Faking an iPhone Reboot

Researchers have figured how how to intercept and fake an iPhone reboot:

We’ll dissect the iOS system and show how it’s possible to alter a shutdown event, tricking a user that got infected into thinking that the phone has been powered off, but in fact, it’s still running. The “NoReboot” approach simulates a real shutdown. The user cannot feel a difference between a real shutdown and a “fake shutdown.” There is no user-interface or any button feedback until the user turns the phone back “on.”

It’s a complicated hack, but it works.

Uses are obvious:

Historically, when malware infects an iOS device, it can be removed simply by restarting the device, which clears the malware from memory.

However, this technique hooks the shutdown and reboot routines to prevent them from ever happening, allowing malware to achieve persistence as the device is never actually turned off.

I see this as another manifestation of the security problems that stem from all controls becoming software controls. Back when the physical buttons actually did things — like turn the power, the Wi-Fi, or the camera on and off — you could actually know that something was on or off. Now that software controls those functions, you can never be sure.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Who is the Network Access Broker ‘Wazawaka?’

In a great many ransomware attacks, the criminals who pillage the victim’s network are not the same crooks who gained the initial access to the victim organization. More commonly, the infected PC or stolen VPN credentials the gang used to break in were purchased from a cybercriminal middleman known as an initial access broker. This post examines some of the clues left behind by “Wazawaka,” the hacker handle chosen by a major access broker in the Russian-speaking cybercrime scene.

Wazawaka has been a highly active member of multiple cybercrime forums over the past decade, but his favorite is the Russian-language community Exploit. Wazawaka spent his early days on Exploit and other forums selling distributed denial-of-service (DDoS) attacks that could knock websites offline for about USD $80 a day. But in more recent years, Wazawaka has focused on peddling access to organizations and to databases stolen from hacked companies.

“Come, rob, and get dough!,” reads a thread started by Wazawaka on Exploit in March 2020, in which he sold access to a Chinese company with more than $10 billion in annual revenues. “Show them who is boss.”

According to their posts on Exploit, Wazawaka has worked with at least two different ransomware affiliate programs, including LockBit. Wazawaka said LockBit had paid him roughly $500,000 in commissions for the six months leading up to September 2020.

Wazawaka also said he’d teamed up with DarkSide, the ransomware affiliate group responsible for the six-day outage at Colonial Pipeline last year that caused nationwide fuel shortages and price spikes. The U.S. Department of State has since offered a $5 million reward for information leading to the arrest and conviction of any DarkSide affiliates.

Wazawaka seems to have adopted the uniquely communitarian view that when organizations being held for ransom decline to cooperate or pay up, any data stolen from the victim should be published on the Russian cybercrime forums for all to plunder — not privately sold to the highest bidder. In thread after thread on the crime forum XSS, Wazawaka’s alias “Uhodiransomwar” can be seen posting download links to databases from companies that have refused to negotiate after five days.

“The only and the main principle of ransomware is: the information that you steal should never be sold,” Uhodiransomwar wrote in August 2020. “The community needs to receive it absolutely free of charge if the ransom isn’t paid by the side that this information is stolen from.”

Wazawaka hasn’t always been so friendly to other cybercrooks. Over the past ten years, his contact information has been used to register numerous phishing domains intended to siphon credentials from people trying to transact on various dark web marketplaces. In 2018, Wazawaka registered a slew of domains spoofing the real domain for the Hydra dark web market. In 2014, Wazawaka confided to another crime forum member via private message that he made good money stealing accounts from drug dealers on these marketplaces.

“I used to steal their QIWI accounts with up to $500k in them,” Wazawaka recalled. “A dealer would never go to the cops and tell them he was selling stuff online and someone stole his money.”

WHO IS WAZAWAKA?

Wazawaka used multiple email addresses and nicknames on several Russian crime forums, but data collected by cybersecurity firm Constella Intelligence show that Wazawaka’s alter egos always used one of three fairly unique passwords: 2k3x8x57, 2k3X8X57, and 00virtual.

Those three passwords were used by one or all of Wazawaka’s email addresses on the crime forums over the years, including wazawaka@yandex.ru, mixseo@mail.ru, mixseo@yandex.ru, mixfb@yandex.ru.

That last email address was used almost a decade ago to register a Vkontakte (Russian version of Facebook) account under the name Mikhail “Mix” Matveev. The phone number tied to that Vkontakte account — 7617467845 — was assigned by the Russian telephony provider MegaFon to a resident in Khakassia, situated in the southwestern part of Eastern Siberia.

DomainTools.com [an advertiser on this site] reports mixfb@yandex.ru was used to register three domains between 2008 and 2010: ddosis.ru, best-stalker.com, and cs-arena.org. That last domain was originally registered in 2009 to a Mikhail P. Matveyev, in Abakan, Khakassia.

Mikhail Matveev is not the most unusual name in Russia, but other clues help narrow things down quite a bit. For example, early in his postings to Exploit, Wazawaka can be seen telling members that he can be contacted via the ICQ instant message account 902228.

An Internet search for Wazawaka’s ICQ number brings up a 2009 account for a Wazawaka on a now defunct discussion forum about Kopyovo-a, a town of roughly 4,400 souls in the Russian republic of Khakassia:

MIKHAIL’S MIX

Also around 2009, someone using the nickname Wazawaka and the 902228 ICQ address started posting to Russian social media networks trying to convince locals to frequent the website “fureha.ru,” which was billed as another website catering to residents of Khakassia.

According to the Russian domain watcher 1stat.ru, fureha.ru was registered in January 2009 to the email address mix@devilart.net and the phone number +79617467845, which is the same number tied to the Mikhail “Mix” Matveev Vkontakte account.

DomainTools.com says the mix@devilart.net address was used to register two domains: one called badamania[.]ru, and a defunct porn site called tvporka[.]ru. The phone number tied to that porn site registration back in 2010 was 79235810401, also issued by MegaFon in Khakassia.

A search in Skype for that number shows that it was associated more than a decade ago with the username “matveevatanya1.” It was registered to a now 29-year-old Tatayana Matveeva Deryabina, whose Vkontakte profile says she currently resides in Krasnoyarsk, the largest city that is closest to Abakan and Abaza.

It seems likely that Tatayana is a relative of Mikhail Matveev, perhaps even his sister. Neither responded to requests for comment. In 2009, a Mikhail Matveev from Abaza, Khakassia registered the username Wazawaka on weblancer.net, a freelance job exchange for Russian IT professionals. The Weblancer account says Wazawaka is currently 33 years old.

In March 2019, Wazawaka explained a lengthy absence on Exploit by saying he’d fathered a child. “I will answer everyone in a week or two,” the crime actor wrote. “Became a dad — went on vacation for a couple of weeks.”

One of the many email addresses Wazawaka used was devdelphi@yandex.ru, which is tied to a more recent but since-deleted Vkontakte account for a Mikhail Matveev and used the password 2k3X8X57. As per usual, I put together a mind map showing the connections referenced in this story:

A rough mind map of the connections mentioned in this story.

Analysts with cyber intelligence firm Flashpoint say Wazawaka’s postings on various Russian crime forums show he is proficient in many specializations, including botnet operations, keylogger malware, spam botnets, credential harvesting, Google Analytics manipulation, selling databases for spam operations, and launching DDoS attacks.

Flashpoint says it is likely Wazawaka/Mix/M1x has shared cybercriminal identities and accounts with multiple other forum members, most of whom appear to have been partners in his DDoS-for-hire business a decade ago. For example, Flashpoint points to an Antichat forum thread from 2009 where members said M1x worked on his DDoS service with a hacker by the nickname “Vedd,” who was reputedly also a resident of Abakan.

STAY  TRUE, & MOTHER RUSSIA WILL HELP YOU

All of this is academic, of course, provided Mr. Wazawaka chooses to a) never leave Russia and b) avoid cybercrime activities that target Russian citizens. In a January 2021 thread on Exploit regarding the arrest of an affiliate for the NetWalker ransomware program and its subsequent demise, Wazawaka seems already resigned those limitations.

“Don’t shit where you live, travel local, and don’t go abroad,” Wazawaka said of his own personal mantra.

Which might explain why Wazawaka is so lackadaisical about hiding and protecting his cybercriminal identities: Incredibly, Wazawaka’s alter ego on the forum XSS — Uhodiransomware — still uses the same password on the forum that he used for his Vkontakte account 10 years ago. Lucky for him, XSS also demands a one-time code from his mobile authentication app.

The second step of logging into Wazawaka’s account on XSS (Uhodiransomwar).

Wazawaka said NetWalker’s closure was the result of its administrator (a.k.a. “Bugatti”) getting greedy, and then he proceeds to preach about the need to periodically re-brand one’s cybercriminal identity.

“I’ve had some business with Bugatti,” Wazawaka said. “The guy got too rich and began recruiting Americans as affiliate partners. What happened now is the result. That’s okay, though. I wish Bugatti to do some rebranding and start from the beginning ? As for the servers that were seized, they should’ve hosted their admin panels in Russia to avoid getting their servers seized by INTERPOL, the FBI, or whatever.”

“Mother Russia will help you,” Wazawaka concluded. “Love your country, and you will always get away with everything.”

If you liked this post, you may also enjoy Who Is the Network Access Broker “Babam”?

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Medigate Acquired by Claroty

Medigate Acquired by Claroty

Cyber-physical systems (CPS) security company Claroty has announced the acquisition of healthcare IoT security business Medigate

In a statement released January 10, Claroty said the deal would allow it to secure the Extended Internet of Things (XIoT) “by delivering unmatched visibility, protection, and threat detection for all connected organizations via one comprehensive solution.”

Medigate, which is headquartered in New York’s Brooklyn borough, is known for creating the first security platform dedicated to healthcare IoT. 

The company was founded in the summer of 2017 by Jonathan Langer, Itay Kirshenbaum, and Pini Pinhasov. Langer serves as the company’s CEO, while Israel-based Kirshenbaum and Pinhasov fulfill the roles of vice president of research and development and vice president of product, respectively.

Since its creation, Medigate has scooped more than 40 industry awards, including the 2021 Best in KLAS for Healthcare IoT Security, the SINET Innovator Award, and Fast Company’s Most Innovative Company Award. It has also been listed in Forbes’ Top 20 IoT Start-Ups to Watch.

“By joining forces between Medigate and Claroty, we are forming the only cybersecurity company that can deliver a best-of-breed solution for all the critical assets across healthcare, industrial, and enterprise environments that comprise the XIoT,” said Langer.

He added: “Our combined talent, technology, and IP empowers us to truly change the way organizations identify, secure, and manage these connected assets on a massive scale, thereby delivering even greater value for our customers.”

Yaniv Vardi, CEO of Claroty, said that Medigate’s team and capabilities would play a key role in Claroty’s vision of a future “where cyber and physical worlds safely connect to support our lives.”

“Highly interconnected CPS have become pervasive in industrial and healthcare environments in recent years in order to drive innovation, resilience, sustainability, and better health outcomes. However, greater connectivity begets greater exposure to risks, with serious consequences for patient safety, public safety, and the environment,” said Vardi.

He added: “Together, Claroty and Medigate will combine our deep domain expertise and specialized technologies into a comprehensive platform that will extend across all types of CPS and connected devices to secure the XIoT.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Hackers Hit Healthcare Data Management Company

Hackers Hit Healthcare Data Management Company

The protected health information (PHI) of thousands of individuals may have been exposed in a hacking incident at a healthcare information management company based in Georgia.

Clinical or treatment information and Social Security numbers were among the sensitive data compromised during a successful cyber-attack on Ciox Health that took place last summer.

Ciox Health, which is headquartered in Alpharetta, provides a variety of services, including information release, medical record retrieval, and health information management to more than 30 healthcare providers.

According to a notice recently issued by Ciox Health, an unauthorized person accessed the email account of a Ciox employee between June 24, 2021, and July 2, 2021. 

The company warned that the threat actor may have used that access to download emails and attachments associated with the compromised account.

“Ciox reviewed the account’s contents to determine whether sensitive information was contained in the account,” said the notice. 

“On September 24, 2021, Ciox learned that some emails and attachments in the employee’s email account contained limited patient information related to Ciox billing inquiries and/or other customer service requests.”

Information that the attacker may have accessed included patient names, provider names, dates of birth, and/or dates of service. Social Security numbers or driver’s license numbers, health insurance information, and/or clinical or treatment information was also exposed in what Ciox described as “very limited instances.”

The data breach was reported to the US Department of Health and Human Services’ Office for Civil Rights on December 30 as a hacking/IT incident impacting 12,493 individuals. 

Ciox Health said it began notifying its healthcare provider customers of the security incident on November 23. The security notice published on Ciox Health’s website was issued on behalf of 32 different healthcare providers, including Children’s Healthcare of Atlanta, Indiana University Health, Niagara Falls Memorial Medical Center Health System, and Sarasota County Public Hospital District d/b/a Sarasota Memorial Health Care System.

“To help prevent something like this from happening again, we have and will continue to identify opportunities to implement additional procedures to further strengthen our email security, including by providing enhanced cybersecurity training to our employees,” stated Ciox Health.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

US Issues Alert Over Russian Hackers

US Issues Alert Over Russian Hackers

The FBI, CISA, and the NSA have warned those in charge of the United States’ critical infrastructure network to prepare themselves against cyber-attacks originating in Russia.

In a joint advisory issued January 11, the three agencies provided an overview of Russian state-sponsored cyber-operations; commonly observed tactics, techniques, and procedures (TTPs); detection actions; incident response guidance; and mitigations. 

The agencies shared attack vectors that have been favored by Russian-based cyber-criminals in the past and urged the cybersecurity community to “adopt a heightened state of awareness and to conduct proactive threat hunting.”

Tactics cited in the advisory include spear phishing, brute force, exploiting known vulnerabilities, compromising third-party software, and developing and deploying custom malware.

“Russian state-sponsored APT actors have used sophisticated cyber-capabilities to target a variety of US and international critical infrastructure organizations, including those in the Defense Industrial Base as well as the Healthcare and Public Health, Energy, Telecommunications, and Government Facilities Sectors,” the joint advisory reads.

The warning came as no surprise to Vectra CTO and technical director Tim Wade. 

He told Infosecurity Magazine: “I can’t recall a time in my life when Russia wasn’t aggressively probing Western resolve, ranging from tactical incursions into air space to pulling strategic economic levers.

“This activity is just a continuation of that longstanding tradition, and I read this advisory as another periodic reminder of the background radiation of global politics – if you’re operating critical infrastructure and are under the impression that you aren’t squarely in an operator’s crosshairs, you’re wrong.”

John Bambenek, principal threat hunter at Netenrich, was similarly insouciant about the latest cybersecurity alert to be issued by the Biden administration.

“Advisories like this do little to help defenders actually protect themselves,” he said. “I read this and don’t have any more insight into detecting and preventing these attacks than before.”

Bambenek called for the NSA, FBI, and CISA to take a different and more direct approach to help America’s critical infrastructure defend against cyber-threats.

“It’s 2022,” he said. “These agencies hopefully can reach directly out to organizations with more-specific guidance, because public announcements aren’t helpful and there are reasons not to be too specific in them as well.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

World Economic Forum: Cybersecurity an Increasing Global Threat

World Economic Forum: Cybersecurity an Increasing Global Threat

Cybersecurity was once again identified as a major short and medium-term threat to the world in this year’s World Economic Forum’s (WEF’s) The Global Risk Report. The analysis was based on insights from nearly 1000 global experts and leaders who responded to the WEF’s Global Risks Perception Survey (GRPS).

Perhaps unsurprisingly, environmental issues like climate action failure and extreme weather ranked highest on the risks facing the world over the short (0-2 years), medium (2-5 years) and long-term (5-10 years). In addition, a number of challenges exacerbated by the pandemic, such as livelihood crises, infectious diseases and mental health deterioration, also scored highly. Overall, this added up to a pessimistic assessment, with 84.2% of respondents stating they were either “worried” or “concerned” about the global outlook.

Digital challenges, such as “cybersecurity failures,” were also viewed as a significant and growing problem to the world. Nearly one in five (19.5%) respondents believe cybersecurity failures will be a critical threat to the world in just the next 0-2 years, and 14.6% said it would be in 2-5 years.

Interestingly, cybersecurity failures didn’t score as highly as a long-term risk. Reflecting on this, the report stated: “This suggests lower relevance to respondents – or a blind spot in perceptions given the potential damage of cyber-risks – compared to economic, societal and environmental concerns.”

Cybersecurity failures also ranked seventh (12.4%) in the risks that have worsened since the start of COVID-19, reflecting how increased reliance on digital technologies has created more opportunities for cyber-threat actors to strike.  

During a WEF press conference launching the report, Carolina Klint, risk management leader, Continental Europe, of Marsh, highlighted cybersecurity as a particularly grave business threat. She noted that the intensification of attacks over recent years means “that cyber-threats are now growing faster than our ability to prevent and manage them effectively.”

The pandemic has offered new opportunities for cyber-criminals to strike, with businesses forced to digitize and adopt new automation technologies rapidly. “Too often this has been built on the back of aging technology, which has led to supply chain disruption and greater exposure to cyber-attacks,” added Klint.

She also noted that the financial costs of cyber-attacks, such as ransomware, have surged in recent years. For example, the report cited data showing a four-fold rise in the total cryptocurrency value received by ransomware addresses last year, reaching $406.34m. In addition, Klint observed that “in 2021, we saw the highest average cost of a data breach in almost two decades.”

Overall, Klint identified four main cyber-risks that need to be tackled over the coming years. These are critical infrastructure failures, an increasingly aggressive regulatory environment, unprecedented identity theft and the failure to execute digital transformation effectively. She warned: “Companies soon won’t be able to claim good ESG credentials without addressing these key areas.”

To address these cyber challenges and more, companies must enhance their resiliency, “which is a journey, not a destination.” These efforts must not only focus on their own internal assets, “but also the vulnerabilities of those in their supply chain.”

In the GRPS survey, the respondents had a dim view of current cyber-threat mitigation efforts. Close to three-quarters (73%) said international risk mitigation efforts in the area of cross-border cyber-attacks and misinformation had either not started or are in early development. The Global Risk Report warned of severe consequences if international cooperation in this area is not improved. This includes the potential for open cyber warfare as governments continue to retaliate against perpetrators and growing “mistrust between societies, business and government.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains