.” He again cited industrial cybersecurity systems, “and if you’re a power station your adversary’s goal is to get into your system, understand every single element and learn everything about it and at a time of their choosing, blow something up or turn something off. Create some mayhem.”

Discussing the various national dilemmas about Huawei, Turnbull said in his experience he was confident “you could mitigate the risk if you limit to the edge of an FTTN network and multi-service access nodes on the streets, and connect to the last mile of copper wire.”

He said it was not a question of mitigating risk, but about trading it off against cost savings enabled by using more vendors. “So that core edge distinction was really central to everything that was being done in network security,” he said.

Turnbull was communications minister between September 2013 and 2015, before he served as Prime Minister, and said there was a view you could live with high risk vendor kit on the edge in most network environments, and from a vendor point of view, that was not a bad outcome.

Turnbull said he had been involved in the process of making a decision to not use Huawei for a year, and his goal “was to see if we could find a way to see if we could allow vendors and satisfactorily mitigate the risk.” This led to a determination that the risk could not be successfully mitigated, and he stressed that this was not a political decision, but one made after careful consideration.

Concluding, Turnbull said at a conceptual level, you can see where the risks and vulnerabilities are, and ask what you’re doing about it. “In a world of Internet of Things, with billions of sensors all talking to each other, risks to operating technologies is going to be so much greater.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

New APT Group XDSpy Targets Belarus and Russian-Speakers

New APT Group XDSpy Targets Belarus and Russian-Speakers

Security researchers have discovered a new APT group that has been stealing sensitive information from Eastern European governments and businesses for over nine years.

Dubbed “XDSpy,” the group shares no similarities of malicious code, network infrastructure or regional targets with any known APT outfit, according to ESET.

It operates largely in a GMT+2 or +3 time zone, the same as its targets, and operatives work only Monday-Friday.

It focuses exclusively on spearphishing to compromise targets, although emails could contain malicious RAR or ZIP attachments or links.

Interestingly, the group’s technical proficiency seems to vary, according to ESET.

On the one hand it has used the same malware architecture for nine years, with the main XDDown malware component downloaded to a victim computer from a C&C server. This installs additional plugins to gather basic info, crawl the C drive, exfiltrate local files, gather browser passwords and more.

However, on the other hand, it was recently spotted exploiting CVE-2020-0968. “At the time it was exploited by XDSpy, no proof-of-concept and very little information about this specific vulnerability was available online,” explained ESET. “We think that XDSpy either bought this exploit from a broker or developed a 1-day exploit themselves by looking at previous exploits for inspiration.”

The security vendor refused to speculate on who could be behind XDSpy. It is most interested in stealing information from government targets in Eastern Europe and the Balkans, including a February campaign against Belarussian institutions in February and Russian-speaking targets in September this year.

Moldova, Serbia, Russia and Ukraine have also come under attack since 2011.

“The group has attracted very little public attention so far, with the exception of an advisory from the Belarusian CERT in February 2020,” said Mathieu Faou, ESET researcher. ““Since we did not find any code similarities with other malware families, and we did not observe any overlap in the network infrastructure, we conclude that XDSpy is a previously undocumented group.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Union Warns of Surge in Employee Monitoring at Home

Union Warns of Surge in Employee Monitoring at Home

A leading union is calling for government leadership and closer engagement with businesses after revealing that a majority of employees are uncomfortable with digital monitoring whilst remote working.

Trade union Prospect, which has 150,000 members including engineers, scientists, managers and civil servants, recently polled over 1800 workers to better understand their attitudes to remote monitoring by employers.

It found that 80% would be uncomfortable with camera monitoring technology, 76% with electronic tracking, and 66% with keystroke monitoring. Nearly half (48%) said the introduction of monitoring software would have a negative impact on their relationship with their manager, rising to 62% among 18-24-year-old workers.

Such activity has become increasingly common, especially during the surge in home working over the past few months. One surveillance software-maker has claimed to have seen a four-fold spike in UK customers year-on-year.

In August it was revealed that UK privacy regulator the Information Commissioner’s Office (ICO) had opened an investigation into Barclays Bank after it was alleged that the lender was spying on its staff.

“People expect that they can keep their personal lives private and that they are also entitled to a degree of privacy in the workplace,” an ICO spokesman said at the time.

“If organizations wish to monitor their employees, they should be clear about its purpose and that it brings real benefits. Organizations also need to make employees aware of the nature, extent and reasons for any monitoring.”

Prospect is calling on the government to regulate monitoring technology before it becomes even more widespread, and to formalize a “right to disconnect” allowing workers to refuse such surveillance. It added that any businesses looking to introduce this kind of technology must abide by the GDPR and be transparent with their workforce.

“Having your every keystroke or app usage monitored by your boss while you are working in your own home may sound like a dystopia, but there are precious few controls in place to prevent it becoming a daily reality for millions of workers across Britain,” argued Prospect general secretary, Mike Clancy.

“The evidence suggests the workforce are simply not ready for it. If government is going to tell workers to stay home, then it needs to get serious about this issue, by bringing businesses, unions, and tech companies together to discuss what modern workers’ rights should look like in this new world of work.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Spies Slam Huawei Security

UK Spies Slam Huawei Security

UK spy agency GCHQ has warned that continued concerns over Huawei’s approach to software development mean national security may be at risk.

Operatives from the Cheltenham-based signals intelligence body staff a Huawei Cyber Security Evaluation Centre (HCSEC), which monitors the Chinese firm’s products and processes as a pre-requisite for it doing business in the UK.

However, having already discovered and flagged major concerns in the last report, it claimed “limited progress” has been made in addressing them.

These unnamed issues bring “significantly increased risk to operators” and require “ongoing management and mitigation,” it said.

Although Huawei-built UK networks are no more vulnerable than last year, the fact that progress hasn’t been made by the Chinese giant in addressing HCSEC’s concerns means its recommendations to government haven’t changed.

“The Oversight Board advises that it will be difficult to appropriately risk manage future products in the context of UK deployments, until the underlying defects in Huawei’s software engineering and cybersecurity processes are remediated,” the report noted.

“At present, the Oversight Board has not yet seen anything to give it confidence in Huawei’s capacity to successfully complete the elements of its transformation programme that it has proposed as a means of addressing these underlying defects. The Board will require sustained evidence of better software engineering and cyber security quality verified by HCSEC and NCSC.”

As a result, the HCSEC said it can only provide “limited assurance” that risks to national security from Huawei’s involvement in UK networks can be effectively mitigated going forward.

The report claimed the number of reported bugs and issues rose “significantly” over the past year, including the discovery of a vulnerability of “national significance” in 2019, although it’s not thought to have been exploited before being fixed.

While there’s no suggestion any of the above issues were deliberately engineered by the company, the findings reflect poorly on its general competence in cybersecurity.

In July, the UK government told operators to stop buying from Huawei by the end of the year and remove the firm’s products from their 5G networks by 2027—delaying rollouts for around a year.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#DTXNOW: Communication is the Foundation of a Strong Cybersecurity Culture

#DTXNOW: Communication is the Foundation of a Strong Cybersecurity Culture

Internal culture is a major determinant in how effective organizations’ cybersecurity practices and behaviors, according to a panel discussion at this week’s Digital Transformation Expo.

They began by looking at how organizations can maintain a strong cybersecurity culture even while many workforces are primarily operating remotely as a result of the COVID-19 pandemic. Sarah Janes, managing director, Layer8, said that organizations must be mindful of the fact that “change is multifaceted, it’s a weave of different conversations with people, hearing things on social media, checking it out with a friend, different opinions.”

Having good communication is inherently more difficult in the work from home model. Nevertheless, James explained that she has been working with companies to develop “security champions”; people who sit in different areas of the business and already are in close contact with their team, to continue the conversation about security. She commented: “It’s important to understand that there’s lots of different things that people may need to know to change their behavior and having local security champions at the grassroots can really enable that.”

Marilise de Villiers, founder and CEO, MdVB Consulting acknowledged that while conversations can take place virtually, they cannot replace the interactions employees have in an office environment, potentially leading to a feeling of disconnect. However, she does believe that those organizations which have leaders who regularly check in with their teams are more successful in helping maintain a culture where all staff feel empowered to speak up to help improved security .

In fact, if done well, the shift to remote working may even prove an opportunity to make better security a company-wide goal, according to James. “I think there always has to be an opportunity to move outside the security teams, to make security work for different parts of the business – we have to take time to build relationships, and understand the perspectives of the different business functions.”

More generally, de Villiers outlined her belief that cybersecurity culture is inherently linked to the overall culture of an organization: “I think organizational cultural either helps or hinders secure behaviors,” she said. As such, the broader values of a company must be taken into account when deciding upon a cybersecurity strategy.

For instance, a key facet of a strong cybersecurity culture is enabling a safe “speak up” environment for all staff, in which anything suspicious or needs to be changed is reported. However, if an overall organization has a fear-based culture, this type of behavior will not be possible. de Villiers added: “I always advise to look at the culture holistically and to see how can we integrate our security efforts with the wider organizational culture.”

Janes added that the way security professionals talk about security in front of senior management in the organization is also crucial to shaping culture, arguing that this needs to be monitored carefully by individuals in these teams. She said: “[For example] are we talking about people being the weakest link, are we talking about are cyber-criminals always be one step ahead of us, because what organizations talk about, they will do more of.”

The panel then delved into the topic of diversity, and discussed why having diverse security teams is important from a business perspective, particularly in developing the right cybersecurity culture within organizations. de Villiers commented: “We need that cognitive dissonance where people can bring in different perspectives but also where those different perspectives are being embraced.”

Janes added: “Diverse teams make better decisions, and organizations that make better decisions perform better… if we bring that into our world, and we think about the critical thinking that’s needed for dealing with an incident, that is immense to be able to make the best decisions.”

Hiring individuals with the right soft skills, such as empathy, as well as technical abilities in security teams is another component of bringing about the right culture across entire organizations, according to Janes. “You can have all the technology in place, you can have your strategies, and they can be the best in the world, but if you lack the ability to build rapport and have a really good conversation with the board, then it makes it really difficult to achieve your objectives,” she noted.

Janes concluded by reaffirming that communication is the foundation for a successful cybersecurity culture: “It is the ability to really integrate and have an understanding of all the different parts of the business.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk