U.S. Charges 4 Chinese Military Officers in 2017 Equifax Hack

The U.S. Justice Department today unsealed indictments against four Chinese officers of the People’s Liberation Army (PLA) accused of perpetrating the 2017 hack against consumer credit bureau Equifax that led to the theft of personal data on nearly 150 million Americans. DOJ officials said the four men were responsible for carrying out the largest theft of sensitive personal information by state-sponsored hackers ever recorded.

The nine-count indictment names Wu Zhiyong (吴志勇), Wang Qian (王乾), Xu Ke (许可) and Liu Lei (刘磊) as members of the PLA’s 54th Research Institute, a component of the Chinese military. They are each charged with three counts of conspiracy to commit computer fraud, economic espionage and wire fraud.

The government says the men disguised their hacking activity by routing attack traffic through 34 servers located in nearly 20 countries, using encrypted communications channels within Equifax’s network to blend in with normal network activity, and deleting log files daily to remove evidence of their meanderings through the company’s systems.

U.S. Attorney General Bill Barr said at a press conference today that the Justice Department doesn’t normally charge members of another country’s military with crimes (this is only the second time the agency has indicted Chinese military hackers). But in a carefully worded statement that seemed designed to deflect any criticism of past offensive cyber actions by the U.S. military against foreign targets, Barr said the DOJ did so in this case because the accused “indiscriminately” targeted American civilians on a massive scale.

“The United States, like other nations, has gathered intelligence throughout its history to ensure that national security and foreign policy decision makers have access to timely, accurate and insightful information,” Barr said. “But we collect information only for legitimate national security purposes. We don’t indiscriminately violate the privacy of ordinary citizens.”

FBI Deputy Director David Bowdich sought to address the criticism about the wisdom of indicting Chinese military officers for attacking U.S. commercial and government interests. Some security experts have charged that such indictments could both lessen the charges’ impact and leave American officials open to parallel criminal allegations from Chinese authorities.

“Some might wonder what good it does when these hackers are seemingly beyond our reach,” Bowdich said. “We answer this question all the time. We can’t take them into custody, try them in a court of law and lock them up. Not today, anyway. But one day these criminals will slip up, and when they do we’ll be there. We in law enforcement will not let hackers off the hook just because they’re halfway around the world.”

The attorney general said the attack on Equifax was just the latest in a long string of cyber espionage attacks that sought trade secrets and sensitive data from a broad range of industries, and including managed service providers and their clients worldwide, as well as U.S. companies in the nuclear power, metals and solar products industries.

“Indeed, about 80 percent of our economic espionage prosecutions have implicated the Chinese government, and about 60 percent of all trade secret thefts cases in recent years involved some connection with China,” he said.

The indictments come on the heels of a conference held by US government officials this week that detailed the breadth of hacking attacks involving the theft of intellectual property by Chinese entities.

“The FBI has about a thousand investigations involving China’s attempted theft of U.S.-based technology in all 56 of our field offices and spanning just about every industry and sector,” FBI Director Christopher Wray reportedly told attendees at the gathering in Washington, D.C., dubbed the “China Initiative Conference.”

At a time when increasingly combative trade relations with China combined with public fears over the ongoing Coronavirus flu outbreak are stirring Sinophobia in some pockets of the U.S. and other countries, Bowdich was quick to clarify that the DOJ’s beef was with the Chinese government, not its citizenry.

“Our concern is not with the Chinese people or with the Chinese American,” he said. “It is with the Chinese government and the Chinese Communist Party. Confronting this threat directly doesn’t mean we should not do business with China, host Chinese students, welcome Chinese visitors or co-exist with China as a country on the world stage. What it does mean is when China violates our criminal laws and international norms, we will hold them accountable for it.”

A copy of the indictment is available here.

ANALYSIS

DOJ officials praised Equifax for their “close collaboration” in sharing data that helped investigators piece together this whodunnit. Attorney General Barr noted that the accused not only stole personal and in some cases financial data on Americans, they also stole Equifax’s trade secrets, which he said were “embodied by the compiled data and complex database designs used to store personal information.”

While the DOJ’s announcement today portrays Equifax in a somewhat sympathetic light, it’s important to remember that Equifax repeatedly has proven itself an extremely poor steward of the highly sensitive information that it holds on most Americans.

Equifax’s actions immediately before and after its breach disclosure on Sept 7, 2017 revealed a company so inept at managing its public response that one couldn’t help but wonder how it might have handled its internal affairs and security. Indeed, Equifax and its leadership careened from one feckless blunder to the next in a series of debacles that KrebsOnSecurity described at the time as a complete “dumpster fire” of a breach response.

For starters, the Web site that Equifax set up to let consumers check if they were affected by the breach consistently gave conflicting answers, and was initially flagged by some Web browsers as a potential phishing site.

Compounding the confusion, on Sept. 19, 2017, Equifax’s Twitter account told people looking for information about the breach to visit the wrong Web site, which also was blocked by multiple browsers as a phishing site.

And two weeks after its breach disclosure, Equifax began notifying consumers of their eligibility to enroll in free credit monitoring — but the messages did not come from Equifax’s domain and were in many other ways indistinguishable from a phishing attempt.

It soon emerged the intruders had gained access to Equifax’s systems by attacking a software vulnerability in an Internet-facing server that had been left unpatched for four months after security experts warned that the flaw was being broadly exploited. We also learned that the server in question was tied to an online dispute portal at Equifax, which the intruders quickly seeded with tools that allowed them to maintain access to the credit bureau’s systems.

This is especially notable because on Sept. 12, 2017 — just five days after Equifax went public with its breach — KrebsOnSecurity broke the news that the administrative account for a separate Equifax dispute resolution portal catering to consumers in Argentina was wide open, protected by perhaps the most easy-to-guess password combination ever: “admin/admin.”

A partial list of active and inactive Equifax employees in Argentina. This page also let anyone add or remove users at will, or modify existing user accounts.

Perhaps we all should have seen this megabreach coming. In May 2017, KrebsOnSecurity detailed how countless employees at many major U.S. companies suffered tax refund fraud with the IRS thanks to a laughably insecure portal at Equifax’s TALX payroll division, which provides online payroll, HR and tax services to thousands of U.S. firms.

Equifax’s TALX — now called Equifax Workforce Solutions — aided tax thieves by relying on outdated and insufficient consumer authentication methods.

In October 2017, KrebsOnSecurity showed how easy it was to learn the complete salary history of a large portion of Americans simply by knowing someone’s Social Security number and date of birth, thanks to yet another Equifax portal.

Around that same time, we also learned that at least two Equifax executives sought to profit from the disaster through insider trading just days prior to the breach announcement. Jun Ying, Equifax’s former chief information officer, dumped all of his stock in the company in late August 2017, realizing a gain of $480,000 and avoiding a loss of more than $117,000 when news of the breach dinged Equifax’s stock price.

Sudhakar Reddy Bonthu, a former manager at Equifax who was contracted to help the company with its breach response, bought 86 “put” options in Equifax stock on Sept. 1, 2017 that allowed him to profit when the company’s share price dropped. Bonthu was later sentenced to eight months of home confinement; Ying got four months in prison and one year of supervised release. Both were fined and/or ordered to pay back their ill-gotten gains.

While Equifax’s stock price took a steep hit in the months following its breach disclosure, shares in the company [NYSE:EFX] gained a whopping 50.5% in 2019, according to data from S&P Global Market Intelligence.

KrebsOnSecurity has long maintained that the 2017 breach at Equifax was not the work of financially-motivated identity thieves, as there has been exactly zero evidence to date that anything close to the size of the data cache stolen from that incident has shown up for sale in the cybercrime underground.

However, readers should understand that there are countless other companies with access to SSN, DOB and other information crooks need to apply for credit in your name that get hacked all the time, and that this data on a great many Americans is already for sale across various cybercrime bazaars.

Readers also should know that while identity theft protection services of the kind offered by Equifax and other companies may alert you if crooks open a new line of credit in your name, these services generally do nothing to stop that identity theft from taking place. ID theft protection services are most useful in helping people recover from such crimes.

As such, KrebsOnSecurity continues to encourage readers to place a freeze on their credit files with Equifax and the other major credit bureaus. This process puts you in control over who gets to grant credit in your name. Placing a freeze is now free for all Americans and their dependents. For more information on how to do that and what to expect from a freeze, please see this primer.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Chinese Military Personnel Charged with Equifax Hack

Chinese Military Personnel Charged with Equifax Hack

The US has indicted Chinese military personnel today on charges of hacking into Equifax’s computer systems and stealing valuable trade secrets and the personal data of nearly 150 million Americans.

A federal grand jury in Atlanta, Georgia, returned the indictment last week against four members of the Chinese People’s Liberation Army (PLA). Wu Zhiyong (吴志勇), Wang Qian (王乾), Xu Ke (许可), and Liu Lei (刘磊) are accused of conspiring to carry out a three-month-long data heist.

According to the nine-count indictment, the defendants exploited a vulnerability in the Apache Struts Web Framework software used by Equifax’s online dispute portal to gain unauthorized access to the credit reporting agency’s computer system. 

Once inside, the quartet allegedly ran around 9,000 queries on Equifax’s system from May to July 2017, obtaining names, dates of birth, and Social Security numbers for nearly half of America’s citizens. 

To obfuscate their location, the defendants are claimed to have routed traffic through approximately 34 servers located in nearly 20 countries and used encrypted communication channels within Equifax’s network to blend in with normal network activity. 

The indictment further alleges that to cover their tracks, the defendants deleted compressed files and wiped log files on a daily basis throughout the prolonged cyber-attack. 

“Today, we hold PLA hackers accountable for their criminal actions, and we remind the Chinese government that we have the capability to remove the Internet’s cloak of anonymity and find the hackers that nation repeatedly deploys against us,” said Attorney General William P. Barr.

“Unfortunately, the Equifax hack fits a disturbing and unacceptable pattern of state-sponsored computer intrusions and thefts by China and its citizens that have targeted personally identifiable information, trade secrets, and other confidential information.”

The defendants are charged with three counts of conspiracy to commit computer fraud, conspiracy to commit economic espionage, and conspiracy to commit wire fraud. They are further charged with two counts of unauthorized access and intentional damage to a protected computer, one count of economic espionage, and three counts of wire fraud. 

The accused are all members of the PLA’s 54th Research Institute, a component of the Chinese military. 

FBI Deputy Director David Bowdich said: “Today’s announcement of these indictments further highlights our commitment to imposing consequences on cybercriminals no matter who they are, where they are, or what country’s uniform they wear.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Social Robot Teaches Kids Cyber-safety

Social Robot Teaches Kids Cyber-safety

A social robot named Zenbo has been using updated versions of classic fairy tales to teach fifth graders in Delaware how to be safe online.

Zenbo was activated at the University of Delaware’s Newark campus during a special lesson laid on by university researchers for a group of students from The College School. 

The two-foot-tall interactive robot was programmed with a number of familiar children’s stories, which had been subtly adapted to promote security in the digital age. For example, in Zenbo’s version of Little Red Riding Hood, entry to grandma’s house is password protected and Red is warned by her mother not to reveal the password to anyone.

When Red encounters a cyber-savvy Big Bad Wolf in the woods, the little girl must grapple with the dilemma of whether she should keep the password a secret or share the private information with a predatory stranger.

Students are asked by the robot what Red should do next. A class confronted with the problem by Zenbo last Tuesday was split down the middle, with half deeming it okay to trust the wolf with the password and the other half believing that to do so would be risky.

“These checkpoints reinforce positive behaviors and create teachable moments for when children make mistakes,” said Chrystalla Mouza, distinguished professor in teacher education in the University of Delaware’s College of Education and Human Development (CEHD). 

“It’s important that this training is provided in school because we cannot rely on it being provided elsewhere.” 

Zenbo’s cybersecurity classroom career is a collaboration between Mouza; professor of computer and information sciences in the College of Engineering Chien-Chung Shen; and Tia Barnes, CEHD assistant professor of human development.

When working to establish an academic minor and a master’s cybersecurity program at the university, Shen observed that children from kindergarten age up to 12th grade were being overlooked when it came to cyber-safety instruction. 

“We envision this social robot being one part of the teacher’s strategy and lesson plan, perhaps as a station that students visit or an activity that they complete during class to generate discussion,” said Mouza.

The project may be expanded in the future to include virtual reality (VR) that would enable children to become characters within the stories and learn through role play.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Facebook’s Social Media Accounts Hacked

Facebook’s Social Media Accounts Hacked

Hackers took over two social media accounts belonging to Facebook on Friday afternoon.

Saudi white hat hacking group OurMine compromised Facebook’s official Twitter and Instagram accounts as part of a publicity stunt to advertise their own security services.

After gaining access to Facebook’s socials, the hackers left a slightly misleading message that implied the Facebook website itself had been hacked as supposed to the company’s Twitter and Instagram accounts (or whichever third-party company was hired to manage them). However, since Instagram is owned by Facebook, the brag was perhaps partially justified.

The group said: “Hi, we are OurMine. Well, even Facebook is hackable but at least their security is better than Twitter.”

OurMine went on to give out its website and email address along with an open invitation for Facebook to get in touch “to improve your accounts [sic] security.” 

In case any onlookers were in doubt as to whom had broken into Facebook’s social media accounts, OurMine also posted a photo of their own logo on the company’s Twitter and Instagram social feeds. 

Twitter confirmed that Friday’s hack occurred via a third party and that Facebook’s account was locked once Twitter had been alerted to the issue.

A spokesperson for Twitter said: “As soon as we were made aware of the issue, we locked the compromised accounts and are working closely with our partners at Facebook to restore them.”

The incident is the latest in a series of high-profile social media hacks perpetrated by OurMine. Just last month, the attention-seeking group hacked the Twitter accounts of America’s National Football League (NFL) and 15 of its teams one week before the Super Bowl.

OurMine is thought to have gotten their mitts on the sports teams’ credentials via third-party social media management platform Khoros. According to their website, Khoros has implemented a number of security measures “throughout the organization to provide full transparency and a peace of mind for Khoros customers that their personal data and information are in good hands.”

Previous online publicity stunts pulled by OurMine include hacking into Twitter founder Jack Dorsey’s Twitter account and compromising the Twitter account of Google’s chief executive, Sundar Pichai. The group has also hacked the corporate Twitter accounts of ESPN and Netflix.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Emotet Spreads Via Newly Discovered Wi-Fi Module

Emotet Spreads Via Newly Discovered Wi-Fi Module

Security researchers have detected a new version of infamous malware loader Emotet designed to spread to any nearby Wi-Fi networks protected only by weak passwords.

The worm.exe is the main executable used for this process, according to Binary Defense.

“Upon startup of Worm.exe, the first action it takes is to copy the service.exe string to a variable that will be used during file spreading. Next, it steps into the main loop and immediately begins profiling the wireless network using wlanAPI.dll calls in order to spread to any networks it can access,” the firm explained.

“The use of purely wlanAPI.dll calls for network profiling makes sense; it is one of the libraries used by native Wi-Fi to manage wireless network profiles and wireless network connections.”

The malware will try to brute force its way past the Wi-Fi password, if the network is protected, and then go searching for all non-hidden shares — either brute forcing these users in turn or doing the same for the “administrator” account for the network resource.

Once individual user accounts are accessed, it drops the service.exe binary, which installs the Windows Defender System Service to gain persistence.

Interestingly, the researchers noted that a worm.exe timestamp of 04/16/2018 indicates that the module may have been running unnoticed for two years. This may be because it is used infrequently by attackers, and also because it will not show up if researchers don’t have a Wi-Fi card in their sandbox environment, Binary Defense claimed.

The good news is that more secure network passwords would help to mitigate the threat.

“Detection strategies for this threat include active monitoring of endpoints for new services being installed and investigating suspicious services or any processes running from temporary folders and user profile application data folders,” the vendor concluded.

“Network monitoring is also an effective detection, since the communications are unencrypted and there are recognizable patterns that identify the malware message content.”

Stay up-to-date with the latest information security trends and topics by registering for Infosecurity Magazine’s next Online Summit. Find out more here.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Docker Registry Snafus Expose Firms to Cloud Compromise

Docker Registry Snafus Expose Firms to Cloud Compromise

Security experts are warning that widespread Docker registry misconfigurations could be exposing countless organizations to critical data theft and malicious attacks.

Palo Alto Networks’ Unit 42 research group focused on one of the most popular platforms around for managing containers. Docker registries are servers designed to store and organize the all-important images, which contain bundled application code, dependent libraries and operating system files.

As these registries therefore provide access to app source code and business-critical data, it’s vital that they are properly secured. However, Palo Alto Networks discovered misconfigurations in registries’ network access controls which left many exposed.

In total, the Unit 42 team found 941 Docker registries exposed to the internet and 117 registries accessible without authentication. There were 2956 repositories and 15,887 tags in these registries, meaning effectively that nearly 3000 applications and almost 16,000 unique versions of these were exposed.

Scores of registries allowed the “push” operation, meaning hackers could replace legitimate app images with those containing backdoors. Others allowed for deletion, meaning cyber-criminals could encrypt or delete and hold them for ransom, while more still allowed any user to pull and run the images.

“The remediation strategy for this particular misconfiguration is straightforward, such as adding a firewall rule to prevent the registry from being accessed from the internet and enforcing authentication header in all the API requests,” the firm concluded.

“However, with an ever-increasing number of applications and complexity of infrastructure, security becomes a daunting job. Automated tools are needed to scan for vulnerabilities and monitor malicious activities constantly. The earlier the issues can be identified, the less chance they will be exploited in the production.”

Stay up-to-date with the latest information security trends and topics by registering for Infosecurity Magazine’s next Online Summit. Find out more here.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

National Portrait Gallery Faced Almost 350,000 Email Attacks in Q4 2019

National Portrait Gallery Faced Almost 350,000 Email Attacks in Q4 2019

The National Portrait Gallery was targeted by 347,602 emails containing spam, phishing and malware attacks in the final quarter of 2019, according to Freedom of Information Act data obtained by think tank Parliament Street.

The National Portrait Gallery is one of London’s most prestigious art galleries, welcoming between 1.1-2 million visitors every year, many of which have private information such as payment details and email addresses stored on its servers. The research highlights the threats posed to the capital’s museums by malicious hackers who seek to steal membership data from popular tourist attractions.

Of the 347,602 blocked emails, 56% were identified as directory harvest attacks, whilst 61,710 emails were blocked as the sender belonged to a ‘threat intelligence blacklist.’ A further 85,793 emails were intercepted as they were believed, or confirmed, to have contained spam content and 418 emails were listed as being blocked for containing viruses.

Andy Heather, VP at Centrify, said: “These figures paint a worrying picture of the volume of malicious email attacks designed to trick unsuspecting staffers into handing over confidential data such as passwords and log-in credentials. The National Portrait Gallery is an incredibly popular destination for tourists, attracting millions of visitors and members every year, which unfortunately makes it a top target for hackers and cyber-criminals seeking to use legitimate, often stolen, credentials to gain access fear of detection.”

Addressing this threat means ensuring a zero trust approach to employee communication, Heather added, ensuring suspicious emails are spotted and full checks are made so that managers can be sure all staffers are who they say they are.

Stay up-to-date with the latest information security trends and topics by registering for Infosecurity Magazine’s next Online Summit. Find out more here.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Likud Election App Exposes All Israel’s Voters

Likud Election App Exposes All Israel’s Voters

An election app used by Israel’s Likud party has leaked the personal information of all of the country’s voters, it has emerged.

Developed and managed by a company called Feed-b, the Elector app is used by prime minister Netanyahu’s party to contact voters with news and updates.

However, serious security and privacy concerns have swirled in Israeli media about the app, before researcher Ran Bar-Zick decided to take a look.

He found serious security deficiencies that exposed the full names, identity card numbers, addresses, phone numbers, gender and other personal details of every eligible voter in Israel.

According to Bar-Zick, all a visitor to the app’s home page would need to do is right click and choose “view source” to expose the underlying code, which reveals all admin usernames and passwords. Entering these would allow an attacker to log in as admin and download the entire voter registry.

The problem stemmed from an API endpoint which was left exposed without a password, and a lack of two-factor authentication throughout the site.

Feed-b claimed it was a “one-off incident that was immediately dealt with.” However, there are concerns that the app also breaches privacy laws because it allows users to also add information including phone numbers on friends and family members whom they believe may vote for Likud.

It’s unclear whether any cyber-criminals or nation state hackers managed to take advantage of the leaky app before the security issue was addressed. The personal details of Israeli lawmakers, military and other VIPs would be of significant interest to many Middle East rivals.

The irony is that Israel prides itself on the quality of its computer engineers. It has a thriving cybersecurity industry, with many companies spun out of former military projects.

Netanyahu himself has boasted in the past that the state’s cyber-spooks have managed to help allies foil numerous terror plots thanks to their signals expertise.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk