Tracking People by their MAC Addresses

Yet another article on the privacy risks of static MAC addresses and always-on Bluetooth connections. This one is about wireless headphones.

The good news is that product vendors are fixing this:

Several of the headphones which could be tracked over time are for sale in electronics stores, but according to two of the manufacturers NRK have spoken to, these models are being phased out.

“The products in your line-up, Elite Active 65t, Elite 65e and Evolve 75e, will be going out of production before long and newer versions have already been launched with randomized MAC addresses. We have a lot of focus on privacy by design and we continuously work with the available security measures on the market,” head of PR at Jabra, Claus Fonnesbech says.

“To run Bluetooth Classic we, and all other vendors, are required to have static addresses and you will find that in older products,” Fonnesbech says.

Jens Bjørnkjær Gamborg, head of communications at Bang & Olufsen, says that “this is products that were launched several years ago.”

“All products launched after 2019 randomize their MAC-addresses on a frequent basis as it has become the market standard to do so,” Gamborg says.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

“FudCo” Spam Empire Tied to Pakistani Software Firm

In May 2015, KrebsOnSecurity briefly profiledThe Manipulaters,” the name chosen by a prolific cybercrime group based in Pakistan that was very publicly selling spam tools and a range of services for crafting, hosting and deploying malicious email. Six years later, a review of the social media postings from this group shows they are prospering, while rather poorly hiding their activities behind a software development firm in Lahore that has secretly enabled an entire generation of spammers and scammers.

The Web site in 2015 for the “Manipulaters Team,” a group of Pakistani hackers behind the dark web identity “Saim Raza,” who sells spam and malware tools and services.

The Manipulaters’ core brand in the underground is a shared cybercriminal identity named “Saim Raza,” who for the past decade across dozens of cybercrime sites and forums has peddled a popular spamming and phishing service variously called “Fudtools,” “Fudpage,” “Fudsender,” etc.

The common acronym in nearly all of Saim Raza’s domains over the years — “FUD” — stands for “Fully Un-Detectable,” and it refers to cybercrime resources that will evade detection by security tools like antivirus software or anti-spam appliances.

One of several current Fudtools sites run by The Manipulaters.

The current website for Saim Raza’s Fud Tools (above) offers phishing templates or “scam pages” for a variety of popular online sites like Office365 and Dropbox. They also sell “Doc Exploit” products that bundle malicious software with innocuous Microsoft Office documents; “scampage hosting” for phishing sites; a variety of spam blasting tools like HeartSender; and software designed to help spammers route their malicious email through compromised sites, accounts and services in the cloud.

For years leading up to 2015, “admin@manipulaters.com” was the name on the registration records for thousands of scam domains that spoofed some of the world’s top banks and brand names, but particularly Apple and Microsoft. When confronted about this, The Manipulaters founder Madih-ullah Riaz replied, “We do not deliberately host or allow any phishing or any other abusive website. Regarding phishing, whenever we receive complaint, we remove the services immediately. Also we are running business since 2006.”

The IT network of The Manipulaters, circa 2013. Image: Facebook

Two years later, KrebsOnSecurity received an email from Riaz asking to have his name and that of his business partner removed from the 2015 story, saying it had hurt his company’s ability to maintain stable hosting for their stable of domains.

“We run web hosting business and due to your post we got very serious problems especially no data center was accepting us,” Riaz wrote in a May 2017 email. “I can see you post on hard time criminals we are not criminals, at least it was not in our knowledge.”

Riaz said the problem was his company’s billing system erroneously used The Manipulators’ name and contact information instead of its clients in WHOIS registration records. That oversight, he said, caused many researchers to erroneously attribute to them activity that was coming from just a few bad customers.

“We work hard to earn money and it is my request, 2 years of my name in your wonderful article is enough punishment and we learned from our mistakes,” he concluded.

The Manipulaters have indeed learned a few new tricks, but keeping their underground operations air-gapped from their real-life identities is mercifully not one of them.

ZERO OPERATIONAL SECURITY

Phishing domain names registered to The Manipulaters included an address in Karachi, with the phone number 923218912562. That same phone number is shared in the WHOIS records for 4,000+ domains registered through domainprovider[.]work, a domain controlled by The Manipulaters that appears to be a reseller of another domain name provider.

One of Saim Raza’s many ads in the cybercrime underground for his Fudtools service promotes the domain fudpage[.]com, and the WHOIS records for that domain share the same Karachi phone number. Fudpage’s WHOIS records list the contact as “admin@apexgrand.com,” which is another email address used by The Manipulaters to register domains.

As I noted in 2015, The Manipulaters Team used domain name service (DNS) settings from another blatantly fraudulent service called ‘FreshSpamTools[.]eu,’ which was offered by a fellow Pakistani who also conveniently sold phishing toolkits targeting a number of big banks.

The WHOIS records for FreshSpamTools briefly list the email address bilal.waddaich@gmail.com, which corresponds to the email address for a Facebook account of a Bilal “Sunny” Ahmad Warraich (a.k.a. Bilal Waddaich).

Bilal Waddaich’s current Facebook profile photo includes many current and former employees of We Code Solutions.

Warraich’s Facebook profile says he works as an IT support specialist at a software development company in Lahore called We Code Solutions.

The We Code Solutions website.

A review of the hosting records for the company’s website wecodesolutions[.]pk show that over the past three years it has shared a server with just a handful of other domains, including:

-saimraza[.]tools
-fud[.]tools
-heartsender[.]net
-fudspampage[.]com
-fudteam[.]com
-autoshopscript[.]com
-wecodebilling[.]com
-antibotspanel[.]com
-sellonline[.]tools

FUD CO

The profile image atop Warraich’s Facebook page is a group photo of current and former We Code Solutions employees. Helpfully, many of the faces in that photo have been tagged and associated with their respective Facebook profiles.

For example, the Facebook profile of Burhan Ul Haq, a.k.a. “Burhan Shaxx” says he works in human relations and IT support for We Code Solutions. Scanning through Ul Haq’s endless selfies on Facebook, it’s impossible to ignore a series of photos featuring various birthday cakes and the words “Fud Co” written in icing on top.

Burhan Ul Haq’s photos show many Fud Co-themed cakes the We Code Solutions employees enjoyed on the anniversary of the Manipulaters Team.

Yes, from a review of the Facebook postings of We Code Solutions employees, it appears that for at least the last five years this group has celebrated an anniversary every May with a Fud Co cake, non-alcoholic sparkling wine, and a Fud Co party or group dinner. Let’s take a closer look at that delicious cake:

The head of We Code Solutions appears to be a guy named Rameez Shahzad, the older individual at the center of the group photo in Warraich’s Facebook profile. You can tell Shahzad is the boss because he is at the center of virtually every group photo he and other We Code Solutions employees posted to their respective Facebook pages.

We Code Solutions boss Rameez Shahzad (in sunglasses) is in the center of this group photo, which was posted by employee Burhan Ul Haq, pictured just to the right of Shahzad.

Shahzad’s postings on Facebook are even more revelatory: On Aug. 3, 2018, he posted a screenshot of someone logged into a WordPress site under the username Saim Raza — the same identity that’s been pimping Fud Co spam tools for close to a decade now.

“After [a] long time, Mailwizz ready,” Shahzad wrote as a caption to the photo:

We Code Solutions boss Rameez Shahzad posted on Facebook a screenshot of someone logged into a WordPress site with the username Saim Raza, the same cybercriminal identity that has peddled the FudTools spam empire for more than 10 years.

Whoever controlled the Saim Raza cybercriminal identity had a penchant for re-using the same password (“lovertears”) across dozens of Saim Raza email addresses. One of Saim Raza’s favorite email address variations was “game.changer@[pick ISP here]”. Another email address advertised by Saim Raza was “bluebtcus@gmail.com.”

So it was not surprising to see Rameez Shahzad post a screenshot to his Facebook account of his computer desktop, which shows he is logged into a Skype account that begins with the name “game.” and a Gmail account beginning with “bluebtc.”

Image: Scylla Intel

KrebsOnSecurity attempted to reach We Code Solutions via the contact email address on its website — info@wecodesolutions[.]pk — but the message bounced back, saying there was no such address. Similarly, a call to the Lahore phone number listed on the website produced an automated message saying the number is not in service. None of the We Code Solutions employees contacted directly via email or phone responded to requests for comment.

FAIL BY NUMBERS

This open-source research on The Manipulaters and We Code Solutions is damning enough. But the real icing on the Fud Co cake is that sometime in 2019, The Manipulaters failed to renew their core domain name — manipulaters[.]com — the same one tied to so many of the company’s past and current business operations.

That domain was quickly scooped up by Scylla Intel, a cyber intelligence firm that specializes in connecting cybercriminals to their real-life identities. Whoops.

Scylla co-founder Sasha Angus said the messages that flooded their inbox once they set up an email server on that domain quickly filled in many of the details they didn’t already have about The Manipulaters.

“We know the principals, their actual identities, where they are, where they hang out,” Angus said. “I’d say we have several thousand exhibits that we could put into evidence potentially. We have them six ways to Sunday as being the guys behind this Saim Raza spammer identity on the forums.”

Angus said he and a fellow researcher briefed U.S. prosecutors in 2019 about their findings on The Manipulaters, and that investigators expressed interest but also seemed overwhelmed by the volume of evidence that would need to be collected and preserved about this group’s activities.

“I think one of the things the investigators found challenging about this case was not who did what, but just how much bad stuff they’ve done over the years,” Angus said. “With these guys, you keep going down this rabbit hole that never ends because there’s always more, and it’s fairly astonishing. They are prolific. If they had halfway decent operational security, they could have been really successful. But thankfully, they don’t.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

DHS Makes Senior Cybersecurity Appointments

DHS Makes Senior Cybersecurity Appointments

Two new senior cybersecurity appointments have been announced by the United States Department of Homeland Security.

Former lead solution engineer at Salesforce, David Larrimore, has been named as the Department’s chief technology officer. Between 2016 and 2019, Larrimore occupied the same position at the Immigration and Customs Enforcement (ICE) component.

Other roles held by Larrimore include an IT manager position at the General Services Administration and a job as a cloud strategist at the United States Department of Agriculture.

Larrimore is a graduate of Salisbury University in Maryland, where he obtained a Bachelor of Arts degree in Visual Communication.  

The second new appointment to be announced by the DHS was the accedence of Robert Costello to the position of chief information officer at the Cybersecurity and Infrastructure Security Agency (CISA).

Costello was previously employed at the United States Customs and Border Protection (CBP), stepping down in March this year to work in the private sector. He is also a United States Air Force and United States Air Force Reserve veteran. 

Over the course of nine years at CBP, Costello took on the roles of executive director of the Office of Information Technology’s Enterprise Networks and Technology Support Directorate and acting executive director of the Border Enforcement and Management Systems Directorate. 

Like Larrimore, Costello also previously worked at ICE, where he filled the position of director of network engineering, and also hold a Bachelor of Arts degree. However, Costello’s BA was in Organizational Leadership and he earned it in New York City at private Jesuit research university, Fordham University. 

“Larrimore and Costello’s appointments indicate that government is rethinking the type of talent it’s bringing in to help wrangle the country’s cybersecurity problem,” said Bill O’Neill, vice president of public sector at ThycoticCentrify, a provider of cloud identity security solutions based in Washington DC.

He added: “These individuals’ careers within military or law enforcement, coupled with their robust technical and engineering expertise reinforces DHS’s need for personnel that can leverage a proficient grasp of technology to both understand the inner workings of cybercrime and work efficiently to stop it.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Accellion Breach Impacts Beaumont Health

Accellion Breach Impacts Beaumont Health

Another Accellion breach victim has been named nine months after threat actors exploited zero-day vulnerabilities in the company’s File Transfer Application.

Beaumont Health has notified approximately 1500 patient that their personal data may have been compromised in the December attack on Accellion software. 

Goodwin Procter LLP, which was hired by Beaumont to provide legal services, used Accellion’s File Transfer software to carry out large transfers on behalf of its clients. On February 5, Goodwin advised the healthcare provider that patient data may have been compromised.

A digital forensics investigation launched by Goodwin after news of the Accellion breach came to light found that an unknown user had exploited a vulnerability in the software to download certain files.

“The potentially impacted information included a listing of roughly 1500 patients who had one of two procedures performed at a Beaumont Hospital,” said a statement issued on August 27 by Beaumont Health.

“The list included the patient name, procedure name, physician name, the internal medical record number and the date of service. This incident is limited to these patients and does not affect all patients of Beaumont.”

The healthcare provider added that no financial information had been impacted by the incident and that neither Beaumont nor Goodwin had found any evidence of the compromised data being used improperly. 

Goodwin, on behalf of Beaumont, contacted impacted individuals by letter at their last known address on August 27 to notify them of the data breach. 

“The notice letter specifies steps impacted individuals may take in order to protect themselves against identity fraud, including enrolling in complimentary credit monitoring services (if eligible), placing a fraud alert/security freeze on their credit files, obtaining free credit reports, remaining vigilant in reviewing financial account statements and credit reports for fraudulent or irregular activity on a regular basis and taking steps to safeguard themselves against medical identity theft,” stated Beaumont.

Following the incident, Goodwin is evaluating its data security procedures and protocols. 

News of the data breach comes a year after a phishing attack on Beaumont Health may have exposed the data of 6000 patients.  

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Student Sues Syracuse University Over Data Breach

Student Sues Syracuse University Over Data Breach

A private university in New York State is being sued for negligence by one of its students over a data breach that may have exposed thousands of Social Security numbers.

Syracuse University (SU) suffered a data breach on September 25 last year after an employee fell victim to a phishing attack and clicked on a malicious link. 

The compromised account was secured by September 28, but the security incident may have exposed the names and social security numbers of nearly 10,000 students, alumni and university applicants. 

An investigation into the security incident, which finished on January 14, was reportedly unable to definitively state whether files containing names and security numbers had been accessed by an unauthorized third party. 

In February, Syracuse University, which offers a Master’s in Cybersecurity, began contacting individuals affected by the data breach to warn them that their personal information may have been exposed. 

Commenting on the breach, Steven Bennett, senior vice president for international programs and operations at SU, said in February: “This was a really regrettable event. I understand it’s quite upsetting to some people.”

He added: “We are looking to tighten up the management of any document that has personally identifiable information in it. That was something that, in the wake of this event, we realized we really needed to do, and that’s underway at the moment.”

On Thursday, one of the students who was impacted by the breach filed a class action lawsuit against SU in Onondaga Supreme Court. The plaintiff alleges that SU didn’t do enough to protect the personally identifiable information (PII) entrusted to its care. 

He claims that inadequate staff cybersecurity training and deficient cybersecurity protocols at the educational establishment left sensitive data vulnerable to exposure. The lawsuit further alleges that SU increased the potential harm caused by the breach by waiting four months after the incident to inform impacted individuals. 

The plaintiff decided to take legal action against the university after he discovered an unauthorized charge on his checking account in the wake of the breach.

In a statement to The Daily Orange, the SU’s senior associate vice president for university communications, Sarah Scalese, said that Syracuse University does not comment on pending litigation.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Eight US States to Begin Accepting Digital Driving Licenses

Eight US States to Begin Accepting Digital Driving Licenses

Tech giant Apple has announced that eight US states will start accepting driver’s licenses and other state IDs that are stored on iPhones and Apple Watch.

Arizona and Georgia will be the first states to allow their residents to use this system, and will be followed by Connecticut, Iowa, Kentucky, Maryland, Oklahoma and Utah.

The first locations to accept IDs that are stored in iPhone Wallets will be select airport security checkpoints and lanes run by the Transportation Security Administration (TSA). Unlike in other countries, where a passport is widely used to travel by air, Americans usually only require some form of state ID to travel by air domestically.

Apple said it has introduced new security features that mean users do not need to unlock or physically handover their phones to police of security officials, helping allay privacy concerns. The company stated: “Only after authorizing with Face ID or Touch ID is the requested identity information released from their device, which ensures that just the required information is shared and only the person who added the driver’s license or state ID to the device can present it. Users do not need to unlock, show or hand over their device to present their ID.”

Apple added that the iPhone Wallet is a more secure method of storing and presenting ID compared to a physical wallet, as the person’s identity data is encrypted and the use of biometric authentication ensures only the person who added the ID to Wallet can view it.

Jennifer Bailey, Apple’s vice president of Apple Pay and Apple Wallet, commented: “The addition of driver’s licenses and state IDs to Apple Wallet is an important step in our vision of replacing the physical wallet with a secure and easy-to-use mobile wallet.

“We are excited that the TSA and so many states are already on board to help bring this to life for travelers across the country using only their iPhone and Apple Watch, and we are already in discussions with many more states as we’re working to offer this nationwide in the future.”

Nevertheless, there are security concerns around having so much sensitive information stored on a single device. Ashutosh Rana, senior security consultant at the Synopsys Software Integrity Group, said “Applications such as Apple Pay, Apple Wallet and Samsung Pay are already being used to store sensitive information, namely credit card information and personally identifiable information in the form of event tickets or membership cards. It doesn’t surprise me that such technologies will be used to store drivers’ licenses and ID cards. This will provide a quick and convenient user experience on the one hand. Then again, it may also make the security of the mobile device itself even more critical as it’s essentially a one-stop shop for malicious actors. The scale of such applications are increasing, and therefore so too should the security of mobile devices and supporting frameworks.”

Civil liberties campaigners have also expressed fears over the shift to digital IDs, demonstrated by the recent debate surrounding vaccine passports. In regard to the use of mobile driver’s licenses, Digital Rights group, Electronic Frontier Foundation, recently wrote: “Designed wrong, it might be a big step towards national identification, in which every time we walk through a door or buy coffee, a record of the event is collected and aggregated. Also, any system that privileges digital identification over traditional forms will disadvantage people already at society’s margins.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Tech CEOs: Multi-Factor Authentication Can Prevent 90% of Attacks

Tech CEOs: Multi-Factor Authentication Can Prevent 90% of Attacks

The use of multi-factor authentication (MFA) could prevent as much as 80–90% of cyber-attacks, according to figures cited by the US national security cyber chief.

Anne Neuberger, who’s deputy national security advisor for cyber and emerging technologies, said the stat was itself referenced by a number of the tech CEOs who attended a meeting with President Biden last week.

MFA is one of the five key measures that Biden has mandated be rolled out across federal government by November, as part of his executive order on cybersecurity.

Alongside MFA, she urged leadership teams at US organizations to implement four steps ahead of the holiday weekend. The others were strong passwords, prompt patching of all software, a review of incident response plans, and up-to-date backups which are segregated from the corporate network.

Given that the press conference with Neuberger was held on Thursday, it’s unlikely that these steps could be actioned in time by end-of-play Friday, especially her exhortation to “update and patch all software.”

However, it served once again to remind organizations that they must play their part in protecting the country and its national security from attacks.

As well as the executive order, Neuberger is said to have penned a letter to business leaders in June, urging them to take action against the mounting threat of ransomware.

It also follows a CISA and FBI alert this week warning that major ransomware attacks like those on Colonial Pipeline, JBS and Kaseya all occurred on holiday weekends.

To that end, Neuberger repeated CISA’s advice to firms that they should engage in threat hunting to try and head-off attacks before they can cause any damage.

“Security teams should proactively hunt on a network. It’s kind of like a digital version of walking the beat. Look for any initial signs of compromise or anything unusual on a network,” she said.

Interestingly, Neuberger also noted a slowing in the frequency of major ransomware attacks in the past couple of months, but wouldn’t be drawn on why this might be.

If you liked this article, be sure to check out this upcoming Online Summit session:

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

FTC Bans Stalkerware App in Industry First

FTC Bans Stalkerware App in Industry First

The Federal Trade Commission (FTC) has issued its first ever ban of a stalkerware app and its CEO, in what could be the start of a crackdown on this category of controversial surveillance software.

The FTC kicked SpyFone and CEO Scott Zuckerman out of the surveillance business due to concerns that the app “secretly harvested and shared data on people’s physical movements, phone use and online activities through a hidden device hack.” That’s basically the definition of stalkerware.

A second complaint was that the app required purchasers to “root” the Android devices they were looking to eavesdrop on, potentially voiding warranties and exposing them to security threats.

“The stalkerware app company not only illegally harvested and shared people’s private information, it also failed to keep it secure. The FTC alleges that SpyFone did not put in place basic security measures despite promising that it took ‘reasonable precautions to safeguard’ the information it illegally harvested,” the FTC notice continued.

“The stalkerware apps’ security deficiencies include not encrypting personal information it stored, including photos and text messages; failing to ensure that only authorized users could access personal information; and transmitting purchasers’ passwords in plain text.”

Moreover, in August 2018, a hacker managed to obtain data on 2200 consumers by accessing the company’s server. The FTC claimed that SpyFone failed to investigate the incident as it had promised.

Stalkerware operates in a kind of grey market, with software often marketed by nefarious developers as a legitimate way of monitoring teens and children, such as the Monitor Minor tool. However, in reality it is used by stalkers, domestic abusers and violent ex-partners to threaten and intimidate victims.

The FTC’s action this week could signal a new regulatory zeal in cracking down on the category.

Although Russia and Brazil are the top two countries for stalkerware, the US is in third place, according to Kaspersky data. The number of users is also on the rise in the UK.

As well as banning Support King, which did business as SpyFone, and CEO Scott Zuckerman, from selling surveillance software, the FTC will require them to delete any information illegally collected from their stalkerware apps and notify victims.

If you liked this article, be sure to check out this upcoming Online Summit session:

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains