Negotiating with Ransomware Gangs

Really interesting conversation with someone who negotiates with ransomware gangs:

For now, it seems that paying ransomware, while obviously risky and empowering/encouraging ransomware attackers, can perhaps be comported so as not to break any laws (like anti-terrorist laws, FCPA, conspiracy and others) ­ and even if payment is arguably unlawful, seems unlikely to be prosecuted. Thus, the decision whether to pay or ignore a ransomware demand, seems less of a legal, and more of a practical, determination ­ almost like a cost-benefit analysis.

The arguments for rendering a ransomware payment include:

  • Payment is the least costly option;
  • Payment is in the best interest of stakeholders (e.g. a hospital patient in desperate need of an immediate operation whose records are locked up);
  • Payment can avoid being fined for losing important data;
  • Payment means not losing highly confidential information; and
  • Payment may mean not going public with the data breach.

The arguments against rendering a ransomware payment include:

  • Payment does not guarantee that the right encryption keys with the proper decryption algorithms will be provided;
  • Payment further funds additional criminal pursuits of the attacker, enabling a cycle of ransomware crime;
  • Payment can do damage to a corporate brand;
  • Payment may not stop the ransomware attacker from returning;
  • If victims stopped making ransomware payments, the ransomware revenue stream would stop and ransomware attackers would have to move on to perpetrating another scheme; and
  • Using Bitcoin to pay a ransomware attacker can put organizations at risk. Most victims must buy Bitcoin on entirely unregulated and free-wheeling exchanges that can also be hacked, leaving buyers’ bank account information stored on these exchanges vulnerable.

When confronted with a ransomware attack, the options all seem bleak. Pay the hackers ­ and the victim may not only prompt future attacks, but there is also no guarantee that the hackers will restore a victim’s dataset. Ignore the hackers ­ and the victim may incur significant financial damage or even find themselves out of business. The only guarantees during a ransomware attack are the fear, uncertainty and dread inevitably experienced by the victim.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Bitcoin Exchange Owner Laundered Millions of Dollars

Bitcoin Exchange Owner Laundered Millions of Dollars

The owner of a Bitcoin exchange has become the seventeenth person to be convicted in the United States in connection with a transnational multi-million-dollar online auction fraud scheme that victimized over 900 Americans.

Rossen Iossifov was found guilty yesterday by a federal jury in Frankfort, Kentucky, of one count of conspiracy to commit racketeering and one count of conspiracy to commit money laundering after a two-week trial in front of US District Judge Robert Wier.  

Iossifov was the owner of RG Coins, a Bitcoin exchange based in his native Bulgaria. Court documents and evidence presented at trial proved that the 53-year-old entered into a fraudulent scheme to launder money for criminals based in Romania.

The elaborate scheme involved posting goods for sale online that didn’t exist and tricking Americans into paying for them, often with fake sob stories around the reason for the sale. 

Members of the conspiracy created fictitious online accounts, often using the stolen identities of Americans, to post these advertisements and communicate with victims. 

Duped Americans received invoices bearing trademarks of reputable companies, cunningly faked to make the transactions appear legitimate. Call centers, impersonating customer support, were also set up by the criminals to address questions and alleviate concerns over the advertisements.

The millions of dollars brought in by the scheme were laundered through RG Coins by Iossifov, who exchanged cryptocurrency into local fiat currency. According to trial testimony, over the course of two and a half years, Iossifov exchanged over $4.9m worth of Bitcoin for just four other members of the criminal enterprise. 

“Romania-based members of the conspiracy posted false advertisements to popular online auction and sales websites—such as Craigslist and eBay—for high-cost goods (typically vehicles) that did not actually exist,” said the Department of Justice in a statement released yesterday.

“Members of the conspiracy would convince American victims to send money for the advertised goods by crafting persuasive narratives, for example, by impersonating a military member who needed to sell the advertised item before deployment.”

Iossifov is scheduled to be sentenced on January 12, 2021. Three other defendants indicted in connection with this case remain at large.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ransomware Attack on Shipping Giant

Ransomware Attack on Shipping Giant

A ransomware attack has hit the servers of French container shipping giant CMA CGM, leading to the temporary closure of the company’s shipping website and applications.

A statement released by the company yesterday morning read: “The CMA CGM Group (excluding CEVA Logistics) is currently dealing with a cyber-attack impacting peripheral servers.”

After a security breach affecting several of the group’s Chinese offices was detected over the weekend, CMA CGM weighed anchor on its entire network in order to prevent the malware from spreading. 

At time of publication, the company’s shipping website (https://www.cma-cgm.com) remains inaccessible, returning the error “504-Gateway Timeout.” The sites of two of the company’s subsidiaries—ANL and CNC—along with the company’s IT application are also unavailable “due to an internal IT infrastructure issue.”

CMA CGM took to Twitter yesterday to inform customers that “external access to CMA CGM IT applications are currently unavailable.”

The group assured its clients with the message that “IT teams are working on resolving the incident to ensure business continuity.”

CMA CGM confirmed to shipping media group Lloyd’s List that the Ragnar Locker ransomware gang was behind the cyber-attack. 

The gang contacted the French carrier via email on Sunday with instructions to make contact within two days “via live chat and pay for the special decryption key.” How much money the gang are demanding in exchange for the key is not yet clear.

CMA CGM is the fourth major container shipping carrier to be attacked by cyber-criminals since 2017. Previous hits were made on Cosco Shipping, Mediterranean Shipping Co, and Maersk Line

Andrea Carcano, co-founder of Nozomi Networks, described the level of system visibility and cybersecurity maturity in the shipping sector as “relatively low.”

“The maritime industry in particular transports 90% of the world’s trade, and like other industries, is becoming increasingly connected, automated and remotely monitored,” said Carcano. 

“Many ships contain devices and systems that their operators aren’t even aware of. The people using the system are oftentimes the weakest element, opting to click a link in an email that says ‘URGENT’ or voluntarily giving up their credentials when somebody named ‘IT Support’ asks nicely.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Americans Plagued by Unsolicited Election Texts

Americans Plagued by Unsolicited Election Texts

With early voting for the US presidential election now underway, more than half of Americans have been sent unsolicited text messages from political candidates hoping to secure their vote. 

According to freshly published research by cybersecurity company Avira, 59% of Americans have received unwanted direct communication from political candidates, and 61% say wireless carriers should block political text messages as spam.

In September, Avira surveyed 2,000 citizens from Germany, Hong Kong, and the United States about their feelings toward upcoming elections. 

The survey found Americans lack confidence that the electoral race currently being run in the US by two septuagenarians is being conducted in a manner that is entirely above board. While nearly half (44%) said the presidential election would be “free but not entirely fair,” 17% said it would be “rigged.”

Just under a quarter (24%) were of the opinion that the process for selecting the next president will be “free and fair.” 

Asked how they believe the election will be disrupted, 50% of respondents said that misinformation would be spread on social media, while 46% said the same thing would occur on mainstream media.

Foreign interference in the election was anticipated by just 14% of those surveyed, while 37% were expecting fraud to occur regarding mail-in ballots. 

The research found that cyber-criminals have been exploiting what Senator Bernie Sanders has described as “the most important election of our lifetimes.” Over half (55%) of Americans surveyed said that they have encountered a scam related to the election, with fake news being the most reported, followed by robocalls.

Nuisance robocalls are a major issue in the US, with nearly 120 million calls received a day by Americans in August alone. 

“The unfortunate truth is, there are criminals in the world that take advantage of pivotal moments, such as national elections, to bribe, intimidate and fool people online to make a profit,” said Travis Witteveen, CEO of Avira. 

“Our survey shows that people are becoming more aware of these threats—such as election scams and misinformation—but the cyber community has more work to do to help people across the world understand how to protect themselves online.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

More Than Two-Thirds of Orgs Plan to Adopt Zero-Trust Architecture

More Than Two-Thirds of Orgs Plan to Adopt Zero-Trust Architecture

Over two-thirds (67%) of European organizations have adopted or are planning to adopt a zero-trust framework in response to an evolving threat landscape, according to a new study by Gigamon.

In a survey of 500 IT and security decision makers across Germany, France and the UK, 84% of respondents reported seeing an increase in threats since the start of 2020. The biggest issues highlighted were increased vulnerabilities from insecure devices as a result of home working (51%) and a rise in phishing attacks (41%) and data breaches (33%).

The respondents cited digital transformation (50%), shadow IT (45%) and employee education (37%) as the biggest internal IT and security challenges over the next 12 months to three years.

As a result of these threats, a strong desire to implement a zero-trust architecture was highlighted. The most important factors in doing so were found to be: to make networks more secure and mitigate risk (54%), to ensure data is better protected and easier to manage (51%) and to reduce the risk of employees compromising the system (49%).

Close to two-thirds (61%) said that zero-trust would enhance their IT strategy, and 30% expressed a belief that this approach would underpin their strategy.

Bassam Khan, VP product and technical marketing engineering at Gigamon, commented: “This research dives into issues that IT and security professionals face, the causes of these issues and frameworks IT is adopting, following a major global shift in how work gets done. With rapid changes and an ever-growing attack surface, IT and security teams are beginning to rely on a solid framework to better manage risks.”

In addition, around one-third of those polled (30%) agreed that zero-trust should absolutely be discussed at board level, while 24% thought it should be a priority at any boardroom table given the current climate.

Khan added: “With digital strategies pivoting to accommodate the economic uncertainty and unprecedented change caused by the new normal, security is only going to become a more prominent topic at the C-level. It is interesting to see that elements of the zero-trust journey are already being discussed, and hopefully this will continue, as board support is vital for the implementation and success of any zero-trust initiative.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Multiple Wireless Router Chipsets Affected by Authentication Bypass Vulnerability

Multiple Wireless Router Chipsets Affected by Authentication Bypass Vulnerability

Details of an authentication bypass vulnerability present in multiple wireless router chipsets have been set out in an advisory published by Synopsys CyRC. Referred to as CVE-2019-18989, CVE-2019-18990 and CVE-2019-18991, the vulnerability affects a variety of chipsets in different devices across three manufacturers: Mediatek, Qualcomm and Realtek.

Attackers can exploit the partial authentication bypass vulnerability by injecting packets into a WPA2-protected network without knowledge of the preshared key. These packets are subsequently routed through the network in the same way valid packets would be.

While responses to the injected packets return encrypted, attackers can eventually find out if the injected packets successfully reached an active system because they have control of what is sent through the network.

Synopsys also detailed a proof-of-concept example, in which it opened a UDP port in the router’s NAT by injecting UDP packets into a vulnerable WPA2-protected network. It said an attacker-controlled host listening on a defined UDP port can then receive the packets when they pass through the public internet. This host can then use this opened UDP port to communicate back to the vulnerable network.

The Synopsys researchers explained: “An attacker can arbitrarily send unencrypted packets and receive encrypted responses. These unencrypted packets are sent from a spoofed MAC address. The vulnerable access point does not drop the plain-text packets and routes them to the network as though they were valid. Response is also received back, but that is encrypted. The only requirement is that there is another properly authenticated client connected to WPA2 network.”

They added: “End users with access points that include the identified chipset and firmware versions are strongly encouraged to upgrade as quickly as possible or replace vulnerable access points with another access point.”

Access point manufacturers that include the identified chipset can also request patches from Mediatek and Realtek.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Receives 2020 European CYBERSEC Award

UK Receives 2020 European CYBERSEC Award

The UK’s cybersecurity posture has received the 2020 European CYBERSEC Award.

Described as “an appreciation for the efforts taken and the collaborative approach to the world’s cybersecurity”, the European CYBERSEC Award was given to the UK after it was determined to be “a role-model for global governments.”

Izabela Albrycht, president of the Kosciuszko Institute, said the UK’s “proactive and innovative approach in building its cyber-policies and capabilities” leads the way way towards building a decent level of security and “fighting against [an] adversarial internet.”

In particular, the formation of the NCSC in 2015 was cited, as well as its Active Cyber Defense program, as well as the UK’s participation in NATO and its action on 5G security.

“Fortunately, the UK does not stay closed to its allies,” Albrycht said. “It shares its world-leading expertise with its allies and other friendly countries, recognizing that cybersecurity is a common goal and making a lawful world is the duty of today’s governments.”

The CYBERSEC committee also praised the UK’s action on dealing “with cyber-hostile countries and the consequences for any breach of international law,” as “we are already at a point in time when such an attack is possible and thinking not only about cyber-defense but also about cyber-offence becomes one of the key topics today.”

Matt Warman, the UK’s minister of digital infrastructure, who received the prize on behalf of the UK government, agreed that part of the UK’s cybersecurity success is due to the international collaboration with like-minded countries, but also through introducing a true partnership between government, industry and academia.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Research: Cloud Skills and Solutions Are in Short Supply

Research: Cloud Skills and Solutions Are in Short Supply

Security is the most vital function to running an application, more so than reliability, portability and cost.

As detailed in new research of 650 IT decision makers by Nutanix, nearly all respondents (95%) believe their organization would benefit from a solution allowing consistent IT constructs and operations across public and private clouds. However, the research also showed that many struggle to adopt it – with nearly three-fourths (70%) of organizations reporting their transformation is taking longer than originally planned.

Wendy Pfeiffer, chief information officer at Nutanix, said businesses want the flexibility to leverage the right tools – and clouds – for their business. “More and more businesses are realizing that a unified hybrid cloud environment – one providing consistent experience, tooling and operational practices across private and multiple public clouds – can break down silos and reduce operational inefficiencies,” she explained.

“This can help businesses fast track digital initiatives by providing a path to easily ‘lift and shift’ legacy applications to public cloud without costly re-architecting exercises. Those legacy applications will then also have direct access to cloud native technologies.”

In an email to Infosecurity, Eugene Cheeks, application security consultant at nVisium, stated that security has to become a bigger part of the DevOps process and in response to this concern, many have begun to move to a DevSecOps model. “DevSecOps, done right, addresses this problem by allowing for companies to speed up deployment of business applications and remediate security issues successfully with smaller, often understaffed teams.”

Brendan O’Connor, CEO and co-founder of AppOmni, added: “No question that security has to be part of DevOps process. However, security for cloud services encompasses much more than DevOps. Enterprises are recognizing the amount of responsibility that falls on their shoulders for the security and management of cloud services.

“Of course, the development and operations of software must have security baked in, but so does the deployment and ongoing management of the cloud services. The oft-talked about lack of SaaS and cybersecurity expertise hampers these efforts.”

The Nutanix research also determined the top challenges with managing applications across private and public cloud environments to be: securing data across both environments (54%), acquiring and retaining IT staff (53%) and cost of migrating applications across environments (49%).

Pfeiffer said finding qualified IT talent is already difficult for many businesses, “and finding IT talent that has the appropriate skills to manage both private and public cloud infrastructure is even more challenging.” In particular, the majority of respondents (88%) noted that their organization struggles to ensure their IT team has the appropriate skills to handle a hybrid cloud environment, and over half (53%) see this as their main concern.  

Meanwhile, 95% of respondents noted they have to rely on different teams with distinct skill sets in order to manage public and private cloud infrastructure, which creates silos.

Steve Durbin, managing director of the Information Security Forum, said: “Shortages in skills and capabilities are being revealed as major security incidents damage organizational performance and reputation. Building tomorrow’s security workforce is crucial to address this challenge and deliver robust and long-term security for organizations in an age where we are seeing more and more remote workers.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#COVID19 WFH Rules Ramp Up Phishing and Insider Risks

#COVID19 WFH Rules Ramp Up Phishing and Insider Risks

Mass home working has exposed US and UK organizations to a greater risk of cyber-attacks and put greater pressure on security teams, a majority of IT leaders believe.

Cybersecurity vendor Tessian polled 250 IT leaders and 2000 workers to compile its Securing the Future of Hybrid Working report. It comes just days after the UK government backtracked on previous advice by urging those who could to work from home (WFH) to do so and help stop the spread of COVID-19.

The report found that a majority of IT leaders believe their organization is at greater risk of phishing attacks (82%) and insider threats (78%) due to WFH orders.

The reasoning behind this is pretty clear: most (57%) employees under lockdown are more reliant on email as a primary communication channel with colleagues, and phishing was the leading cause of cyber-attacks between March and July 2020.

In fact, it accounted for half of all incidents recorded by Tessian during that time, with 30% of IT leaders reporting a rise in ransomware attacks delivered by phishing, while nearly a quarter (24%) reported an increase in vishing compared to the previous five months.

BYOD presents a persistent risk in this context: 78% of remote workers using personal devices during the period received phishing emails in their work or personal inbox, and a worrying 68% said they clicked through or opened an attachment in unsolicited mail.

There are also concerns about remote workers logging-on to public Wi-Fi when out-and-about. Over half (53%) of IT leaders are worried about the associated security risks, and they are right to: 58% of employees said they’ve either considered connecting to public Wi-Fi or have already done so.

Partly as a result of this behavior, and other factors like limited budgets and distributed working, most (85%) IT leaders believe COVID-19 has put greater pressure on their teams, and 34% are worried they will be too stretched to cope with the increase in threats.

To help mitigate these WFH risks, 43% of respondents claimed they are looking to upgrade BYOD policies and 58% will introduce more staff training, according to the report.

“Business leaders must understand the strain that remote working puts on IT teams and address the risks people are exposed to,” argued Tessian CEO, Tim Sadler.

“Legacy security protocols are no longer equipped to protect distributed workforces and provide visibility into the behaviors of employees who rely on personal devices, risky channels like email and public Wi-Fi to get their jobs done.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Hacking Prosecutions Drop by 12% in 2019

UK Hacking Prosecutions Drop by 12% in 2019

Hacking prosecutions fell by 12% to 57 in 2019 compared to the previous year in the UK, according to an analysis by the law firm RPC. This meant that just 0.33% of the 17,600 hacking offences reported in the UK in 2019 resulted in a prosecution under the Computer Misuse Act.

RPC believes lack of resources being provided to the police to investigate such cases is the biggest factor in prosecutions being so low. It added that the UK government typically focuses its resources on targeting cyber-criminals involved in attempts to compromise national security.

In addition, it is often very difficult to identify and pursue attackers, as the majority of offences reported in the UK are likely to be carried out abroad. The primary reason for this, according to the RPC, is that attackers are more likely to route attacks through countries which do not necessarily have a co-operative law enforcement relationship with UK authorities.

Worryingly, there has been a significant growth in phishing attacks and scams this year as a result of COVID-19. For example, in April Google revealed it was blocking over 240 million COVID-themed spam messages each day in addition to 18 million malware and phishing emails. Many emails intercepted by Google contained malware designed to allow hackers access to the recipient’s system.

Examples of phishing attacks include messages impersonating government agencies or charities asking for donations or attempting to scam small businesses.

Richard Breavington, partner at RPC, commented: “Tracking down cyber-criminals is a very resource-intensive task. Hackers know how to cover their tracks, and doing so is relatively straighforward. Cyber-criminals view hacking as a low-risk activity, with virtually zero risk of prosecution.”

Commenting on the findings, Ollie Whitehouse, global CTO at the NCC Group, outlined the need to reform the current legislation: “As the global threat landscape evolves and broadens and technology becomes ever more complex, the fact that fewer true hackers are being prosecuted successfully in the UK demonstrates the urgent need for new legislation. The Computer Misuse Act – which is now 30 years old – was originally introduced to avoid unauthorized access to computer data and systems, but it is no longer fit for purpose in the interconnected digital world of the 21st century.”

He added:  “We want modern legislation to acknowledge the important role cybersecurity professionals play in keeping citizens and businesses safe and secure. We want to transform what constitutes unauthorized access in the act and introduce statutory defenses, so that security professionals can identify and investigate threats without fear of legal action, ensure cyber-criminals do get punished appropriately, and ultimately prevent real-world cyber-attacks in the future.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk