Ukrainian police have swooped on five suspected members of a ransomware affiliate that targeted dozens of foreign companies and made at least $1m in profits.
Officers from the country’s Cyber Police Department and the Security Service (SBU), teamed-up with law enforcers in the US and UK to track down the gang, which is said to have hit more than 50 companies in Europe and America.
They arrested the alleged leader, a 36-year-old from Kyiv, his wife and three other co-conspirators.
They also sold IP address-spoofing services to other hackers to help them stay hidden while launching ransomware, information theft, DDoS and other attacks, the SBU said.
“Unlike ‘regular’ VPN services, which can be legally purchased and used, the services offered by this group had broader functionality. For example, they enabled the user to download viruses, spyware and other malware through the platform. It was an unlawful organization set up by criminals for other criminals,” the SBU explained.
“The investigation revealed that the organizers were Ukrainian citizens, including those wanted by foreign law enforcement agencies. They administered the service from personal computers, and, to avoid responsibility, disguised themselves under various nicknames in the darknet.”
Criminal proceeds were laundered using “complex financial transactions” via a number of online services, including some banned in Ukraine. Assets were then transferred to payment cards registered in false names, the SBU added.
According to the Cyber Police Department, one of the suspects is wanted in the UK after stealing bank card details from customers of British lenders and using them to buy goods online, which they later resold.
Ukrainian officers and police from the UK and US carried out nine searches in suspects’ homes and cars, seizing computer equipment, mobile phones, bank cards, flash drives and three vehicles
Tech Giants to Team-Up on Open Source Security After White House Meet
Technology leaders met at the White House yesterday to discuss ways to improve open source security in the wake of the Log4j saga.
According to an official statement on the meeting, the discussion focused on three areas: finding better ways to prevent, detect and mitigate vulnerabilities in code and accelerate the deployment of patches.
“In the first category, participants discussed ideas to make it easier for developers to write secure code by integrating security features into development tools and securing the infrastructure used to build, warehouse and distribute code, like using techniques such as code signing and stronger digital identities,” noted the White House statement.
“In the second category, participants discussed how to prioritize the most important open-source projects and put in place sustainable mechanisms to maintain them. In the final category, participants discussed ways to accelerate and improve the use of Software Bills of Material, as required in the President’s executive order, to make it easier to know what is in the software we purchase and use.”
Participants at the meeting included Alphabet, IBM, RedHat, Amazon, Apple, Meta, Microsoft, Oracle, the Apache Software Foundation, the Linux Foundation and the Open Source Security Foundation (OpenSSF).
Alphabet president of global affairs and chief legal officer, Kent Walker, later argued for greater public-private cooperation to identify the most critical open-source projects and the software that may pose the greatest systemic risks.
The community should then build on initiatives like OpenSSF, he said.
“Growing reliance on open source means that it’s time for industry and government to come together to establish baseline standards for security, maintenance, provenance and testing – to ensure national infrastructure and other important systems can rely on open source projects,” Walker said in a blog post.
“These standards should be developed through a collaborative process, with an emphasis on frequent updates, continuous testing, and verified integrity.”
Walker added that Google had suggested the creation of a new marketplace for open source maintenance that would help match volunteers from companies with critical projects that need support.
Another attendee, Akamai, went further, arguing that the tech community needed to provide financial investment to identify the key open source libraries targeted by threat actors and help in vulnerability management.
Echoing the White House statement, the firm called for better public-private information sharing to swarm problems when vulnerabilities are first identified and the development of “reliable containment plans” to protect consumers and businesses when bugs are inevitably exploited.
The Apache Software Foundation broadly welcomed moves to improve collaboration across open source, private tech companies and government.
“The ASF produces software for the public good. We are committed to working with the larger community, including industry and government consumers of open source software, to find ways to improve security while adhering to The Apache Way,” it said.
“This means that we believe the path forward will require upstream collaboration by the companies and organizations that consume and ship open-source software. There’s no single silver bullet to get there, and it will take all of our organizations working together to improve the open-source supply chain.
The researchers from the FAS Center for Systems Biology discovered a network of genes important in squid eye development that are known to also play a crucial role in limb development across animals, including vertebrates and insects. The scientists say these genes have been repurposed in squid to make camera-lens-type eyes.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
People have made it clear. They’re feeling more exposed to online threats and want stronger protection.
Our 2022 Trends Study puts figures to these feelings, saying that they believe the risks to their online privacy have increased over the past year. Moreover, 42% believe the risks to their personal and financial information have increased as well.
These findings come as more consumers shift their daily lives online, with greater use of internet banking, more investment in virtual assets, and a proliferation of online activities due to COVID-19. A lot more sensitive personal information is being stored and shared on the web, which is putting increased pressure on passwords and security measures.
As more sensitive personal information is being stored and shared on the web, people are showing a strong preference for increased security overall. For example, when asked to choose between connecting with others from anywhere to always being fully protected, the response was overwhelming in favor of strong protection (63%) over ease of connection (16%). The same sentiment extended to the workplace, where “work meetings that are guaranteed seamless” trailed significantly at 14% versus “meetings that are guaranteed secure” at (62%).
Curious as to what steps you can take to be safer online? A few tools along with a few good habits can go a long way toward keeping your privacy and identity secure.
1. Install and use online protection software: By protecting your devices, you protect what’s on them, like your personal information. Comprehensive online protection software can protect your identity in several ways, like steering you clear of malicious downloads and links, protecting your email from phishing attacks, and providing you with a digital shredder that can permanently remove sensitive documents from your computer (simply deleting them won’t do that alone).
2. Use a VPN:A VPN is a Virtual Private Network, a service that protects your data and privacy online. It creates an encrypted tunnel to keep you anonymous by masking your IP address while connecting to public Wi-Fi hotspots. This is a great way to shield your information from crooks and snoops while you’re banking, shopping, or handling any kind of sensitive information online.
3. Improve your passwords and use multi-factor authentication (MFA): Strong, unique passwords for each of your accounts, updated regularly, offer a strong line of defense against attackers. While this may require a bit of effort, a password manager can do the work for you by securely creating and storing strong, unique passwords for you. Comprehensive online protection software will include a password manager as one of its many features. Additionally, MFA adds yet another layer of security by double-checking your identity beyond your username and password, usually with a text or email. If any of your accounts offer MFA, consider using it.
4. Monitor your accounts: Give your statements a close look each time they come around. While many companies and institutions have fraud detection mechanisms in place, they don’t always catch every instance of fraud. Look out for strange purchases or charges and follow up with your bank or credit card company if you suspect fraud. Even the smallest charge could be a sign that something shady is afoot.
The Russian government said today it arrested 14 people accused of working for “REvil,” a particularly aggressive ransomware group that has extorted hundreds of millions of dollars from victim organizations. The Russian Federal Security Service (FSB) said the actions were taken in response to a request from U.S. officials, but many experts believe the crackdown is part of an effort to reduce tensions over Russian President Vladimir Putin’s decision to station 100,000 troops along the nation’s border with Ukraine.
The FSB headquarters at Lubyanka Square, Moscow. Image: Wikipedia.
The FSB said it arrested 14 REvil ransomware members, and searched more than two dozen addresses in Moscow, St. Petersburg, Leningrad and Lipetsk. As part of the raids, the FSB seized more than $600,000 US dollars, 426 million rubles (~$USD 5.5 million), 500,000 euros, and 20 “premium cars” purchased with funds obtained from cybercrime.
“The search activities were based on the appeal of the US authorities, who reported on the leader of the criminal community and his involvement in encroaching on the information resources of foreign high-tech companies by introducing malicious software, encrypting information and extorting money for its decryption,” the FSB said. “Representatives of the US competent authorities have been informed about the results of the operation.”
The FSB did not release the names of any of the individuals arrested, although a report from the Russian news agency TASSmentions two defendants: Roman Gennadyevich Muromsky, and Andrey Sergeevich Bessonov. Russian media outlet RIA Novosti released video footage from some of the raids:
REvil is widely thought to be a reincarnation of GandCrab, a Russian-language ransomware affiliate program that bragged of stealing more than $2 billion when it closed up shop in the summer of 2019. For roughly the next two years, REvil’s “Happy Blog” would churn out press releases naming and shaming dozens of new victims each week. A February 2021 analysis from researchers at IBM found the REvil gang earned more than $120 million in 2020 alone.
In November 2021, Europolannounced it arrested seven REvil affliates who collectively made more than $230 million worth of ransom demands since 2019. At the same time, U.S. authorities unsealed two indictments against a pair of accused REvil cybercriminals, which referred to the men as “REvil Affiliate #22” and “REvil Affiliate #23.”
It is clear that U.S. authorities have known for some time the real names of REvil’s top captains and moneymakers. Last fall, President Biden told Putin that he expects Russia to act when the United States shares information on specific Russians involved in ransomware activity.
So why now? Russia has amassed approximately 100,000 troops along its southern border with Ukraine, and diplomatic efforts to defuse the situation have reportedly broken down. The Washington Post and other media outlets today report that the Biden administration has accused Moscow of sending saboteurs into Eastern Ukraine to stage an incident that could give Putin a pretext for ordering an invasion.
“The most interesting thing about these arrests is the timing,” said Kevin Breen, director of threat research at Immersive Labs. “For years, Russian Government policy on cybercriminals has been less than proactive to say the least. With Russia and the US currently at the diplomatic table, these arrests are likely part of a far wider, multi-layered, political negotiation.”
President Biden has warned that Russia can expect severe sanctions should it choose to invade Ukraine. But Putin in turn has said such sanctions could cause a complete break in diplomatic relations between the two countries.
Dmitri Alperovitch, co-founder of and former chief technology officer for the security firm CrowdStrike, called the REvil arrests in Russia “ransomware diplomacy.”
“This is Russian ransomware diplomacy,” Alperovitch said on Twitter. “It is a signal to the United States — if you don’t enact severe sanctions against us for invasion of Ukraine, we will continue to cooperate with you on ransomware investigations.”
The REvil arrests were announced as many government websites in Ukraine were defaced by hackers with an ominous message warning Ukrainians that their personal data was being uploaded to the Internet. “Be afraid and expect the worst,” the message warned.
Experts say there is good reason for Ukraine to be afraid. Ukraine has long been used as the testing grounds for Russian offensive hacking capabilities. State-backed Russian hackers have been blamed for the Dec. 23, 2015 cyberattack on Ukraine’s power grid that left 230,000 customers shivering in the dark.
The warning left behind on Ukrainian government websites that were defaced in the last 24 hours. The same statement is written in Ukrainian, Russian and Polish.
Russia also has been suspected of releasing NotPetya, a large-scale cyberattack initially aimed at Ukrainian businesses that ended up creating an extremely disruptive and expensive global malware outbreak.
Although there has been no clear attribution of these latest attacks to Russia, there is reason to suspect Russia’s hand, said David Salvo, deputy director of The Alliance for Securing Democracy.
“These are tried and true Russian tactics. Russia used cyber operations and information operations in the run-up to its invasion of Georgia in 2008. It has long waged massive cyberattacks against Ukrainian infrastructure, as well as information operations targeting Ukrainian soldiers and Ukrainian citizens. And it is completely unsurprising that it would use these tactics now when it is clear Moscow is looking for any pretext to invade Ukraine again and cast blame on the West in its typical cynical fashion.”
The assistant principal of a high school in Florida has been charged with aggravated cyber-stalking.
Duval County School Board Police arrested 42-year-old Kenyannya Wilcox on Friday over an alleged incident involving her former romantic partner.
The defendant’s arrest report alleges that Wilcox was involved in a scheme that aimed to cause “adverse economic impact” to her ex and his current romantic partner.
News source News4JAX obtained a petition for injunction for protection against stalking in which Wilcox’s former partner alleges that he and his girlfriend were approached by Wilcox while attending the Jacksonville Jaguars’ NFL home game against Denver on September 19.
In the petition, Wilcox is accused of punching her former boyfriend twice and then following him out of the game while telling him that she “would cost him his job.”
Wilcox’s ex reportedly claimed that Wilcox then contacted the employers of both himself and his current girlfriend and lodged false allegations against them.
In a separate petition filed by Wilcox, the assistant principal alleges that she was assaulted by the “other girlfriend” of a man she had been dating since November 2020. Wilcox further alleges that the man had started false rumors about Wilcox and had attempted to harm her physically.
Wilcox, who was formerly principal at Highlands Middle School, was serving as assistant principal at Jean Ribault High School at the time of her arrest. Police set the educator’s bond at $22,000.
Police charged Wilcox with criminal use of personal identification, criminal use of public records information, official misconduct, aggravated stalking with a credible threat to life or injury, and battery.
Duval County Public Schools said in a statement: “While we commend the work of our police department, it is disappointing when allegations of this nature arise and lead to arrest.
“Duval County Public Schools has high expectations for employee conduct, and we will take appropriate action pending the outcome of the case.”
Following her arrest, Wilcox has been assigned to what the district described as “non-school duties.”
Duval Country Public School said it is monitoring the judicial process and that it has plans to conduct a concurrent professional standards review.
A new facility that aims to train the next generation of cybersecurity professionals is coming to Pennsylvania.
The formation of the new Pennsylvania Cybersecurity Center (PCC) was announced by LindenPointe Development Corporation’s technology business incubator, the eCenter@LindenPointe.
Sited in Mercy County in the city of Hermitage, the new center will focus on providing individuals with a pathway to beginning a career in cybersecurity. Training will follow a holistic approach, combining training and certifications with practical lessons on handling real-world cyber-threats.
Users will also be offered opportunities to secure paid internships and apprenticeship positions within the cybersecurity industry.
Jeffrey Meier, executive director at LindenPointe Development Corporation, said: “With approximately 16,000 open cybersecurity positions in Pennsylvania alone, and more than 600,000 across the country, the Pennsylvania Cybersecurity Center represents an opportunity for our area to become a leader in training the next generation of cybersecurity professionals.”
A kickoff meeting for the new center is due to take place at the end of this month, and the PCC plans to launch its very first pilot program in February. Participating in the program will be 15 high school students and 15 college students from educational establishments in the local area, including Sharon, Hickory, Greenville, Sharpsville, Farrell, Thiel College, Penn State Shenango, and Westminster College.
“In addition to our academic partnerships with local high schools and colleges, our workforce and industry partners will play a large role in the success of the Center,” said Meier.
High school students will study three courses designed by LindenPointe partner CompTIA, while college students will be taking five courses formulated by partner Cisco Network Academy.
On December 20, State Representative Mark Longietti announced $250,000 in new funding to help the Pennsylvania Cybersecurity Center launch a pilot program that aims to prepare students for high-demand careers in cybersecurity.
“As the world grows increasingly digital, the demand for high-paying cybersecurity jobs has quickly increased, and our region needs to keep pace with that demand by providing training for those careers,” said Longietti.
“This funding will allow the eCenter@LindenPointe to lay the groundwork for its pilot program geared toward area high school and college students by funding efforts at recruitment, industry exposure, curriculum, and placement.”
FCC Proposes Stricter Data Breach Reporting Requirements
The United States’ Federal Communications Commission (FCC) has proposed the introduction of stricter reporting requirements around data breaches.
On Wednesday, FCC chairperson Jessica Rosenworcel circulated a Notice of Proposed Rulemaking (NPRM) that kicked off the process of strengthening the Commission’s rules on notifying customers and federal law enforcement when customer proprietary network information (CPNI) is breached.
The Commission said the proposed updates would more closely align FCC data breach notification rules with federal and state data breach laws governing other sectors.
Rosenworcel said: “Current law already requires telecommunications carriers to protect the privacy and security of sensitive customer information. But these rules need updating to fully reflect the evolving nature of data breaches and the real-time threat they pose to affected consumers.”
Several updates to existing FCC rules around telecommunications carriers’ breach notification requirements are included in the proposal. Among these is the suggestion to eradicate the current seven business day mandatory waiting period for notifying customers of a breach.
The NPRM also proposes making it a requirement to notify customers of inadvertent breaches, and requiring carriers to notify the FCC, the FBI, and United States Secret Service of all reportable breaches.
“Customers deserve to be protected against the increase in frequency, sophistication, and scale of these data leaks, and the consequences that can last years after an exposure of personal information,” said Rosenworcel.
She added: “I look forward to having my colleagues join me in taking a fresh look at our data breach reporting rules to better protect consumers, increase security, and reduce the impact of future breaches.”
The FCC said that the new rules outlined in the NPRM would help to ensure that “the Commission and other federal law enforcement agencies receive the information they need in a timely manner so they can mitigate and prevent harm due to the breach and take action to reduce the likelihood of future incidents.”
Comments are now being sought by the FCC as to whether the Commission should require customer breach notices to include specific categories of information.
The suggestion to expand data breach reporting requirements follows the FCC’s September proposal to introduce new rules targeting SIM-swapping cybercrime and port-out fraud.