Coronavirus Attacks Aim to Spread Malware Infection

Coronavirus Attacks Aim to Spread Malware Infection

Security experts are warning of new phishing campaigns designed to capitalize on global fears of the fast-spreading coronavirus.

Last week saw the first reported UK infections of the virus, known for now as 2019-nCoV, after it spread around the world from an epicenter in Wuhan, China. Concerns persist over whether the true extent of the virus, which is said to have a mortality rate of 2%, has been downplayed by Beijing.

True to form, cyber-criminals are looking to exploit the widespread hunger for news about the outbreak by using it as a phishing lure.

Mimecast has detected one such campaign, with emails titled “Singapore Specialist: Corona Virus Safety Measures.”

Of course, clicking on the link in the email will lead to a covert malware download.

“The sole intention of these threat actors is to play on the public’s genuine fear to increase the likelihood of users clicking on an attachment or link delivered in a malicious communication, to cause infection, or for monetary gain. This is a rational choice by criminals as research has shown that over 90% of compromises occur by email, and that over 90% of those breaches are primarily attributable to user error,” explained director of threat intelligence, Francis Gaffney.

“There are a number of simple steps you can take to minimize your risk, such as using a reliable AV solution and following safe cyber-hygiene practices such as strong password usage and never enabling macros in any attachments if you do open them. I urge everyone to be vigilant at this time in relation to any emails or electronic communications purporting to be in relation to the support of those affected by the coronavirus.”

Kaspersky has also sounded the alarm over coronavirus-themed attacks. It detected multiple malicious pdf, mp4 and docx files claiming to contain updates and information on how to stay safe from the virus.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Over 80% of UK Firms Don’t Have Specialist Cyber Insurance

Over 80% of UK Firms Don’t Have Specialist Cyber Insurance

More than 80% of UK businesses still don’t have cyber-related insurance despite widespread recognition of the risks associated with rising threat levels, according to Gallagher.

The insurer polled 1000 UK business leaders in organizations of various sizes, and nearly two-fifths (39%) cited cyber-attacks as one of their biggest concerns. However, 82% claimed not to have specialist insurance.

Gallagher argued that many firms may be buying catch-all policies which may not pay out in the event of a serious security breach, while others either underestimate cyber-threats or have too much confidence in their ability to defend against attacks.

It claimed that nearly half (46%) of respondents from mid-sized firms believe that cyber-attacks are “mainly an issue for bigger organizations.”  

Of course, the stats show that, while sophisticated targeted attacks may only strike larger companies, firms of all sizes are regularly the subject of automated cyber-raids. ISP Beaming warned in January that the average UK firm was hit by over half a million attempts to compromise systems last year, a 152% increase on 2018.

Network device admin tools and IoT endpoints like connected security cameras and building control systems were most commonly targeted, followed by file sharing platforms.

Tom Draper, head of cyber at Gallagher, added that smaller firms may also be compromised in an attempt to reach higher value clients and partners.

“Clearly there are practical steps businesses can take to help protect against cyber-attacks, but unfortunately the risk remains significant and many businesses are leaving themselves exposed to financial and reputational damage if they do not consider having specialist insurance in place,” he argued.

“It is evident from our research that many bosses believe they are covered in the event of a cyber-attack, however traditional or off-the-shelf business insurance policies do not typically provide cover for cyber-related issues.”

Big-name organizations including Cadbury-owner Mondelez and law firm DLA Piper are currently involved in litigation with their insurers over failure to pay-out following the NotPetya ransomware worm of 2017, highlighting the importance of nailing down the small print in policy documents.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

EKANS Ransomware Detected with ICS-Specific Functions

EKANS Ransomware Detected with ICS-Specific Functions

Security researchers are warning of a new ransomware strain containing functionality to target industrial control systems (ICS) — evidence that cyber-criminals are gearing up for more attacks on such environments.

Discovered in mid-December last year, EKANS joins just a handful of similar ICS-specific variants including Havex and CrashOverride, according to security vendor Dragos.

It’s described as relatively straightforward ransomware that encrypts files and displays a ransom note, but the malware differs from most in that it names ICS processes in a static “kill list.” In the past, ransomware that has impacted ICS environments, such as the LockerGaga shutdown of NorskHydro, has been IT-focused and only spread into such systems via enterprise mechanisms, Dragos explained.

Among the ICS products referenced in the code are: GE’s Proficy data historian, GE Fanuc licensing server services, Honeywell’s HMIWeb application and ThingWorx Industrial Connectivity Suite, as well as a range of other remote monitoring and licensing server offerings.

There’s no self-propagation mechanism included in the ransomware, instead it must be launched interactively or via a script once the threat actors behind it have achieved large-scale compromise of a victim organization, such as via Active Directory.

Although primitive, EKANS presents “specific and unique risks and cost-imposition scenarios for industrial environments,” warned Dragos.

“EKANS (and its likely predecessor MegaCortex) represent an adversary evolution to hold control system environments specifically at risk. As such, EKANS despite its limited functionality and nature represents a relatively new and deeply concerning evolution in ICS-targeting malware” the firm concluded.

“Whereas previously ICS-specific or ICS-related malware was solely the playground of state-sponsored entities, EKANS appears to indicate non-state elements pursuing financial gain are now involved in this space as well, even if only at a very primitive level.”

However, not all experts agree. Emsisoft threat analyst, Brett Callow, argued that the ransomware isn’t designed to target ICS environments specifically.

“The most likely reason for it stopping ICS processes is simply so that the files used by those processes can be encrypted. In-use files cannot be encrypted, which is why ransomware typically tries to stop a multitude of processes,” he explained.

“Additionally, there’s no reason to believe that EKANS was developed to target a specific company or industry. Nor is it running rampant: there have been a grand total of five submissions to ID Ransomware.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk